Live data from Hacker News

Europe is scaling back GDPR and relaxing AI laws

theverge.com

521–530 of 1001 posts

Re: Europe is scaling back GDPR and relaxing AI laws

#521
post #500
post #270

I get that too many regulations is a bad thing. But when we talk privacy and personal data there should be no gray zone. It has to be black and white. When I see a stupid cookie banner I search for "Reject all". There's no some data that companies can collect and process without my consent, they just shouldn't be able to collect anything without me actively opting in. Business never respects anything, but profits. Se…

You can do this trivially in modern browsers: private browsing. I have one "normal" browser window for "persistent cookie" use (like gmail, youtube, etc) and another "private" window for everything else. Cookies are lost anytime a tab closes.

Yeah idk why there's a law trying to poorly enforce this instead

Re: Europe is scaling back GDPR and relaxing AI laws

#522
post #502
post #391

Earlier quoted context omitted.

More regulation , or stronger regulation, as in less wiggle room for businesses, may be a good thing. Case in point: a regulation requiring to disclose the ingredients of food. Too many regulations is almost always a bad thing: numerous pieces of regulation rarely fit together seamlessly. It becomes easier to miss some obscure piece, or to encounter a contradiction, or to find a loophole. The cost of compliance also…

> The cost of compliance also grows, and that disproportionately favors big established players. Not true at all. Most of the harsher regulations only come into effect when the company hits a specific size. Examples from Australia (my country): - Online shops that operate overseas, and import to Australia have to collect sales tax... but only if they make more than $75,000 from Australia per annum. - Social media has…

Actually, online shops that mail stuff to Australian customers who request them to do so don't have to collect or pay any sales tax. The Australian government might stomp their feet and declare otherwise, but they have no legal or jurisdictional authority to do so, nor any real means for enforcement.

This trend of countries declaring that everyone on the planet is under their jurisdiction if they mail something there (or respond to a network request) is bananas.

Re: Europe is scaling back GDPR and relaxing AI laws

#523
> Under the new proposal, some “non-risk” cookies won’t trigger pop-ups at all, and users would be able to control others from central browser controls that apply to websites broadly.

For 'central browser control', what is technically mechanism behind this? Is it something like an entirely new request header sent by the browser? Or re-using some existing RFC? Also curious if the regulation will compel browsers to implement this or something.

Managing cookie permissions at the browser level always made the most sense, but implementing it with regulation is what seems hard.

Re: Europe is scaling back GDPR and relaxing AI laws

#524
post #367

Earlier quoted context omitted.

Who is the audience your comment is trying to reach? Who are these mysterious "companies"? It's important to realize companies are made of people. Someone had to explicitly code the dark pattern in the GDPR cookie dialog. Ever notice the button for "Accept All" is big and shiny, while refusing all is more often than not a cumbersome, multi-click process? That's not an accident. That was coded by people. People around…

My theory is that companies are not the sum of their employees. Employees are generally good; toxic humans are a small minority (unfortunately they tend to be over-represented at the head of companies). But put employees together into a profit-maximisation machine, and the machine will try to maximise profit, with dark patterns and downright evil things. Similar with our species as a whole: nobody is actively working…

That's why we need to realize, that decisions in the small constitute what happens in the large. If some person comes and tells me to implement dark patterns into the consent popup, I'll tell them that this is illegal. I'll also tell people, when their current consent is manufactured or when their cookie/consent popup does not conform with GDPR. Been there, done that. Only unfortunate, that it was not my role to deal with that. It was simply that most people didn't care (I must assume frontend developer knew better, otherwise they were utterly uninformed about their job), some people who should have known better didn't (everyone else in the engineering team), some people wanted dark patterns to be in there (project management and marketing/sales, as usual), and I was the only one pointing out the tiny problem with the law. Of course no one ever thanked me for that.

Re: Europe is scaling back GDPR and relaxing AI laws

#525

Earlier quoted context omitted.

Which is why we need professional licensure: You get to tell your boss "If I tell you to go fuck yourself, then I risk this job. If I implement your feature, I risk losing every future job by losing my license. And everybody you can hire to do this will tell you the same thing".

I don't want to live in your hellscape where my government tells me I can't program a website without a license. Grow up and tell someone you won't implement a feature because you don't like it. I do it all the time - "that's a bad idea, I'm not doing that". I still manage to eat, it's not either/or, you have agency, you can refuse without resorting to regulation saying you must.

Maybe you could still program a website. But you might not be able to do it professionally.

But yes, more people should tell other people that they won't do that.

Re: Europe is scaling back GDPR and relaxing AI laws

#526

Earlier quoted context omitted.

Who is the audience your comment is trying to reach? Who are these mysterious "companies"? It's important to realize companies are made of people. Someone had to explicitly code the dark pattern in the GDPR cookie dialog. Ever notice the button for "Accept All" is big and shiny, while refusing all is more often than not a cumbersome, multi-click process? That's not an accident. That was coded by people. People around…

Having coded multiple such buttons in the past, I'd like to ask to consider that the person doing the coding is barely the person making the decision. It's hard to reject such a request when your lifelihood depends on the job

It might be hard in some places, with especially toxic higher ups. A good start is pointing out the law a few times. If that doesn't get them to stop, what you can do is ask them to give you a signed piece of paper, where it says, that against your objection and warning about this being illegal, they want you to still do that. Usually at that point they will find someone else, or stop trying to do it.

Re: Europe is scaling back GDPR and relaxing AI laws

#527
post #376

Earlier quoted context omitted.

> we've lost a lot of the hacker spirit and have a larger proportion of "chancers", people who are only in tech to "get rich quick". Doesn't that describe SV in general, and big tech in particular?

> Doesn't that describe SV in general, and big tech in particular? Absolutely! It's just that the hopeful hacker/nerd culture used to be more dominant here (slashdot had the more cynical types). Now there are a generation who don't know anything but Javascript but think that they're God's gift to programming. I can understand it as ZIRP resulted in the bar being dropped to the floor for jobs which paid SV salaries. I…

This sounds too much like a 'good old days' argument, which is actually in the HN guidelines (something like, 'don't say HN is becoming Reddit').

Re: Europe is scaling back GDPR and relaxing AI laws

#528

Earlier quoted context omitted.

I've stopped thinking of regulations as a single dial, where more regulations is bad or less regulations is bad. It entirely depends on what is being regulated and how. Some areas need more regulations, some areas need less. Some areas need altered regulation. Some areas have just the right regulations. Most regulations can be improved, some more than others.

>I've stopped thinking of automobile repair as a single dial, where more automobile repair is bad or less automobile repair is bad. It entirely depends on what is being repaired and how. Some areas need more automobile repair , some areas need less. Some areas need altered automobile repairs . Some areas have just the right amount of automobile repair . Most automobile repairs can be improved, some more than others.…

Your midbrow dismissal only makes sense if there is nobody who denies that regulation is nuanced. In fact, the entire political landscape is set up around a "regulation is GOOD" vs "regulation is BAD" worldview.

Re: Europe is scaling back GDPR and relaxing AI laws

#529
post #432

Earlier quoted context omitted.

Who is the audience your comment is trying to reach? Who are these mysterious "companies"? It's important to realize companies are made of people. Someone had to explicitly code the dark pattern in the GDPR cookie dialog. Ever notice the button for "Accept All" is big and shiny, while refusing all is more often than not a cumbersome, multi-click process? That's not an accident. That was coded by people. People around…

someone coded it once, everyone else just adds another dependency that fulfills the spec, they don't even have to search for "dark patterns", just "most effective"

How much incompetence do we accept or tolerate, before we deem it negligence? If someone adds a consent popup or similar thing to a website, usually knowing, that there is a reason why this must be done, and that this reason is GDPR, it seems quite incompetent to not know the first bit about what is required, and not doing their due diligence to read up on it when not one doesn't know.

Perhaps it would change things for the better, if this special kind of people were at least temporarily removed from the job, until they have gained basic knowledge about their job and how it affects other people.

Re: Europe is scaling back GDPR and relaxing AI laws

#530
post #270

I get that too many regulations is a bad thing. But when we talk privacy and personal data there should be no gray zone. It has to be black and white. When I see a stupid cookie banner I search for "Reject all". There's no some data that companies can collect and process without my consent, they just shouldn't be able to collect anything without me actively opting in. Business never respects anything, but profits. Se…

The trouble is that everyone else is pursuing tech unhindered by such regulations at breakneck speed, and Europeans realize that Europe - once the center of science and technology - is increasingly sliding into a backwater in this space and an open air museum. Now, some will agree with you and say that privacy should never be violated, but nonetheless accept a certain measure of tolerance toward that kind of violatio…

I don't think GDPR is the problem that makes science and technology succeed more elsewhere or fail more in the EU. There are far, far bigger problems, that are at play here. For starters we have a war still ongoing in the east. Economic power houses have had utterly corrupt governments for decades. Standardization of many things is difficult with so many separate nations. Education systems are questionable. All of these will play a larger role than GDPR.
Post reply on HN