4 ms·
HN has been overrun by MBAs a long time ago
by zerostar07 8y ago
HN has been overrun by MBAs a long time ago
- lomnakkus 8y agoI'm not sure whether you're agreeing or disagreeing with your parent comment, but I'm just tacking this on there because it feels right: I think HN has just hit peak stupidity. The amount of paranoia, misreading, misunderstanding, etc. about the GDPR is just insane (or intentional shilling, but let's not go all tin-foil-hatty prematurely). Nobody who's doing anything even remotely above-board is panicking or anything of the sort. If you weren't already mostly complying with the GDPR (paperwork notwithstanding) your security practices and/or business practices were sloppy and/or dishonest and/or exploitative to begin with. EDIT/Addendum: People who are not in the know are (somewhat understandably) a little bit nervous about "interpretation" and such, but there's a reason there's a "sliding scale" of potential penalties. Regulators don't tend to go for people/companies who are actually trying to do the right thing. They go for the people/companies who are the most egregious violators. (I hope I don't have to explain the reasoning behind this, but do ask if you're confused.)
- zerostar07 8y ago> paperwork notwithstanding thats the main point for me. Some of GDPR is good: right to delete in a reasonable fashion is great. Right to not be personally identified is awesome, but that's much easier to do in the ISP level. Adtech creates problems - that should mean you have to regulate adtech. But GDPR is more about documentation, bureaucracy and Vista-style popups than about how to protect data. You need a lawyer just to put ads on your site. It's a draconian law designed by a single-issue Green leftist, which relegated IP addresses to the status of some kind of fatally dangerous information. It breaks the web from a "web" to a series of tubes with doors in between. The severity of the law is out of proportion with the average internet user's concern about privacy: time and again people have shown they just don't value it as much as the law suggests. After a few days, when the cheerleading has stopped people are going to be faced with some unpleasant realities: small business switching to facebook (because otherwise their website would contain more legalese than content) and ecommerce turning more towards the large marketplaces. In this sense, Facebook, Google and ebay/amazon become one-stop shops for GDPR-compliant solutions. The reason: GDPR removes options but offers no alternatives.
- lomnakkus 8y agoThis is paperwork you should already have in some form if you're actually following (and I hate this phrase) "best practices" for customer data and trying to explain to your employees how to handle a (suspected) security breach, etc. IMO, it's good to actually at least try (as a company) to come with some sort of consistent set of guidelines as to how a security breach should be handled. And a company-wide policy on how company laptops should be treated (disk encryption, etc.). It's just that nobody actually bothered to actually do these things because the potential penalties were absolutely trivial. I know of at least one company which chose to just pay the regulator in their country a monthly fine instead of fixing the problem because it was cheaper than paying developers to fix the issue. How is that not broken? (I should say that I have problems in which this was "released", so to speak, since there hasn't been time for any establishment of practice based on the intent of the law, etc. It should definitely have been a gradual rollout, but that's not really relevant now that it has been "released".)