HN user

MrQuimico

14 karma
Posts0
Comments13
View on HN
No posts found.

Something to keep in mind is that this is about certification of products, not people. This is not a regulation for the profession of Software Developer, but a regulation for software products. The EU knows very well that it needs more people from all backgrounds writing and understanding software, not less.

As it is, I think this is going to be very similar to what is already required for some specific industries like healthcare or finance. Startups that want to operate in these industries already need to go through some certification processes of their products and services. Most startups will probably fall under the "low risk status" category until they are a big enough. If self-assessment is anything similar to what it is already required for things like PCI DSS or GDPR, then most small companies will be fine until they are big enough to care.

And by the way, there is no easy way for the EU to regulate that to write software you need a specific degree.

How is a car a digital service? Is this system using some type of software? Sure, but that doesn’t make it a digital service.

Also, where do you live that businesses selling goods to you are not liable if they don’t work as expected? This is not a software problem, the problem here is that a key doesn’t work as expected. The fact that it may “have software” somewhere doesn’t make the problem go away.

The problem is not only the geo location of the datacenters. As long as these subsidiaries are under the control of a USA corporation, this is illegal, since the USA corporation can be requested by the USA gov to share any data they may have not matter where it's stored. Only options are a 100% GDPR compliant solution (European or from a country with similar laws) or self-host. Hopefully another Privacy Shield like agreement will be in place soon.

I'm sure this change from country to country, but at least in my country you don't need to be "licensed" to be held liable because of the damage you do and you can be disqualified to do that job.

My point being that better software is not going to be written just because the people writing it is afraid of losing their license or being held liable, because in many circumstances that can already happen.

The problem here are not only the developers and the crappy code. Some people here put this thing in production knowing that it was faulty, or once they knew it didn't work as expected they did all they could to hide this for years, blaming others of their own mistakes.

And yes, I agree we need to be better. But it's very important to understand that many of the potential licensed software engineers that are already writing crappy software today and will continue to do so if licensed because they just don't know better.

I have a VPS in SBG1.

So far I haven't got any communication from OVH alerting me about this. I think that's the first thing they should do, alerting their customers that something it's happening.

Anyway I was running a service that I was about to close, so this may be it. I do have a recovery plan, but I don't know it it is worth it at this point.

I'm never using OVH again. The fire can happen, but don't ask me about my recovery plan, what about yours?

This is stupid. It's like asking a blacksmith to not build a specific knife, because it'll be used in a murder. You need to prosecute the murderer not the people building the knife.

Software, as an object, is harmless. It can be used for good or evil, just like anything else. So if anybody needs an oath is the people using the software, not the people building it.

Apple WWDC Keynote 6 years ago

They can remove the app from the App Store at will. We need to wait to know the details, but it's very likely this will be one of the reasons the will use.

How do you enforce that when the service is provided by a company in another country?

GDPR solves that because if you want to do business with European citizens you must comply with it no matter where you are. GDPR is not only about the fines, it stablishes protocols to communicate breaches, makes somebody responsible for it (the DPO) and makes distinctions between the different types of data and the requirements to handle it.

Also, enforcing GDPR is no joke, and we are still learning its consequences (http://www.london-registrars.co.uk/first-prison-sentence-ari...).

As I see it, Licensed Data Engineers won't make companies more careful with our data, since all they need to do is to sue them and fire them when there is a problem. We need laws that make data hard to use, so companies will only ask for what they really need, will use the data with a purpose and will store it only while it's useful.

Software is more similar to a car than it is to a bridge. Companies build and sell them all over the world. Cars are certified at each country as needed, but it doesn't matter who is building them, as long as they meet all the requirements. Software should be similar.

If you want voluntary targeted advertising, then read sites or sign up for newsletters that cover these topics. These sites can show you ads that are relevant for their audience, without having to track your activity.

Sites that are not niche specific (like newspapers) shouldn't try to microtarget each user. They lose control of the ads they show near their content, making them less relevant. I'm tired of reading news about the coronavirus crisis surrounded by Amazon's offers on some items I visited a month ago. I still think ads are better when they are somewhat related to the content you are reading, rather than to the user's past activity on other websites.