If I had the relevant Presidential powers, I'd offer citizenship to every one of the threatened students, and the rats would be sent packing home to China the second they were identified.
The 50 cent lackeys of Pooh-Bear[1] are not welcome here in America. Go home, scumbags!!
[1] https://www.theguardian.com/world/2018/aug/07/china-bans-win...
More seriously, it's also interesting when you think back to how asylum worked during the cold war. Migrants, even explicit economic migrants, were encouraged to emigrate from communist countries (cuba, east germany, etc), while asylum seekers in imminent threat of torture and death (say, 70's era Iranians, 80's tamils, etc) were blocked.
As far as Czechoslovakia goes, the success rate was WAY beyond 1:10000, that is why people still tried.
About 400 people were killed on our militarized border with West Germany and Austria. The # of people who succeeded was actually over 10 thousand, especially in the earliest phase (1948-51), when the security of the border was far from perfect.
You could also escape in less dramatic fashion, for example by going to Yugoslavia (a non-aligned country) for a vacation and defecting.
Of course, whoever was caught and their families would face serious repercussions. In the Stalinist era, Gulag, after it, less pronounced bullying (loss of jobs, forbidden from higher education, forcibly moved to rural regions).
Trust me most students in US nowadays are family financial support. They are already rich. And the US do not often give enough working position for them (outside of tech, which h1b is not particularly friendly)
> better quality of life
This definitely is wrong. Those kids enjoyed a far better life in China than US.
> more personal freedoms.
Well, for what they want to do, they'll have more freedom...
they can stay there then lol
Bad assumption. Maybe an unpopular fact, but many sites simply block EU access to avoid potential legal pitfalls of navigating foreign laws. Getting the site compliant would require review from legal teams and work from (likely contracted) web developers, which is almost certainly not in the budget for a side site like this.
Not every website is backed by a corporation with on-staff web developers and corporate counsel to double-check everything. Their audience is primarily a local one, so allocating the budget to do this and maintain it isn’t worth it.
• A static site without JavaScript;
• with all images / external resources hosted on the same domain;
• where the logs are default configuration, don't leave the server (except as GoAccess reports), and are deleted / anonymised eventually;
is GDPR-compliant. Sure, there are other ways to be compliant, but this works, and is basically the default way of setting up a website. It's not hard to check whether this is how your website works.
You can get this knowledge with just the first 7 articles.
It's not the default way of setting up an online content management system to which student journalists can post articles without going through some convoluted command-line build process ("...then you do a git commit and push, run the Hugo script, and rsync the files to the server"... yeah, no.)
> It's not hard to check whether this is how your website works.
Since they're using a third-party content management system, they most likely neither know nor even care how the website works. Why should they? They're journalists, not system administrators.
As others have noted, this is an independent student newspaper. Their normal readership outside the Purdue community is probably in the low single digits on a percentage basis, and their EU readership is likely close to non-existent. They (or, more likely, the people who run the CMS for them) have concluded that a full audit of their system to ensure GPDR compliance is simply not worth it for the minuscule number of additional readers they'd gain. And they're almost certainly right.
I collaborated with some EE and ME students on personal projects, but they were 1) more interesting than GDPR and 2) friends.
You can’t just round up some CS students and have them produce a website compliant with international law for free.
This involves legal teams, contracted developers, and constrained budgets that are already stretched thin on operating in their core business. It’s not reasonable to demand they invest tens of thousands of dollars (or demand equivalent free labor from CS students and lawyers) to serve a population that almost never visits the site.
But the issue isn't "international law" in the general case (which, indeed, would be very hard), it's the specific case of the GDPR, the solution to which (for this particular site, which only serves static content) is mind-numbingly trivial: don't collect personal data, don't set cookies. That's it. That's all you have to do.
Though I'm not sure if a local US newspaper even needs to be compliant, since it doesn't target EU residents and thus might be out of scope.
Parent comment is convinced the site is doing something that would be illegal.
You are convinced that the site’s GDPR risk is non-existence.
It’s amazing how many people sitting on the sidelines can be so confident about GDPR while having entirely opposite opinions.
But my point stands: This stuff is complicated and requires sign-off from the lawyers in any large institution. If you don’t have a reason or budget to go through that process, you don’t do it. It’s not virtue signaling or anything silly like that. It’s basic corporate legal protections.
In fact this is the first one I’ve seen that isn’t being done as a protest.
For example, I still receive a lot of commercial spam that advertises in-EU businesses.
GDPR-related 451 is quite widespread in my experience, but that is what VPNs are for :-)
If you do not need opt-in consent just to view the page, then no coercive wall is ever required.
Literally every single one of the sites with so-called cookie walls can be divided into two categories: site owners that have no idea what the law actually says but they think it's trendy or something, and sites that have no legitimate interest or other legal reason for processing some data and therefore need to seek your "freely given" opt-in consent. If they already had a legal grounds, they wouldn't need to ask for it.
For most companies figuring out if they violate a foreign privacy law like GDPR and remaining compliant with it isn't a technical question, it's a legal one.
Attempting to hand-wave this away is likely what led to the decision to geo-block in the first place (tech person says "there's no risk", board says "prove it", lawyer says "pay me", tech person blocks the EU).
Possibly it'd be nice to have some boilerplate and possibly config tweaks for some of the most common default server configurations though. (Eg. for a standard Wordpress site).
This is really just scaremongering. Usually there are exceptions to a rule but here I feel fairly comfortable saying: show me a single case where someone got "hit with some fines" and then they needed a lawyer to "explain" things in a lawyery manner and then suddenly everything was fine whereas it wasn't when the site owners responded to an inquiry in normal human language.
If you don't do tracking for no reason and aren't blatantly invading privacy, you'll get a warning if anything -- and for a USA-only site, no country's DPA feels responsible anyway so I'd be highly surprised if they even got to the warning phase even if you were doing something wrong.
I know there are technically some requirements in every privacy policy, e.g. mentioning which rights the user has (I'm not in favor of having those, citing the law in every policy makes them much longer than necessary to read and dilutes the real content, and also it makes it so that you can't have a legal website without complying with the EU's specific laws -- that won't scale if all ~190 countries in the world try to pull that crap), but that's not the same as needing to lawyer up to wave away fines that you got hit with out of the blue as a website that had nothing to do with the EU in the first place.
That's not to mention that what's much more likely here is that a student focused and student run campus newspaper in West Lafayette, IN likely just considers the EU out of scope of their audience vs the cost of figuring out if they're GDPR compliant.
I for one am a little tired of EU citizens telling me something doesn’t have compliance costs when I’ve been in the room when outside counsel couldn’t agree if a brochure ware site was compliant because the logs contained IP addresses.
You may wish that the regulations didn’t make the choice of blocking EU citizens the more palatable but that doesn’t make it true.
At times it seems like the common sense behind the GDPR is not -in fact- entirely common to American (lawyers) somehow.
That can't be entirely true though, since some US states seem to have been considering similar laws recently.
Color me confused by it all. (see also an earlier comment I made in a similar conversation https://news.ycombinator.com/item?id=29126413 )
To trigger GDPR, you need to be collecting PII (of EU citizens).
What interest would a student focused and student run campus newspaper in West Lafayette, IN have in people's PII (let alone the PII of European Citizens) in the first place, and why would they be collecting it?