That is to say, each one cannot make much of an impact, but the responsible thing to do would be to not contribute or at least openly advocate for change from within. If enough people inside shift, then change can happen.
Can't wait until first party isolation is the default in browsers.
Oh and default no js means that I typically don't see those pubups in the first place.
Archive.is, it is.
AND drop all cookies from all domains.
> There are many, many, ways
There probably are. I haven't ever seen it work though. If I get into incognito, my ads show something different my normal profile.
In theory, they can track you from your OS/browser combination (and many more variables), but is there a way to test it?
[0] https://www.gizmodo.com.au/2020/06/google-facing-us5-7-billi...
It’s not theoretical; it’s used in practice today.
I found a very convoluted way of opting out: https://twitter.com/pos43/status/1001331147110957056
It is now 2020 and I would be interested to see if these methods have been changed to make them easier or harder.
I use everything I can to prevent tracking on my machine. But for a general solution for everyone, I don't know what would be the answer, but I don't think it's GDPR. If it's to work, acts forbidden by GDPR need to be handled very fast, and without interaction from user nor legal mumbo jumbo. Without a zero-tolerance policy, the cheap tricks will only grow stronger.
Edit: So apparently if you criticize gov/bureaucrats on HN you get downvoted.
When they can set up anywhere and access everywhere it is asking to be flouted. Geolocated financial intergration is about the only area they can start to touch with enforcement. Without that they have about as much sway as a backwater dictatorship writing hate mail threatening arrest to every first world newspaper which refers to him as a dictator. Right or wrong morally they just look stupid and delusional.
The reason it is unenforced is that the agencies that seem to have the responsibility to do so are understaffed and afraid of the drawn out litigation and political backlash.
All this on top of the larger concerns in the GDPR - for example, companies that, once they've collected data for one purpose, proceed to process it for another purpose without any legal basis at all.
If you think that was an easy feat, then I don't know what to tell you.
Do you know how it was achieved? With finely tuned and ruthlessly efficient bureaucracy.
When people really care, bureaucracy works wonders.
Bureaucracy is basically formalizing social interactions for a specific topic. Formalizing something ossifies it, but it also prevents your pilot telling your copilot "Shut up!" just as the plane is about to crash into the mountain.
> Bureaucracy is basically formalizing social interactions for a specific topic.
One could even say that bureaucracy is one form of organized collective action. Which in general is quite necessary for humans as a social species.
I presume you meant commercial aviation, rather than aviation in general. Unfortunately not quite true even there. Your broader point stands though.
https://en.wikipedia.org/wiki/Category:Aviation_accidents_an...
Well no, you've neatly disproved it.
The reason it works for commercial aviation and not anything else -- not even aviation in general -- is that the bureaucratic processes used for commercial aviation incur a massive overhead. When you have a product which costs a hundred million dollars a unit anyway and can kill 300 people in one shot if it fails, you pay the cost. For anything else it's too expensive, but spending less money causes the bureaucracy to be ineffective.
And even in commercial aviation, the overhead is still there, it's just capable of eating the loss. (Or maybe it isn't, given the miserable lack of competition in that industry now. And then where does that lead us on safety, Boeing?)
Not to dispute the effectiveness of a finely tuned and ruthlessly efficient bureaucracy, but pilots and airlines have a strong incentive to not have fatal accidents; websites however have a strong incentive to track their users.
To use an analogy, enforcing this will be less like mandatory driving exams and more like net-zero carbon emissions.
It could be in an individual manager's interest because then they get a bonus and are working for some other company by the time the plane crashes, but the airline itself has the aforementioned incentive to put processes into place all on their own to prevent that from happening.
It’s not like a major airline is going to intentionally crash an airplane, but if they can trade 1 billion dollars for an extra crash every 20 years that’s a net financial benefit.
A 50 year old aircraft still costs tens of millions, and the biggest cost of a crash is the lawsuits anyway.
> especially when the options are to retire it or keep flying.
50 year old planes fly all the time. The options aren't retire it or keep flying, they're maintain it properly or don't.
> Further risking a crash when your airline is facing bankruptcy suddenly looks like a reasonable trade off.
Which is where the insurance company comes in, and we're back to having an existing bureaucracy with an incentive to prevent that from happening.
> It’s not like a major airline is going to intentionally crash an airplane, but if they can trade 1 billion dollars for an extra crash every 20 years that’s a net financial benefit.
The value of a statistical life is generally regarded as being about ten million dollars. Times 300 passengers that's $3 billion. So that's how much they can expect to get sued for when the plane crashes, in addition to whatever the plane was worth. If they're "only" saving a billion dollars, they're losing money.
And if they could somehow save more than 3 billion dollars then that's what they're supposed to do -- at some point safety measures cost more than the value they provide and VSL calculations tell you where that is. (And if you don't think so then I assume you never travel by automobile or buy anything that has ever been in a truck.)
Your lawsuit numbers are also wildly off. Ex: “The US aviation giant has settled the first in a series of lawsuits filed by families of 737 Max crash victims. Boeing will reportedly pay $1.2 million to 11 families of victims killed in the 2018 Lion Air crash.“ https://www.dw.com/en/boeing-settles-first-lawsuit-with-737-...
Imagine if we took car safety so seriously.
I am curious? How does regulation prevents that?
(and how does it prevent a suicidal pilot, from locking out the co pilot and crashing in a mountain on purpose?
https://en.m.wikipedia.org/wiki/Suicide_by_pilot
)
Why don't we just skip a few steps ahead - delete the internet and go back to cable TV? That's where we're headed for anyway.
The GDPR is actually sufficiently abstract IMO to make government enforcement possible and practical. And if you look at how tracking evolved, much of it is still the same old cookie-setting (from what, 25 years ago?) and the stuff that isn't (like ultrasonic profile matching and other shady stuff) is pretty clearly illegal. So it just needs political will on the national level where the enforcement agencies reside. Max Schrems' cases against facebook have shown time and again that these enforcement agencies are often simply unwilling to do their job, with the Irish one being a particularly bad example. But it is possible to do this.
EDIT
Also, regarding the personal responsibility aspect: we're being tracked by platforms we don't even have a user/customer relationship or any other contract with. Someone uploads a picture of me on facebook, and they build a profile based on that? Uncool. Is that a problem between me and the uploader? Certainly. Does that take responsibility from facebook to not mine that data? Nope.
But here's the big question: would these services have even existed in the first place if these laws had been in place? The internet has gained massive popularity because most of the resources on it are free. Look at porn - all of the known sites and run on ads, all the paid sites are essentially unknown. I don't know anybody who uses the latter. Wouldn't Facebook, Twitter, news sites etc have gone the same way if they required you to pay? Just look at what happens when a paywalled article gets posted. Either somebody posts a way to bypass it or a lot of people will never read the article.
Somehow they managed, without the need to track ones every move.
Would the internet look the same, with the same players and behaviours if these laws existed? No probably not. But I also don't think the internet is in a very desirable state.
Maybe, we would have had more invention and uaee acceptance in different ways to pay and consume services instead of this race to the bottom of cheap ads.
Yes, but aren't most of those newspapers essentially partisan politics? Every free newspaper I've seen IRL has been backed by somebody trying to push for politics. From my experience they also tend to not be that informative.
>Maybe, we would have had more invention and uaee acceptance in different ways to pay and consume services instead of this race to the bottom of cheap ads.
The problem is that there is no price equilibrium that will work. People from poor countries can't afford to pay what is a reasonable price for people from rich countries. Poor people in general can't afford to pay. Kids/teenagers can't afford to pay. And this gets complicated even more by the fact that we don't even have payment methods available to everyone. Even if you could afford it, you couldn't pay. Ie I've never owned a credit card in my life and as far as I know I'm not eligible for one. They have a minimum income limit that I fall under.
I'm saying that the ad model is what made the internet so commonplace for a lot of information.
As for informational value. They were good enough to keep up to date what is going on, and then use other sources to dig deeper.
I'm not against ads, in fact in small populations like Switzerland where I'm from, fully subscription funded news papers have never been viable to my knowledge. They were always majority advertisment funded. The subscriptions basically pays for having the news paper printed and delivered, not much more.
But the ads that used to pay the peoples bills were those full pagers, clients payed tens to hundreds of thousand of dolars for a single issue. It still worked reasonably well online on desktop with plenty of screen real estate, but with the raise of mobile prices collapsed.
I worked at one of the largest publishers in Switzerland during that time and saw first hand what got cut during re-org: Fact checkers, specialists, investigative departments, international correspondents, etc. News rooms from supposedly independent news papers in the portfolio got merged. More and more pressure to write article to perform on facebook.
All things that a normal reader will not immediately notice, but that severly affect quality and journalistic integrity long term.
While I think having all information available for everyone worldwide would be amazing, I don't see the current situation sustainable quality wise for anyone beyond the few top percent of market leaders.
I don't know how to solve it either, why I said, maybe we would have come up with different models if we didn't go down the path we did. And a lot of these old organisations have to take a lot of the blame of just not reacting to change for years.
But whoever you point fingers at, as it it stands, we are headed for a lose-lose information wise in my opinion.
If there was an easy way to anonymously pay the site the five cents they get from the advertiser without incurring 500% payment processing overhead then would sites even be using advertising?
But then we get to much the same result. What we need isn't new privacy rules, it's to delete the old banking rules that prevent efficient payment systems from operating.
You can actually make more money using a pricing model like that, because you get to charge $1 to everyone who will pay $1 (everybody wants everything ASAP), but in a few months you still get the quarter from the guy who would only pay a quarter. And having a large volume of free old works to show the world you can produce good material is how you get new customers.
Which also solves the problem for people without money. (This is, incidentally, how copyright was originally intended to work. Screw you again, Mickey Mouse.)
A lot of what we have online just isn't viable on pricing models like this. The main divide you'll see is likely by country due to wealth differences.
What do you say we try it and find out?
> So the moment you run into a paywall you will turn around and start searching for the same thing you were just looking for but for free.
Because the existing paywalls are some nonsense where you have to give them your home address and sign up to pay a recurring monthly fee which you know is going to be a bear to cancel and costs dollars rather than cents, whereas what it ought to be is a browser plugin that just pays them automatically when you visit the site as long as the amount is below your threshold (with a circuit breaker that requires you to manually approve if you get charged more than like $5 over the course of an hour).
None of them caught on though because when it comes down to it, most sites that successfully make money can probably make more money from advertising than they can from this microtransaction system so there's no incentive for them to adopt it.
We as society implement laws to prevent undesirable behaviour all the time. You can certainly argue that the law against robbing banks for example has prevented business innovation around bank robbery, but I believe this is a desirable outcome, and I think most would argee.
I think the internet providing so much information for free is what made it so amazing. I understand that it's not really free, but it's at no monetary cost to the user. The moment you slap a monetary cost on it you create a disincentive for the user to engage with the service.
I do understand though that nothing is free. We are probably going to pay a large price as a society for it.
Ads must die.
It's a proven, efficient, and universally approved way to already enforce food, fire, travel safety and so on. It's only logical that privacy safety follows the same steps. GDPR seems to be a good approach for it, just pending on widespread enforcement of the rogue entities that aren't yet following the law.
I liken the difference between actors to a housecat and a large dog with a lamb. The cat at worst could give some scratches but at worst would probably just annoy the lamb jumping into its wool and kneading it. The dog ideally would look after tbe lamb but could also inflict serious bites or even rip out its throat if it wants. Both may want the meat but only one has the ability to kill it to get what it wants. When it comes to unknowns as the lamb I would go with the cat as opposed to the dog out of sheer distrust.
First, there's the historic precedent of collected information eventually making it into the wrong hands. The Preussian "pink lists" are a classic example, but essentially everything that ended up as PRISM can be taken as a more modern example.
And yes, putting power into government hands so regulate the collection of that data, and then arguing that it's dangerous because of the government might seem a bit contradictory. It's not in my mind. These types of legislation are supposed to disincentivize the collection by private entities after all. Government and intelligence services are (too) close but they are distinct.
And then there's the very real [1] ([2] if you want it more juicy) possibility of corporations targeting individuals for one reason or another directly. Here in the west, this sort of thing would result in your Uber becoming more expensive or unavailable, but imagine being a government critic (or activist against e.g. organized crime) in Brazil right now. All that data going god-knows-where, with the express intent of the collectors to sell it to anynone? Not a great outlook.
[1]: https://en.wikipedia.org/wiki/Greyball [2]: https://news.ycombinator.com/item?id=23529035
It's just a question of how much the companies in question believe that the EU is going to come after them. Once the cost calculus shifts to being on the safe side it'd quickly turn into a norm, but it requires showing some teeth.
Additionally, the risks to advertisers and websites are quite large, which I'm not sure they fully appreciate (unless I'm misunderstanding something here?) - it's not that the consent form is illegal, after all - perfectly legal to have a confusing consent form. Rather, it's that all the personally identifying information thus collected is illegal acquired and held (and it's hard to argue the violation wasn't intentional, to boot!), and the fines for that can be quite large, and can be applied retroactively to whenever the GDPR came into force. Rules always get stretched, but specifically in this way sounds pretty unwise (unless they're cynically trying to have some subsidiary go bankrupt or otherwise encapsulate the risk).
With any luck, the GDPR norms on this front will become global norms, but it's too early to tell.
A coercive opt-in isn't so much illegal; it's simply void. Having a coercive opt-in would be fine yet weird (as I understand it) if you then proceeded to only retain and process personal information to the extent you would be permitted without the opt-in. (IANAL, and only as far as the GDPR is concerned, perhaps if it's misleading enough that violates some fraud statutes somewhere, but that's a different issue).
I can't stress enough how much of a game changer that is, by revealing the amount of third-party trackers on websites (in the order of up to 500 on a single site) alone.
So I guess GDPR works for me. There's a lack of enforcement, though. But that could change; for example, in Germany, bored law firms (eg those not having clients currently), or anybody actually, can print money by starting an "Abmahnwelle" eg. insist on GDPR compliance within a certain period of time, then sue any site for non-GDPR compliance, all the while being entitled for compensation of their expenses if they have a cause.
Sounds to me like it's not in general permitted (but with a huge exemption), but is possibly permitted to the extent that failure to comply with the GDPR constitutes unfair competition. So that means you can't simply use the "Abmahnen" procedure to enforce privacy rights, but rather need to demonstrate you're a market competitor and that it's relevant to your competitive position. Edit: no, I think I misread- that may be a possible conclusion but it's just not clear.
IANAL and all that.
This is very much not true. GDPR isn't restricted to regulating tracking on websites. It also restricts and regulates what companies can do with the customer data they are in possession of. Through my day job I constantly interact with large enterprises (Fortune XXXX) that have vast amounts of personal data through their regular operations (banks, telcos, car manufacturers, airlines, insurance companies and the likes). Nearly without exception they go to great lengths to ensure the data is managed correctly, not used for purposes the customer hasn't explicitly consented to etc. This is as a direct result of the GDPR.
I also do my best to avoid tracking (Firefox add-ons, Hosts file). But up until now I had no leverage against any companies. Now they ought to be afraid when they play dirty.
GDPR is about a lot more than the tracking stuff though, it is about the personal data companies hold and are responsible for, your permission to request it, the risk of fines if they don't comply. Whatever dark patterns they use for tracking logic, they are still bound to use best practice security on the personally-identifiable-information they may hold and may be fined if they do not. That is what GDPR is mostly about, as I see it.
And judging from comments here on HN, it seems to be working. Just two post above yours there's a comment stating that any government solution cannot fix the tracking issue, and it can only be addressed by a company or an individual
And I just upvoted for this piece of comedy:
> So apparently if you criticize gov/bureaucrats on HN you get downvoted.
It's useless because only a few people care enough to report these violations. If anything we need a campaign to get people to start reporting sites which violate the GDPR requirement of an informed opt-in.