Live data from Hacker News

How the UK's online safety bill threatens Matrix

matrix.org

161–165 of 165 posts

Re: How the UK's online safety bill threatens Matrix

#161

Earlier quoted context omitted.

Commenting to follow up later. I'm really interested in the use case. The only thing I can think of would be a website similar to mid-2000s youtube to mp3 converters.

Alas they are all behind ssl authentication so you wouldn't be able to access them, but the stuff I currently have open includes a switch port mapper (every 20 minutes all my switches are scanned and reports generated on what's plugged in where), a firewall config interpretor (a list of current port forwards is generated), and a logging server showing me what But if you want an example of a fully featured public site…

> Under GDPR, a website doesn't need to ask for permission to have necessary cookies which enable core functionality such as security, network management, and accessibility.

I am not convinced this is true. See: https://law.stackexchange.com/a/32157

Also note that HN is likely in violation of this since there is no "Remember Me" checkbox when logging in. There is no indication that logins will be persistent.

Re: How the UK's online safety bill threatens Matrix

#162

Earlier quoted context omitted.

The UK has never not been eager to censor to a sometimes comical extent. Just look at the "Video Nasty" moral panic, or the hilarious dubbing of Northern Irish people on television. https://en.wikipedia.org/wiki/Video_nasty https://en.wikipedia.org/wiki/1988%E2%80%931994_British_broa...

Now that you mention Ireland, it occurs to me the UK plays second fiddle compared to its former colony. After achieving independence, the Irish Free State and its successor, the Republic of Ireland were dominated by right-wing, conservative, Papist and authoritarian nationalists. Modern art and music – particularly “evil” jazz – were all banned. Our best writers had to leave the country. The writers that didn’t leave…

I have a tendency to focus on the good things in life and try not dwell on the negative. As a result, I have nostalgic memories of the nineties (formative era for music) but forget how bad things actually were in the “good old days”. A more important example I forgot to mention in my comment above was the censorship of information relating to contraception (“family planning”), abortion and anything else relating to reproductive rights.

Until the late nineties, it was illegal to provide any information about abortion services – regardless of circumstances or if the services were in other countries. Newspapers and periodicals from the UK that contained listings or advertisings for abortion services had the relevant pages removed before they could be sold by Irish newsagents. The Society for the Protection of Unborn Children successfully won cases against family planning agencies (that went all the way up to the European Court of Human Rights) and the Union of Students of Ireland for providing information about clinics in the UK that provided abortion services.

Re: How the UK's online safety bill threatens Matrix

#163

Earlier quoted context omitted.

What was particullary easy implementing GDPR for you? I found some areas particullary hard. Legitimate interest is a minefild and mostly can't be used, except e.g. delivery addresses. Finding GDPR compliant companies - with the US out of question - was also hard. Tracking and deleting data on request when storing in dozens of systems was hard - even returning all the data stored in dozens of external SaaS companies w…

> What was particullary easy implementing GDPR for you? Deleting people's private data upon request, namely when they click a button -- in my case (unlike yours) there's not many places to delete the data from. The most challenging thing is instead writing a DPA, and wondering what to write about inspections and auditing, in a remote only company with servers in the cloud (any thoughts about that?)

I think auditing is an unsolved problem for now, I haven't heard of any implementation that works.

I would assume special companies will arise that do the auditing for you - and that work with AWS and GCP for you.

Re: How the UK's online safety bill threatens Matrix

#164

Earlier quoted context omitted.

> What was particullary easy implementing GDPR for you? Deleting people's private data upon request, namely when they click a button -- in my case (unlike yours) there's not many places to delete the data from. The most challenging thing is instead writing a DPA, and wondering what to write about inspections and auditing, in a remote only company with servers in the cloud (any thoughts about that?)

I think auditing is an unsolved problem for now, I haven't heard of any implementation that works. I would assume special companies will arise that do the auditing for you - and that work with AWS and GCP for you.

> special companies will arise that do the auditing for you

I think so too -- I had a look at Google's DPA and it seemed to me that when one agrees to Google's DPA, one agrees to trust some Google approved companies to do the auditing for everyone (for all Google cloud customers). Maybe there's not any other way to make it work (it'd be crazy with random people in their datacenters "auditing" things)

Re: How the UK's online safety bill threatens Matrix

#165

Earlier quoted context omitted.

As both a private citizen, and one who implements it, I hate it. It’s increased regulation around a subject that I was not doing in the first place (I don’t care what you’re doing online, never tracked, etc) that only increased the cost of business. We need more competition, not less.

> It’s increased regulation around a subject that I was not doing in the first place Maybe you were handling personal data correctly. Very many were not (witness numerous data breaches and private data exploited that was held for no reason). Therefore regulation was needed. > We need more competition Competition is good. A race to the bottom is not.

Where does relaxed regulation and the reintroduction of morality into business mean a race to the bottom?

It also could’ve been implemented in such a way where there were no required new positions and the gov spent tax dollars to write a greatly detailed dummies guide to GDPR, how to implement it, etc so that smaller companies without the resources would have just as much of an advantage.

Post reply on HN