Live data from Hacker News

Google’s GDPR Workaround

brave.com

81–90 of 629 posts

Re: Google’s GDPR Workaround

#81
post #22
post #6

Earlier quoted context omitted.

And I'm very annoyed that your initial reaction to reading this article is to blame the GDPR instead of blaming Google for these shady practices. Boycott that crap, move to other services. This shouldn't be acceptable. I'm very happy that the GDPR exist, if only because it forced all these websites from explicitly giving me a list of the literally hundreds of partners they want to share my data with, along with a way…

- my initial reaction is to blame GDPR, yes, because it's just security theater that does so little to actually ensure privacy. Sure Google is at fault but GDPR was supposed to regulate this and it is clearly failing to do so. And if you want to boycott it you're welcome to but they've built an empire with their cloud, search, email, etc to the point where that would be pretty difficult and annoying to the average co…

> GDPR was supposed to regulate this and it is clearly failing to do so

How do you know? The fact that there's still crime doesn't mean that law enforcement doesn't do anything. Somebody reports an alleged violation, an investigation is started, and maybe the investigation will produce that Google is in violation (in which case a fine will "regulate" Google's behavior) or they are not (in which case it may be fair to criticize GDPR for allowing that behavior, or it may not be because the info wasn't correct).

> almost every site uses Google analytics which doesn't really comply with do not track all too well, and Google will then share their data with everybody else

Unless you have specific info, I believe you're mistaken here. GA is generally seen to be compliant if anonymizeIp is active and you're not pushing PII into it via customization. Google is, if I understand it correctly, not "sharing" GA raw data with anyone, but analyzing the data for their own research and providing the website owners with aggregate data (i.e. demographic information) without sharing data on individuals. I'm not a fan of GA, but I haven't seen any info that they're that obviously in violation.

> It was a pain for us to become GDPR compliant because that disables our metrics entirely and requires a bunch of banners and checkboxes everywhere even though we literally store nothing.

What was the specific pain? I get that having to add a privacy info sucks (and might cost money if you get a customized version), but I never found it to be that big a deal. If you don't store any PII, it's pretty straight forward, and so will the procedures be if anybody asks about the data you stored: just inform them that your systems do not store any data in general and also didn't store any data on them in particular.

Re: Google’s GDPR Workaround

#82

>I was branded as a 'privacy nut' Companies do actually employ shills to go on forums and try to sway public opinion. They call them something like public advocates, doesn't change the idea though.

Should their point of view just not be heard then, in such discussions?

Is it really a point of view, or is it a carefully engineered sequence of words designed to program people with certain opinions? There are lots of ways to "program" people that bypass their rational mind, and creating a false sense of social consensus is one of them.

Re: Google’s GDPR Workaround

#83
post #40
post #13

What is sad is that the EU commission doesn't take real action against Google. At best we are to expect a slap in the hand, at worst, the investigations will drag on and nothing will happen.

I was curious what the maximum fine for Google could be under GDPR. Google's 2018 revenue was $136.22 billion. GDPR allows for a maximum fine of 4% of global turnover. At a maximum 4%, GDPR could impose up to a $5.5 billion fine. I agree, getting something closer to the maximum might help the situation. Although ultimately, my bet is that Google is already baking the 4% revenue risk into their business model. If that…

They can assess that fine for each major incident, can't they?

Re: Google’s GDPR Workaround

#84
post #64

Targeted ads are already a serious leak of information. If somebody looks over my shoulder and sees the ads presented to me, they can infer things about me. Also, if a malicious actor targets an ad to a group of people, and some of these people buy the advertised items, then the actor can infer things about those people not necessarily related to the items sold.

if someone looked over your shoulder and saw you browsing HN they could infer things too

Yet, they choose to surf to HN.

They're not choosing to have targeted ads that share their info around the web and cause someone over their shoulder to infer things about them.

That's the point -- we should have that choice. And the default should be "no".

Re: Google’s GDPR Workaround

#85
post #64

Targeted ads are already a serious leak of information. If somebody looks over my shoulder and sees the ads presented to me, they can infer things about me. Also, if a malicious actor targets an ad to a group of people, and some of these people buy the advertised items, then the actor can infer things about those people not necessarily related to the items sold.

At my last job the traffic was filtered through a proxy due to FINRA regulations. I’d see Portuguese ads for diabetes medication and there were 2 Brazilian guys in the office.

Seemed like a major HIPAA violation to me.

Re: Google’s GDPR Workaround

#86
post #64

Targeted ads are already a serious leak of information. If somebody looks over my shoulder and sees the ads presented to me, they can infer things about me. Also, if a malicious actor targets an ad to a group of people, and some of these people buy the advertised items, then the actor can infer things about those people not necessarily related to the items sold.

if someone looked over your shoulder and saw you browsing HN they could infer things too

Yeah, but HN is not shown as part of every website out there.

Re: Google’s GDPR Workaround

#87

>I was branded as a 'privacy nut' Companies do actually employ shills to go on forums and try to sway public opinion. They call them something like public advocates, doesn't change the idea though.

Should their point of view just not be heard then, in such discussions?

Not if it's disguised as a private individual (which is the default assumption in discussion forums such as this one).

If a company wants to present its views, they can do so via press releases or clearly mark their posts as such (or via verified accounts like on Twitter).

Re: Google’s GDPR Workaround

#88

>I was branded as a 'privacy nut' Companies do actually employ shills to go on forums and try to sway public opinion. They call them something like public advocates, doesn't change the idea though.

Should their point of view just not be heard then, in such discussions?

I think if you want the point of view of a corporation you should feel free to go read their official blog, press releases, etc. They have plenty of ways to spread their point of view that aren't people pretending to be individual commenters.

Re: Google’s GDPR Workaround

#89
post #23

Earlier quoted context omitted.

Q4 2018 earnings were around $40 billion. EU will have to try significantly harder.

That's the revenue, not profit.

That's also the point. Profit shouldn't have anything to do with fines. Redress and compensation should. A fine is supposed to make business-as-usual unpalatable.

Re: Google’s GDPR Workaround

#90
post #8

It's really funny to see that yesterday, I was branded as a 'privacy nut' after the release of Android 10 as I was concerned about the privacy issues that are in Android. Then the Go modules proxy issue around the Go Programming language that raised suspicions about tracking usage statistics around downloading modules turned on by default without any consent and now this. I think there are some folks at Google who ha…

"You know, that PATRIOT act really allows spying on everyone"

"Come on that's just paranoia"

Snowden leaks secret program that implements everything details in the patriot act.

"WHO COULD HAVE SUSPECTED?"

Post reply on HN