Live data from Hacker News

Silicon Valley is terrified of California’s privacy law

techcrunch.com

181–190 of 553 posts

Re: Silicon Valley is terrified of California’s privacy law

#181
post #19

Does anyone know the real implications of the CCPA for things like Sift Science, Google's Recaptcha, and maybe even Cloudflare? All of these are based on many companies contributing information about users to create profiles which curb abuse. And Sift/Google/etc. get commercial benefit from this data sharing, which might trigger the CCPA. But you can't give bad actors the ability to opt out of this kind of data shari…

If Recaptcha gets the ax due to CCPA, the internet will be better off for it.

There needs to be some way to identify non-humans and/or malicious actors.

Re: Silicon Valley is terrified of California’s privacy law

#182

Earlier quoted context omitted.

Just block your website from being accessed in any country where you aren’t sure you can comply with their laws. A lot of sites are doing that for GDPR.

The GDPR only applies to websites / companies that either have offices / legal status in a european country or that specifically target / sell to europeans (e.g. they place ads in Europe, ship merchandise to Europe, etc.). You don't need to block european countries if you have no business or interest there.

It also applies to sites not in the Union if their processing activities are related to "the monitoring of their behaviour as far as their behaviour takes place within the Union". (Article 3 section 2(b)).

Unlike the target/sell case, this doesn't seem to require intent to specifically deal with Europeans.

If you aren't sure that what you do doesn't count as monitoring behavior, then blocking can make sense.

Re: Silicon Valley is terrified of California’s privacy law

#183
post #52

I see a lot of comments deriding this law, can someone explain to me why these are bad things? Quoting from this article - https://techcrunch.com/2018/06/28/landmark-california-privac... - Businesses must disclose what information they collect, what business purpose they do so for and any third parties they share that data with. - Businesses would be required to comply with official consumer requests to delete that d…

Some problematic scenarios: - How do you identify what is customer data? There may be information stored in logs somewhere. Do you now have to write log parsers to extract personal data for everything that previously you just stored for general debugging and security purposes? How do you even know all the permutations of personal data that came be stored in the logs. There are possibly infinite possible ways personal…

> engineers now must fully understand the consequences of anything they log

I don't think this is quite the dichotomy you make it out to be.

So we can create optimizing compilers, but we can't figure out what to log?

This seems like a problem of never having motivation to solve the problem before.

"We can't do that, it's too hard" is often a mea culpa I'm industry when they oppose regulation. Then they will come up with a solution from having actually spent some effort to actually think of potential solutions.

Re: Silicon Valley is terrified of California’s privacy law

#184

How is this not a violation to the first amendment? Does the first amendment not extend as follows: (?) As a citizen don't I have the right to create a business and privately take notes on whatever I'd like to about my customers? If i run a dry cleaners and take notes about my customers, should I be obligated to disclose these notes or even the existence of these notes to my customers? I don't see why extending the d…

> As a citizen don't I have the right to create a business

Nope. That's not an express Constitutional limit imposed on states and thus states general police powers extend to regulating that behavior. (To the extend the proposed business engages in, or impacts, interstate commerce there is also federal regulatory power under the commerce clause, but the immediate issue is the broader state regulatory power.)

Re: Silicon Valley is terrified of California’s privacy law

#185

Earlier quoted context omitted.

Its intended to fuck over Facebook. If you're charging for a service you can simply offer a discount for allowing data collection after bumping prices for everyone by the same amount, Facebook however isn't charging. Facebook can't offer a discount on free, and they can't just force only users who opt-out to go pay (because that falls afoul of the first quote you put). Basically this puts Facebook in a real tight sit…

Opt-out for GDPR is under 1%. Most people don't care at the moment, sadly. However, a mass movement to opt-out would absolutely affect them. This lays the groundwork for that, and thats what they should be afraid of.

> Opt-out for GDPR is under 1%. Most people don't care at the moment, sadly.

Correct.

On top of that, many people on HN, aware of the privacy implications, continue to have a Google Home / Alexa in their homes. Myself included.

Sadly, I (and many people) simply don't care about privacy. The probability/expected negatives of surveillance abuse is far less than the benefit of being able to turn my lights on and off with my voice.

The US will for sure become like China in 10-20 years, with regards to surveillance.

Re: Silicon Valley is terrified of California’s privacy law

#186

Earlier quoted context omitted.

> We need to have a conversation about jurisdictions in the digital age. The way governments have decided that having a website accessible in a country makes you liable to respect the law of this country is a convulted and hacky notion that has been accepted way too fast. You know if you turn that around and say "How come we have to respect the laws of every country we do business in?" it sounds a lot more self servi…

> Nobody said your movie has to be viewable in China. You will of course forgive me if I do not find economic favoritism that benefits politically connected industrialists, the restriction of freedom of thought by oppressive governments, and the general Balkanization of the Internet, to be things that we ought to celebrate. Once upon a time the memes of Internet culture would suggest that "information wants to be fre…

> Once upon a time the memes of Internet culture would suggest that "information wants to be free!" Oh, sweet halcyon days of yore!

Agreed. But martech pretty much killed that dead.

Re: Silicon Valley is terrified of California’s privacy law

#188
post #78

Earlier quoted context omitted.

It's all about marketing and perception. See how credit card companies set rules regarding surcharges and cash. Before credit card companies tried to prevent a discount being offered if a customer paid cash as stipulation for taking credit cards. Durbin Act of 2010 changed that which made it legal in all 50 states.

> Durbin Act of 2010 changed that Ah! I was always saying I'm surprised by the brazenness of gas stations to offer cash discounts in violation of their credit processing agreements. Today I learned that as of 2010 the law protects them. Thanks!

The gimmick has always been that you can't charge more for using a credit card, but you can offer a cash discount. So basically you just have to advertise the credit card price rather than it being a surprise fee added on at the last second.

Which makes sense, most other countries actually roll sales tax and others into the advertised prices, and what you see is what you'll pay out the door.

Re: Silicon Valley is terrified of California’s privacy law

#189

Earlier quoted context omitted.

The GDPR does a lot to protect user data. As someone that’s implemented stuff at a huge company for GDPR and at my startup, it was waaaay harder at the larger company. The ICO has been beyond helpful with the few questions I’ve had recently and implementation for my startup has been fairly straightforward.

“The GDPR does a lot to protect user data” As you proceed to state absolutely nothing. Before GDPR my information was in a bunch of databases managed by other people. After GDPR my information is in the same databases managed by the same people. Except now they have legalese stating this totally fucking obvious fact. Before GDPR if my information was hacked and used to hurt me, the business was not liable. After GDPR…

Dude, GDPR's effects just began. Give it time. A sudden enforcement of GDPR would destroy too many business and so it's being enforced gradually. Still, there are beginning to discuss the complete outlaw of the real time bidding in adtech because completely incompatible with the GDPR. That means destroying bilions of dollars of businesses, so they go slow until there's enough political consensus to do so without fear of retaliative lobbying. This is not something that is done overnight.

Re: Silicon Valley is terrified of California’s privacy law

#190

So the author would rather see each state/country implement it’s own laws so that a small startup needs to ensure they comply with hundreds of regulatory jurisdictions... awesome.

The gist of these laws are all the same. Just respect ALL users' data from the start, and you shouldn't have any difficulty with compliance.

The GDPR is pretty bad for under 5 engineer startups. They can be very privacy respecting small businesses that charge for their product, like sql training courseware[0], and wouldn't mind clearing what little personal data they had on you (user server logs, billing info, etc).

But being privacy respecting and properly complying with GDPR with audit log systems, etc are 2 different things that require hiring 1 or 2 extra engineers or causing them to pause the companies roadmap as 1 or more people implement government bureaucracy infrastructure for half a year.

If they say it's easy and cheap, then they haven't actually tried to do it properly and are exposing themselves to multi-million dollar penalties.

[0] https://www.brentozar.com/archive/2017/12/gdpr-stopped-selli...

Post reply on HN