Live data from Hacker News

Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

brave.com

181–190 of 238 posts

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#181

Earlier quoted context omitted.

What earthly consumer is going to go through these steps? I have requested the removal of my personal data from multiple business, and I can assure you I'm quite earth-bound. Copy-pasting a template and filling in my name and account ID is not that hard.

I'm going to go out on a limb and guess that you are a fairly technical user. My snarkiness in the previous reply was excessive, but reflected my frustration with being told that something is simple that is actually a multi-step process with questions that are not easy to find the answer to. I guess the problem with email for this process is that you have a number of questions, all of which may not have an easy answe…

I'm going to guess you're a technical user :) my parents would never think to search for standardized or GDPR-specific email addresses. What they did was find some generic way to contact the company (phone number, possibly Facebook or email) and ask them "where should I send a request for you to delete my data?"

Regarding the content, they would find some template they can mostly understand, then change/add a paragraph to include whatever specifics they need.

As for verification of identify, they would not even think much about it. They would sign with their name, and of course send from their email. The company would have to reply back to ask for whatever they need to verify it properly.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#182
post #30

The practical effect of GDPR seems to me that I have to click away about half a dozen consent popups every day. Sometimes a cookie warning in addition to that. If I use Private Browsing (to protect my privacy) I am punished with more popups. If I open a website within a browser shell on mobile that doesn't have my cookies (some kind of webview of an app), I am punished with more popups. Am I expected to look at every…

> These are very real, very concrete negative effects of GDPR Your annoyance is misplaced. Don't be annoyed at GDPR: be annoyed at all the companies who have spent the last decades building an entire web-infrastructure with zero respect for user privacy. We built massive amounts of technology infrastructure that just assumed that privacy and tracking wasn't an issue. Why do these websites need all these cookies in th…

The cost of determining the tracking behavior of every dependency of every part of your web site is prohibitive. Can you be sure that every hosted font and JavaScript framework you use is hosted on a server that isn't, say, logging IP addresses? Why bother? It's much easier to just throw up a warning popup, which users universally dismiss.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#183
post #30

The practical effect of GDPR seems to me that I have to click away about half a dozen consent popups every day. Sometimes a cookie warning in addition to that. If I use Private Browsing (to protect my privacy) I am punished with more popups. If I open a website within a browser shell on mobile that doesn't have my cookies (some kind of webview of an app), I am punished with more popups. Am I expected to look at every…

> These are very real, very concrete negative effects of GDPR Your annoyance is misplaced. Don't be annoyed at GDPR: be annoyed at all the companies who have spent the last decades building an entire web-infrastructure with zero respect for user privacy. We built massive amounts of technology infrastructure that just assumed that privacy and tracking wasn't an issue. Why do these websites need all these cookies in th…

Most of these sites do have high regard for your privacy. It's not all for ads. Much of it is just for tracking logins and preferences, but warnings for that are required now too.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#184

Earlier quoted context omitted.

> And then, without your consent, without even notifying you they sold this information to credit score companies, to advertising companies and to whoever the fuck will buy it. > Without. Your. Consent. I'm really sure that every hotel has its terms of services. So does Facebook and every other site. What you described has always been illegal, and it has also never happened. What was sold was composed of data accordi…

Did you read, or was even aware of, a ToS of a hotel on use of personal data? This is entering the "local planning department in Alpha Centauri" territory. As a regular person, you should not need to be aware of such things. What GDPR tries to do is to restore some sane defaults into the process, just like customer protection laws do.

This quote seems apropos:

“It is difficult to get a man to understand something, when his salary depends on his not understanding it.” --Upton Sinclair

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#185

The practical effect of GDPR seems to me that I have to click away about half a dozen consent popups every day. Sometimes a cookie warning in addition to that. If I use Private Browsing (to protect my privacy) I am punished with more popups. If I open a website within a browser shell on mobile that doesn't have my cookies (some kind of webview of an app), I am punished with more popups. Am I expected to look at every…

GDPR is simply forcing them to show how these sites violate your privacy by trying to take information without your consent.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#186

Earlier quoted context omitted.

What earthly consumer is going to go through these steps? I have requested the removal of my personal data from multiple business, and I can assure you I'm quite earth-bound. Copy-pasting a template and filling in my name and account ID is not that hard.

I'm going to go out on a limb and guess that you are a fairly technical user. My snarkiness in the previous reply was excessive, but reflected my frustration with being told that something is simple that is actually a multi-step process with questions that are not easy to find the answer to. I guess the problem with email for this process is that you have a number of questions, all of which may not have an easy answe…

> 1. Identify an email address -- is this standardized?

Interesting, wasn't that addressed by GDPR? For that reason does german law requires information like this to be easily accessible, aka "Impressumspflicht". Lets compare for example amazon footers links.

Amazon.com

> Conditions of Use | Privacy Notice | Interest-Based Ads | © 1996-2018, Amazon.com, Inc. or its affiliates

Amazon.de

> Conditions of Use & Sale | Privacy Notice | Imprint[0] | Cookies Notice | Interest-Based Ads Notice | © 1998-2018, Amazon.com, Inc. or its affiliates

[0] https://www.amazon.de/gp/help/customer/display.html/ref=foot...

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#187
post #91

Earlier quoted context omitted.

Chrome is the biggest browser by market share and is maintained by a company whose entire business model revolves around tracking users to feed them ads. They have zero incentive to remove cookies. Same goes for Safari and Edge, even though they're not as dependent on ad revenue. This is a textbook example of negative externalities that can't be solved by market forces. That's where regulators should be stepping in.

> Chrome is the biggest browser by market share and is maintained by a company whose entire business model revolves around tracking users to feed them ads. They have zero incentive to remove cookies. Not true. If they don't do something, legislators are going to impose hamfisted regulation like GDPR which does impact their bottom line and hampers their business. So Google's incentives overlap somewhat with users here…

GDPR may affect Google's bottom line in EU markets (we are still awaiting proof as it's too early too tell). But seeing how the FCC dealt with the issue of net neutrality, I have serious doubts that they'd get anywhere near a consumer-first policy regarding Internet privacy.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#188

Earlier quoted context omitted.

> Somehow, I feel like the old, unregulated internet was better. I wonder if that is just nostalgia or there is something to it. >With an unregulated internet, any internet user has to take care of their own privacy and anonymity. Barriers for entry for new websites and services are very low. Data breaches and abuses of data can lead to users being concerned about giving their data to tech monopolies, which can enabl…

> How can I be 'less complacent' and 'have my guard up' if I don't even know that companies sell my data behind my back? By assuming they will, and taking steps to not provide your data to all and sundry. At the end of the day, companies can sell your data because they have it.

Right, and the logical conclusion of this is to stop interacting with companies. Any companies. All companies. Always. Because they are all doing it to an offensive degree. GM want to know where your car has been, and what radio stations you listen to. Facebook want everything, Google have everything. The pretty light bulb you bought is both a privacy risk and an attack vector.

Phone apps want to know your location all the time, Google maps constantly nags you to enable constant location tracking. Every other app has dark patterns to accidentally get the land grab on every mis-click, like Facebook's "Accept", "not yet" and no is buried many clicks deep in a new set of check boxes in some 8th level settings page.

Presumably if I had made my career in a different field like medicine or plumbing you would expect me to "educate" myself enough about IT to understand the real implications too, and the ways the tables can be joined. The genius who tunes your classic car should be learning advanced Wireshark to understand the complete fucking liberties and data mugging the weather app his friend recommended is taking multiple times daily.

It doesn't occur to you that this is ever so slightly asymmetric? Each individual should "take steps" whilst single-handedly going up against the combined might of regulation-free corporate America, where we learn everything can be sold and probably already has been. So what steps if it's not "go live in a cave and buy nothing made since 1999"?

Next week how Vatican City can successfully invade Russia and USA at the same time.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#189

I would prefer starting small and cautiously scaling up. “If you lose my data, you are strictly liable” is a good start because it lets case law work through the holes. (It also causes companies to see personal data as an asset and a liability, not just the former.) Full-blown GDPR is overkill. It makes more sense to wait a few years and see if the situation in Europe evolves differently from the U.S. I personally be…

"This is not the time to talk about guns"

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#190
post #10
post #5

Earlier quoted context omitted.

Do you actually know any MEP? The younger generations are less stupid than you might think. Politics is a slow game, the people who grew up with Windows 95 are only now starting to get elected.

In the current legislature, there is one former software programmer MEP and a Linus's uncle, who is not a programmer but knows a bit about software. There's also Julia Reda, but she is really just a filesharer and a politician.

I know Elly Schlein is switched on, although she works mostly on non-IT topics. I'm sure there are many others.
Post reply on HN