Also, the original Pi (2012) was able to run Wireguard well enough for light VPN, although I didn't push it too much since I didn't use it for anything heavy like video streaming.
Also, the original Pi (2012) was able to run Wireguard well enough for light VPN, although I didn't push it too much since I didn't use it for anything heavy like video streaming.
Yes, and it's infuriating. For example, it was (and probably still is) impossible to access the NY MTA's OMNY portal from many, but curiously not all, European countries. The OMNY system itself works using foreign cards, but this makes it very annoying to download receipts for expense reports.
Another fun one was not being able to cancel some streaming service from outside of the US due to the service geoblocking their account management site as well. I actually had to use a VPN to cancel!
There are countless other examples.
I am French. What I find fascinating is that there are local US newspapers (that server a tiny community) that went through the effort to do a geoblock from the EU and put a page along the lines "we cannot be compliant to Privacy laws in the EU so we must block you".
Why do they care at all? How is the EU law relevant to their small, local business?
Large companies are different - there could be some litigation against their footprint in the EU etc. - but for thosewho just live in the US (or anywhere outside the EU) going the extra mile to block because of non compliance is really weird.
If I was issued a fine by the US, China, India or Japan it would directly go to the trashbin. It is their law, and their problem, not mine.
Of course this means that I will not be able to do business there, if I travel I may be in trouble etc. But again - we are talking about small local newspapers (and similar businesses).
A. [re-]architect in in GDPR compliance;
B. deal with incoming legal documents, likely can't just discard;
C. block country representing tiny share of viewership,
option C seems to present the least hassle
Not sure whether C or D would be more complicated long term (you need to manage the geoloc somehow, or outsource and pay for the service)
The US does do that kind of thing though. As a dev, break some law, step foot in the US for a conference, get arrested (ex: Sklyarov 2001 case, for breaking PDF encryption).
Although for most financial things, it's common in US/CA to block non-local IPs. Heck, I was in Mexico and I couldn't login to my provincial government tax portal. There are constant security issues with those sites.
They can tell whatever they want, but it would need to be a US court (in that case) who would do the litigation. Which they won't.
> The US does do that kind of thing though. As a dev, break some law, step foot in the US for a conference, get arrested
yes, this is why I mentioned that my point is only for local businesses. Travel or business in the EU can/will be problematic.
> Heck, I was in Mexico and I couldn't login to my provincial government tax portal. There are constant security issues with those sites.
Blocking for security is another thing. Maybe a good idea, maybe not - but that's another story.
That's a pretty incomplete view of how jurisdiction works. You do probably need a US court ruling to enforce a claim against a US entity – but if that entity has any EU subsidiaries or assets, you can bet that European courts will come after those.
> Blocking for security is another thing. Maybe a good idea, maybe not - but that's another story.
As a customer/taxpayer that needs access to a service from abroad, I really don't care why I have to jump through hoops to cancel a subscription/order or pay my taxes owed.
I am not sure you read my post in details - I explicitly mentioned that I am talking about local services, without any international footprint. And mentioned that in case of this footprint - yes, they will be sought after.
This is also exactly waht the US does to enforce their "extraterritoriality"
And they can be enforced not only from assets, but also from travel or various financial tools at their disposal. (it would be surprising, but for many businesses, it's not worth the hassle)
The golden days of global network accessibility are closing little by little.
Exactly, except that it is just simpler to do nothing.
Do you (I assume you are not in either of the countries I give an examples, nor travel there) worry about laws in, say, China when you state "Taiwan is an independent country", or Russia when you say "Russia invaded Ukraine", or North Korea when you say "NK is a tyranny", or France when you say "Retirement should be at 60 and not 64". No. Because the local laws that forbid these statements are, well, local. Nobody cares outside of these countries. They could send you letters informing that you did wrong and that you have to pay 1M USD and you would just put that to trash.
> I guess my question to you is why do YOU care if they're accessible or not? If a (local) business really just wants to sell within their own (local) country (or even smaller municipality such as state/county/city), is there something wrong with blocking everything outside it out and just not worrying about it?
I do not care - it is just that I ended serendipitously on a few of these places and was wondering why they care (I would not care about the cookie law in Zimbabwe or Patagonia if I had a web site).
> They could send you letters informing that you did wrong and that you have to pay 1M USD and you would just put that to trash.
I think it's just better to not get those letters in the first place (any more than spam phone calls or texts) and have to waste time reading them, or having to possibly consult an attorney over them to see if they have merit. It's just not something I want to be bothered with, nor should I. It has nothing to do with the company, what we do or our customers.
> Do you (I assume you are not in either of the countries I give an examples, nor travel there) worry about laws in, say, China when you state "Taiwan is an independent country", or Russia when you say "Russia invaded Ukraine", or North Korea when you say "NK is a tyranny", or France when you say "Retirement should be at 60 and not 64".
We don't say anything like that on our company sites.
Not that I disagree with you on the 'it seems stupid' front. But that doesn't change the risk profile for the company.
Lesson learned: configure the UPS to communicate with the servers and shut them down in a controlled manner when batteries are dying.
There are commands to enable/disable read-write mode, so you can still make changes and do upgrades.
I've had 0 problems with SDcard death after I started using it.
I don’t outright block them because I myself travel, and some foreign laws apply to their citizens wherever they are.
I can completely see why you might want to ban overseas IP connections though, and I’ll probably do it soon.
For Homedepot to comply with GPDR, they would have to treat EU and non-EU users differently, or they could just block EU. Since you're not trying to sell anything to EU users, blocking them makes things easier.
But EU has less of the leverage if company refuses to do business in EU — that's true.
on the other hand, CCPA is still a thing
This part of GDPR has always seemed completely unpracticable/unenforceable to me. How would a non-EU company even know that one of their customers is an EU resident and only temporarily visiting? Most services in the US aren't asking for my passport, at least.
Practically, I'd assume that this will be interpreted by courts to only apply to companies "intentionally doing business with/commercially targeting EU residents", which is already the case for similar scenarios (e.g. that's how, to my understanding, German law requiring all sites to provide an imprint has been interpreted by courts).
In any case, I suppose we'll have to wait for precedent; I'm not aware of any at the moment.
Err, or treat everyone in a compliant way?
It's not like you don't already see this within the US anyway - particularly California.
And if you decide to treat everyone the same way, you likely end up with a higher bounce rate for the existing US customers. Hence, blocking.
> (a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or
> (b) the monitoring of their behaviour as far as their behaviour takes place within the Union
Did I quote the correct section? Doesn't collecting all the analytics fall under section B? I'm not a lawyer of course, but it seems pretty reasonable to me that if you have interest in the EU market, blocking them is easier than figuring out if GDPR applies to you or not.
Or you could just not spy on your users of course, but I guess I'm too pessimistic to see that as an option a company would choose.
You need to not sell goods and services to EU citizens for the law to not be in effect.
Even if said citizens are in the US. You don't cease being a EU citizen when you're traveling.
I can understand that an American company does not want to make such an investment when there is literally 0 added business value, as EU customers don't shop at that company.
If McDonalds and Aldi can work on multiple continents I'm sure it's not logistically impossible.
Blocking users on a two-level-deep assumption is wrong.
Even though blocking by traffic source is not always accurate, I’d expect that it would still greatly help show that the site did not envisage offering goods and services to people in the EU.
More than a “small amount of legit pain” was the result.
Also, plenty of people live far away from family and have to deal with death (I’m in the same boat). It sucks but I’m also curious why the obit was particularly important to you because as far as I understand that’s topically just a small blurb in the newspaper? My family doesn’t do obits so I’m curious.
Not to minimize what you went through at all, but it’s interesting in today’s times how we expect so much immediacy. My immediate family escaped the USSR just before it collapsed but my dad’s was family was stuck in Russia and couldn’t leave even after it fell. My father had to deal with his brother, father, and mother dying within 5 years or so with no visits in between that time (a combination of finances + probably fear about traveling back). Comparatively I personally have a much easier time in that I at least get to see my family once a year or so. Again, in no way a comparison as dealing with loss and living far away from family is always hard. Just a reflection of how much technology has changed and made maintaining more closeness easier (eg video calling).
Well, I guess it depends on the type of attacks one experiences, but hackers and spammers who target US-based businesses are not idiots, they know how to use vpns and tor and proxies. So on a technical level you get close to nothing security-wise. You reduce a number of bots and worms randomly accessing your servers, can stop some script kiddies who don't know better and make life a bit harder to web scrapers (but not much) - and that's it.
You forgot to consider "any of my company's existing US-resident customers temporarily traveling outside of the US".