Live data from Hacker News

GDPR: US news sites unavailable to EU users over data protection rules

bbc.com

501–510 of 680 posts

Re: GDPR: US news sites unavailable to EU users over data protection rules

#501

Earlier quoted context omitted.

Exactly. The most basic/outrageous example: anyone in the EU who installs Apache and leaves it in its default configuration which logs all page visits indefinitely is now a criminal. Spin up a DO/Linode/etc. instance and apt-get install apache2? You're now theoretically liable for a 20 million Euro fine.

Oh, it's much worse than that :) Do the same, but from any country in the world, and make sure your welcome page has multiple languages, including some EU ones. Now you're specifically targeting EU users and you're liable for up to $20 million euros. The response from GDPR fans is that: a) regulators would never levy such a fine, or b) they can't enforce it, or even c) that of course you should be fined because you'r…

> If someone in the EU puts some personal info in an envelope and mails it to me and I never get around to opening it and it just sits on a stack with other junk mail, am I now violating their human rights by keeping the info they voluntarily sent to me?

Everyone I've tried to make this point to has ultimately said something to the effect of "yes, you're violating their rights by not throwing out the letter." It's baffling.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#502

Earlier quoted context omitted.

if you do not value my privacy False equivalence. You can do nothing untoward with user data and still not be compliant.

Exactly. The most basic/outrageous example: anyone in the EU who installs Apache and leaves it in its default configuration which logs all page visits indefinitely is now a criminal. Spin up a DO/Linode/etc. instance and apt-get install apache2? You're now theoretically liable for a 20 million Euro fine.

Your point is that apache default config is horrendous regarding log keeping policy ? I agree.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#503
post #462

Earlier quoted context omitted.

Well, "HQ based law" not the case and it's a much larger discussion that doesn't have anything to do with the GDPR or EU. The USA too is going after foreign companies doing business with Iran or Cuba. The USA is not happy with cryptocurrency ICO's and it's enforcing it. The USA is forcing the world to respect DMCA. The taxes are also an issue, even within the USA doe to different VAT in different states. These are to…

You don't have to convince me that the US tramples on the sovereign rights of other countries just because it can. The tax situation is a good example. Historically, sales tax has not been able to be levied by states against companies just because they have customers in that state. They have to have physical "nexus" in that state as well. There are a number of states trying to do an end run around that right now with…

Let's agree to disagree about GDPR.

Anyway, it boils down to enforceability. EU is a huge entity and probably will be able to enforce the GDPR by forcing payment systems and gatekeepers like Google and Apple that legally operate in the EU not to do business with businesses that do not respect GDPR. Maybe it will be a bargaining point in some trade talks between other countries and the EU and EU will insist that the countries will help with the enforcement of the GDPR in exchange for something that other countries want from the EU.

As long as we don't live in some kind of libertarian anarchy world order, these things will be determined by the politicians.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#504
post #471

Earlier quoted context omitted.

File a complaint with who ? There's no EU-wide data privacy regulator. Which specific EU country would have jurisdiction over an interaction which took place in the US?

> Which specific EU country would have jurisdiction over an interaction which took place in the US? OP’s country. The "place" that interaction took place in is irrelevant here, unless the company "doesn’t specifically target its services at individuals in the EU"; OP is citizen of an EU country so the GDPR rules apply. (edit: rephrasing)

That's not how jurisdiction normally works. A French citizen working within the US for a US company can't demand that they follow French employment regulations.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#505
post #502

Earlier quoted context omitted.

Exactly. The most basic/outrageous example: anyone in the EU who installs Apache and leaves it in its default configuration which logs all page visits indefinitely is now a criminal. Spin up a DO/Linode/etc. instance and apt-get install apache2? You're now theoretically liable for a 20 million Euro fine.

Your point is that apache default config is horrendous regarding log keeping policy ? I agree.

Nobody would have said this a year ago. How are people getting so swept up in this privacy zeitgeist that they think web admins keeping logs is horrendous?

Re: GDPR: US news sites unavailable to EU users over data protection rules

#506

Earlier quoted context omitted.

Here's an example: I have a profitable, bootstrapped SaaS business based in US . It's not based on ads or selling data. I don't even have a freemium plan. Only a limited free trial after which you have to start paying. It's a trivial application that stores mostly already public data. Only email is required to login so that I can send password reset and other such communication. I've been talking to a very well known…

>It's a trivial application that stores mostly already public data So wtf are you worrying about then? Only shady companies are afraid of GDRP, the fact that you look at GDPR as a problem is a huge let down in trust for your company

That's a gross generalization. In fact, the parent explained quite well why GDPR can become a problem for smaller companies.

It's not the law itself that matters in this case but the clients' (quite possibly wrong) interpretation of that law. As of now, GDPR unfortunately leaves a lot of room for interpretation.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#507
post #87

Earlier quoted context omitted.

People have tried lots of other stuff in the last 10-15 years, it was not sustainable (micro-transactions never took off, subscription-based newspapers are the exception rather than the norm etc). I'm personally fine with newspapers like the LA Times collecting and selling my personal data as long as I can read articles for "free" on their website, I think it's a pretty fair deal.

Part of the reason for the failure of those other models is their need to compete with an exploitative ad driven model. When you remove the lowest common denominator, you make it is easier for the market to accomplish something better.

If payment is optional then you are only likely to hand over money out of principle, or your own personal values.

I don’t think it’s as simple as finding the same news elsewhere for free though, or accepting this level of data collection, or subscribing to every site with micro transactions.

I would pay to use HN if the articles I clicked through to (or upvoted, or engaged with in the comments) got a piece of the pie. I’d pay a fair amount because I get a lot of value out of the aggregation and community HN offers. There’s no obvious allegiance to a particular perspective on life so one day I can enjoy a spiritual read and another I can learn about baking bread. I’m not only challenged, my curiosity is being piqued. It may be that HN works this way because there is no direct profit motive in HN itself except to point budding startups to Y Combinator.

I’m unlikely to pay an individual publication (say, The Guardian) because such publications have a specific editorial viewpoint, and more often than not it’s going to be the point of view that supports my own. My money is wasted on an echo chamber that makes me mad about the state of the world.

Neither am I likely to pay a publication that I persistently disagree with because our values are incompatible. I might read them if they have something profound to say but I’m not going to commit to them for that.

So maybe there’s something in a co-operative effort where the community collectively funds the content it engages with. But rather than it being an individual thing like with Patreon or individual subscriptions, it’s a pool you contribute to in order to participate further in the community.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#508

Earlier quoted context omitted.

Of course, that vision of what the internet could be never really answered the question of where the money was coming from to pay for the servers that are delivering that content.

Or how to pay the people who create the content

It seems many people think content worth enjoying is somehow created and delivered freely.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#509
post #502

Earlier quoted context omitted.

Exactly. The most basic/outrageous example: anyone in the EU who installs Apache and leaves it in its default configuration which logs all page visits indefinitely is now a criminal. Spin up a DO/Linode/etc. instance and apt-get install apache2? You're now theoretically liable for a 20 million Euro fine.

Your point is that apache default config is horrendous regarding log keeping policy ? I agree.

I know! Just imagine...your (likely dynamic) IP address exists in forgotten log files all over the web. The horror!

One of the most annoying things about the GDPR fandom is the black and white nature it seems to inevitably take. If your log files store IP addresses, you're clearly evil and shady and are violating human rights, just as bad as if you're recording people's conversations at home with the intent to deprive them of insurance or publish their sexual histories or whatever.

What possible "horrendous" harm is there from apache's default config storing IP addresses? Can you give me an actual harm that has befallen someone as a result of this that isn't some freak one-in-a-billion example?

Re: GDPR: US news sites unavailable to EU users over data protection rules

#510
post #70

Earlier quoted context omitted.

I see this 'VPN' argument a lot, but it's wrong. If the Chicago Tribune tracks users accessing their site through a VPN, without informed consent, they are in violation. Art 3 para 2 in b makes the Regulation apply to them and doesn't make provisions about whether the controller or processor has a way to find out if the behaviour of the data subject takes place within the Union. I don't see any reason for a different…

If you use a VPN to access a server that does it want you to access it, then you are breaking the computer fraud and abuse act in the United States. Shouldnt you be the one sent to jail, as you are illegally accessing a computer that you were sepecially told not to access?

Maybe. That's entirely orthogonal to the question whether or not the person who's server it is, is affected by the GDPR though.
Post reply on HN