HNHacker News
TopNewBestAskShowJobs

lwyr

131 karma · joined April 10, 2013

submissionscomments
lwyr··on Apple Successfully Implements OpenID Connect with Sign in with Apple
Mobile ecosystem issues aside, IRMA looks excellent. Could IRMA's decentralization and selective disclosure features somehow be combined with OpenID? For example, could the IRMA application serve as a standalone OpenID provider, perhaps using OpenID Connect Federation to establish trust? [0]

[0] https://openid.net/specs/openid-connect-federation-1_0.html

lwyr··on Complete guide to GDPR compliance
Warning: The privacy notice template on this site (https://gdpr.eu/privacy-notice/) omits basic mandatory elements (e.g. retention periods, right to lodge a complaint). The template's section on cookies is insufficient and misleading. Cookies are regulated by a different law (the ePrivacy Directive) and their explanation does not go into these rules at all.

As frereubu notes elsewhere in this thread, the UK regulator's GDPR guide is excellent, and is a much better starting point in my opinion: https://ico.org.uk/for-organisations/guide-to-data-protectio...

lwyr··on Bitwarden Completes Third-Party Security Audit
At the time of writing the link to actual report in the blog post does not work. Here is the correct link: https://cdn.bitwarden.com/misc/Bitwarden%20Security%20Assess...
lwyr··on What is the ‘legitimate interests’ basis?
The legitimate interest has been around for a while. It was also a legal basis to process personal data under the 1995 Data Protection Directive which the GDPR replaced. If you are interested in learning more about the notion of legitimate interest and balancing it against the interests of individuals, there is a 2014 opinion from the body of EU data protection regulators that explains the concept with a number of examples. [1]

> If a company sells something online they only really need your address & name for delivery + credit card details.

That would likely be "necessary for the performance of a contract" which is also a legal basis to process personal data. [2]

> I know of multiple companies where they prior to GDPR asked for explicit concent during signup for being allowed to send newsletters, but who post-GDPR dropped the concent and use 'Legitimate intrests' to justify it. Basically leaving the individual worse off.

That could be a violation of the ePrivacy Directive which provides that email marketing requires consent. [3]

[1] https://ec.europa.eu/justice/article-29/documentation/opinio...

[2] See Article 6.1(b) GDPR at https://eur-lex.europa.eu/eli/reg/2016/679/oj

[3] For information about how this rule is implemented in the UK, see: https://ico.org.uk/for-organisations/guide-to-pecr/electroni...

lwyr··on DuckDuckGo Traffic
Should I care about free speech if I have nothing controversial to say?
lwyr··on Am I logged in or not? GDPR case study on the example of Chrome browser change
A tracking link from the International Association of Privacy Professionals...
lwyr··on More diagnostics data from desktop
In addition to the GDPR concerns mentioned in sibling posts, this type of collection is likely covered by Article 5.3 of the EU ePrivacy Directive, which requires consent for storing or reading information from end-users' devices (also known as the "cookie rule").[0] The Dutch Data Protection Authority recently applied this rule to Microsoft's collection of telemetry data through Windows 10.[1] Notably, this rule is not limited to personal data; it applies to all "information."

[0] http://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:020... [1] https://www.autoriteitpersoonsgegevens.nl/sites/default/file...

lwyr··on No matter what, Equifax may tell you you’ve been impacted by the hack
cynicism == obedience
lwyr··on Why check-cashing stores are a good deal, according to a UPenn professor
By removing bad options. Like cars without seatbelts, or toys with lead in them.
lwyr··on There is no WhatsApp 'backdoor'
Why is moxie doing PR for WhatsApp?
lwyr··on Ask HN: Are there real-world examples of moral failures of software engineers?
Nobody mentions software freedom? [0] Arguably any software that restricts user freedom is the result of a moral failure somewhere in the process.

[0] https://en.wikipedia.org/wiki/Free_software

lwyr··on Coffee Delivery Is the Future of On-Demand Ordering
The viability of this service is inversely proportional to income equality.
lwyr··on FreedomBox 0.7 released
Debian Pure Blends are not derivatives. [0]

[0] http://blends.debian.org/blends/ch02.html

lwyr··on FreedomBox 0.7 released
I think FreedomBox is a Debian "pure blend" configured to provide self-hosted communication services such as blog, dav, tor, voip, vpn, wiki and xmpp on low-power open hardware such as single board computers, and any other hardware that runs Debian.
lwyr··on FreedomBox 0.7 released
Our dependence on technology enables new vectors of control and I am not as optimistic about the ability of laws to guarantee these will not be abused. Trust in government as an agent of freedom is a very recent (not to mention regional) development. I say we err on the side of freedom and don't tempt government too much with opportunities for technology-assisted totalitarianism.
lwyr··on Europe's highest court has rejected the 'safe harbor' agreement
That's the press release, which is a good summary, but not the actual judgment. The judgment is available at: http://curia.europa.eu/juris/documents.jsf?num=C-362/14