Live data from Hacker News

Smartphone makers don't bother to comply with EU repairability requirements

theregister.com

61–70 of 202 posts

Re: Smartphone makers don't bother to comply with EU repairability requirements

#61
post #37

Earlier quoted context omitted.

GDPR is reasonable, maybe too weak regulation of big businesses with lots of data. The problem is that it applies to small organisations, even non-profits, that do not trade that information which is proportionately a much bigger burden. Real examples of organisations I have come across who have to comply with GDPR include a local community theatre, a parish church etc. They are keep fairly simple information, and no…

> Real examples of organisations I have come across who have to comply with GDPR include a local community theatre, a parish church etc. They are keep fairly simple information, and not exchanging it with anyone, but they still have to put effort into ensuring compliance. Yeah, and that is precisely where you want something like the GDPR to be as well! Large corporations are one thing, they have compliance department…

Well, wait until you are at the receiving end. It can get nasty pretty quickly.

What does each one of your systems store exactly? Do they allow configuration of reasonable data retention policies for PII? What do your systems log? How do you make sure that only the minimum amount of PII (including user IP addresses) is logged and that the covered logs are destroyed at the end of a reasonable retention period?

How do you handle Data Subject Access Requests? Can you compile all the data related to that person in a reasonable time to send it to them?

How do you handle deletion requests? Can you name all the data storage that is affected if a deletion request comes in? Are your systems technically capable of deleting the data? What data is exempt (e.g. billing addresses can't just be deleted before the mandated archival period is over)? Do you maintain backups? Then how do you make sure that data covered by a deletion request is destroyed and stays gone even in the event of a backup recovery?

Nobody who wants to bootstrap a business wants to deal with any of this. It's an enormous time sink.

Re: Smartphone makers don't bother to comply with EU repairability requirements

#62
post #55

Earlier quoted context omitted.

> Ironically the fact that the howls need to come from the other side of the Atlantic, rather than having any domestically, should tell anyone all they need to know about the situation. Europeans by and large don't care about American companies these days. They use American software products because frequently there are no alternatives. And most of the news about them are negative.

>They use American software products because frequently there are no alternatives Hint hint

Hint hint to what?

South Korea is a very dynamic, tech heavy country and it hasn't managed to push any software product as a market leader.

The EU is bigger, but it's fractured, so functionally it's basically 2-3x South Korea in terms of "software power". And that's not enough to compete with the much larger US juggernaut. Only China has managed to hold its own by simply banning US software all together.

I'm actually all in favor of the EU banning all American software. Fairly sure that after a huge initial tumble a healthy EU software market would thrive.

Edit: I need to brace myself, the Americans are waking up :-)))

Re: Smartphone makers don't bother to comply with EU repairability requirements

#63
post #61

Earlier quoted context omitted.

> Real examples of organisations I have come across who have to comply with GDPR include a local community theatre, a parish church etc. They are keep fairly simple information, and not exchanging it with anyone, but they still have to put effort into ensuring compliance. Yeah, and that is precisely where you want something like the GDPR to be as well! Large corporations are one thing, they have compliance department…

Well, wait until you are at the receiving end. It can get nasty pretty quickly. What does each one of your systems store exactly? Do they allow configuration of reasonable data retention policies for PII? What do your systems log? How do you make sure that only the minimum amount of PII (including user IP addresses) is logged and that the covered logs are destroyed at the end of a reasonable retention period? How do…

> Nobody who wants to bootstrap a business wants to deal with any of this. It's an enormous time sink.

Indeed but it forces you to answer these questions and to think about them during the development process as well, maybe even enough to write decent unit and regression tests for anything authentication/authorization related before some security "researcher" siccs Claude Code or whatever on your API and pwns it.

Re: Smartphone makers don't bother to comply with EU repairability requirements

#64

As its the EU and regulation, its time to trott out your hobby horse. So let me trot out mine: regulation is good so long as it is backed up by even handed, robust, transparent, quick and effective sanctions. the Online safety act is a good example of a bad law, which is enforced badly. The first big test (X producing industrial quantities of minors engaging in sexual activity) was failed. Had a small company produce…

> An example of good enforcement is the UK's scores on the doors, where the public can see what the standard is, and if they fall below a certain level, the food place is fined/shutdown/other until it improves. > Another good example is NCAP ratings. Worth noting that NCAP and Scores on the Doors are not regulators. NCAP is an industry body; SotDs is run by TripAdvisor.

I think the food hygiene ratings are a regulatory thing - https://ratings.food.gov.uk - places are required to show their stickers by law.

I'm not sure how the Scores on the Doors website, which is at least related to TripAdvisor, fits into all of this...

Re: Smartphone makers don't bother to comply with EU repairability requirements

#65
post #37
post #33

Earlier quoted context omitted.

I really don't get the big deal with GDRP. Consider what you are storing and why you are storing. Decide if those things align. If they do not, well don't implement that in first place. And I suppose LLMs are perfect for the boiler plate documentation so not big effort there either. Somethings are big more challenging like getting the data for customer when asking or deleting it when reasonable. But as user I also li…

GDPR is reasonable, maybe too weak regulation of big businesses with lots of data. The problem is that it applies to small organisations, even non-profits, that do not trade that information which is proportionately a much bigger burden. Real examples of organisations I have come across who have to comply with GDPR include a local community theatre, a parish church etc. They are keep fairly simple information, and no…

> The problem is that it applies to small organisations, even non-profits, that do not trade that information which is proportionately a much bigger burden.

Eh?

Collect only the personal data you need (with permission) and keep it secure. Such a basic responsibility to your members privacy and safety is hardly a burden.

Re: Smartphone makers don't bother to comply with EU repairability requirements

#66
I'm wondering whether it is now time for regulators to pressure mobile phone companies to install longer life batteries. There is not really an incentive to prolong device life for manufacturers and when I look at recent progress on the car industry and utility battery side there is imho. potential.

Re: Smartphone makers don't bother to comply with EU repairability requirements

#67
post #61

Earlier quoted context omitted.

> Real examples of organisations I have come across who have to comply with GDPR include a local community theatre, a parish church etc. They are keep fairly simple information, and not exchanging it with anyone, but they still have to put effort into ensuring compliance. Yeah, and that is precisely where you want something like the GDPR to be as well! Large corporations are one thing, they have compliance department…

Well, wait until you are at the receiving end. It can get nasty pretty quickly. What does each one of your systems store exactly? Do they allow configuration of reasonable data retention policies for PII? What do your systems log? How do you make sure that only the minimum amount of PII (including user IP addresses) is logged and that the covered logs are destroyed at the end of a reasonable retention period? How do…

> Nobody who wants to bootstrap a business wants to deal with any of this. It's an enormous time sink

I doubt anybody wants to deal with fire safety inspections either.

Though I'm quite sure you will change your mind when your personal data gets hacked or your office burns down.

Re: Smartphone makers don't bother to comply with EU repairability requirements

#68

Earlier quoted context omitted.

> An example of good enforcement is the UK's scores on the doors, where the public can see what the standard is, and if they fall below a certain level, the food place is fined/shutdown/other until it improves. > Another good example is NCAP ratings. Worth noting that NCAP and Scores on the Doors are not regulators. NCAP is an industry body; SotDs is run by TripAdvisor.

I think the food hygiene ratings are a regulatory thing - https://ratings.food.gov.uk - places are required to show their stickers by law. I'm not sure how the Scores on the Doors website, which is at least related to TripAdvisor, fits into all of this...

It shows the ratings that are provided by food standards inspectors.

Re: Smartphone makers don't bother to comply with EU repairability requirements

#69

I'm wondering whether it is now time for regulators to pressure mobile phone companies to install longer life batteries. There is not really an incentive to prolong device life for manufacturers and when I look at recent progress on the car industry and utility battery side there is imho. potential.

Batteries always have a limited lifetime.

"back in the day" we had waterproof phones with user replacable batteries, you could just buy another battery and replace it yourself. I have no idea why we can't do this now.

Re: Smartphone makers don't bother to comply with EU repairability requirements

#70

I'm wondering whether it is now time for regulators to pressure mobile phone companies to install longer life batteries. There is not really an incentive to prolong device life for manufacturers and when I look at recent progress on the car industry and utility battery side there is imho. potential.

Batteries always have a limited lifetime. "back in the day" we had waterproof phones with user replacable batteries, you could just buy another battery and replace it yourself. I have no idea why we can't do this now.

Plain old, madagascar vanilla artificial obsolescence.
Post reply on HN