HNHacker News
TopNewBestAskShowJobs

simpss

254 karma · joined August 2, 2017

submissionscomments
simpss··on (Telemetry) Pseudonymization Feedback and Question
Full disclosure, I have some rather strong feelings about telemetry on gitlab and the implementation process itself.

-----------------------

I originally posted a different issue labeled "Pseudonymization MVC Rollout Plan"[1] but that issue went private rather quickly after appearing here. Sadly it wasn't archived.

To keep this issue from just going private, it (and some other relevant issues) have been archived: http://web.archive.org/web/20211012193943/https://gitlab.com...

There is atleast one more telemetry related issue that[2] has had their access limited after being mentioned in the feedback thread.

Also, I'd recommend checking out:

* the last telemetry attempt from 2019: https://gitlab.com/gitlab-com/www-gitlab-com/-/issues/5672

* feedback from last time: https://gitlab.com/gitlab-com/support/support-team-meta/-/is... & https://gitlab.com/groups/gitlab-org/-/epics/2280

* self-hosted instance telemetry(operational data section) that is already live and has a pretty severe dark pattern for opting out: https://about.gitlab.com/blog/2021/07/20/improved-billing-an...

[1] - https://news.ycombinator.com/item?id=28840685

[2] - Telemetry .com user interviews - User interviews - GDPR compliance is the standard and absolutely required - https://gitlab.com/gitlab-org/uxr_insights/-/issues/839

simpss··on How to permanently delete your Facebook account
As a counter point to this. Facebook has (tried and mostly succeeded) to replace community forums that used to be either public or with open registration and without the negative effects of facebook.

Stuff that's running phpbb or other similar software.

simpss··on Ask HN: Recruiters want people who do side projects, yet contracts forbid them?
the way it should be done is not just crossing it out. You also add the signatures of both sides to the redaction. One copy stays with you, the other with the employer.

In digital terms, it's easier just to amend the whole file.

simpss··on Manual for a popular facial recognition tool shows how much the software tracks
Someone linked "little brother" in another thread, which is a fiction novel of a very similar situation. I found it a good read sprinkled with realistic descriptions of the tech & countermeasures.

https://www.gutenberg.org/files/30142/30142-h/30142-h.htm

simpss··on Massachusetts health notifications app installed without users’ knowledge
it could work with google cloud providing oauth and the phone verifying it's the same account.
simpss··on Massachusetts health notifications app installed without users’ knowledge
Thank you, I've even used this functionality some years ago but didn't remember it existed.

I've since de-googled my phone and sacrificed some apps that require google services, but this whole thing shows (to me) that it was the right decision.

simpss··on Massachusetts health notifications app installed without users’ knowledge
I think the real question is what mechanism allows them to push a random app to some phones? google play services is actively listening for remote installation requests?

that's essentially a remote-code-execution backdoor to all android phones?

simpss··on New browser signal could make cookie banners obsolete
smaller, local(to me) sites have started to have cookie banners that have an effect. My bank, 1/3 of the bigger news sites here etc...

They all started with a single "agree" button, then went to "agree/disagree" with no effect and are finally starting to come around to a functioning disagree button.

GDPR also helps here, as it defined what identifies an individual and that made most of the tracking PII even when it's all merged by a random ID that stays with the user. The effect is slow, but it's starting to work.

Hopefully the next step will be abandoning cookie banners and only using technically required cookies(don't need conset) and/or non-identifying tracking for aggregate results. This is a massive improvment on UX and actually gives the company more quality data that doesn't identify any single individual.

I'm personally pushing for aggregated tracking in my current company. It's an uphill battle, but one that can be won I think.

simpss··on Data portability, the forgotten right of GDPR
data needs to be provided in a machine readable format.

From there, a specific parser/converter needs to be built by the competing service for imports.

simpss··on Using GDPR to obtain one’s data as JSON
not sure if you want to say that such a session cookie would require consent or not, but just to make it clear, it definitely doesn't.

See 3.2 in data protection working party recommendations: https://ec.europa.eu/justice/article-29/documentation/opinio...

simpss··on Using GDPR to obtain one’s data as JSON
If i can delete the cookie and nothing goes visibly wrong, it's obviously not needed.

Same with blocking a script that sets such a cookie. Most cookies are not needed for providing a service.

edit: see the article 29 data protection working party guidelines here: https://ec.europa.eu/justice/article-29/documentation/opinio...

simpss··on 60% of school apps are sending student data with third parties without consent
Turn to the European ombudsman and start forcing your government to work.

https://www.ombudsman.europa.eu/en/publication/en/3510

simpss··on Belgian farmer accidentally moves French border
it has a small price so it becomes difficult/cost-prohibitive to use for nastier purposes.

ex, in my country forest owners get spammed and targeted by forest-management companies that want to cut it down.

simpss··on Dark patterns after the GDPR: consent pop-ups and their influence
It's usually a good hint that it really isn't a legitimate intrest case if they allow you to turn it off.

A legitimate intrest does not require an opt in (or an opt out). Consent does. If the page mixes those two up they're either clueless or trying to walk in the gray area and don't really understand(or don't want to understand) what either of those terms mean.

simpss··on Apple's privacy labels show WhatsApp and Facebook Messenger hunger for user data
It doesn't have to have an effect to everyone, it's about taking responsibility and actually defining what they're doing.

Once we have everyone actually publishing what they're doing it's a lot simpler to file complaints to DPA's and to verify they're actually compliant with legislation.

simpss··on French watchdog fines Google, Amazon for breaching cookies rules
GDPR deals with identifiers that can tie data to a single individual. Cookie IDs are just one way of doing that, true.

That's why GDPR is so powerful and a well thought out regulation. Replace the technology completely, but GDPR still applies as user-unique identifiers are still used. ex, cookie with fingerprint.js, nothing really changes. You still need to ask for consent for user-level tracking.

simpss··on French watchdog fines Google, Amazon for breaching cookies rules
it takes a lot of time for regulators to catch up with all the shenanigans the bigger offenders are pulling.

But, it does give internal employees the tools to fix it in smaller companies, or smaller companies that use the services of these global companies(ex, google analytics).

Pre-gdpr, if I raised some of these points in any of my workplaces, nothing ever came out of it. Now, it's a different story.

Same with direct-marketing spam e-mails, where a customer complains.

It'll take some time for regulators to sort out the big offenders, but the regulation is already having a positive effect within smaller companies.

simpss··on Using Google Analytics without GDPR consent
yes, that is a good clarification. Probably shouldn't have tacked on the "not a company" bit.

A person without a company can act outside of the personal bounds.

simpss··on Using Google Analytics without GDPR consent
I completely agree, if you're acting outside of personal bounds this does not exclude you. ex, generating profit by selling ads, which gets taxed as income.

Probably shouldn't have tacked on the company bit.

simpss··on FTC Sues Facebook for Illegal Monopolization
This is one of the things GDPR tries to achive.

> To further strengthen the control over his or her own data, where the processing of personal data is carried out by automated means, the data subject should also be allowed to receive personal data concerning him or her which he or she has provided to a controller in a structured, commonly used, machine-readable and interoperable format, and to transmit it to another controller.

https://gdpr-info.eu/recitals/no-68/

simpss··on Using Google Analytics without GDPR consent
exactly, this does not require a cookie notice. See here for explanations: https://europa.eu/youreurope/business/dealing-with-customers...

Consent is mainly required for cookies that are not technical requirements for providing the service.

simpss··on Using Google Analytics without GDPR consent
yes, and you have to line out how the processing is necessary for providing the service, there has to be no less-intrusive method of achieving the desired result and be ready to prove it.

hint, user-level analytics rarely is. And in this specific example, repurposing logs kept for one purpose(ex, security/auditing) to user analytics is definitely not something you can just do

simpss··on Using Google Analytics without GDPR consent
GDPR doesn't apply to personal websites where there is no company behind the website.

edit: here's a source: https://gdpr-info.eu/art-2-gdpr/

This Regulation does not apply to the processing of personal data:

(c) - by a natural person in the course of a purely personal or household activity;

simpss··on Using Google Analytics without GDPR consent
log files have a different original purpose. But yes, if you repurpose your log files to track individual users granularly, that processing would be illegal without gathering informed consent first.
simpss··on S&P Dow Jones Indices to launch cryptocurrency indexes in 2021
wouldn't storing electricity mean that you're able to take some out of storage & use that stored electricity?

I don't see a way to turn bitcoin back into electricity. One could exchange bitcoin to fiat currency and then buy new electricity(created from a different source) but that's not really using stored electricity.

simpss··on macOS has checked app signatures online for over 2 years
ofcourse it can be divorced, keep the data client-side, as kindle does?
simpss··on Samsung TV owners complain about increasingly obtrusive ads
oh god, I just broke my last xperia compact that stayed with me for years(x compact) and it's impossible to find something small again, not even getting into android updates and a cleanish android experience.

well. I'm a nokia 5.3 owner now. It's big, but ticks all the other boxes & is cheap...

simpss··on Historical programming-language groups disappearing from Google
take a look at AMP for emails...

https://amp.dev/about/email/

simpss··on Microsoft adding support for custom '+' email addresses in Office 365
The social acceptance part is truly hard. I recently received a BS trademark cease & desist because i was using the company name in the e-mail address I provided them & was using to communicate with them.

Personally, i've just replaced the recipient_delimiter default value(+) with "." as that is basically impossible to strip out. Ex, firstname.COMPANY@example.net

I do get a lot of weird looks when handing the addresses out in person, but a quick explanation usually works. I just tell them, that if I start receiving spam from one one the addresses, I can just block it and be done with it. They sometimes counter with "but we won't spam you" and I acknowledge that with "but not everyone is so nice as you" or something like that.

ps: you can use multiple delimiters, so grouping is possible with firstname.bills.COMPANY@example.net

simpss··on Google no longer providing original URL in AMP for image search results
yep, that works, sadly .uk doesn't so domain endings that are commonly found in words can't be used.
← PreviousPage 2 of 4Next →