Is anyone talking about the harmful effects on startup companies that may want to create new social platforms to compete against the incumbent players? All the talk about regulating facebook, twitter, etc are actually great for those companies because they can afford compliance. But it raises the bar of entry so high that new companies wouldn't be able to compete since with limited resources they wouldn't be able to…
The GDPR makes some things easier for start ups. Users now have a right to their personal data in a "commonly used" digital file. Now the start up can have a "Import your Facebook data" feature. Currently a provacy conscious start up is competing with those who aren't, making it harder. But with this law, you won't have as many shady companies like Facebook. Storing less private data makes you less liable to get hack…
Facebook urged to make GDPR its “baseline standard” globally
231–236 of 236 posts
Re: Facebook urged to make GDPR its “baseline standard” globally
#232Earlier quoted context omitted.
> not allowing that export at all would probably be met with legally-binding criticism Yeah? Can you point me towards any law that says I have the right to export data I did not enter? > The main use-case that was discussed then was to empower services like Riot, to encourage competition — something that, surprisingly, Facebook was very supportive of at the time. You have any evidence for that encouraging competing s…
> Yeah? Can you point me towards any law that says I have the right to export data I did not enter? In the case in point, you did approve, i.e. enter, all the relation on your graph so I’m not sure how your question is related. To your question: GDPR allows you to access any information associated to identifiable information, there are explicitly no limits on whether you entered it, it was scraped, logged or if it wa…
I did not enter my friend's birthday, or other "extended profile properties". In what world does GDPR legally require facebook to allow me to export my friend's birthdays and their extended profile information?
> I probably should have phrased it better, “the most discussed case”.
Yeah, I'd totally buy that they tried to sell the feature externally as supporting social competitors. That is very distinct from what you claimed.
> Every one of them granted access to their likes and social graph to their friends.
You were distinctly talking about the permissions people were granting facebook applications and blaming the problem on people not reading those permissions carefully. Now you seem to be blaming people for using Facebook at all?
> What you are asking is for you to be able to tell Facebook that the company should not accept, or store, the information that your friends want
I'm not asking for it, (though GDPR will provide that), but you were claiming it existed.
Re: Facebook urged to make GDPR its “baseline standard” globally
#233Earlier quoted context omitted.
> Yeah? Can you point me towards any law that says I have the right to export data I did not enter? In the case in point, you did approve, i.e. enter, all the relation on your graph so I’m not sure how your question is related. To your question: GDPR allows you to access any information associated to identifiable information, there are explicitly no limits on whether you entered it, it was scraped, logged or if it wa…
> In the case in point, you did approve, i.e. enter, all the relation on your graph so I’m not sure how your question is related. To your question: GDPR allows you to access any information associated to identifiable information, there are explicitly no limits on whether you entered it, it was scraped, logged or if it was inferred. I did not enter my friend's birthday, or other "extended profile properties". In what…
It doesn’t and that’s not what the API allows today. At the time this was a feature, there were arguments that allowing that would help new competing services to emerge, but they never became law.
Because they did not, competing services now rely on a handful of people claiming they switched, rather than have more effective (or invasive) ways to remind people to switch. That means that it’s extremely unlikely that any project competing with Facebook, many of which have recently felt a gust of interest will actually take off meaningfully. So the reaction you are asking now from Facebook, thinking you are being critical and provocative, happened six years ago and locked them as a monopoly. I guess that’s hindsight.
> That is very distinct from what you claimed.
Yes, because what I claimed is that external activists, developers who set up OpenSocial (OAuth and OAuth 2.0, Activity Streams, and Portable Contacts) were the ones asking for it.
> Now you seem to be blaming people for using Facebook at all?
I’m not blaming anyone (except you): I’m just stating that having a social service means sharing access to personal information. Once information is shared, you have to trust people who are not the person who the information is about, but their friends, with said information. Facebook empowers that trust: you can learn about how long lost friends are doing, which is a great way to leverage that trust; or you can sell their details for a dollar, which is less great.
Re: Facebook urged to make GDPR its “baseline standard” globally
#234Earlier quoted context omitted.
> In the case in point, you did approve, i.e. enter, all the relation on your graph so I’m not sure how your question is related. To your question: GDPR allows you to access any information associated to identifiable information, there are explicitly no limits on whether you entered it, it was scraped, logged or if it was inferred. I did not enter my friend's birthday, or other "extended profile properties". In what…
> In what world does GDPR legally require facebook to allow me to export my friend's birthdays and their extended profile information? It doesn’t and that’s not what the API allows today. At the time this was a feature, there were arguments that allowing that would help new competing services to emerge, but they never became law. Because they did not, competing services now rely on a handful of people claiming they s…
>"not allowing that export at all would probably be met with legally-binding criticism"
What legally binding criticism were you talking about? Why did you bring up the GDPR to defend this statement?
> Because they did not, competing services now rely on a handful of people claiming they switched, rather than have more effective (or invasive) ways to remind people to switch. That means that it’s extremely unlikely that any project competing with Facebook, many of which have recently felt a gust of interest will actually take off meaningfully. So the reaction you are asking now from Facebook, thinking you are being critical and provocative, happened six years ago and locked them as a monopoly. I guess that’s hindsight.
Oh please tell me, what reaction am I asking for? Are you saying we should have legally force Facebook to continue letting CA strip mine users data? WFT are you talking about?
> The main use-case that was discussed then was to empower services like Riot, to encourage competition — something that, surprisingly, Facebook was very supportive of at the time.
> Yes, because what I claimed is that external activists, developers who set up OpenSocial (OAuth and OAuth 2.0, Activity Streams, and Portable Contacts) were the ones asking for it.
No, you never claimed that at all. You claimed that facebook was discussing this API mainly as a means of fostering competition.
> Once information is shared, you have to trust people who are not the person who the information is about.
And you have to trust the platform to respect your privacy and not give any random quiz app full access. Obviously Facebook is not trust worthy and should not be given this information.
> Facebook empowers that trust: you can learn about how long lost friends are doing
Facebook doesn't empower trust at all: it abuses it to make money off of our information.
Re: Facebook urged to make GDPR its “baseline standard” globally
#235Earlier quoted context omitted.
> respond to that email in under quarter of an hour. Let's take an app like Instagram as an example. Instagram had over 1 million users within two months and 10 million within a year, and no profits. You're running on a shoestring trying to keep servers online without any serious budget to speak of. It's probably you and a few friends/associates working closely together. All of a sudden with GDPR, you have to pay a l…
If the concern is that business owners can no longer cut costs by being lax with people's data... isn't that the whole point of the GDPR? That we've collectively decided that letting people cut those costs is having too many negative concequences too often and that we need to stop?
Re: Facebook urged to make GDPR its “baseline standard” globally
#236Earlier quoted context omitted.
I think "reasonable measures" is pretty typical language when talking about compliance. I don't know GDPR regulation very well but I know FDA regulation reasonably well and I imagine compliance will be similar, and much easier for the new GDPR. Most important is to document everything. Have a design history file that you can show in case you get audited. When you design your software, save your designs in the DHF. Wh…
Well said! Thank you for your comments. With all that said, my point was that it's not obvious what is and isn't reasonable. Hiring a security specialist won't necessarily help you understand what bureaucrats will or won't deem reasonable, especially when there's no history to provide context.