Live data from Hacker News

Google’s GDPR Workaround

brave.com

441–450 of 629 posts

Re: Google’s GDPR Workaround

#441
post #269
post #7

Earlier quoted context omitted.

It is very not legal, but I think the parent was saying these regulations are more onerous to small dev shops rather than Google and the fine for this will be minuscule. Hopefully companies will find paths to revenue that do not require selling out there users to this level, maybe by just having ad auctions without any identifying information at all.

This has always been absurd. Large companies have way more code and features in general which need to be checked for compliance, whereas small shops with small sets of data and features will have a far easier time complying with GDPR.

Large companies have the means to pay for the manpower (lawyers/consultants, developers, etc) to certify compliance with GDPR. Small companies often don't.

I paid $2K for my first GDPR consulting session for a $7K MRR app and was quoted ~$25K for consulting while I would personally implement what needed to be done. $25K is nothing for a large company, but it's prohibitively expensive for a lot of small companies. This cost also doesn't include the (probably hundreds of) man hours required to implement and certify GDPR compliance, which are also disproportionately valued when it's being done by 1 person in a 5K person company.

Hopefully these costs will fall as more people become lawfully knowledgable about what GDPR entails and the market of people available to help grows. Unfortunately there's no "feel free to wait if you can't afford it yet" clause in GDPR.

Re: Google’s GDPR Workaround

#442

Earlier quoted context omitted.

I discussed GDPR with you before and based on your answer here and maxidorius answer to you I will not accept anything you say about the GDPR unless it is obvious or has references I can verify.

You're suggesting that hospitals would be allowed to sell patient info to anybody willing to pay, as long as they have a contract?

I'm suggesting :

1.) it might be stricter than you say.

2.) you (possibly like me? ;-) seems to have stronger views on what GDPR means than you can argue for.

Re: Google’s GDPR Workaround

#443

Earlier quoted context omitted.

I had a coworker from the Netherlands over recently. I think by the end of the trip he thought I was making stuff up trying to correct this misconceptions. I do know he never believed me about the hot coffee lawsuit. Sample set of 1, but it was odd for someone not from America, and indeed it was his first time in America, to be as misinformed about things. Not knowing things is fine, but knowing wrong facts, and refu…

Out of curiosity do you have any particular examples other than the coffee lawsuit?

The things I remember:

Most Americans have guns, support open carry, etc. I was an unfathomable oddity for not owning a firearm.

Most Americans support the current president (whoever that may be at the time), or at least hope he succeeds with his plans.

We only eat fast food, or at the least primarily as a people, prefer "American Food".

And a lot of things that can be boiled down to "America is horribly unsafe, if you go for a walk alone, you WILL get mugged or otherwise hurt"

The Hot Coffee thing was part of a larger thread about the American legal system being a game people play.

There are truths in some of these things, of course, but the scale of them was way off in his head.

Re: Google’s GDPR Workaround

#444

Earlier quoted context omitted.

Normally coffee is not brewed on boiling water, and losses a lot of heat during the brewing process. So, McDonalds' coffee (and the ones on many more stores) is significantly hotter than normal coffee. But recently brewed coffee is dangerous anyway, it's quite stupid to hold it with one's legs. Still, I don't know about the details, and even the defamation she suffered might be enough for the punishment.

I don’t know how fast food companies brew it, but frequently coffee shops who do drips and care about the flavor more insist that the most important thing in drip coffee is a temperature that’s only around 10°F/5°C under boiling. Of course if they do brew that, they won’t give it to you before either adding a bit of cool water (most places prefer to brew strong and then dilute) or letting it cool down (if they just i…

The grounds and equipment are not at similarly high temperatures, so the coffee going into the cup is significantly cooler than the water being poured.

IIRC at the time the McDonald's stated rationale was that by serving at that temperature it would be at a good drinking temperature when people arrived at their offices. These days that seems ludicrous to me.

Re: Google’s GDPR Workaround

#445
post #8

It's really funny to see that yesterday, I was branded as a 'privacy nut' after the release of Android 10 as I was concerned about the privacy issues that are in Android. Then the Go modules proxy issue around the Go Programming language that raised suspicions about tracking usage statistics around downloading modules turned on by default without any consent and now this. I think there are some folks at Google who ha…

> I was branded as a 'privacy nut' after the release of Android 10

You were doing baseless accusation on something you don't know anything about. Your comment was basically "they market it as being better to handle privacy thus they clearly are worst with your privacy!".

You didn't raise anything substantial at all in that comment.

Re: Google’s GDPR Workaround

#446
post #309

This is exactly what happened in the McDonald's "hot coffee" lawsuit. It wasn't some "Karen" who hit a bump while driving. It was an elderly woman (in her 70s, IIRC), sitting in the passenger seat. McDonalds already had complaints (and some lawsuits) over the (significantly higher than industry standard) temperature of their coffee, so this wasn't exactly out of the blue. She ended up with 3rd degree burns on her leg…

Curious how this one has changed on the internet. From a UK perspective I'd always thought of it as a case of crazy pay-out. Why does this one women get several million dollars (although googling reveals this number went down a bit on appeal)? Especially if others had a similar experience. Either there should be a limit on the temperature of hot drinks, or there shouldn't. The fact a warning is deemed adequate seems…

From memory I believe the case was settled for a presumably lower undisclosed amount rather than go through a long appeals process.

Re: Google’s GDPR Workaround

#447
post #279

Earlier quoted context omitted.

> HIPAA only keeps healthcare providers from sharing your information. It's not an omnibus shield for your health information. Maybe not, but GDPR sure is.

Is it really? If Alice tells Bob she has diabetes and Bob tells Charlie, is Bob in violation of GDPR?

No, GDPR does not apply between 2 persons.

Re: Google’s GDPR Workaround

#448

Earlier quoted context omitted.

The reason the McDonald's lawsuit is framed that way in popular circles is because it is easily fits the mold for a frivolous lawsuit. 1. A woman willingly purchased hot coffee from McDonald's. 2. She spilled it on herself. 3. She sued McDonald's because of her injuries. Those three things are true no matter which circle you ask. A lot of people I talk to, even when given all of the facts of the case still consider i…

Mark me down as a person who considers it a frivolous lawsuit. And yes I've read the background. She balanced the cup not in a cupholder, but between her knees. Even normally hot coffee is going to be bad news if it spills like that - the only difference the increased temp made was that the burns were more severe. But the coffee would not have spilled at all if she was not negligent in handling it (i.e. she should ha…

Spills are a normal and expected occurrence in the course of life. I've spilled coffee on myself before, but I've never needed 8 days in the hospital as a result.

It is also worth noting that the court in this case did not assign full responsibility to McDonald's; your point was certainly considered in this case.

Re: Google’s GDPR Workaround

#449

I'm an engineer who has worked on ad systems like this and I'm really struggling to make sense of this article - what hope does a layman have? Here's my understanding: Google runs real-time bidding ad auctions by sending anonymized profiles to marketers, who bid on those impressions. The anonymous id used in each auction was the same for each bidder, which is in violation of GDPR. If Google were to send different ids…

> Why would it matter that the bidders are able to match up the IDs with each other, aren't they all receiving the same profile anyway?

I would guess that yes, they're all receiving – _from Google_ – the "same profile" but they also are collecting additional info that they can then share with each other and, because they can match profiles exactly, they can access each other's info about specific people.

> Wouldn't privacy advocates consider the sending of the profiles at all an issue?

I'd imagine that the profile Google has and shares is by itself fairly anodyne, but I could be (very) wrong about that. The problem seems to be more (if not entirely) that different advertisers can share info using a common profile ID.

I'd imagine that even a single advertiser would be able to perform a similar 'attack' by, e.g. running multiple different campaigns, but I may be misunderstanding exactly what info is being shared. It's possible advertisers are able to match the Google profiles to specific unique identities and thus are sharing much more than just the info they're collecting directly from their ads.

Re: Google’s GDPR Workaround

#450

I'm an engineer who has worked on ad systems like this and I'm really struggling to make sense of this article - what hope does a layman have? Here's my understanding: Google runs real-time bidding ad auctions by sending anonymized profiles to marketers, who bid on those impressions. The anonymous id used in each auction was the same for each bidder, which is in violation of GDPR. If Google were to send different ids…

Are they maybe only receiving a partial profile, with info relevant to that ad buy? And by compiling that data with the unique identifier, they can match it with other partial data from other ad buys?
Post reply on HN