Live data from Hacker News

GDPR for lazy people: Block all European users with Cloudflare Workers

apility.io

641–650 of 1001 posts

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#641

Earlier quoted context omitted.

GDPR is simply a response to abusive behavior. May not be the best response, but it was about time. Then, it is surprising to me that Americans are against a national id card, but are not OK with a privacy protection law.

I believe it's because, in general, Americans distrust government and trust corporations

We distrust both but only one has a monopoly on violence that can be pointed in our direction at any time.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#642
post #635

Earlier quoted context omitted.

I'm not onboard with the idea that Silicon Valley holds a monopoly on technical innovation. Getting people to click on ads on smartphones doesn't capture the entire scope of technology. Europe's economy is roughly as large as that of the United States. Many world-leading companies from the car industry, to chemicals, to biotech reside in Europe. The US holds one dominating advantage in one subset of technology. Consu…

That's exactly my point. The EU is built for entrenched institutions. There is no entrepreneurial spirit -- and that's why there's N-number of self driving car companies in the US and zero(?) in the EU, for example.

All (or most?) of the big European car manufacturers in Europe provide and actively research self-driving technology. Volkswagen's research budget is five times as large (iirc correctly) as Tesla's.

You are succumbing to a lot of stereotypes here, which I might add is fuelled by a cargo cult tendency within Silicon Valley.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#643

Earlier quoted context omitted.

Thank you for saying this, another thing that is ridiculously difficult is to delete specific user from all your backups. This is made even worse if you have multi region backups and cold back ups. Even a one-year-old start up could have literally thousands of database dumps in different places if they followed best practice of triple redundant daily dumps.

It sounds to me like this reflects more on the startup's sloppy practices than anything else. Prevalence of this bad practice shouldn't be an excuse for it.

Regular database backups are a bad practice?

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#644

Earlier quoted context omitted.

Tired of the eternal startup excuse to justify bad behaviour when it comes to protection of consumer privacy. If it is impossible for some startups to respect strong privacy practices maybe we simply don't need those startups. This 'startupism' is almost an ideology. No mechanical engineer would complain about safety regulation just because it means that they cannot start a business in their garage. In other industri…

Also tired of people thinking that a company not wanting a rule means they were intending to do the exact the opposite of that rule, especially given said rule is incredibly vague and designed to be applied "on principle". Fortunately for all of us, safety regulation is actually very specific in requirements.

> especially given said rule is incredibly vague and designed to be applied "on principle".

You know, I'm starting to feel that at least some of this contention is based on how Americans interpret the law vs. how Europeans do it. Somehow it seems that Americans (and the UK) has this huge legal corpus but everything has to be nitpicked to the letter, or the common law judges' interpretations may vary wildly, and some people might skate on technicalities, i.e. abuse of the letter of the law.

Whereas in civil law, which the EU is, there's less leeway for interpretation, however, the spirit of the law is also taken into account.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#645
post #635

Earlier quoted context omitted.

I'm not onboard with the idea that Silicon Valley holds a monopoly on technical innovation. Getting people to click on ads on smartphones doesn't capture the entire scope of technology. Europe's economy is roughly as large as that of the United States. Many world-leading companies from the car industry, to chemicals, to biotech reside in Europe. The US holds one dominating advantage in one subset of technology. Consu…

That's exactly my point. The EU is built for entrenched institutions. There is no entrepreneurial spirit -- and that's why there's N-number of self driving car companies in the US and zero(?) in the EU, for example.

European car companies sell identical technology to Tesla, it's just they call it lane assist (accurately), not autopilot.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#646
post #620
post #613

Earlier quoted context omitted.

> This may be an edgy and rebellious sentiment that makes me a radical anti-privacy activist, but unless you're storing levels of information on me that are similar to facebook/google/etc., I do not give a damn whether you're soft-deleting or hard-deleting my IP address and my user account. If your web app is just a web app, and not one component of a vast surveillance octopus which puts tentacles on almost every web…

If you don't store PII, you don't have to do any work. Done. If you need to have PII for your webapp to function, you barely have to do any work besides giving the that care people their rights The problem is not the work that the GDPR requires, the problem is the work I'll have to put into understanding the GDPR. I think it's mainly a difference in viewpoint: this is my data for me. Not yours. This is the part that…

If I go home and write in my diary that today hekfu bought lots of broccoli, you don't have the right to come to me in five years and demand that I remove all mention of you from my diary at my own cost.

I asked this question in a comment [1] here on HN a few weeks ago. There were affirmative responses that yes, the shopkeeper should in fact be held to account for keeping notes on who came into his store.

[1] https://news.ycombinator.com/item?id=16509598

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#647

Earlier quoted context omitted.

GDPR is simply a response to abusive behavior. May not be the best response, but it was about time. Then, it is surprising to me that Americans are against a national id card, but are not OK with a privacy protection law.

I believe it's because, in general, Americans distrust government and trust corporations

[deleted]

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#648
post #590

Earlier quoted context omitted.

The problem isn’t so much as there’s a cost to implementing GDPR, but that the tech community has been “move fast and break things” and refused to handle things properly before. If all you do about my PII is “set delete = 1” (which one could argue isn’t even the best practice in every scenario), then I probably don’t want you to handle my PII at all. To your example, you could easily not switch to a CASCADE, but inst…

This may be an edgy and rebellious sentiment that makes me a radical anti-privacy activist, but unless you're storing levels of information on me that are similar to facebook/google/etc., I do not give a damn whether you're soft-deleting or hard-deleting my IP address and my user account. If your web app is just a web app, and not one component of a vast surveillance octopus which puts tentacles on almost every websi…

TBH location tracking is the most sensitive PII I've seen anywhere, and plenty of 1 man shops are doing it. It takes like 100 lines of code.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#649

A trend I've noticed from lurking and browsing these comments: commenters who have experience taking risk and operating under existential conditions in stressful, budget constrained companies (AKA, startup founders) tend to be critical of the GDPR. Commenters who work as 9-5 employees or have never started a company (or at least, don't mention as having done so in their profiles) tend to be more supportive of the GDP…

It's easier to ask for forgiveness than permission. It's the Facebook Way™ and the dream for all those soon to be failed startups.

Funny how that works...

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#650
post #624

Earlier quoted context omitted.

Upthread we have the claim that "most early-stage startups use the... best practice of 'delete=1'," pretending to delete user data while actually retaining it. So, the exact opposite of the rule.

Why is delete=1 a best practice? There are competing concerns here. The government has now decided for everyone. Agree or disagree it is not worth implyng immorality where no immoral intent is present.

I’m not sure that delete=1 is a good idea, because you’re still mutating database records. But, it’s often lot cleaner conceptually to model state as an append-only log of assertions and retractions or via a log-structured system, where you never delete old records but just push a new index record that leaves the appropriate record out.
Post reply on HN