Live data from Hacker News

GDPR for lazy people: Block all European users with Cloudflare Workers

apility.io

851–860 of 1001 posts

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#851
post #668

Earlier quoted context omitted.

> I do not give a damn whether you're soft-deleting or hard-deleting my IP address and my user account You don't give a damn; neither do those computer illiterate people who use the same email address and password for everything, and one leak of some shitty inconsequential website may obliterate their entire online presence.

I'm not sure how the GDPR fixes anything, since those people aren't going to be capable of finding the hidden "delete account" button five pages into a big tech company's byzantine privacy settings.

The GDPR says "It shall be as easy to withdraw as to give consent". If you're hiding the "delete account" button, you're breaking the law.

https://gdpr-info.eu/art-7-gdpr/

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#852

I’ve been reading hacker news for about a decade, and it’s getting to the point where I don’t think there are many entrepreneurs and/or technical people on here anymore. The number of people who are saying it’s no big deal to comply with this huge law, especially for very small startups, is mind boggling. Let’s just take one feature: the requirement that you can permanently delete all of your information. Most early-…

> the requirement that you can permanently delete all of your information.

Can you point to the bit of GDPR that says I can have all my data permanently deleted?

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#853

Earlier quoted context omitted.

Is it? Visit Germany sometime. Drive through the countryside. Most parts of the US look like a hollowed out shell by comparison.

That might have something to do with the fact that Germany has 7x higher population density.

You may or you may not have an argument - but you only present the most cliché, most superficial version. You merely divide total population by total area, which is utterly useless and misleading. Why does that keep happening on a supposedly "better" forum like HN? Each time this topic is touched this exact same tired and wrong pseudo-argument is presented as if population follows an equal distribution per area.

Just like in the rest of the world, in the US too the vast majority of people are clustered in and around urban areas. In order to achieve your goal/argument you counted vast stretches of nothingness. At least since the early 20th century migration to cities has been going on, and it still does - large urbanized areas continue to suck in people from the already emptier areas of the country.

https://en.wikipedia.org/wiki/Megaregions_of_the_United_Stat...

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#854

Earlier quoted context omitted.

Tired of the eternal startup excuse to justify bad behaviour when it comes to protection of consumer privacy. If it is impossible for some startups to respect strong privacy practices maybe we simply don't need those startups. This 'startupism' is almost an ideology. No mechanical engineer would complain about safety regulation just because it means that they cannot start a business in their garage. In other industri…

>No mechanical engineer would complain about safety regulation Mechanical engineering projects are too costly to be undertaken casually in the first place. Regulation is unlikely to be the long pole, so do you don't hear them complain about it. It only takes a few minutes and some easily self-teachable skills to start serving HTTP traffic; now it's going to take a few months and some lawyer hours to create the bureau…

> Mechanical engineering projects are too costly to be undertaken casually in the first place.

Yes, because of the implications, as the parent said. Just making stuff is cheap these days, that's not just true for software. You don't have to build a factory, if you want you can even outsource the actual construction entirely if you don't want to go through the trouble and remain flexible, just like "cloud computing" using startups.

> It only takes a few minutes and some easily self-teachable skills to start serving HTTP traffic;

Because people do it without caring for or knowing the consequences.

> now it's going to take a few months and some lawyer hours to create the bureaucratic cover for doing so.

I don't understand your point, it's exactly what the parent said? Yes, this forces the startups to actually care about the consequences of what they are doing.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#855
post #735

Earlier quoted context omitted.

Thank you for saying this, another thing that is ridiculously difficult is to delete specific user from all your backups. This is made even worse if you have multi region backups and cold back ups. Even a one-year-old start up could have literally thousands of database dumps in different places if they followed best practice of triple redundant daily dumps.

The general recommendation is that if it's too difficult to purge specific users from your backups then: * Have a clear data retention policy and make sure that all backups have an expiration date. * Secure your backups with strong encryption to protect user data in the event of a leak. * Explain it to the user when the account is deleted when the deletion will filter through your backups. * Guarantee that if a resto…

How do you keep track of what info needs to be deleted on restore without violating GDPR?

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#856

I’ve been reading hacker news for about a decade, and it’s getting to the point where I don’t think there are many entrepreneurs and/or technical people on here anymore. The number of people who are saying it’s no big deal to comply with this huge law, especially for very small startups, is mind boggling. Let’s just take one feature: the requirement that you can permanently delete all of your information. Most early-…

>I’ve been reading hacker news for about a decade, and it’s getting to the point where I don’t think there are many entrepreneurs and/or technical people on here anymore.

The number of people who are saying it’s no big deal to comply with this huge law, especially for very small startups, is mind boggling.

You want it to sound like the second phrase is the observation that proves the first, but in my eyes the two sentences are contradicting.

You can very well be technical and/or entrepreneur and think it's "no big deal to comply with this huge law".

Because, in fact, one of the defining characteristics of being an entrepreneur is taking risk, including the risk to not comply 100% with all BS laws. And one of the defining characteristics of hackers and programmers is thinking they can solve a problem (and often underestimating how long it would take).

So your GDPR-related observation would in fact prove the opposite of what you're stating: that there are plenty of entrepreneurs and technical people on HN.

Now, if you wanted to say: "there are no conservative, risk adverse entrepreneurs, and by-the -book corporate software engineers in HN anymore", then yes, that would be something that your GDPR related observation would support.

P.S Note that I'm not making an argument either way. There might be many or few entrepreneurs and technical people on HN. I'm just saying that if the latter is the case, it's not at all supported by your observation re: GDPR.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#857
post #829

Earlier quoted context omitted.

You have delete as a boolean? My standard (well, Mongoid::Paranoia) is a timestamp and after a reasonable time to cover accidental deletions (like facebook does) a worker job can do the actual deletion.

DHH has a video about how this is implemented in Basecamp. https://www.youtube.com/watch?v=AoxoPfilKqE

Oh, did the series move to a different channel, I missed that announcement. I only watched upto #5, thanks for reminding me :)

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#858
post #813

I’ve been reading hacker news for about a decade, and it’s getting to the point where I don’t think there are many entrepreneurs and/or technical people on here anymore. The number of people who are saying it’s no big deal to comply with this huge law, especially for very small startups, is mind boggling. Let’s just take one feature: the requirement that you can permanently delete all of your information. Most early-…

Technical person here! I was tech lead at an energy company in the Netherlands. We had a compliance dept (mostly 1 person) I worked closely with before GDPR was on the radar as the energy sector here is fairly well regulated. It’s true that compliance can sometimes be scary and requirements are not always clear. Big company ending fines probably keep some people awake at night. The point is regulators don’t generally…

Bullshit. Sometimes regulators want to shut down your company. Bureaucrats are not immune from politics.
Post reply on HN