Software engineer working on very high scale systems, and dad.

Born and raised 🇫🇷, now resident and naturalized citizen 🇺🇸.

🎹🎸🪕🥁🎮

  • 3 Posts
  • 61 Comments
Joined 1 year ago
cake
Cake day: June 17th, 2023

help-circle



  • Yeah, there were different interpretations there from different counsels. It went from “well, they put it there and we don’t store it anywhere else, so nobody is preventing them from removing it, we don’t need to do anything”, with some “oh this field is actually durably stored somewhere else (such as an olap db or something), so either we need to scrub it there too when someone changes a value, or we can just add a ‘don’t share personal information in this field’ little label on the form”; to doing that kind of stuff on all fields.

    Overall, the feeling was that we needed to do best effort depending on how likely it would be for a field to durably contain personal info, for it to smell a judge’s smell test that it was done in good faith, as is often the case in legal matters.


  • Reposting what I posted here a while ago.

    Companies abiding by the GDPR are not required to delete your account or content at all, only Personally Identifiable Information (PII). Lemmy instances are unlikely to ask for info such as real name, phone number, postal address, etc; the only PII I can think of is the email that some (not all) instances request. Since it’s not a required field on all instances, I’m going to guess that the value of this field does not travel to other instances.

    Therefore, if you invoked the GDPR to request your PII to be deleted, all that would need to happen is for the admin of your instance to overwrite the email field of your account with something random, and it would all be in compliance. Or they could also choose the delete your account, if they prefer.

    Source: I’m a software engineer who was tasked at some point with aligning multi-billion-dollar businesses to the GDPR, who had hundreds of millions of dollars in liability if they did it wrong and therefore took it very seriously. I am not a lawyer or a compliance officer, but we took our directions from them directly and across several companies, that’s what they all told us.




  • I once had a conversation under NDA (which has expired since) with an engineer at Apple who was working on iCloud infrastructure, and he was telling me that his team was a bit shocked to read that Dropbox was releasing apps for photos at the time “because they’ve noticed that most of the files users are uploading to Dropbox are photos”. He was like: how do they know that exactly? His team had no idea and couldn’t possibly find out if the encrypted files they were storing were photos, sounds, videos, texts, whatever. That’s what encryption is for, only the client side (the devices) is supposed to know what’s up.

    Not having that information meant a direct loss of business insights and value for Apple, since Dropbox had it and leveraged it. But it turns out Apple doesn’t joke around about security/privacy.










  • Ugh, sorry, the “do your research” phrase to deflect something makes me roll my eyes hard. It might kinda make sense for topics where there is actually research, like COVID prevention, or climate change; and even then, people seem to use it a lot to mean “read stuff I’ve read that I had preselected to agree with my views regardless of whether it’s backed by actual science”. But I find it even more out-of-place when the science we’re talking about is a Kickstarter campaign… It’s become such a catchphrase for thinly veiled attempts at gaslighting people.

    But anyway, back to the substance of it. I definitely didn’t mean that anyone in this thread anywhere blames companies for that, I only meant it in a general sense. I agree no one here was particularly doing it. But I’m sure you’d agree that large companies being out-of-touch with their customers is hardly a marginal view.

    If by “paywall options” you mean the cheap levels that don’t grant you the actual product, yeah, I posted another comment about those, I’m a bit puzzled why people would actually give their money for that. I just don’t see the point of those, so I can’t really judge the ethical aspects without understanding why on Earth people feel compelled to buy those. I would have expected those levels to have 0 people, but I guess they don’t.

    However, for people interested in getting the product, and companies interested in wrapping up the product with those people’s input, I still really can’t see anything unethical going on here. It feel like a win for everyone.




  • Yeah, same, I’m not particularly shocked here. We often blame large companies for being oblivious to what their audience really wants; this is a large company trying to test the waters to better understand and produce what their audience really wants. I’d say that’s not a bad thing for whoever’s interested in those kinds of products for that kind of price.

    Also, I bought a few things out of Kickstarter over the years, and some came out looking pretty good, some… not so much. When the Kickstarter campaign fails hard enough, the supplier ends up disappearing into the ether, and the consumer is left holding the bag. It’s the name of the game, it is what it is. Another upside of this Kickstarter campaign is that since there’s a wealthy company behind it, the people giving that money know that they’ll at least get something.