15 ms·
Ask HN: Can we delete our accounts?
I was checking out a post yesterday that used stylometry to group HN accounts, potentially doxxing the authors:
https://news.ycombinator.com/item?id=33755016
Honestly, it was pretty concerning to be able to locate an old account of mine. Given the potential danger of being doxxed, it would be very nice to be able to delete our accounts and old comments. I think HN is one of the only sites that doesn’t allow you to do that in an automated fashion. Can we request that feature be implemented? I worry that people are building tools to reverse engineering people’s true identities and it seems like an important feature to keep users safe from physical and commercial harm.
- theknocker 4y ago
- theknocker 4y ago
- cloudking 4y agoYou should be able to request your account be deleted if HN is compliant with GDPR https://gdpr-info.eu/art-17-gdpr/ https://gdpr-info.eu/art-17-gdpr/
- justinzollars 4y agoDoes HN Follow GDPR?
- ransom1538 4y agoI hope not. I don't think HN should follow Indian or Cameroonian laws either. Why should it respect EU laws? Are EU laws more important than Republic of Peru laws?
- deleted 4y ago[deleted]
- eddsh1994 4y agoIf the website serves EU users and collects any personal data then it must follow GDPR. Fwiw, I think following Indian laws isn't an insane thing either seeing as tech is global and India is 4x bigger than the US - although I don't think there's any laws quite like GDPR in India that'd actually matter.
- ransom1538 4y agoWell, it MUST follow Cameroonian law too then. What if they conflict? "GDPR in India that'd actually matter" Ah. There it is. The EU matters, others don't. Well, I think that is a terrible elitist opinion. I vote HN shouldn't bother enforcing other counties laws.
- djbusby 4y agoEuropean laws for European residents, Cameroonian law for their residents. California law for those residents, Massachusetts law for them. So request deletion before you leave CA.
- eddsh1994 4y agoThe population of Cameroon is 1/10th of the US so it seems less important. The population of the EU is almost double the US, and the law encompasses all companies globally that store data of people living there. Seems sensible to follow it else you'll be paying GDPR fines out your nose. If India came out with some consumer-friendly law that Indians can ask Dang to delete their comments, and I'd bet a good percentage of HN are Indian, I'd agree it's something that should be included. This is part of the difficulty of a global website :)
- deleted 4y ago[deleted]
- 4y ago
- tdeck 4y agoIt has to follow the CCPA presumably, which is very similar.
- notananthem 4y ago"it applies to any entity (any person, business, or organization) that collects or processes personal data from any person in the European Union" It should
- generalizations 4y agoHN is a US website. The EU doesn’t have jurisdiction in the US. I’m pretty sure it’s that simple.
- eddsh1994 4y agoYou're wrong. https://www.cookiebot.com/en/gdpr-usa/#:~:text=Does%20the%20GDPR%20apply%20inside,to%20collect%20their%20personal%20data https://www.cookiebot.com/en/gdpr-usa/#:~:text=Does%20the%20....
- generalizations 4y ago> The GDPR has extra-territorial scope, which means that websites outside the EU that process data of people inside the EU are obligated to comply with the GDPR. I see that site makes the same assertions about jurisdiction that the comments here are making. However, it provides no explanation for why the EU can actually claim that jurisdiction, which is my whole point. Why are they obligated? How does the EU have such authority? I say it doesn’t, for the simple reason given upthread, and you have provided no evidence to the contrary.
- anigbrowl 4y agoSame reason Americans can sue companies from other countries in American courts: treaty recognition of legal judgments.
- generalizations 4y agoYeah, but AFAIK there is no such treaty.
- counttheforks 4y agoDang has confirmed via email he doesn't care about GDPR and has no intention to conform to it.
- noasaservice 4y ago
- justinzollars 4y agoor at the very least be able to change your user name to something that is obfuscated
- 8organicbits 4y agoI don't think that technique works too well. The bigtable dataset (and I believe firebase as well) both keep the original comment and original username. If you change your username, then someone can trivially check old comments on bigtable and see how HN currently renders those same comments today to learn the new name. Although increasing the complexity of doxing is a worthwhile goal.
- deleted 4y ago[deleted]
- ldjb 4y agoSee the FAQ [0]: "Can I delete my account? We try not to delete entire account histories because that would gut the threads the account had participated in. However, we care about protecting individual users and take care of privacy requests every day, so if we can help, please email hn@ycombinator.com. We don't want anyone to get in trouble from anything they posted to HN. More here [1]." [0] https://news.ycombinator.com/newsfaq.html https://news.ycombinator.com/newsfaq.html [1] https://news.ycombinator.com/item?id=23623799 https://news.ycombinator.com/item?id=23623799
- wannabeanon 4y agoI saw that but I’m looking for an automated approach that doesn’t involve email, which increases the surface area for doxxing. I feel like this is a pretty humble request, HN is the only site I can think of that doesn’t let users delete their own data. The world is a much different place then it was when HN was founded and it seems like this feature would be important to many people.
- peruvian 4y agoHN is put together with lisp-flavored duct tape. It is not reddit or a Discourse forum with robust admin tools. I had to email dang to change my username (quick response btw!).
- rahimnathwani 4y ago"doesn’t let users delete their own data" I consider my HN comments to be contributions to the HN community. I received some benefit in return for those comments, e.g. responses that improve my thinking. I may retain copyright over those comments, but by posting them on a public forum I've given that forum licence to publish them.
- avereveard 4y agoIrregardless of your license the site need to comply with local regulations. In gdpr especially consent might be retracted at any time regardless of whether the consent was given or not at the time.
- deleted 4y ago[deleted]
- amelius 4y agoDo other commenting websites (like Reddit, Disqus, ...) allow the user to delete an account and all the associated comments? I think Reddit only shows [deleted] next to a comment, with the comment still there. Are they obliged to delete the comments according to laws like GDPR?
- joshuamorton 4y agoIt's possible to go back and delete individual posts, which hn doesn't allow.
- deleted 4y ago[deleted]
- deleted 4y ago[deleted]
- 13of40 4y agoOne thing to be aware of for Reddit (and perhaps HN) is there are multiple scrapers archiving it in real time, so even if you delete a post from the main site it's still going to be available to anyone who takes the time to look. I would assume that government agencies archive and index all of that low hanging fruit as well.
- fasthands9 4y agoI would think this is true though admittedly I think 95% of people just want their comments deleted so co-workers/friends can't stumble upon a semi-political hot take from a few years ago. Not because there is anything illegal or even career ruining.
- generalizations 4y agoI don’t think hn is subject to GDPR, since hn is based in the us, and GDPR doesn’t have jurisdiction.
- 4y ago
- deleted 4y ago[deleted]
- qwertyforce 4y agoThe problem is the data is already archived, indexed, and probably in some machine learning dataset
- bob1029 4y agoExactly. The first thing that popped into my head was "archive.org". The only thing that ever helped me was setting my HN comment delay to a non-zero integer. That 1-5 minutes is usually when I want to delete something the most. I think we are relearning some basics about the internet. HN cannot protect you from yourself. If you press the "reply" button, assume that under that button is a synchronous blocking call wherein your comment + username + timestamp go to a database owned by a 3rd party with questionable intentions.
- shagie 4y agoFor any wondering about that 'delay' feature - https://news.ycombinator.com/item?id=231024 https://news.ycombinator.com/item?id=231024 It is a field in the settings.
- MerelyMortal 4y agoJust because an attack can already be carried out by one entity, doesn't mean the attack surface shouldn't be reduced for other entities.
- pifm_guy 4y agoAnd before long, someone will make a 'deleted comment finder', which highlights only deleted comments. Could be especially handy for journalists and law enforcers.
- shagie 4y agohttps://console.cloud.google.com/marketplace/details/y-combinator/hacker-news https://console.cloud.google.com/marketplace/details/y-combi... > This dataset contains all stories and comments from Hacker News from its launch in 2006 to present. Each story contains a story ID, the author that made the post, when it was written, and the number of points the story received. > This public dataset is hosted in Google BigQuery and is included in BigQuery's 1TB/mo of free tier processing. This means that each user receives 1TB of free BigQuery processing every month, which can be used to run queries on this public dataset. Watch this short video to learn how to get started quickly using BigQuery to access public datasets.
- dataviz1000 4y agoInteresting. I'm more concerned with the stylometry showing accounts which don't belong to me saying things that I might not agree with and have never said being accidentally mistaken for one of my own accounts.
- ALittleLight 4y agoThe stylometry "attack" doesn't get around plausible deniability. For example, for me, two of the top ten related accounts are actually me - but I don't think you could tell which and even if you could be pretty sure I could always say "no" and I think it would leave either you or an observer uncertain. I don't think my employer or future employer would fire me because an account that's kind of similar, lexically, to mine said bad things about the company - or whatever. If your threat model is people cancelling you for controversial statements - I don't think there's anything to worry about. If your concern is governments or stalkers coming after you - then deleting your account probably won't solve the issue because they'll be able to access archived versions. These actors don't need to "prove" you said something to anyone but themselves. In this case the solution is just not to post anything sensitive regardless of the name you publish under.
- tinus_hn 4y agoRule #1 on the internet: if you don’t want something on the internet, don’t post it to the internet because once you do it’s pretty much impossible to remove it.
- kogir 4y agoSince nobody has linked it yet, there's a comprehensive document covering this and related topics, here: https://www.ycombinator.com/legal/ https://www.ycombinator.com/legal/ YC has multiple in-house lawyers. They're not going to risk their business over this. However, I'm unaware of any law that requires the process be completely automated.
- samus 4y agoGDPR and similar laws require action within certain timeframes. If the volume of requests increases, it becomes worthwhile to think about automating timeconsuming parts of those processes.
- ed25519FUUU 4y agoHN doesn’t need to even to delete the posts themselves, just delete the association of posts with an account.
- newbieuser 4y agoHN is a project carried out with the motto of zero features. So there is probably no such feature and never will be.
- cassianoleal 4y agoThat's absurd. What about the feature of posting a link? Writing a comment? Replying on a thread? Reading the comments? Sorting by new? Voting, flagging... There are lots of features on this site.
- AlchemistCamp 4y agoHN doesn’t care. In the past, I requested this very feature citing both the increasing ease and likelihood of correlating user data since 2006 and the very much increased safety risk of certain speech wrt to various authoritarian world actors. In an email to hn@ycombinator.com, I wrote: > ”I understand the user interface doesn't provide for comment removal, but with all due respect it's only a matter of time before that policy contributes to the imprisonment or even death of some of your users.” > ”It's too late to be entirely safe from historical comments but we have no idea how much the threshold for what is truly dangerous to have said on the internet will change going forward. Even a small decrease in the personal risk going forward is important to me.” HN’s response was no, because that would “gut the threads the account had participated in”. He then suggested there was upcoming an account renaming feature. Obviously, that feature would do nothing to alleviate the doxxing concerns brought up by the OP. It was very disappointing. YC literally put a higher value on maintaining old forum threads than reducing risk former users faced being detained, beaten or killed by religious or political organizations.
- pr337h4m 4y agoEverything will remain available on the Wayback Machine even if HN nukes your account
- kyleyeats 4y agoAnd deleting your account here would signal to bad actors to look there.
- counttheforks 4y agoYou can email them and they will remove the content. Unlike HN.
- shagie 4y agoYou can get them to remove a page without too much difficulty. It may be more difficult to get them to remove a subset of the content on of every capture of https://web.archive.org/web/20220000000000*/https://news.ycombinator.com/item?id=29344709 https://web.archive.org/web/20220000000000*/https://news.yco... That becomes even more difficult if you want to have them find (and remove) all comments from all captures on all pages for a particular user. Noting that you don't have authoritative control over HN, archive may be a bit reluctant to have {random person} asking for all of the comments that {random account} made on all the captures to be removed. If archive was able and willing to do that (remove content from a random account as requested by a random person), I believe that it would be abused much more than it was used.
- MonkeyMalarky 4y agoYou know how much it sucks to google something, find a super relevant reddit thread, then because its old and half the accounts are gone it's just one deleted user replying to another? It would be sad to see HN become the same. Some of the most interesting content are old threads that are re-linked in new comments.
- aaron695 4y agoIt's always funny people don't seem to get you don't own your data on HN. The algorithms used are also not transparent. Whether that's good or bad is a moot point to discuss while people are to stupid to even get the basics. Let's talk about whether the cia could scape archive.org and use stylometry on single comments on a system we don't even get the basics on.
- logifail 4y ago> HN’s response was no, because that would “gut the threads the account had participated in” I participate at Flyertalk, and a good friend of mine had a major falling-out with them a few years ago. As a leaving gift, he wrote a script to edit every single comment he'd ever made over the [many] years he'd been contributing, to remove his many many thousands of comments. As a result, there are thousands of removed comments, and of course, many thousands of threads which are, well, gutted. In our new GDPR-aware world, isn't that his right?
- xg15 4y agoThere is also a psychological aspect of account deletion: Deleting an account can provide closure and make it clear to yourself and others that you distance yourself from a site - even if your old comments stay up. By preventing users from closing accounts, HN is deliberately blurring the lines of who is still active on the platform and who isn't. Lastly, if it really turns out there is a reliable method to associate HN accounts with a real-world identity, HN will get in trouble with the GDPR. Really guys, leave the comments up if you have to, but give people a way to remove their account from it.
- Trouble_007 4y agoDear Ones, the proverbial horse has long bolted, rss feeds and easy site scraping has long leaked all your stylometry data which long ago was leached up. What is the point of deleting your HN account, if multiple third party copies all ready exist?
- EVa5I7bHFq9mnYK 4y agoHow come they still didn't doxx Satoshi Nakamoto, with all those smart tools?
- jll29 4y agoAn optional data retention policy would have the advantage of not exposing HNers to the risk of having their data taken to train a language model that emulates their style (which in the audio medium is called "voice morphing", and in the video medium is called "deepfakes"; it doesn't seem to have a name of its own in the written medium yet).
- jacooper 4y agoIts rather too late now, the cat is out of the bag. I think there are many other archives such as one posted above hosted by Google's bigquery. a better strategy would be to divert your writing to something new and different, defeating simple stylometry analysis.
- Mandatum 4y agoBased on HackerNews' current policies, it is impossible to address your concerns surrounding content posted. HackerNews leadership have chosen to not allow anyone to delete content after a period. Regardless, it would be pointless given how easy it is to scrape this website (on purpose).
- yunchley 4y agoThis makes me glad that I decided a while ago to use only throwaway accounts on HN, to avoid doxxing. One account per thread, and no more. Good luck tracking that, stalkers.
- t0bia_s 4y agoEmail suffix.