1. prevent you (or anyone else) using your handle to post submissions or comments
2. delete all posted submissions and comments in addition to option 1 above; this is a little futile as HN has been indexed and replicated elsewhere
EDIT: the following is incorrect, as pointed out by jacobsheehy.
I will note that both are possible without any assistance from HN, though perhaps option 2 could be made easier.
"Easy to sign up yourself and impossible to remove yourself" - the perfect dark pattern. All we need to ask now is "Why"...
You can't think of anything worse than not having a delete account button on a pseudonymous list of article comments?
> All we need to ask now is "Why"
HN already employs someone to manage this little discussion site, and he seems to have the bandwidth to handle an occasional delete request by hand. Why assume there's a more nefarious reason for not investing resources into automating that process?
Why is HN somehow outside of critique of Dark Patterns?
> HN already employs someone to manage this little discussion site, and he seems to have the bandwidth to handle an occasional delete request by hand. Why assume there's a more nefarious reason for not investing resources into automating that process?
The "little discussion site" is a feeder venue for the venture capitalist side. The words, "Strategic Operations" come to mind.
And I don't have to come up with "assumptions" of nefarious reasons. The fact is, that deletion is not available to us without significant dark patterns. Every other site has this to maintain data and/or users. Why would I expect HN not to be in this category when every other one is?
I believe you own the copyright to each comment though, but does GDPR cover PII only or all other data as well?
Threads would be confusing if non-leaf nodes were to be removed.
The YC privacy policy seems to me to patently be in violation of the GDPR. Namely Article 13(2)(a), (b), (c), and (d). It's arguable whether 13(1)(a) and (f) are being complied with as well.
They also appear to rely on consent. Consent can be withdrawn at any time (Article 7(3)) and the personal data must then not be further processed.
YC could change the legal basis for processing to, say, legitimate interests. This would allow them to claim that comments are an integral part of HN and shouldn't be removed as it would cause disruption.
btw I’m using HN as a convenient example; i don’t consider the maintainers to be naughty.
No. Consent is opt-in only. It must be "freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her" (Recital 11)
>And you could withdraw consent by simply deleting the cookie. You’d still have your “account” and related comments
The data would remain on HN, and thus would still be processed by YC. If deleting the cookie deleted the data then that would be okay, but it doesn't.
>; I can’t figure out if the comments themselves are “personal data”. I feel like they ought not be though the linkage of author to commend might be.
Personal data is any data about an identified or identifiable individual. So not every comment would - by itself - be personal data. But some would be, and the corpus of comments by an individual might be considered personal data in the whole.
>btw I’m using HN as a convenient example; i don’t consider the maintainers to be naughty.
I find it frankly incredulous that YC doesn't know about the GDPR, and yet they refuse to comply. Does that not qualify as "naughty"?