Live data from Hacker News

Facebook now denying access unless EU users opt-in to tracking

twitter.com

361–370 of 385 posts

Re: Facebook now denying access unless EU users opt-in to tracking

#361
post #360

Earlier quoted context omitted.

I'd phrase it the other way around: you can't impose certain clauses in the contract (in this case, an obligation to consent to certain kinds of processing of personal data). Laws forbidding certain contract clauses are nothing new.

So I’m required to develop a bad version of my product for the small subset who don’t consent? Sounds a ton like the Windows Reduced Edition fiasco all over again but at a much more massive scale - forcing by law the development of a product almost no one wants.

You don't need consent for the cases when processing personal data is necessary to provide a feature for the user. For example, if you have a "find my friends near me" feature, you don't have to ask for consent to use the user's location for that purpose.

So there's never a reason why the product must be worse for any particular subset of users.

When you need to ask consent is when you're trying to use personal data in ways that aren't directly related to providing features for that user. Like, for example, ads.

And you can't develop a bad version to "punish" users who don't consent to those unrelated uses of their personal data, because then the consent wouldn't be freely given.

Re: Facebook now denying access unless EU users opt-in to tracking

#362
post #359

Earlier quoted context omitted.

That is very explicitly not allowed by the GDPR. You cannot make access to your service contingent on opting in. The consent has to be given freely, otherwise FB will be in violation of the regulation. Consent must also be given explicitly, you cannot have a pre-checked "yes" checkbox or an "accept and continue" button. Consent can also be given in a legally binding contract. A website ToS is very much not able to ov…

So you’re saying I’m required to develop two separate versions of my product? One for the users I can actually make money off and another for people who opt to get my product for free against my will?

You cannot base your business model on violating the privacy of EU citizens. That's just too bad, you'll have to find a non-scumbag way to fund your endeavors. You can absolutely still make money off ads, but you cannot target them based on personal information.

You are of course perfectly in your right to block all EU IP ranges, if you think that's a better solution, although cutting off 500 million potential customers is a bit harsh.

In short, EU citizens have absolutely no obligation to support your flawed business model.

Re: Facebook now denying access unless EU users opt-in to tracking

#363

Earlier quoted context omitted.

I don't think the GDPR's "necessary to work" clause considers profit models. I believe, (again, IANAL) that "necessary to work" is really "necessary for a feature to function"; how a company derives revenue from the service doesn't come into account. It would be interesting to see revenue as a necessity be tested in court, since there are open-source social networks that don't rely on user tracking or data sales to t…

On the contrary, commercial interests, including things like direct marketing, are considered acceptable "legitimate interests" under the GDPR, assuming the practice follows industry standards, ethics, and are legal. However, they need to pass two other tests, a "necessity" test that determines that the processing of information is necessary to serve the interest, and, most crucially, a "balancing" test which balance…

Erroneous guesses about GDPR, upvoted. Legal fact citing the law itself, downvoted.

Vote me down all you like, but it doesn't affect what is actual legal fact :-)

Re: Facebook now denying access unless EU users opt-in to tracking

#364

Earlier quoted context omitted.

I agree that people can have different views on these things for various reasons. But I don't see how "FB's behaviors are not necessarily objectively bad", unless one considers only the profit motive as prime without giving any thought to other factors. Can you expand on that?

Well, for one thing, nothing is objectively good or bad. Value judgments come from people, and people have widely varying perspectives. For another, the reason there's no mass exodus from Facebook is that Facebook users do not perceive the company as harming them. They perceive it as a useful service for staying in touch with friends and family. The utility it provides outweighs privacy concerns, because most people…

> nothing is objectively good or bad

Really? Nothing?

Re: Facebook now denying access unless EU users opt-in to tracking

#365

Earlier quoted context omitted.

Same at least in Portugal, Spain, Belgium, the Netherlands, Luxembourg and France.

I should have been more clear in my comment, I was referring to international high speed trains. Including mandatory registration of passengers and keeping the data for X years. Presumably these passenger manifests are also exchanged with other countries. But even regional services include oodles of cameras, including on the trains. There's tracking of passengers and their destination. There are heavily armed guards/…

Hmmm...those trains I step onto are (a) typically high speed and (b) quite often "international", though the concept really doesn't make much sense in the Schengen Area.

Are you talking about the Eurostar service from London (I remember the Waterloo station, though I hear it has moved to St. Pancras). That's the only one I can think of that fits your description.

The Thalys from Cologne to Paris via Belgium is/was also simple walk on walk off with normal train stations.

Re: Facebook now denying access unless EU users opt-in to tracking

#366
post #346

Earlier quoted context omitted.

can you expand on this? How is good or bad not subjective?

I'm not really interested in expanding directly, but if you're curious, answering that question is an entire field of study called ethics . https://en.wikipedia.org/wiki/Ethics

This is a dicy ground to enter.

As Voltaire said about God, same goes for absolute morals.

They ought to exist because without absolutes society is liable to collapse.

That does not mean that absolute morals exist just that we sort of pretend they do.

Take any human behaviour and you will find pros and cons in the good/evil category.

Liqueur/weed laws, sexuality laws, voting laws, slavery laws, etc etc etc.

Extreme example. Bio-hackers release a virus which manages to kill the whole of humanity on Earth including themselves. Evil/bad absolutely?

Certainly bad for humanity if there are humans left on other planets. But otherwise the question is meaningless to humans.

All morals are localized to time/space.

Re: Facebook now denying access unless EU users opt-in to tracking

#367

Earlier quoted context omitted.

Same at least in Portugal, Spain, Belgium, the Netherlands, Luxembourg and France.

I should have been more clear in my comment, I was referring to international high speed trains. Including mandatory registration of passengers and keeping the data for X years. Presumably these passenger manifests are also exchanged with other countries. But even regional services include oodles of cameras, including on the trains. There's tracking of passengers and their destination. There are heavily armed guards/…

On the TGV from Luxembourg to France, there were no barriers. And nobody ever asked me for my ID; in one of the legs, they didn't even check our tickets.

I don't doubt they keep those manifests, but I've found very little actual control.

Brussels does have troops going around, which is unsettling, but I never saw them inside the actual station, nor stopping people entering it, even after that poor devil immolated himself last year.

Re: Facebook now denying access unless EU users opt-in to tracking

#368
post #137
post #85

Earlier quoted context omitted.

It's how they pay the bills, to be fair. I don't think that's much of a secret anymore but looks like they're making it more explicit.

You could make an argument that the malware that encrypted your /home folder is also "just a way to pay the bills". In many jurisdictions that's illegal. EU is saying FB's approach is also illegal unless they make some key changes. Personally, I hope FB just quits Europe.

That's what I would do: quit Europe. FB is part of life of millions of people. They would cancel this GDPR thing in a day to save their FB experience. Or at least add an exception to GDPR for FB.

Re: Facebook now denying access unless EU users opt-in to tracking

#369

Earlier quoted context omitted.

I don't know if you are trolling or serious...I guess I and about 2B others might be using facebook differently than you then? I also don't find any of the data that FB or Google have of me "disturbingly extensive" or that they have been "breaking laws" to get it. I give them data so they can provide value to my life...it's as simple as that! If that deal doesn't work for you then you simply shouldn't use their produ…

I work at a telco/ISP, where I am directly responsible for multiple web-accessible and internal applications that have to be GDPR-compliant. I assure you that I am absolutely not trolling. As a professional, I take the GDPR extremely seriously, and in my private life I am very interested in keeping my private information private. Have you downloaded FB's data dump of you? That is only the bare surface of what they co…

I am aware that they use the data I put in in form of friends, posts, etc to inform ML models. And it makes sense that they don’t deliver those when I download my data!

Frankly I would argue that the ML models they create from usage data are theirs! Regardless of how useful they would be to me as a individual to download or not.

Now about the FB tracking pixels and the data they collect, I consented to those when I used the third parties websites they were in and accepted their TOS...and I have a choice to not use those sites or if I choose to block the pixel from firing via technical methods.

FB tracking pixels are on less then .1% of all websites...so I also don’t buy that arguments that Facebook follows anyone around, because it’s simply not true!

Update: so I was curious to see how this actually works and looked up the documentation: https://developers.facebook.com/docs/facebook-pixel/events-a...

So there is two ways to do it for third parties: get user consent before starting to use the website or use their advanced API and delay firing of the pixels until users have consentent later in the process...like for example on the checkout page!

Re: Facebook now denying access unless EU users opt-in to tracking

#370

Earlier quoted context omitted.

The content of the article presents no evidence, proof or confirmation from FB that such profiles exist

It depends on what you mean by "profile". I've got a feeling you're using a very specific definition and we're not going to come to an agreement. For me, a shadow profile is a set of data that can be correlated with you personally after the fact if you do decide to sign up for an account.

I can agree with you on that definition and have yet to see evidence that they do what you say.

I think we need to distinguish what data collection means...just because you have a Facebook cookie in your browser which causes the browser to fire a request everytime there is a call to facebooks domains and therefore send meta information about OS, Browser, IP, etc (which is hard to turn off without reinventing the web) doesn’t mean FB (just like any other website that uses cookies) does anything with that meta data or stores it at all.

I think we need to be careful about judging what they technically do and what they actually do!

Many people in this debate default to assuming the worst...which is never a useful position to take. I would suggest assuming the good intent on FBs behalf and then reverse engineer from there

Post reply on HN