Live data from Hacker News

Google’s GDPR Workaround

brave.com

121–130 of 629 posts

Re: Google’s GDPR Workaround

#121
post #17
post #8

It's really funny to see that yesterday, I was branded as a 'privacy nut' after the release of Android 10 as I was concerned about the privacy issues that are in Android. Then the Go modules proxy issue around the Go Programming language that raised suspicions about tracking usage statistics around downloading modules turned on by default without any consent and now this. I think there are some folks at Google who ha…

The Go module hash checking seems to be more about avoiding the problems encountered by other language repos integrity and versioning issues ( cough NPM), and in terms of tracking it seems about as invasive as Debian's popcon. Enabled by default can and should be the default for security-related features. I tend to agree about the rest of the creepiness, especially anything personally behavioral.

On HN it is taken as gospel that any information sent to a server will absolutely compromise your privacy. If anyone points out that the information is trivial or useless the rebuttal is instant - it can be cross referenced with other sources to build a complete profile of you.

If you want to know which Go modules I use, go check out my github. They're listed right there in import statements. If I'm hacking on a project that I want to keep private, I'll disable this feature with a command line flag - easy.

My issue with the paranoid folks in that thread is not that they made no sense (they can't help that), it was they were attacking the person who implemented the feature viciously. He had implemented a feature that a majority of Go developers had been requesting for 5+ years, had done it in a way that improved clean build time, improved security and could easily be disabled or replaced with a private DB. Literally what else could that man have done?

Even though all his work could be verified trivially (Go is open source!), they still chose to attack him.

Re: Google’s GDPR Workaround

#122
post #17
post #8

It's really funny to see that yesterday, I was branded as a 'privacy nut' after the release of Android 10 as I was concerned about the privacy issues that are in Android. Then the Go modules proxy issue around the Go Programming language that raised suspicions about tracking usage statistics around downloading modules turned on by default without any consent and now this. I think there are some folks at Google who ha…

The Go module hash checking seems to be more about avoiding the problems encountered by other language repos integrity and versioning issues ( cough NPM), and in terms of tracking it seems about as invasive as Debian's popcon. Enabled by default can and should be the default for security-related features. I tend to agree about the rest of the creepiness, especially anything personally behavioral.

Google (as well as surveillance states) use security arguments conveniently a bit too often to try and justify their actions.

Re: Google’s GDPR Workaround

#123

Earlier quoted context omitted.

The executives should face jail time. That would certainly light a fire under Google's ass to finally "do no evil".

Jail time? For telling companies what kinds of shoes you shop for on Amazon?

What about for creating and keeping up a global surveillance-capitalism system where billions of people are tracked, profiles, stripped of their privacy and manipulated, thus disrupting democracy and civic society?

Re: Google’s GDPR Workaround

#124
post #98
post #90

Earlier quoted context omitted.

"You know, that PATRIOT act really allows spying on everyone" "Come on that's just paranoia" Snowden leaks secret program that implements everything details in the patriot act. "WHO COULD HAVE SUSPECTED?"

If I remember right, after the leaks the faux-sophisticated take was "well of course , everyone knew this was going on, are you naive?".

I think some commentators were sophisticated enough to deposit both of these stinkers on the same thread...

Re: Google’s GDPR Workaround

#125

>I was branded as a 'privacy nut' Companies do actually employ shills to go on forums and try to sway public opinion. They call them something like public advocates, doesn't change the idea though.

I'm no marketing expert, but I doubt that the best way Google can think of to sway public opinion is to call people privacy nuts. Google employs over 100,000 people and even more people work at similar companies like Facebook or buy targeted ads. Many of these people browse Hackernews and get offended if others accuse their livelihoods of being evil.

Re: Google’s GDPR Workaround

#126
post #8

It's really funny to see that yesterday, I was branded as a 'privacy nut' after the release of Android 10 as I was concerned about the privacy issues that are in Android. Then the Go modules proxy issue around the Go Programming language that raised suspicions about tracking usage statistics around downloading modules turned on by default without any consent and now this. I think there are some folks at Google who ha…

> branded as a 'privacy nut' Only the Paranoid Survive. A book by The President and CEO of Intel. https://en.m.wikipedia.org/wiki/Andrew_Grove

Wide-ranging thoughts and examining what-ifs makes you a curious individual. Failure to counterbalance confirmation bias by critically examining and deconstructing your own hypotheses makes you a crackpot.

The main difference between the two is just which paranoid thoughts you give credence to.

Re: Google’s GDPR Workaround

#127

>I was branded as a 'privacy nut' Companies do actually employ shills to go on forums and try to sway public opinion. They call them something like public advocates, doesn't change the idea though.

Could also be selfishness, I remember reading an article about leaked internal Facebook employees where some employees would pressure others to not talk about privacy or sensitive topics because it would hurt the stock price further and therefore hurt all employees. I can't seem to find the article. I can see employees of big companies trying to sway or minimize decisions to feel like they are protecting their future earnings.

Re: Google’s GDPR Workaround

#128

Earlier quoted context omitted.

> Your other claims are more reasonable. But they would lead me to the conclusion we need bigger fines on bigger businesses. Not absolutely bigger, as the law already does, but relatively bigger. The more power you have to break the law, the bigger the stakes should be. GDPR penalties are a flat fee or a percentage of revenue, whichever is higher . If Google is truly willfully violating the GDPR, the maximum penalty…

If their whole business model is selling personal data, then 4% is clearly just a cost of running their business.

Given that "European Commision fines" is its own bullet point under "Costs and Expenses" in Alphabet's latest quaterly report, that view sounds about right.

Re: Google’s GDPR Workaround

#129
post #17

Earlier quoted context omitted.

The Go module hash checking seems to be more about avoiding the problems encountered by other language repos integrity and versioning issues ( cough NPM), and in terms of tracking it seems about as invasive as Debian's popcon. Enabled by default can and should be the default for security-related features. I tend to agree about the rest of the creepiness, especially anything personally behavioral.

On HN it is taken as gospel that any information sent to a server will absolutely compromise your privacy. If anyone points out that the information is trivial or useless the rebuttal is instant - it can be cross referenced with other sources to build a complete profile of you. If you want to know which Go modules I use, go check out my github. They're listed right there in import statements. If I'm hacking on a proj…

[deleted]

Re: Google’s GDPR Workaround

#130

Earlier quoted context omitted.

Jail time? For telling companies what kinds of shoes you shop for on Amazon?

Yep. Privacy violations and leaks should be punished with fines and jail time. Period. End of sentence. Just like execs have to personally sign for and are accountable for their financial statements, they should do the same thing with privacy. GDPR sets a very common leveling of the field so it's completely fair now.

"Privacy violation" is a huge, gigantic category of all kinds of things. One kind of privacy violation is completely different from another; some privacy violations are completely harmless, and some are actually directly harmful, and some in between.

Giving jail time for any of these is like giving jail time for any kind of "offensive behavior". Maybe someone just didn't like what someone said and called it offensive, or maybe someone physically attacked someone else. You don't get jail time just because someone claimed offense, you have to prove harm, and fit the punishment to the crime.

This is why I can't take privacy advocates seriously. Their effort to fight for all privacy undermines the attempt to prevent real harm from specific kinds of information being exposed.

Post reply on HN