4 ms·
This is a completely backwards way of looking at it. If you don't have the budget, create a static website and throw it behind github pages or s3 or whatever. A
by bubblethink 5y ago
This is a completely backwards way of looking at it. If you don't have the budget, create a static website and throw it behind github pages or s3 or whatever. An entire university with a school of computer science cannot figure out some standard way of doing this ?
- tapoxi 5y agoThis publication is independent and not run by the school.
- bubblethink 5y agoRight, but surely they have resources at the school if they need technical assistance. It's a university. Just find any CS major and they'll tell you how to set up a website.
- Benlights 5y agoIt's not the technical assistance needed it's the legal review. Go get that from a CS major.
- wizzwizz4 5y agoYou don't need a legal review. • A static site without JavaScript; • with all images / external resources hosted on the same domain; • where the logs are default configuration, don't leave the server (except as GoAccess reports), and are deleted / anonymised eventually; is GDPR-compliant. Sure, there are other ways to be compliant, but this works, and is basically the default way of setting up a website. It's not hard to check whether this is how your website works.
- dogleash 5y agoWhen you put together that simple bulletpoint approach you still leveraged baselevel knowledge about the GDPR that would be ridiculous to assume of a CS major.
- wizzwizz4 5y agoI'm not even a CS major. I just read the thing. It's not that long. https://gdpr-info.eu/ https://gdpr-info.eu/ You can get this knowledge with just the first 7 articles.
- oytis 5y agoI miss the web of the 90s too. User expectations and web economy have changed a lot since then though.
- Turing_Machine 5y ago> is basically the default way of setting up a website It's not the default way of setting up an online content management system to which student journalists can post articles without going through some convoluted command-line build process ("...then you do a git commit and push, run the Hugo script, and rsync the files to the server"... yeah, no.) > It's not hard to check whether this is how your website works. Since they're using a third-party content management system, they most likely neither know nor even care how the website works. Why should they? They're journalists, not system administrators. As others have noted, this is an independent student newspaper. Their normal readership outside the Purdue community is probably in the low single digits on a percentage basis, and their EU readership is likely close to non-existent. They (or, more likely, the people who run the CMS for them) have concluded that a full audit of their system to ensure GPDR compliance is simply not worth it for the minuscule number of additional readers they'd gain. And they're almost certainly right.
- dogleash 5y agoI don't know about you, but when I was at school I didn't have much luck getting randos from other majors to do free work for me. I collaborated with some EE and ME students on personal projects, but they were 1) more interesting than GDPR and 2) friends.
- bubblethink 5y agoI don't know how this newspaper works, but typically the team itself will comprise students from different majors, seniority, etc. So it's not a question of begging for help or money.
- PragmaticPulp 5y agoThis is an independent website, not part of the official University budget. You can’t just round up some CS students and have them produce a website compliant with international law for free. This involves legal teams, contracted developers, and constrained budgets that are already stretched thin on operating in their core business. It’s not reasonable to demand they invest tens of thousands of dollars (or demand equivalent free labor from CS students and lawyers) to serve a population that almost never visits the site.
- bubblethink 5y agoHow are they producing a website compliant with local laws then ? What if they inadvertently end up violating DMCA ? What happens then ? The answer to that is one can be reasonably sure that they aren't doing anything stupid or malicious. It's the same with GDPR. Don't use trackers, cookies, adware etc., none of which are necessary for a college newspaper. This is a simple technical problem.
- throw10920 5y ago> You can’t just round up some CS students and have them produce a website compliant with international law for free. But the issue isn't "international law" in the general case (which, indeed, would be very hard), it's the specific case of the GDPR, the solution to which (for this particular site, which only serves static content) is mind-numbingly trivial: don't collect personal data, don't set cookies. That's it. That's all you have to do.
- CodesInChaos 5y agoYou're only talking about the technial part. But there are non technical requirements as well: In many cases you need to name a person responsible for data protection, a privacy policy, a list of services you're sharing data with,... Though I'm not sure if a local US newspaper even needs to be compliant, since it doesn't target EU residents and thus might be out of scope.