Earlier quoted context omitted.
> engineers now must fully understand the consequences of anything they log I don't think this is quite the dichotomy you make it out to be. So we can create optimizing compilers, but we can't figure out what to log? This seems like a problem of never having motivation to solve the problem before. "We can't do that, it's too hard" is often a mea culpa I'm industry when they oppose regulation. Then they will come up w…
Oh we can figure out what to log - and figure out how it would suck donkey balls. Just like the other "too hard" areas like the magic golden key backdoor. It can trivially backfire to make things less secure if it is poorly defined which is generally a given. The GDPR made exfiltration easy as an account compromise - one could argue it is an acceptable trade off for transparency but the regulators must bear full resp…
Silicon Valley is terrified of California’s privacy law
321–330 of 553 posts
Re: Silicon Valley is terrified of California’s privacy law
#322Earlier quoted context omitted.
Some problematic scenarios: - How do you identify what is customer data? There may be information stored in logs somewhere. Do you now have to write log parsers to extract personal data for everything that previously you just stored for general debugging and security purposes? How do you even know all the permutations of personal data that came be stored in the logs. There are possibly infinite possible ways personal…
> How do you even know all the permutations of personal data that came be stored in the logs. There are possibly infinite possible ways personal information can manifest in logs. Nonsense. You write the log statements. You know what data structures you are logging. If you're using some server's built in logging, or some logging library or middleware you don't understand, turn that off until you understand what it's l…
Logs that do not contain explicit PII are still rife with pseudo-identifiers that could possibly (but not typically) be used to join activity with PII.
For example:
- You have one set of logs that stores anonymized click activity
- You have another set of logs that stores purchase transactions
- Both have millisecond timestamps
You could potentially link the click record from one logs database to the purchase record in the transaction database, when during a single millisecond there is only one transaction and one click happening. Now your anonymized click ID and all your click activity is linked to your PII in your transaction.
Sometimes it's off by a few millisecond. Sometimes the logs are obfuscated up to the second level, but then you'll still have instances of a single click and transaction in a second. Does this activity still need to be removed from logs, despite not being linked to your PII or even being identifiable? These are the challenges that need to be addressed.
Re: Silicon Valley is terrified of California’s privacy law
#323Earlier quoted context omitted.
I think this is a very important distinction you make, but it doesn't necessarily mean that they are fundamentally incompatible. It today's world, data about a person is an asset. A person should own their assets, and have control over them. If there were only one option, this would have to be it - it's the only one that aligns with business interests. If you instead go purely the route of anonymous data collection,…
In practice, this doesn't really work. You can compromise and build a system out of elements of each individual philosophy (and many people do), but there are going to be conflicts, and at that point you're going to have decide which system takes precedence. The first issue is that many privacy advocates who believe in anonymity do not believe in data ownership (or believe it should be much weaker). To them, the jump…
How is that? GDPR protects EU residents when they are outside the EU, so you already can't just look at someone's location and decide not to give them GPDR protections. If the GDPR applies to you, your GDPR related features need to accessible to all your users.
Re: Silicon Valley is terrified of California’s privacy law
#324Earlier quoted context omitted.
The reason there are so many wonderful services available for free is because they make money selling your data. If the service is free, the product is you. For many, many people, that is _fine_. The real issue I see here is how this law is written and how we're interpreting it. If the law makes it so that people who want to opt out of free internet services because of privacy concerns are free to do so, then we're a…
> For many, many people, that is _fine_. I would argue this isn't the case. For many people it is out of sight and out of mind. They don't realize what's happening. I came to this conclusion after talking with people about it. Numerous people didn't believe it. I had to show people documents and articles for them to believe me. Most of the people I've spoken with do not like this behavior and would rather not use a s…
Re: Silicon Valley is terrified of California’s privacy law
#325Earlier quoted context omitted.
> If you don't collect any information that's not essential to delivering content and services, there shouldn't be any problem. That's pretty ambiguous. For example, I'm pretty sure everything Google does that can be considered against privacy can and is tied to the service they provide as features. The fact they keep a history of everywhere you went to can be used by users to recall the locations they've been too. T…
That's really stretching the meaning of "essential to delivering content and services". If I search using Google, all I want is the results. If I have Gmail, all I want is an email account. Anything else is clearly extraneous. Edit: And they can always offer more. With clear explanation of what information they'll need to retain. And users can either accept, or decline.
They also remember your searches to provide personalized results, and many people do like that.
> Anything else is clearly extraneous.
Isn't the point of a business to provide the best product or service they can (for the price they ask)? What's the point of a business that does the bare minimum? How are they supposed to compete?
In any case, the point is that it's not as clear cut to know what violates privacy and what doesn't. To tie it back to your original comment:
> The gist of these laws are all the same. Just respect ALL users' data from the start, and you shouldn't have any difficulty with compliance.
They aren't necessarily going to be the same. What is to respect all users' data? There's no concrete consensus on what violating privacy consists of. Is saving searches for personalized results consistent across personal devices violating privacy? Some will say yes, others will say no.
Also, if you err on the side of caution and avoid providing features, you're going to lose edge. It seems to me that it's very important to a business's survival to know where the borderline is.
That's why I would agree with rdlecler1 that
> a small startup needs to ensure they comply with hundreds of regulatory jurisdictions
if they want to have a chance for survival and peace of mind that they aren't even technically guilty of anything in any one jurisdiction even if in their own eyes they did everything to respect their users' data.
The internet probably wouldn't have gotten as big if it weren't for the fact that it's largely lawless. If every geographical region makes their own regulations, only big world corporations will be able to comply.
Re: Silicon Valley is terrified of California’s privacy law
#326Earlier quoted context omitted.
I've commented in the past that the privacy community is diverse. I divide the community into (at least) two major groups: - People who believe that privacy means being able to anonymously use services. - People who believe that privacy means being able to control what other people do with data about you. These are not compatible views, and they often conflict with each other -- both philosophically and practically.…
There's no conflict. necessarily there needs to be a way for that business to confirm your identity and link you to that data Why would linking you to that data require confirming your identity? My password links my HN account to me and me alone, while revealing nothing about my identity. There's no conflicting views. They're two, completely compatible aspects of the same view. One is how much or how little data each…
Let's say someone else uploads a photo of my face to an image sharing site. Is there a way for me to prove to that site that the face belongs to me without sharing additional information?
This principle also applies in the opposite direction. Let's say a third-party noncommercial site uploads a photo of my face and makes it publicly fixing. In order to demand they remove the photo, I need to be able to link that website to an owner.
It's not that the systems can never be combined. It's that following either system in the absolute results in conflicts with the other.
Re: Silicon Valley is terrified of California’s privacy law
#327Earlier quoted context omitted.
But you don't. If I am from South Africa and I buy a US product from a smaller website I don't pay South Africa sales taxes. If I buy from Amazon I would because they have offices or a physical presence. When you buy a product from a website hosted/incorporated in a different country you are literally going into another country and buying a product under their laws. Your local taxes (national/stat wide/city wide) sho…
You don’t pay US sales tax, though. You should probably be paying South Africa sales tax? You would have to if importing into the U.K. at least
Re: Silicon Valley is terrified of California’s privacy law
#328Earlier quoted context omitted.
No argument there; just pointing out that many of the common complaints around ambiguity are explicitly addressed in the text of the bill already.
They're really not - the definition of using California household vs resident creates a huge unenforceable gray area for compliance
The only other place households are referred to is in the section defining which companies the rules apply to, which is also pretty straightforward in a plain reading. If a company's number of consumers, households, or devices exceeds 50k, they qualify.
> (B) Alone or in combination, annually buys, receives for the business’ commercial purposes, sells, or shares for commercial purposes, alone or in combination, the personal information of 50,000 or more consumers, households, or devices.
Re: Silicon Valley is terrified of California’s privacy law
#329Earlier quoted context omitted.
> How do you even know all the permutations of personal data that came be stored in the logs. There are possibly infinite possible ways personal information can manifest in logs. Nonsense. You write the log statements. You know what data structures you are logging. If you're using some server's built in logging, or some logging library or middleware you don't understand, turn that off until you understand what it's l…
GP is referring to pseudonymization, not data structures. Logs that do not contain explicit PII are still rife with pseudo-identifiers that could possibly (but not typically) be used to join activity with PII. For example: - You have one set of logs that stores anonymized click activity - You have another set of logs that stores purchase transactions - Both have millisecond timestamps You could potentially link the c…
Emplify, for example, makes it a point not to reveal averaged responses for subgroups of size less than 5, for similar reasons: https://intercom.help/emplify-insights/en/articles/1731829-c...
We should be making an effort to take such care with all customer data, even just when storing it. Mistakes are inevitable, of course, so small gaps that are soon fixed should be let off with a warning, with any fines proportionate to the amount of exposure and negligence involved. How would we do that? Maybe have an agency of experts tasked with determining the fines, and allowing companies to appeal those fines in open court. Like what GDPR does.
I'm a software engineer who works for a SaaS data analytics startup that has to comply with GDPR. It's not cheap, just like it's not cheap complying with all the laws restricting pollutants emitted by my car, but it's still completely worthwhile.
(My employer is not Emplify, although we are a customer of theirs. Good service.)
Re: Silicon Valley is terrified of California’s privacy law
#330One can only hope they make sure it hits big actors more than any other ones, because they are what makes this kind of data collection dangerous for societies.