What does it mean to make your 1 pagers and technical documents "float around" in your case?
HN user
j_san
Hey, another overengineer! :D
My solution was to just highlight the last anchor if the user scrolled to the very bottom. Although this might skip the second last heading if its too close to the bottom.
See here: https://sharezone.net/privacy-policy (most visible on desktop, on mobile you have to open the "Inhaltsverzeichnis" at the bottom)
Is there a way to make it loop? (So that one only needs to record e.g. 20 seconds, after which it loops to save space)
I don't think that far-left was primarily only written because of the tax returns. I followed some links in the article and came to this twitter thread which might explain where that notion comes from: https://x.com/lukerosiak/status/1885523747425399247
(Disclaimer: I don't live in the US and don't want to take any political stance with this)
Biased against the approach of your former coworker and thus the "Clean Code" way? I assume it did not work out well, because you needed to move fast to build an MVP before trying to do it right?
Is there a plan to make it self-hostable?
The text in the "Choose your membership" column at https://fund.krita.org/ is broken for me, it's not visible.
Do you have any links where one can read about the removal of DIDs?
For me the Android mobile app is sometimes skipping songs or not switching to the next one when swiping or tapping the next icon. Often recognizing another device as playing doesn't work. If it recognizes it then editing the song queue doesn't work more often than not (especially removing songs from the queue). I hate it. It is so bad, I'd be ashamed having so many users, so much money but such an bad app.
flox.dev/terms leads to a 404
Thanks for your answer, I appreciate it.
Although strictly speaking if they would only want to do AdES and not QES, they wouldn't have to be in the EU Trusted List, would they?
Is this targeted for the US market or also the EU? Does this qualify as a an advanced electronic signature (AdES) under the eIDAS regulation?
Can some EU citizen please make a complaint to a DPA (Data Protection Authority)? It's gathering so much stuff, I don't think that this would hold up to scrutiny.
Is it open-source by any chance? I would be very interested to see all the logic that is necessary to handle all the different jurisdictions. Sounds complicated!:)
I'm european and dont like thousands of satelites swirrling around in the sky as well but I'd rather have government-founded satelites for the public benefit than from some way-too-rich sociopath's private company.
Of course - this project would probably not exist without Starlink, so credit where credit is due.
Personally I find it quite sad that we're destroying the night sky in the sense that before these projects people could look in the sky and know that all humans before them had more or less the same sight. Now there are just so many satellites swirling around in your sight. I find that quite sad.
Under GDPR they'll still have to comply.
If they have a data protection officer then send him an email. Else if you're in the EU get the Data Protection Authority (DPA) of your country in the loop.
I don't think this is true, many news sites either offer the option to accept cookies and show ads or offer a subscription without ads and tracking cookies.
This has been ruled as being valid by courts.
I just wrote them an email:)
The privacy policy is not compliant from what I see. I still love the mission but it just leaves a bad taste in my mouth - if one makes privacy a marketing point then at least the privacy policy should be compliant.
One example missing in the privacy policy is information regarding "the existence of the right to request from the controller access to and rectification or erasure of personal data or restriction of processing concerning the data subject or to object to processing as well as the right to data portability;" There is more stuff that should be included, see: https://gdpr-info.eu/art-13-gdpr/.
(Technically it doesn't have to be in the privacy policy document but could be provided in some other kind of document. I guess thats not done though.)
Some more information about this case and overall context: https://verfassungsblog.de/travelling-courts-and-strategic-v...
I very opposed to the proposal of the commission - in fact I even went to a demonstration today against it. It's a horrible privacy invasion and very bad in many different ways, but...
But I think your take is not true. I can imagine that it might just be a really misinformed proposal to actually go against child abuse. I hope.
Depending on how it's implemented it could still use the same mechanism, couldn't it? (genuine question)
For me the question is if this is a webauthn thing in general or a security key thing (to include the domain in the challenge to prevent phishing)
But isn't the "thing" about FIDO (or maybe just security keys?) that the domain is also integrated into the challenge the client/key has to solve?
So from what I understand a attacker couldn't as easily fish me by pretending e.g. to be Google. With a password or even a TOTP code the attacker could just pose as Google and forward the credentials to the actual site.
As they were a US company, many of the "violations" that they picked up just weren't considered problematic for a UK / EU audience.
Just out of curiosity: could you provide some examples?
You know thats the funny thing - actually this would be pretty close on how one could do it right now. Nobody actually forces sites to show a big cookie banner, they choose to do it. The user could have a small button on the side to open a dialog and to activate more cookies than just the necessary ones if one really wants to (I think).
It's of course not how you describe it on a technical level but from a UX standpoint.
I don't know if this is in the category that you're asking for but right now there is tons of experimentation with "Content centric networking" e.g. "Named data networking" to better optimise how we load content inside the web. Instead of using an IP to connect to some server of e.g. Google to get content we just say what data we want and load it from where ever (with better prospects of caching).
Props for the GDPR compliant Cookie decline button! :)
I don't think the imprint is really hindering.
Not using SASS services (e.g. Firebase) just really sucks though.
We still use it (started with it before privacy shield was demolished) but we will have to migrate eventually. Don't know what we'll use exactly, maybe managed kubernetes with some platform for an easier workflow running on it? Idk yet.
Nah also just the principle of data minimisation - if there is no good reason to save it (this long) then it shouldn't be saved. A DPA would probably have Google pay for that if it would come that far.
The Norwegian Data Protection Authority imposed a fine of €6,500,000 on Grindr for not collecting users' valid consent for sharing data with third parties for profiling and advertising purposes from the Grindr App.
Particularly interesting is that it is not allowed under GDPR to have a free version of an app with the condition that it shares personal data (in this case for targeting and profiling for ads) as the consent of the user is not freely given in this case - in a "Take it or leave it" situation, consent cannot be seen as freely given.
Link to the section "Consent as a condition to access the service ": https://gdprhub.eu/index.php?title=Datatilsynet_(Norway)_-_2...