HNHacker News
TopNewBestAskShowJobs

buzer

1,313 karma · joined October 8, 2016

Staff Software Engineer at 8x8

Especially interested in systems scaling & IAM and also general interest in most of thing on backend side.

You can reach me via <username>@<username>.net

submissionscomments
buzer··on EU Council forces Chat Control via fast-track
It's called "pay-or-okay" (or "consent-or-pay") and there hasn't been many decisions on it yet which has led noyb to sue German DPAs: https://noyb.eu/en/years-inactivity-pay-or-ok-cases-noyb-sue...

There is one case where DPA ruled in favor of the company, but it's currently being appealed: https://noyb.eu/en/pay-or-ok-der-spiegel-noyb-sues-hamburg-d...

Another one ruled against company and court agreed: https://noyb.eu/en/court-decides-pay-or-okay-derstandardat-i...

buzer··on Amazon seller reveals glimpse of shadow bribery market
In 2022 I got physical mail about leaving a review for something I bought from Amazon (sold by company X, shipped by Amazon) in exchange for Amazon Gift Card. It contained the name of the product I bought. When I tried to report it to Amazon:

* there was no obvious way to do it. Closest thing was by reporting issue on product.

* there was no way to show the customer service agent a picture of the mail. Chat did not support sending pictures & they were unable to open imgur link.

* agent recommended me to leave a report it by leaving review to the seller page. I did that and next day review was deleted.

So it's pretty clear that Amazon didn't care and I doubt it has changed (unless the law you are talking about is recent one).

buzer··on Tell HN: Installing Cursor on iOS irreversibly changes your privacy settings
2 weeks ago it was $60 billion apparently. https://news.ycombinator.com/item?id=48553224

It might be higher now.

buzer··on US Supreme Court Just Blew Up EU-US Data Transfers
You are somewhat confusing two distinct concepts. IP addresses are considered to be personal data because they can be linked to single individual and controller is allowed to give this personal data to someone who can do the linking (e.g. police who can then request logs from ISP or NAT connection logs from the company).

Now it doesn't mean it will always link to single individual, but unless controller can be sure that there are always at least 2 people behind the IP and the devices on that side do not keep enough information to ever link IP+timestamp+destination service to single individual, the controller essentially must assume that IP address is personal data.

This is different from civil liabilities. National courts determine what is the threshold for that. For example in Finland the court has ruled that if the owner of the car cannot name the person who parked the then the presumption is that they did it and are responsible for parking contract breach (KKO 2026:24). National courts could end up with similar ruling for civil liability for sharing content, i.e. assumption that the IP owner either is the person who shared it or knows who they did it & if they refuse to name the person then presumption is that they did it.

buzer··on US Supreme Court Just Blew Up EU-US Data Transfers
> nor are there any major EU software services and there never will be

SAP and Spotify come to my mind first. Some ex-EU services include Skype and Booking.com (latter might still be counted as EU service depending on definition).

buzer··on HackerRank open sourced its ATS. My resume scored 90/100. Oh wait 74. No – 88
Mostly yes.

Note the chance to object must be given before decision is made, i.e. not to give option for human review after the fact. Human must also be able to actually have meaningful chance to affect the decision.

If the decision is based on purely objective facts that are actually necessary (like you must have certain license) then human and computer always coming to same decision is likely correct and compliant, but as soon as you start putting in subjective criteria and human agrees with 100% of computer denials it becomes a lot harder to demonstrate that human is actually able to affect the decision as required by Article 5. Note that demonstration burden is on controller, not on data subject/DPA.

Objective criteria also isn't always enough by itself. If both human and computer calculate the same credit score and you must score X points to get a loan then human isn't actually able to affect the decision. Essentially the credit score calculation itself ends up being the automated decision rather than the formal rejection that is later given to data subject.

buzer··on HackerRank open sourced its ATS. My resume scored 90/100. Oh wait 74. No – 88
That's why I said consent usually cannot be used in employment context. I wouldn't rule it out 100% for everything employment related, but application screening is unlikely to qualify for those rare cases.
buzer··on HackerRank open sourced its ATS. My resume scored 90/100. Oh wait 74. No – 88
> this is most likely highly illegal to use in the EU due to violating anti discrimination laws in multiple ways.

It's generally illegal under GDPR Article 22.

> The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.

Exceptions in 22(2) are unlikely to apply. It's hard to argue that it's truly necessary (a) and consent (c) is almost always unavailable in employment context. (b) might apply, but it requires specific law in EU or Member State to authorize it.

buzer··on PlayStation Is Deleting 551 Movies from Customers' Accounts
Finnish case happened after DVD-Jon. To my knowledge there also hasn't been any new cases which went other way (or any way) in Finland & law hasn't changed so it's technically still illegal. Of course it's up to prosecutor to determine if they want to actually go ahead with prosecution & it's also not a crime which gets discovered often so the risks are quite low, especially if you are just ripping DVDs for personal use.
buzer··on PlayStation Is Deleting 551 Movies from Customers' Accounts
In Finland DVD's CSS was ruled to be strong technical copy protection system (tehokas tekninen toimenpide). In that exact case a person had made a program which bypassed it and published it. He was found to be criminally liable though he didn't get any fine/prison time from what I remember.

In Finnish criminal law the threshold is "significant harm", but given that there were already multitude of ways to get around DVD copy protection the "significant harm" clearly isn't very high bar. Also both distribution the method and actually using the method are both criminalized.

Finnish Copyright Act does individual to bypass copy protection to view the content, but it notably does say that you are not allowed to copy the work.

Unfortunately I cannot find the exact page right now, but I found one of the appeal documents from from https://www.yumpu.com/fi/document/view/38482300/1-helsingin-.... It's probably under https://www.cs.helsinki.fi/u/nikki/, but it's no longer available and Internet Archive is currently giving 503 when trying to access the old pages.

buzer··on LastPass notifies users of yet another data breach
Assuming you are in EU you could report them to local DPA. Objection (i.e. unsubscribing. Original automatic subscription may or or may not have been legal) to direct marketing is pretty much absolute due to GDPR Article 21(2), I'm not aware of any "workaround" companies have successfully managed to argue.

In the US you can report it to FTC for CAN-SPAM violations, but don't hold your breath on any enforcement.

buzer··on Founding a company in Germany: €9600, 152 days and I still can't send an invoice
Worth noting is that there was 2500 € capital requirement until 1st of July 2019 and it was reduced to 0 €.

Public limited liability company (Oyj) still has 80 000€ capital requirement.

buzer··on Chevron signs 20-year power agreement with Microsoft for West Texas data center
Not 3 month period, but looking at e.g. capacity factor over 5 day period can be under 3% and even 10 day period can be under 5%. Capacity factor for whole year is around 30% (22TWh produced with 9433MW in 2025, rounded it up since some capacity came online during 2025). That's a lot of extra power or storage.
buzer··on Chevron signs 20-year power agreement with Microsoft for West Texas data center
> Near the arctic circle Wind fill the same niche.

What do you mean? Long periods of calm weather during cold temperatures is not unheard of in Finland and does cause issues at times due to amount of wind energy that has been built in recent times.

buzer··on I told them forced consent was unlawful. 5 years later it cost Elkjop €1.8M
I would like to see that thread if possible just out of curiosity.

I looked a bit into EUDPR and the earlier 45/2001 regulation (EUDPR came in effect in December 2018 so a bit later than GDPR). EUDPR explicitly imports Article 5(3) of ePD (via Article 37) and thus whatever case law there is around it. The earlier regulation seems to do this more indirectly (references in recitals), but EDPS view from 2016 is that it effectively does import Article 5(3) as well.

Personally I haven't dealt with EU institutions so far. On general public sector side I did recently seek some clarifications from Finland's Ministry of Justice regarding one of their websites and their responses weren't exactly reassuring.

I asked for the GDPR Article 15(1) information regarding single visit (i.e. information about processing, not actual copies of data) and it took them almost 3 months to give official response. Even after that time they, for example, failed to identify if they are actually the controller or not for some of the processing (Cloudflare challenge). And their stance is that analytics (Matomo) does not need Article 6 legal basis at all, i.e. they seem to think that anonymization step itself is not processing.

buzer··on I told them forced consent was unlawful. 5 years later it cost Elkjop €1.8M
Official EU website, generally speaking, are not bound by GDPR or ePD. Rather EU bodies are bound by EUDPR. I'm not well-versed on that specific thing, but EDPS and courts have previously found that EC has infringed EUDPR so it wouldn't be weird if their cookie banner was breaking the law as well.
buzer··on I told them forced consent was unlawful. 5 years later it cost Elkjop €1.8M
It's called "pay-or-okay" and there hasn't been many decisions on it yet which has led noyb to sue German DPAs: https://noyb.eu/en/years-inactivity-pay-or-ok-cases-noyb-sue...

There is one case where DPA ruled in favor of the company, but it's currently being appealed: https://noyb.eu/en/pay-or-ok-der-spiegel-noyb-sues-hamburg-d...

Another one ruled against company and court agreed: https://noyb.eu/en/court-decides-pay-or-okay-derstandardat-i...

buzer··on I told them forced consent was unlawful. 5 years later it cost Elkjop €1.8M
While we cannot be sure what Elkjøp exactly told him, the Norwegian DPA's findings included following:

* Published benefits: https://web.archive.org/web/20220613175535/https:/www.elkjop... (e.g. "Rabatt på en rekke av våre tjenester utført i varehus", i.e. something like "Discount on a number of our services performed in warehouses")

* Conditions to join, i.e. to receive the benefits (DPA's translation):

* You may be contacted electronically (e.g via SMS and e-mail), via phone and mail with personal offers and other relevant information

* Collect and analyse information about you and your customer relationship.

* Create a customer profile, in order to provide more relevant information and a better service.

* You have to be minimum 15 years old and you can choose to leave the customer club at any time.

So to get the discount you would need to consent to being contacted for "personal offers and other relevant information".

buzer··on I told them forced consent was unlawful. 5 years later it cost Elkjop €1.8M
It's also worth noting that it's not the first time Swedish DPA has been criticized regarding GDPR complaint handling:

https://noyb.eu/en/gdpr-rights-sweden "GDPR Rights in Sweden: Court confirms that authority must investigate complaints. So far, the Swedish IMY has taken the view that users don’t have party rights in GDPR procedures."

https://noyb.eu/en/noyb-takes-swedish-dpa-court-refusing-pro... "IMY frequently just forwards a complaint to the company that illegally processes personal data - and then immediately closes the case without investigating." (no decision on this as far as I know. A bit surprising since it has been almost 2 years)

buzer··on I told them forced consent was unlawful. 5 years later it cost Elkjop €1.8M
That's a bit more complex.

Everyone is free to make a tip to DPA. However DPA is free to decide if they want to start their own investigation based on that unlike when you make Article 77 complaint.

There isn't a lot of case law around the threshold of Article 77. The text says "if the data subject considers that the processing of personal data relating to him or her infringes this Regulation". If read completely alone one could make argument that since you didn't consent no processing occurred -> you do not have right to make an Article 77 complaint.

However when taking the in account the goals and purpose of GDPR as well as recital 141 I would argue otherwise. To be specific recital 141 says "if the data subject considers that his or her rights under this Regulation". CJEU also often refers to GDPR's objective of ensuring high level of protection of fundamental rights and freedoms of natural persons. I feel that ex post requirement would be quite contrary to that.

Due to this my personal stance would be that just offering invalid consent choice where refusal has negative consequences is something that violates data subject's rights even if processing didn't occur and would be eligible for actual Article 77 complaint rather than just tip to DPA.

[EDIT] Also, there is Article 82 path via damages. In your case you could potentially argue that you suffered damages (like lost wages) due to company's invalid consent requirement. This, however, is generally a lot harder and more expensive path. Depending on how legal costs are allocated in your jurisdiction you could also end up with judgement where you need to pay your opponent's legal costs if you lose.

For Article 82 claim you almost definitely will need a lawyer.

buzer··on I told them forced consent was unlawful. 5 years later it cost Elkjop €1.8M
What do you mean? It sounds like he is planning to sue company in question and possibly lodging complaint against Swedish DPA. Norwegian DPA is the one who found case in his favor.
buzer··on I told them forced consent was unlawful. 5 years later it cost Elkjop €1.8M
I haven't personally encountered that, but you are free to lodge complaint with your local DPA about it.

That exact language is unlikely to be compliant. If you want to maximize your effect you could make Article 15 request to the company in question, get the list of actual recipients of data (make sure to be ask for this specifically) and then make another request to all of those companies. That will then allow you to possibly make further complaints (e.g. why exactly they didn't send Article 14 information to you, are the legal basis they use actually proper in your case especially if the original one was consent and it was not freely given).

buzer··on I told them forced consent was unlawful. 5 years later it cost Elkjop €1.8M
Actual decision (Norwegian): https://www.datatilsynet.no/contentassets/c8d0551d2a64403285...

Machine translation of overview & 5.1 which is what the blog post is about (covers some other things as well): https://chatgpt.com/share/6a34732c-0fa4-83e8-aae1-95c25dd117...

[EDIT] Oh, there was actually official English decision available as well: https://www.datatilsynet.no/contentassets/59addbef9c1b48a28f...

buzer··on The UK's Teen Social Media Ban Is Political Theater, Not Child Safety Policy
Kids (or more specially teens) will just find a site that doesn't require the verification. There will be some and you better hope it's not one run by intelligence agency in unfriendly country.

It would be way better to just reduce the harms in general by e.g. regulating algorithms. Those are things that you can do when people are using platform that you still have some control over.

buzer··on Google Chrome update will close the door on ad blockers
Windows so maybe that is related.

Do note that I regularly have multiple browser windows open (and these are usually on private mode) with 50+ tabs so my usage pattern is not very standard.

buzer··on Google Chrome update will close the door on ad blockers
> - Firefox limits how small I can shrink my tabs in the tab bar.

This can be changed via chrome/userChrome.css.

Mine is:

  @namespace url("http://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul");
  
  .tabbrowser-tab {
    min-width: 3em !important;
    clip-width: 3em !important;
    
  }
  
  [uidensity="compact"]:root {
    --tab-min-height: 30px !important;
    --newtab-margin: -3px 0 -3px -3px !important;
  }
  
  .tabbrowser-tab {
    max-height: var(--tab-min-height) !important;
  }
  
  .tabs-newtab-button{
    margin: var(--newtab-margin) !important;
  }
buzer··on Google Chrome update will close the door on ad blockers
Firefox leaks memory. When I have it open for long time the memory usage will increase and even if I were to close all tabs & do memory minimization it will still use multiple gigabytes of memory.

While I cannot be sure, I assume that is the cause of the general slowdown I experience as well.

Restarting Firefox will fix free up the memory & fix the slowness. I do still use it as my primary browser despite these issues.

buzer··on Anthropic requires 30 day data retention for Fable and Mythos
You have right to ask for it, but it doesn't guarantee that they will do it. It's also limited to data they hold as controller (i.e. the copy they hold for "safety" purposes), not the original copy that is controlled by customer. For that you will need to contact the source.
buzer··on Anthropic requires 30 day data retention for Fable and Mythos
Mentioned in the earlier, topic as well, but one very important point here is that it looks like Anthropic is becoming GDPR controller for all submitted data for this model (when they are in GDPR scope anyway). So data subjects would have Article 15 right to request information about processing and possibly a copy of the data. Latter might be contested under "rights of others", but former is more absolute.

What this means it that if someone makes an Article 15 request, they would be entitled to know if Anthropic holds personal data about them and also from who they received this data at minimum.

If someone wants to do that, I would recommend combining it with Article 18 request to forbid deleting the data for legal claim in case you contest Anthropic's reply. Otherwise they could just delete the data per their retention policy and DPA would find much later that they no longer hold the data.

Another issue here is that their DPA frames everything as controller-to-processor, i.e. they do not appear to have SCCs in place to actually receive this personal data as controller. So the original exporter would likely also be in breach if they send any GDPR covered personal data to this model.

buzer··on AWS Bedrock to require sharing data with Anthropic for Mythos and future models
One very important point here is that it looks like Anthropic is becoming GDPR controller for all submitted data. So data subjects have Article 15 right to request information about processing and possibly a copy of the data. Latter might be contested under "rights of others", but former is more absolute.

What this means it that if someone makes an Article 15 request, they would be entitled to know if Anthropic holds personal data about them and also from who they received this data at minimum.

If someone wants to do that, I would recommend combining it with Article 18 request to forbid deleting the data for legal claim in case you contest Anthropic's reply. Otherwise they could just delete the data per their retention policy and DPA would find much later that they no longer hold the data.

← PreviousPage 3 of 16Next →