There is a way to implement this functionality in an interoperable way that complies with the DMA. Apple just chose not to. Not because it's impossible to implement it in a privacy-respecting way, it just wants to lock people into their ecosystem, the exact thing DMA is protecting users against. Apple realized its standard malicious compliance playbook won't fly this time, so now they're trying to sway public opinion…
Apple decided not to roll out Siri in EU after denied request for exemption
221–230 of 735 posts
Re: Apple decided not to roll out Siri in EU after denied request for exemption
#222Earlier quoted context omitted.
Lemma 1: you want to protect your users privacy, and are also beholden to regulation enforcing that commitment (GDPR). Lemma 2: you are obliged by other regulation to offer equal access to user data to third parties, so others can build equivalent functionality (DMA). Lemma 3: malicious third parties will absolutely try to abuse the access and trick the user into sharing their data by all means possible. You will be…
I am not sure this is as much of a tension as you make it sound: where is the obligation that a marketplace administrator will be blamed for any and all breaches of data privacy trust from a participating (likely malicious) third party? According to GDPR, the app developer is the "data controller" and thus ultimately responsible. Only in the case where Apple knowingly participated in unlawful behavior is it likely to…
Re: Apple decided not to roll out Siri in EU after denied request for exemption
#223Earlier quoted context omitted.
Privacy laws are not complex, they only become complex if your goal is to actually skirt them. Tax laws are also quite easy, tax lawyers are only needed if you want to NOT pay what the country you're operating in is owed.
Respectfully, it sounds like you just haven't dealt with any significant tax or regulatory tasks. There's entire industries of experts who work on these tasks, and they don't just work for people trying to skirt the rules. I've hired people for both tasks and the reason was specifically to comply.
NIST, MS, and the security community all recommend against forcing people to change their passwords on fixed intervals. They should only be changed when there is an indication they have been compromised.
PCI requirements demand mandatory 30 day rotation intervals on user passwords for users with administrative privileges, IORC. Something like that.
They haven’t kept up. So until they change the rules you can either be PCI compliant or implement the current best practice. Not both.
Re: Apple decided not to roll out Siri in EU after denied request for exemption
#224Earlier quoted context omitted.
Google eng mgr here. I've worked on a few projects related to compliance with various government policies. This isn't "assign a two-pizza team to it, will be done in a quarter"; these types of compliance efforts can mean completely redoing multiple core systems to handle privacy, wipeout, audit, reporting, per-location policies, etc etc. These efforts can involve hundreds to thousands of people for multiple years. Su…
Okay? I don’t see the problem, these requirements are known from the beginning so if complying wasn’t planned and requires re-architecturing the software to make it happens that’s on the engineering org not on the EU regulator. Unless I’m missing something?
I suppose if you think these rules are reasonable, you’d be happy to not have this functionality. The rest of the world will be happy to not allow third parties access to our data.
As a small developer, the cost to support something like this would be so overwhelming I wouldn’t consider supporting the EU officially.
Re: Apple decided not to roll out Siri in EU after denied request for exemption
#225Apple must know that they have customers in EU countries..?
Re: Apple decided not to roll out Siri in EU after denied request for exemption
#226Re: Apple decided not to roll out Siri in EU after denied request for exemption
#227Apple said "hey, can we not comply with the law", the EU said no, so it didn't launch. Seems pretty straightforward to me. I can see why Apple might want to request an 18 month exemption, there's clearly extra work required to comply with EU regulations. But on the other hand it also feels like a straightforward play for consumer sympathy: let them get used to using it every day for 18 months, then pressure the EU to…
Re: Apple decided not to roll out Siri in EU after denied request for exemption
#228Of all the crimes Big Tech is committing against humanity, Apple's attempt to safeguard user privacy is the one the EU cannot abide?
Re: Apple decided not to roll out Siri in EU after denied request for exemption
#229Earlier quoted context omitted.
I am perfectly ok with EU having different rules of their own but they also can't be upset when features aren't offered there. That is the trade-off they have chosen and I am ok with it.
People in EU are upset that Apple is saying that EU would not let them build it, not that it's not offered there.
Re: Apple decided not to roll out Siri in EU after denied request for exemption
#230Earlier quoted context omitted.
Personally, I wouldn't want Apple to comply with this EU law and I hope that more companies refuse to release features with onerous requirements. Opening up all access to control the phone to some random app the consumer installed seems super dangerous.
Don’t install the app then. Consumer protection at some level means the consumer needs to be informed. I’d rather have a choice than just chow down on whatever the gatekeepers call food.