Live data from Hacker News

Google’s GDPR Workaround

brave.com

341–350 of 629 posts

Re: Google’s GDPR Workaround

#341
post #184

Earlier quoted context omitted.

Every company I've worked at has had an explicit policy of not commenting on that company's business on the internet.

Just because a company has a policy does not mean that employees adhere to that policy.

Or that they start every comment with 'I'm an employee of X'

They might just say, 'That seems silly!', 'You're a nut', 'Do you have a source other than yourself'. Or they might just downvote stories that have a negative effect on their income.

You've got 100k people working at google and many of them are going to be active on this type of forum. The same goes for the other big guys that have a ton of employees

Re: Google’s GDPR Workaround

#342

I checked the sample log provided. Below is the google_gid for different publishers, there is no proof of overlap, they have different google_gid for same person. Which is exactly what google describes. [1] I don't understand what Brave claims. d.agkn.com CAESEP-S3Zs5f0_kq11XTCZP_mE id.rlcdn.com CAESEPpf2T4-2AsAR_4rer3RfNs image6.pubmatic.com CAESEB9H3qdV26kxEiz-BJ_TY-M pippio.com CAESEJyqG1Pg1j-_scqW8kDzTkg token.ru…

which is the "workaround" to the gdpr the article badly describes (probably because brave upcoming ad network will do the same but more workaroundily)

now those are used to match a 3rd party id. you just need a gdpr_workaround schema in your data base with two columns user-id, google-random-id with N-1 records indexed both ways.

gdpr has restrictions on pin pointing a single person. this is effectively doing that, but claim it is not, because random ids. apple is just a little better with how device-advertiser-id works.

Re: Google’s GDPR Workaround

#343

Earlier quoted context omitted.

I think that’s incorrect, relevant ads could be displayed based purely on the site content, without user info attached to ad calls. We’ve been there.

True and irrelevant. If you're displaying ads based on site content, you are matching ads to the site content, not to the viewer.

It is actually relevant because they are matching the ads to the user, only it happens by a proxy variable which is the site you are visiting.

Re: Google’s GDPR Workaround

#345

Earlier quoted context omitted.

I think that’s incorrect, relevant ads could be displayed based purely on the site content, without user info attached to ad calls. We’ve been there.

True and irrelevant. If you're displaying ads based on site content, you are matching ads to the site content, not to the viewer.

false and irrelevant. advertising to the site content really means "to the site's content audience demographics".

what you describe is actually the personal ad targeting apocalypse we experienced recently. very well illustrated with the famous Taboola scam, where tabloid sites only had ads taking you to other tabloid sites.

Re: Google’s GDPR Workaround

#346
post #309

This is exactly what happened in the McDonald's "hot coffee" lawsuit. It wasn't some "Karen" who hit a bump while driving. It was an elderly woman (in her 70s, IIRC), sitting in the passenger seat. McDonalds already had complaints (and some lawsuits) over the (significantly higher than industry standard) temperature of their coffee, so this wasn't exactly out of the blue. She ended up with 3rd degree burns on her leg…

Curious how this one has changed on the internet. From a UK perspective I'd always thought of it as a case of crazy pay-out. Why does this one women get several million dollars (although googling reveals this number went down a bit on appeal)? Especially if others had a similar experience. Either there should be a limit on the temperature of hot drinks, or there shouldn't. The fact a warning is deemed adequate seems…

The payout is because _without it_ companies wouldn't change what they do. The punitive damages serve as an "example" for other corps to not do the same thing or risk losing that much money, too. If anything, I think punitive damages for corporate negligence would be _higher_. Maybe some of the payment could be directed to funds for victims instead of all going to one person, but that person (and their lawyers) also had to combat a multi-million dollar defense team.

Re: Google’s GDPR Workaround

#347
post #17

Earlier quoted context omitted.

The Go module hash checking seems to be more about avoiding the problems encountered by other language repos integrity and versioning issues ( cough NPM), and in terms of tracking it seems about as invasive as Debian's popcon. Enabled by default can and should be the default for security-related features. I tend to agree about the rest of the creepiness, especially anything personally behavioral.

> Enabled by default can and should be the default for security-related features. Not since Google uses the argument of increased security to justify data collection for quite some time in the interest of itself.

You are free to setup your own DB if that's a concern for you. It's a totally justified concern, but this is just concern-trolling. Most people would use this either way. People with strong privacy concerns may setup their own DB, but they represent the minority (despite the heavily privacy-biased stance of HN users).

If you're in the minority, you should expect to have to do more work to get the right balance of security and privacy.

Re: Google’s GDPR Workaround

#348

Earlier quoted context omitted.

The real time bidding on ad placements seems like a thing that a user could never give consent to as it's literally feeding your info to a massive ever churning list of companies that get to bid on it. Aka - you land on a site, it send your IP and whatever identifiers it has to 10,000+ companies who all then figure out if they want to bid on showing you an ad.

Do you have to give consent for each individual third party your data gets shared with? I’d thought that if you give consent for some purpose, the company can use whatever processors it wants as long as it ensures they protect your privacy.

Yep, thats what those ridiculous pop up boxes with 400 (I counted one) "carefully select partners" of the websitd you visit are supposed to be.

It is IMO just a mockery of the intent of the law and I wonder when this will be punished.

I personally think GDPR might be a bit strict, but adtech have practically been begging for this for years so acting surprised now doesn't cut it.

Re: Google’s GDPR Workaround

#349
post #325
post #287

Earlier quoted context omitted.

It's mostly harmless to spill regular drinkable-temperature coffee on yourself, so she took appropriate level of precaution (i.e. very little) for that reasonable assumption. She shouldn't be to blame even if she showered in the coffee. To bring it back on topic: when web users are told "we care about your privacy", they should be able to take it at face value. When the company then weasels out of the headline promis…

Yes, once again, when an issue is systemic (in this case, all coffees by McDonalds are super-hot), the user is not to blame but the vendor/system designer. It reminds me of that recent case of 90%+ passengers "putting the oxygen masks wrong" because they are "idiots" - an opinion that seemed to be shared by a lot of people even here on HN, but even more so on Twitter. https://www.stuff.co.nz/travel/travel-troubles/10…

Why the hell does that article not include a photo or diagram of a mask properly worn? Even despite knowing that it goes over your mouth and nose, the design of the mask makes it difficult to understand how one would actually do that. Seems like a huge, huge omission.

Re: Google’s GDPR Workaround

#350
post #96

Earlier quoted context omitted.

Debian's popcon is really irritating because Debian actually uses it as a source of evidence... systematically eliminating those of us who keep it off for privacy/security reasons.

Let me get this straight. You have an opt-in way of telling them what you use, which you don't use and then get upset because your use isn't considered? What should do they do, send a surveyor to your house? Sound decision making requires metrics. If you opt-out of metrics, you don't get to participate in decisions.

Sound decision making requires reasonable metrics. To quote the lead dev of popcon when someone said that they couldn't recommend it due to specific concerns:

"If you deal with people with strict security/privacy requirement, you are correct to do so. I would do the same."

Post reply on HN