Live data from Hacker News

CCPA Will Hit Dev Teams Harder Than GDPR

tonic.ai

171–179 of 179 posts

Re: CCPA Will Hit Dev Teams Harder Than GDPR

#171

The way this came into existence is what scares me.

The "if they knew what we know" part or the you can (kind of) buy policy part? If the latter is shocking to you, I have some very bad news for you. (The process would have been more difficult and more expensive if the law wasn't genuinely benefiting the people, but still possible.)

Also, Mr. Mactaggart, what a guy!

Re: CCPA Will Hit Dev Teams Harder Than GDPR

#172
post #88

Counting an IP address as PII is kind of crappy, you need a court order to turn an IP alone into PII. Operators should be free to log traffic at the network level, PII should only come into play once you're asking someone to provide personal information.

Yeah it is odd. You decided to hit my server, I should be able to record the occurance. How am I suppposed to deflect DoS attacts if I can't maintain a list of nefarious IPs. I know that's a fairly low tech attack, but they still happen constantly. Is Fail2Ban no longer compliant? I wouldn't be surprised if some policies pertaining to record keeping in some sectors contradict that requirement as well.

You absolutely can still maintain that list under CCPA. What you can't do is sell your list of nefarious IP addresses. You could sell (or buy) the service of checking various IP addresses against a proprietary list of nefarious IP addresses.

Re: CCPA Will Hit Dev Teams Harder Than GDPR

#173

Earlier quoted context omitted.

A reversable hash "could reasonably be linked" with the plaintext. You can't get around the law on technicalities. Judges are not computers.

> You can't get around the law on technicalities. Simply out of curiosity, what do you mean by that? All my life experience and knowledge tells me it's exactly how you get around the law, unless court has its own agenda or strong bias.

https://en.wikipedia.org/wiki/I_know_it_when_I_see_it

Re: CCPA Will Hit Dev Teams Harder Than GDPR

#174

The way this came into existence is what scares me.

The "if they knew what we know" part or the you can (kind of) buy policy part? If the latter is shocking to you, I have some very bad news for you. (The process would have been more difficult and more expensive if the law wasn't genuinely benefiting the people, but still possible.) Also, Mr. Mactaggart, what a guy!

The part that bothers me is how hastily the "compromise" was drafted, without any public debate. I don't like the idea of an individual holding the legislative process hostage.

There are limits on campaign contributions, perhaps there should be limits on individual contributions for these signature drives, which are essentially just large marketing efforts.

And just because this guy got x number of signatures, I don't see why he should now have the power to make compromise deals with the government.

This isn't my area of expertise so I may be missing something here.

Re: CCPA Will Hit Dev Teams Harder Than GDPR

#175

Earlier quoted context omitted.

Once again your only world view is "oh these poor devs" and "oh these poor companies". > the tech behemoths you complain about to get a free competitive advantage Where would that "free" competitive advantage come from? A "behemoth" would have a petabyte of data coming in daily, spread over hundreds of systems and dozens of applications (both internal and external). If anything, startups benefit: they have less data…

I'm rather confused as to why you're harping on about whether or not developers "deserve sympathy". I'd be making the same points about pretty much any business regulation - that they impose costs, and that we need to be cognizant of them in order to make sure it's a net positive. If the costs outweigh the benefits, then the regulation is a good thing. If they don't, but you advocate for it anyways because don't care…

Once again, I've yet to see a compelling study addressing any of the emotional points about economic burden you make.

I see one clear net benefit: without regulation companies had zero care for private data. Well, time to suffer for it. I won't shed a tear.

Re: CCPA Will Hit Dev Teams Harder Than GDPR

#176

Earlier quoted context omitted.

> how these data protection laws are implemented in general and I wish the discussion would be about that instead Let’s do that, shall we? Before GDPR there were laws in each European country protecting private data (GDPR is basically Sweden’s data protection law in that regard). Not a single “poor company that will need comply” gave a damn. Then GDPR was introduced, discussed, amended. Quite publicly. Not one of the…

As a top engineer of a EU headquartered company, I can be one instance of saying this was not true of us. We started our preparations almost a year and a half in advance of the March 2018 deadline. Once we engineers and our GC were done interpreting the extent of what we believed we needed to do and the resources to do it, we were basically ordered by the CEO to do as little as possible as late as possible, automate…

Yes, true. In the end it comes to business decision. My focus on devs is mostly because it's devs who comment and complain on HN, so my comments are mostly geared towards them.

It's true, businesses (or people who run them) will in the end judge the direction where the company will go, and their judgment is often worse that that of developers.

So yes, I would replace "devs" etc. with just "companies" in my comment.

Re: CCPA Will Hit Dev Teams Harder Than GDPR

#177
post #4

Great article, until the end. Who uses PII in test data derived from real customers? That's just an absurd practice to begin with, and no one who takes security seriously would even consider doing this.

A huge part of the problem is that many companies don't take security seriously.

Re: CCPA Will Hit Dev Teams Harder Than GDPR

#178

Earlier quoted context omitted.

As a top engineer of a EU headquartered company, I can be one instance of saying this was not true of us. We started our preparations almost a year and a half in advance of the March 2018 deadline. Once we engineers and our GC were done interpreting the extent of what we believed we needed to do and the resources to do it, we were basically ordered by the CEO to do as little as possible as late as possible, automate…

Yes, true. In the end it comes to business decision. My focus on devs is mostly because it's devs who comment and complain on HN, so my comments are mostly geared towards them. It's true, businesses (or people who run them) will in the end judge the direction where the company will go, and their judgment is often worse that that of developers. So yes, I would replace "devs" etc. with just "companies" in my comment.

I wouldn't say "worse" judgement in general. Just "different" in general. I have had both "worse" and "better" cases.

However, the better integrated and communicated the company's goals and rationales are, the more aligned the judgements become.

Re: CCPA Will Hit Dev Teams Harder Than GDPR

#179

Earlier quoted context omitted.

Once again your only world view is "oh these poor devs" and "oh these poor companies". > the tech behemoths you complain about to get a free competitive advantage Where would that "free" competitive advantage come from? A "behemoth" would have a petabyte of data coming in daily, spread over hundreds of systems and dozens of applications (both internal and external). If anything, startups benefit: they have less data…

I'm rather confused as to why you're harping on about whether or not developers "deserve sympathy". I'd be making the same points about pretty much any business regulation - that they impose costs, and that we need to be cognizant of them in order to make sure it's a net positive. If the costs outweigh the benefits, then the regulation is a good thing. If they don't, but you advocate for it anyways because don't care…

> If they don't, but you advocate for it anyways because don't care about hurting a specific class of people that don't "deserve sympathy", that makes you quite a mean-spirited person.

Let's not gloss over the fact that the specific class of people who are "hurt" are the ones causing the hurt. If they only collected data they needed and secured the data they did collect, the regulation wouldn't be needed in the first place.

It's not mean-spirited to expect people who have widely profited from collecting bulk data to foot the bill for securing that data.

Post reply on HN