Hacker News new | ask | show | jobs
by lostlogin 2945 days ago
> How do you know you aren't talking with your user's spouse or a hacker and are make things worse for that user by dumping data to requester?

Playing devils advocate here - don’t store a single thing more than needed. It’s a toxic liability.

1 comments

> don’t store a single thing more than needed

Easier said than done and is harder than what sanctimonious pricks that designed this law probably had in mind.

Everyone with presence on Apple's platforms fears them like the wrath of God and you can't risk not storing data that your users _volunteered_ if that will help you stay on Apple's good side by having better control over more abusive portion of your users.

Then there's the question of whether it is ethical to delete data that was volunteered that could however aid in discovering criminals that chose to abuse your system. Authors of these laws probably think that and nsa would know that I would often seem to agree with them but deep down I'm not so sure as I have deep suspicion that we are cared for and our european security is deeply dependent on arrangements similar to ones done in bletchley. If it's moral for them to store data then it should be by analogy for us. Or in short I dread that my inaction on my web properties would aid existing criminality so out of ethical considerations I'd rather store more.

But now with GDPR I have fears of scenarios like someone admitting to cheating on their spouse on my properties, deleting that info later on, then the spouse discovering that through GDPR request and committing physical violence. Or dictators hunting dissidents by submitting GDPR requests over european VPN. (edit: maybe they wouldn't even need VPN as I'm from EU and would have to grant requests irrespective of user's citizenship? headache)

I don't want to contribute to either scenario but it would seem EU is thrusting this headache of a choice on me, so as a citizen of EU country, fuck the EU.