9 ms·
Show HN: Ship Your Enemies GDPR
- sparrish 7y agoEU-enabled DDoS attacks. Expect automation developments on both the attack and the mitigation side to grow until it's cost prohibitive to do business with those in the EU and companies simply stop offering services to its members.
- mike-cardwell 7y agoHopefully. It will be a good thing to see these privacy abusing services/companies ceasing to exist in the EU.
- TomMarius 7y agoAt least 90% of sites [in the Czech Republic] required to implement GDPR are not abusing privacy
- yeppie 7y agoWhat does that even mean? Where did you get the 90% from? Do you have a list of said sites? Not abusing privacy according to whom?
- TomMarius 7y agoWell abusing privacy is a punishable crime here, so according to our courts - do you say you don't trust the courts of a western, functioning, EU member country? The figure is definitely way higher than I said since only a handful of website operators have been found guilty ever since the law is active. The law is not an exhaustive list btw. > Do you have a list of said sites? You are the one who claimed that all sites required to implement GDPR are privacy abusers. Do you have a list? In my country we adhere to the concept of "innocent until proven guilty" and we don't keep lists of innocent websites.
- solarkraft 7y agoSo it should be really easy for them to implement.
- TomMarius 7y agoI had to implement it and it is definitely not easy for me. It involves e.g. setting up, collecting, reading and reacting to snail mail.
- Proven 7y agoSmaller (aka "less evil") companies are the first to go. Well-connected. large ones will outlast everyone (lawyers, temps, AI, etc.). The socialists behind that site don't understand there's a civilized way to deal with your "enemy": stop doing business with them. But I fully expected the violent sociopaths would prefer to employ the EU to do destroy private property on their behalf.
- nxc18 7y agoOr companies might just make the effort to take their governance of user data seriously. Once you've complied once, you should be able to comply for everyone else automatically. See Google takeout.
- vonmoltke 7y ago> Once you've complied once, you should be able to comply for everyone else automatically. How do you automatically comply with a free-form letter sent via e-mail or, even worse, snail mail? You need one or more humans in the loop to identify these requests, even if it is just to send a canned response back.
- theamk 7y agoYes, but the balance of power is in the favor of the company. You can have thousands of people send GDPR requests. Each person will take at least half an hour to print, compose, wrap and send letter. And someone at the company will take under a minute to reply to each one, because all they'd need to do is a quick scan of the letter, then send a pre-printed response.
- TomMarius 7y agoI don't even have a mailbox and now I need to have one, and actually read the mail - which I'm unable to even reach as I'm often thousands of kilometers far. Will you do it for me? I just wanted to have comments on my site... Not all websites are ran by huge companies. Actually, most are not.
- vonmoltke 7y ago> Each person will take at least half an hour to print, compose, wrap and send letter. The point of this site is that there is no composition. Just print, address, and send if you want to snail mail. If that takes you half an hour, I don't know what to tell you. > And someone at the company will take under a minute to reply to each one, because all they'd need to do is a quick scan of the letter, then send a pre-printed response. Under a minute to 1) identify the letter and the sender; 2) pull the correct pre-printed response; 3) address and send the response? How does your hypothetical employee do this so much faster than your hypothetical private citizen?
- solarkraft 7y ago... Or the companies that don't abuse users' data implement simple mechanisms to comply with GDPR and gain/keep access to a huge market.
- JanMatas 7y agoSo, let's say that I receive this and do no comply. What should my "enemy" who sent this do next? What is the worst case outcome for me?
- JerreBM 7y agoThey can report you to their local authorities and (potentially) sue you. Take a look at this: https://ec.europa.eu/info/law/law-topic/data-protection/reform/rights-citizens/redress/what-should-i-do-if-i-think-my-personal-data-protection-rights-havent-been-respected_en https://ec.europa.eu/info/law/law-topic/data-protection/refo...
- emiliobumachar 7y agoArguably it's an "undue burden" to send a form letter "designed to waste as much of their time as possible"
- vonmoltke 7y agoThe targets will still need to spend time (and thus, indirectly, money) to demonstrate that such a letter is such an "undue burden". This assumes they can even do so; if there are national regulators who hold the same opinions that some HN posters do about Google and Facebook, there may be no definition of "undue burden" they are willing to accept.
- ericb 7y agoWhat about if you're not in the EU?
- compuguy 7y agoI'm honestly not sure. I doubt you could do this if you weren't a EU resident or citizen...
- fghtr 7y agoBut what do you do with our personal information entered?
- JerreBM 7y agoNo personal data is captured or stored. The form fields are pure front-end (VueJS), immediately outputting the values you enter into the preview box. There is no backend that stores anything. The only tracker currently installed is GA, which doesn't capture inputs either.
- panarky 7y agoDo you have my IP address in your logs or the logs of third parties like Google or jquery.com or jsdelivr.net or producthunt.com? Please post the name and address of your data protection officer.
- theamk 7y agoIsn't it kinda pointless because it will only work once per "enemy"? Sure, the first time it will waste a bunch of their time, but the second email will just get the same canned response. I suppose you could make it a bit worse by asking to see the information collected - then simple copy-paste will be insufficient, they will have to run a script as well.
- airza 7y agowhy would it be a good thing if companies spent more on fines than on costs to comply with regulations?
- dqpb 7y agoPeople will do the thing that costs less.
- glacials 7y agoTotal amount fined vs total amount spent complying aren't comparable numbers. One side has orders of magnitude more organizations comprising its number than the other. We need a median amount fined to non-complying organizations vs. median amount spent complying by complying organizations.
- asdfman123 7y agoIf it costs less to build adequate storage tanks than it costs to pay fines for your oil leaks, companies will build adequate storage tanks. That's how regulations protect public interest.
- NoGravitas 7y agoThe usual New Yorker comic caption applies here.
- nsfmc 7y agoWhat a Misunderstanding! ?
- hprotagonist 7y agoChrist, what an asshole
- Y_Y 7y agoFTA on why it was made: > To show that GDPR is fucking stupid. Really, have a look at these crazy stats after 1 yr of GDPR: ~$60m in fines compliance costs for US firms estimated at $150b (2500x fine amount!) small co's hurt more than large. GOOG actually benefits! VC $ invested in EU startups drops significantly Is it redundant to say that this characterisation seriously misses the point of the legislation, and that this is a lot of trouble to go to just make a childish nuisance?
- benjohnson 7y agoIn my opinion, regulation is better judged on the facts and not on it's intent. For example, draconian drug laws have great intent but horrible externalities - so much so, that even though I'm vehemently opposed to recreational drug use, I'm now sympathetic to treating it as an illness and not as a crime.
- solarkraft 7y agoWow, that's hilariously silly.
- Silhouette 7y agoMost of the criticism of the GDPR isn't about its apparent intent, it's about its actual implementation, particularly with regard to ambiguity and proportionality. I'm a critic of the GDPR, yet I'm also a big advocate of stronger privacy protections. I see no conflict here, because my criticism isn't about what the GDPR is trying to do, it's about what it actually does.
- jarcane 7y ago3/4 his bullet points sound like selling points to me. I'm glad to see surveillance companies suffer. That's rather the point of the thing.
- Vinnl 7y agoThis very much reminds me of people using Freedom of Information Requests to inconvenience the government, because they have some beef with them. That does not make the right to such requests stupid, and it's annoying that there are people that abuse it and risk getting it watered down, thereby removing all positive effects. (Such as the effects those fines and compliance costs have on civil liberties.)
- Avernar 7y agoSaving this. If it works, it's spectacular. And using it for Revolut, they're horrible scammers.
- tomc1985 7y agoGDPR may be overkill but god damn is it needed. Startup "hackers" playing fast and loose with data need to be reigned the fuck in.
- newaccoutnas 7y agoIt's not startups you should be worried about as finding data for them is difficult unless they already have a widely used product, use open data or have a partner. The real ones to be worried about are the usual 'do no evil' suspects. They already have all the data.
- eli 7y agoGoogle will have no problem complying with this request. They already have the systems in place to do so without much effort. Many people have already requested data from Google. Small companies dealing with their first request likely have (at best) a manual process that will take many hours of someone's time to process.
- newaccoutnas 7y agoWhilst their processes might be superior (although that's debatable), they very much aren't up to speed with GDPR https://www.bbc.co.uk/news/technology-46944696 https://www.bbc.co.uk/news/technology-46944696 (even if the fine is small fry to them and it's financially more attractive to flaunt the rules)
- eli 7y agoThat's a completely different issue from their ability to respond to data requests like the one linked. I'd assume the incremental cost for Google to send you the data it has on you is close to zero.
- newaccoutnas 7y agoAnd being able to respond to requests is completely different to the op's comment about startups, which was the original comment I added.
- dqpb 7y agoIs there any research on combating policies by artificially overwhelming them? This seems widely applicable.
- filoleg 7y agoI don't know about any actual research, but some people are doing that to the software patent system in the US. Current wait for a patent to be approved (or rejected) is 3+ years iirc (and it keeps getting longer). And I definitely know some people irl who think the whole software patent system is a load of bs, which is why they keep filing patents (90%+ of which won't be approved) for even the most minutiae stuff.
- bryanrasmussen 7y agoI noticed it asked if you hate your government, government agencies do not have as stringent requirements as non-governmental because damn if they did there is a particular agency I would be screwing with daily.
- scottlawson 7y agoBut... Wouldn't the end result just be that your tax dollars get spent responding to bogus requests that waste a lot of time? If you are dissatisfied with a government agency, it seems counterproductive to deliberately make them operate less efficiently. This attitude seems like it would just reinforce an endless cycle of inefficiency and dissatisfaction
- bryanrasmussen 7y agoSince the only real interactions I've had with this agency is them screwing me over I don't care that much about its efficiency, and I couldn't be more dissatisfied. On the other hand you are right in that it helps do other stuff that does benefit me, I just don't notice the benefits as much as the harm because the harm is direct and the benefits are societal.
- megous 7y agoIf you want to weaken this regulation, abuse it like this.
- Latty 7y agoThat is the point of this page, if you see lower down the author is against the regs and this is an attempt to undermine them. Honestly, it's crazy—HN is the only place I see this kind of anti-GDPR stuff. Everyone I have talked to about it sees it as a huge positive. I include myself in that by the way—being able to get (and delete) my data from providers reliably is a huge positive, and it has clearly improved the way my data gets handled a lot of the time. The cost is relatively small.
- qwsxyh 7y agoThat's because on HN there's five general types of people against the GDPR: 1) People who think any sort of government regulation is pure evil 2) People who read the opinions of the first group and assume that because it was said on HN it's correct 3) Adtech startup devs 4) People who really hate not being able to hoard personal data for no reason 5) People who think money is significantly more important than privacy
- citilife 7y ago5) People like myself who are annoyed that people think GDPR is enforceable to non-EU entities. It's not... You cannot enforce GDPR on any person / company who doesn't have a presence in the EU. That annoys me, because _although I'm willing and do comply_ many people reach out to me regarding their personal data with a lot of arrogance. However, my company isn't based on the EU and I don't have to comply (which I cleared with a lawyer already). Their method of their approach makes me not want to comply.
- kyriakos 7y agoI understand your problem with arrogance but as long as you service users in EU you are still liable. There are legal ways they can get to you and at best you may avoid fines but be banned from offering your service to EU citizens. Of course that's an option you already have I.e stop servicing EU
- Quanttek 7y agoI actually like this but there are a lot of similar services that make it easy to send GDPR requests with less such biased framing and without the abusive intent. The arguments brought forwards against GDPR tell you probably more about the author than the regulation if Jerre's only concern is with the potential costs for businesses. That may be news to some, but the maximization of company's profits is not a value in itself or should be the goal of our societies. Otherwise, we wouldn't have safety/labor/product standards regulations, such as OSHA. Instead, ensuring human rights, such as privacy and data rights, (and a high quality of life) should be our concern - and that can cost companies - slavery would've been a lot cheaper too. It speaks to a certain discourse prevalent in Silicon Valley and among business owners. The main source has been pretty well counter-argued in the original thread [1] but the author rather parrots that misleading information. [1] https://news.ycombinator.com/item?id=20009017 https://news.ycombinator.com/item?id=20009017
- inapis 7y ago+1 to this. Author is primarily concerned about financial costs without taking into account all other externalities that such hoarding such data causes.
- talonbragg 7y agoThis is a really cool application. I like that you are advocating for internet privacy. To add on to this, it would be cool if you made a .onion version of the site for even better privacy. Then google isn't collecting my data while I am on the site.
- the_gipsy 7y agoMhh, a gmail extension to reply to newsletter spam with this would be nice.
- return1 7y agothis is BS that trivializes GDPR and almost amounts to fraud. someone will get sued for this.
- hrbf 7y agoThis is why we can’t have nice things.