Live data from Hacker News

Proposed Jail Time for Tech Companies Who Steal Data

trofire.com

171–180 of 203 posts

Re: Proposed Jail Time for Tech Companies Who Steal Data

#171
post #166
post #102

Earlier quoted context omitted.

It's easy to complain, but the problem is that status quo ISN'T WORKING . That's no longer on the table. So, you either have to come up with something constructive, or someone else will.

That's called "politician's fallacy" - "something needs to be done! This is something, therefore this needs to be done!". Obvious comment on it is that "something" must improve the situation after being done, merely doing something that doesn't work because current situation doesn't work is not likely to make it work. And if you're implying I have to right to criticize stupid proposals from politicians before I mysel…

> That's called "politician's fallacy" - "something needs to be done! This is something, therefore this needs to be done!".

You are arguing that doing nothing is superior to this proposal. While you may be correct, that train has left the station and is no longer on the table. Both the public and the politicians are in agreement on this, so, good luck changing that narrative.

> And if you're implying I have to right to criticize stupid proposals from politicians before I myself am elected into political office and make a full-formed policy proposal that solves all the problems - sorry, it's not how this thing works.

Sorry, but, at this point, either you come up with an alternative, or a proposed alternative is likely to get implemented. This IS already moving, so all you can do at this point is nudge the direction.

"The avalanche has already started, it is too late for the pebbles to vote."

Re: Proposed Jail Time for Tech Companies Who Steal Data

#172
post #154

Earlier quoted context omitted.

I think this is nonsense - it’s only true if you believe the businesses should have existed without protecting user privacy. GDPR and such don’t require you to go out and buy any hardware, or pass through any other expensive compliance audits. PCI/DSS didn’t kill e-commerce, it just set a minimum bar for what companies SHOULD have already been doing.

You dismissed my comment as “nonsense” but then didn’t refute anything I said. You implied it doesn’t matter if Google has less competition, and conveyed an unexamined assumption that the GDPR is the most reasonable and optimal way of assuring user privacy.

Is the cost of compliance truly prohibitive to new entrants? Because if it isn’t, then the claim truly is nonsense.

Re: Proposed Jail Time for Tech Companies Who Steal Data

#173

Earlier quoted context omitted.

Netflix is basically just an incremental update to the cable TV model: one centralized distribution service that negotiates broadcasting rights. The only real difference is that people are free to choose when to watch things, and even that is just an "Internet version" of the same thing people had with their VCRs (time shifting) or rental services. It is innovation, yes, but in a box that does not really change the l…

I think you are placing too much faith in the P2P technology and overlooking the consumer side. Facebook and YouTube users don’t care about what tech is underlying their apps, so long as it is convenient and easy is use. Would Mastodon, had it existed in 2003, have beaten FB? Depends if they could have presented a better user experience. Ultimately I don’t think it’s the tech- nor regulation that supposedly suppresse…

You are right that UX was a problem for P2P systems, but there is no technical reason that the UX problems could not have been solved had serious effort been devoted to it. The problem is that the technology had become de-legitimized and it was too risky to work on. Imagine if iTunes had natively supported P2P downloads with all of Apple's UX expertise going into it -- do you doubt that Apple could have designed a good P2P UI?

Blockchain is indeed another P2P application, but as you say, it is questionable as far as mainstream adoption goes (though it is likely to see use in non-consumer, business-to-business applications where the hard technical problem of identity is easier to manage). The thing about P2P filesharing is that it was very popular and was starting to enter the mainstream, and we are sitting here arguing about whether or not the UX problems were a cause or effort. Blockchain also came after years of stagnation and missed opportunities in P2P because the first killer app was snuffed out.

Re: Proposed Jail Time for Tech Companies Who Steal Data

#174

Earlier quoted context omitted.

“Did partners get access to messages? Yes. But people had to explicitly sign in to Facebook first to use a partner’s messaging feature,” Konstantinos Papamiltiadis, director of developer platforms and programs at Facebook, wrote in the blog post. “Take Spotify for example. After signing in to your Facebook account in Spotify’s desktop app, you could then send and receive messages without ever leaving the app. Our API…

So all they had to do was sign in, and those programs got access to private messages. What are you trying to refute, exactly?

I'm refuting that they gave away user data, which is factually false. Here's Facebook's explanation: https://newsroom.fb.com/news/2018/12/facebooks-messaging-par...

"In order for you to write a message to a Facebook friend from within Spotify, for instance, we needed to give Spotify “write access.” For you to be able to read messages back, we needed Spotify to have “read access.” “Delete access” meant that if you deleted a message from within Spotify, it would also delete from Facebook. No third party was reading your private messages, or writing messages to your friends without your permission. Many news stories imply we were shipping over private messages to partners, which is not correct."

It's become clear from engaging in this discussion that people aren't interested in facts or context, but have a chip on their shoulder about Facebook. Others have also been misinformed by inaccurate news stories.

I don't even use Facebook, yet it's pretty easy to understand the facts if you're actually interested in them.

Re: Proposed Jail Time for Tech Companies Who Steal Data

#175

Earlier quoted context omitted.

I think you are placing too much faith in the P2P technology and overlooking the consumer side. Facebook and YouTube users don’t care about what tech is underlying their apps, so long as it is convenient and easy is use. Would Mastodon, had it existed in 2003, have beaten FB? Depends if they could have presented a better user experience. Ultimately I don’t think it’s the tech- nor regulation that supposedly suppresse…

You are right that UX was a problem for P2P systems, but there is no technical reason that the UX problems could not have been solved had serious effort been devoted to it. The problem is that the technology had become de-legitimized and it was too risky to work on. Imagine if iTunes had natively supported P2P downloads with all of Apple's UX expertise going into it -- do you doubt that Apple could have designed a go…

iTunes is not a particularly great example of Apple providing excellent UX- but that aside, I doubt that they deigned to pursue P2P because of “delegitimization” or fear of having to deal with regulation.

Did these P2P services even offer any major consumer benefits aside from convenient ways to pirate media? Because that’s a value proposition that could return as the proliferation of streaming subscriptions (having to juggle multiple accounts at once to gain access to desired content) may cause some to simply kiss goodbye to streaming and return to the Pirate Bay. But even with legal challenges taking out the Groksters and the like, I fail to see how P2P for other purposes were damaged. They could’ve simply lost out because of lack of interest from both consumers (poor UX, no value add) and tech companies (saw no interest in pursuing such tech).

Re: Proposed Jail Time for Tech Companies Who Steal Data

#176
post #123

Earlier quoted context omitted.

> What is MY recourse? Your first statement would imply that the photographer has some responsibility to gain consent for the picture and its use.

And what about the other 30 people taking selfies whose background I am in. Those people didn't ask me because they didn't need to. They don't know me; I don't know them; we're not going to interact. Facebook, however, is coordinating all those pictures, their GPS coordinates, their tags, and working out everybody in them. I did not give anyone permission for that. Yet I don't have a way to stop it.

You can wear a mask

Re: Proposed Jail Time for Tech Companies Who Steal Data

#177

Earlier quoted context omitted.

You dismissed my comment as “nonsense” but then didn’t refute anything I said. You implied it doesn’t matter if Google has less competition, and conveyed an unexamined assumption that the GDPR is the most reasonable and optimal way of assuring user privacy.

Is the cost of compliance truly prohibitive to new entrants? Because if it isn’t, then the claim truly is nonsense.

You've just re-asked the very question my parent commenter should have addressed if they were going to dismiss my first comment, avoided addressing it yourself, then repeated the "nonsense" dismissal with the addition of an emphatic word.

People who are committed to logical argumentation – and I've seen this point made often on HN – will say that the reduction in the quantity and formidability of new startups is an acceptable price to pay for improved user privacy.

It still leaves open the question of whether the GDPR is a reasonable and optimal way of achieving improved user privacy, but at least it's a logical argument.

The question of whether GDPR really is reducing startup formation and success is unclear at this stage, and it's possible it will never really be known.

This Bloomberg article [1] from November cites research suggesting that it is, but argues that it's probably not a bad thing.

As I said, that's a fair enough position, but we all need to be clear clear about what our position is.

[1] https://www.bloomberg.com/opinion/articles/2018-11-14/facebo...

Re: Proposed Jail Time for Tech Companies Who Steal Data

#178

Earlier quoted context omitted.

So all they had to do was sign in, and those programs got access to private messages. What are you trying to refute, exactly?

I'm refuting that they gave away user data, which is factually false. Here's Facebook's explanation: https://newsroom.fb.com/news/2018/12/facebooks-messaging-par... "In order for you to write a message to a Facebook friend from within Spotify, for instance, we needed to give Spotify “write access.” For you to be able to read messages back, we needed Spotify to have “read access.” “Delete access” meant that if you del…

The claim wasn't that they opened a TCP connection to the partners and forced private data over the line. The claim was that they gave away access to partners that didn't need it, or even know about it.

"These partnerships were agreed via extensive negotiations and documentation, detailing how the third party would use the API, and what data they could and couldn’t access."

That's not how you treat people's private data. Allow the app to send messages, maybe allow the app to read replies to what it sent (did Netflix even need this at all?), don't give it full read access that relies on a pinky swear to keep data safe.

And at your earlier comment, sending a message does not inherently require that the sender be able to read anything.

Re: Proposed Jail Time for Tech Companies Who Steal Data

#179

Earlier quoted context omitted.

I'm refuting that they gave away user data, which is factually false. Here's Facebook's explanation: https://newsroom.fb.com/news/2018/12/facebooks-messaging-par... "In order for you to write a message to a Facebook friend from within Spotify, for instance, we needed to give Spotify “write access.” For you to be able to read messages back, we needed Spotify to have “read access.” “Delete access” meant that if you del…

The claim wasn't that they opened a TCP connection to the partners and forced private data over the line. The claim was that they gave away access to partners that didn't need it, or even know about it. "These partnerships were agreed via extensive negotiations and documentation, detailing how the third party would use the API, and what data they could and couldn’t access." That's not how you treat people's private d…

The linked Facebook article includes a screenshot of the feature in Spotify allowing people to send and receive Facebook messages.

"In order for you to write a message to a Facebook friend from within Spotify, for instance, we needed to give Spotify “write access.” For you to be able to read messages back, we needed Spotify to have “read access.” “Delete access” meant that if you deleted a message from within Spotify, it would also delete from Facebook."

You've got an axe to grind and its tiring me out. Whatever.

Re: Proposed Jail Time for Tech Companies Who Steal Data

#180

Earlier quoted context omitted.

Is the cost of compliance truly prohibitive to new entrants? Because if it isn’t, then the claim truly is nonsense.

You've just re-asked the very question my parent commenter should have addressed if they were going to dismiss my first comment, avoided addressing it yourself, then repeated the "nonsense" dismissal with the addition of an emphatic word. People who are committed to logical argumentation – and I've seen this point made often on HN – will say that the reduction in the quantity and formidability of new startups is an a…

The study is examining the amount of venture funding received in countries affected by GDPR, which seems unrelated to your statement “startups that never get off the ground because the cost of compliance is prohibitive”. Investors backing off because of perceived costs of compliance do not necessarily mean compliance is all that much expensive. Furthermore, it would appear that the study is incomplete.

> Wagman and Zhe Jin didn’t break down their data by business model, but if companies in the data extraction business receive less funding, Europe as whole and European consumers in particular probably won’t be any worse off.

> There’s also the question of data quality; Jia, Wagman and Zhe Jin cautioned in their paper that their dataset was not complete. And indeed, according to Pitchbook, a multinational firm that tracks public and private equity investment, while venture activity in Europe dropped somewhat in the third quarter and is likely to be relatively flat for the year as a whole, the share of capital received by software companies is higher than ever before, which would suggest tech innovation isn’t exactly being stifled.

It would seem that we are an impasse until further empirical data is collected. Perhaps an American experiment is in order?

Post reply on HN