That's uBlock Origin Lite, not uBlock Origin. They are two very different extensions. Lite, for example, does not allow you to add custom filters.
HN user
buzer
Staff Software Engineer at 8x8
Especially interested in systems scaling & IAM and also general interest in most of thing on backend side.
You can reach me via <username>@<username>.net
If someone is in EU and is affected by this they could potentially utilize GDPR to make both Microsoft and LG take responsibility for this.
It's hard to say directly from the article if there is any GDPR breach. If everything was part of the installer and it doesn't actually submit anything (including downloading the ad) to LG then it's harder to argue that there is GDPR violation, but knowing the SOP of these kinds of software that is unlikely.
If the software did indeed send personal data to LG then there are at least following question: How was Article 13 notice delivered to user? Article says that this was installed quietly. Did Microsoft deliver Article 13 compliant notice to user at some point? They probably did deliver their own notice (though it's open question if it's compliant), but not LG's. However since Microsoft is the one that installed the software and they exercise control over the standards which must be met, it's possible that they would end up being joint controller at least for some processing.
I should add that Article 13 requires that the notice is given "at the time when personal data are obtained". The only exception is when "data subject already has the information" and possible Article 23 restrictions, but those are unlikely to apply.
If someone wants to make a complaint they should first make Article 15 request to LG. Copy of personal data is useful, but 15(1) information is the primary goal. Additionally ask for information on how and when did LG provide you the Article 13 notice if they did indeed process your personal data.
After that if they cannot show that they provided Article 13 notice when they received your personal data submit a complaint to your local DPA. You can additionally flag other violations as well if they are applicable (e.g. not naming recipients as part of Article 15 response, not giving actual retention time or meaningful information how that is determined, invalid legal basis etc.). You should also flag in the complaint that Microsoft is likely joint controller for some of the processing given that they are the ones who approved the automatic install of the software which violated GDPR.
That's good if true. When did it change? I very much do remember that back when the change happened the modal I received didn't actually say anything (https://news.ycombinator.com/item?id=45064212) and thus I was by default opted-in until I saw the news and went to disable it, fortunately before the training actually started.
No for what? The opt-in for model training? About a year ago Anthropic changed "Allow use of your chats and coding sessions to train and improve Anthropic AI models" to default to on: https://www.anthropic.com/news/updates-to-our-consumer-terms
Or do you mean the feedback stuff? Their KB article at least seems to contradict that.
Sure, but the point is more that once you submit feedback then the usual "opt out of using my data for training" no longer apply and at least that reply (and possibly whole conversation) can be included in training set in one way or another.
They don't use your general chats it if you have opted out (note: opted out, not opted in). However if you submit feedback then whole conversation can be used.
https://help.openai.com/en/articles/5722486-how-your-data-is...
Even if you have opted out of training, you can still choose to provide feedback to us about your interactions with our products (for instance, by selecting thumbs up or thumbs down on a model response). If you choose to provide feedback, the entire conversation associated with that feedback may be used to train our models.
https://privacy.claude.com/en/articles/7996885-how-do-you-us...
If you explicitly report materials to us (e.g.via our thumbs up/down feedback mechanisms), or by otherwise explicitly opting in to training, then we may use those materials to train our models.
There are multiple ways to use feedback. Personally I would often be fine with actual human reading my feedback, taking in account the points I made and evaluating how it should affect their feature development and future roadmap.
Now what I would expect AI companies to do is to take things which were submitted as feedback and pretty much adding to training:
"Do more of this: <copy of the whole response which was flagged as good in feedback>"
"Do less of this: <copy of the whole response which was flagged as bad in feedback>"
It's paraphrased, but the point is that they will most likely use it more-or-less as-is and thus whatever is in there will be part of the model's training set rather than someone picking up the parts from response that are important and only including them (which happens with traditional feedback).
Aren't the cameras on city's land or did city lease the land to Flock? If they are on city's land couldn't city require that Flock removes their stuff from city's property or city will do it on Flock's expense?
It's unfortunately somewhat common these days and personally I actively avoid any place which does this. At least it's only somewhat common rather than the standard so it's still possible. Couple of examples:
https://sushiconfidential.com/wp-content/uploads/2024/07/sc_... "3.5% Living Wage Surcharge added to each bill which allows us to provide the service you have always enjoyed!"
https://www.pacificcatch.com/menu/ "NorCal - A 3% surcharge (5% in San Francisco) will be added to all Guest checks to help offset the rising cost of wages and benefits. This is not gratuity."
Personally I do agree, but enforcement is unfortunately behind DPAs and it's pretty clear that they are trying to avoid ruling on it.
In theory someone could directly sue some company which engages on this via Article 79, but this can be expensive and depending on jurisdiction the plaintiff can end up with personal liability on defendant's legal costs if court ends up finding that this is actually legal (e.g. Finland has "loser pays" rule in civil suits).
Additionally this does also touch ePD and in some countries there might be different agency which handles ePD complaints compared to GDPR, like in Finland Data Protection Ombudsman handles GDPR, but Transport and Communications Agency (Traficom) handles ePD. If there is something that touches both the Ombudsman usually lets Traficom take care of ePD aspects before they give any GDPR ruling. Both of these can take years.
Not quite.
This shall not prevent any technical storage or access for the sole purpose of carrying out or facilitating the transmission of a communication over an electronic communications network, or as strictly necessary in order to provide an information society service explicitly requested by the subscriber or user.
This is the reason why these are usually separated to "strictly necessary" and "functional" cookies. Functional cookies are things which enhance the functionality, but are not strictly necessary. These would generally include things like persistent cookie for language choice rather than just session one.
It's called "pay-or-okay" (or "consent-or-pay") and there hasn't been many decisions on it yet which has led noyb to sue German DPAs: https://noyb.eu/en/years-inactivity-pay-or-ok-cases-noyb-sue...
There is one case where DPA ruled in favor of the company, but it's currently being appealed: https://noyb.eu/en/pay-or-ok-der-spiegel-noyb-sues-hamburg-d...
Another one ruled against company and court agreed: https://noyb.eu/en/court-decides-pay-or-okay-derstandardat-i...
In 2022 I got physical mail about leaving a review for something I bought from Amazon (sold by company X, shipped by Amazon) in exchange for Amazon Gift Card. It contained the name of the product I bought. When I tried to report it to Amazon:
* there was no obvious way to do it. Closest thing was by reporting issue on product.
* there was no way to show the customer service agent a picture of the mail. Chat did not support sending pictures & they were unable to open imgur link.
* agent recommended me to leave a report it by leaving review to the seller page. I did that and next day review was deleted.
So it's pretty clear that Amazon didn't care and I doubt it has changed (unless the law you are talking about is recent one).
2 weeks ago it was $60 billion apparently. https://news.ycombinator.com/item?id=48553224
It might be higher now.
You are somewhat confusing two distinct concepts. IP addresses are considered to be personal data because they can be linked to single individual and controller is allowed to give this personal data to someone who can do the linking (e.g. police who can then request logs from ISP or NAT connection logs from the company).
Now it doesn't mean it will always link to single individual, but unless controller can be sure that there are always at least 2 people behind the IP and the devices on that side do not keep enough information to ever link IP+timestamp+destination service to single individual, the controller essentially must assume that IP address is personal data.
This is different from civil liabilities. National courts determine what is the threshold for that. For example in Finland the court has ruled that if the owner of the car cannot name the person who parked the then the presumption is that they did it and are responsible for parking contract breach (KKO 2026:24). National courts could end up with similar ruling for civil liability for sharing content, i.e. assumption that the IP owner either is the person who shared it or knows who they did it & if they refuse to name the person then presumption is that they did it.
nor are there any major EU software services and there never will be
SAP and Spotify come to my mind first. Some ex-EU services include Skype and Booking.com (latter might still be counted as EU service depending on definition).
Mostly yes.
Note the chance to object must be given before decision is made, i.e. not to give option for human review after the fact. Human must also be able to actually have meaningful chance to affect the decision.
If the decision is based on purely objective facts that are actually necessary (like you must have certain license) then human and computer always coming to same decision is likely correct and compliant, but as soon as you start putting in subjective criteria and human agrees with 100% of computer denials it becomes a lot harder to demonstrate that human is actually able to affect the decision as required by Article 5. Note that demonstration burden is on controller, not on data subject/DPA.
Objective criteria also isn't always enough by itself. If both human and computer calculate the same credit score and you must score X points to get a loan then human isn't actually able to affect the decision. Essentially the credit score calculation itself ends up being the automated decision rather than the formal rejection that is later given to data subject.
That's why I said consent usually cannot be used in employment context. I wouldn't rule it out 100% for everything employment related, but application screening is unlikely to qualify for those rare cases.
this is most likely highly illegal to use in the EU due to violating anti discrimination laws in multiple ways.
It's generally illegal under GDPR Article 22.
The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.
Exceptions in 22(2) are unlikely to apply. It's hard to argue that it's truly necessary (a) and consent (c) is almost always unavailable in employment context. (b) might apply, but it requires specific law in EU or Member State to authorize it.
Finnish case happened after DVD-Jon. To my knowledge there also hasn't been any new cases which went other way (or any way) in Finland & law hasn't changed so it's technically still illegal. Of course it's up to prosecutor to determine if they want to actually go ahead with prosecution & it's also not a crime which gets discovered often so the risks are quite low, especially if you are just ripping DVDs for personal use.
In Finland DVD's CSS was ruled to be strong technical copy protection system (tehokas tekninen toimenpide). In that exact case a person had made a program which bypassed it and published it. He was found to be criminally liable though he didn't get any fine/prison time from what I remember.
In Finnish criminal law the threshold is "significant harm", but given that there were already multitude of ways to get around DVD copy protection the "significant harm" clearly isn't very high bar. Also both distribution the method and actually using the method are both criminalized.
Finnish Copyright Act does individual to bypass copy protection to view the content, but it notably does say that you are not allowed to copy the work.
Unfortunately I cannot find the exact page right now, but I found one of the appeal documents from from https://www.yumpu.com/fi/document/view/38482300/1-helsingin-.... It's probably under https://www.cs.helsinki.fi/u/nikki/, but it's no longer available and Internet Archive is currently giving 503 when trying to access the old pages.
Assuming you are in EU you could report them to local DPA. Objection (i.e. unsubscribing. Original automatic subscription may or or may not have been legal) to direct marketing is pretty much absolute due to GDPR Article 21(2), I'm not aware of any "workaround" companies have successfully managed to argue.
In the US you can report it to FTC for CAN-SPAM violations, but don't hold your breath on any enforcement.
Worth noting is that there was 2500 € capital requirement until 1st of July 2019 and it was reduced to 0 €.
Public limited liability company (Oyj) still has 80 000€ capital requirement.
Not 3 month period, but looking at e.g. capacity factor over 5 day period can be under 3% and even 10 day period can be under 5%. Capacity factor for whole year is around 30% (22TWh produced with 9433MW in 2025, rounded it up since some capacity came online during 2025). That's a lot of extra power or storage.
Near the arctic circle Wind fill the same niche.
What do you mean? Long periods of calm weather during cold temperatures is not unheard of in Finland and does cause issues at times due to amount of wind energy that has been built in recent times.
I would like to see that thread if possible just out of curiosity.
I looked a bit into EUDPR and the earlier 45/2001 regulation (EUDPR came in effect in December 2018 so a bit later than GDPR). EUDPR explicitly imports Article 5(3) of ePD (via Article 37) and thus whatever case law there is around it. The earlier regulation seems to do this more indirectly (references in recitals), but EDPS view from 2016 is that it effectively does import Article 5(3) as well.
Personally I haven't dealt with EU institutions so far. On general public sector side I did recently seek some clarifications from Finland's Ministry of Justice regarding one of their websites and their responses weren't exactly reassuring.
I asked for the GDPR Article 15(1) information regarding single visit (i.e. information about processing, not actual copies of data) and it took them almost 3 months to give official response. Even after that time they, for example, failed to identify if they are actually the controller or not for some of the processing (Cloudflare challenge). And their stance is that analytics (Matomo) does not need Article 6 legal basis at all, i.e. they seem to think that anonymization step itself is not processing.
Official EU website, generally speaking, are not bound by GDPR or ePD. Rather EU bodies are bound by EUDPR. I'm not well-versed on that specific thing, but EDPS and courts have previously found that EC has infringed EUDPR so it wouldn't be weird if their cookie banner was breaking the law as well.
It's called "pay-or-okay" and there hasn't been many decisions on it yet which has led noyb to sue German DPAs: https://noyb.eu/en/years-inactivity-pay-or-ok-cases-noyb-sue...
There is one case where DPA ruled in favor of the company, but it's currently being appealed: https://noyb.eu/en/pay-or-ok-der-spiegel-noyb-sues-hamburg-d...
Another one ruled against company and court agreed: https://noyb.eu/en/court-decides-pay-or-okay-derstandardat-i...
While we cannot be sure what Elkjøp exactly told him, the Norwegian DPA's findings included following:
* Published benefits: https://web.archive.org/web/20220613175535/https:/www.elkjop... (e.g. "Rabatt på en rekke av våre tjenester utført i varehus", i.e. something like "Discount on a number of our services performed in warehouses")
* Conditions to join, i.e. to receive the benefits (DPA's translation):
* You may be contacted electronically (e.g via SMS and e-mail), via phone and mail with personal offers and other relevant information
* Collect and analyse information about you and your customer relationship.
* Create a customer profile, in order to provide more relevant information and a better service.
* You have to be minimum 15 years old and you can choose to leave the customer club at any time.
So to get the discount you would need to consent to being contacted for "personal offers and other relevant information".
It's also worth noting that it's not the first time Swedish DPA has been criticized regarding GDPR complaint handling:
https://noyb.eu/en/gdpr-rights-sweden "GDPR Rights in Sweden: Court confirms that authority must investigate complaints. So far, the Swedish IMY has taken the view that users don’t have party rights in GDPR procedures."
https://noyb.eu/en/noyb-takes-swedish-dpa-court-refusing-pro... "IMY frequently just forwards a complaint to the company that illegally processes personal data - and then immediately closes the case without investigating." (no decision on this as far as I know. A bit surprising since it has been almost 2 years)