Live data from Hacker News

EU Copyright: Block Everything, Never Make Mistakes, but Don't Use Upload Filter

techdirt.com

171–180 of 266 posts

Re: EU Copyright: Block Everything, Never Make Mistakes, but Don't Use Upload Filter

#171

People underestimate what a big pain in the ass internet has been for the EU bureaucrats in the last 5 years. They can't just remove users freedom in one hit, they need to do it slowly: cookie laws, gdpr, copyright. And of course they always put a little bit of "sense" in every rule. This is a classic tactic that has been used by State organizations for maybe thousands of years. You can find examples in ancient Rome,…

GDPR is a good thing for citizens. But leave it to Americans to proclaim something that is good for people bad because it inconveniences corporations.

One of the first fines went to an online forum critizing GDPR.

Re: EU Copyright: Block Everything, Never Make Mistakes, but Don't Use Upload Filter

#172

Earlier quoted context omitted.

What if: > Genetics regulations, while I absolutely realize their necessity, have made it difficult for me to expand my side business into the EU. This would just be another road block for innovation. When I look at GDPR I see a safeguard against mass surveillance and dystopian add ruled societies.

GDRP is a reflection of a mass surveiled and dystopian ad ruled society. GDRP makes it HARDER for consumers once the’ve consented. All that will happen is that this will be gamed instead.

No it doesn't. Consumers can withdraw consent at any time, they have to give informed consent (i.e. the consent is void and null if the consumer can't reasonably be expected to understand what they consented to) and companies have to keep track of what data they acquired and what they have done with it.

The "consent" popups you see on loads of websites these days actually run counter to the GDPR because they usually opt-in by default or tie consent to uses for which that consent is not necessary. They also rarely provide detailed information about what data is used and what they do with it.

Re: EU Copyright: Block Everything, Never Make Mistakes, but Don't Use Upload Filter

#173

Earlier quoted context omitted.

What if: > Genetics regulations, while I absolutely realize their necessity, have made it difficult for me to expand my side business into the EU. This would just be another road block for innovation. When I look at GDPR I see a safeguard against mass surveillance and dystopian add ruled societies.

GDRP is a reflection of a mass surveiled and dystopian ad ruled society. GDRP makes it HARDER for consumers once the’ve consented. All that will happen is that this will be gamed instead.

That is not even remotely true. GDPR expressly affords revoking consent—and deleting any information gathered—at any time.

Re: EU Copyright: Block Everything, Never Make Mistakes, but Don't Use Upload Filter

#174
post #3

Policies like this make it glaringly obvious how little our government representatives around the world understand technology. It almost seems malicious, or at the very least anticompetitive. Who has access to such filtering systems already, or the resources to create one? GRPR regulations, while I absolutely realize their necessity, have made it difficult for me to expand my side business into the EU. This would jus…

Isn't the unspoken rule to just ignore GDPR until you're big enough and EU starts bitching at you, at which point you just pay them off and spend some resources on compliance?

If you escalate things to the point where you need to "pay them off" you're entering serious monetary fines territory.

Re: EU Copyright: Block Everything, Never Make Mistakes, but Don't Use Upload Filter

#175
post #95
post #58

Earlier quoted context omitted.

Blame the web devs and their bad implementation of it. It’s really not that hard to get right (unless of course you don’t really want to comply).

Agree that getting the region wrong is sloppy. But how does one avoid asking every time when cookies are blocked? What other implementation option is possible? This is what cookies are for .

Cookies don't matter. Personally identifiable information matters. Storing a "seen_cookie_notice=true" flag is fine (assuming the banner itself indicates that interacting with it will set the flag) as long as you don't use it for anything else.

Re: EU Copyright: Block Everything, Never Make Mistakes, but Don't Use Upload Filter

#176

Earlier quoted context omitted.

The greatest irony is EU regulators whining about the dominance of Google, Facebook, etc, while passing regulations like this which make it impossible for anyone to compete with their ilk. Google and Facebook will have no trouble building the automated filters that are mandated by this legislation. The impact of this will be felt entirely by smaller companies with either will shut down, or, more likely, will never be…

Despite best efforts, there's just no way around the general notion that affecting the tide affects all boats. You take the bad with the good of an internet with fewer restrictions, or you add both bad and good for everyone with restrictions. Even attempts to target legislation tend to have an unquantifiable ripple effect beyond the foresight of naive legislators.

Despite best efforts, there's just no way around the general notion that affecting the tide affects all boats.

Of course there is. You just add a minimum scale requirement before these obligations kick in, so they only affect sites that are big enough both to cause significant problems with illegitimate uploads and to have the resources to do something reasonable about it. Laws are written like this all the time in places with more sensible legal cultures, but the EU is infamous for not understanding why that is useful, and that brings us back to quanticle's point.

Re: EU Copyright: Block Everything, Never Make Mistakes, but Don't Use Upload Filter

#177
post #3

Policies like this make it glaringly obvious how little our government representatives around the world understand technology. It almost seems malicious, or at the very least anticompetitive. Who has access to such filtering systems already, or the resources to create one? GRPR regulations, while I absolutely realize their necessity, have made it difficult for me to expand my side business into the EU. This would jus…

What part of the GDPR makes things difficult for your side business? Every discussion I run into has people claiming this sorta thing, but my reading of the text make it fairly clear that for 90% of non-despicable use cases there's really not that much of a problem...

Re: EU Copyright: Block Everything, Never Make Mistakes, but Don't Use Upload Filter

#178
post #121

Earlier quoted context omitted.

You mean the DNT header which is set by default in browsers? Then we can simplify your proposal to: "Don't track people"

The only browser that set it by default was IE, and Microsoft ended that with Windows 10.

I've seen different Linux distros have it as default both for Firefox and Chromium as well.

But yes, the userbase for those is so small that we can assume that people with the header on simply don't want to be tracked.

Re: EU Copyright: Block Everything, Never Make Mistakes, but Don't Use Upload Filter

#179
post #173

Earlier quoted context omitted.

GDRP is a reflection of a mass surveiled and dystopian ad ruled society. GDRP makes it HARDER for consumers once the’ve consented. All that will happen is that this will be gamed instead.

That is not even remotely true. GDPR expressly affords revoking consent—and deleting any information gathered—at any time.

No, it doesn't. In fact, the rules about what must or must not be deleted are more complicated than that and in some respects ambiguous, and as yet there is little useful guidance from regulators to clarify those ambiguities. This is a significant problem with the GDPR.

Re: EU Copyright: Block Everything, Never Make Mistakes, but Don't Use Upload Filter

#180

Earlier quoted context omitted.

How is GDPR a problem at all? Is it so hard to avoid personalized tracking of unregistered users, ask users for their consent at sign-up time and implement a button for them to export and delete their data?

The problem with GDPR is that the actual scope of it applies to is rather unclear, and the regulatory guidance hasn't been reassuring as to what the actual extent will be in practice. For example, do email addresses on the comments on a blog site fall under that protection? If so, there are some agencies in charge of enforcing GDPR that are violating GDPR on their sites...

You seem to be making the same mistake a lot of people (especially those from countries with no regard for consumer protection or privacy) do with regard to the GDPR:

It's not about e-mail addresses. It's about personal information. It's not about what data you can have. It's about how you can use data.

You don't own my personal information, I do. If I give my information to you, you can only use it in whichever ways I consented to when I gave it to you. If you want to use it for something else, you need to ask me again. And you can't just give me a blanket CYA contract to sign just so you can decide later.

This is precisely how it would work in normal everyday social interactions. If I go to a Mom & Pop shop and give them my number so they can call me when my favorite brand of soup is back in stock that doesn't mean they can call me to tell me about random new stuff they carry or give my number away to someone else.

Personal information is owned by the person it is about. It gets murky with aggregates (but the GDPR helps you figure out which ones are still considered personally identifiable) but it's blindingly obvious for things like "enter your e-mail address".

Do you have an e-mail input in a contact form? I'm going to assume that'll be used so you can respond to me although it'd nice of you if you say that explicitly right there on the form. If it's a comment form, why do you need my address? Who will it be shown to? What are you going to do with it? Where will it be stored and how can I tell you to delete it later? That's why you now need to think up a Privacy Policy: these are questions you always had to answer for yourself but now you're legally required to make conscious decisions about this.

Is this too much of a hassle? That likely means you didn't have any good reason to collect that information in the first place. Great! Personal information is a liability and it's better to collect less of it than more. Although that may disappoint future Zuckerbergs, collecting people's private information (even if they give it away voluntarily) imbues a lot of responsibility on you if you don't want to be completely careless. And the GDPR is an example for a policy that gives that responsibility teeth and punishes companies who are careless.

You don't want to store passwords in plaintext. You don't want to hoard credit card details or medical data. Personally identifiable information is no different. The GDPR just provides ways for you to store and use that information legally, in addition to reiterating that privacy and control of your personal information is a human right.

Post reply on HN