The way this came into existence is what scares me.
Also, Mr. Mactaggart, what a guy!
171–179 of 179 posts
The way this came into existence is what scares me.
Also, Mr. Mactaggart, what a guy!
Counting an IP address as PII is kind of crappy, you need a court order to turn an IP alone into PII. Operators should be free to log traffic at the network level, PII should only come into play once you're asking someone to provide personal information.
Yeah it is odd. You decided to hit my server, I should be able to record the occurance. How am I suppposed to deflect DoS attacts if I can't maintain a list of nefarious IPs. I know that's a fairly low tech attack, but they still happen constantly. Is Fail2Ban no longer compliant? I wouldn't be surprised if some policies pertaining to record keeping in some sectors contradict that requirement as well.
Earlier quoted context omitted.
A reversable hash "could reasonably be linked" with the plaintext. You can't get around the law on technicalities. Judges are not computers.
> You can't get around the law on technicalities. Simply out of curiosity, what do you mean by that? All my life experience and knowledge tells me it's exactly how you get around the law, unless court has its own agenda or strong bias.
The way this came into existence is what scares me.
The "if they knew what we know" part or the you can (kind of) buy policy part? If the latter is shocking to you, I have some very bad news for you. (The process would have been more difficult and more expensive if the law wasn't genuinely benefiting the people, but still possible.) Also, Mr. Mactaggart, what a guy!
There are limits on campaign contributions, perhaps there should be limits on individual contributions for these signature drives, which are essentially just large marketing efforts.
And just because this guy got x number of signatures, I don't see why he should now have the power to make compromise deals with the government.
This isn't my area of expertise so I may be missing something here.
Earlier quoted context omitted.
Once again your only world view is "oh these poor devs" and "oh these poor companies". > the tech behemoths you complain about to get a free competitive advantage Where would that "free" competitive advantage come from? A "behemoth" would have a petabyte of data coming in daily, spread over hundreds of systems and dozens of applications (both internal and external). If anything, startups benefit: they have less data…
I'm rather confused as to why you're harping on about whether or not developers "deserve sympathy". I'd be making the same points about pretty much any business regulation - that they impose costs, and that we need to be cognizant of them in order to make sure it's a net positive. If the costs outweigh the benefits, then the regulation is a good thing. If they don't, but you advocate for it anyways because don't care…
I see one clear net benefit: without regulation companies had zero care for private data. Well, time to suffer for it. I won't shed a tear.
Earlier quoted context omitted.
> how these data protection laws are implemented in general and I wish the discussion would be about that instead Let’s do that, shall we? Before GDPR there were laws in each European country protecting private data (GDPR is basically Sweden’s data protection law in that regard). Not a single “poor company that will need comply” gave a damn. Then GDPR was introduced, discussed, amended. Quite publicly. Not one of the…
As a top engineer of a EU headquartered company, I can be one instance of saying this was not true of us. We started our preparations almost a year and a half in advance of the March 2018 deadline. Once we engineers and our GC were done interpreting the extent of what we believed we needed to do and the resources to do it, we were basically ordered by the CEO to do as little as possible as late as possible, automate…
It's true, businesses (or people who run them) will in the end judge the direction where the company will go, and their judgment is often worse that that of developers.
So yes, I would replace "devs" etc. with just "companies" in my comment.
Great article, until the end. Who uses PII in test data derived from real customers? That's just an absurd practice to begin with, and no one who takes security seriously would even consider doing this.
Earlier quoted context omitted.
As a top engineer of a EU headquartered company, I can be one instance of saying this was not true of us. We started our preparations almost a year and a half in advance of the March 2018 deadline. Once we engineers and our GC were done interpreting the extent of what we believed we needed to do and the resources to do it, we were basically ordered by the CEO to do as little as possible as late as possible, automate…
Yes, true. In the end it comes to business decision. My focus on devs is mostly because it's devs who comment and complain on HN, so my comments are mostly geared towards them. It's true, businesses (or people who run them) will in the end judge the direction where the company will go, and their judgment is often worse that that of developers. So yes, I would replace "devs" etc. with just "companies" in my comment.
However, the better integrated and communicated the company's goals and rationales are, the more aligned the judgements become.
Earlier quoted context omitted.
Once again your only world view is "oh these poor devs" and "oh these poor companies". > the tech behemoths you complain about to get a free competitive advantage Where would that "free" competitive advantage come from? A "behemoth" would have a petabyte of data coming in daily, spread over hundreds of systems and dozens of applications (both internal and external). If anything, startups benefit: they have less data…
I'm rather confused as to why you're harping on about whether or not developers "deserve sympathy". I'd be making the same points about pretty much any business regulation - that they impose costs, and that we need to be cognizant of them in order to make sure it's a net positive. If the costs outweigh the benefits, then the regulation is a good thing. If they don't, but you advocate for it anyways because don't care…
Let's not gloss over the fact that the specific class of people who are "hurt" are the ones causing the hurt. If they only collected data they needed and secured the data they did collect, the regulation wouldn't be needed in the first place.
It's not mean-spirited to expect people who have widely profited from collecting bulk data to foot the bill for securing that data.