Some regulations are good. Some regulations are bad. Some regulations are smart. Some regulations are dumb. Reasonable people can disagree on the quality or intelligence of a given regulation, or its impact on a given industry, but that doesn't change that most regulations do tend to make products more expensive to manufacture and by proxy, more expensive to buy.
In Europe, if you want to sell eggs, you're required not to wash them or get them wet, because doing so erodes the natural coating that protects them from diseases. This is a regulation implemented to prevent salmonella.
In America, if you want to sell eggs, you're required to wash them in water at least 90 degrees, to make sure that they're clean, then rinse them with a chemically infused spray, then because you've got them wet, they need to be thoroughly dried to prevent bacterial growth. Further, because you've now washed and dried them, removing the natural protective coating, they need to be refrigerated in transit, at the store, and at home.
Both regulations are imposed to defend against Salmonella, and both are apparently quite effective, but the American regulations in play require the purchase of (conservatively) thousands of dollars in washing, sanitizing and drying equipment, and at least a partnership with a refrigerated trucking company. If you're selling the eggs in California, there's the additional requirement that the eggs were laid by free-range hens, which of course increases the amount of land required to raise the chickens upon, which of course makes it harder to prevent and protect the hens against predators.
Like I said, reasonable people can disagree on any given regulation, but it's hard to make the claim that egg regulations in America are more effective than those in Europe, or that the American regulatory environment doesn't make it the egg business a more capital intensive affair.
Not only that, even auto safety regulations do favor incumbents. There were far more new independent car companies created before the 1970s when the safety regulations were passed, and they were often created by small groups of people rather than huge established companies.
It's possible that the safety improvement is worth that cost, but that doesn't mean the cost isn't still there.
When we start talking about other industries where the result isn't literally a matter of life and death, it becomes much more likely that the cost outweighs the benefit. You're essentially talking about destroying competition -- the same competition that keeps companies from doing things you don't like.
If you want to pass regulations that destroy competition, those regulations had better prevent companies from doing more evil on net than competitive pressure does. Which is a pretty high bar.
Apparently there is some evidence that egg-related salmonella is 7x more prevalent in Europe vs the US.
I'm European and have never washed an egg before cooking it in my life. what is this ? I crack it open and cook it and am still here.
I do wash my tomatoes when I make a salad with raw tomatoes though. And that's mostly to get stuff off since I'd argue my vinegrette would kill all the bacteria.
And washing your potato ? I'm so confused. Don't we all cook potatoes in boiling hot water ?
As for potatoes, no, we don't all cook them by boiling them in water -- many of us bake them, fry them, or use them for making hash browns. This might just be cultural, but I would actually be more inclined to wash them before boiling them, since the reason you wash potatoes is because they have dirt on them, and just as I wouldn't want to toss dirt into my boiling water, I would prefer to clean (or peel) my potatoes before boiling them.
It is? What is the data?
No one here is saying that ALL regulations are bad or should be removed, just that all regulations have unintended consequences.
You can launch and run a business similar to Facebook from a dorm room.
A car factory? Not so much, regardless of the regulatory issues.
Maybe it's because the auto industry is far more capital-intensive than software. I don't see anyone taking on incumbents in capital-intensive IT businesses, such as cloud services (do you want to compete with Google, Amazon, and Microsoft with your VC money?), or in software, operating systems in entrenched markets (desktop and smartphone).
Taking the piss with laws and employment rights such as Deliveroo etc, or taking the piss with user data and personal privacy.
We'll be left with some of the regulation long after many of the disruptors that caused it have burnt out.
GDPR is full of vague terms and is global regulation based on principle rather than actual hard rules, which will increase costs and come nowhere near accomplishing the objectives it claims to do.
Modern cars need ABS, TPMS, electronic stability control, passenger airbags, a backup camera and crash test standards all but demand side curtain airbags.
Don't get me started on emissions. Fuel economy really isn't a big deal or hard to meet. It's the half million other little things that need to be in a specific range that really waste the R&D time and money.
For something like a low end subcompact compliance is a huge chunk of the price.
Given the choice between a 1999 Toyota Solara (or whatever) which has one or two airbags for $5k or a new subcompact hatch with none of the listed safety features for $6k or $7k I'd probably take the subcompact. There's been huge improvements in all sorts of non-safety aspects of vehicle design in the past ~20yr that the subcompact has that the old sedan doesn't.
There's rapidly diminishing returns for regulating cars because by driving up the price of new cars you extend the time that the old ones stick around and the people who choose less safe alternatives (see mopeds in Asia)
Saying "regulation that mandates $goodthing is good" as a blanket statement is approximately of the same dumbness as saying "regulation is bad" as a blanket statement.
Look at how fines work, say with the GDPR. The maximum fine is 20 million or 4% of revenue, which ever is larger, which means that small businesses see a much larger risk as a percent of revenue from these regulations. This is independent of the chance of the max fine being applied. This inherently creates a pro-incumbent bias even if nothing else about the law created pro-incumbent bias.
Now with something like car safety it's easy to say - no one will come up with something like this or if they do then the regulator will immediately allow it. But what about something like Internet privacy? I think it's more likely in that case for the rules like the GPDR to be used to protect incumbents by keeping out competition.
A more realistic example:
Regulations say cars are required to have steering wheels. They also say cars are expected to be under the control of a driver at all times.
Good and all if you expect to have human drivers. But it increases the cost of self-driving cars. And humans are terrible at mode-switching right before an emergency (we know this from studies on airplanes, as well as from studies on self-driving cars).
The two ways of solving this: (1) develop a self-driving car that doesn't need a steering wheel (ala trains under positive train control) or (2) restrict operation of self-driving cars to people who are highly trained and regularly operate cars in manual mode (ala the airplane industry).
Alphabet/Waymo/Google can afford the army of lawyers and lobbyists required to make this happen. All the other start-ups in this space had to get acquired by an incumbent (GM or Uber) or restrict their domain to something with less regulation (e.g. private land -- golf courses; university campuses; the Las Vegas Strip).
Selling used cars? Generally, as long as the car is sold as originally equipped, there's no issues. I can sell or drive a 1970s era car without having to add modern emissions equipment, bumpers, and airbags for example. At least I can where I live.
"A Federal agency today abandoned the longdisputed requirement that automobile manufacturers install automatic crash protection, such as airbags or ''passive'' safety belts.
The action by the agency, the National Highway Traffic Safety Administration, drew immediate protest from safety groups and praise from the automobile industry."
https://www.nytimes.com/1981/10/24/us/airbag-regulation-on-c...
I think by going to cars to prove your point proves how ridiculous regulation for websites are. For some reason there exists a group of people that believe that websites like facebook need regulations that are as strict as those required for developing cars.
People die from cars that are badly designed. People don't die from facebook (yes I'm sure you can find some contrived example.)
Unrelated but something that further adds to the irony of using cars as an example is that companies such as VW haven't even been fined for cheating on their emissions test.
I doubt a country like Germany would ever consider allowing the EU to fine 4% of Vws global revenue even though they broke the law in a way that has resulted in people's deaths.
The fact you think GDPR only applies to websites rather than the huge clusterfuck of personal data loss means you haven't understood the reason behind GDPR.
Equifax lost millions and millions of records and have so far faced no meaningful punishment from the UK regulators: as far as I can tell, they've so far made one brief statement on their website, and one tweet.
Major ISPs like TalkTalk lost millions of records (and ignored security researchers telling them about gaping security holes) and were given a slap on the wrist - £400,000 by the UK ICO. Mere pennies per user in fines; a drop in the bucket compared to their annual revenue. There is no economic interest to change their behaviour.
The negligence of these companies has led to millions of people having their personal and financial data stolen, having to keep eagle-eyed over bank statements and credit cards, having to worry that their transactions (or their travel bookings) might get flagged up as suspicious, that their credit rating gets eaten, and much else besides.
If a company you've entrusted your personal data with—not just your tweets or whatever, but sensitive personal data including health data, data about your religious affiliation, sexual orientation, etc. loses that data, as a UK citizen, you currently have no right to appeal the ICO failing to take action. GDPR/DPA2018 changes that balance.
Companies tell consumers "hey, trust us with your personal data". Consumers do in the false belief that there is some protection or basic responsibility taken. When they colossally fail to take the most basic steps to protect consumers from data loss, the status quo was this: nothing happens to them.
You present a false dichotomy here. As much as the GP is wrong for boldly asserting the negative as fact, you are wrong for just as boldly asserting the opposite, without allowing for the panoply of options that inevitably arise from the point a regulation is conceived to the point that it is enacted. During the process of drafting the legislation, at least here in America, the existing players have a voice on the legislation's course, and the larger the existing player is, the louder their voice gets to be.
Sounds like you need campaign finance and lobbying regulations. ;-)
Hacking is not a problem you can solve by passing a regulation that says "don't get hacked".
No, it boils down to an incentive. No company wants to get hacked, but a lot those same companies aren't willing to invest in security measures and training that could mitigate the risk.
> Hacking is not a problem you can solve by passing a regulation that says "don't get hacked".
I don't think anyone's proposing a regulation like that. However, it's not fair to put the costs of a data-theft squarely on the victims, when it was really the company that was responsible for securing the data.
It's also not even always clear what hacking actually means. A common way users get hacked is by reusing the same password on every website. One of those small sites gets hacked, the hackers try the users password at bigger sites to see if they work. Big players like Google and Facebook have heuristic systems that try to detect and block that, but sometimes they don't work.
So who's at fault then? The user for losing control of their password? The small site, probably not EU based, doesn't give a shit? Or the big guys who tried to protect the user but failed? Given the way the GDPR is being done my guess is the big guys will get taken to the cleaners even though they did nothing wrong.
Basically, you can't stop a big company from getting hacked no matter how much you spend on security.
I never said anything to the contrary, but the observation is irrelevant. You can't stop all pollution, but that doesn't mean you shouldn't pass regulations that ether ban it or impose liability for it.
The GDPR authors appear to believe that not being hacked is merely a matter of choice, despite all evidence to the contrary. They are clearly dangerously delusional. If even Google, with its pick of the crop, unlimited budget and massive security team, cannot avoid being hacked, then nobody else has a chance.
What they care about is how much data you had (and did you need all of it), did you tell the users, have you put things right, had you done anything to protect the data?
If you have a lump of data that you don't need, that you store with no attempt at encryption, and it's held behind software that you haven't bothered to update even though security patches have been released then yes, you're going to be regulated.
It was the financial industry and government that were responsible for implementing an identity scheme with a less insane architecture than handing the same secret material to every relying party. I disagree that we can or should force everyone to tie themselves in knots supporting it.
- Unpatched, publicly documented vulnerabilities.
- Unauthenticated S3 buckets.
- Unencrypted laptops.
- Default passwords.
This isn't subtle crypto weaknesses or attack vectors missed in the security assessment of protocol designs. It's carelessness. It's stuff that any high school kid who's good with computers will tell you about, let alone any IT professional or software engineer.
People who think defending networks is merely a matter of choosing not to get hacked have clearly never tried to do it.
It doesn't say "don't get hacked", it says "if (when?) you get hacked, minimize the the cost to people who trusted you with their data". And the easy way to conform is: 1. do not collect more than you need to provide the service, and 2. do not keep the data you don't need any more just in case. Which should be the default, but in the world of cheap storage and data mining seems to be forgotten, or an afterthought. E.g. when a user unsubscribes we tend to set the flag "subscribed" to false next to the rest of their data, instead of removing the e-mail address we don't need.
Good work everyone.
We'll see. I have a feeling that European consumers and web companies are in for a world of hurt.
>The fact you think GDPR only applies to websites rather than the huge clusterfuck of personal data loss means you haven't understood the reason behind GDPR.
I know that GDPR applies to everyone, I think it's pretty obvious it will be selectively enforced since the regulation is too burdensome. Do you think your local mom and pop hair salon that is not in compliance will ever be fined?
Exec has been fined and sentenced to 7 years[0] VW have been fined $2.8B[1]
[0] https://arstechnica.com/tech-policy/2017/12/judge-sentences-...
[1] https://www.nbcnews.com/business/autos/judge-approves-larges...
You must point to the laws violated. E.g. Schmidt made a false statement to the California Air Resources Board under the Clean Air Act.
Trial in the court of opinion and mob lynching is not compatible with the Western tenements of law.
>Trial in the court of opinion and mob lynching is not compatible with the Western tenements of law.
Stop trying to shift goalposts, my point is that if any company deserved to be fined 4% of global turnover it's VW and they have currently received a total of $0 in fines even though they have probably increased the likelihood of you getting cancer.
Their annual profit is about $13BN, they were fined $2.8BN which is about 22%. I think that along with imprisoning an exec that was complicit in the lie is a significant and reasonable deterrent/punishment.
As for VW significantly increasing the likelihood of any given arbitrary citizen getting cancer I'd love to see the numbers on that. Sounds like hyperbole to me[0]
[0] http://scienceblog.cancerresearchuk.org/2012/06/14/diesel-fu...
I think the public, and much of HN, disagrees and is beginning to believe that the lack of privacy is undermining democracy, liberty, and human rights.
There are actually some historic examples. A university once performed scientific research on a minority group. Then the Nazis acquired the list and murdered the participants.
https://en.m.wikipedia.org/wiki/Institut_f%C3%BCr_Sexualwiss...
Obviously that's at risk of happening again, but machine learning and AI are risk of learning to be discriminatory by training on data sets resulting from historic and modern discrimination.
When applying for jobs, it may be possible to enter somebody's info into a next generation background check software to get a % probability of the candidate voting for a specific political party, and declining to call/interview based on that alone.
Even when it's not intentionally discriminatory, this is leading to a future where the teller says "sorry, you were declined. I don't really know why, the computer just made the decision". Where's the accountability?
In credit reports, I can at least request my credit report and understand how to improve my score or dispute line items.
In the US, people who gave their information to the government as part of a program to protect them from deportation are being deported.
Privacy and safety/security are not distinct concepts.
It is for that reason in the German constitution.
It's not like a future hypothetical fascist dictatorship isn't going to have access to the necessary records to piece it together or would follow its own GDPR constraints, nor would the GDPR stop it from arbitrarily deciding some people are Jewish without detailed evidence.
I'd like to think the GDPR is underpinned by better philosophy than a false hope it could prevent a future Holocaust.
A core rule of data privacy is to restrict yourself to the necessary information you need. Religion like sexual orientation is rarely justifiable why it is collected at all.
Onerous regulations are always overcome, one way or another. (And airbags are not onerous.)
Car manufacturers are required to put seatbelts in their cars because of regulation. In this case, it's not done to "decrease competition". It's not done to "increase monopoly". It's not done to "create central hubs of systemic risk". It's done to save lives.
Regulations affect profits, yes. Regulations may have unintended consequences. Making regulations that protect people and still allow for a healthy free market is a hard thing to do. It's heavily context- and market-dependent.
It is what it is and we have to live with it, but it's not as black-or-white as you make it sound.
When Amazon entered the French market, it tripped over laws putting a floor on discounts allowed that are intended to protect book sellers, not purchasers.
Except in Europe where it has done the exact opposite for telecom, especially compared to the unregulated US.
> unregulated US
On the contrary, telecoms are very much regulated in the US. There is an entire commission for regulating radio/television/cable communications: the FCC.
I could hardly choose a more regulated industry than telecommunications.
Regulation can mean different things to different people. It's just stupid, one-dimensional, shallow thought to try to paint all regulation with a broad good-vs-bad brush.
And while all those has their share of monopolies, I do not see how the current data handlers on the web before GDPR is better. Google is massive. Facebook is massive. The number of online news papers that hold 90% of the market are few. Talking about how regulations is going to increase monopolies where its already monopolized seems strange.
I realize that I've heard that before, but what is that based on?
> There is no free lunch with one-size-fits-all rule making. Unfortunately regulators think there is.
I've never heard of regulators, at least in the U.S., not considering the cost of regulations. It would be hard to avoid in the legal rule-making process.
Whio is more likely to be hurt by GDPR. Google, or DuckDuckGo?
Have there been studies on this?
See everything from lemonade stands[1] to taxis[2] to banks[3].
What is disputable is whether in total a regulation has a net positive or negative effect.
[1] http://www.newyorkcityfamily.com/2017/08/are-lemonade-stands...
[2] https://www.linkedin.com/pulse/uber-business-model-breaking-...
[3] https://www.investopedia.com/ask/answers/031015/what-barrier...
A lot of things “make sense” but aren’t true.