Live data from Hacker News

Silicon Valley is terrified of California’s privacy law

techcrunch.com

431–440 of 553 posts

Re: Silicon Valley is terrified of California’s privacy law

#431
post #411

Earlier quoted context omitted.

My shared secret with HN, my password, is an identity? I don't think you'll find a lot of people who agree with that definition of the word. As for the use of photos of me that are owned by other people, I'm pretty certain that neither CCPA nor GDPR cover those. The EU might have some relevant privacy laws, but they're not relevant to the "dichotomy" you brought up, because no one expects to be unidentifiable in a ph…

No. But in the HN context, your user id is. If HN decided one day to monetize the site by showing you ads based on your posts, the kind of discussions you frequent, or your location, then it's a profile of personal info.

I am 100% okay with HN doing whatsoever they'd like with posts I've made that I haven't deleted. I know they have them. I personally wrote them here with my own two hands.

I am 100% not okay with HN doing anything at all with my location information. Why would they have that information in the first place? Why would they keep it?

The discussions I frequent are more of a gray area; I favor Maciej Ceglowski's Six Fixes a lot: https://idlewords.com/six_fixes.htm

But all of this is irrelevant to the thread you're replying to, because my user id is anonymous.

Re: Silicon Valley is terrified of California’s privacy law

#432
post #380

Earlier quoted context omitted.

General population is simply not aware of how much surveillance is involved and how much of their private information said companies collect, use or sell to 3rd parties. Many are happy to get "free" service in exchange for "some data", but most people people would be very much against someone data mining their health or pregnancy status, using some sophisticated algorithm to selling something harmful to their kids or…

> Most people don't understand the risks and how badly mass surveillance done by Google / Facebook / etc can be abused. This is totally dodging the issue. Would they pay instead of allowing that collection? Given the choice of "pay for this service", "stop using this service", "give up your data", even with a full understanding of the risks and the extent of this data, the general public has shown time and time again…

> People will pay 5$ for 50 cents of coffee beans and enough sugar to drown a fly a day, but they will never pay 5$ a month to access nearly the entirety of mankind's collective knowledge at their fingertips in milliseconds

I pay a lot more than $5/month for Internet service.

Re: Silicon Valley is terrified of California’s privacy law

#433
post #323

Earlier quoted context omitted.

In practice, this doesn't really work. You can compromise and build a system out of elements of each individual philosophy (and many people do), but there are going to be conflicts, and at that point you're going to have decide which system takes precedence. The first issue is that many privacy advocates who believe in anonymity do not believe in data ownership (or believe it should be much weaker). To them, the jump…

> The "anonymous" side's solution here is, "anybody should be able to convincingly and legally lie about their physical location to (virtually) any business." If that solution is implemented, GDPR and Right to Be Forgotten don't work because it's impossible to verify jurisdiction. How is that? GDPR protects EU residents when they are outside the EU, so you already can't just look at someone's location and decide not…

GDPR protects EU residents (even abroad) when a business sells to them (or when a website targets them). At the point of sale, in order to figure out whether or not GDPR applies, a business needs to figure out whether or not someone is an EU citizen.

You have a couple of choices with a law like this:

1. Just comply with GDPR anyway. That's honestly the easiest choice, especially if you're already privacy conscious. But you're lucking out, because GDPR is a relatively mild law and comes with a bunch of exceptions that make it easy to comply with. It's not a good long-term strategy to say, "I'll just comply with every country, and that way I'll never need to figure out who my customers are."

If you're not interested in complying with GDPR, then you have to stop selling to EU citizens.

2. At the point of sale, you can use something like billing information to try and figure out where your customer lives and block them if they're an EU citizen. This is unacceptable to someone who wants universal anonymity for citizens, because it requires billing information to be tied to identity/location. You're basically guaranteeing that you can't ever move to a payment system that doesn't provide that information.

Maybe you can skip billing information, and use some kind of government ID number instead. But no matter what, you need some way to tie the thing giving you money to the person who legally has a citizenship in a country.

3. If you don't want to verify, you can just ask the person if they're European and block them if they say 'yes.' This is probably the compromise that would make anonymity-advocates happiest, because it doesn't require any extra data to be collected and customers can lie. But that's also the problem -- customers can lie.

In the US, the most direct analogy here is COPPA. COPPA is a set of privacy restrictions for what information can be collected about children under the age of 13. There are traditional ways you can fall foul of COPPA (some sites are just obviously targeting children). But for the most part, the US went with option 3 -- you ask people their age before they sign up for your site, and you block them if they're under 13.

Again, option 3 is great for people who love anonymity. But it takes all the teeth out of COPPA, because children just lie and use the services anyway, and then their privacy gets violated. And the company winks and very coyly says, "Oh, we had no idea 10 year olds were signing up for Facebook. It's not our fault."

If you wanted a COPPA that did more to restrict data collection, you would probably prefer something like option 2 -- where we collect enough information about children so that they can't fake their age, and use that to block access. Except doing that reliably would require either building a national identity database or collecting other data that would itself be considered by some people to be a violation of privacy.

Re: Silicon Valley is terrified of California’s privacy law

#434

Earlier quoted context omitted.

Is this anecdotal or do you have empirical evidence?

No one's performed a proper survey AFAIK, but the GDPR opt-out rate is very very low, which provides weak evidence. This is not evidence of numbers, but I have an existence proof in that I also personally know a lot of people who know and insist on not opting out.

Your proof is that you “personally know a lot of people who know and insist on not opting out”? That’s anecdotal evidence at best (aka not proof).

Re: Silicon Valley is terrified of California’s privacy law

#435

Earlier quoted context omitted.

I am on board with this law, but I’m curious how these two points will shake out: > - Consumers can opt out of their data being sold, and businesses can’t retaliate by changing the price or level of service. > - Businesses can, however, offer “financial incentives” for being allowed to collect data. Seems to me that it’s a distinction without a difference. Is there something I’m missing?

Its intended to fuck over Facebook. If you're charging for a service you can simply offer a discount for allowing data collection after bumping prices for everyone by the same amount, Facebook however isn't charging. Facebook can't offer a discount on free, and they can't just force only users who opt-out to go pay (because that falls afoul of the first quote you put). Basically this puts Facebook in a real tight sit…

I don't think that specific part fucks over Facebook; Facebook doesn't sell data (it sells ads based on the data, which, having skimmed the law, it doesn't seem to cover).

Re: Silicon Valley is terrified of California’s privacy law

#436
post #411

Earlier quoted context omitted.

No. But in the HN context, your user id is. If HN decided one day to monetize the site by showing you ads based on your posts, the kind of discussions you frequent, or your location, then it's a profile of personal info.

I am 100% okay with HN doing whatsoever they'd like with posts I've made that I haven't deleted. I know they have them. I personally wrote them here with my own two hands. I am 100% not okay with HN doing anything at all with my location information. Why would they have that information in the first place? Why would they keep it? The discussions I frequent are more of a gray area; I favor Maciej Ceglowski's Six Fixes…

> Why would they have that information in the first place?

IP based geolocalization?

> But all of this is irrelevant to the thread you're replying to, because my user id is anonymous.

Just because your hacker news user id is anonymous doesn't mean your account can't have an ad targeting profile built based on it if HN decided. They are sort of independent, and most sites don't care so much about who you actually are, but rather that you can be shown relevant ads.

> I favor Maciej Ceglowski's Six Fixes a lot

Those are very interesting. Thanks for sharing!

Re: Silicon Valley is terrified of California’s privacy law

#437
post #5

Earlier quoted context omitted.

I'm just going to ignore them all until my actual operating jurisdiction implements one, I'm not beholden to the laws of another country, let alone a specific state in it.

I’m not sure this is entirely true. Texas for example has some pretty big arms (long-arm statute) when conducting business in or with a resident or Texas business. Maybe helpful - http://euro.ecom.cmu.edu/program/law/08-732/Jurisdiction/Lon...

I'm not even in their country, pretty sure I'm not going to get extradited for breaking the privacy laws of a jurisdiction in which I have no physical presence.

Re: Silicon Valley is terrified of California’s privacy law

#438

Earlier quoted context omitted.

> Nobody said your movie has to be viewable in China. You will of course forgive me if I do not find economic favoritism that benefits politically connected industrialists, the restriction of freedom of thought by oppressive governments, and the general Balkanization of the Internet, to be things that we ought to celebrate. Once upon a time the memes of Internet culture would suggest that "information wants to be fre…

> Once upon a time the memes of Internet culture would suggest that "information wants to be free!" Oh, sweet halcyon days of yore! Turns out it’s not free — it’s actually very valuable , and the cost is borne by society writ large.

Information does want to be libre.

Information is not gratis.

Re: Silicon Valley is terrified of California’s privacy law

#440
post #263

Earlier quoted context omitted.

You just have to change the onboarding process to include a fee, and offer an incentive/rebate of the subscription price to match the cost to basically make it free. That way if they decide to change their mind and not give their data, you're still in the clear by removing the incentive and either charge their payment method or disable their service until they do (or reenable data sharing). That way it feels more tra…

>You just have to change the onboarding process to include a fee, and offer an incentive/rebate of the subscription price to match the cost to basically make it free. That way if they decide to change their mind and not give their data, you're still in the clear by removing the incentive and either charge their payment method or disable their service until they do. What's the practical difference between these two sc…

One difference, it seems, is that under the proposed law you couldn’t advertise your $3 service as “free”, maybe?

Either way though, I’d be happy if it were just required that there BE an opt out even with a price tag. Google can then finally tell me how much money they want for their services.

Post reply on HN