HNHacker News
TopNewBestAskShowJobs

buzer

1,290 karma · joined October 8, 2016

Staff Software Engineer at 8x8

Especially interested in systems scaling & IAM and also general interest in most of thing on backend side.

You can reach me via <username>@<username>.net

submissionscomments
buzer··on LinkedIn wins court order blocking mass scraping of user data
The article says "deal". I assume that means settlement between these parties rather than actually evaluating the law?
buzer··on Meta takes down a critical video about meta AI Glasses after filming at Meta
> I am just an American, but I live in Portugal and it is legally not allowed to film people in public without their consent

If that's actual law that's a bit surprising. In many EU countries there are journalistic exceptions (which may or may not apply in this specific case depending on local law)

> (you also can't have a street facing surveillance camera like in the US)

And same here. Usually the limit is that if you do it within GDPR household exemption then you cannot have it facing street, but if you do it on GDPR scope then you need to fulfill the GDPR requirements (e.g. posting notice, be ready to answer GDPR requests, perform balancing tests for recording etc.).

buzer··on Grammarly will send unhinged messages to all your users if you try to cancel
According to https://superhuman.com/legal/dpa they claim that their role is processor. Processor is only allowed to use personal data they obtained from controller under controller's documented instructions. Unless those included authorization to send such an email to controller's users it's quite likely that they exceeded those. GDPR-wise (and likely that DPA-wise) that is a breach on it's own.
buzer··on German court rules Meta liable for scam ads on Facebook and Instagram
This was civil injunction & damages case. For court to declare judgement against Google (or any other company) someone needs to sue them. That's expensive and people in EU are not nearly as sue-happy as people on other side of Atlantic. Many courts in EU also have loser-pays model so there is huge financial risk in suing huge multinational corporation whose final legal bill might be bigger than person's lifetime earnings. And depending on country they might not even have personal bankruptcy available to discharge that.

This also heavily relies on recent CJEU ruling (WebGroup/Coyote, 16 June 2026, C-188/24) which essentially opened up the E-Commerce Directive's liability shield that platforms have been relying on so far. Essentially it said that that platform's are not necessarily neutral hosting providers when they control the algorithms that determine the dissemination. So I would expect more rulings to come, but it will take time.

buzer··on German court rules Meta liable for scam ads on Facebook and Instagram
GDPR Hub article, contains (machine translated) judgement: https://gdprhub.eu/index.php?title=LG_Frankfurt_am_Main_-_2-...
buzer··on Data Protection Commission fines Google €403M over processing of location data
No. For example:

https://www.enforcementtracker.com/ETid-3171 Yangoo. UAE.

https://www.enforcementtracker.com/ETid-1912 Criteo. French.

https://www.enforcementtracker.com/ETid-3162 Intesa Sanpaolo. Italian.

https://www.enforcementtracker.com/ETid-2864 Shein. Chinese.

https://www.enforcementtracker.com/ETid-2306 Enel Energia. Italian.

American companies fines tend to be highest since they are biggest and revenue affects the fine amount.

buzer··on Turn off and restrict access to Apple Intelligence features on Mac
And people complained about Symbian menus...
buzer··on ChatGPT now knows what you do on other websites via ad collector
There are multiple reasons for it. One of the major issues is that some DPAs pretty refuse to enforce GDPR (e.g. DPC in Ireland). Hopefully the changes to cross-border enforcement that are coming in force next year will help with this as it at least has some deadlines unlike currently.

Another issue is that controllers generally do not need to change their behavior before the final lawful decision which can take a lot of time to go through the court system, especially if it needs CJEU referral. And once the decision comes in force they can often make small changes and restart the whole process.

Also another issue is that DPAs do not often initiate the investigations themselves (unless breach is involved), they only happen at the request of data subjects and not that many people bother making complaints or follow them up. Just yesterday I had to follow up with 9 page reply to the controller's response to the DPA inquiry.

Additionally ePD and GDPR enforcement is sometimes split between different agencies. In those cases GDPR agency tends to wait for ePD case to be solved before investigating the GDPR aspects, often because the ePD consent validity will affects e.g. GDPR legal basis analysis.

buzer··on ChatGPT now knows what you do on other websites via ad collector
They keep trying it via e.g. chat control
buzer··on Microsoft director: AI scraping 'the largest theft of labor in human history'
Discussion from yesterday (811 comments): https://news.ycombinator.com/item?id=49752056
buzer··on I'm being cyberattacked by Tesla, Inc
CNAME'ing pool-ntp.tesla.com to something they do not control is already quite risky as it would allow someone to e.g. request pool-ntp.tesla.com certificate though it might take quite a few tries.
buzer··on LG denies TV spying claims, says tracking and snooping concerns 'not true'
https://youtu.be/6IFVTcM28KA?t=1370

They at least use a pattern where you need to accept terms of use & privacy policy when you download an app. Same screen has option to accept other agreements like ACR. However by default "select all" option is highlighted so people will often click that.

Slightly earlier on video they state that certain ad related things got turned on automatically during software updates.

buzer··on More questions about whether researchers can trust OpenAI with unpublished math
Some of the recent statements have caused at least me to look those claims in a bit more nuanced light. In particular what does OpenAI consider to be "your data"? I would assume input (prompt) to be it at least. However it becomes more murky when you consider other aspects. Is output "your data"? Is the chain of thought that you are not even allowed to see? Can they use these and possibly even inputs to generate synthetic data that is then used?

All of these would seem to be "your data", but when they are carefully only including certain aspects (like prompts) in their statements it starts to sound they want to hide something.

buzer··on 216M Spy TVs – The LG Smart TV Problem [video]
Is that actually for smart tvs? The first paragraph includes "the products you may access or otherwise connect to via the ThinQ mobile application (not including Smart TVs)" and "These Terms of Use do not apply to any other LG products or services, including Smart Media Products."

[EDIT] Smart Media products terms appear to be at https://us.lgappstv.com/main/terms (for comparison here's UK: https://gb.lgappstv.com/main/terms, there are some other EU versions available for e.g. Germany but I imagine UK terms should be quite close and more accessible for most of readers)

buzer··on Flock used >100 times to track veteran who recorded traffic stop
> Then that officer tracked him thru flock over 100 times for some personal vendetta.

That's not quite accurate according to the article. It was actually worse: There were over 100 searches and some of them were done by officer in question, but some were done by other officers. This was due to lieutenant's order in connection with Jones' citizen complaint. So it wasn't just one officer abusing the system.

buzer··on Ubisoft's FOR HONOR will block SteamOS / Linux players starting September 10
The age verification is it's own can of worms. I'm currently waiting for my native country (but not the one where I reside) to actually publish their wallet implementation. I'm planning to make complaint around it because the whole thing almost certainly breaches ePD. ePD's exceptions are actually for "information society service" rather than just any service. The ISS itself has it's own sets of requirements, but the important one here is that "normally provided for remuneration". Service provided by government as part of their public duty almost never fulfills that requirement.

So in order to store or read data they would need consent. But consent requirements come from GDPR and it's unlikely that this type of consent would be "freely given" given the impact of refusal.

buzer··on Ubisoft's FOR HONOR will block SteamOS / Linux players starting September 10
Someone in EU should try to make a complaint to the local authority who is enforcing ePrivacy Directive regarding anti cheats in general. Despite what people think ePD isn't limited to cookies and rather also applies all data read or stored in "terminal equipment" via use of electronic communications networks. I would say anti cheat should usually qualify. If they want to do it without consent then they need to show that it's strictly necessary for the service user specifically requested (and that applies for each piece of data written/read, including the OS information).

There's good argument that anti cheat itself would need to be consent based. If you don't accept then you simply don't get placed in games with users who have it enabled.

buzer··on DHS is using obscure law to snoop on journalists, non-profits, unions
It is, but T-Mobile's terms at least used to allow you to opt out from what I remember.
buzer··on DHS is using obscure law to snoop on journalists, non-profits, unions
Both SCA and 18 U.S.C. §2712 can grant punitive damages and attorney fees. So there might be lawyers who would take it on contingency, and in this kind of case some non-profit could also have interest in litigating the issue.

And as this is something that has already happened there isn't much else the person in question can do. Third parties always have option to just disclose information to whoever asks it, at most you can hold them accountable for it later if it was unlawful. And what accountability exactly means depends on what laws exists. If you want some real accountability for the people/companies involved in these kinds of decisions then get Congress to pass such laws (however impossible it might be).

buzer··on DHS is using obscure law to snoop on journalists, non-profits, unions
Wouldn't the affected individual be able to sue the provider at least in some cases? From what I understand e.g. Stored Communications Act might allow suing T-Mobile in this case, at least if the individual isn't covered by binding arbitration. And possibly even government under 18 U.S.C. §2712.

Of course then it's up to judge to determine if the request was valid or not.

buzer··on MS Paint and Photos inivisibly watermark even locally generated output with GUID
There are several paragraphs where output looks very AI-like (and Claude flavored one at that), e.g.

> In other words, “generated locally” does not mean that the complete operation is local. Microsoft receives and moderates the prompt, then issues the unique GUID that Paint embeds into the locally generated image. Paint also sends the previous promptGenerationId as lastPromptGenerationId with its next moderation request, allowing successive requests to be linked explicitly.

> That relationship is important. C2PA calls this a soft binding: a value derived from, or embedded into, the content so that the content can still be matched with its provenance record after the file-level manifest has been removed. For a watermark soft binding, the value is the watermark’s content identifier. Microsoft cryptographically signed this assertion.

> After an AI result is applied to the Paint canvas, the available formats are still restricted to PNG, JPEG, GIF, and Paint’s own .paint format. BMP—the classic Paint format—is conspicuously absent.

Personally it didn't bother me too much.

buzer··on MS Paint and Photos inivisibly watermark even locally generated output with GUID
I don't think adding an identifier which can most likely be mapped back to user is "standard mark".

It doesn't explicitly say it, but there is hardly any other reason why it would add server generated ID (from authenticated session) to the saved file.

buzer··on Sol loves to cheat
> I had Claude Code drive a robot last week, and it was very visibly "delighted" like this, more than I've ever seen.

At least it didn't (hopefully?) start the driving by reloading the gun like Neuro did https://www.youtube.com/watch?v=LQ0VEDNR_jE

buzer··on Google has stopped pushing Git tags for some Android source code
Google Drive is customarily used for software interchange?
buzer··on Police officer used Flock cameras to track estranged wife 717 times
Qualified immunity concerns civil liability. Prosecution is about criminal liability.

Civil liability is helpful because tax payers do care about $$$ (if judgements/settlements are starting to eat major part of budget the people will start to care on how to lower those costs) and victims are not limited by what prosecutors are ready to do. The QI is especially problematic because it has essentially become "did someone prosecute cops about this before" because that's effectively the only way to establish precedence that allows you to get across the QI-line in future for sufficiently similar conduct. And like you said, prosecutors are often unwilling to prosecute cops.

buzer··on Google has acquired the data of failed US airline Spirit
It heavily depends on country if employer can access the email or not. For example in Italy:

> Italian Supreme Court case law according to which defensive controls may be carried out where there is a well-founded suspicion of unlawful conduct, provided that an appropriate balance is struck between the employer’s interests and the employee’s dignity and privacy, and that the control concerns data acquired after the suspicion arose.

buzer··on German advocacy group lodges criminal complaint over Meta AI glasses
As per Article 4:

> ‘controller’ means the natural or legal person

There have been various cases where individuals have been determined to be separate controllers. For example there have been many cases where doctors/nurses/police looked into the employer's databases without having professional need and were determined to be separate controllers and were fined under GDPR.

buzer··on German advocacy group lodges criminal complaint over Meta AI glasses
The full analysis of this would need to take in account:

* Who actually determines the essential means and purposes for each processing purpose (and is truly doing it). Fashion ID case is quite relevant here.

* If terms which grant Meta these rights and user a lot of obligations would fall under unfair terms or unfair commercial practices directives. If they do then those aspects of the terms are invalid. These could, for example, affect requirement that the user must get consent from data subject for Meta's processing operations.

buzer··on German advocacy group lodges criminal complaint over Meta AI glasses
I don't think the owner is on the hook if they simply use the service. The individual wasn't the one who truly decided the essential means and purposes beyond personal use, Meta is the one who did that and is thus the controller for that processing.

And I believe in case of European users the contract is between Meta Ireland and user, Meta Ireland is the one who would be the one doing the exporting in that case.

Now if user actually did publish it on Meta's service for broader consumption then they might become controller for that & if initial purpose was that then the initial recording is unlikely to be exempted under household exemption.

buzer··on German advocacy group lodges criminal complaint over Meta AI glasses
Look at what how GDPR is interpreted in regards to CCTVs and bodycams. You generally do need to give proper Article 13 notice in regards to those recordings. In particular EDPB Guidelines on video recording (3/2019) state that:

> The first layer concerns the primary way in which the controller first engages with the data subject. At this stage, controllers may use a warning sign showing the relevant information. The displayed information may be provided in combination with an icon in order to give, in an easily visible, intelligible and clearly readable manner, a meaningful overview of the intended processing (Article 12 (7) GDPR). The format of the information should be adjusted to the individual location (WP89 par. 22).

> The information should be positioned in such a way that the data subject can easily recognize the circumstances of the surveillance before entering the monitored area (approximately at eye level). It is not necessary to reveal the position of the camera as long as there is no doubt as to which areas are subject to monitoring and the context of surveillance is clarified unambiguously

> The first layer information (warning sign) should generally convey the most important information, e.g. the details of the purposes of processing, the identity of controller and the existence of the rights of the data subject, together with information on the greatest impacts of the processing

While recording by these might not always implicate GDPR directly (as it might be exempted under household exemption or the broader allowances given for journalistic purposes), it does give good idea on how unambiguous it should be.

Page 1 of 16Next →