Live data from Hacker News

CCPA Will Hit Dev Teams Harder Than GDPR

tonic.ai

161–170 of 179 posts

Re: CCPA Will Hit Dev Teams Harder Than GDPR

#161
post #147

Earlier quoted context omitted.

It's not possible to one-way hash a 32-bit IP address. A hash of a 32-bit value can always be reversed because the search space is so small.

Store only the first 16 bits of the hash maybe?

Google Analytics is supposedly GDPR compliant when they store only the first 3 octets, un-hashed.

However I'm not sure myself it makes sense. Some people will be identified by just a partial IP or even a partial hash.

Re: CCPA Will Hit Dev Teams Harder Than GDPR

#162

Earlier quoted context omitted.

You need to talk about both costs and benefits when discussing public policy. Otherwise, you end up with a ton of terrible policy that looks good due to an obvious tangible benefit, but nets out to more harm than good. For example, minimum bedroom sizes for rental units. Seems nice to have enough space to live comfortably, right? End result though is the $20M apartment complex has 35 units instead of 40, and is only…

Let’s look at the cost, shall we? Invasive and pervasive surveillance. Private and sensitive data sold wholesale not even to the highest bidder, but to anyone. Hell, when news about NSA surveillance broke, it was a huge scandal that was the focus of attention of all media for more than a year. Now Facebook alone is reported to have the same level of maliciousness and willfull ignorance on a monthly basis, and it’s bu…

"these costs fall on people who I feel deserve it" isn't a good reason to completely ignore the size of the costs being imposed. Especially since these costs are sublinear with respect to organization size, causing the tech behemoths you complain about to get a free competitive advantage against upstarts threatening their business model.

Re: CCPA Will Hit Dev Teams Harder Than GDPR

#163
post #89

Earlier quoted context omitted.

"Process PII" is incredibly vague. You could define that in a hilarious amount of ways with the amount of complexity we introduce to our software products, especially with code we don't even write ourselves that widens your security surface. This is especially true if you use a service that allows others to inject code into your code base. If NPM has a security failure that leads to a breach at a company, who is at f…

>> You could define that in a hilarious amount of ways with the amount of complexity we introduce to our software products, especially with code we don't even write ourselves that widens your security surface. You could define in a hilarious amount of ways in which your chef can pee in the broth you ordered in a local diner. But it generally doesn't happen, does it?

[deleted]

Re: CCPA Will Hit Dev Teams Harder Than GDPR

#164

Earlier quoted context omitted.

Let’s look at the cost, shall we? Invasive and pervasive surveillance. Private and sensitive data sold wholesale not even to the highest bidder, but to anyone. Hell, when news about NSA surveillance broke, it was a huge scandal that was the focus of attention of all media for more than a year. Now Facebook alone is reported to have the same level of maliciousness and willfull ignorance on a monthly basis, and it’s bu…

"these costs fall on people who I feel deserve it" isn't a good reason to completely ignore the size of the costs being imposed. Especially since these costs are sublinear with respect to organization size, causing the tech behemoths you complain about to get a free competitive advantage against upstarts threatening their business model.

Once again your only world view is "oh these poor devs" and "oh these poor companies".

> the tech behemoths you complain about to get a free competitive advantage

Where would that "free" competitive advantage come from? A "behemoth" would have a petabyte of data coming in daily, spread over hundreds of systems and dozens of applications (both internal and external).

If anything, startups benefit: they have less data and systems. And, once again, if the devs do what they had to do in the first place, there's not that much of an additional burden.

These "poor" devs and companies had literally decades[1] to get their shit together. Now they want sympathy? What did they do to deserve sympathy?

[1] https://news.ycombinator.com/item?id=19052563

Re: CCPA Will Hit Dev Teams Harder Than GDPR

#165

Earlier quoted context omitted.

"these costs fall on people who I feel deserve it" isn't a good reason to completely ignore the size of the costs being imposed. Especially since these costs are sublinear with respect to organization size, causing the tech behemoths you complain about to get a free competitive advantage against upstarts threatening their business model.

Once again your only world view is "oh these poor devs" and "oh these poor companies". > the tech behemoths you complain about to get a free competitive advantage Where would that "free" competitive advantage come from? A "behemoth" would have a petabyte of data coming in daily, spread over hundreds of systems and dozens of applications (both internal and external). If anything, startups benefit: they have less data…

I'm rather confused as to why you're harping on about whether or not developers "deserve sympathy". I'd be making the same points about pretty much any business regulation - that they impose costs, and that we need to be cognizant of them in order to make sure it's a net positive. If the costs outweigh the benefits, then the regulation is a good thing. If they don't, but you advocate for it anyways because don't care about hurting a specific class of people that don't "deserve sympathy", that makes you quite a mean-spirited person.

>If anything, startups benefit: they have less data and systems.

It's not about the absolute costs of regulatory compliance, which are relatively small. It's about the relative costs of compliance compared to the economic value of regulated activity. Google has roughly a million times more revenue than a ten-person start-up will. Privacy compliance is not a million times more expensive for Google than it is for the start-up. If it costs a startup a day of engineering effort to comply, and it costs Google ten million dollars, this is a relative business advantage for Google.

This is a pretty general pattern; established businesses get a competitive advantage from regulation, since it prevents competition from arising. If it costs $400 to get your setup inspected before you can sell lemonade that you make, this helps Nestle sell more bottled lemonade at the cost of your kids' lemonade stand.

Re: CCPA Will Hit Dev Teams Harder Than GDPR

#167
post #58

Earlier quoted context omitted.

Could you salt and perform a one-way hash on the IP address and store that? It would alleviate a large amount of leakage issues while still giving you uniqueness counts.

IPv4 addresses are only 32 bits, which makes building rainbow tables almost trivial.

Not if you salt them.

Re: CCPA Will Hit Dev Teams Harder Than GDPR

#168
post #2

> if a data breach occurs, the law permits consumers to recover up to $750 per incident This is great!

Simple, you just add this to clickwrap agreement: The Parties mutually agree that any and all disputes arising from or relating to this Agreement, including the interpretation or application of this Agreement will be submitted exclusively to final and binding arbitration pursuant to the Federal Arbitration Act. The arbitration will be conducted the state of Delaware or such other location as the Parties may agree, by…

I'd love to see them try this in the EU.

Re: CCPA Will Hit Dev Teams Harder Than GDPR

#169

Going into effect in a year? Seems like a business opportunity. Someone let me pay them $X and review my systems every so often and give me a seal saying I'm compliant with all these laws, and include some insurance up to $Y. Especially given the selective enforcement, there's money to be made from the chill alone. Compliance audit companies can probably just roll this into their package. Also, I'm a bit annoyed at l…

> how these data protection laws are implemented in general and I wish the discussion would be about that instead Let’s do that, shall we? Before GDPR there were laws in each European country protecting private data (GDPR is basically Sweden’s data protection law in that regard). Not a single “poor company that will need comply” gave a damn. Then GDPR was introduced, discussed, amended. Quite publicly. Not one of the…

As a top engineer of a EU headquartered company, I can be one instance of saying this was not true of us. We started our preparations almost a year and a half in advance of the March 2018 deadline. Once we engineers and our GC were done interpreting the extent of what we believed we needed to do and the resources to do it, we were basically ordered by the CEO to do as little as possible as late as possible, automate as little as possible, and just wait to see if anything came of it. I left the company a few months after GDPR-day so cannot say how it worked out, but it was the CEO’s company and his choice to do it in a way that it then became my responsibility to implement.

Compliance/legal is a company risk and as I indicated in the challenger article here a few days ago, as an engineer I can advise on hat the risks are and the potential consequences of bad outcomes, as well as the costs to reduce them. The business decides what level of risk to take. I personally would have preferred a robust response to GDPR and thorough internal procedures, but it was not my call to make.

Of course, I personally believe that we humans should own our data and digital footprints, so I agree with a lot of the concepts behind GDPR and CCPA even if I do not agree with all and as an engineer may think some are ... silly/overzealous/misguided or what have you. Case in point: the IP tracking discussion above. If I hit your network, thats on me (barring externalities or bad actors, etc.). Retention periods and use definitions are fine, but a requirement to treat it as PII or other super sensitive data seems a bit much to the engineer in me.

Re: CCPA Will Hit Dev Teams Harder Than GDPR

#170
post #2

> if a data breach occurs, the law permits consumers to recover up to $750 per incident This is great!

Simple, you just add this to clickwrap agreement: The Parties mutually agree that any and all disputes arising from or relating to this Agreement, including the interpretation or application of this Agreement will be submitted exclusively to final and binding arbitration pursuant to the Federal Arbitration Act. The arbitration will be conducted the state of Delaware or such other location as the Parties may agree, by…

Section 1798.192 covers that:

    Any provision of a contract or agreement of any kind that purports to waive or limit in any way a consumer’s rights under this title, including, but not limited to, any right to a remedy or means of enforcement, shall be deemed contrary to public policy and shall be void and unenforceable
Edit: I suppose that I should say that I'm not a lawyer. This isn't legal advice. And it's completely possible that I have misunderstood this section of the law.
Post reply on HN