Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
buzer
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
1.
▲
by
buzer
4d ago
CNAME'ing pool-ntp.tesla.com to something they do not control is already quite risky as it would allow someone to e.g. request pool-ntp.telsa.com certificate though it might take quite a few tries.
2.
▲
by
buzer
5d ago
https://youtu.be/6IFVTcM28KA?t=1370 They at least use a pattern where you need to accept terms of use & privacy policy when you download an app. Same screen has option to accept other agreements like ACR. However by def
3.
▲
by
buzer
6d ago
Some of the recent statements have caused at least me to look those claims in a bit more nuanced light. In particular what does OpenAI consider to be "your data"? I would assume input (prompt) to be it at least. However it becomes
4.
▲
by
buzer
9d ago
Is that actually for smart tvs? The first paragraph includes "the products you may access or otherwise connect to via the ThinQ mobile application (not including Smart TVs)" and "These Terms of Use do not apply to any other L
5.
▲
by
buzer
12d ago
> Then that officer tracked him thru flock over 100 times for some personal vendetta. That's not quite accurate according to the article. It was actually worse: There were over 100 searches and some of them were done by officer in q
6.
▲
by
buzer
16d ago
The age verification is it's own can of worms. I'm currently waiting for my native country (but not the one where I reside) to actually publish their wallet implementation. I'm planning to make complaint around it because the
7.
▲
by
buzer
16d ago
Someone in EU should try to make a complaint to the local authority who is enforcing ePrivacy Directive regarding anti cheats in general. Despite what people think ePD isn't limited to cookies and rather also applies all data read or s
8.
▲
by
buzer
18d ago
It is, but T-Mobile's terms at least used to allow you to opt out from what I remember.
9.
▲
by
buzer
18d ago
Both SCA and 18 U.S.C. §2712 can grant punitive damages and attorney fees. So there might be lawyers who would take it on contingency, and in this kind of case some non-profit could also have interest in litigating the issue. And as this is
10.
▲
by
buzer
18d ago
Wouldn't the affected individual be able to sue the provider at least in some cases? From what I understand e.g. Stored Communications Act might allow suing T-Mobile in this case, at least if the individual isn't covered by bindin
11.
▲
by
buzer
23d ago
There are several paragraphs where output looks very AI-like (and Claude flavored one at that), e.g. > In other words, “generated locally” does not mean that the complete operation is local. Microsoft receives and moderates the prompt, t
12.
▲
by
buzer
23d ago
I don't think adding an identifier which can most likely be mapped back to user is "standard mark". It doesn't explicitly say it, but there is hardly any other reason why it would add server generated ID (from authentica
13.
▲
by
buzer
28d ago
> I had Claude Code drive a robot last week, and it was very visibly "delighted" like this, more than I've ever seen. At least it didn't (hopefully?) start the driving by reloading the gun like Neuro did https:/
14.
▲
by
buzer
28d ago
Google Drive is customarily used for software interchange?
15.
▲
by
buzer
28d ago
Qualified immunity concerns civil liability. Prosecution is about criminal liability. Civil liability is helpful because tax payers do care about $$$ (if judgements/settlements are starting to eat major part of budget the people will s
16.
▲
by
buzer
1mo ago
It heavily depends on country if employer can access the email or not. For example in Italy: > Italian Supreme Court case law according to which defensive controls may be carried out where there is a well-founded suspicion of unlawful co
17.
▲
by
buzer
1mo ago
As per Article 4: > ‘controller’ means the natural or legal person There have been various cases where individuals have been determined to be separate controllers. For example there have been many cases where doctors/nurses/pol
18.
▲
by
buzer
1mo ago
The full analysis of this would need to take in account: * Who actually determines the essential means and purposes for each processing purpose (and is truly doing it). Fashion ID case is quite relevant here. * If terms which grant Meta the
19.
▲
by
buzer
1mo ago
I don't think the owner is on the hook if they simply use the service. The individual wasn't the one who truly decided the essential means and purposes beyond personal use, Meta is the one who did that and is thus the controller f
20.
▲
by
buzer
1mo ago
Look at what how GDPR is interpreted in regards to CCTVs and bodycams. You generally do need to give proper Article 13 notice in regards to those recordings. In particular EDPB Guidelines on video recording (3/2019) state that: > Th
21.
▲
by
buzer
1mo ago
My first thought was "huh, I wonder if they follow GDPR, that starts sound to like Article 32 violation" (related to security of processing). I checked the privacy policy and yes, they are based in Germany so GDPR likely applies
22.
▲
by
buzer
1mo ago
Storing IP address itself is not illegal. The questions are: 1) what is the legal basis for storing it and if that's proper or not (e.g. legitimate interest requires balancing test) 2) if proper GDPR Article 13 notice was given and it
23.
▲
by
buzer
1mo ago
> If the company decides that a certain user should not see the website, the user will not see the website, and no one will know about it, and the user will have no recourse. If the the processing is subject to GDPR (e.g. if controller i
24.
▲
by
buzer
2mo ago
Of one year. How many years does it take complete the investigation and let courts handle appeals? I assume they do not need to change behavior nor can the fine increase during the appeals.
25.
▲
by
buzer
2mo ago
That's legalization setback, not court setback.
26.
▲
by
buzer
2mo ago
Can you be more specific? The only related court cases I'm aware of are U.S. The Crew lawsuit which seems to have reached settlement recently and the French case regarding which I haven't seen any updates since it's filing.
27.
▲
by
buzer
2mo ago
No, it's not. ePD is lex specialis in relation to original Data Protection Directive (and later GDPR). DPD was replaced by GDPR, ePD was not. There has been talks about ePrivacy Regulation over the years, but it was shelved again in 20
28.
▲
by
buzer
2mo ago
"legitimate interest" is legal basis in GDPR. ePD (which governs access to cookies) does not have such legal basis, only consent and the two exceptions. Other processing (like after value is read) can happen under GDPR if the data
29.
▲
by
buzer
2mo ago
This is actually slightly narrower exception than people (and regulators) think. The exception is: > strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide
30.
▲
by
buzer
2mo ago
Well, if you presented them with list of 100 partners each with 20 page of privacy policies and they accept it within 10 seconds it should be tricky to argue that user actually read it all. You could, for example, require that user answers
More ›