Live data from Hacker News

Silicon Valley is terrified of California’s privacy law

techcrunch.com

541–550 of 553 posts

Re: Silicon Valley is terrified of California’s privacy law

#541
post #172
post #52

I see a lot of comments deriding this law, can someone explain to me why these are bad things? Quoting from this article - https://techcrunch.com/2018/06/28/landmark-california-privac... - Businesses must disclose what information they collect, what business purpose they do so for and any third parties they share that data with. - Businesses would be required to comply with official consumer requests to delete that d…

> - Consumers can opt out of their data being sold, and businesses can’t retaliate by changing the price or level of service. This is something I object to. It's just fundamentally stupid and doesn't make sense. The entire premise of free exchange is that I give you my services in exchange for something of value of yours. Making it illegal to withhold services if you don't give up your data is crazy. The only reason…

I think you've missed the point. This does not make it illegal to collect or even sell user data, it makes it illegal to do so without consent.

Any concern regarding whether consent is likely to be withheld really just points out how stupid a company's business model is. Incumbent vs. Startup is also a false premise because Facebook is an incumbent that relies on selling user data. They do make some money from purely internal advertising, but in total Facebook only makes less than $5 per user when selling data, and that's lifetime, not per year. So the only way to make real profits from selling data is if you sell millions of people's data. Their internal data use however, is just for add targeting which they make more money from each year. This internal use makes more per user and is therefore a more viable strategy for a small company than selling data.

There are already regulations that make it impossible to sell user data that would be valuable that apply to more than just internet collected information. So, any data selling strategy a startup or incumbent company might have will either not earn significant profits or is very likely already illegal.

In any case, advertising revenue rarely ever covers a company's expenses. If a company is only staying afloat because of selling data, then that company is achieving a very poor return on investment and is wasting the time of everyone involved. Either they need better business processes, strategies or they're not offering something of sufficient value to be worth the time put into the business.

Re: Silicon Valley is terrified of California’s privacy law

#542
post #263

Earlier quoted context omitted.

You just have to change the onboarding process to include a fee, and offer an incentive/rebate of the subscription price to match the cost to basically make it free. That way if they decide to change their mind and not give their data, you're still in the clear by removing the incentive and either charge their payment method or disable their service until they do (or reenable data sharing). That way it feels more tra…

>You just have to change the onboarding process to include a fee, and offer an incentive/rebate of the subscription price to match the cost to basically make it free. That way if they decide to change their mind and not give their data, you're still in the clear by removing the incentive and either charge their payment method or disable their service until they do. What's the practical difference between these two sc…

The difference is mostly to do with user experience. It also has to do with the requirements of how you bill the customer. It means you can't give them a "free" sign up and then charge them a fee after the click the data selling opt out button.

What's meant by saying you can offer incentives is that you must present all information at the same time and that users are considered as opt-out by default.

Basically, the user must go through a sign up page that has a box that says "You may sell my data in exchange for a $3 discount" and it cannot be selected by default. You also cannot have a sign up page that has a box that must be selected to opt-out whether the box is selected by default or not.

The no-relatiation clause also has addition requirements that are not related to money. For example, you cannot refuse to allow a user to access your site because they didn't allow their data to be sold. You also couldn't impose access limitations like slowing the rate of page response or increasing the number of advertisements on the page or send spam only to users that opt-out.

The difference isn't really about charging a fee to users that won't let you sell their data. It's more about not allowing websites to harass users with increased advertising on behalf of whoever they wanted to sell your data to. It's only illegal for them to sell the data, internal use is still legal, so they're preventing a loopholes.

Re: Silicon Valley is terrified of California’s privacy law

#543
post #190

Earlier quoted context omitted.

The GDPR is pretty bad for under 5 engineer startups. They can be very privacy respecting small businesses that charge for their product, like sql training courseware[0], and wouldn't mind clearing what little personal data they had on you (user server logs, billing info, etc). But being privacy respecting and properly complying with GDPR with audit log systems, etc are 2 different things that require hiring 1 or 2 e…

I've heard this line so many times, but there are vanishingly few examples of companies that really suffered for it ("just don't sell in Europe" implies, to me, that Europe wasn't valuable enough to you as a market to take the time engineering GDPR compliance--and that's just fine). The ones that did crash overwhelmingly seemed to be sketchy data brokers.

I think a bunch of them took the "if audited we will probably be screwed unless the enforcing body takes leniency on us" and just kept on going. It opens up everyone to another huge liability but that's business. DPOs only have so many staff to investigate complaints.

Re: Silicon Valley is terrified of California’s privacy law

#544

Earlier quoted context omitted.

You used the first person pronoun a lot there. Do you yourself actually feel that you are short-sighted and that you consistently underestimate the value of your data? Or are you putting yourself in the place of a hypothetical other person?

Hypothetical. The post I replied to used "I" and "you", so I used "you" and "I". That said, I genuinely don't know how much my data is worth…

I ask because people are often very quick to suppose that they are part of the educated elite but other people need them to protect them from their own bad choices.

Do you, for example, not use Google because you are concerned they are getting too good a deal from you? Duck Duck Go exists.

Re: Silicon Valley is terrified of California’s privacy law

#545

Earlier quoted context omitted.

Your identity on HN is your profile and posts, and your shared secret is how you prove you own that identity. Is that actually uncommon? I would call `laughinghan` an identity. > As for the use of photos of me that are owned by other people, I'm pretty certain that neither CCPA nor GDPR cover those. You're talking about specific laws, and I'm talking about general principles. The dichotomy I'm supposing is between co…

You're making no sense. If someone publishes a link between my address and my name, or my address and an online handle of mine or something, in order to remove that link I would have to prove that I am the person with that name at that address, or that I am the person with that online handle or whatever, but there's no fundamental reason I would have to further identify myself in any way. There's no conflict between…

> in order to remove that link I would have to prove that I am the person with that name at that address, or that I am the person with that online handle or whatever, but there's no fundamental reason I would have to further identify myself in any way.

I feel like I'm missing something fundamental with your point, because this sounds to me like you're saying the same thing I'm saying, and then coming to a different conclusion. How would you prove that you were the owner of a name and address without revealing additional information about yourself?

The best way I can think of is to use a trusted third-party for verification. For example, send a censored utility bill that's in your name. But this still seems to me like it's a compromise -- it means that 3rd party needs to know your name/location, and it means you need to reveal your relationship with the third party.

Is there another strategy I'm not familiar with? I suppose in some cases, like with a government ID, your relationship with the third party wouldn't be new information. But it seems like a stretch to say that a government database of names and addresses wouldn't impact anonymity.

> The possibility of corporations being anonymous is not an example of a tradeoff between anonymity and control either.

If a website operator is anonymous, how are you going to contact them and require them to take down your information? If they refuse, or if you get their website removed and they just keep buying and posting it on new domains, how are you going to stop them from doing that?

I'll fully admit I've been talking a lot about theoretical extremes, but this particular problem isn't theoretical at all. Onion sites are already a thing, and it is notoriously difficult to get illegal information removed from the dark web because the site owners, site visitors, and even server locations are anonymized.

Tor makes it easy for me to stay anonymous, but it seems to me like Tor makes it very hard for me to control my data.

Re: Silicon Valley is terrified of California’s privacy law

#546
post #534

Earlier quoted context omitted.

I'm no expert. But typically, when installing web servers, I don't enable logging. I'm more familiar with the issue of logging by VPN services. And I've been assured, by someone who runs one, that logging isn't necessary. Everything can be done in real time, with any "logs" retained briefly in RAM.

I'm an expert. The correct answer is to not log any PII data. Logging obvious PII because it might be useful in some hypothetical future sounds like plain incompetence. If you really need to log PII, log it separately and set clear policies about how this data is stored, how it's replicated, who can access it. If you need to log some PII IDs in common logs, use some fuzzy hashing: good enough for logs, not good enoug…

Thank you.

PII that you don't need can become like radioactive waste. If it gets subpoenaed, and it comes out that you retained and produced it, your reputation may be hosed. But if there's nothing to produce, no problem.

That's actually not quite correct. If you're required by law to retain that PII, you'll be hosed if you can't produce it. But then, maybe you should be doing business in a different jurisdiction.

I'm thinking of Private Internet Access. To my knowledge, logs have been subpoenaed in two US criminal cases. And they just said that they didn't retain logs. But then, VPN services aren't required to retain logs in the US.

Re: Silicon Valley is terrified of California’s privacy law

#547

Earlier quoted context omitted.

You're making no sense. If someone publishes a link between my address and my name, or my address and an online handle of mine or something, in order to remove that link I would have to prove that I am the person with that name at that address, or that I am the person with that online handle or whatever, but there's no fundamental reason I would have to further identify myself in any way. There's no conflict between…

> in order to remove that link I would have to prove that I am the person with that name at that address, or that I am the person with that online handle or whatever, but there's no fundamental reason I would have to further identify myself in any way. I feel like I'm missing something fundamental with your point, because this sounds to me like you're saying the same thing I'm saying, and then coming to a different c…

How would you prove that you were the owner of a name and address without revealing additional information about yourself?

Theoretically, there could be a system where, if the publisher of a name+address gets an anonymous request to remove that information, then they have to mail a letter with a nonce to that address, and then if they get a followup request with that nonce, then they have to comply and remove it.

In practice, a system involving third-parties such as a lawyer or government agency is more likely, I'm just proving my point that there's nothing fundamental that requires compromising anonymity.

It's also worth noting that if a client is known to their lawyer but unknown to anyone else, it's pretty widely accepted to describe that client as anonymous, even if they're not technically anonymous in the ultimate, purist sense.

If a website operator is anonymous, how are you going to contact them and require them to take down your information? [What] if they refuse?"

First of all, that's not a conflict or tradeoff between my ability to anonymously use services and my control over my data.

And the obvious solution, which is the one we have, is that to run a website, someone has to give up a little anonymity and be subject to laws. But there's no fundamental reason people can't anonymously use services and maintain control over their data.

Re: Silicon Valley is terrified of California’s privacy law

#548
post #453

Earlier quoted context omitted.

I agree and this seems to be the main problem: we are losing privacy today but we will suffer most of the consequences tomorrow. So most of us are not aware of the real cost we're paying and unable to make an informed decision.

Welcome to democracy, where an individual with zero understanding of an issue can vote on it and is legally entitled to have their opinion taken seriously.

Yes, I think about this often and it appears to be a bug in the democracy system but any attempt to tie voting rights to knowledge seems to create even more bugs.

Re: Silicon Valley is terrified of California’s privacy law

#549

Earlier quoted context omitted.

Hypothetical. The post I replied to used "I" and "you", so I used "you" and "I". That said, I genuinely don't know how much my data is worth…

I ask because people are often very quick to suppose that they are part of the educated elite but other people need them to protect them from their own bad choices. Do you, for example, not use Google because you are concerned they are getting too good a deal from you? Duck Duck Go exists.

I use DuckDuckGo, and only fairly rarely fall back to Google. My Gmail account is dormant, I set up my own mail server. But I still have an Android phone…

Re: Silicon Valley is terrified of California’s privacy law

#550
post #52

I see a lot of comments deriding this law, can someone explain to me why these are bad things? Quoting from this article - https://techcrunch.com/2018/06/28/landmark-california-privac... - Businesses must disclose what information they collect, what business purpose they do so for and any third parties they share that data with. - Businesses would be required to comply with official consumer requests to delete that d…

If you favor an idea that a private company should be compelled to provide a service for free, even if you don't share your data, would you also agree to the idea that a private company should be compelled to respect freedom of speech on their platform even if they don't benefit from it?
Post reply on HN