HNHacker News
TopNewBestAskShowJobs

buzer

1,302 karma · joined October 8, 2016

Staff Software Engineer at 8x8

Especially interested in systems scaling & IAM and also general interest in most of thing on backend side.

You can reach me via <username>@<username>.net

submissionscomments
buzer··on Sol loves to cheat
> I had Claude Code drive a robot last week, and it was very visibly "delighted" like this, more than I've ever seen.

At least it didn't (hopefully?) start the driving by reloading the gun like Neuro did https://www.youtube.com/watch?v=LQ0VEDNR_jE

buzer··on Google has stopped pushing Git tags for some Android source code
Google Drive is customarily used for software interchange?
buzer··on Police officer used Flock cameras to track estranged wife 717 times
Qualified immunity concerns civil liability. Prosecution is about criminal liability.

Civil liability is helpful because tax payers do care about $$$ (if judgements/settlements are starting to eat major part of budget the people will start to care on how to lower those costs) and victims are not limited by what prosecutors are ready to do. The QI is especially problematic because it has essentially become "did someone prosecute cops about this before" because that's effectively the only way to establish precedence that allows you to get across the QI-line in future for sufficiently similar conduct. And like you said, prosecutors are often unwilling to prosecute cops.

buzer··on Google has acquired the data of failed US airline Spirit
It heavily depends on country if employer can access the email or not. For example in Italy:

> Italian Supreme Court case law according to which defensive controls may be carried out where there is a well-founded suspicion of unlawful conduct, provided that an appropriate balance is struck between the employer’s interests and the employee’s dignity and privacy, and that the control concerns data acquired after the suspicion arose.

buzer··on German advocacy group lodges criminal complaint over Meta AI glasses
As per Article 4:

> ‘controller’ means the natural or legal person

There have been various cases where individuals have been determined to be separate controllers. For example there have been many cases where doctors/nurses/police looked into the employer's databases without having professional need and were determined to be separate controllers and were fined under GDPR.

buzer··on German advocacy group lodges criminal complaint over Meta AI glasses
The full analysis of this would need to take in account:

* Who actually determines the essential means and purposes for each processing purpose (and is truly doing it). Fashion ID case is quite relevant here.

* If terms which grant Meta these rights and user a lot of obligations would fall under unfair terms or unfair commercial practices directives. If they do then those aspects of the terms are invalid. These could, for example, affect requirement that the user must get consent from data subject for Meta's processing operations.

buzer··on German advocacy group lodges criminal complaint over Meta AI glasses
I don't think the owner is on the hook if they simply use the service. The individual wasn't the one who truly decided the essential means and purposes beyond personal use, Meta is the one who did that and is thus the controller for that processing.

And I believe in case of European users the contract is between Meta Ireland and user, Meta Ireland is the one who would be the one doing the exporting in that case.

Now if user actually did publish it on Meta's service for broader consumption then they might become controller for that & if initial purpose was that then the initial recording is unlikely to be exempted under household exemption.

buzer··on German advocacy group lodges criminal complaint over Meta AI glasses
Look at what how GDPR is interpreted in regards to CCTVs and bodycams. You generally do need to give proper Article 13 notice in regards to those recordings. In particular EDPB Guidelines on video recording (3/2019) state that:

> The first layer concerns the primary way in which the controller first engages with the data subject. At this stage, controllers may use a warning sign showing the relevant information. The displayed information may be provided in combination with an icon in order to give, in an easily visible, intelligible and clearly readable manner, a meaningful overview of the intended processing (Article 12 (7) GDPR). The format of the information should be adjusted to the individual location (WP89 par. 22).

> The information should be positioned in such a way that the data subject can easily recognize the circumstances of the surveillance before entering the monitored area (approximately at eye level). It is not necessary to reveal the position of the camera as long as there is no doubt as to which areas are subject to monitoring and the context of surveillance is clarified unambiguously

> The first layer information (warning sign) should generally convey the most important information, e.g. the details of the purposes of processing, the identity of controller and the existence of the rights of the data subject, together with information on the greatest impacts of the processing

While recording by these might not always implicate GDPR directly (as it might be exempted under household exemption or the broader allowances given for journalistic purposes), it does give good idea on how unambiguous it should be.

buzer··on Tl;dv: Over 180k meetings left wide open
My first thought was "huh, I wonder if they follow GDPR, that starts sound to like Article 32 violation" (related to security of processing). I checked the privacy policy and yes, they are based in Germany so GDPR likely applies to all of their processing.

However that privacy policy raises also quite a few concerns. They say that "profile image URL" is based on contractual obligation which is quite weird, just why profile image is necessary to fulfill a contract? Additionally IP address and location are collected for "adapted pricing" and it's "legal and contractual obligation". I can somewhat understand that if it's used to calculate VAT, but "adapted pricing" sounds much wider thing. And even VAT calculation itself isn't really "adapted pricing", it's something that the company needs to handle. They are of course free to change the price based on that, but that price change goes more to legitimate interest rather than legal (or contractual) obligation.

They also claim that "Product analysis and improvement, marketing and attribution, incident management and in some of our logs" as well as "Analysis of products and navigation on the site and application" are also "legal and contractual obligation". I honestly want to hear what contract necessitates those or exactly what law requires them to do that.

buzer··on Deletes all instances of Microsoft's GDID and prevents minting of new ones
Storing IP address itself is not illegal. The questions are:

1) what is the legal basis for storing it and if that's proper or not (e.g. legitimate interest requires balancing test)

2) if proper GDPR Article 13 notice was given and it covers that processing

3) if all Article 5 principals are being followed in regards to it (e.g. data minimization, retention period etc.)

4) if Microsoft had legal basis to transfer the data to police (they probably did, that's not high bar to clear)

buzer··on 99% of My Website Traffic Is Bots
> If the company decides that a certain user should not see the website, the user will not see the website, and no one will know about it, and the user will have no recourse.

If the the processing is subject to GDPR (e.g. if controller is in EU) then you do have recourse. You can complain to DPA or sue the company. The company is ultimately responsible for the decision to block you, at least in cases where you personally tried to access the site.

buzer··on ChatGPT, Roblox to fall under strictest EU rules for platforms
Of one year. How many years does it take complete the investigation and let courts handle appeals? I assume they do not need to change behavior nor can the fine increase during the appeals.
buzer··on Stop Killing the Internet: No Digital ID and No Age Verification
That's legalization setback, not court setback.
buzer··on Stop Killing the Internet: No Digital ID and No Age Verification
Can you be more specific? The only related court cases I'm aware of are U.S. The Crew lawsuit which seems to have reached settlement recently and the French case regarding which I haven't seen any updates since it's filing.
buzer··on Kill The Cookie Banner
No, it's not. ePD is lex specialis in relation to original Data Protection Directive (and later GDPR). DPD was replaced by GDPR, ePD was not. There has been talks about ePrivacy Regulation over the years, but it was shelved again in 2025.

ePD is still active and national laws implement it. GDPR itself is not implemented by national laws as it's EU regulation rather than EU directive. Member States primarily repealed their DPD-based laws after GDPR and implemented various things that GDPR allows (like Article 23 restrictions). Some countries may have explicitly imported GDPR into their own law due to how their own legalization works. Like that's why UK DPA was originally pretty much just copy of GDPR.

buzer··on Kill The Cookie Banner
"legitimate interest" is legal basis in GDPR. ePD (which governs access to cookies) does not have such legal basis, only consent and the two exceptions.

Other processing (like after value is read) can happen under GDPR if the data is personal data.

buzer··on Kill The Cookie Banner
This is actually slightly narrower exception than people (and regulators) think. The exception is:

> strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.

One very ignored qualifier here is "information society service". This is defined in Directive 2015/1535 and one of the requirements is that the service is "normally provided for remuneration". That is usually understood to mean that the service needs to be tied to provider's economic activity. This effectively excludes, for example, public authorities websites which are for their own public duties. It does however include e.g. ad supported websites.

And yes, I'm aware that many national implementations actually miss that qualifier. That can save the non-commercial private sector websites, but public authorities do not benefit from Member States failing to transpose Directive correctly.

buzer··on Kill The Cookie Banner
Well, if you presented them with list of 100 partners each with 20 page of privacy policies and they accept it within 10 seconds it should be tricky to argue that user actually read it all.

You could, for example, require that user answers very specific questions regarding 10 randomly selected partners and how exactly they can use the data ("is partner x allowed to build very detailed profile of you and target you with political adverts that are designed to manipulate you?").

buzer··on Kill The Cookie Banner
Legitimate interest is not currently enough to read or write cookies. You need either consent or it must be "strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service." (or "sole purpose of carrying out the transmission of a communication over an electronic communications network", but that's harder to apply to cookies)
buzer··on Orion Browser by Kagi
That's uBlock Origin Lite, not uBlock Origin. They are two very different extensions. Lite, for example, does not allow you to add custom filters.
buzer··on LG monitors silently install software through Windows Update without consent
If someone is in EU and is affected by this they could potentially utilize GDPR to make both Microsoft and LG take responsibility for this.

It's hard to say directly from the article if there is any GDPR breach. If everything was part of the installer and it doesn't actually submit anything (including downloading the ad) to LG then it's harder to argue that there is GDPR violation, but knowing the SOP of these kinds of software that is unlikely.

If the software did indeed send personal data to LG then there are at least following question: How was Article 13 notice delivered to user? Article says that this was installed quietly. Did Microsoft deliver Article 13 compliant notice to user at some point? They probably did deliver their own notice (though it's open question if it's compliant), but not LG's. However since Microsoft is the one that installed the software and they exercise control over the standards which must be met, it's possible that they would end up being joint controller at least for some processing.

I should add that Article 13 requires that the notice is given "at the time when personal data are obtained". The only exception is when "data subject already has the information" and possible Article 23 restrictions, but those are unlikely to apply.

If someone wants to make a complaint they should first make Article 15 request to LG. Copy of personal data is useful, but 15(1) information is the primary goal. Additionally ask for information on how and when did LG provide you the Article 13 notice if they did indeed process your personal data.

After that if they cannot show that they provided Article 13 notice when they received your personal data submit a complaint to your local DPA. You can additionally flag other violations as well if they are applicable (e.g. not naming recipients as part of Article 15 response, not giving actual retention time or meaningful information how that is determined, invalid legal basis etc.). You should also flag in the complaint that Microsoft is likely joint controller for some of the processing given that they are the ones who approved the automatic install of the software which violated GDPR.

buzer··on Kimi K3: Open Frontier Intelligence
That's good if true. When did it change? I very much do remember that back when the change happened the modal I received didn't actually say anything (https://news.ycombinator.com/item?id=45064212) and thus I was by default opted-in until I saw the news and went to disable it, fortunately before the training actually started.
buzer··on Kimi K3: Open Frontier Intelligence
No for what? The opt-in for model training? About a year ago Anthropic changed "Allow use of your chats and coding sessions to train and improve Anthropic AI models" to default to on: https://www.anthropic.com/news/updates-to-our-consumer-terms

Or do you mean the feedback stuff? Their KB article at least seems to contradict that.

buzer··on Kimi K3: Open Frontier Intelligence
Sure, but the point is more that once you submit feedback then the usual "opt out of using my data for training" no longer apply and at least that reply (and possibly whole conversation) can be included in training set in one way or another.
buzer··on Kimi K3: Open Frontier Intelligence
They don't use your general chats it if you have opted out (note: opted out, not opted in). However if you submit feedback then whole conversation can be used.

https://help.openai.com/en/articles/5722486-how-your-data-is...

> Even if you have opted out of training, you can still choose to provide feedback to us about your interactions with our products (for instance, by selecting thumbs up or thumbs down on a model response). If you choose to provide feedback, the entire conversation associated with that feedback may be used to train our models.

https://privacy.claude.com/en/articles/7996885-how-do-you-us...

> If you explicitly report materials to us (e.g.via our thumbs up/down feedback mechanisms), or by otherwise explicitly opting in to training, then we may use those materials to train our models.

buzer··on Kimi K3: Open Frontier Intelligence
There are multiple ways to use feedback. Personally I would often be fine with actual human reading my feedback, taking in account the points I made and evaluating how it should affect their feature development and future roadmap.

Now what I would expect AI companies to do is to take things which were submitted as feedback and pretty much adding to training:

"Do more of this: <copy of the whole response which was flagged as good in feedback>"

"Do less of this: <copy of the whole response which was flagged as bad in feedback>"

It's paraphrased, but the point is that they will most likely use it more-or-less as-is and thus whatever is in there will be part of the model's training set rather than someone picking up the parts from response that are important and only including them (which happens with traditional feedback).

buzer··on LAPD lets contract with surveillance giant Flock expire
Aren't the cameras on city's land or did city lease the land to Flock? If they are on city's land couldn't city require that Flock removes their stuff from city's property or city will do it on Flock's expense?
buzer··on New York City to ban deceptive subscription practices
It's unfortunately somewhat common these days and personally I actively avoid any place which does this. At least it's only somewhat common rather than the standard so it's still possible. Couple of examples:

https://sushiconfidential.com/wp-content/uploads/2024/07/sc_... "3.5% Living Wage Surcharge added to each bill which allows us to provide the service you have always enjoyed!"

https://www.pacificcatch.com/menu/ "NorCal - A 3% surcharge (5% in San Francisco) will be added to all Guest checks to help offset the rising cost of wages and benefits. This is not gratuity."

buzer··on EU Council forces Chat Control via fast-track
Personally I do agree, but enforcement is unfortunately behind DPAs and it's pretty clear that they are trying to avoid ruling on it.

In theory someone could directly sue some company which engages on this via Article 79, but this can be expensive and depending on jurisdiction the plaintiff can end up with personal liability on defendant's legal costs if court ends up finding that this is actually legal (e.g. Finland has "loser pays" rule in civil suits).

Additionally this does also touch ePD and in some countries there might be different agency which handles ePD complaints compared to GDPR, like in Finland Data Protection Ombudsman handles GDPR, but Transport and Communications Agency (Traficom) handles ePD. If there is something that touches both the Ombudsman usually lets Traficom take care of ePD aspects before they give any GDPR ruling. Both of these can take years.

buzer··on EU Council forces Chat Control via fast-track
Not quite.

> This shall not prevent any technical storage or access for the sole purpose of carrying out or facilitating the transmission of a communication over an electronic communications network, or as strictly necessary in order to provide an information society service explicitly requested by the subscriber or user.

This is the reason why these are usually separated to "strictly necessary" and "functional" cookies. Functional cookies are things which enhance the functionality, but are not strictly necessary. These would generally include things like persistent cookie for language choice rather than just session one.

← PreviousPage 2 of 16Next →