HNHacker News
TopNewBestAskShowJobs

miken123

636 karma · joined March 3, 2013

submissionscomments
miken123··on Apple decided not to roll out Siri in EU after denied request for exemption
> As a small developer, the cost to support something like this would be so overwhelming I wouldn’t consider supporting the EU officially.

As a small developer, you wouldn't fall under the DMA.

miken123··on Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2
> So far, the only sin archive.today has been accused of is retaliating against a guy attempting to dox them.

I think you're missing that circumventing paywalls is unlawful in most parts of the world.

miken123··on Multiple Digital Ocean services down
It is mentioned in their list of subprocessors: https://www.digitalocean.com/trust/subprocessors
miken123··on Fire destroys S. Korean government's cloud storage system, no backups available
Because these companies never lose data, like during some lightning strikes, oh wait: https://www.bbc.com/news/technology-33989384

As a government you should not be putting your stuff in an environment under control of some other nation, period. That is a completely different issue and does not really relate to making backups.

miken123··on Meta enforces purpose limitation via Privacy Aware Infrastructure at scale
“Never attribute to malice that which is adequately explained by stupidity.”

https://en.m.wikipedia.org/wiki/Hanlon%27s_razor

Also, I don’t think that the parent comment was being serious.

miken123··on Meta enforces purpose limitation via Privacy Aware Infrastructure at scale
Many reasons:

- They are not asking for consent, there is just an ok button. - They assume consent when you navigate further on the site, this is not valid consent. - Consent needs to be for specific, well defined purposes. “help personalize content, tailor and measure ads and provide a safer experience” are three purposes in one and none of them are well defined. - They are probably already setting the cookies in your first request, when you have not seen any information yet (did not check)

miken123··on Meta enforces purpose limitation via Privacy Aware Infrastructure at scale
Lovely that their blog with privacy propaganda has a cookie banner that is not compliant with any privacy law in any way. Says everything about their efforts, I guess.
miken123··on Big Tech to EU: "Drop Dead"
> Imagine 2007 and the following years already with the EU act in full effect. AppStore would be dead on arrival.

No, it wouldn't have been, as the DMA only applies to 'gatekeepers' and if you're new, you're simply not a gatekeeper. You need at least 45 million monthly active users and 7,5 billion of revenue for three years.

> So EU should change Apple’s and Google’s status from producer to provider of essential service like electricity for example.

That's the whole point of the DMA: designate these parties as 'gatekeepers', providing essential services ('core platform services' in terms of the DMA). Once you are, you have certain obligations that should allow proper interoperability with other/smaller parties.

miken123··on Google Blog on DMA
> Hotels are concerned that direct booking clicks are down as much as 30% since our compliance changes were implemented. These businesses now have to connect with customers via a handful of intermediaries that typically charge large commissions, while traffic from Google was free.

That's because your search engine results are a joke, not because of the DMA.

If I search for 'hotel <city>', I get an ad from Booking.com, then some hotel ad, then an ad from Trivago, then some Google map with hotels (make sense, but all results there are sponsored by intermediaries), then Booking.com, then Booking.com again, then Expedia, then Tripadvisor, then Trivago.

If you only present me sponsored results from intermediaries, then don't be surprised that people only click on sponsored results of intermediaries.

miken123··on Keep your phone number private with Signal usernames
Except that, you can actually disable them.

https://support.signal.org/hc/en-us/articles/360007061452-Do...

miken123··on EU to hit Apple with first ever fine in €500M penalty over music streaming
You're talking about the Digital Markets Act (DMA) which will come into effect in the EU in about two weeks. It does exactly what you say, although Apple is still actively trying to sabotage it with a sloppy implementation.

Hopefully the US will follow some day.

miken123··on German credit agency earns millions through unlawful customer manipulation
> A country like the Netherlands has its own issues (mainly housing) but doesn't have the myriad of pain points you can find in Germany like Schufa

In the Netherlands we have BKR, which is less all-encompassing than SCHUFA, but also needed to be fined before giving proper right to access under the GDPR: https://edpb.europa.eu/news/national-news/2020/national-cred...

miken123··on Ireland’s DPC set to hit Meta with record privacy fine over US data transfers
There is nothing in there about retroactively applying laws. If there is anything, it may be that the laws were(/are) unclear.

The Irish DPC states they never approved anything (but there has been discussions between various European data protection authorities and the EDPB during the investigation). See for example 2.44 or 2.46 of the report [1]:

> It is factually not the case that the Commission endorsed or approved of the Terms of Service and Data Policy of Facebook or indeed of any other organisation

and

> To the extent that Facebook seeks to rely on or has ever relied on any consultative process with the Commission in order to defend the lawfulness of a particular practice, this has been in error. More pertinently, for present purposes, Facebook makes no such argument in the context of this Complaint. This is because the Commission never provided any such approval in this case nor does it do so in the context of its engagement and consultation role more generally

If you look at the final decision on Meta, you'll see that most of the fine (80+70=150 million) is for the fact that Meta was not clear on what they were doing with user's data. Only the last 60 million is about the actual legal ground of the processing. So the past that Ben Thompson mentions essentially skips 70% of the fines.

And yes, the data protection authorities are acting like a fair player and they are not the referee. We have courts for that (and this will find it's way through the courts, no worries).

[1]: https://www.dataprotection.ie/sites/default/files/uploads/20...

miken123··on Ireland’s DPC set to hit Meta with record privacy fine over US data transfers
It's great that you have a non-publicly available newsletter as a source, but if you read the DPC item [1] you'll see that it's just about the GDPR. What Ben probably does not understand, is that the fine is not about the TOS change _before_ the GDPR came in effect, but about the fact that data was processed without valid legal basis _after_ the GDPR came in effect as the TOS change and an 'I accept' button was simply not sufficient.

[1]: https://www.dataprotection.ie/en/news-media/data-protection-...

miken123··on Ireland’s DPC set to hit Meta with record privacy fine over US data transfers
> Yeah, especially when in the case of the fine for consent about personal ads, the fine was for violations before the law was in place.

Do you have any source for that, or are you just making up things on the spot here? (I can help you, it's the latter)

miken123··on Tell HN: The “Y” logo in the top-left corner has been upgraded to SVG
But is it an optimisation to send the SVG contents in every request, instead of just letter the browser cache the image?
miken123··on 1Password to Add Telemetry
> I could sell an app in the EU that just pinged my server once a day. As long as I wasn't keeping a record of who pinged what when, there is no PII.

Data processing is not just about 'keeping a record'. Processing even for a millisecond is also processing.

> Otherwise everything is PII and you would need consent before every TCP handshake.

Consent is not the only ground for data processing. Normally, it would just be performance of a contract, as the user wants something from you.

miken123··on 1Password to Add Telemetry
> Anomyous telemetry is not PII. GDPR is personal data.

How are you exactly going to submit it anonymously? Will it connect over Tor? Because if you just send it over your internet connection, it arrives with your IP address on the packets, which is PII, which makes it data processing of PII, which makes it require a legal basis to process. And it is legally uncertain that 'legitimate interest' is a valid ground for telemetry data, leaving only opt-in consent.

miken123··on Your.Online: Gandi continues its development
Expect 50 to 200% price increases within a year or so, it is what TWS has been doing with all hosting parties they acquired.

For example, PCExtreme had simple dynamic hosting for 1.95 EUR/month before acquisition [1]. Current pricing after a rebrand is 4.99 EUR/month [2] and in turn you get 1/10th of the storage and traffic.

[1]: https://web.archive.org/web/20180831051543/https://www.pcext... [2]: https://www.versio.nl/webhosting

miken123··on FCC threatens to disconnect Twilio for illegal robocalls
https://status.phoneburner.com/incidents/q55r8f62p437

I guess it was taken care of.

> Our system is currently down due to upstream telephone carrier issues

miken123··on Facebook tracking is illegal in Europe
That's Max Schrems, founder of noyb, the NGO that filed the complaints. An image caption would have been useful.

https://en.wikipedia.org/wiki/Max_Schrems

miken123··on Linux Kernel MultiPath TCP Project
A bonded/teamed interface usually load balanced based on a flow. Thus, over a single TCP flow you will only use one of the interfaces.

On top of that MPTCP also offers advantages when it comes to handover in mobile networks: if your IP address changes for some reason (e.g., switching from Wifi to mobile), existing connections won't be interrupted.

miken123··on Windows Will Die: 90 Minutes to Do 5 Minutes of Work
> even just asleep is fine, for a laptop

Except that Windows never-ever-ever reliably sleeps. There is always something, some program, some driver, whatever, waking it up from sleep.

miken123··on Venmo forces binding arbitration unless you opt out by mail before June 22
> Unfortunately, the law treats negotiations between actual peers and large companies "negotiating" with individual customers the same way--it'd be hard to delineate distinct classes of actors that can and cannot enter into arbitration agreements (or contracts in general).

And yet we are able to do so in the EU, with just one sentence: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...

> (b) ‘consumer’ means any natural person who, in contracts covered by this Directive, is acting for purposes which are outside his trade, business or profession;

and that directive prohibits binding arbitration in the annex:

> (q) excluding or hindering the consumer’s right to take legal action or exercise any other legal remedy, particularly by requiring the consumer to take disputes exclusively to arbitration not covered by legal provisions, unduly restricting the evidence available to him or imposing on him a burden of proof which, according to the applicable law, should lie with another party to the contract.

miken123··on RT challenges EU ban at Europe's second top court
> What actual law, that they recognize, are they breaking?

The current ICJ court case is about the Convention on the Prevention and Punishment of the Crime of Genocide, which was signed and ratified by both parties. If that is proven, that is the law they are breaking.

miken123··on iCloud+ custom email domains should be better
I believe the webinterface signs with the icloud.com domain and not your own.

Happy for you to update the article, no need for credits.

miken123··on iCloud+ custom email domains should be better
I would say another main issue is that while they ask you to setup DKIM records, they do not actually DKIM-sign your emails. Hence your mails may be more easily flagged as spam. Several people have reported this to Apple, but AFAIK it still hasn’t been fixed.
miken123··on Google requiring all ‘G Suite legacy free edition’ users to start paying
When you cancel GSuite you can enable Cloud Identity Free. That will keep all your accounts, just the GSuite functionality will be dropped. At least that was the way it worked a while ago.
miken123··on AWS us-east-1 outage
Well, the narrative is sort of what Amazon is asking for, heh?

The whole us-east-1 management console is gone, what is Amazon posting for the management console on their website?

"Service degradation"

It's not a degradation if it's outright down. Use the red status a little bit more often, this is a "disruption", not a "degradation".

miken123··on Video of Tesla FSD almost hitting pedestrian receives DMCA takedown
Funny, you see the same mistake at exactly the same spot, albeit less spectacular, in the video linked from the tweet: https://www.youtube.com/watch?v=xWc-r0InwVk&t=148s
Page 1 of 3Next →