HN user

AlexanderHanff

48 karma
Posts5
Comments41
View on HN

OK it should be fixed now - there was a rate limit which doesn't normally land but due to multiple Tor users coming through the same exit node, it was triggering the limit.

Nothing to do with the certs just told me a cert error because it never finished the handshake.

I tested through Tor on multiple machines now and multiple circuits and is working clean - thanks for the heads up.

I cannot see what is causing the issue, the certificate's full chain is sent, the clock is synced, the cert is showing zero errors in OpenSSL - so this is very confusing.

The irony is, you don't actually need Tor on my site because there is no logging, no third parties, no adtech etc. it is just static HTML files - so whereas I would normally recommend Tor I designed the site specifically to be privacy first.

I will try to figure out what is going on though because obviously I am fully supportive of people protecting their privacy with Tor.

Not sure why, it is working fine everywhere else - I see in Tor it gives an invalid certificate error, but the Lets Encrypt certificate is working fine in other browsers, so seems to be a Tor thing specifically.

I will investigate.

[dead] 15 days ago

After yesterday disastrous result for democracy, where the President of the European Parliament used her power to force a vote on ChatControl I which the Parliament already voted against and allowed to expire earlier this year.

The move by the President is unprecedented and marks a dangerous time for EU democracy where if the President of the Parliament can overturn a democratic vote they disagree with - what is the point of the Parliament at all?

So I have collected all the details on the MEPs who failed to vite against the procedure yesterday along with their voting history on issues relating to fundamental rights and their history of meetings with lobbyists.

The results paint a very clear picture that these MEPs represent business, not the people who elected them.

[dead] 16 days ago

As a CSA survivor I have spent decades campaigning for victims and survivors of CSA/CSAM and even wrote my Master Thesis on the topic.

Yesterday I once again pleaded with EU law makers not to pass Chat Control.

[dead] 19 days ago

Whereas the main story here is the Commission's complete failure to do anything about Pegasus - I focused on the fact that the MEP in question and MEPs in general - should not be using their phones as information archives.

[dead] 21 days ago

With Trump vs Slaughter gutting independence of the FTC - the Data Privacy Framework agreement used to transfer personal data from the EU to the US is unlikely to survive.

I wanted to see if US Frontier Models are exhibiting censorship so I asked Gemini a question about the current state of the world - the response was quite concerning as Gemini informed me it is "structurally protective of Donald Trump".

Given the recent German ruling on Gemini output being Google's speech and the DSA requirements on misinformation/disinformation it looks like more trouble ahead for Google Gemini.

I have also filed a report with the Commission's DSA enforcement team expressing concerns that Google is interfering with political speech.

You are assuming that the author (me) hasn't tried to help the UN do it right in the past and that assumption would be wrong.

They don't get to shout at big tech when they are doing exactly the same thing and using the same vendors they are berating, to do it for them. It is rank hypocrisy.

Also, I was very clear in the introduction that I support the UN and their mission, which is precisely why they need to be held to account because their own Charter requires it.

As much as I support the UN (I have worked in privacy for 20 years, my life's work is in the field of human rights) - I do not support hypocrisy and it is long past due that the UN lead by example.

No, it argues that the use of javascript for purposes which require consent, requires consent...

EU law only allows strictly necessary use for the provision of the requested service so adtech and analytics require consent as they are not considered as strictly necessary.

Today I have successfully managed to get the police to investigate the deployment of adtech software (scripts) without consent as a criminal offence under unauthorised computer access and misuse.

I am basically arguing that deployment of these adtech payloads by websites and apps without consent, is a criminal offense.

Yes this is the difference, they did not allow you to opt out previously, they explicitly said that if you want to be in the club you have to accept their spam. Now they allow you not to accept their spam.

Now they rely on Soft Opt-In (which again might not be valid in your case, if you signed up to their site but didn't actually buy anything the soft opt-in exemption does not apply) so you may still have an actionable complaint here.

Processing my personal data in such a way (to ban me from your services pre-emptively) would be a breach of the GDPR and in some member states could involve criminal sanctions.

For example, in the UK we have a very famous case (The Consulting Association (TCA)) where building contractors joined together to build a list of construction workers they didn't want to hire - this was determined as a criminal breach of UK data protection law.

So have at it, I love a challenge...

They actually are bound by the ePrivacy Directive due to jurisprudence (EU bodies must comply with CJEU rulings).

I actually wrote to the EDPB on 25th May 2018 (the day GDPR came into effect) and forced them to make their own website compliant with the ePrivacy Directive (I still have the email thread, it was quite an interesting discussion).

I also filed a complaint against the Court of Justice on October 1st 2019 within minutes of them publishing their Judgment on the Planet49 case (C-673/17) because their own website didn't comply with the judgment - they fixed it within 18 minutes.

So yes EU institutions get it wrong sometimes, but they generally fix it quickly when they are informed. I currently have a big case ongoing with the EDPS against the European Commission and the European Parliament for hosting live streams directly on social media instead of the official live streaming platform setup for EU bodies (on the basis that forcing people to engage on social media is a breach of fundamental rights because it allows those platforms to infer special category data (political interests and others depending on the topic of the live stream).

EDPS just actually updated me this week that they have concluded their side and are now waiting on the final responses from the Commission and Parliament.

So yes, the rules do work, but you have to be pro-active, armchair activism doesn't work.

Absolute nonsense. Any company that was complying with the old Data Protection Directive should have had zero issues upgrading their processes and policies to comply with GDPR there are very few material differences between the two and the previous law existed since 1995 - most of the changes are around accountability (record keeping).

Also cookies literally have nothing to do with GDPR other than the definition of consent - Cookies are governed under and entirely different law which has existed since 2002 (Directive 2002/58/EC).

It bugs me when I see people criticising the law when they actually havent even bothered to research and understand it or even look at the correct law.

It is not just the fine - they are no longer permitted to conduct the processing activities - so no they don't continue to profit from it, one of the reasons the fine was reduced was specifically because they made changes to bring themselves into compliance during the investigation. This is stated in the Regulator's press release directly.

Well John Edwards just resigned yesterday so maybe you will get a real Commissioner this time - although that said, John was hired specifically as someone who would do nothing, so I guess he did what he was paid to do.

He has largely been ostracised by the privacy and data protection community (even at regulatory events) I have seen him wandering around alone and aimlessly at a number of regulatory events, he didn't seem very comfortable and didn't really have a lot of interaction with his peers.

The fine is largely irrelevant, now they have faced enforcement we have a decision to file a Representative Actions Directive (equivalent of a US class action) claim with - the cost of that will be 100-1000x more than the fine and will likely lead to shareholder revolt as well (institutional shareholders will likely sue the parent Currys PLC for breach of fiduciary duty and not disclosing these issues during earnings calls and annual reports.)

So the fine is the first step to a much wider legal action.

The fine also puts other loyalty clubs on notice that if they do this, they are going to face consequences - so it has a much wider impact than simply monetary.