7 ms·
If your annual revenue is above $100M, you should be held accountable to a strict version of GPDR enforced by an ombudsman, that requires you to patch all data
by aetherspawn 5y ago
If your annual revenue is above $100M, you should be held accountable to a strict version of GPDR enforced by an ombudsman, that requires you to patch all data leaking vulnerabilities within 90 days, or pay out everyone who bought your product.
I just updated to iOS 15 and it now tells you which sites you have been compromised on, or had your passwords/info compromised on. To be clear, I use a password manager with a unique password on every site, so it is difficult for something like this to have a significant impact. Nethertheless, I was compromised on hundreds of sites and products, and those were just the accounts that iOS Safari knew about. None of them bothered to reach out and tell me. Even my coffee machine was compromised. Ridiculous.
- whoknowswhat11 5y agoGod, I would HATE if the US follows the EU with this craziness. I'm already sick of the cookie popups, now layer on the GDPR insanity and we will definitely lose the privacy fight to users who will be sick of this nonsense as well. I've seen studies that show crap like GDPR (which makes basically all normal interaction cumbersome) has like 10% of folks clicking around to "opt-out" while 90% can't be bothered. And of course, you COULD just clear your own cookies. There is no more real security in the EU. Your mental health records will be leaked there. The EU will spy on you like crazy. And more.
- arvindamirtaa 5y agoIs there a point to this...? Or did you just want to crap on GDPR? Not saying it's good or bad. But just...relevance?
- cmeacham98 5y agoGDPR cookie consent banners that make it more difficult to opt out than opt in are illegal, and only continue to exist because the GDPR is poorly and inconsistently enforced.
- thatswrong0 5y agoMost of the cookie consent banners I see are illegal in that case..
- rcMgD2BwE72F 5y agoThat's right.
- maccard 5y agoAnd how many have you reported to your local data commissioner?
- throwawayswede 5y agoThat's the point. GDPR without good enforcement is useless and meaningless. I'd even argue that all this time since GDPR and until something is done about enforcement if ever (that is not just a random fine, which is considered cost of doing business) all that GDPR is doing is allowing these companies to come up with more elaborate ways to scam (I'm looking at whoever the assholes who work, run, or are remotely involved with trustarc.com).
- Reventlov 5y agoCookie consent banners have nothing to do with GDPR, but with the ePrivacy directive. GDPR clarifies what is "consent", but this is not what leaded to the proliferation of cookie banners. Please note if you have strictly necessary cookies, you don't need to have cookie banners, and if your cookies are anonymous, you don't need them either ! The proliferation of cookie banners just means that people running such websites are usually terrible with regards to consent, personally identifiable information, and so on.
- cmeacham98 5y agoNon-essential cookies are personal data as regulated by the GDPR. It is true the EPD started the cookie consent popup craze though.
- RamblingCTO 5y ago
- howaboutnope 5y ago> crap like GDPR (which makes basically all normal interaction cumbersome) Only if you count "tracking users on first visit before they do anything else" as normal. Otherwise, there isn't a banner needed; sites could simply have a link to opt-in to tracking in the header or footer, and not track unless the user opts in. This is like passing a law making it illegal to just hit people in the street, requiring you have to ask them for consent first. So most of the people who want to hit others up come up with some gish gallop that most people fall for, and then hit them. And people bitch about the law, and claim it "makes it necessary for people to chew off the ear of other people they pass by in the streets"... with a straight face, that's what they twist it into, with an air of indignation even... and not just for a few weeks, until they read up and the initial misunderstandings are cleared up, but year in and year out, because they never read up, and the falsehoods you just posted keep getting repeated.
- filleokus 5y ago>> crap like GDPR (which makes basically all normal interaction cumbersome) GDPR do make a lot of things cumbersome, not only if you are doing "bad" things. Remember that GDPR covers information gathered and stored on paper as well. And it covers not only companies but also organisations, like children's soccer clubs. So let's say you have a printed list where kids and their parents signup with name and phone numbers, you should probably have a data integrity policy and someone akin to a DPO. In your small non-profit soccer club! (My problem with GDPR is that it doesn't really, at least so far, hinder the worst trackers, but incur large cost all across society, even where handling personal data isn't really a problem)
- howaboutnope 5y ago> GDPR do make a lot of things cumbersome, not only if you are doing "bad" things. That's a far cry from "they make these cookie banners necessary". Tracking people without consent on first visit is what makes them necessary. The anger is consistently misdirected at the people who violate the boundaries of others, not the law that requires consent for it. > So let's say you have a printed list where kids and their parents signup with name and phone numbers, you should probably have a data integrity policy and someone akin to a DPO. In your small non-profit soccer club! "We'll ask them if it's okay to store it, and once they leave the club we delete their contact information after N months." Now you have a policy. The person who does everything else, the person who is already secretary, receptionist, accountant, project manager, janitor, coach, counselor, CEO, is now also the PDO. Human rights being trampled on with an ever increasing mesh of surveillance by big agencies and corporations as well as little informants are such gross violations, such a terrible trajectory we put society on, that mere complication and discomfort is not something that can ever trump them in my book. I would even say if you can't put food on the table without ignoring the human rights of others, just don't put food on the table -- because that's the negotiable part, while the preservation of human rights is not. We need human righs, we don't need ad-hoc low-effort soccer clubs. Like, at all. Just get a ball and some friends in that case.
- mmarq 5y agoThe only interactions made cumbersome by GDPR are those with organizations that abuse their users/customers’ data. Otherwise you don’t even need a cookie banner.
- tonypace 5y agoSo, all of them.
- Nextgrid 5y agoDoesn't mean the law is bad.
- neon_electro 5y agoGiven that, is the law bad, or is the default behavior of companies?
- arghwhat 5y agoThe cookie popup is something else, and the result of misinterpreted legislation and companies trying to cry foul that they can't do whatever they want anymore. It's not at all needed for common cookie usage - just the unexpected soul-selling kind. GDPR restricts companies from using data however they want, makes you able to obtain a copy, and makes you able to require it deleted. It also required the company to document, provide a person responsible to contact, etc. It only benefits you as a consumer, and the downside in proper uses is that the webpage/app might have a page somewhere with data processing information should you be curious. Nothing major. Any nuisance are poor implementations or because companies can no longer do terrible unexpected things, like selling your data to hundreds of companies just by accessing a page, without permission, because it is nonsense no one would expect or want. And with everyone clicking "no" (which must be at least as easy as clicking "yes" as determined in court), the practice would die eventually.
- Cipater 5y agoHang on, you have a coffee machine that is capable of being compromised? How exactly? Further to this, you claim that you have been compromised on HUNDREDS of sites even though you use a unique password everywhere? How is this happening to you? Isn't this a huge concern?
- rablackburn 5y agoRight, it’s hard to compromise a kettle and manual grinder, the only thing I could possibly consider a benefit of a networked coffee machine is you can schedule it/script it with home assistant. But even then, I’m pretty sure you can buy simple electric ones with timers…
- consp 5y agoOnly if it is HTCPCP(-TEA) compatible. Otherwise they should not bother. /s, since it is not the specialized coffee machine on the office floor which is the biggest problem but the thousands of ones at home where people do not even bother to firewall it.
- wil421 5y agoWhen I was looking for an espresso making a lot of them have touch screens and connected features. They will wake up before you get out of bed and have hot water ready. I specifically bought one without touch screens and all that crap. It takes maybe 30 seconds for the water to heat up. Lots of people will get their regular coffee maker ready the night before with water and ground beans. At a specific time in the AM it will brew. Lots of old models have timers you can set. I avoid smart devices like the plague. My Bosch fridge is a smart fridge and I plan on putting it on a VLAN.
- 0xffff2 5y ago>My Bosch fridge is a smart fridge and I plan on putting it on a VLAN. As another new owner of a Bosch fridge, why put it on anything at all? I just peeled the sticker that told me how to connect off, threw it in the trash, and treat it just like my old non-connected fridge. Is there actually some beneficial feature that makes it worth connecting at all?
- kf6nux 5y agoAren't Ombuds generally limited to investigations and recommendations (not enforcement)? What country colors your context? (e.g. I'm in the US where federal Ombuds aren't much of a thing, though similar roles may be filled by other persons).