Live data from Hacker News

Silicon Valley is terrified of California’s privacy law

techcrunch.com

351–360 of 553 posts

Re: Silicon Valley is terrified of California’s privacy law

#351
post #52

I see a lot of comments deriding this law, can someone explain to me why these are bad things? Quoting from this article - https://techcrunch.com/2018/06/28/landmark-california-privac... - Businesses must disclose what information they collect, what business purpose they do so for and any third parties they share that data with. - Businesses would be required to comply with official consumer requests to delete that d…

I think there are a lot of people here whose employment depends on being able to sell and buy peoples data freely.

Many of the people here who work for these companies truly and honestly believe the online services they are offering are/will change the world for the better.

As such, they view hindrances to this as threatening to the progress they are trying to help bring about.

Personally, I support this privacy initiative and think SV companies are many times viewed through rose tinted glasses by their employees, but that's just my perspective.

I can totally see how viewed through the lens of a hindrance to progress, some people would feel very strongly that I'm wrong in supporting such legislation.

Re: Silicon Valley is terrified of California’s privacy law

#352

Earlier quoted context omitted.

I see a lot of comments deriding this law, can someone explain to me why these are bad things? Jeff Hammerbacher: ‘The best minds of my generation are thinking about how to make people click ads… That sucks.’ Those best minds are now having to change the way they generate revenue..

Hardly. It doesnt seem the law will affect the business, it will just make the cost of data collection explicit: "Pay $40/month to use facebook or get a free rebate by enabling ads".

It doesn’t cost anything like $40 per month per user to operate Facebook, it’s not even $40 per year. (Facebooks operating revenue per user in 2018 was about $25).

Of course, they’d hate the idea of having a fixed revenue per user. They want to keep sucking out more revenue per user until the well runs dry.

Re: Silicon Valley is terrified of California’s privacy law

#353
post #80
post #46

Earlier quoted context omitted.

Each state can choose to be as restrictive as they like in their laws, and each startup can chose to invest in compliance on a wide scale or in the narrow scale as they'd like. It'd be nice if this was unified but it ain't because: 1. Tech companies lobby like hell at a national level 2. The national government is sort of broken right now so that's how the cookie crumbles. The fact that a number of companies have ski…

> Each state can choose to be as restrictive as they like in their laws, and each startup can chose to invest in compliance on a wide scale or in the narrow scale as they'd like. There's a special hell that exists where one state mandates records must be held for at least seven years and another mandates deletion at five. When the two states border one another and you may not have home addresses, how do you determine…

In the bill:

1798.145. (a) The obligations imposed on businesses by this title shall not restrict a business’s ability to: (1) Comply with federal, state, or local laws.

Now I wonder what sort of dance would occur if, in your example, both states' laws had such a clause.

Re: Silicon Valley is terrified of California’s privacy law

#354

Earlier quoted context omitted.

Yes, I replied to the right comment, you're getting hung up on an irrelevant detail. I'm saying that the thought they put into anonymizing the data they surfaced through their UI, that same amount of thought should be put into the data we all store. If the data can't be clustered in a way that preserves anonymity, it should be deleted (after the desired aggregate statistics are computed). Emplify probably isn't requi…

It is not known at the time of storing the data if the data being stored will be denonymizable - especially for logs data. Saying, "Just don't store logs data" is a fundamental misunderstanding of how web development works. This data is crucial for operational uptime, debugging, and running an online business. The scope of the data is so large that there inevitably are factors that can be used for denonymization, whi…

I'm not fundamentally misunderstanding anything. We both understand the problem quite well, you're just refusing to take on the burden of trying to solve the problem.

I didn't suggest not storing any logging data, actually. I suggested deleting it. Old, stale logs are unnecessary for operation uptime or debugging and low-value for usability or security investigation.

They also cumulatively presents risks to customers. A gay blogger in Russia who used LiveJournal in 2004 might regret their decision now, even though in 2007 when LiveJournal sold to a Russian company, few reasonable people would have foreseen the country's turn towards homophobia later. If LiveJournal had, for example, replaced all IP addresses with cities in historical, pre-2007 HTTP logs, they would have lost nothing of value to them while their customers would be that much safer. If they had gone so far as aggregated statistics of requests and unique visitors per tuple of (user agent, city, timestamp truncated to 15-minute intervals), and then deleted detailed all HTTP logs older than 90 days as suggested by Maciej Ceglowski [1], can you think of anything of value they would have lost?

But of course I'm sure they didn't, because they weren't required to put that much thought into the data they stored.

I'm saying we should be required to.

[1]: https://idlewords.com/talks/haunted_by_data.htm

Re: Silicon Valley is terrified of California’s privacy law

#355
post #172
post #52

I see a lot of comments deriding this law, can someone explain to me why these are bad things? Quoting from this article - https://techcrunch.com/2018/06/28/landmark-california-privac... - Businesses must disclose what information they collect, what business purpose they do so for and any third parties they share that data with. - Businesses would be required to comply with official consumer requests to delete that d…

> - Consumers can opt out of their data being sold, and businesses can’t retaliate by changing the price or level of service. This is something I object to. It's just fundamentally stupid and doesn't make sense. The entire premise of free exchange is that I give you my services in exchange for something of value of yours. Making it illegal to withhold services if you don't give up your data is crazy. The only reason…

In the case of data, is it always yours to give? Is the fact that I am friends with Friendo my data or Friendo’s? Both? Neither? Collectively both? Taken further is my contact info about Friendo mine to give? Is the photo with Friendo’s face that I took of a group of us at a bar my data to give?

If Friendo doesn’t have the same relationship I have with Tech.co, how is Friendo benefitting? Where is the exchange there?

Re: Silicon Valley is terrified of California’s privacy law

#356

Earlier quoted context omitted.

> (4) Exercise free speech, ensure the right of another consumer to exercise his or her right of free speech, or exercise another right provided for by law. Well, thanks for the link. For example, informing people that a user is located in a dormitory in The Netherlands sounds like free speech to me. So is location tracking information exempt from deletion?

Location data is explicitly called out as sensitive personal information in the text of the bill, so it's definitely not exempt as a category of data. > (e) Many businesses collect personal information from California consumers. They may know where a consumer lives and how many children a consumer has, how fast a consumer drives, a consumer’s personality, sleep habits, biometric and health information, financial info…

For a law to cover the set of data which is not necessary to exercise free speech would infringe on free speech, because the set and its complement are not disconnected sets. So either the company has stay on the safe side, and delete information necessary for it to exercise free speech, or miss the other way and be subject to penalties.

The example I gave, by the way, is a real one: https://news.ycombinator.com/item?id=8418885

Re: Silicon Valley is terrified of California’s privacy law

#357

Earlier quoted context omitted.

Is there a difference between offering, say, $12 monthly opt-out & $10 plan for opt-in vs flat $12 with a $2 discount to opt-in?

Given how hidden opt-out settings tend to be, yes. If the user has to opt in explicitly, it’s much less likely they’ll consent unintentionally.

In practice it will be a dull button saying “$12 plan” and a bright shiny button saying “$2 DISCOUNT” with everything else in fine print.

Re: Silicon Valley is terrified of California’s privacy law

#358

Earlier quoted context omitted.

I think the idea is that regulation always has unexpected side effects, some of which can be abused to actually do the perverse inverse of what they're intended to protect against. This is intuitive because regulation + law can really put a competitive barrier for established incumbents who (and arguably, they would be the target for lawsuits here) have resources to implement and comply with these regulations. The la…

Wrt the laws benefiting incumbents with more resources: in this case I think it’s simple. If you don’t have the resources, just don’t collect the data! If your business model absolutely depends on it, then you should have the resources to do it correctly anyway, so the extra burden of this law shouldn’t be too much on top of that. This is definitely a simplified view, but I think it’s worth noting that following thes…

I disagree with this so much. Data is used for far more than ads. If you can't collect data but your competition can, they'll run a more efficient business, offer better products and be more adaptive to change.

Re: Silicon Valley is terrified of California’s privacy law

#359
post #332

Earlier quoted context omitted.

> The entire premise of free exchange is that I give you my services in exchange for something of value of yours. "Something" doesn't mean "anything". You can't offer your services in exchange for e.g. my body parts. Why are we willing to ban that but not our data? > The only reason those services are being provided at all is to get that data. That's effectively a requirement that people provide services for free. We…

> "Something" doesn't mean "anything". You can't offer your services in exchange for e.g. my body parts. Why are we willing to ban that but not our data? Because if you were to run a survey over the general population the large majority is fine not having to pay for gmail, google search, maps and other "free" services while some data may be collected doing so while a much smaller percentage thinks it's OK to sell the…

This is your opinion, unless you actually did a survey of violating a citizens privacy by big tech. Have you?

Re: Silicon Valley is terrified of California’s privacy law

#360
post #33

Earlier quoted context omitted.

If you don't collect any information that's not essential to delivering content and services, there shouldn't be any problem. If you have a shopping cart, you must collect billing and shipping information. But you don't need to use it for any other purpose.

The IRS may see that differently.

Good point, perhaps. I'm not familiar with reporting requirements for online sales in business returns. I did manage a small restaurant at one point, and I don't recall that we had to track customer identity.
Post reply on HN