13 ms·
One reason the EU missed out on the internet is our unlimited willingness to be regulated. And we keep piling more and more bureaucracy on top of it. This only
by FreeHugs 5y ago
One reason the EU missed out on the internet is our unlimited willingness to be regulated. And we keep piling more and more bureaucracy on top of it.
This only cements the power of US big tech like Google and Facebook.
And it sets the stage for the next big applications of the web all being build outside the EU as well.
Here in Germany, everyone is afraid to start a web startup. And if they do, they spend endless amounts of energy on agonizing over the GDPR and how to build useful international services without using international tools. We sanctioned ourselves by making the use of foreign SAAS illegal.
If you are in the EU, try out surfing the web via a non EU IP once. It is an eye-opening experience. No cookie banners! Only Europeans have to deal with those.
But it gets worse: Look at European websites from a US IP. You do get cookie banners. European companies deal with degraded user experience, slower build time and worse monetization. On a worldwide basis. While the rest of the world only applies these downsides to the European part of their business.
- mschuster91 5y ago> One reason the EU missed out on the internet is our unlimited willingness to be regulated. Bollocks. The key difference between here and the US is the simple fact that we don't have enormous amounts of "dumb money" from pension and hedge funds screaming to be invested into anything that remotely smells like it could be worth money one time - remember Yo! which got 1M funding?! - and then founders making big money at IPO time, which many of them then choose to invest into new startups. That means that you have to either rely on philantropic investors, family or borrow money from banks at ridiculous interest rates (and often requiring deposit of a car/house or other expensive assets to back the loan). Navigating GDPR and the laws here is easy - one might say, life is even easier here than in the US for startups because you don't have to fear getting kicked in the nuts over bogus patent and other IP claims or absurd multi-million dollars civil damages lawsuits.
- 37rucxuu 5y ago
- FreeHugs 5y agoDumb money is not the basis for the web as we know it. Look at where we are communicating here. On a US website built by a single person.
- ChuckNorris89 5y ago>Dumb money is not the basis for the web as we know it. It's not, but it's the basis of ad-driven, surveillance-ware, and user engagement optimized companies that drive the ludicrously high profits and wages in the US tech sector. Do you see US tech workers lining up to work for Canonical? Yeah, I thought so too.
- aspenmayer 5y agoWell once I saw their application, I wasn't interested in working at Canonical either. And I'm currently looking for work, for what it's worth. https://news.ycombinator.com/item?id=30735678 https://news.ycombinator.com/item?id=30735678
- ChuckNorris89 5y agoI know that thread, that's why I used it as an example. Hiring in tech is broken regardless, so most candidates optimize for compensation as that way at least the end result justifies the effort of going through those several stages of various hazing rituals each company has lined up. And like the Canonical employee said in that thread, they receive 80% quality applications despite all of those shitty hoops Canonical makes you jump through even before they talk to you. So yeah, there seems to be no shortage of devs regardless of how bad a company's hiring practices are, as long as they're an established name and/or pay great.
- mschuster91 5y agoFor the web itself, yes. But for a lot of the services we use daily - Google, Facebook, Twitter, Reddit, Uber, AirBnB - lots of "dumb money" for cheap/free services or to outright price-dump the legitimate competition were the basis of their success.
- 5y ago
- drumhead 5y agoWhy aren't they investing their "dumb money" in EU web start ups then?
- mschuster91 5y agoEasier to invest into something if you only have a short car drive to the company you're investing in; additionally everything cross-border involves a lot more effort with coordinating taxes. In any case at least YC does invest into European companies [1] - the key thing is you have to get far enough to have a meaningful product that VC funds can invest in, and unlike the US we don't have a lot of billionaire former founders who go around throwing a couple thousand dollars left and right for promising ideas they hear in an elevator. [1] https://www.ycombinator.com/library?categories=Europe https://www.ycombinator.com/library?categories=Europe
- drumhead 5y agoAre you saying they'll miss out on a multi billion dollar profit opportunity because "it's not a short drive". Many VC firms have European offices, there's Zoom or a plane flight. Cross border investment is not a new or alien thing so dealing with taxes or regulation isn't something they can't cope with. So money not being available isn't a convincing reason.
- mschuster91 5y ago> Are you saying they'll miss out on a multi billion dollar profit opportunity because "it's not a short drive". Not "miss out" per se, rather a "prioritize companies in close proximity". There's a reason why a lot of the former startup turned unicorns are all concentrated around the Silicon Valley.
- thow-58d4e8b 5y agoBecause in the US, money has nowhere else to go. Stocks? Wildly overpriced. Real estate? Wildly overpriced. Bonds? Zero returns. Mineral extraction? Risky outlook. Energy sector? Subsidies are likely on the horizon, better to wait. Infrastructure? NIMBYs That's not the case for the EU. Money gets reasonable returns in energy sector, industry, any investment in Eastern Europe, tourism, PPP infrastructure projects, etc.
- netheril96 5y agoIn this case, the rules only apply to corporations with large enough revenue, so startups remain unaffected.
- ivancho 5y agoOh, man, such a shame about all these laws.. [checks notes].. protecting users from predatory company behavior. Things would be so much easier if we didn't have those laws - we could all start web startups.
- FreeHugs 5y agoRegulating local companies is making things only worse. That is the reason why all of Europe depends on foreign tools in the first place. It is a similar death spiral to how we deal with the housing problem. People have a hard time finding affordable apartments in the city centers? Create more laws that limit rents! Does this create more apartments? No. It just send the local housing market further down the drain.
- AitchEmArsey 5y agoBy your own argument, foreign companies can navigate the rules for selling into Europe just fine - so what is stopping a European company from doing the same? If there is any remaining problem it is that the rules are not enforced strictly enough on tech giants.
- FreeHugs 5y agoLets talk about startups first: An indie dev in New York does not care about the GDPR. The just build cool shit and put it online. Look at all the Show HNs here. In the EU, the situation is very different. Indie devs are super afraid and work hard to make their stuff less useful to please the GDPR. Now about larger players: EU companies agonize their worldwide users with cookie banners. Because that is what the GDPR tells them to do. Non EU companies dont do that. Because why should they? Will a lone Italian traveller in the USA sue them for using Google fonts? Probably not. And if they do - they can handle it. So they only agonize their EU users with cookie banners.
- ClumsyPilot 5y agoUnlike in UE, EU companies are not allowed to sell their customers data to random third parrty spammer, scammers, adtech companies and bounty hunters. That is it - as a startup, GDPR is not a massive prohlem. You know what is a real problem? The fact that you can raise 10x more investment in the US with the same slide deck.
- matthewmacleod 5y agoOne reason the EU missed out on the internet… Here in Germany, everyone is afraid to start a web startup The EU does actually have a variety of "internet" companies – and that includes Germany! There are certainly less of them; regulation could be one of the things that affects that, but it seems way more likely to be a wildly different environment for funding. Investors are more conservative and far less likely to throw dumb money at anything that moves, which means fewer successful unicorns. I'm not sure that's the best approach, but I'm not an investor. they spend endless amounts of energy on agonizing over the GDPR No they don't. GDPR compliance is generally fairly straightforward for any company which isn't trying to deliberately harvest and profit from your data—particularly a new company with no legacy—and in any case represents a set of practices that should be followed by any company dealing with private data in any case. By the same token, those startups have to worry far less about the nonsense patent and IP environment in the US. So worst case we'll call it a wash. We sanctioned ourselfes by making the use of foreign SAAS illegal. This did not happen. Use of non-EU SaaS is legal, subject to it being compliant with local regulation. I'm always a bit weirded out by strenuous objections to GDPR – it seems to me that the data privacy environment in Europe is broadly pretty sensible. You need to: - know what data you are using - have a good justification for using it - take appropriate precautions to secure it - make sure users are aware of what you are doing with it - allow users to access and correct the data you hold on them I find it hard to object to that.
- FreeHugs 5y agoThat sounds very theoretical. I witness the journey of several German startups for a while now and get a very different picture. Many of the most powerful web tools are not compatible with the GDPR. Google Analytics. Ad marketplaces. Free CDNs. And its all a moving target. I see small companies struggling for years now with these problems. And they will keep struggling for the forseeable future.
- gcthomas 5y agoIt is the most powerful tools that I want restricted. the milli-second bidding auctions for ad placements and the tracking that goes on to enable that is unethical and illegal. There are perfectly good alternatives that don't abuse my personal data — companies should use those.
- hnbad 5y agoFunny how I have worked both as a developer and a business owner building applications for startups and established businesses alike and yet as both a consumer and a professional I'm glad to live under EU jurisdiction instead of the US because all those evil privacy protections and regulations mean I can have a reasonable expectation that companies can't just do what they want with the data I entrust them. People like you love to complain about cookie banners but somehow fail to acknowledge that the reason cookie banners are a thing is that companies go out of their way to try and game the regulations instead of actually implementing them. Sure, you can't build the next Facebook in the EU but maybe not being able to build a business on intentionally abusing your users' trust is not a bad thing. If you just want to get rich, there's still plenty of nigh-unregulated banking and speculative investment you can get involved in with narry a consequence. If you want to build software, I'm not very sorry you're inconvenienced by regulations that actually protect people from your overreach.
- trh0awayman 5y agoI would say most people don't agonize over it because most people don't follow GDPR here in Germany. I think more and more people are slowly complying, but certainly in the last 3 years no one has cared. I personally believe GDPR will never be properly enforced and most people will ignore it. The easy parts of GDPR (cookies, fonts, I guess CDNs now) are automatically detectable, and the hard parts (deletion of data, data processing agreements, necessary collection) are not. There is no way to automatically find out if someone is storing IP addresses in their access logs. One of the really funny things I encountered in Germany is the emphasis on data privacy/protection... But every single citizen has to inform the government where they live and their religion. You also have to inform your boss of your religion. If you make creative content, you have to publish your address as well (unless you can afford to start a business at another location). You can find out where anyone in Germany lives for a small fee. Those things have about 10x greater impact on my day-to-day life than Twitter finding out I watched a "cancer prognosis" video. I know they're not mutually exclusive, but it shows where priorities lie.
- mschuster91 5y ago> But every single citizen has to inform the government where they live and their religion. You also have to inform your boss of your religion. That depends on the religion. For a bit more context (read the full history in [1]): As part of the 1800s separation between state and church, the major ones (Catholic and Evangelic-Lutheran) got the right to a percentage of employed people's wages as a sort of "membership fee". This gets deducted by the employer out of your paycheck and collected by the tax office, then distributed to the church you're a member of. Over the years, the right to collect these taxes expanded by quite a number, although currently only the Roman Catholic, Old Catholic, Evangelic-Lutheran, Free Protestant and Jewish synagogues use that right. In real life, no one but HR at onboarding cares which religion you specify. Also note, this is not exclusive to Germany. Italy, Sweden, Austria, Finland, Denmark and Switzerland all have a similar system. [1] https://de.wikipedia.org/wiki/Kirchensteuer_(Deutschland) https://de.wikipedia.org/wiki/Kirchensteuer_(Deutschland)
- trh0awayman 5y ago
- mhitza 5y agoEvery developer should try to understand GDPR to a basic level, as those basic principles are good enough of a baseline. Won't go into minutia, cause at the enterprise/large scale level you'll need a DPO (data protection officer) and follow stricter auditing practices (among other things). Second, cookie banners are unrelated to GDPR. They became mandatory years before the GDPR, and the level of intrusiveness is because websites don't follow the "spirit of the law". With time hopefully the cookie banners dark patterns will subdue (after a few more entities get fined). In terms of EU startups, what I'm familiar with, is them getting bought by US corporations, and not failing under the pressure of EU pro-consumer bureaucracy.
- CaptainNegative 5y agoA high level overview may be possible, but any amount of actionable detail is impossible for laymen and lawyers alike. The GDPR is intentionally vague; there are entire academic papers from respected researches dedicated to trying to parse individual sentences from the document. See e.g. Cohen and Nissim's 33 page article on intepreting the sentence > To determine whether a natural person is identifiable account should be taken of all the means reasonably likely to be used, such as singling out, either by the controller or by another person to identify the natural person directly or indirectly. https://arxiv.org/pdf/1904.06009.pdf https://arxiv.org/pdf/1904.06009.pdf Turns out writing vague laws lets you turn entities you don't like into cash cows.
- mhitza 5y agoI think actionable details are left vague as to not create legislation that's left behind by technological advances. You're right, that personal identifiable information is a hot topic. Partly because you need immense foresight (a.k.a. impossible) to see how multiple data points can be correlated to identify someone, but also because you need to be aware of large-scale actors (e.g. state supported dragnet surveillance). As an industry I don't think we have reached yet that discussion point, when we still have common basic practices we need to change. For example, I know that most small/medium companies don't even attempt to anonymize their database dumps. Those are the issues we have to focus on first, and those actions become clear to any developer that reads the GDPR for the first time. It's actionable insight without being explicitly stated. I think that the GDPR is *incompatible with the web 2.0 model, and the internet as it exists today*, and I also think that is a good thing! It should push us to build services that in the end treat all users data as personal information, and lead to anonymous internet services by default. I have my own laundry list of things I dislike about GDPR, which makes compliance harder than it should be. One such example is that IP addresses are "an exercise left to data controllers to anonymize", where I hold the belief that the legislature should have forced ISPs to be the ones to anonymize user IP addresses (anonymize things at the source). That way data protection agreements would not be even necessary when you use a CDN in front of your website (for example). By the same token, browsers should be forced to use generic User Agents, as those leak platform information like crazy. I also disagree that "vague laws lets you turn entities you don't like into cash cows", because what I see most common is that companies get a slap on the wrist (so to speak) and fines are not always the first recourse, only affecting those that are majorly negligent and repeat offenders. These laws are not draconian tools to suppress digital products, but to protect users from life affecting data leaks, automated decision making and profiling, which we've seen to be objectively bad in the past. But as you can tell this is my highly subjective take on the issue. I might be completely wrong in my belief after all.
- ClumsyPilot 5y agoSo you like that your code is protected by intellectual property so that you can make money off it and noone can just take it and use it whoit permission? But you dont like that your users data is protected by GDPR, so that you cant take it without permission? Thats unnessesary regulation holding back business? Does not sound like it has anything to do with regulation, it sounds like you want the fovernment to give you an advantage.
- Dracophoenix 5y agoThere's no contradiction. Intellectual property protection is opt-in. It requires the individual to enforce his rights before a court in the relevant jurisdiction. The government only facilitates registration and adjudication. Courts don't force individuals into global protection schemes against claimant's own will. Whatever the expected merits were, GDPR's existence as a policy has been of little more use than a protectionist beating stick in service of the EU. It gave the EU the power to dictate how websites are to be designed. Non-Europeans with business interests inside the EU had no say or representation in the matter. Governments shouldn't claim universal jurisdiction over the Internet, whatever their reasoning for such claims might be.
- ClumsyPilot 5y agoSo if governments didnt sue you for violations of GDPR, but your users did so personally then the situations would be exactly idebtical and you would be happy?
- Dracophoenix 5y agoYes and No. Yes in that people already have that agency to sue. I'm sure you've heard of a class action lawsuits. No in that I don't approve of the GDPR prescribing what constitutes a privacy violation rather than leaving such deliberations to contracts and courts.
- ClumsyPilot 5y ago
- koonsolo 5y agoFellow EU entrepreneur here: you being downvoted says enough about what kind of people are commenting here. US works with a "better ask forgiveness than permission" model, where you are pretty free to do what you want, but people can sue you. EU works with the opposite: create rules and keep companies compliant with those rules. It's pretty obvious to see that the 1st model is very beneficial for startups and bootstrappers.
- chalst 5y agoI didn't downvote but I thought it was a weak comment: it's a generally valid perspective but doesn't seem tailored to the actual news, which is mostly tailored to large capitalisation/turnover companies. The general pro-vs-anti regulation dimension of the argument over tech policy seems to lack the necessary nuance if it doesn't ask about antitrust. The lack of antitrust regulation in the US has meant that the SV pipeline which fifteen years ago supported a diverse tech landscape is at risk of degenerating into one that only aims to produce targets for monopolists to buyout. It's a possible future of your "1st model" I'd rather we were more worried about.
- watwut 5y agoThat does not make US less regulated. It makes regulations unpredictable and unevenly enforced. Also, cookie banners are mostly bad faith restriction implementation. You can have functional cookies with no banner. What you cant have are those tracking cookies which is what the whole thing is about.
- yywwbbn 5y agoAre there any actual cases of EU startups being fined under GDPR without being given a chance to fix their stuff. I was under the impression that the enforcement so far has been pretty lenient.
- koonsolo 5y agoThe real problem is not the fines, but to comply to all of them. For example, EU article 13 has a direct impact on my product (my users can upload custom resources). Good thing that Belgium didn't implement it yet. But when they do, I probably need to move my business to Delaware or something. They claim that article 13 is to reign in the big companies like YouTube. But in the end this also makes sure that EU has a hard time of building their own YouTube. Anyway, I looked into it, and it seems possible for me to move my business abroad when we get that far. But all this basically proves my point. It's easier to build a startup when you are outside of the EU.
- sofixa 5y ago> This only cements the power of US big tech like Google and Facebook Au contraire. This regulation will force the big tech companies to open up their platforms, thus enabling innovation and competition.
- deburo 5y ago>If you are in the EU, try out surfing the web via a non EU IP once. It is an eye-opening experience. No cookie banners! Only Europeans have to deal with those. I'm in Qc, Canada and I see them very often. Is it only checking for a US IP, and everything else gets the banner?
- andrew_ 5y agoIn the U.S. and I'd seen so many of them that I have an extension installed specifically to hide them while browsing.