Live data from Hacker News

GDPR for lazy people: Block all European users with Cloudflare Workers

apility.io

871–880 of 1001 posts

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#871

Earlier quoted context omitted.

Who are you arguing with that thinks DMCA was a great idea but GDPR isn't?

Not saying anyone thinks it's a good idea. I'm saying I haven't seen that many comments, annoyed people, and general discussion about other laws, which actually impact US people and can be enforced there. I'm guessing they also ignore those laws, because of posts like this one. If you're running a business complying with regulations, you likely already know how to block a country. I mean, you keep track of the curren…

Because this is a thread about GDPR, and the GDPR is not the same as the DMCA in either impact or scope. Take your whataboutism elsewhere.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#872

I’ve been reading hacker news for about a decade, and it’s getting to the point where I don’t think there are many entrepreneurs and/or technical people on here anymore. The number of people who are saying it’s no big deal to comply with this huge law, especially for very small startups, is mind boggling. Let’s just take one feature: the requirement that you can permanently delete all of your information. Most early-…

There are literally hundreds of laws, some very large, that tech startups must comply with from day 1. Yet somehow we still have startups and small companies, and the world goes on, round and round. Why no complaints about these other big laws? None of them get the vitriol hurled at them quite like GDPR. I suspect this is because having to comply with big laws is not really the issue. The real issue is that GDPR hits…

>There are literally hundreds of laws, some very large, that tech startups must comply with from day 1.

> The real issue is that GDPR hits Silicon Valley right in the soft spot where it hurts: Callous and unrestrained collection of user data.

I've kept myself to lurking in those threads, simply because there's been so much FUD about this for the last few months. This, however, is spot on and it needs to be pointed out.

If people think GDPR is bad, then they should have a look at what it takes for a small startup that want to sell chicken eggs for breeding purposes, especially if you buy/sell across the EU borders. The requirements are quite insane compared to GDPR. :)

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#873
post #53

I keep seeing these posts on how to block European users to avoid the GDPR. As a citizen of Europe, seeing these posts consistently making it to the front page is disappointing. It would seem that Silicon Valley perceives the GDPR as more of a hindrance than an opportunity to offer users better privacy. Nothing has been learned.

If I were running my own company right now, this is probably the approach I would take. I'm a big privacy advocate, but I'm also anti-authoritarian and don't like being forced into things by overbearing laws. Blocking Europeans sounds a lot more reasonable than having to hire a lawyer and spend double the time and effort just to be compliant while writing a new JavaScript MVC Todo List app.

GDPR is happening because for the last several (10s?) of years companies have been playing fast and loose with people's data. They've had their chance and they've blown it fairly comprehensively.

The people (by and large government is run by the people, for the people, at least in some countries) have had enough. I've had enough, and this is us telling companies they've had their chance and not made the grade so we're dictating now. As a person, and father (who has to worry for the rest of my live about my offspring's health and happiness, and linked to that, privacy) I'm very happy with this law. I support it, as seemingly a lot of people do. That's not authoritarian, it's the will of the people.

And no, I'm not some sort of communist beard stroker, I'm pretty central in my political beliefs and I also don't appreciate governments sticking their noses in where it's not welcome, but this, this is welcome.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#874

I’ve been reading hacker news for about a decade, and it’s getting to the point where I don’t think there are many entrepreneurs and/or technical people on here anymore. The number of people who are saying it’s no big deal to comply with this huge law, especially for very small startups, is mind boggling. Let’s just take one feature: the requirement that you can permanently delete all of your information. Most early-…

The problem isn’t so much as there’s a cost to implementing GDPR, but that the tech community has been “move fast and break things” and refused to handle things properly before. If all you do about my PII is “set delete = 1” (which one could argue isn’t even the best practice in every scenario), then I probably don’t want you to handle my PII at all. To your example, you could easily not switch to a CASCADE, but inst…

From technical perspective, overwriting values is more deleting than deleting itself. God knows when DELETEd records will be overwritten in the database file. I once found very interesting remains in our ‘cleared copies’ of financial databases during the restoration process.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#875

Earlier quoted context omitted.

"The hacker spirit" was NEVER about harvesting user data so you could sell it to advertisers. Bite your tongue.

Yes, and? No one claims that it is. It is, however, about iterating quickly on networked software in the absence of heavy bureaucratic process. Process that is now necessary to ensure auditable, provable compliance with the letter of the law, even for activities that are already complaint with its spirit. One can argue this is necessary for society, but it's certainly a crackdown on the hacker spirit. Fun fact: GDPR…

Not about creating broken networking software or broken software in general.

Have you been in Usenet in a networking group around 2000. Good luck with these fake opinions.

Just because some startup incubator is great at grabbing words from the hacker culture ("ycombinator", "hacker" "news"), does not mean they get to redefine the meaning.

They are just greedy, greedy for money and words they can appropriate.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#876

Earlier quoted context omitted.

I've been wondering the same thing. Maybe the true hacker spirit is dead. I just want to roll my eyes when I see comments to the effect of, "Oh, it's so simple, just read the 80+ pages! The language is clear and straightforward, we promise! Also, you should have separated duties, full CI/CD that sanitizes any possible user data from leaving its hermetically sealed tier, and delete data early and often. If you don't,…

"The hacker spirit" was NEVER about harvesting user data so you could sell it to advertisers. Bite your tongue.

This is a false dichotomy that I fully reject. I feel disgust for the current generation of creepy, centralized, ad-ridden websites that make a pittance on each of us and use our data to create the next generation of (proprietary) AI.

I also don't think the _solution_ to that problem is to create a new bureaucracy and complex set of rules ("you won't be targeted, trust us!") that seems to address a "problem" (if it even is so) that is a large superset of ad-driven tech. Overcharged bureaucracy goes against the hacker spirit.

By the way, a way out of this mess seems to include crypto. We know right now that most ICOs are scams, crypto has lots of technical issues, and is in general still not ready for "prime time." That being said, when it _is_ ready for prime time, it's hard to even imagine how a crypto network could even comply with any of the basic ideas of GDPR, despite the fact that privacy is not really a concern.

How would you implement a "right to be forgotten" on a blockchain ledger? It may not even matter that the EU itself would not interfere, as GDPR also apparently creates private rights of action. Any sufficiently loony EU citizen can drag foreigners to court with gigantic lawsuits.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#878

Earlier quoted context omitted.

I have keyed in and deleted so many efforts at an answer to your question that I have given up and find myself merely asking: "Have you actually read the regs?" http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX... My reading of them finds no second/third order anything. The regs are surprisingly clear. I forgot to mention that unless you are trying to abuse EU citizens in some way then you have no problems…

> surprisingly clear This is an 88 page document with extremely dry language. Just confirming your assertion will be time consuming. No wonder many American services would rather shut out EU users than comply.

"No wonder many American services would rather shut out EU users than comply."

Good bye and good riddance. And I don't really care if the door hits you in the ass.

If Instapaper, to name an example, wouldn't do shady shit with user data, there would be no reason at all to forgo the European market.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#879
post #683

Earlier quoted context omitted.

The problem isn’t so much as there’s a cost to implementing GDPR, but that the tech community has been “move fast and break things” and refused to handle things properly before. If all you do about my PII is “set delete = 1” (which one could argue isn’t even the best practice in every scenario), then I probably don’t want you to handle my PII at all. To your example, you could easily not switch to a CASCADE, but inst…

And going through all the backups to overwrite the data? Backups that would have been written to CD or tapes?

Your backup retention policy should comply with GDPR, and you should be prepared to justify extended retention periods.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#880
post #865
post #633

Earlier quoted context omitted.

It's reassuring to hear that the GDPR is not meant to target little startups and projects but I would like it a lot better if it said that in the actual law, rather than just trusting all current and future regulators to treat me kindly. If it's only meant to be used against big companies or extreme offenders, why doesn't it say so? It seems like the spirit of the law and the language of the law are not aligned and i…

Because if your business model is based on selling user data, it doesn't matter if you're a small startup, it absolutely is meant to target you. If you aren't competent at responsibly handling personal data and you want to build a project or startup, pick one that doesn't handle personal data, or put in the effort to learn how to do things properly.

How does for example a small yoga studio’s email list fit in your examples? Or even just it’s website? Without cookies and login even - the IP adress in the log files alone is considered potential personal data that basically puts people in the need of consulting a lawyer about how to safely deal with that. And makes you a potential target to being sued and getting a lot of hassle. Even found nit guilty in the end, no one will pay days of time and energy needed for defense.

And then: What kind of online business can reasonably be done without using an email adress, if only for login/resetting password if lost? You either have no option to reset passwords, or must do it by phone, which is extremely expensive.

Post reply on HN