15 ms·
Brendan Eich Writes to the US Senate: We Need a GDPR for the United States
- aerovistae 8y agoData protection we do need indeed, but the EU is the last entity I want to be emulating on internet laws, except maybe China.
- akuji1993 8y agoI just love having internet laws written by people who can't use a computer without help. Makes so much sense...
- toyg 8y agoDo you actually know any MEP? The younger generations are less stupid than you might think. Politics is a slow game, the people who grew up with Windows 95 are only now starting to get elected.
- lowry 8y agoIn the current legislature, there is one former software programmer MEP and a Linus's uncle, who is not a programmer but knows a bit about software. There's also Julia Reda, but she is really just a filesharer and a politician.
- simion314 8y agoIs something wrong with the data protections laws that apply to medical data? Those could be expanded for all private data.
- NeedMoreTea 8y agoLike a 35 year old with a degree in information and communications technology law? Seems like he might possibly have encountered a computer or two given his special interests https://en.wikipedia.org/wiki/Jan_Philipp_Albrecht https://en.wikipedia.org/wiki/Jan_Philipp_Albrecht As well as GDPR, which is one of the better IT related laws, he has sensible views on mass surveillance.
- not_kurt_godel 8y agoWhat specifically do you take exception to with regard to GDPR/EU Internet laws? Having hands-on experience with compliance, I find GDPR to be quite reasonable - if anything, I'd say it's overly lax with regards to deletion of data that's not visible to the user (i.e. logs, 'shadow profiles', etc.).
- simplecomplex 8y agoWhat material harm or damage to you or your person did you experience prior to GDPR that GDPR has prevented or compensated for?
- not_kurt_godel 8y agoWhat material harm or damage would you suffer if I snooped on all of your Internet browsing activity with the knowledge of who you are in real life and kept that information around forever to use for whatever purposes I so choose?
- simplecomplex 8y agoStraw man. That’s not analogous to what was being discussed. A better analogy is: HN can see my email because I gave it to them to login. I don’t need to request what HN is doing with my email, because I already know I gave it to them. Giving them my email doesn’t harm me. Using it to do something illegal might, but the GDPR wouldn’t be able to stop that.
- not_kurt_godel 8y agoYou misunderstand how third-party cookies & tracking work. You also misunderstand the intent of the legislation if you think GDPR is about preventing 'illegal' things. It's about protecting individual citizens' sovereignty and privacy.
- aerovistae 8y agoMaybe GDPR is okay, I'm not terribly well informed about it. But every couple weeks the entire internet is up in arms against a new attempt by the EU to censor the entire internet, and I've been dealing for too long with the damn "We use cookies" pop-up they ignorantly required. So I'm just saying their track record isn't great.
- snaky 8y agoThat's acute, considering there's at least a couple of major competitors in every area of Chinese internet economy, unlike the Google, Facebook, YouTube and Amazon de-facto monopoly.
- Aissen 8y agoIt's funny, I was listening to the Hanselminutes, and in a recent episode, his guest (a lawyer) was underlining that the US partially created the current situation where current its companies are at loss in front of GDPR: by refusing to take the lead on data privacy issues, the US didn't have a framework for privacy laws, and couldn't negotiate a convergence of laws with the EU (I'm paraphrasing). https://www.hanselminutes.com/647/how-gdpr-is-affecting-the-american-legal-system-with-gary-nissenbaum https://www.hanselminutes.com/647/how-gdpr-is-affecting-the-...
- 18pfsmt 8y agoWhile I haven't listened to your linked episode, 'privacy laws' by definition come into direct conflict with the 1st amendment (i.e. free speech) to the U.S Constitution.
- Tecuane 8y agoI admit I'm not an American citizen, and have never actually stepped foot on American soil, but I do see the "first amendment" and "free speech" arguments being trotted out for almost anything that involves communication between two parties being restricted. This, in my experience has been common in (privately owned) web forums when an American user is banned for misbehaviour, or rules are changed to prohibit certain types of content or speech on those forums. The text of the amendment, as I'm sure you're aware, reads as follows: > Congress shall make no law respecting an establishment of religion, or prohibiting the free exercise thereof; or abridging the freedom of speech, or of the press; or the right of the people peaceably to assemble, and to petition the Government for a redress of grievances. I admit I fail to see how this prohibits introducing a law preventing an organisation from collecting data from individuals without them explicitly opting in to it.
- SamReidHughes 8y agoIn the same way that recording your interactions with the police is protected.
- smu 8y ago
- a008t 8y agoSomehow, I feel like the old, unregulated internet was better. I wonder if that is just nostalgia or there is something to it. With an unregulated internet, any internet user has to take care of their own privacy and anonymity. Barriers for entry for new websites and services are very low. Data breaches and abuses of data can lead to users being concerned about giving their data to tech monopolies, which can enable competition. Regulations like GDPR arguably make users complacent and lowers their guard, as well as strengthens the tech monopolies by adding to their moats. Would Facebook have been able to displace Myspace in the current environment? Or Google displace Yahoo? The internet was doing fine for decades with minimal involvement from governments - why change things?
- oblio 8y ago> The internet was doing fine for decades with minimal involvement from governments - why change things? Things change on their own. The internet used to be accessed by highly sophisticated and technical users. Now it's mainstream. And all mainstream things follow two basic rules: 1. Everything move at the speed of the slowest person. 2. The weakest members of the community need to be protected.
- shady-lady 8y ago> The internet used to be accessed by highly sophisticated and technical users. Quaint but that's simply not true unless you're talking pre 90's. No point in kidding ourselves. The internet was accessed by people who accessed the internet. They popped a floppy/cd in a drive and followed instructions. They then opened a browser and typed a url. Nothing sophisticated about it. Nobody was creating electrical signals by hand and sending them down a home made wire.
- oblio 8y ago> Nobody was creating electrical signals by hand and sending them down a home made wire. I think we're talking about completely different levels of sophistication. You're talking about electrical engineers vs regular users, I'm talking about levels of functional literacy... Don't forget that the average Joe/Jane has a level of functional literacy of somewhere around mid to late secondary school. The earliest internet adopters were universities (so a entirely different level of education) and after that it was middle or upper class people who could afford a PC and an internet connection plus had the interest in doing so, considering that PCs until Windows 95 were either too expensive or not very user friendly. The current internet, thanks to mobile devices and cheap, ubiquitous internet access, is truly accessible universally.
- jMyles 8y ago1) I don't agree. I prefer to have GDPR in Europe, no GDPR in the USA, and see which turns out to be better for human rights. I suspect that GDPR will very soon start to be used by corrupt politicians and other criminals who want "to be forgotten" for their misdeeds (ie, censor us when we want to remind the public). 2) I can't help but notice that GDPR is a great idea for Brave / BAT. And look: I'm long on BAT (I'm not wealthy enough to be a whale or anything, but I bought a small amount in the very early days). But this seems self-interested to me, rather than an assessment of the proper course for American politics. Eich admits this in part, of course, saying early in the letter that "I view the General Data Protection Regulation (GDPR) as a great leveller. The GDPR establishes the conditions that can allow young, innovative companies like Brave to flourish." But he also says "The enormous growth of ad-blocking by people across the globe (to 615 million active devices by late 2017) proves the terrible cost of inadequately regulating the tracking-based advertising system." Does it? It seems to me that people are working to find ways to improve their lives, and that they'll keep doing so to the shegrin of the internet behemoths absent any "regulation". In other words, the state is not needed to make this phenomenon regular - it's already quite regular and becoming moreso. Let Brave and Chrome fight it out and the best (not the most politically expedient) one win. For now, I'm using Firefox.
- realusername 8y ago> GDPR will very soon start to be used by corrupt politicians and other criminals who want "to be forgotten" for their misdeeds GDPR isn't the right to be forgotten, it's mainly about ownership of customer data, consent & privacy. You can have a look at this developer guide: https://techblog.bozho.net/gdpr-practical-guide-developers/ https://techblog.bozho.net/gdpr-practical-guide-developers/ for what it means as a developer.
- jMyles 8y ago> GDPR isn't the right to be forgotten, it's mainly about ownership of customer data, consent & privacy. I'm not sure if you're making a humorous observation about how the "right to be forgotten" is not a legitimate form of privacy. If you are, bravo. If you're not, and you are actually unaware of article 17, please see this link: https://gdpr-info.eu/art-17-gdpr/ https://gdpr-info.eu/art-17-gdpr/
- aaaaaaaaaab 8y agoI wish him more luck than he had with California Proposition 8.
- miracle2k 8y agoThe practical effect of GDPR seems to me that I have to click away about half a dozen consent popups every day. Sometimes a cookie warning in addition to that. If I use Private Browsing (to protect my privacy) I am punished with more popups. If I open a website within a browser shell on mobile that doesn't have my cookies (some kind of webview of an app), I am punished with more popups. Am I expected to look at every one of those dialogs and figure out what I have to click to "customize" my tracking? Then there are the technical problems; one of those consent "solutions" that you see around actually shows a spinner while your "preferences are being saved". Sometimes it never closes. I am frankly already so tired of this that I don't even care to look which of the buttons says "Agree" and which one says "Refuse". I just click on whatever I see. I know for certain that for less experienced users (my parents), every additional button to click is just another hindrance to achieving what they need to do. The thought "what if I click the wrong thing" is a permanent companion of their computer use. These are very real, very concrete negative effects of GDPR. Is there something that we gained to make me feel better next time I am annoyed with all the popups?
- Cthulhu_ 8y agoTL;DR yes, yes you do; the sites have to ask for explicit content, and that's the patterns they use to give you (or, the EU) what you/they want (fine-grained control over what they can use your data for). In practice, it's not something people care about because they just want to get to the content and don't care about the cost. The EU / GDPR and internet rights activists care for your sake. Of course, these fine grained access controls are also a dark pattern, make it annoying and look difficult just so you consent. There's even a few out there that take a minute with a spinner going "Please wait, storing your preferences..." even if just hitting "accept" is instant. As is "cancel". Dark patterns.
- OskarS 8y ago> These are very real, very concrete negative effects of GDPR Your annoyance is misplaced. Don't be annoyed at GDPR: be annoyed at all the companies who have spent the last decades building an entire web-infrastructure with zero respect for user privacy. We built massive amounts of technology infrastructure that just assumed that privacy and tracking wasn't an issue. Why do these websites need all these cookies in the first place? If I'm visiting a random blog with no advertising on it, why is it asking my for cookie consent? What possible purpose could that cookie serve, except tracking users? As an analogy, imagine taking a black-light to a hotel room and realizing that the room is absolutely filthy. Would you be angry at the black-light for revealing the filth to you? Or would you be angry at the hotel, for not properly cleaning up? If cookie consent forms or GDPR compliance forms annoy you, don't blame GDPR. Blame the sites that have no regard for your privacy and make no effort to comply beyond throwing up annoying prompts.
- cinquemb 8y agoIt's somewhat amusing watching the overt rhetoric of advocating for data privacy enforced by governments when the majority of even technical people understand covert exploitation that is happening by said governments (and leaked to n number of 3rd parties [non govs, ngos, even the public occasionally via incompetence/leaks/hacks, etc] around the world on an increasing basis), which has the dual benefits of making the uniformed or willful ignorant feel good without actually changing the state of things.
- simplecomplex 8y agoYup, and notice not a single person crying about privacy has been materially harmed from companies using their information to target ads or provide better products.
- kodablah 8y agoIf legislation is really required, and I'm not convinced it is, can we start small? This stuff never gets rolled back and tech companies' use of personal data is the new terrorism. Again I'll take none, but if this ridiculous fervor that's been built requires something, how about not-tech-specific rules around data sharing transparency? Just require details on what's shared and with whom for those seeking it (ideally companies publish it to prevent requiring individual request/response scaling issues, but their choice). You're gonna find most people don't care anyways, so they shouldn't be burdened with more hardline privacy requirements. Just increase the visibility for now. And please please learn from EU mistakes and establish enforcement mechanisms. Don't just make exorbitant ceilings and move on. Have a framework to punish violators, and again start with small legislation until it can be shown enforcement occurs and is working. Having said all that, can we just start with pro-privacy PSAs, education, targeted advertisement awareness, punitive measures for breaches, and relaxation of legislation preventing me from scraping/manipulating/proxying these sites however I want? If we all have to hire lawyers and/or compliance assistance, then the first step is too large. We can make our way towards delete-all-my-data-on-request laws later. Not sure what made this an emergency (actually I do know based on media and political driven fervor, but that will be best studied through the lens of history). But all these tech people, OP and commenters here especially, don't speak for many people who accept the current state or reasonably understand heavy-handed government regulations on the internet bring more bad than good. And for goodness sake, don't use the domain of your should-be-neutral software to make a political post. You aren't gonna feel any pain now because you are in the same line with other popular pitchfork wielders, but your political leanings have bit you before, why would you associate your company with them?
- kiriakasis 8y ago> And please please learn from EU mistakes and establish enforcement mechanisms. Don't just make exorbitant ceilings and move on. Have a framework to punish violators, and again start with small legislation until it can be shown enforcement occurs and is working. There are enforcement mechanism in the GDPR. IMO they also are quite good. The max fine are huge, but there are mechanism to help misbehaving companies into compliance and also protect companies from random lawsuit by individuals.
- matchagaucho 8y ago"Right to be forgotten" is a core tenant of GDPR. It'd be interesting to see if the U.S. would enforce the hard delete of social media profiles upon opting out.
- scoom 8y agoSomething to torpedo tech everywhere. Yay!
- frockington 8y agoMaybe if the US regulates hard enough, they can stifle progress and become like Europe!
- denysonique 8y agoI don't want it to end up in annoying dialog boxes and degraded UX on every website like it currently is in Europe.
- furicane 8y agoThat's great. I don't want my information stored, analyzed, cross-referenced and re-sold around without me knowing what's going on. Oddly enough, you're frustrated about "degraded UX", but for several years now - UX has been terrible with annoying popups asking you for your email, advertisement-ridden websites that attracts traffic via well-crafted titles while the content is something to be desired... Don't be a peon. But if you decide you want to be one, think about your other fellow humans - maybe they don't want to be peons.
- simplecomplex 8y agoYour information is still “stored, analyzed, cross-referenced and re-sold” and even though the GDPR doesn’t stop that, you feel better because you “know that’s going on”. I don’t get it. Have you ever been materially harmed by businesses storing, analyzing, or reselling information regulated by the GDPR?
- alkonaut 8y agoThe GDPR is mostly good. The right to find out and delete the data is excellent. The bad thing is the constant consent popups which have become synonymous with the GDPR. Obviously there are also still a lot of sites that try to wiggle around the GDPR by saying "By entering the site you agree to X", a practice that should soon be found to be in violation of the regulation. If that is allowed, the regulation for storage/processing becomes almost pointless. That data collection should be opt in if it isn't an essential function of the app/site/service.
- icebraining 8y agoIt's certainly in violation - Recital 43 is quite clear on that.
- deleted 8y ago[deleted]
- deleted 8y ago[deleted]
- exabrial 8y agoGdpr makes using websites a terrible user experience with the million cookie prompts. My parents will click on anything to make popups go away. Please no.
- the_gastropod 8y agoReally strange that the Brave website of all places includes a Javascript that hijacks your native scroll. Why is that smooth scroll library so popular? It's really obnoxious.
- JumpCrisscross 8y agoI would prefer starting small and cautiously scaling up. “If you lose my data, you are strictly liable” is a good start because it lets case law work through the holes. (It also causes companies to see personal data as an asset and a liability, not just the former.) Full-blown GDPR is overkill. It makes more sense to wait a few years and see if the situation in Europe evolves differently from the U.S. I personally believe the law fails to incentivise the sort of behaviour it aspires to, but that’s merely a hunch—better to wait until we have data.
- brynjolf 8y ago"This is not the time to talk about guns"
- JumpCrisscross 8y ago> This is not the time to talk about guns That’s disengenuous. I’m saying this is the time to talk about data. But instead of coming out of the gate with a gargantuan salvo or complicated, expensive and unpredictable regulation, let’s start small and work gradually.
- PatentlyDC123 8y agoI agree with the sentiment of starting small, but your example of strict liability might be starting too strong. Personally, I would start with a lower mens rea. Maybe I see the situation differently, but I believe most of the subjects covered by GDPR are distinguishable from areas of law such as, e.g., products liability, that utilize strict liability.
- simplecomplex 8y agoNo we don’t. There’s no privacy problem that needs solving. Brendan Eich is seeking protection for his failing business from the government. He wants to use the force of law to make his browser more competitive. I’ve got a better idea: let’s make JavaScript illegal. That’ll hurt the advertising industry too!
- Chris_Chambers 8y agoGDPR is absurd and I refuse to take any steps to comply with it. How on earth can I be expected to precisely know if a visitor is in the EU? Do I use an unreliable geolocation database, a shot in the dark based on IP? Do I check the default system language and ridiculously assume it somehow indicates the country the user is currently in? And what about the pop up itself? If I display it in the wrong language (showing English to a French user for instance), then am I even in compliance? Just one wrong guess and I’m screwed. Who do I consult for answers on this? Life ruiningly expensive lawyers? One wrong answer from them and I’m screwed. It’s all bullshit. The day some prick in the EU comes after me for not implementing GDPR is the day I disable all monetization, sell my business to some entity that is probably a hundred times more evil and greedy than I am, and retire early.
- mychael 8y agoThis is so misguided. GDPR is a disaster and only entrenches large companies.
- BrendanEich 8y agoNo, big companies have the greatest business-plan, tech, and compliance debt and are slowest to change -- the bizplan debt alone can be retired rapidly only at great risk of breaching fiduciary duty to shareholders. Neither Google nor Facebook is in compliance with GDPR. FB was busted using 2FA phone number for ad targeting. Google has been taking data for various purposes for decades and linking it all together for other purposes. These are bright-line violations of GDPR's purpose-limitation design. Smaller companies, by contrast, can change more quickly or start with compliance by construction, as Brave has. It's a silly slogan that GDPR only helps big incumbents. Regulation tends to help incumbents under varying degrees of regulatory capture, as in the US. Europe is different, and India, Brazil, and others jurisdictions are following suit. California's CCPA is weaker (on protected data, opt out rather than opt in, ambiguity about duress = denial of service if off-purpose data not provided, enforcement), but also in line.
- desireco42 8y agoI am sick and tired of auto playing videos, popups etc. It is not GDPRs fault, media companies are milking us. Yesterday I got to an article that was covered with overlays and popups. You couldn't even see the title. I realized, I didn't care that badly to read it anyway and abandoned it. Strangely, we are still enduring this terrrible UX experience, mostly because we don't have good alternatives or those that exist, are not known. I think we should spend time creating those and discovering and promoting healthier information sources.
- Tsubasachan 8y agoGood luck getting that through Capitol Hill. The Republicans are scum ofcourse but its not like the Democrats don't get funding from vested business interests...
- dang 8y agoWould you please not post flamebait to HN, or use it for political battle? https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- throwawaymanbot 8y agoLooking at the popular comments.. I just dont think that Americans get it. They are already indoctrinated to the corporate prison thats going to factor in to their lives in about 20 years.