Earlier quoted context omitted.
> trained users to consent to anything that comes their way and corporations now have legal basis to use, process and sell that data. Sorta? I don't consent to much when I get the pop-up. You can revoke consent at any time as well and you're entitled to the data the company has on you.
Average person don't understand what they click on and they just want the pop up the get out of their way. You have a bias for being a tech person who understand this, but vast majority of people have no idea what it is about and they just consent because they don't care or know the impact of their decision.
Statement on 4 Years of GDPR
81–90 of 195 posts
Re: Statement on 4 Years of GDPR
#82Earlier quoted context omitted.
> The legislation itself is sane On paper yes, great intentions[1], in practice no. E.g. Right to be forgotten. Implement RTBF in context of IPFS. [1] Second order effects like prevent rats/snakes by awarding award for rat/snake heads, lead to rat/snake farms. > if privacy-violating monopolies retract from the market You get Splinternet. Several independent Internets, walled from each other.
I find the right to be forgotten very valuable in a world where everything is permanent, searchable and every little mistake will be used against you in the future. > Implement RTBF in context of IPFS. How does IPFS deal with CSAM being published on it? Not saying it should detect CSAM, but once it is found, how does one go about having it removed? You use the same system to handle RTBF, and if you can't, then maybe…
So do people with skeletons in the closet. Not saying you do, but right to be forgotten can infringe on other people's right to be well informed.
This is not a hypothetical. It has already happened.
> How does IPFS deal with CSAM being published on it?
Using CSAM to justify a law, is not a winning strategy.
It would be tedious but probably destroying all nodes. Which means IPFS is not compatible with RTBF.
> If there's an internet where Facebook and Google can't spy on me, sign me up!
That does leave state actors though.
Re: Statement on 4 Years of GDPR
#83Earlier quoted context omitted.
> Is there really no way to monetise an audience with ads without collecting their personal info? There sure is: Contextual ads. DuckDuckGo does it, various documentation sites do it ( https://www.ethicalads.io/ ), a dutch broadcaster does it ( https://archive.ph/Zk4Pv ). It's how newspapers used to work and TV channels still do, as well as YouTube sponsorships (and probably many more). It improves the UX over person…
Contextual ads have their own set of problems for advertisers though. Think of a blog post writing about someone's traumatic experiences with pregnancy and miscarriages and the algo decides to put an ad for newborn clothes next to it. Ouch...
Re: Statement on 4 Years of GDPR
#84Cookie banner alone has probably done more harm in terms of wasted human life than anything else combined. 4.66 billion active internet users, 92% of which are web users, spending 5 secs per day on clicking all cookies allowed. That's 680 human years wasted per DAY on these banners.
Re: Statement on 4 Years of GDPR
#85Cookie banner has ruined the whole web. - Does not protect people (99% are just fake. If you reject cookies you keep get them) - Cost money to company (so cost to customers). A simpler browser extension where you manage your preference once far all (default) with the possibility to personilize x site (think like you do for camera permission) would have solved the problem in a real way and without all the hussle.
Re: Statement on 4 Years of GDPR
#86This article is excessively negative on the effectiveness of the law. I would say the biggest issue is inconsistent enforcement by DPAs. The other problems are overstated. Believe me, as someone who sees things from the inside of european companies, compliance is still taken very seriously.
Wasn't this called out repeatedly over the years and obvious from the start? That a double forum shopping model will produce paperwork and voluntary compliance, in cases where the offender literally didn't know they were misbehaving, but little real action?
Re: Statement on 4 Years of GDPR
#87Cookie banner alone has probably done more harm in terms of wasted human life than anything else combined. 4.66 billion active internet users, 92% of which are web users, spending 5 secs per day on clicking all cookies allowed. That's 680 human years wasted per DAY on these banners.
Because big companies with deeply unethical business practices are basically saying: "if we annoy you to death, maybe you get governments off our backs and let us make even more money".
They're like Big Tobacco when tobacco ad regulations were introduced.
Re: Statement on 4 Years of GDPR
#88Earlier quoted context omitted.
> trained users to consent to anything that comes their way and corporations now have legal basis to use, process and sell that data. Sorta? I don't consent to much when I get the pop-up. You can revoke consent at any time as well and you're entitled to the data the company has on you.
Average person don't understand what they click on and they just want the pop up the get out of their way. You have a bias for being a tech person who understand this, but vast majority of people have no idea what it is about and they just consent because they don't care or know the impact of their decision.
Do you have a link to the study that shows this?
Re: Statement on 4 Years of GDPR
#89This is an excellent quote that reflects a notable share of opinions that I see in the comments here on HN whenever the GDPR is discussed: > Hardly any other area of law is politicized to that extent – at least I have never heard that building or tax codes were openly ignored with the argument that compliance would “undermine the business model” of a company. The privacy bubble accepts such narratives as a legitimate…
This is a disingenuous framing of the argument as it commonly appears on HN, sometimes by me.
The complaint isn't with respect to what the rules permit and prohibit. (Some people complain about that, but it's not the common mode.) It's the enforcement mechanism. Complaint initiated. Multi-forum and portable. Imprecise on implementation details. Those factors make compliance, even for someone looking to do everything right, expensive. Which raises barriers to entry. (And creates room for mischief.)
The closest similar thing in the U.S. is our approach to securities regulation. Complaint initiated. Each state has its own forum. Each side can complain and defend in different forums and then expensively argue over arcane rules for forum selection. Details hashed out through enforcement actions versus ex ante published rules. Now imagine there was no SEC corralling the mess. That's GDPR.
Re: Statement on 4 Years of GDPR
#90This is an excellent quote that reflects a notable share of opinions that I see in the comments here on HN whenever the GDPR is discussed: > Hardly any other area of law is politicized to that extent – at least I have never heard that building or tax codes were openly ignored with the argument that compliance would “undermine the business model” of a company. The privacy bubble accepts such narratives as a legitimate…
> compliance would “undermine the business model” of a company This is a disingenuous framing of the argument as it commonly appears on HN, sometimes by me. The complaint isn't with respect to what the rules permit and prohibit. (Some people complain about that, but it's not the common mode.) It's the enforcement mechanism. Complaint initiated. Multi-forum and portable. Imprecise on implementation details. Those fact…