Live data from Hacker News

Silicon Valley is terrified of California’s privacy law

techcrunch.com

261–270 of 553 posts

Re: Silicon Valley is terrified of California’s privacy law

#261

Lot's of (mis)information floating around regarding CCPA. I recommend taking the time to read the actual text[1]. The text is not particularly long or dense. There has been a lot of speculation about complex compliance procedures, but the main thrust of the bill is to provide users with information about how their data is collected, who it is shared with, and the rights to prevent certain types of selling or sharing…

The main problem is that the bill is rushed and the legal bits have a lot of ambiguity. source: CCPA and its potential compliance has been a big PITA

It's not rushed. It's agile!

Re: Silicon Valley is terrified of California’s privacy law

#262
post #243

Earlier quoted context omitted.

How do car dealerships do it then?

Because when you buy a car you aren't usually buying "a [year] [make] [model] [with these features]". You're buying " that specific car with that unique identifier"

The correct answer is “it’s not the law”. Or at least the way the OP described it.

https://www.ftc.gov/tips-advice/competition-guidance/guide-a...

Re: Silicon Valley is terrified of California’s privacy law

#263
post #172
post #52

I see a lot of comments deriding this law, can someone explain to me why these are bad things? Quoting from this article - https://techcrunch.com/2018/06/28/landmark-california-privac... - Businesses must disclose what information they collect, what business purpose they do so for and any third parties they share that data with. - Businesses would be required to comply with official consumer requests to delete that d…

> - Consumers can opt out of their data being sold, and businesses can’t retaliate by changing the price or level of service. This is something I object to. It's just fundamentally stupid and doesn't make sense. The entire premise of free exchange is that I give you my services in exchange for something of value of yours. Making it illegal to withhold services if you don't give up your data is crazy. The only reason…

You just have to change the onboarding process to include a fee, and offer an incentive/rebate of the subscription price to match the cost to basically make it free. That way if they decide to change their mind and not give their data, you're still in the clear by removing the incentive and either charge their payment method or disable their service until they do (or reenable data sharing).

That way it feels more transparent to the end-user, and they have to make the conscious choice of either giving a bit of their data in exchance of a free service or be prepared to pay to keep their data private.

Re: Silicon Valley is terrified of California’s privacy law

#264
post #200
post #123

Earlier quoted context omitted.

When I first wrote that comment, it was at -2 after three minutes. Which is interesting because usually HN users claim they care about privacy.

Oh hell no, HN users are largely startup types who are all-in on adtech/tracking tech and metrics for building their businesses. There is an incessant amount of whining about GDPR for example, and how "confusing" the regulations supposedly are. What it comes down to is many HN denizens are doing things that are explicitly prohibited by these data collection laws and want to continue doing the things that have been ou…

You are well on your way to having this comment pulled. Heaven forbid you cast any blame on those who are building our dark-patterned surveillance dystopia. Note, I have been told on good authority that the pay is good and the work is interesting. And that makes it okay.

Good luck!

Re: Silicon Valley is terrified of California’s privacy law

#265
post #33

Earlier quoted context omitted.

Totally disagree. Complicate is not the same thing as following the spirit of the rules. Compliance is proving you followed the rules. Totally different. Also, you have to define what you mean by “respecting privacy”. Something that I do on my website, like basic retargeting marketing for abandoned shopping carts doesn’t feel to me like an invasion of privacy. To you, it might. The rules have to be defined clearly.

If you don't collect any information that's not essential to delivering content and services, there shouldn't be any problem. If you have a shopping cart, you must collect billing and shipping information. But you don't need to use it for any other purpose.

> If you don't collect any information that's not essential to delivering content and services, there shouldn't be any problem.

That's pretty ambiguous. For example, I'm pretty sure everything Google does that can be considered against privacy can and is tied to the service they provide as features. The fact they keep a history of everywhere you went to can be used by users to recall the locations they've been too. That Google keeps one's contacts can be used in case you lose your phone and get a new one. That Google uploads your voice to their servers is to improve their speech recognition. All privacy violations can be made "essential" by tying it to a feature.

Re: Silicon Valley is terrified of California’s privacy law

#266
post #232

Earlier quoted context omitted.

The reason there are so many wonderful services available for free is because they make money selling your data. If the service is free, the product is you. For many, many people, that is _fine_. The real issue I see here is how this law is written and how we're interpreting it. If the law makes it so that people who want to opt out of free internet services because of privacy concerns are free to do so, then we're a…

> For many, many people, that is _fine_. I would argue this isn't the case. For many people it is out of sight and out of mind. They don't realize what's happening. I came to this conclusion after talking with people about it. Numerous people didn't believe it. I had to show people documents and articles for them to believe me. Most of the people I've spoken with do not like this behavior and would rather not use a s…

I like that the webshit data robbers downvote me for saying what they're doing is evil, yet if I showed any particular one what kind of information I have access to about them, just as a random private citizen interested in these things, they'd freak out and call me a creep. It's a shame what money does to people.

Re: Silicon Valley is terrified of California’s privacy law

#267

Earlier quoted context omitted.

Totally disagree. Complicate is not the same thing as following the spirit of the rules. Compliance is proving you followed the rules. Totally different. Also, you have to define what you mean by “respecting privacy”. Something that I do on my website, like basic retargeting marketing for abandoned shopping carts doesn’t feel to me like an invasion of privacy. To you, it might. The rules have to be defined clearly.

> Something that I do on my website, like basic retargeting marketing for abandoned shopping carts doesn’t feel to me like an invasion of privacy. It sure does to me. So much so that if it happened to me, I'd be sure to never buy from that site again.

I'm with you.

I was on a web site with several items in the shopping cart. I went to the bathroom on my way into another room of the house to get my phone to make a payment on my credit card so I could make the purchase. When I got to my phone I already had one of those abandoned cart remarketing e-mails from the company.

I went back to my computer and closed the browser tab. No sale, creeps.

Re: Silicon Valley is terrified of California’s privacy law

#268
post #52

I see a lot of comments deriding this law, can someone explain to me why these are bad things? Quoting from this article - https://techcrunch.com/2018/06/28/landmark-california-privac... - Businesses must disclose what information they collect, what business purpose they do so for and any third parties they share that data with. - Businesses would be required to comply with official consumer requests to delete that d…

I've commented in the past that the privacy community is diverse. I divide the community into (at least) two major groups: - People who believe that privacy means being able to anonymously use services. - People who believe that privacy means being able to control what other people do with data about you. These are not compatible views, and they often conflict with each other -- both philosophically and practically.…

I think this is a very important distinction you make, but it doesn't necessarily mean that they are fundamentally incompatible.

It today's world, data about a person is an asset. A person should own their assets, and have control over them. If there were only one option, this would have to be it - it's the only one that aligns with business interests. If you instead go purely the route of anonymous data collection, because data is such an asset it just gives businesses the strong incentive to find ways to de-anonymize your data. That is an unstable situation, and a societal counter-productive incentive.

Since data on me has value (clearly since businesses are run off it), make it a true product. Give it value, allow me as a consumer to trade it, allow businesses to quantify it's value in the market place, and explicitly bid on. That aligns incentives. As data becomes more (or less) valuable, businesses will adjust their prices for it. This aligns incentives, the more data is worth to a business, the more they'll be willing to pay for it. IMHO this is clearly the right approach.

That said, there is still a world where both methods exist. Users choose when they interact if they want to perform anonymous interaction (or pseudoanonymous), and people provide services to ensure it is anonymous. HN, reddit those are forms people would likely choose pseudoanon for, but there would be a firewall between someones pseudoanon identity and their true identity. And people would be pseudoanon knowing the risks and taking care to not divulge linking identityy info, and businesses would ensure there are limits on data preservation / recording of pseudoanon interactions. The same way people post on HN and use care in what they choose to disclose, HN would also ensur data expiry is short enough and would not share/sell pseudoanon data to 3rd parties.

Again, if you can only pick one, it has to be consumer ownership of their data, but I think they both can work together.

Re: Silicon Valley is terrified of California’s privacy law

#269
post #172

Earlier quoted context omitted.

> - Consumers can opt out of their data being sold, and businesses can’t retaliate by changing the price or level of service. This is something I object to. It's just fundamentally stupid and doesn't make sense. The entire premise of free exchange is that I give you my services in exchange for something of value of yours. Making it illegal to withhold services if you don't give up your data is crazy. The only reason…

> - Consumers can opt out of their data being sold, and businesses can’t retaliate by changing the price or level of service. > - Businesses can, however, offer “financial incentives” for being allowed to collect data. This just means your service always costs money, but you can refund the full amount for allowing you to collect data.

Exactly. And i think it 's better UI overall: You default to no ads , but when it comes payment time, you present the ad opt-in to the users. My bet is 99.99% of users will choose free with ads. This also crosses a psychological barrier to disable their ad blocker.

Re: Silicon Valley is terrified of California’s privacy law

#270

Earlier quoted context omitted.

This statement is too broad brush for me to actually understand where you're coming from. Let's try a few variations of the theme and see if we can suss out why we perceive this so differently. If none of these touch on your perspective, I'd appreciate it if you could propose some of your own. Please note that these are deliberately constructed as strawmen; I am not advocating for them or saying you do. 1/ Would you…

These all sound fine, except I don't know that credit agencies are held to high standards.

Ok, maybe I'm asking questions too close to my own viewpoint. Let me ask some follow-up questions that are a bit further out.

Would you approve of a law which forbade advertising of any sort?

Would you approve of a law which required service providers to offer their service for free?

Would you approve of a law which forbade service providers from offering their service for free?

Would you approve of a law banning the sale of digital goods or rights to digital goods?

Would you approve of a law banning subscriptions or recurring payments?

Would you approve of a law forbidding the use of cameras in public places?

Would you approve of a law forbidding companies from having more than $X in revenue, for some X?

Post reply on HN