Live data from Hacker News

Silicon Valley is terrified of California’s privacy law

techcrunch.com

471–480 of 553 posts

Re: Silicon Valley is terrified of California’s privacy law

#471
post #332

Earlier quoted context omitted.

> "Something" doesn't mean "anything". You can't offer your services in exchange for e.g. my body parts. Why are we willing to ban that but not our data? Because if you were to run a survey over the general population the large majority is fine not having to pay for gmail, google search, maps and other "free" services while some data may be collected doing so while a much smaller percentage thinks it's OK to sell the…

I strongly suspect that if you asked people 50 years ago whether it was ok for companies to eg. track everywhere most people go, I think the vast majority would have said no. Google et al. just started spying on everyone without any serious debate over whether it was right. Then once people caught on, they either had to stop caring about privacy, or they had be Richard Stallman and eschew pretty much all mainstream c…

> I strongly suspect that if you asked people 50 years ago whether it was ok for companies to eg. track everywhere most people go, I think the vast majority would have said no. Google et al. just started spying on everyone without any serious debate over whether it was right. Then once people caught on, they either had to stop caring about privacy, or they had be Richard Stallman and eschew pretty much all mainstream computing technology.

Sure, but if you had phrased the question more fairly and said "Should it be ok for a company to give you free services in exchange for tracking everywhere you go?" I think almost everyone would have said yes.

> If someone went back in time to tell people that this new internet thing was going to lead to the US having more surveillance than East Germany or the Soviet Union, there would have been laws passed and systems designed from the start to prevent it from happening. The fact that it didn't happen this way, and our culture's privacy norms have been destroyed as a consequence, is more reason to act to prevent further damage, not a reason to just give up.

My intuition here is the same as yours. That this is a bad thing. That privacy matters in an intrinsic sense, not an operational sense. But i'm not so sure that's really true anymore. The privacy ship has sailed off into the sunset for a while now, and at least to me, the harms don't seem that substantial. All that data is mostly used to give me ads that are more targeted to what I might want to see anyway. There certainly could be lurking latent risks about, but it's a little hard to see exactly what they are.

Re: Silicon Valley is terrified of California’s privacy law

#472
post #462
post #52

I see a lot of comments deriding this law, can someone explain to me why these are bad things? Quoting from this article - https://techcrunch.com/2018/06/28/landmark-california-privac... - Businesses must disclose what information they collect, what business purpose they do so for and any third parties they share that data with. - Businesses would be required to comply with official consumer requests to delete that d…

It makes it extremely difficult to legally be a tech firm unless you're already a tech giant, just like the FDAs procedures make it impossible to invent a new drug unless you're already an established, giant pharma company. None of the big names in tech will have any trouble at all complying with this; I'd be very surprised if any at all are not already compliant today. At the same time, the percentage of tech startu…

I doubt this to be true honestly, because having user data worth selling already implies you to have a certain size. The request are reasonable and the dismissal with reference to difficulties startups might face is probably not applicable.

But if that is really a problem, just apply the requirements to companies with a minimum amount of users. Venture capital funded companies don't need to cut corners and shouldn't be allowed to when it comes to privacy.

Re: Silicon Valley is terrified of California’s privacy law

#473
post #428
post #386

Earlier quoted context omitted.

> Because if you were to run a survey over the general population the large majority is fine not having to pay for gmail, google search, maps and other "free" services while some data may be collected doing so How is this an argument against the law? It doesn't make it illegal to share data but requires that users can opt out. If said large majority is fine with surveillance, I guess Silicon Valley can relax.

He's saying being able to "opt out" is absurd. It's equivalent to getting the product for free in most cases. "Hey, I want to use your free service but I want to go ahead and opt out of the part that enables it to be free " You don't see a problem with that? It would be like if there were a restaurant that gave free food in exchange for filling out surveys (data collection). So you eat the free meal and then "opt out…

> You don't see a problem with that?

in this case, NOPE

Re: Silicon Valley is terrified of California’s privacy law

#474
post #273

Earlier quoted context omitted.

> The entire premise of free exchange is that I give you my services in exchange for something of value of yours. "Something" doesn't mean "anything". You can't offer your services in exchange for e.g. my body parts. Why are we willing to ban that but not our data? > The only reason those services are being provided at all is to get that data. That's effectively a requirement that people provide services for free. We…

There's also the dilemma that if you pay for something with a credit card, you have to identify yourself.

Will credit card companies fall under this law so I can opt out of them selling my purchase history?

Re: Silicon Valley is terrified of California’s privacy law

#475
post #462

Earlier quoted context omitted.

It makes it extremely difficult to legally be a tech firm unless you're already a tech giant, just like the FDAs procedures make it impossible to invent a new drug unless you're already an established, giant pharma company. None of the big names in tech will have any trouble at all complying with this; I'd be very surprised if any at all are not already compliant today. At the same time, the percentage of tech startu…

This law's implementation is bad for the same reason GDPR's implementation is bad: the people it's meant to target are easily capable of complying (and likely already do) and it's good for "the people" on paper, but disproportionately affects (hurts) small businesses that don't have the means to comply (or even know if they're properly complying to the extent of avoiding a lawsuit).

The GDPR requirements are not that hard to follow. Yes, it takes time to audit your tech stack and website, but small companies can certainly get it to work without paying thousands of dollars. Tools like this one (It was just $49 bucks) help you get started. https://appsumo.com/gdpr-tracker/

Re: Silicon Valley is terrified of California’s privacy law

#476

Earlier quoted context omitted.

> It also shows a direct discrimination against poor and/or young people who might not afford the service. As opposed to what, treating everybody badly? McDonalds discriminates between people who can afford a Big Mac and people who can't, and that's not a problem.

The internet is not the same as a food place. People expect and have gotten used to services for free. If you put a price tag on a software library, you obviously discriminate against students and poor people.

Students pay $200 for a single textbook. That they wouldn’t be able to afford some internet service is ridiculous. They could abstain from beer if necessary.

Re: Silicon Valley is terrified of California’s privacy law

#477

So the author would rather see each state/country implement it’s own laws so that a small startup needs to ensure they comply with hundreds of regulatory jurisdictions... awesome.

The gist of these laws are all the same. Just respect ALL users' data from the start, and you shouldn't have any difficulty with compliance.

Bullshit. "Respect users data" means different, incompatible things to different people and in different circumstances. You can't "respect" all of them at the same time.

Take the data deletion requirement. I know of many instances where users have permanently lost absolutely critical data because of that provision (already found in other privacy laws). When a user (accidentally) indicates they want you to delete their content, the provider has to permanently delete it within a reasonable timeframe, including purge from all backups.

Most users don't give a flying f'ck about all this privacy BS, but they care very much about what happened to their Master's thesis. They want a company who will be able to rescue them from their own mistakes. They want dependability. But they get "privacy" instead, and their accidentally wishes that you purge all their stuff gets obeyed.

Maybe you call that progress. But it really sucks when you purchase vague hypothetical benefit at the cost of real-world misery.

Re: Silicon Valley is terrified of California’s privacy law

#478
post #462
post #52

I see a lot of comments deriding this law, can someone explain to me why these are bad things? Quoting from this article - https://techcrunch.com/2018/06/28/landmark-california-privac... - Businesses must disclose what information they collect, what business purpose they do so for and any third parties they share that data with. - Businesses would be required to comply with official consumer requests to delete that d…

It makes it extremely difficult to legally be a tech firm unless you're already a tech giant, just like the FDAs procedures make it impossible to invent a new drug unless you're already an established, giant pharma company. None of the big names in tech will have any trouble at all complying with this; I'd be very surprised if any at all are not already compliant today. At the same time, the percentage of tech startu…

I just wanted to piggy-back onto the parent’s comment with a concrete example.

I’ve always been told that it’s good practice to take periodic backups. In the absolute worst cases, you can simply restore directly from these.

If a customer requests that their data are deleted, in addition to my production instance, does that mean that I have to remove their data from my backups? If so, I’m uncertain of the best way to do this. I’m uncertain if many managed services will allow me to mutate backups. And even if I were managing my database and backups directly, it seems painful to load each backed up database, remove the data, and rewrite the backup.

Note: I’m not saying that any of this is impossible. However, it does require a lot of ancillary engineering work difficult for a small company that’s just trying to get to product market fit.

Re: Silicon Valley is terrified of California’s privacy law

#479

Earlier quoted context omitted.

It doesn’t cost anything like $40 per month per user to operate Facebook, it’s not even $40 per year. (Facebooks operating revenue per user in 2018 was about $25). Of course, they’d hate the idea of having a fixed revenue per user. They want to keep sucking out more revenue per user until the well runs dry.

Yeah, but that's averaged across their global users. Stands to reason that most people in developing nations will not pay $25/mo to access Facebook; nor is their data worth that much. Ergo, Facebook will charge a different rate per nation; per state; ideally per user (they already have all the data they need to calculate exact revenue per user based on their data).

Why would they do that? They re not required to charge according to their costs

Re: Silicon Valley is terrified of California’s privacy law

#480
post #462

Earlier quoted context omitted.

It makes it extremely difficult to legally be a tech firm unless you're already a tech giant, just like the FDAs procedures make it impossible to invent a new drug unless you're already an established, giant pharma company. None of the big names in tech will have any trouble at all complying with this; I'd be very surprised if any at all are not already compliant today. At the same time, the percentage of tech startu…

I just wanted to piggy-back onto the parent’s comment with a concrete example. I’ve always been told that it’s good practice to take periodic backups. In the absolute worst cases, you can simply restore directly from these. If a customer requests that their data are deleted, in addition to my production instance, does that mean that I have to remove their data from my backups? If so, I’m uncertain of the best way to…

For GDPR it's sufficient to inform about the backups and when they are expected to be deleted. If you restore them you must have procedures in place to delete the requested data. I don't think this is any different.
Post reply on HN