Live data from Hacker News

GDPR for lazy people: Block all European users with Cloudflare Workers

apility.io

941–950 of 1001 posts

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#941

Earlier quoted context omitted.

I disagree strongly. "...cascade delete is only easy if you’re a very experienced programmer or who knows what he’s [sic] doing." No it's not. Nothing could be easier than foreign key constraints & cascade deletes in a relational database. It's literally "built in." If you're a garage-startup, you're unlikely to be slapped with fines under GDPR. Let's be honest- if you're a garage startup you're lucky to be noticed b…

> If you're a garage-startup, you're unlikely to be slapped with fines under GDPR. Let's be honest- if you're a garage startup you're lucky to be noticed by anyone, much less European regulators. You might be noticed by your competitor, who reports you to the regulator. > The argument expressed here is sleight of hand: complaining about the supposed impact on "the little guy" when the regulations themselves are desig…

And if you're flagged to the regulator, what do you think is going to happen?

They'll contact you and let you know there's a problem, and you need to fix it - that's it.

If you continually flout the regulations after being warned then sanctions will be escalated.

Half the world is running around saying "I'm going to be fined 20 million euros!" and it's just fear-mongering.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#942

Earlier quoted context omitted.

You don't necessarily have to delete stuff from cold storage right away. You just need to have a process to remove deleted PII when you retrieve/rewrite your backups.

This might be a bit of a weird question, but how do you remember which information needs to be deleted when you're at the point where you need to use backups?

How long are you keeping backups in cold storage for - usually you'd want maybe 6 months there, but no more, otherwise it's just going to grow unbounded and become a financial burden.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#943

Earlier quoted context omitted.

> This culture has driven innovation of the last 2 decades. So what? Communism turned feudal Russia into a world superpower in less than 2 decades. Do the ends justify the means?

Not making a moral argument. @gkya's comment paints a picture where entrepreneurs unhappy with GDPR are perhaps just a small contingent of incompetent amateurs who shouldn't be doing business in the first place. While I, in agreement with OC/OP, see it as a threat to the entire industry.

Nearly, what I think is that, those unhappy with GDPR are either malevolent actors or incompetent people. And I think the bar to entry to the industry should be elevated (while bar to entry to learning ones way to that bar and to hacking should always be as low as possible; but you can't hack together and end user product, period).

BTW I'm not in the US not in a country where GDPR is effective. But I CRAVE that my country implement the same measures or better. Unfortunately that's unlikely.

Finally, it's a threat to the bad part of the industry. And then there are those who exaggerate the situation while they are not really affected by the regulation. But the hysteria will diminish and hopefully most of the bad actors wil either change their business or just go out of the industry, searching for other places to exploit (which hopefully they will not find).

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#944

Earlier quoted context omitted.

This culture has driven innovation of the last 2 decades. You can't point me to one other industry which enjoyed as much success. Of course, Europe couldn't care less - they never had a real startup industry in the first place.

The other side of this is that the GDPR puts all those companies from jurisdictions with no privacy regulations to speak of in front of a choice to either stop doing business with a huge market or actually stop ignoring privacy concerns. The important consequence of this is that it puts EU startups on more equal footing than in the past. Most EU countries already had fairly solid privacy regulations, some more, some…

> The important consequence of this is that it puts EU startups on more equal footing than in the past.

I can easily say that if I had to choose between a US service and an EU one, from now on the answer is almost always the EU one.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#945
post #913

Earlier quoted context omitted.

I'm a Brit. I am the MD of a small IT company. I have two partners and 20 employees. We started in 2000. We turn over about £1.5Mpa. We sell our services to people and organisations. Our backups are now smaller these days (thanks to GDPR). I understand that because you are outside the EU you might feel like a target but that is not the point of GDPR. There is no way on earth that the EU as a whole has looked on your…

The thing for me is that it requires me to log additional data. Now I need to know where my users are from, how old they are, and how often and how they access their account. All data I happily ignored so far to increase privacy.

>Now I need to know where my users are from

Why do you need to know that? Why don't treat all users with respect?

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#946
post #913

Earlier quoted context omitted.

The thing for me is that it requires me to log additional data. Now I need to know where my users are from, how old they are, and how often and how they access their account. All data I happily ignored so far to increase privacy.

>Now I need to know where my users are from Why do you need to know that? Why don't treat all users with respect?

What respect? Saving additional metadata?

I totally get your point. But my product already focuses on privacy. Saving any kind of metadata/communication data is more than I do now.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#947
post #909
post #244

Earlier quoted context omitted.

I feel the EU regulators could stand to learn something. If EU citizens are small portion of your users, and your tasked with parsing this document http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX... just blocking them doesn't seem like that bad of an idea, especially with the fines involved. I think the things that bother me is: 1) A College student working on a side project with no revenue are treated t…

> I think the things that bother me is: > > 1) A College student working on a side project with no revenue are treated the same as some massive multi-national. That's false. The GDPR repeatedly refers to evaluating the risk with regards to various decisions. The ICO even has separate guidance for small businesses and big businesses. > 2) It's a foreign requirement that feels like a violation of sovereignty. Most busi…

"You're violating our laws that protect our citizens. Why would we possibly have any sympathy for that?"

No one forced your citizens to come to my website.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#948

I’ve been reading hacker news for about a decade, and it’s getting to the point where I don’t think there are many entrepreneurs and/or technical people on here anymore. The number of people who are saying it’s no big deal to comply with this huge law, especially for very small startups, is mind boggling. Let’s just take one feature: the requirement that you can permanently delete all of your information. Most early-…

I’ve been reading web news for over a decade, and it’s getting to the point where I don’t think there are many hackers and/or privacy sensitive people on here anymore.

The number of people who are saying it’s no big deal to ignore privacy rights that should be law, especially for sensitive information, is mind boggling.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#949

Earlier quoted context omitted.

Equivocating mishandling user data on a project that some kid in a dorm made for fun, which collects maybe an email address. With putting someone in the hospital with food poisoning is beyond a dishonest comparison.

So? Projects like that aren't forbidden now that the GDPR is in force. Just put up a paragraph explaining why you need that email address, an unchecked checkbox if you want them to agree to send irrelevant emails, and you're done. When corporations like Equifax or Cambridge Analytica have engaged in identity theft to the tune of basically half the continent of North America, you want to repeal one of the few laws fig…

> Just put up a paragraph explaining why you need that email address, an unchecked checkbox if you want them to agree to send irrelevant emails, and you're done.

Oops, seems you’ve forgotten about the “right to be forgotten”, and several other requirements. Better prepare yourself for those >$20 million fines — how dare you negligently handle personal data, college software engineering student!

I’m all for strengthening privacy protections and punishing bad actors in this domain, but designing strong regulations that don’t have seriously bad unintended consequences, is a really really difficult task. I’m not necessarily saying it shouldn’t be done; just that I don’t envy the jobs of those trying their best to do good for the world via regulations without accidentally destroying some really good things.

It may turn out that GDPR has few unintended negative consequences, or it may turn out the harmful side effects are far more severe than anyone predicted. Only time will tell, I suppose.

Personally, I wish there were a technical solution to privacy concerns — something akin to DRM, but applied to each individual’s personal data to prevent it from being used in unauthorized ways. That’s about the only kind of DRM I think I could really get excited about :)

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#950
post #897

Earlier quoted context omitted.

driving innovation while having the biggest number of homeless people in the streets and no health care.

Not even close[0] There is healthcare in America[1] [0] https://en.wikipedia.org/wiki/List_of_countries_by_homeless_... [1] Doesn't actually need a source

Holy shit. As a Canadian who moved to the US, that was quite surprising.

Homeless people in big American cities are everywhere. In the couple of large Canadian cities I lived in, they were present, but not nearly as much. I guess Canada is better at hiding the problem.

I'm mostly surprised though that the Canadian social safety nets don't prevent it from happening more. As a kid my family was.... "not doing well" (understatement), and we were able to bounce back up and avoid becoming homeless reasonably easily by using every program imaginable (it took a lot). In the US, we would have been screwed. Yet those numbers...

Post reply on HN