Live data from Hacker News

Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

brave.com

211–220 of 238 posts

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#211

The practical effect of GDPR seems to me that I have to click away about half a dozen consent popups every day. Sometimes a cookie warning in addition to that. If I use Private Browsing (to protect my privacy) I am punished with more popups. If I open a website within a browser shell on mobile that doesn't have my cookies (some kind of webview of an app), I am punished with more popups. Am I expected to look at every…

This should be temporarily as it shows (IMO) an extreme misunderstanding of the GDPR: - by default they are not allowed to collect more data than strictly necessary. - additional collection must be opt-in, and there can be no punishment for not opting in. - showing these dialogs that are opt-out seems like a way to beg for a fine: "We hereby declare to all our visitors that by default we collect way more information…

But the windows aren’t opt-out (that would actually provide better UX if you don’t care, see cookie banners).

They are annoying precisely because they do comply and require explicit opt-in into tracking. In other words, they ask you to make your choice as the first interaction.

By default, they collect nothing - and immediately show the form. You are not punished for opting out and can continue the same way as those opting in.

But everybody is annoyed by being asked. Regulators perhaps expected this to be some setting hidden somewhere, but that’s so incompatible with free content business models that it was clear that won’t happen. This is the compliant consequence.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#212
post #210
post #170

Earlier quoted context omitted.

I agree that these are real negative effects of GDPR. However, the concrete design of these pop-ups is mostly not GDPR-compliant: for example, users not agreeing to being tracked must not be disadvantaged, and having to click through a cumbersome array of options is certainly a disadvantage. At least for European web sites, the authorities will hopefully take action after a while, and then these bad practices will st…

I don’t get the disadvantage comment: everyone gets the popup crap, whether you say no or yes. Maybe I visit different sites, maybe I don’t notice because I reflexively click the closest button? In any case, the disadvantaging language is hardly meant that way: it’s about withdrawing actual content or features from you. We have waited a few years with cookies law and nothing changed. Unless some browser based fix tak…

The way it is supposed to work is you are supposed to be able to visit the site and get the same experience whether or not you accept the popup and ridiculous opt-out dark patterns. So declining should not disadvantage you.

Most of these pop ups appear to go against both the spirit and letter of the law, so will hopefully see some regulator response. Now whether regulators have enough budget to respond to all the wilful evasion remains to be seen.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#213

The practical effect of GDPR seems to me that I have to click away about half a dozen consent popups every day. Sometimes a cookie warning in addition to that. If I use Private Browsing (to protect my privacy) I am punished with more popups. If I open a website within a browser shell on mobile that doesn't have my cookies (some kind of webview of an app), I am punished with more popups. Am I expected to look at every…

Yes. And you're lucky if you see any Refuse button. Most all what I see the choices are to Agree completely to all terms, or "do not use this site".

Example?

That is illegal under GDPR. I’ve yet to see it. The only dark pattern I’ve seen mentioned is “agree” and “fine tune the settings” (with rejecting all as level 2).

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#214
post #138

Earlier quoted context omitted.

As with every law, we will see how it's actually used in practice but on my case I did not have much doubts about how it's supposed to be applied, I never understood it as an equivalent on the French one. For me, one of the goals here is when you delete your Facebook account, the data is actually deleted unlike what probably happens now.

There's been public analysis of the right to be forgotten. A few good reads: A summary article from NPR [1] and a research paper with a lot more details [2]. [1] https://www.npr.org/sections/thetwo-way/2018/02/28/589411543... ) [2] https://g.co/research/rtbf_report

That's not the same concept as the one from the GDPR (even if they share the same name).

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#215
post #206
post #69

Earlier quoted context omitted.

But is GDPR really making the kind of difference people wanted? What I see, is that mostly companies continue the same behavior, but now with a disclosure you are prompted to accept. I predicted everyone would just accept those terms in exchange for free services they already have invested into. Now we just have an extra annoyance. Has anything substantially changed?

Well, you can’t even access some major news sites from EU...

European news sites work fine without problems for Europeans.

What does one in Europe gain with reading, say, American news sites which have a mostly local (e.g. American West Coast) focus?

Sure, one may find more entertaining news in a way, and get perhaps another perspective, but I would say that this perspective is obtainable via other means. It is usually even spelled out in the news articles themselves, but perhaps not explicitly. So what does a European really lose by not being able to read, say LA Times, or a news provider from Kentucky?

Not trying to troll.

After the GDPR I noticed I was not able to read some sites. First I was a bit annoyed, then realized the links I tried to access were to some random US news sites. I realized I should be interested in more local happenings versus those in a remote place that is beyond a vast ocean. Also, I wanted to know in more detail what world events mean for me and my area, since that is where I live. And I want to avoid political paint in my news, as far as possible.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#216
post #211

Earlier quoted context omitted.

This should be temporarily as it shows (IMO) an extreme misunderstanding of the GDPR: - by default they are not allowed to collect more data than strictly necessary. - additional collection must be opt-in, and there can be no punishment for not opting in. - showing these dialogs that are opt-out seems like a way to beg for a fine: "We hereby declare to all our visitors that by default we collect way more information…

But the windows aren’t opt-out (that would actually provide better UX if you don’t care, see cookie banners). They are annoying precisely because they do comply and require explicit opt-in into tracking. In other words, they ask you to make your choice as the first interaction. By default, they collect nothing - and immediately show the form. You are not punished for opting out and can continue the same way as those…

Interesting and well written, you made me think, thanks.

I do not think it us that easy to fool seasoned regulators the second time though (the first time being the cookie law).

Also:

> but that’s so incompatible with free content business models that it was clear that won’t happen.

There is no reason why they need to track me around the we to serve ads.

Im fact, given the recent accuracy of the biggest actor in that space I'd argue that you'd do significantly better in many cases by using contextual ads.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#217

Earlier quoted context omitted.

What specifically do you take exception to with regard to GDPR/EU Internet laws? Having hands-on experience with compliance, I find GDPR to be quite reasonable - if anything, I'd say it's overly lax with regards to deletion of data that's not visible to the user (i.e. logs, 'shadow profiles', etc.).

Maybe GDPR is okay, I'm not terribly well informed about it. But every couple weeks the entire internet is up in arms against a new attempt by the EU to censor the entire internet, and I've been dealing for too long with the damn "We use cookies" pop-up they ignorantly required. So I'm just saying their track record isn't great.

> the entire internet is up in arms against a new attempt by the EU to censor the entire internet

I must be out of the loop because I'm not familiar with what "the entire Internet" is up in arms about. Can you give a specific example?

Re:cookies - you do realize that "we use cookies" almost universally means "we use third-party cookies" and that third-party cookies are the number one way that advertisers and other unsavory entities track your Internet usage across sites, right? Don't you think people deserve to know that their Internet usage is essentially being tracked granularly without their consent or knowledge for profit? If not, why not?

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#218

Earlier quoted context omitted.

What specifically do you take exception to with regard to GDPR/EU Internet laws? Having hands-on experience with compliance, I find GDPR to be quite reasonable - if anything, I'd say it's overly lax with regards to deletion of data that's not visible to the user (i.e. logs, 'shadow profiles', etc.).

What material harm or damage to you or your person did you experience prior to GDPR that GDPR has prevented or compensated for?

What material harm or damage would you suffer if I snooped on all of your Internet browsing activity with the knowledge of who you are in real life and kept that information around forever to use for whatever purposes I so choose?

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#219

Earlier quoted context omitted.

Good, you can opt in to tracking and profiling, if you wish. The rest of us would rather abolish this flagrant abuse of personal information.

> Good, you can opt in to tracking and profiling, if you wish. What we wish is to be able to opt-in once and for all, to get rid of these incessant interstitial pop-ups sprouting like mushrooms across the Internet. Perhaps we could introduce a new HTTP header X-GDPR-Consent-Granted, controlled by a checkbox in the browser, to explicitly acknowledge that yes, we know that anyone we interact with online is going to lea…

I think the way this would play out is that sites would attempt to only respect the header if consent is granted, and would prefer to still show the popup to those who set a header indicating to deny consent. In that case, it would be interesting to see what percentage of users are willing to deal to trade their data in exchange for being not bothered.

I would guess though that businesses would be wary that supporting such a header would legally put them in a position to also support a deny version of it.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#220

The practical effect of GDPR seems to me that I have to click away about half a dozen consent popups every day. Sometimes a cookie warning in addition to that. If I use Private Browsing (to protect my privacy) I am punished with more popups. If I open a website within a browser shell on mobile that doesn't have my cookies (some kind of webview of an app), I am punished with more popups. Am I expected to look at every…

> Am I expected to look at every one of those dialogs and figure out what I have to click to "customize" my tracking?

Most of the sites you're talking about are probably in violation of the GDPR. They're hoping that by adding a big notice telling you about their violations they'll be OK. We'll have to see. But there should be a "Refuse" option that's just as prominent as the "Accept" option.

Post reply on HN