Live data from Hacker News

EU negotiators agree new rules to rein in tech giants

politico.eu

121–130 of 351 posts

Re: EU negotiators agree new rules to rein in tech giants

#121
post #111
post #96

Earlier quoted context omitted.

If one side supports a feature and the other doesn't, they're still interoperable, just without that feature.

how are they interoperable when one side uses a feature and the other doesn't support it? that's just degrading the experience... and this is just one small reason why the industry decided against moving forward with this decades ago. it simply didn't make any sense then, certainly doesn't make sense now.

> > that's just degrading the experience... > Uhhh yes? That's the point? The alternative to this degraded experience is no experience at all.

so basically it's either degraded experience but w/ interoperability or great experience but w/o interoperability?

that doesn't really make sense. why not a third way with great experience and great interoperability?

i'm asking because i can guarantee that no one will use clients that provide a degraded experience when you've got the established players providing a great experience.

Re: EU negotiators agree new rules to rein in tech giants

#122
post #100
post #44

Earlier quoted context omitted.

>interoperability requirements for messaging services, meaning outfits such as WhatsApp, Facebook Messenger Who will be decrypting WA and Signal message to pass them to Facebook Messanger?

yeah, i don't think this was thought out, or at least i haven't read anything on this subject. how does the draft text deal with cryptography?

Something like this can't really make end to end encryption interoperable. There will be no encryption at the transitions between systems. Clients would have to use something that can work over arbitrary textual channels like OTR or PGP.

Re: EU negotiators agree new rules to rein in tech giants

#123
post #2

> Parliament also succeeded in convincing the Council of interoperability requirements for messaging services, meaning outfits such as WhatsApp, Facebook Messenger or iMessage will have to open up and interoperate with smaller messaging platforms. For group chats, this requirement will be rolled out over a period of four years. This would be great. I remember using pidgin back in the day and it was really convenient…

> meaning outfits such as WhatsApp, Facebook Messenger or iMessage will have to open up and interoperate with smaller messaging platforms The way i read it, they're calling for open standards, which can be a good thing. Sadly, open standards also slow down the development of new features, as everybody needs to be "on board" for new features to roll out. Take email (SMTP, IMAP, etc) as an example, where no major progr…

I think in this case it's more about services allowing stuff like third party clients or providing APIs, not binding themselves to a specific standard

So if I'm whatsapp I have to allow third party clients, but I can also change my API as needs change, as long as I don't lock it.

Re: EU negotiators agree new rules to rein in tech giants

#124
post #19

Earlier quoted context omitted.

Oh, man, such a shame about all these laws.. [checks notes].. protecting users from predatory company behavior. Things would be so much easier if we didn't have those laws - we could all start web startups.

This is already a pattern in HN discussions: legislation is proposed, news outlets vaguely summarize it, the HN crowd interprets the summary in absurdly maximalist way without bothering to read the spirit and letter of the law; outrage ensues. This is coupled with an "I-know-better" condescension towards authorities, reinforced by a weird ideology that code is above law The legislation, at least the one coming from B…

The GDPR had consequences that were both wider and wilder than even its most aggressive critics predicted at the time, such as making it illegal for the banking system to continue using their existing EBCDIC-based systems: https://news.ycombinator.com/item?id=28986735 The HN discussion was also full of comments about how the bank should've changed its systems already because it had ample time to come into compliance with the GDPR, never mind that no-one really even anticipatd this as a compliance issue at the time.

Re: EU negotiators agree new rules to rein in tech giants

#125
post #121
post #111

Earlier quoted context omitted.

how are they interoperable when one side uses a feature and the other doesn't support it? that's just degrading the experience... and this is just one small reason why the industry decided against moving forward with this decades ago. it simply didn't make any sense then, certainly doesn't make sense now.

> > that's just degrading the experience... > Uhhh yes? That's the point? The alternative to this degraded experience is no experience at all. so basically it's either degraded experience but w/ interoperability or great experience but w/o interoperability? that doesn't really make sense. why not a third way with great experience and great interoperability? i'm asking because i can guarantee that no one will use clie…

It's important for the capability to be there. The issue is that currently "established players" control that experience. In a saner world, experience needs to be decoupled from infrastructure.

Somehow, ICQ worked wonderfully despite everyone I knew using an unofficial client. The official client (at least Windows one) was a terrible mess. It had ads and all those features no one ever asked for, like games and and news and an entire picture-based language (I'm not joking). But QIP, the client I used, only did the things I needed an ICQ client to do, and nothing more. It also had no ads.

Re: EU negotiators agree new rules to rein in tech giants

#126

Earlier quoted context omitted.

Lets talk about startups first: An indie dev in New York does not care about the GDPR. The just build cool shit and put it online. Look at all the Show HNs here. In the EU, the situation is very different. Indie devs are super afraid and work hard to make their stuff less useful to please the GDPR. Now about larger players: EU companies agonize their worldwide users with cookie banners. Because that is what the GDPR…

Small correction: the indie devs just building cools shit are fine under GDPR. The indie dev who wants to monetize his community while not caring about the externalities of possibly leaking their information has a headache. If your business model depends on creating undesirable externalities for your "users" then you don't have my sympathy. The only shame is that we still need to enforce GDPR properly on large player…

What's the limit that an indie could go without caring about GDPR. Is it actually until they want to be "commercial"?

Re: EU negotiators agree new rules to rein in tech giants

#127
post #44
post #2

> Parliament also succeeded in convincing the Council of interoperability requirements for messaging services, meaning outfits such as WhatsApp, Facebook Messenger or iMessage will have to open up and interoperate with smaller messaging platforms. For group chats, this requirement will be rolled out over a period of four years. This would be great. I remember using pidgin back in the day and it was really convenient…

>interoperability requirements for messaging services, meaning outfits such as WhatsApp, Facebook Messenger Who will be decrypting WA and Signal message to pass them to Facebook Messanger?

Presumably if you as a user want to use an app that interoperates with Signal, Whatsapp and Messenger then you'll be logging in with your signal, whatsapp and messenger credentials and give it permission to read your messages and relay them

I don't think this is to be interpreted as "from now I need to be able to send messages from a Whatsapp client to a Signal client"

Of course any such app would be able to read all the messages in the clear and would be able to store them in the clear, leak them, sell them or whatever. As with any other case in which you choose to use a chat app you have to trust the chat app to read your messages if it wants to

I imagine if that's the case whatsapp or signal, when you do a first login from a different app, will flash a warning that you're using a third party client which might not be trustworthy

Re: EU negotiators agree new rules to rein in tech giants

#128

> EU officials have agreed on landmark rules I'm not sure what this means in terms of the timeline. Will it be voted for in European Parliament and if yes, when? To what extent this may be changed in the final edition? And if it's adopted as a law, how much of a grace period will the companies have?

The trilog between the parliament and the member states decided upon a text. Next each chamber will vote on it but this is usually just a formality since they gave the negotiators a mandate beforehand. If it passes, the text will become a EU directive which needs to be incorporated into national law by the member states. After that it becomes enforceable.

>If it passes, the text will become a EU directive which needs to be incorporated into national law by the member states.

The DMA is a Regulation, not a Directive. It doesn't need to be transposed in to national law in member states.

Regulations become law across the whole EU (and usually the EEA as well) as soon as they are published in the Official Journal.

Re: EU negotiators agree new rules to rein in tech giants

#129
post #55

Earlier quoted context omitted.

Every developer should try to understand GDPR to a basic level, as those basic principles are good enough of a baseline. Won't go into minutia, cause at the enterprise/large scale level you'll need a DPO (data protection officer) and follow stricter auditing practices (among other things). Second, cookie banners are unrelated to GDPR. They became mandatory years before the GDPR, and the level of intrusiveness is beca…

A high level overview may be possible, but any amount of actionable detail is impossible for laymen and lawyers alike. The GDPR is intentionally vague; there are entire academic papers from respected researches dedicated to trying to parse individual sentences from the document. See e.g. Cohen and Nissim's 33 page article on intepreting the sentence > To determine whether a natural person is identifiable account shou…

I think actionable details are left vague as to not create legislation that's left behind by technological advances.

You're right, that personal identifiable information is a hot topic. Partly because you need immense foresight (a.k.a. impossible) to see how multiple data points can be correlated to identify someone, but also because you need to be aware of large-scale actors (e.g. state supported dragnet surveillance).

As an industry I don't think we have reached yet that discussion point, when we still have common basic practices we need to change. For example, I know that most small/medium companies don't even attempt to anonymize their database dumps. Those are the issues we have to focus on first, and those actions become clear to any developer that reads the GDPR for the first time. It's actionable insight without being explicitly stated.

I think that the GDPR is *incompatible with the web 2.0 model, and the internet as it exists today*, and I also think that is a good thing! It should push us to build services that in the end treat all users data as personal information, and lead to anonymous internet services by default.

I have my own laundry list of things I dislike about GDPR, which makes compliance harder than it should be. One such example is that IP addresses are "an exercise left to data controllers to anonymize", where I hold the belief that the legislature should have forced ISPs to be the ones to anonymize user IP addresses (anonymize things at the source). That way data protection agreements would not be even necessary when you use a CDN in front of your website (for example). By the same token, browsers should be forced to use generic User Agents, as those leak platform information like crazy.

I also disagree that "vague laws lets you turn entities you don't like into cash cows", because what I see most common is that companies get a slap on the wrist (so to speak) and fines are not always the first recourse, only affecting those that are majorly negligent and repeat offenders.

These laws are not draconian tools to suppress digital products, but to protect users from life affecting data leaks, automated decision making and profiling, which we've seen to be objectively bad in the past.

But as you can tell this is my highly subjective take on the issue. I might be completely wrong in my belief after all.

Re: EU negotiators agree new rules to rein in tech giants

#130
post #44
post #2

> Parliament also succeeded in convincing the Council of interoperability requirements for messaging services, meaning outfits such as WhatsApp, Facebook Messenger or iMessage will have to open up and interoperate with smaller messaging platforms. For group chats, this requirement will be rolled out over a period of four years. This would be great. I remember using pidgin back in the day and it was really convenient…

>interoperability requirements for messaging services, meaning outfits such as WhatsApp, Facebook Messenger Who will be decrypting WA and Signal message to pass them to Facebook Messanger?

Why would they need to decrypt anything? If they use open standards such as the signal protocol, there's no need to decrypt anything.

https://signal.org/docs/

Post reply on HN