Live data from Hacker News

Tell HN: Interviewed with Triplebyte? Your profile is about to become public

news.ycombinator.com

251–260 of 605 posts

Re: Tell HN: Interviewed with Triplebyte? Your profile is about to become public

#251

The fundamental disconnect here is that Ammon seems to think this data belongs to him, for uses he deems appropriate, rather than belonging to his users. This works for Facebook and LinkedIn because of network effects, but not for some random staffing agency with a tech gimmick. If Adecco or MichaelPage did this it’d attract the attention of ambitious public prosecutors worldwide. It’s almost a shame, as the idea its…

>The fundamental disconnect here is that Ammon seems to think this data belongs to him, for uses he deems appropriate, rather than belonging to his users.

This is the reason why I ultimately like GDPR: the foundation is that the user owns their data and not the company that has it on a database server.

Re: Tell HN: Interviewed with Triplebyte? Your profile is about to become public

#252
post #176

Earlier quoted context omitted.

Still, please don’t do things that need actual consent in IRL (making something that was private, public) If your new service is of true benefit, it will be used.

What makes you think anything on your TripleByte profile was ever "private." It was not. It was merely hidden from the majority of the world. If you have a TripleByte profile, presumably, at some point, you were job hunting, and likely advertising that fact to anyone you thought could help you.

> What makes you think anything on your TripleByte profile was ever "private." It was not. It was merely hidden from the majority of the world. If you have a TripleByte profile, presumably, at some point, you were job hunting, and likely advertising that fact to anyone you thought could help you.

Are you arguing for this change? Whatever the argument is seems to be based on misinterpreting 'private' as 'known by no-one else'. Exactly the same argument could apply to e-mail: it's not private in the sense that no-one else sees it, just hidden from the majority of the world; presumably, when you sent it, you were advertising what it said to the recipient.

Re: Tell HN: Interviewed with Triplebyte? Your profile is about to become public

#253
post #245
post #119

Earlier quoted context omitted.

> Government identification may be required Ah yes, the classic "send us more of your PII to delete your information." I've ran into that too many times.

It's a horrible way companies try to discourage data subjects from exercising their rights. This is not lawful under both the GDPR and the CCPA. If Triplebyte follow through with their request against an EU or California resident, they'd be breaking data protection laws. If comments here are any indication, too many people, being unaware of their rights, may fall for it though.

Well I live in France and will certainly not send them my ID. Lets see how they respond.

Re: Tell HN: Interviewed with Triplebyte? Your profile is about to become public

#254
post #73

Earlier quoted context omitted.

Your Triplebyte profile will NOT contain any data/details about you or your job search that will undermine you at your current employer. We should have included a screenshot and more details in the email. I'll talk to my team about following up with more details tomorrow. We are talking about a lightweight profile, like your Stack Overflow or HN profile, to provide us the canvas to release badges. That's it.

If someone goes from not having a profile to having one, you know they’re job hunting. It’s like saying “Your Tinder profile will NOT contain any data/details about you or your dating search that will undermine you in your current relationship.”

How about if you just always have a profile?

Re: Tell HN: Interviewed with Triplebyte? Your profile is about to become public

#255
post #245
post #119

Earlier quoted context omitted.

> Government identification may be required Ah yes, the classic "send us more of your PII to delete your information." I've ran into that too many times.

It's a horrible way companies try to discourage data subjects from exercising their rights. This is not lawful under both the GDPR and the CCPA. If Triplebyte follow through with their request against an EU or California resident, they'd be breaking data protection laws. If comments here are any indication, too many people, being unaware of their rights, may fall for it though.

This is not lawful under both the GDPR and the CCPA. If Triplebyte follow through with their request against an EU or California resident, they'd be breaking data protection laws.

IANAL, but they may already be in violation of the GDPR with the 30 days processing time. While the GDPR states 30 days as the upper bound, the article about erasure also states:

The data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay and the controller shall have the obligation to erase personal data without undue delay where one of the following grounds applies [...]

Notice the phrase undue delay. It seems that the legal interpretation of undue delay is as soon as possible [2]. Since the sign-up for Triplebyte seems to be immediate (you just create an account), they could also remove an account with a simple delete account button (remove some rows from a SQL database). So in the case of most web services as soon as possible seems to be with the click of a button to delete an account itself. Allowing a few more days for changes to propagate through storage systems and backups.

For anything longer, they should probably come up with damn good reasons when this is brought to court.

At any rate, they will have more serious problems if they make citizens public for people in the EU. They'll open up themselves to a huge liability. You are simply not allowed to use data for other purposes than what the data subject gave explicit well-informed consent for. And no, burying somethings in the terms and conditions is not explicit consent.

[1] https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...

[2] https://www.linkedin.com/pulse/term-without-undue-delay-cont...

Re: Tell HN: Interviewed with Triplebyte? Your profile is about to become public

#256
post #73

Earlier quoted context omitted.

Your Triplebyte profile will NOT contain any data/details about you or your job search that will undermine you at your current employer. We should have included a screenshot and more details in the email. I'll talk to my team about following up with more details tomorrow. We are talking about a lightweight profile, like your Stack Overflow or HN profile, to provide us the canvas to release badges. That's it.

Hey! Welcome to your first PR disaster. I would suggest you step away from any scripts and turn on the company ears. Simply explaining what is going on more “clear” and repeating it more often probably won’t get you anywhere good. Why does this make your users uncomfortable? How can you work with them to achieve your product goals without undermining your relationship with them? Good luck!

Thank you for the calm and instructive response. I was about to hoist my pitchfork but set it aside instead.

Re: Tell HN: Interviewed with Triplebyte? Your profile is about to become public

#257
They are really putting the smtp servers to work this week, I've been getting two or three emails a day from Triplebyte, spamming about these changes.

If they are really doing remote jobs, maybe I'll have to look again, but when I aced their silly test and got interviewed originally, they only worked in the Bay Area, Seattle, and NYC, and I'd rather pull out my toenails with hot pincers than relocate to any of those places.

Re: Tell HN: Interviewed with Triplebyte? Your profile is about to become public

#258
post #228

Earlier quoted context omitted.

In which case, it sounds like at the moment they carry out a "data processing operation" to make your data public, you would have standing to make a formal complaint to your local data protection authority. Article 18 restriction of processing can apply here. Art. 25 "Data protection by design and by default" would seem to be relevant as well. The section I alluded to above is the latter half of 25(2), saying "In par…

I am not a lawyer and this is not legal advice but ... I don’t think the European government has legal standing to fine triplebyte. Triplebyte doesn’t have offices, employees or customers in Europe. A European visiting the US and interacting with an American business does so under the protection of US law, not EU law. This is complicated in the case of Facebook and google because they also do business in Europe, so E…

This may be true, but I have had US websites flat out refuse me access because they detect I'm in Europe.

Re: Tell HN: Interviewed with Triplebyte? Your profile is about to become public

#259
post #12

This is awful. And announcing this late on a Friday is what news organizations call “taking out the trash,” publicizing something when people aren’t paying attention.

Really sorry that you think this is awful. Certainly do opt-out. I think that taking on LinkedIn and creating a better engineering resume is a good thing to do. I can assure you that the Friday announcement is a result of our team grinding to hit a planned release week, not anything other than that (I would have loved to get this out earlier in the week)

You apologize for your actions, not because someone had a reaction to something you did. I suggest therapy.

Re: Tell HN: Interviewed with Triplebyte? Your profile is about to become public

#260
post #98

Earlier quoted context omitted.

It takes 30 days for any of these, actions to take place, but the window in which it was announced is a week. Something seems off.

And you need to have logged in already for the delete to work, after which you get an email to approve the request which ends up with this notice of requiring government id as well. Govt Id, really, what are they thinking here? ``` We're processing your request and should be done within 30 days. We will verify your request using the information associated with your account. Government identification may be required a…

This corresponds to the 30 days allowed for GDPR:

"Under Article 12.3 of the GDPR, you have 30 days to provide information on the action your organization will decide to take on a legitimate erasure request. This timeframe can be extended up to 60 days depending on the complexity of the request"

I deleted my account today and will issue a GDPR request if It doesn't get deleted.

Post reply on HN