Live data from Hacker News

Silicon Valley is terrified of California’s privacy law

techcrunch.com

81–90 of 553 posts

Re: Silicon Valley is terrified of California’s privacy law

#81

We need to have a conversation about jurisdictions in the digital age. The way governments have decided that having a website accessible in a country makes you liable to respect the law of this country is a convulted and hacky notion that has been accepted way too fast. The physical establishment rule was the only sound approach. The fact that some countries started to lose shouldn't have allowed them to rewrite the…

> We need to have a conversation about jurisdictions in the digital age. The way governments have decided that having a website accessible in a country makes you liable to respect the law of this country is a convulted and hacky notion that has been accepted way too fast. You know if you turn that around and say "How come we have to respect the laws of every country we do business in?" it sounds a lot more self servi…

You are dead wrong.

A completely friction free experience is exactly what you should expect.

Every political obstacle we create for data traveling through wires undermines the entire point of having an internet, and cedes more power to legislating bodies who are clueless about technology.

An individual should be empowered to serve data to another individual anywhere in the globe without barriers, period. If people can’t get behind that idea, then just get the fuck out of the way.

Re: Silicon Valley is terrified of California’s privacy law

#82

We need to have a conversation about jurisdictions in the digital age. The way governments have decided that having a website accessible in a country makes you liable to respect the law of this country is a convulted and hacky notion that has been accepted way too fast. The physical establishment rule was the only sound approach. The fact that some countries started to lose shouldn't have allowed them to rewrite the…

> We need to have a conversation about jurisdictions in the digital age. The way governments have decided that having a website accessible in a country makes you liable to respect the law of this country is a convulted and hacky notion that has been accepted way too fast. You know if you turn that around and say "How come we have to respect the laws of every country we do business in?" it sounds a lot more self servi…

The problem is that both views are essentially correct. The business is located in one country, but the customers can be in any country, and customers are not really entering another country and the businesses are kind of, but not really doing business "in" another country, to the extent that they know what country they're doing business in at all. We're still at that stage in the computer of using physical analogies to reason about how things "should be" even though those metaphores don't really work anymore.

Re: Silicon Valley is terrified of California’s privacy law

#83

So the author would rather see each state/country implement it’s own laws so that a small startup needs to ensure they comply with hundreds of regulatory jurisdictions... awesome.

Just don't do stupid privacy violating shit and you'll be fine anywhere.

Collect no information. Share no information. You are good - everywhere. And that really ought to be the default behaviour..

Re: Silicon Valley is terrified of California’s privacy law

#84
post #36

Earlier quoted context omitted.

Many companies have to RADICALLY change their architectures just to support these laws. And often the costs will be enormous. How do you scan all the logs that might somehow have an association with the requesting user that are in cold storage and alter data on write only archived optical media? You have to make an entire copy of it with those data removed. It's not about just treating customers better. It's governme…

>Many companies have to RADICALLY change their architectures just to support these laws. And often the costs will be enormous. Bummer dude. As an engineer type, I say, bring it on. Hard for me to have much sympathy ZuckerBrin can't afford another island or whatever because they made unethical decisions in the past. And if companies blow up because of it: good, that's the idea. There needs to be consequences.

Facebook will be just fine and probably come out ahead. Same with google. They have the money and resource to comply. These kind of regulation that don't take reality into account when written are a god send to large corps.

Re: Silicon Valley is terrified of California’s privacy law

#85

What will these laws accomplish in real terms? This just seems like poorly written legislation with the purpose of pandering to the populist public. I guess if it makes you all at least feel better.

Nothing, except soon there will be annoying legalese on every website form. Just like the GDPR. Large businesses will benefit at the expense of smaller ones. Lawyers will make more money selling these legalese templates, and sometimes when a big company doesn’t pay the right bean counter they’ll end up being investigated by regulators, and paying the state money to continue doing the same thing.

But it will be celebrated as a heroic victory because “privacy good. Business bad. I want a banana.”

Re: Silicon Valley is terrified of California’s privacy law

#86
post #52

I see a lot of comments deriding this law, can someone explain to me why these are bad things? Quoting from this article - https://techcrunch.com/2018/06/28/landmark-california-privac... - Businesses must disclose what information they collect, what business purpose they do so for and any third parties they share that data with. - Businesses would be required to comply with official consumer requests to delete that d…

I am on board with this law, but I’m curious how these two points will shake out: > - Consumers can opt out of their data being sold, and businesses can’t retaliate by changing the price or level of service. > - Businesses can, however, offer “financial incentives” for being allowed to collect data. Seems to me that it’s a distinction without a difference. Is there something I’m missing?

The way I'm guessing that will be clarified is that if you are charging for your product, you cannot offer a lower price point for allowing data collection. This will probably boil down to professional, paid for services, being allowed to collect only a small amount of information, and what is strictly needed.

The second line would allow companies to pay people to permit them to collect information. I imagine that because of the first statement, a company that is charging for the service cannot take advantage of this statement.

Re: Silicon Valley is terrified of California’s privacy law

#87
post #83

So the author would rather see each state/country implement it’s own laws so that a small startup needs to ensure they comply with hundreds of regulatory jurisdictions... awesome.

Just don't do stupid privacy violating shit and you'll be fine anywhere. Collect no information. Share no information. You are good - everywhere . And that really ought to be the default behaviour..

That is what they said about GDPR...

Re: Silicon Valley is terrified of California’s privacy law

#88
post #36

Earlier quoted context omitted.

The gist of these laws are all the same. Just respect ALL users' data from the start, and you shouldn't have any difficulty with compliance.

Many companies have to RADICALLY change their architectures just to support these laws. And often the costs will be enormous. How do you scan all the logs that might somehow have an association with the requesting user that are in cold storage and alter data on write only archived optical media? You have to make an entire copy of it with those data removed. It's not about just treating customers better. It's governme…

Just a shameless plug here -- we've been building a super developer friendly product to allow your application to comply w/ these laws with minimal (and sometimes NO code changes). You can email me directly mahmoud - @ - verygoodsecurity.com (https://verygoodsecurity.com/) and I can show you how it works.

Our idea is that complying w/ data security & privacy laws should be a devops shift + costs to keep up w/ them shouldn't stop us, as developers, from keeping us just as productive in our application development lifecycle.

We're still trying to figure out the right pricing structure for smaller companies, so if you have any insight there, I'm very interested to hear it.

Re: Silicon Valley is terrified of California’s privacy law

#89

So the author would rather see each state/country implement it’s own laws so that a small startup needs to ensure they comply with hundreds of regulatory jurisdictions... awesome.

The gist of these laws are all the same. Just respect ALL users' data from the start, and you shouldn't have any difficulty with compliance.

If there was an easily defined definition of "respecting users data" the we wouldn't be in this situation. Plenty of people think putting a clause in the EULA that says user data can be monetized is being respectful of user data, but this is often prohibited by law. Plenty of people don't think having a tool to dump user data is necessary to respect user data.

Re: Silicon Valley is terrified of California’s privacy law

#90

Earlier quoted context omitted.

GDPR is not a difficult law to comply with for an EU company, unless you're adtech.

Our EU employees could not file expense reports for months, because our expense management software (FROSCH or something) could not figure out GDPR compliance. Soooo I kinda suspect you're talking with absolutely no first-hand experience.

I’ve now been at three large multinational companies who have gone through GDPR process. It’s not easy or simple for an established company, but it’s not impossible.

Additionally:

- before GDPR most EU countries already had similar laws (e.g. data protection laws in Sweden). Sometimes for decades

- GDPR gave two years to become compliant

All in all everyone had two to twenty years to become compliant. Those who didn’t? I personally wouldn’t give two shits about them.

Your expense management software? Well, you company chose it. It looks like your company are responsible for making sure that the software you use is GDPR compliant. Someone at your company and at FROSCH screwed up and now you blame GDPR for the screw-up.

Post reply on HN