Live data from Hacker News

Silicon Valley is terrified of California’s privacy law

techcrunch.com

281–290 of 553 posts

Re: Silicon Valley is terrified of California’s privacy law

#281
post #275
post #263

Earlier quoted context omitted.

You just have to change the onboarding process to include a fee, and offer an incentive/rebate of the subscription price to match the cost to basically make it free. That way if they decide to change their mind and not give their data, you're still in the clear by removing the incentive and either charge their payment method or disable their service until they do (or reenable data sharing). That way it feels more tra…

I wonder if that will have unintended consequences. It might inadvertently assign a price to the data collected. It also shows a direct discrimination against poor and/or young people who might not afford the service.

You need parental permission to collect data from young people in the US anyway (see COPPA). But an age gate and asking for a credit card number are very different levels of sign up friction for a young person to try to get around.

Re: Silicon Valley is terrified of California’s privacy law

#282

Earlier quoted context omitted.

> We need to have a conversation about jurisdictions in the digital age. The way governments have decided that having a website accessible in a country makes you liable to respect the law of this country is a convulted and hacky notion that has been accepted way too fast. You know if you turn that around and say "How come we have to respect the laws of every country we do business in?" it sounds a lot more self servi…

We need a principle-based approach, sound societies can only be built with sound principles. If I have interesting ideas, I could write a book and sell it in every country of the world. Then this product would be taxed and would need to respect the publication-related laws of that country. On the other hand, if someone reads my book and then travels across the country to hold free seminaries to teach my ideas to the…

> The physica[l] establishment rule is the only sound and workable principle.

I don't think you can state this as fact without some justification. I think it's very debatable, and, frankly, I disagree. The physical establishment rule was borne out of practical enforcement considerations, not out of any principled approach.

Re: Silicon Valley is terrified of California’s privacy law

#283
post #275
post #263

Earlier quoted context omitted.

You just have to change the onboarding process to include a fee, and offer an incentive/rebate of the subscription price to match the cost to basically make it free. That way if they decide to change their mind and not give their data, you're still in the clear by removing the incentive and either charge their payment method or disable their service until they do (or reenable data sharing). That way it feels more tra…

I wonder if that will have unintended consequences. It might inadvertently assign a price to the data collected. It also shows a direct discrimination against poor and/or young people who might not afford the service.

There is already a price in the data collected (for FB i think $120 / year). I think making it public is a good thing. I think the law will also force facebook to offer ad free subscription plans, something people have been asking for. My bet is nobody is going to use them though.

Re: Silicon Valley is terrified of California’s privacy law

#284
post #52

I see a lot of comments deriding this law, can someone explain to me why these are bad things? Quoting from this article - https://techcrunch.com/2018/06/28/landmark-california-privac... - Businesses must disclose what information they collect, what business purpose they do so for and any third parties they share that data with. - Businesses would be required to comply with official consumer requests to delete that d…

These laws may be targeted at companies that deal in advertising data relating to consumers, but the laws as written affect all of us.

Are these the right laws to regulate SaaS companies that build business software? Should a consumer be allowed to request that data about them be deleted if that data are records of legitimate business transactions? If you buy a car from a dealership, do you "own" the data in their systems about your transaction and should you be able to request its deletion?

Re: Silicon Valley is terrified of California’s privacy law

#285
post #96

Earlier quoted context omitted.

That is what they said about GDPR...

And what is your problem complying with that if you collect no information nor share any information?

The main issue is proving compliance. Any website could, in theory, be recording information that counts as "personal data" under GDPR and CCPA without the user realizing it. What happens if a user doesn't believe you when you say you don't store or share anything? How do you prove to a regulator that you actually don't?

Re: Silicon Valley is terrified of California’s privacy law

#286
post #52

I see a lot of comments deriding this law, can someone explain to me why these are bad things? Quoting from this article - https://techcrunch.com/2018/06/28/landmark-california-privac... - Businesses must disclose what information they collect, what business purpose they do so for and any third parties they share that data with. - Businesses would be required to comply with official consumer requests to delete that d…

I've commented in the past that the privacy community is diverse. I divide the community into (at least) two major groups: - People who believe that privacy means being able to anonymously use services. - People who believe that privacy means being able to control what other people do with data about you. These are not compatible views, and they often conflict with each other -- both philosophically and practically.…

There's no conflict.

necessarily there needs to be a way for that business to confirm your identity and link you to that data

Why would linking you to that data require confirming your identity? My password links my HN account to me and me alone, while revealing nothing about my identity.

There's no conflicting views. They're two, completely compatible aspects of the same view.

One is how much or how little data each service gets about you. The other is how much control you have over what those services do with the data they do get.

That's why technical and legislative solutions work in tandem, reducing the former (amount of data) and increasing the latter (control over data). That's also why technical solutions are preferable: there's no need to legislate control over data that services are unable to collect about you in the first place.

Re: Silicon Valley is terrified of California’s privacy law

#287
post #183

Earlier quoted context omitted.

Some problematic scenarios: - How do you identify what is customer data? There may be information stored in logs somewhere. Do you now have to write log parsers to extract personal data for everything that previously you just stored for general debugging and security purposes? How do you even know all the permutations of personal data that came be stored in the logs. There are possibly infinite possible ways personal…

> engineers now must fully understand the consequences of anything they log I don't think this is quite the dichotomy you make it out to be. So we can create optimizing compilers, but we can't figure out what to log? This seems like a problem of never having motivation to solve the problem before. "We can't do that, it's too hard" is often a mea culpa I'm industry when they oppose regulation. Then they will come up w…

Oh we can figure out what to log - and figure out how it would suck donkey balls. Just like the other "too hard" areas like the magic golden key backdoor.

It can trivially backfire to make things less secure if it is poorly defined which is generally a given. The GDPR made exfiltration easy as an account compromise - one could argue it is an acceptable trade off for transparency but the regulators must bear full responsibility for their constraints.

"We can't log sensitive customer data slowing down debugging and worsening data integrity" is one thing but now imagine "can't log customer IDs in a read only way as sensitive information" oops there goes a lot of useful auditing information as it is excluded or forced to be writeable.

Re: Silicon Valley is terrified of California’s privacy law

#288
post #52

I see a lot of comments deriding this law, can someone explain to me why these are bad things? Quoting from this article - https://techcrunch.com/2018/06/28/landmark-california-privac... - Businesses must disclose what information they collect, what business purpose they do so for and any third parties they share that data with. - Businesses would be required to comply with official consumer requests to delete that d…

These laws may be targeted at companies that deal in advertising data relating to consumers, but the laws as written affect all of us. Are these the right laws to regulate SaaS companies that build business software? Should a consumer be allowed to request that data about them be deleted if that data are records of legitimate business transactions? If you buy a car from a dealership, do you "own" the data in their sy…

Agreed. It’s been tough for us as well. We don’t monetize customer data in any way yet these regulations add real cost for us. We’re in the business software SaaS world as well, so it’s not really even our data to delete. We end up having to have a 3-way ticket between the business, the customer and us (the SaaS provider) and explain how we are deleting data from their system.

Re: Silicon Valley is terrified of California’s privacy law

#289
post #265
post #33

Earlier quoted context omitted.

If you don't collect any information that's not essential to delivering content and services, there shouldn't be any problem. If you have a shopping cart, you must collect billing and shipping information. But you don't need to use it for any other purpose.

> If you don't collect any information that's not essential to delivering content and services, there shouldn't be any problem. That's pretty ambiguous. For example, I'm pretty sure everything Google does that can be considered against privacy can and is tied to the service they provide as features. The fact they keep a history of everywhere you went to can be used by users to recall the locations they've been too. T…

That's really stretching the meaning of "essential to delivering content and services". If I search using Google, all I want is the results. If I have Gmail, all I want is an email account. Anything else is clearly extraneous.

Edit: And they can always offer more. With clear explanation of what information they'll need to retain. And users can either accept, or decline.

Re: Silicon Valley is terrified of California’s privacy law

#290
post #52

I see a lot of comments deriding this law, can someone explain to me why these are bad things? Quoting from this article - https://techcrunch.com/2018/06/28/landmark-california-privac... - Businesses must disclose what information they collect, what business purpose they do so for and any third parties they share that data with. - Businesses would be required to comply with official consumer requests to delete that d…

These laws may be targeted at companies that deal in advertising data relating to consumers, but the laws as written affect all of us. Are these the right laws to regulate SaaS companies that build business software? Should a consumer be allowed to request that data about them be deleted if that data are records of legitimate business transactions? If you buy a car from a dealership, do you "own" the data in their sy…

There are a bunch of exceptions to the requirement to delete user data in the law (full text: https://leginfo.legislature.ca.gov/faces/billTextClient.xhtm...), the exception for data that is collected "to enable solely internal uses that are reasonably aligned with the expectations of the consumer based on the consumer’s relationship with the business" would probably apply in the cases you cite.
Post reply on HN