HN user

mehdim

583 karma

Founder at ALIAS, a decentralized data and identity platform. Previously founder of APIdays conferences and OAuth.io.

Posts50
Comments130
View on HN
bunnyandcloud.com 8d ago

Opensourcing Multiplayer AI in Discord

mehdim
2pts0
isthispii.com 3y ago

Show HN: Is This PII?

mehdim
2pts1
github.com 3y ago

Show HN: Making GDPR Machine-Readable

mehdim
2pts0
news.ycombinator.com 4y ago

Ask HN: Replacing the word “Cookie” by “Tracer/Tracker” in banners

mehdim
16pts5
apilandscape.apiscene.io 4y ago

Show HN: The Interactive API Industry Landscape

mehdim
1pts0
news.ycombinator.com 4y ago

Ask HN: What critical open source software you use that is not well maintained?

mehdim
3pts3
www.alias.dev 5y ago

Data portability, the forgotten right of GDPR

mehdim
312pts217
techcrunch.com 5y ago

Ford Foundation grants $1.3M toward making digital infrastructure more equitable

mehdim
2pts0
www.apiscene.io 6y ago

Democratizing data regulations with APIs and JWT tokens

mehdim
3pts0
news.ycombinator.com 7y ago

Ask HN: If you can get users'data from GAFAs for your startup, you'd ask what?

mehdim
1pts2
news.ycombinator.com 9y ago

Ask HN: An insurance to cover API changes?

mehdim
2pts1
news.ycombinator.com 9y ago

Ask HN: Does YC blog has an expired SSL certificate?

mehdim
1pts3
getmateria.com 9y ago

Materia v0.7 – Use back end components to build web and mobile application faster

mehdim
6pts1
github.com 9y ago

Materia v0.3 now supports MySQL – September release

mehdim
8pts3
getmateria.com 9y ago

Show HN: Materia – A modern dev environment to build mobile and web applications

mehdim
127pts43
medium.com 10y ago

We all owe something to the API evangelist

mehdim
2pts0
news.ycombinator.com 11y ago

Ask HN: Is really .CC the new .IO for Bitcoin companies?

mehdim
6pts2
connorleech.ghost.io 11y ago

Log in with Twitter from Client with Angular and OAuth.io

mehdim
1pts0
github.com 11y ago

Show HN: Unifying Identities of Users

mehdim
3pts0
medium.com 12y ago

5 ways an API is more than an API

mehdim
5pts0
fr.slideshare.net 12y ago

OAuth you said? [slides]

mehdim
6pts0
medium.com 12y ago

APIs are coming. Welcome in the B2B Sharing Economy

mehdim
3pts0
thyb.github.io 12y ago

Show HN: Contentify – A real-time, collaborative content manager over GitHub

mehdim
38pts9
techcrunch.com 13y ago

API economy : Speed and Automation

mehdim
4pts0
api500.com 13y ago

APIs are the new software patents

mehdim
2pts0
api500.com 13y ago

Why big companies didn't jump into open data but will open APIs

mehdim
3pts0
api500.com 13y ago

APIs are the new patents

mehdim
2pts0
news.ycombinator.com 13y ago

Ask HN : YCombinator or Techstars Boulder for hackers?

mehdim
3pts1
news.ycombinator.com 13y ago

Ask HN: Why I should attend to Google I/O?

mehdim
2pts3
api500.com 13y ago

Developers are the blood of API economy

mehdim
5pts0

In bullet points : - GDPR is a risk management policy about personal data protection more than a privacy regulation

- for any personal data (PII) all companies must declare the following :

  - purpose of the collection and the treatment of the specific data

  — legal base of the treatment (6 available, they are the field card in Magic the gathering, they define a context of what is possible to do)

  - data category (what type of data you are collecting i.e if you declare collecting delivery shipping information for a purpose, you limit yourself to data that correspond to that category )

  - data retention duration (how long you declare storing the data in production and then in archive)

  - list of recipients (all the 3rd party companies who will access the data)

  - security measures (what is the level of security for keeping that data safe from breaches)

  - some infos about the company, the data controller (who is responsible) etc…
So all companies must do a internal data mapping to know and declare where is the data and where it flows in production and write for every PII a ROPA (record of processing activity) You can find an open source specification UROPA here)

https://github.com/uropa-project/uropa

- consent is just one of the 6 legal bases to collect and treat data. The comment above that everything is possible with consent is wrong.

- below 250 employees you don’t need officially a DPO

We are building one such service and I agree (to name a few services doing GDPRaaS : soveren.io, ethyca.com, securiti.ai, datagrail.com, alias.dev) .this is so much needed as there is almost no legally valid answer on the whole comment section! I started to write an article on all the points above… should get back in 2 hours and post it here

I am a multiple meetup organizer and owner on meetup.com and I find it actually great that the meetup can stay alive if the organizer stop to pay. Your communities are not owned by you. Also, they don't give subscribers infos but just "an access" to send them email communication to the list, not the "list" with email list etc...

Either you don’t do business anymore with Eu users or any user on Eu territory (but how do you know there are not actually on Eu territory), either you try to automate it so you continue to “not care about it”

Nice. Do you plan to match it with marketing/sales budget per product line or Business unit? To be sure that the effort of "maintaining legacy" is equally measured versus over funded efforts on new features for growth?

Disclaimer : I am running a non profit in my country called "The Maintainers", this is why I look for products that can give more merit to code maintainers.

We have never been successful showing that internal maintainers of the legacy were the ones really paying the bills and delivering the current value of the company. Fame and payroll was mostly towards the cool engineers working on new tech not yet in production serving real customers. I hope Echoes helps giving merit to the one contributing to the economic value of the company

The link between "groups never admit failure" and "non-profit organizations are not sustainable by design" is a little bit too direct and non relevant.

Lots of non-profits make revenues, selling stuff with customers, they just don't pay dividends by design and re-invest everything. So what he says does not apply.

And again, even foundations are at least oriented to hear feedbacks from donators who are their "customers". So it does not apply here.

The only valid point is that yes, group never admit failure as a whole, but the post should have stopped after this

Co-author here of the research. The most simple and effective and rapid solution would be to impose API neutrality. As explained in the report, it would just obliges API providers to give back the same API access to users than they give to their partners. For instance, why I get less data from Facebook if I ask my personal data, than if I create an app and ask maximum app permission (all OAuth scopes)? API neutrality already works. For instance, Open banking in UK and PSD2 in Europe apply API neutrality. Any 3rd party can access to a bank API if they are granted by the user to do so. After 2 years, for instance, up to 20% of the UK online banking population beneficiated from it as "Banking data Portability via APIS" . 20% is huge. If FAMGAs and all other big companies data was accessible via "neutral APIs" to users, data portability would be "a thing"

Also, the fact that you don't know what to do with you data dump in JSON is a blocker. With APIs, integrations by 3rd parties are simpler and more user oriented.

Last point, with API neutrality, no need of maximizing "interoperablity" (even is is always useful and makes things simpler, we have seen that with DataTransferProject it does not work really as companies don't work with the same data model) Developers will do the matching work between the original app and the destination app, no worries, when incentive is here, middleware glue will come. The problem these days is that the source of data is useless, has no value, so no incentive. You can look at this study with GDPR Facebook data value for developers https://www.law.nyu.edu/centers/engelberg/pubs/2019-11-06-Da... The main question is : Why a Facebook GDPR Data dump/takeout has no value for developers where Facebook API has value for millions of applications developers and businesses? With API neutrality it will have maximum value for users (as it has already value for partners) and minimizing fatigue to implement portability (an API is lot more developer friendly than a JSON dump that you receive in 30 days via email and that the user need to upload somewhere)

author here. We divided the number of revenues and the marketcapitalization per regional revenues US user : $1294 market cap in average, EU user : $494 market cap in average, Asia $109, Rest of the world $80 It is explained in more detail in the report

I like how you try to growth hack the Growth Hacking Slack with referral viral engine to get in. Nice try.

I really love the execution. Neat, slick and they even had the luxury to be open about it in their blog. They attacked a simple-to-understand but real problem, on a niche, making something people wanted to have and not wanted to do. They built the right integrations...making money since the beginning, increasing revenue per user and overall revenue... They probably made lots of mistakes , but according to public information and taking the time to analyze it with some prospective, they did (almost) everything right. Following their traction and revenue, they must have sold for a good price as Atlassian really needs such products to renew their platform and they have the portfolio of customers Statuspage would have tried to acquire. Great story.

Personally I find that Cognito is a great name, which represent well the big picture and challenge ls of identity issues.on the web.

Disclosure : I am Founder of oauth.io to what Cognito is compare.

You can do both. I will take our example at OAuth.io, we have built an open source daemon for OAuth that solve a problem for developers and we made a startup to sell the service on top. Look what Docker is becoming. Being a startup and contributing to open source are not opposite.

Or you can see even Github that contribute to open source by making a startup to help everybody contribute on open source...

Or Twitter with Bootstrap etc....