Live data from Hacker News

GDPR for lazy people: Block all European users with Cloudflare Workers

apility.io

981–990 of 1001 posts

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#981

Earlier quoted context omitted.

> I see that as a symptom of thoughtless hoarding and unreasonable prying It's a symptom of people not paying for content and news. Also the fact that publishers want to provide equal and easy access to everyone regardless of affordability. > demonstrable, substantial benefit to all this for the end-user it might make a bit more sense. The content you're consuming.

Guess what sir/madam? when I started using the net, there was plenty of great content on bulletin boards and on usenet. And when the WWW started up, there was plenty more great content. SHARED. Eminently affordable. And very, very social. People talking to people, with no overseer/exploiter in between. > publishers want to provide equal and easy access What they want is money. 'Content' is what they've got to sell. A…

> ou're never going to convince me that the commercialization ... is an improvement.

Ok, then live in the past I guess? Both content quality and quantity has vastly increased over the past 2 decades to meet the modern demands of billions of people who are now online. This is fact, the world has moved on. Either way you are not the arbiter of what is valuable content or not for someone else. People choose for themselves.

Yes, publishers are businesses. They must make money to create commercial content. This doesn't mean there isn't free content available, and in fact there's more of it than ever before due to the trivial costs of publishing media, but the rest of the stuff has to be paid for somehow.

As stated, consumers do not like to pay (often due to bad value assessment and inability). Ads are much more granular, passive, and equally accessible whether you're a billionaire or a 3rd-world farmer. This also doesn't mean subscriptions and other patronage options don't exist, there are millions examples of those as well.

Does the implementation of advertising online suck? Yes. It's slow, frustrating, privacy invasive and filled with fraud, but you're talking to one of the few people who has pushed for regulation for the last 5 years. It's not a new complaint and it'll take time to change a 12-figure global industry.

However if you think the world hasn't benefited from the commercialization of the internet, with education, entertainment, and information creating progress in every corner of the world, than you are most definitely not in the majority. You're actually in such a minority that it's basically considered the same as any other conspiracy group and largely irrelevant in any serious economic, societal, political or business discussion.

I recommend revising your perspective and acknowledging the differences between advertising as a concept vs the implementation, and especially the progress that it has brought that has led to the world that you seem to take for granted today.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#982

A trend I've noticed from lurking and browsing these comments: commenters who have experience taking risk and operating under existential conditions in stressful, budget constrained companies (AKA, startup founders) tend to be critical of the GDPR. Commenters who work as 9-5 employees or have never started a company (or at least, don't mention as having done so in their profiles) tend to be more supportive of the GDP…

A little nuance to your stats: I've spend the majority of my career in startups, mostly my own, many times struggling to survive. Never worked in a comfy big corp. I currently work in a startup and my hours are far from 9-5.

I support GDPR. It's the first reasonable solution to privacy I've seen. And I hated the cookie alerts. The transition is tough and we're fighting to figure it out at the moment. But the basic principles in GDPR are solid.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#983
post #962

Earlier quoted context omitted.

This culture has driven innovation of the last 2 decades. You can't point me to one other industry which enjoyed as much success. Of course, Europe couldn't care less - they never had a real startup industry in the first place.

I actually think it is exactly the opposite: the culture like this was killing the innovation. That is reason biggest companies are ads companies: Facebook, Google, Twitter, etc. And that is the reason companies like Oracle and other will still make big $$ - why? Because you cannot "break things and sell ads" and do "delete=1" when you are developing RDMBS.

I find this pretty rich. Breaking things and selling broken stuff to clients, and then turning around and selling them expensive consulting services is pretty much the biz-model of Oracle.

And then there's this: "In 1990, Oracle laid off 10% (about 400 people) of its work force because of accounting errors.[53] This crisis came about because of Oracle's "up-front" marketing strategy, in which sales people urged potential customers to buy the largest possible amount of software all at once. The sales people then booked the value of future license sales in the current quarter, thereby increasing their bonuses.[54] This became a problem when the future sales subsequently failed to materialize. Oracle eventually had to restate its earnings twice, and also settled (out of court) class-action lawsuits arising from its having overstated its earnings. Ellison stated in 1992 that Oracle had made "an incredible business mistake."[53]"

So Oracle isn't a particularly good example of a well run business with good internal processes (I also wouldn't put them in a list of ethically run companies either)

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#984

Earlier quoted context omitted.

Clearly you have a different definition of entrepreneurs/technical people than I do. Those seems like impositions on people who implement bad practice or work in fields that have morally questionable practices regarding people's data and identification. Many people I know don't engage or work in such industries because of the moral implications of doing so and what people are doing with data. Its not about "just ask…

Again, I was in my early 20s and fresh out of college. I had no idea what I was doing. It’s not that I was trying to cut ethical corners or do things poorly, I just didn’t know what the right way to do things was. Computer science education is often very theoretical and high level and not at all practical . I’ll be the first person to say that I was not the most experienced and or talented programmer in the world, bu…

Perhaps this is a cultural difference, but I've collected names and addresses and phone numbers, and I worked under legislation where I can go to jail if i disclose the information i saw or had access to.

Later, outside of that legislation, when I'm collecting it, I deal with the Australian Privacy Principles [0].

It doesn't bother me that much, because I take a "well if we don't need it, we shouldn't be collecting it, and if we are collecting it, we should do so minimally and protect it anyway."

I believe under GDPR, if you need it, you can collect it. If you don't need it, why would you be/collecting or holding it?

There are certainly legal problems/ambiguities around ip and data collection, and yes, its usually legislated by people who really don't understand tech or information theory or data linking, but frankly I haven't heard very many legitimate ones brought up in relation to GDPR.

What I think someone naive and fresh out of college would do, for instance, when asked to delete data is...delete data.

And if they think that "delete my data" means go through a database and put a '1' in a delete flag against a record that is still retained, then I think they're not so naive, they picked that up somewhere from someone acting nefariously who told them it was "best practice".

And if they picked that up somewhere and it is industry "best practice", that's the kind of bullshit we should be weeding out of the tech industry.

If the user can't view/delete their data, that's a dark pattern. Which again, see above: needs to be weeded out of tech.

[0] https://www.oaic.gov.au/privacy-law/privacy-act/australian-p...

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#985
post #897

Earlier quoted context omitted.

driving innovation while having the biggest number of homeless people in the streets and no health care.

Not even close[0] There is healthcare in America[1] [0] https://en.wikipedia.org/wiki/List_of_countries_by_homeless_... [1] Doesn't actually need a source

Firstly, that list is useless because you're comparing wildly different definitions of "homeless". The US was counting

> The U.S. Department of Housing and Urban Development released its annual Point in Time count Wednesday, a report that showed nearly 554,000 homeless people across the country during local tallies conducted in January. That figure is up nearly 1 percent from 2016.

> Of that total, 193,000 people had no access to nightly shelter and instead were staying in vehicles, tents, the streets and other places considered uninhabitable. The unsheltered figure is up by more than 9 percent compared to two years ago.

While the UK was counting

> The study, by housing charity Shelter, found that 307,000, or one in every 200, people are now either sleeping rough or in temporary accommodation.

Temporary accommodation includes bed&breakfast, staying with friends, emergency shelters. There are about 5000 people sleeping rough in the UK at the moment in a population of about 60million.

And then look at the countries who have worse homelessness than the US.

Nigeria, South Africa, Russia, Indonesia, China, Haiti, Venezuela, India, Zimbabwe, Honduras, Ukraine.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#986

I’ve been reading hacker news for about a decade, and it’s getting to the point where I don’t think there are many entrepreneurs and/or technical people on here anymore. The number of people who are saying it’s no big deal to comply with this huge law, especially for very small startups, is mind boggling. Let’s just take one feature: the requirement that you can permanently delete all of your information. Most early-…

If you don't have the ability to delete a user from your database, you got issues.

Getting a banking permit requires an awful lot of money and you have to go though a lot of bureaucracy to get it, do you also have a problem with that?

What if a startup leaked your private data, like Equifax did? would you still feel the same way about this?

If the industry would have been able to self regulate, big bad government wouldn't have dropped the hammer on them.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#987

I’ve been reading hacker news for about a decade, and it’s getting to the point where I don’t think there are many entrepreneurs and/or technical people on here anymore. The number of people who are saying it’s no big deal to comply with this huge law, especially for very small startups, is mind boggling. Let’s just take one feature: the requirement that you can permanently delete all of your information. Most early-…

“...it’s no big deal to comply with this huge law”

Sorry but this comment has been driving me crazy. The GBDR about 100 pages? Obamacare is 20,000.

This law may be a lot of things. It may have a huge impact. It may require companies to do things hugely differently. It may require a huge amount of work for some. It could do a huge amount of good or bad.

But, it is NOT a huge law.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#988

Earlier quoted context omitted.

"The hacker spirit" was NEVER about harvesting user data so you could sell it to advertisers. Bite your tongue.

Yes, and? No one claims that it is. It is, however, about iterating quickly on networked software in the absence of heavy bureaucratic process. Process that is now necessary to ensure auditable, provable compliance with the letter of the law, even for activities that are already complaint with its spirit. One can argue this is necessary for society, but it's certainly a crackdown on the hacker spirit. Fun fact: GDPR…

I don't agree that keeping track of data processing operations, where you store data, creating an ability to delete user data and basic security hygiene is onerously burdensome on projects where you know about these requirements ahead of time. Yes it absolutely is a major pain in the butt for existing projects but that's a different argument and not a good reason not to improve consumer protections.

> Meanwhile all networked software is illegal by default unless its operator can prove that it stays within the defined GDPR exceptions.

This doesn't make sense to me. Can you please instruct me how I would go about suing the curl project? Please help me understand how this networked software is "illegal by default." I actually don't understand precisely what you mean by "networked software" so perhaps my misunderstanding lies there.

Overall I find statements like this "all networked software is illegal" to be FUD hogwash. It's just the same as when environmental regulations are going to "destroy the energy industry" and labor regulations are going to "destroy the service industry" etc.. Industry (represented here by tech entrepreneurs) is doing their typical disingenuous wringing of hands they always do when consumer/worker/environmental protections are brought forth.

Let's get rid of the GDPR, the EPA and the Paris climate accords while we're at it.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#989

Earlier quoted context omitted.

Yes, and? No one claims that it is. It is, however, about iterating quickly on networked software in the absence of heavy bureaucratic process. Process that is now necessary to ensure auditable, provable compliance with the letter of the law, even for activities that are already complaint with its spirit. One can argue this is necessary for society, but it's certainly a crackdown on the hacker spirit. Fun fact: GDPR…

I don't agree that keeping track of data processing operations, where you store data, creating an ability to delete user data and basic security hygiene is onerously burdensome on projects where you know about these requirements ahead of time. Yes it absolutely is a major pain in the butt for existing projects but that's a different argument and not a good reason not to improve consumer protections. > Meanwhile all n…

>suing the curl project

Any server you curl is processing your personal data by addressing the HTTP response to your IP address. Curl itself arguably fails "privacy by design" test in that there is no Tor, etc. enabled by default, although I admit that's a stretch. The entire HTTP protocol design of obtaining documents by interacting directly with their publishers is similarly careless from a privacy perspective.

>"all networked software is illegal"

It's not always illegal. It's illegal by default, and up to you to demonstrate that it falls within one of the defined exceptions.

>"destroy the energy industry"

I'm quite happy that only serious and well-capitalized entities can surmount the regulatory hurdles to running a smoke-billowing power plant. I'm not happy that we're doing the same things to websites.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#990
post #53

I keep seeing these posts on how to block European users to avoid the GDPR. As a citizen of Europe, seeing these posts consistently making it to the front page is disappointing. It would seem that Silicon Valley perceives the GDPR as more of a hindrance than an opportunity to offer users better privacy. Nothing has been learned.

My gut tells me Europe will use GDPR to further attack (and fine) large US tech companies (Facebook, Google, Apple, etc.). Everybody is likely breaking these sorts of laws in some small way, but I doubt the EU will bother going after a small startup. If you can't avoid a lawyer, I doubt you're worth being prosecuted.
Post reply on HN