Live data from Hacker News

Silicon Valley is terrified of California’s privacy law

techcrunch.com

421–430 of 553 posts

Re: Silicon Valley is terrified of California’s privacy law

#422
post #412

Earlier quoted context omitted.

> I would prefer to minimize regulation controlling people That seems like a weird spin. Businesses are being regulated here, not individuals. I don't see how the law would control me.

Okay, I'm happy to rewrite that whichever way you like, but I believe businesses are just groups of people. If you wish, consider that 'prefer to minimize regulation binding units of people or groups of people acting in concert'. I'm also content with it just being 'prefer to minimize regulation binding businesses or people so long as no active harm yada yada'.

I would submit that mass surveillance is doing harm, see Cambridge Analytica and other recent scandals.

Re: Silicon Valley is terrified of California’s privacy law

#423
post #273

Earlier quoted context omitted.

> The entire premise of free exchange is that I give you my services in exchange for something of value of yours. "Something" doesn't mean "anything". You can't offer your services in exchange for e.g. my body parts. Why are we willing to ban that but not our data? > The only reason those services are being provided at all is to get that data. That's effectively a requirement that people provide services for free. We…

There's also the dilemma that if you pay for something with a credit card, you have to identify yourself.

Not if you use Apple Pay though no?

Re: Silicon Valley is terrified of California’s privacy law

#424
post #19

Does anyone know the real implications of the CCPA for things like Sift Science, Google's Recaptcha, and maybe even Cloudflare? All of these are based on many companies contributing information about users to create profiles which curb abuse. And Sift/Google/etc. get commercial benefit from this data sharing, which might trigger the CCPA. But you can't give bad actors the ability to opt out of this kind of data shari…

If Recaptcha gets the ax due to CCPA, the internet will be better off for it.

Do you have a proposed alternative way of preventing spam? Neural networks basically mean that any traditional captcha too hard for a bot is also too hard for a human.

Re: Silicon Valley is terrified of California’s privacy law

#425
post #380
post #332

Earlier quoted context omitted.

> "Something" doesn't mean "anything". You can't offer your services in exchange for e.g. my body parts. Why are we willing to ban that but not our data? Because if you were to run a survey over the general population the large majority is fine not having to pay for gmail, google search, maps and other "free" services while some data may be collected doing so while a much smaller percentage thinks it's OK to sell the…

General population is simply not aware of how much surveillance is involved and how much of their private information said companies collect, use or sell to 3rd parties. Many are happy to get "free" service in exchange for "some data", but most people people would be very much against someone data mining their health or pregnancy status, using some sophisticated algorithm to selling something harmful to their kids or…

> Most people don't understand the risks and how badly mass surveillance done by Google / Facebook / etc can be abused.

This is totally dodging the issue.

Would they pay instead of allowing that collection?

Given the choice of "pay for this service", "stop using this service", "give up your data", even with a full understanding of the risks and the extent of this data, the general public has shown time and time again they will take the last option.

People do not like to pay for things.

I see way too many arguments about privacy that doesn't seem to grasp that the core of today's tech industry is built around this fact.

People will pay 5$ for 50 cents of coffee beans and enough sugar to drown a fly a day, but they will never pay 5$ a month to access nearly the entirety of mankind's collective knowledge at their fingertips in milliseconds in the form of a search index spending millions of dollars a year to index it all.

Re: Silicon Valley is terrified of California’s privacy law

#426
post #422

Earlier quoted context omitted.

Okay, I'm happy to rewrite that whichever way you like, but I believe businesses are just groups of people. If you wish, consider that 'prefer to minimize regulation binding units of people or groups of people acting in concert'. I'm also content with it just being 'prefer to minimize regulation binding businesses or people so long as no active harm yada yada'.

I would submit that mass surveillance is doing harm, see Cambridge Analytica and other recent scandals.

Those were non-consensual, so yes, I'm on board with not allowing them.

Re: Silicon Valley is terrified of California’s privacy law

#427
post #275
post #263

Earlier quoted context omitted.

You just have to change the onboarding process to include a fee, and offer an incentive/rebate of the subscription price to match the cost to basically make it free. That way if they decide to change their mind and not give their data, you're still in the clear by removing the incentive and either charge their payment method or disable their service until they do (or reenable data sharing). That way it feels more tra…

I wonder if that will have unintended consequences. It might inadvertently assign a price to the data collected. It also shows a direct discrimination against poor and/or young people who might not afford the service.

For a short time AT&T GigaFiber was charging $30/month to opt out of surveillance and I thought they can't possibly be selling my data for that much. I wonder if this new law will also lead to some unrealistically high prices.

Re: Silicon Valley is terrified of California’s privacy law

#428
post #386
post #332

Earlier quoted context omitted.

> "Something" doesn't mean "anything". You can't offer your services in exchange for e.g. my body parts. Why are we willing to ban that but not our data? Because if you were to run a survey over the general population the large majority is fine not having to pay for gmail, google search, maps and other "free" services while some data may be collected doing so while a much smaller percentage thinks it's OK to sell the…

> Because if you were to run a survey over the general population the large majority is fine not having to pay for gmail, google search, maps and other "free" services while some data may be collected doing so How is this an argument against the law? It doesn't make it illegal to share data but requires that users can opt out. If said large majority is fine with surveillance, I guess Silicon Valley can relax.

He's saying being able to "opt out" is absurd. It's equivalent to getting the product for free in most cases.

"Hey, I want to use your free service but I want to go ahead and opt out of the part that enables it to be free" You don't see a problem with that?

It would be like if there were a restaurant that gave free food in exchange for filling out surveys (data collection). So you eat the free meal and then "opt out" of doing the survey.

Re: Silicon Valley is terrified of California’s privacy law

#429

Earlier quoted context omitted.

This works because you're the person who uploaded the data, and because you have a shared secret with Hackernews: in other words, an identity and a link between that identity and the data. Let's say someone else uploads a photo of my face to an image sharing site. Is there a way for me to prove to that site that the face belongs to me without sharing additional information? This principle also applies in the opposite…

My shared secret with HN, my password, is an identity? I don't think you'll find a lot of people who agree with that definition of the word. As for the use of photos of me that are owned by other people, I'm pretty certain that neither CCPA nor GDPR cover those. The EU might have some relevant privacy laws, but they're not relevant to the "dichotomy" you brought up, because no one expects to be unidentifiable in a ph…

Your identity on HN is your profile and posts, and your shared secret is how you prove you own that identity. Is that actually uncommon? I would call `laughinghan` an identity.

> As for the use of photos of me that are owned by other people, I'm pretty certain that neither CCPA nor GDPR cover those.

You're talking about specific laws, and I'm talking about general principles. The dichotomy I'm supposing is between complete anonymity and complete ownership over my own data. Owning data means being able to restrict how other people use it.

No expects to be unidentifiable in a photo where their face is visible. But if I own my face, I expect to be able to issue a takedown request to sites who post images of my face without my permission. If I genuinely own my address, or my contacts, and a third-party site makes them publicly available, I should be able to do something about that, the same way that I would be able to restrict them from distributing a piece of IP I owned.

CCPA and GDPR don't cover individuals, just companies. This is a compromise, because it's just not feasible right now to have a version of GDPR that covers what ordinary citizens share. But there's nothing special about companies. If I'm committed to a world where I own my data, I don't want my rights to vanish just because the information was posted on a blog instead of Facebook.

And that's where you start to see this conflict -- because in order to maintain control over data, you have to, well... maintain control over data. You have to know who's posting it and who it belongs to. People who advocate primarily for anonymity are opposed to that kind of world. Their extremes look different.

In the real world, most people will be somewhere in the middle. They'll lean towards data ownership on some things, and anonymity on others. For example, I doubt that many people on HN believe that companies should be able to operate anonymously. Even though anonymity/ownership is not a binary choice, different people are going to be lean towards different sides of the continuum, and that's where you see these conflicts.

Re: Silicon Valley is terrified of California’s privacy law

#430

Earlier quoted context omitted.

Wrt the laws benefiting incumbents with more resources: in this case I think it’s simple. If you don’t have the resources, just don’t collect the data! If your business model absolutely depends on it, then you should have the resources to do it correctly anyway, so the extra burden of this law shouldn’t be too much on top of that. This is definitely a simplified view, but I think it’s worth noting that following thes…

I disagree with this so much. Data is used for far more than ads. If you can't collect data but your competition can, they'll run a more efficient business, offer better products and be more adaptive to change.

I totally agree. You should definitely be able to A/B test features, for instance, but if that's the point where the business is, you can run focus groups and do similar studies without running up against these regulations. My point is just that the business may need to succeed to some level before these regulations really become an issue. An analogous situation may be a small business being burdened by complex tax laws, but not until they acquire sufficiently sophisticated internal structure and revenue streams.

My point is that this can be factored into the growth of the company, rather than seen strictly as a barrier to entry, as suggested by the comment above. Are there really fresh startups that really need to worry about this kind of data gathering out of the gate? I'm imagining they're going to be spending a lot more time engineering features and interfacing with important clients to get data to improve their product directly. I often see business/marketing folks wanting user data for what amounts to very premature optimization.

Post reply on HN