US Anti-Robocall Litigation Task Force
thecentersquare.com
thecentersquare.com
The carriers are clearly customer-hostile, as this is really a very solvable problem. Instead, we now are moving to alternate mechanisms to manage audio calls (eg: Signal, Whatsapp, Facebook, etc.). My wide-open Verizon cell-phone number is my least preferred method of contact by far, due to the fact that I cannot trust that unknown numbers are high-value incoming calls.
times have changed for phone calls, but the lack of Anti-Spam from these providers only hastened the change away from their core service
Here is an app that allows any rando person in the world to cause your device to wake up, interrupt whatever you are doing, display a notification, play a sound, vibrate, and if you push the green button, that rando person (identifiable by a spoofable string of numbers) can hear and talk to you! It would not be well received in 2022 where privacy and digital well-being is increasingly important to people. Yet for historical reasons, it’s pre-installed on every phone.
At least with the old school phone, you could leave the receiver off hook to send the callers a busy signal or just unplugged.
I thought it was a legal requirement for phone network operators to leave phone numbers accessible to all, and hence their inability to effectively fight spam.
Otherwise, what would stop the situation from becoming like email, where email is more likely to be delivered if sent from a big player and less likely from a small player.
Why do I in Europe get almost zero spam calls or text while in the US it seems like a plague?
I suspect the vector is moving away from VoIP systems and more toward buying masses of prepaid plans and stuffing them into various contraptions that hold hundreds of sims to blast out messages/calls.
https://en.wikipedia.org/wiki/Public_switched_telephone_netw...
Again, I am not sure and very well may be wrong, but I think I recall reading or maybe just assuming that the FCC or maybe a global agreement bars individual network operators from not accepting calls from others within the network.
I imagine this gets very hairy due to international jurisdictions and things like caller ID spoofing.
See section on Legal Considerations:
https://en.wikipedia.org/wiki/Caller_ID_spoofing
An interesting conversation that came up in my research about this topic for why a telco might be barred from blocking against certain numbers:
https://www.techdirt.com/2007/03/16/can-a-telco-block-phone-...
I have no idea why European numbers might not get spam calls with the same frequency as American. Maybe the spammers are looking for English speaking people, or Americans are richer or easier to scam?
French numbers can get tons of spam calls, because there’s no shortage of impoverished French speakers in the world.
People who need to answer unknown callers for business reasons (small business owners, sales, etc.) get put on lists of "known active numbers" and may get multiple spam calls a day. Folks like me who can just ignore any unknown number & respond only if they leave a real voicemail, get FAR fewer (maybe 1 a month on avg). We tend to complain less about the issue (even if it is annoying & I still treat all unknown calls as spam by default).
Also, if you own a google device, they're very good at IDing spam callers. I recently switched from Google to Samsung and get far more.
Thus the smaller carriers were incentivized by profit to connect the calls.
And any new features or technologies often introduce or expose problems.
When Caller ID was introduced, there was a huge backlash around privacy. Callers were upset about having the number they were calling from being exposed. If a doctor called a patient it could expose his direct or home number instead of the office number. In the age of phone books, a phone number could be associated with an address. The ACLU sued to block Caller ID until it was possible to disabled it.
Because large call centers operated hundreds of numbers and wanted a way for them to all appear as the same business entity. Carriers later implemented ways for these customers to spoof Caller ID so that the carrier wasn't responsible for maintaining it. Carriers connecting calls had to trust the originating carrier's caller ID info as well.
All these requirements allowed for a bad actor to spoof Caller ID and for it to just be trusted.
Carriers use to have star codes you would use for certain features like disabling Caller ID, disabling Call Waiting, and, famously, calling back a number that called you. These are similar to the AT codes you can issue to the modem in your cellphone via the dialer. Kids today will never appreciate REM's Star 69.
When digital cellphones arrived, they presented some odd challenges too like the fact that call information was transmitted digitally to the carrier and not via analog tones. Because number presses on your cellphone didn't equate to analog tones over the line, cellphone users couldn't interact with IVR menu systems (e.g., "Press 1 for English...").
Character limits in SMS messages come from the fact that they occupied the null space in beacon messages transmitted between cell towers and phones. Before MMS was a thing you couldn't send longer messages or if your phone broke them up into chunks, they might be delivered out of order or not at all.
The bigger issue though is not about domestic origin calls, it's about foreign originated calls that the FCC has no power over. The domestic carriers had to forward these calls. There is traction gaining to require that calls that originate overseas verify their identity to US based networks. Domestic carriers can reject calls that don't verify (spoofed numbers that originate offshore).
That still may not stop all the spam calls but it will slow it down. The problem here is really that telephony became extremely cheap and accessible to the whole world.
Well, perhaps callbacks from helpdesks located in other countries, in which case give me time-boxed control over foreign calls, and perhaps a passcode that I can communicate along with my callback number.
There are billions of dollars at stake, of course. This is a solvable problem, and the FCC doesn't even need to get involved. The carriers care more about the money than their customers (so what else is new?)
I have never received a legitimate phonecall from overseas, and I don't expect I ever will. In every case that I've had a legitimate reason to talk to somebody overseas, we used voip-to-voip, never telephones.
They're not interested.
I can make this real simple. I don't want any robocalls.
And do you think illicit callers are going to follow the law? They're already committing wire fraud, and the software already exists.
A lot of the crime you see on TV comes from highly irrational and unpredictable people, but scamming is usually a pretty rational decision if you live somewhere where repercussions are unlikely and the expected income is high.
And I don't know why I have to get robocalls because gramma can't operate the internet.
And both my 80+ year old parents can navigate the internet well enough to get lab test results off of websites.
I just doubt that the result of your stated preference is a solution that would be workable enough for the general public. The rest of the world just wants the spam calls to go away but still get calls from their bank/pharmacy/doctor/school/etc. Asking them to choose between the two is not a solution for them, even if it is for you. No law maker is going to propose that. And your carrier already DGAF.
Most people do want fraud notifications from their bank, notifications from their utilities about maintenance, notifications that their kid's school is closed today, a call back from customer service when they ask for one, etc. But nobody would think or even have the ability to know about this when checking your "block all robocalls" option, and now you have created a new problem.
If you give people a footgun, they will use it, and they will blame whoever came up with the idea. This is why nobody will do what you are asking.
There will always be people left to the wayside, and we need to act when that number is manageable. 25% might be way too much to legislate against robocalls in all forms, but we need to weigh the loss against the gains; how many seniors would benefit from less scams?
You might as well ban robocalls for legitimate uses too, since legitimate users won't be able to rely on it anymore.
Surely most doctors offices use a vanishingly small amount of EMR providers, and they could support similar very easily.
An iptables concept with a user friendly UI would address much of this problem, particularly if we could filter on useful call origination data, or lack thereof.
If only they were required to use caller ID to reliably tell us who is calling...
Is it a legal requirement to allow spoofed caller ID from bad actors?
Spoofed IP addresses used to be a much bigger problem on the Internet than they are today (many examples but see Smurf Attack).
We collectively implemented security to reduce the threat. Phone companies could do the same for spoofed caller ID for companies that consistently abuse it.
Most of the large DDoS attacks are UDP reflection, the attacker spoofs the victims address and sends to chargen[1] servers or whatever. So spoofing is still alive and well.
[1] yes really, the worst ones are people who install Microsoft's Services for Unix and enable the chargen server to the public... It sends a 64k fragmented response. Thanks Microsoft.
Today’s situation is the product of literally 2.5 decades of encouraging and/or shaming Internet-connected networks into properly configuring their routers to drop spoofed packets egressing from their network with a spoofed IP address not from their network.
Back to the topic of telco spam. STIR/Shaken should maybe get us actual caller-ids soonish, I think there's one more deadline for small carriers that service actual phone lines. OTOH, what are you going to do with a real caller id? I'm pretty sure phone companies just don't want to do it anymore, there's no money in voice calling, and it'll fall apart like landlines have.
We were more sophisticated back then. So picture your netblock is 207.180.10.0/24 and you've directly connected all 200 computers on your Class-C netblock directly to the public Internet without any NAT. 207.180.10.0 is your network ID and 207.180.10.255 is your broadcast address.
Someone comes along and sends a 64 byte ICMP ECHO request to 207.180.10.255. And they get 200 responses. Literally every one of the computers on your entire network responds with an ICMP ECHO reply.
So now they can spoof an IP address from Victim IP address to send 1k ICMP ECHO requests to 207.180.10.255 and multiply their attack 200:1.
But now imagine instead of a tiny Class-C netblock they find a similarly configured broadcast address for a huge Class-A netblock. And their scanner counts 29,000 ICMP ECHO replies for each request they send out. Now their attack is multiplied 29,000:1.
And since they've been scanning for broadcast addresses on the public Internet every day for a month they have compiled a list of hundreds of them so the attack seems to be coming from everywhere.
https://www.fortinet.com/resources/cyberglossary/smurf-attac...
And they did this while loudly complaining that they don't want to become a mere dumb pipe! That is the true twist.
This has real world consequences, last year a lost hiker ended up declining calls from search and rescue[1] since they assumed they were spam.
There is a really easy and extremely effective solution to this problem - charge calls on both ends. Make the caller pay a few cents for every call placed instead of placing the full charge on the receiver.
1. https://www.npr.org/2021/10/26/1049252333/lost-hiker-mount-e...
Political calls and texts should absolutely be blockable by users if they so choose.
Cost-based calling may not be practical, IMO. I look at the amount of junk mail I get from the USPS and I am not sure a "sender pays" approach would result in a meaningful reduction with a cost structure that didn't also impact regular users. A rate-limiting approach on call origination could work, but in the end I still think that a simple that gives the users control to block unwanted calls/texts, coupled with an origination source validation would solve most of the problem. There is nothing preventing us from capturing and passing accurate call origination data.
Politicians want you to know who is calling - name recognition is important. "I got a call from X is a big deal".
It’s actually not the carriers. The carriers actual try to actively block spam.
It’s actual the Twilio’s of the world that originate the bulk of the spam.
The irony is incredible: the literal phone company cannot use their own product to contact their own customers, because they have let that product become a cesspool of spam.
iOS transcribe feature makes it easy to read the voicemail and then in the 1/20 case where it’s legit, i act accordingly
In my experience, the signal:noise of unknown calls is about 1:20. VMs, on the other hand, are much higher — about 1:2.
Are the carriers willing to stop robocalls and spam texts, but not able? The very idea is absurd, as it's their network. As others have pointed out it can't be that hard to identify and interdict abusive behavior on such a massive scale.
Are they able, but not willing? Then they're complicit, and should face wire fraud charges.
Are they both able and willing? Then why don't they?
If you're an Android and Tasker user you can take matters into your own hands and set Tasker as your call screen app. There are two different blocking types, one shows that you missed a call as a notification and one does not. I have set it so that all non-contact calls are rejected but I see a missed call notification. I also have a contact with a growing list of numbers that is rejected and I do not see a notification. Additionally there is a regex filter that rejects several area codes without a notification.
When I start seeing more spam calls from a random area code in Michigan (or wherever), I just add that area code to my regex filter and then just have to worry about clearing my voicemail at the end of the day.
If I'm expecting a call from a doctor or someone who is not a contact in my phone, I just turn off the profile and deal with some spam for a day.
Of course, I would love some strict regulations around this, but I do no expect the legislation to go far enough or be effective (I'm in the US).
it's not an unusual situation unique to that applicant. it's so rampant, that even the HR/hiring people will be subject to it and totally understand the request. if you want to stand out to me as a potential employer, being proactive and stating we don't have answer unknown calls as alternate arrangements via _____ method to set up a call.
I presume this is because these spammers just keep selling other spammers valid phone numbers to add to their own lists.
The only phone number that gets spam calls anymore is that Google Voice number.
For all other numbers, the calls have virtually stopped.
The problem with your method is that spammers call phones just to see if they pick up. This then confirms an active number that they maintain in their lists. This can be done legally because technically calling and hanging up and never calling again (from the same number) isn't spam. So just don't answer.
Not the ones from politicians.
- It's a simple technical problem to identify potential spammers. There are clear patterns & habits of robocallers to id them.
- It's fairly simple to confirm spam/scams by pretending to be a target.
- Scam spam calls, though profitable, are relatively isolated and any public support will make them easier to trace. So we aren't facing huge lobby pressure to oppose the nearly universal support for spam reduction.
So it's really just a matter of allocating the resources to do something, which is exactly what this is.
Sure, right now, that spam that's identical every time would be easy to detect and block. But if it's blocked, they start adding variation. Block that too and they get more and more creative. Every time a way to block the spam is found, the spammers just get more creative with getting around it. It's an arms race, and is essentially un-beatable because the spammers outnumber those trying to stop them by a magnitude or two.
I'm sure Google and Apple are nipping at the bit to add "Report as spam" in their apps, carriers just need to provide a way to ingest that information and have it be actionable by disallowing spoofing.
Nobody has called my bluff, but usually that call center stops trying that scam to your number. I guess that's enough to trigger a do not call by their supervisors or they don't want to get in trouble by even hearing that opportunity.
Unfortunately, I do occasionally get stuck in a system where I get a robocall, but once I get past the sweet robot named Mary asking for final living expense coverages, I now get a 'this number is no longer available' when transferred. After a couple of weeks, I do drop off that list too.
Legally require large providers to never allow their customers to falsify caller ID. Then have the large providers disconnect small providers who pass along fraudulent caller ID until all small providers are either out of business or aren't facilitating spammers.
It's literally that easy, but Congress has ducked this up time and time again, and the FCC has been neutered. We really need proper, technically sound legislation to fix this.
1) we get calls if one of our kids misses class. The number is of their school but they use an outside service.
2) we get calls from business on one of their lines but they want the number to show as the main number. Businesses have a few to a few thousand outgoing lines but they may have many too many thousand extensions.
3) there are people who work from home and call out to customers.
There are legit reasons to falsify caller ID. The issue seems to be more "this call is from a number belonging to a Verizon Wireless customer but it's originating from John's Bait and Telco".
If some random scammer tries to set its ID to the school, the call should not go through. If for some reason the school lends out its number to scammers, then the school should face legal consequences along with the scammer.
Using a caller ID name / number that you have the right to use is, of course, fine. Using a caller ID name / number that is clearly and obviously not you is attempting to mislead.
You can't walk in to a bank and say you're someone else. So, just like that, but with phones.
But I really wonder why you think it necessary to make excuses for scammers...
BUT... at the same time my wife called AT&T and kind of read them the riot act. We figured if everyone started complaining maybe they'd get their collective act together and start solving this. Overhearing the call, it sounded like the agent recommended moving to VOIP to gain access to tools to help cut this down.
If they can largely solve this on cell (we get maybe a 1/10th of the calls on cell) and voip, why can't they solve this for landlines? I suspect the industry has a vested interest to get us off of landlines/POTS.
No call center supervisor is going to allow an employee to keep asking 'Hello....hello....can you hear me....?" for very long.
As for robocalls...they just play all the way through. I don't care, as I'm not listening.
I get very few spam calls compared to my friends and colleagues.
Haven't gotten one in a year or so. Would love to know why. Does the well dry up a bit for them on that one particular thing?
Please put those who are doing this to jail for life. I will vote for you in the midterm election.
Simple bash script to lookup what companies own spam numbers. Almost all of my spam calls are from domestic VOIP companies.
>>> ./lookup.sh -n 907-200-1234
"GCI COMMUNICATION CORP. DBA GENERAL COMMUNICATION"
>>> ./lookup.sh -f path/to/numbers.txt
"GCI COMMUNICATION CORP. DBA GENERAL COMMUNICATION"
"CELLCO PARTNERSHIP DBA VERIZON WIRELESS - NC"
"ONVOY, LLC - TN" 907|200||GCI COMMUNICATION CORP. DBA GE|PCS||6872
Given 907-200-1234 lookup.sh looks it up by grepping for '907\|200\|1'.Compare to a number that works, 858-598-7654. That ends up grepping for '858\|598\|7' and that matches this line from database.csv:
858|598|7|T-MOBILE USA, INC.|PCS|tmomail.net|6529
In general lookup.sh looks for the first 3 digits of the phone number in the first field of database.csv, the second 3 digits in the second field, and the next digit in the third field.Looking up 907200 or 907-200 (but not 907-200-) will match.
I'd guess that the database allows a blank third field to mean that the entry covers all numbers that match the first 6 digits that aren't covered by a more explicit entry.
If that's the case the database is not using that mechanism optimally. For example there is this:
360|654||ZIPLY FIBER NORTHWEST, LLC DBA|ICO||4324
360|654|0|ZIPLY FIBER NORTHWEST, LLC DBA|ICO||4324
360|654|1|ZIPLY FIBER NORTHWEST, LLC DBA|ICO||4324
360|654|2|ZIPLY FIBER NORTHWEST, LLC DBA|ICO||4324
360|654|3|ZIPLY FIBER NORTHWEST, LLC DBA|ICO||4324
360|654|4|LEVEL 3 COMMUNICATIONS, LLC - |CLEC||6121
360|654|5|AT&T - LOCAL|CLEC||7421
360|654|6|LEVEL 3 COMMUNICATIONS, LLC - |CLEC||6121
360|654|7|ONVOY, LLC - WA|CLEC||483E
360|654|8|ZIPLY FIBER NORTHWEST, LLC DBA|ICO||4324
360|654|9|ZIPLY FIBER NORTHWEST, LLC DBA|ICO||4324
which could be reduced to: 360|654||ZIPLY FIBER NORTHWEST, LLC DBA|ICO||4324
360|654|4|LEVEL 3 COMMUNICATIONS, LLC - |CLEC||6121
360|654|5|AT&T - LOCAL|CLEC||7421
360|654|6|LEVEL 3 COMMUNICATIONS, LLC - |CLEC||6121
360|654|7|ONVOY, LLC - WA|CLEC||483E
There are 92492 different 6 first digit combinations where the database has explicit entries for all 10 possible 7th digits has a wildcard/default entry also. Cleaning up all these will cut the database.csv size to 52% of its current size. Appended is a script to do that.Anyway, it seems like what lookup.sh should be doing is doing the 7 digit lookup like it does now, but if that doesn't match try a 6 digit lookup.
Here's a script to clean up database.csv. The output is sorted by name not number, but a "sort -n" can fix that.
#!/usr/bin/perl
use strict;
main();
sub main
{
my %db;
my %wild;
while (<>) {
chomp;
my($f3, $s3, $t1, @rest) = split /\|/;
my $rest = join '|', @rest;
my $key = "$f3|$s3|$rest";
if ($t1 eq '') { $wild{$key} = 1; }
else { push @{$db{$key}}, $t1; }
}
foreach my $key (sort keys %db) {
my($f3, $s3, @rest) = split /\|/, $key;
my $rest = join '|', @rest;
if ($wild{$key}) {
print "$f3|$s3||$rest\n";
} else {
if (10 == scalar(@{$db{$key}})) {
print "$f3|$s3||$rest\n";
} else {
foreach my $t1 (sort @{$db{$key}}) {
print "$f3|$s3|$t1|$rest\n";
}
}
}
}
}Since it's all 50 U.S. State's Attorney Generals, this might actually help a little because AGs can file suits & subpoenas against US-based companies which are landing the offshore VOIP calls. This won't stop phone spammers entirely but it might raise their costs somewhat by pressuring their supply chain.
I remember a time when I could answer my phone. Today phone calls are almost unknown, not because it's "out of fashion" but because thieves have stolen the ability to practically use phones. I would like my phone back, please.
I have my mobile phone, which I never published. Only my family has it.
I have a VoIP number tied to my mobile phone, and desktop computer. This allows me to take calls with my headset on, not just on my mobile.
All calls from numbers not in my contacts list go to the VoIP voice mail, which gets auto-transcribed. (If it is English, it works well, but any other languages it fails.)
If someone really wants to talk to me, they will leave a name, reason for the call, and the number I can call them back.
I also use Tasker[0] on my Android mobile. The carrier charges a monthly fee to have the feature to identify spammers and auto-reject them.
Type
Incoming
Number
!C:ANY
This rejects all calls that are not in the contacts list.2) Yes, I’m happy to lose all calls that come via VoIP.
3) I don’t answer my phone anymore, so I miss those calls anyway
4) I’m very happy to sacrifice 1% of signal for 100% of noise
At that point, why not just block everything other than contacts?
For instance, contractors coming to do work on the house may be calling from any number of cell phones, or people buying things from Craigslist. For Craigslist, if I were to filter out all the non-US originating calls and texts, would probably result in all the spam being dropped and at no expense to legitimate buyers.
Blocking all numbers not in one's contacts list is therefore not a solution to blocking spam calls while allowing legitimate callers.
https://en.m.wikipedia.org/wiki/STIR/SHAKEN
Many of the spam calls I receive come from my own area code, with the number spoofed.
This, plus state/province level filtering as well would completely solve the issue for me.
Why did this take so long?
There are already laws on the books. New legislation (read: added time) isn't necessary. Everyone suffers from this problem. No one, sans the violators, is in favor of this problem. That is, it's a political win regardless of party, state, etc.
Yet after years of pin-prick torture there's going to be a task force?
I'm confused.
Let’s say I’m at the DR’s office and I’d like them to call me with my test results.
Before giving them my phone number, I pull out my phone, open the phone app, and tap the “new trusted contact extension” button. It then displays the text “ext 47901” and prompts me to input a contact name.
Then, when I give the front desk my phone number, I give “5558081111*47901”.
One could then have a setting on the phone for “send non-trusted contacts to voicemail”.
Is this feasible from a technical standpoint?
I think the motivation would be there (in the us at least) socially. I’d generate these ext numbers for close friends and family and whenever a business asks for my number.
My inspiration was the Gmail “+” email address thing that allows one to create infinite sub-email addresses for specific purposes ie myemail+newsletters@gmail.com for easy filtering.
This filters out pretty much all spam!
[1]: https://apps.apple.com/us/app/wideprotect-spam-call-blocker/...
"You actually can turn off cellular network calling altogether, if you are willing to do that. Dial (star)#67# (or call 611 if it doesn't show up there) to see what number your voicemail center is. Then dial (star)21(star)1(that number)#. That will automatically forward all calls, at the network level, to your voicemail. To cancel this, dial #21#."
i get 2-20 spam call a day
It makes my life better when they block Europe, and I wish more did. I also wish Europe got rid of the GDPR.
pretty sad that this is unthinkable.
The reality is, however, unless you have a major presence in the EU, or are the size of Google or Facebook... you can freely ignore the GDPR without consequence. EU laws do not apply across the ocean.
You don't need to be a legal expert to just not collect data you don't need.
The "technical resources" involved in identifying EU traffic is nearly always just a simple IP block list, where one can often just checkmark a list of countries in their web host's portal.
I think you grossly overestimate the technical prowess required to operate a website these days, and I think many grossly overestimate the actual real-world impact of GDPR outside the EU borders.
The reason why such "technical prowess" is needed is because businesses have made it more complicated than it needs to be. Keep in mind, the context of this conversation is the arrogance of literally claiming claiming you are being "censored" (because that's what the 451 response code indicates), just because you refuse to remove tracking analytics from your website.
The dude trying to sell custom T-Shirts has a website because it's a necessity to sell T-Shirts, not because he enjoys operating, optimizing and customizing websites. He just wants to sell more T-Shirts, and some European Union law isn't going to give him pause even for a second if he is physically not in a EU country.
While good intentioned, the GDPR was specifically designed to be a "viral" law and force the entire internet to comply... unfortunately the EU's long arm of the law is fairly short. Further, the EU's ability to enforce the GDPR is limited to businesses physically under it's jurisdiction - ie. the US is not going to extradite some website operator for an alleged GDPR violation, no matter how severe the case may be, and the EU can only fine a business into compliance if the business cares about EU laws (which would imply a physical presence in the EU).
Ignoring the GDPR is the right move for most websites.
If people desire comprehensive, impactful privacy guarantees, then a similar law needs to be passed within the US.
It is also more expensive to implement than
if(blocklist.contains(ip)) res.sendStatus(451)Meanwhile, GDPR is yet another disruptive annoyance to users, a burden on overworked, under-funded website teams and isn't delivering the benefits promised.
The GDPR provides a framework by which bad actors can do their thing legally without too much trouble. To a good actor, who only stores the data they actually need and doesn't track users, the GDPR still applies and is just as big a pain in the ass.
Users can now demand we delete their account and data and we have to do it, this is some work for us but it is good for users.
Also do you forget that popups were a thing before GDPR? Modal for you to subscribe to some shit,monthly Terms of Service changes, notifications to see what new feature was added, to see what new stuff some contact posted were a thing, with GDPR you get a one time popup , you make your choice and you should be done.
In summary
Pros for users:
- transparency, you now know about the 100+ partners and you can decide
- you can ask for your data and ask for it to be deleted
- you will get notified if your private data is lost(mioght be adifferent law for security breaches)
Cons:
- Shit websites use dark patterns and annoy you with a popup one time
No Pros for developers, companies: Cons for devs and companies:
- you need to research the law and find ways to screw the user with dark patterns
- you need to update some old project and remove tracking or implement some popup , implement account deletion, data demands etc
- you need to update your ToS documents, privacy policies
- almost never happens, you remove tracking or configure your ad script to don't track and you don't store private data.
From what I see users EU ones) have a lot to win, I assume if you are not in EU seeing the popup is a bug and would be fix .
It's only a burden on these people if they choose to be user-hostile.
There are really easy ways to deal with GDPR but these dumb companies insist on avoiding those solutions at all cost.
If companies insist on being dicks, then the only possible government-level solution might be to just ban this kind of tracking outright.
Just being able to receive such requests has costs, because GDPR requires that you have a contact in the Union that users can contact for such things.
So say you've got an online forum in California and some EU people join and participate. Whether or not that is enough to make you subject to GDPR depends on Article 3(2). There's lots of subjectiveness in Article 3(2) so it is not at all clear where the boundaries are.
If it does, then whether or not you have to have an in-Union representative is covered under Article 27. You do not need one if your processing of covered data is all of the following: (1) occasional, (2) does not fall under some special categories of data, (3) is unlikely to result in a "risk to the rights and freedoms of natural persons".
That's pretty fuzzy. What is occasional processing?
If you aren't sure that GDPR does not apply, or aren't sure that if it does your processing is occasional enough to fly under Article 27's radar, you need an Article 27 representative.
Eventually there will be rulings from EU data regulators that will make the boundaries of Article 3(2) clearer, so that you may be able to stay in "does not apply" without blocking. Or maybe rulings will clarify Article 27 so you will be able to confidently determine that your processing is occasional enough to not need a rep.
There's actually a lot of unclarity in GDPR. Take the data subject's right to have you delete their data. How do you actually implement that? Writing some scripts to delete from your database is probably not too hard.
But what about backups? Do you need to go through all your backup sets and delete their data from those? What about printed records (yes, GDPR covers printed data)? Offsite long term archives?
For a site like a forum, what about data that was in messages they posted that were quoted in messages from other users?
Until all these kind of things are cleared up by EU data regulator rulings it can make a lot of sense for a site that is aimed mainly at a non-EU audience to block EU users.
However, it would be totally legal for them to provide the content. They just don't want to take responsibility for their privacy invading practices. So it's not censorship at all.
/me shrugs. Personally, I have yet to find the website I can't just close if it behaves like this.
Nonetheless, it is a shame that they engage in such behavior and that they live under abusive government structures that funnel them into such things.
Communism does not produce globally competitive industries. So the only thing left to do is either to steal and pillage what is left or work in an industry that has local demand like food or energy. Those tend not to be very attractive jobs.
That's not exactly explanatory, though. Any time a position is powerful or enriching well beyond the extent to which it serves others, the people optimizing to seek out and attain those positions are those who want the power and wealth, rather than those who care about the organization's mission. For those people, the original mission is, at best, a distraction, and at worst actively antithetical to their personal goals.
[1]https://www.aljazeera.com/features/2011/5/13/defeat-rocks-in...
[2]https://www.ideasforindia.in/topics/macroeconomics/west-beng...