7 ms·
See the FAQ [0]: "Can I delete my account? We try not to delete entire account histories because that would gut the threads the account had participated in. H
by ldjb 4y ago
See the FAQ [0]:
"Can I delete my account?
We try not to delete entire account histories because that would gut the threads the account had participated in. However, we care about protecting individual users and take care of privacy requests every day, so if we can help, please email hn@ycombinator.com. We don't want anyone to get in trouble from anything they posted to HN. More here [1]."
[0] https://news.ycombinator.com/newsfaq.html https://news.ycombinator.com/newsfaq.html
[1] https://news.ycombinator.com/item?id=23623799 https://news.ycombinator.com/item?id=23623799
- wannabeanon 4y agoI saw that but I’m looking for an automated approach that doesn’t involve email, which increases the surface area for doxxing. I feel like this is a pretty humble request, HN is the only site I can think of that doesn’t let users delete their own data. The world is a much different place then it was when HN was founded and it seems like this feature would be important to many people.
- peruvian 4y agoHN is put together with lisp-flavored duct tape. It is not reddit or a Discourse forum with robust admin tools. I had to email dang to change my username (quick response btw!).
- rahimnathwani 4y ago"doesn’t let users delete their own data" I consider my HN comments to be contributions to the HN community. I received some benefit in return for those comments, e.g. responses that improve my thinking. I may retain copyright over those comments, but by posting them on a public forum I've given that forum licence to publish them.
- avereveard 4y agoIrregardless of your license the site need to comply with local regulations. In gdpr especially consent might be retracted at any time regardless of whether the consent was given or not at the time.
- 9wzYQbTYsAIc 4y agoThis is the full license you give for posting to HN: “By uploading any User Content you hereby grant and will grant Y Combinator and its affiliated companies a nonexclusive, worldwide, royalty free, fully paid up, transferable, sublicensable, perpetual, irrevocable license to copy, display, upload, perform, distribute, store, modify and otherwise use your User Content for any Y Combinator-related purpose in any form, medium or technology now known or later developed.” [1] [1] https://www.ycombinator.com/legal/ https://www.ycombinator.com/legal/
- asdff 4y agoIt almost reads like this forum is designed to be a training set
- 9wzYQbTYsAIc 4y agoI just assume that I’m contributing to a variety of machine learning efforts when I post on HN.
- rahimnathwani 4y agoThat page links to another page for California residents, which includes: Exercising Your Rights: California residents can exercise the right to request deletion of Personal Information by contacting us at hn@ycombinator.com.
- yjftsjthsd-h 4y ago> an automated approach that doesn’t involve email, which increases the surface area for doxxing. Under what threat model does it meaningfully increase the surface area? If you're worried about HN admins then I think email is the least of your concerns (I'm pretty sure they can see your IP address), and if you're worried about the general public then your email isn't being leaked to them so it shouldn't matter.
- MerelyMortal 4y agoThen for the threads to be preserved, the content should remain, but the associated username should just be changed. I imagine if HN created an account with the username "DELETED" or similar, that a script could just change comment ownership from the account to be deleted to the special "deleted" account - that would be the easiest to implement as well as keep thread continuity. (Don't delete the comment just delete the connection to the user.)
- philwelch 4y agoThat still doesn’t account for the stylometry.
- MerelyMortal 4y agoYes it does, not everyone gets a unique "deleted" account. Everyone's comment gets attributed to a single special "deleted" account.
- Operyl 4y agoThe problem still remains: HN’s “API” is incredibly simple and people have full datasets downloaded locally for every comment. In this case, the OP is already out of luck if he’s looking for anonymity against a hostile entity.
- MerelyMortal 4y agoThat problem seems like an extreme outlier. Such user protection would prevent "crimes of opportunity". The average person is not going to have a constant backup of HN in case one day they might want to spy on someone's past.
- AnimalMuppet 4y agoAnd if they do, they're likely to start with Twitter or Facebook - something useful against more of the population. HN users are still very much a minority.
- ilyt 4y agoSo not GDPR compliant ?
- hijodelsol 4y agoTo my understanding they would still be GDPR-compliant if they delete your data upon receiving an email that you would like to exercise this right under GDPR, even if they don't automate that process but IANAL. Perhaps someone can confirm whether this has in fact worked for them in the past.
- ldjb 4y agoAlthough many large websites and services allow you to request erasure of your data in an automated way, this is not required by GDPR. GDPR allows individuals to request erasure verbally or in writing, and the data controller than has one month to respond.
- pifm_guy 4y agoThere is no requirement to automate GDPR requests. However all organisations must be able to handle GDPR requests via any communication channel. Eg. They need to treat a data deletion request sent via twitter DM as a valid request if they have an official Twitter presence. It is insufficient to require the customer fill out a special web form.
- misnome 4y agoIsn’t it all organisations _that do business_ in the EU? Since this is a free forum with no paid features, I wonder if it would be excluded?
- chriswait 4y agoIANAL but I don't think it matters whether the purpose of collection is specifically to facilitate paid features. From the European Commission: > The GDPR applies to: [...] > 2. a company established outside the EU and is offering goods/services (paid or for free) or is monitoring the behaviour of individuals in the EU. Assuming account names or the content of comments constitute personal data within GDPR, I think YCombinator falls into this group. Edit: I forgot HN collects an optional email address too, which is definitely personal data. Details here: https://www.ycombinator.com/legal/#:~:text=Hacker%20News%20Information%3A https://www.ycombinator.com/legal/#:~:text=Hacker%20News%20I...
- Beldin 4y agoWhile [0] doesn't come across as GDPR-compatible to me (not a lawyer), the further explanation in [1] sounds a lot more compatible with it. Basically, HN will work with a requester to update the site to give the desired amount of anonymity whilst preserving history as much as possible with those limitations -- including editing past comments. Full GDPR compatability would probably require to support complete removal of user name and comment/submission contents as written - but even that seems on the table in [1]. (DanG could simply summarise each comment worth multiple replies and delete all the ones without replies.)
- squiffsquiff 4y agoWhilst the intention may be admirable, it doesn't look like this would be compliant with the GDPR right to be forgotten which applies to any natural person who can be identified.
- deleted 4y ago[deleted]