Hacker Newsnew | past | comments | ask | show | jobs | submit | av501's commentslogin

It is a function of incentives and punishments. The nature of the company you are in and the risk the org is willing to bear plays out. I work for one that puts in a lot of effort to get rid of all the user data if they request a deletion based on the laws of the country they are from which we can expand to any user as needed. Whenever we have found gaps in our existing data storage, we go back and really try to clean it up. However there is a lot of legacy that surfaces out time to time.

   The reality is doing this is messy and is going to remain so for some time.  One cannot suddenly start after years of no incentives in the online economy to do this and get to cover all areas without huge cost. This requires giving up competitive advantage today. Mid to small organisations that were beyond startup state but not yet having 1000's of engineers, which have to balance growth and operational aspects are left in the most difficult situation. As the laws started taking hold, their incentive structure is still not fully aligned with this as the digital economy does not yet reward them for this enough nor does enforcement create a large enough risk yet.  Same thing plays out with some of the larger orgs, just that they have more lawyers to help them stall this as humans are always biased to keep the status quo if it is beneficial to them.

   Personally I think we've had a start but its going to take some time to get to where we need to be. I really applaud the idea of the privacy laws and the intent behind them. Its just that one has to recognise we won't be getting to a state of good behaviour within a few years after a couple of decades of not having those requirements baked in from the get go.  Old habits have to be replaced as well. The enforcement is hard and that will be something that has to be bubbled upwards from the ground up by users themselves to create a digital economy where consumers/users reward those that respect their privacy. It is just not yet that way today, so why would the organisations change? The risk is low as enforcement is hard and the user demand is not enough.

   Most successful would be attempts by large organisations such as Apple and laws like GDPR which forces developers and companies to change their thinking. By asking for change and continuing to iterate on that you can start seeing a slow move towards development practices that will have privacy by default. You need the whole chain of actors to move towards this: The product managers, the engineering leads and architects, the decision makers, the risk assessors. Once enforcement is more steady alongside more demand from users the balance will come. All of this moves slowly whether we like it or not.
(edit - grammar and made some long sentences shorted)


Yes, In India incoming calls are free (been like that for a very long time).


Nothing says GDPR is something that can't be improved upon. Better enforcement, refinement of laws, everything is possible. It has to begin somewhere and that beginning is rarely perfect. Every failure is also an opportunity to learn what to do better. As some other people have commented, the intent is right, the execution has to be improved. Edit: Fixed grammar and some words


The issue is the collateral damage. The EU doesn't have a thriving web/tech sector to begin with when compared to the US or China. These kinds of things likely make it worse.


I see this argument every so often but I'm wondering, what did we actually lose?

Nasty social media that makes their money on outrage and exposing people to scam ads? That's about the only thing I can think of, and I don't think it's a big loss. The legal environment of the EU might actually pave the way for better social media, if the market wasn't already monopolized by the current incumbents.

As a counter-argument, Europe and especially the UK has a thriving fintech scene that produces solutions light-years ahead of what's currently in the US, despite the stronger consumer protection laws that we have.


I see this argument every so often but I'm wondering, what did we actually lose?

As many of us pointed out two years ago: time and money.

The collateral damage aspect is all the businesses that weren't doing dodgy things in the first place but still had to spend that time and money, because documentation had to be rewritten according to new formats, and policies had to be expressed in terms of the new sets of acceptable X, Y and Z, and so on.

I was not happy back then to find that despite having run businesses that were scrupulously respectful of privacy and security, we still ended up wasting weeks just on figuring out what we had to change (spoiler: nothing of substance, it was all red tape) and for a small business that is a nasty blow.

If you assume, probably rather naively, that all small businesses here in the UK had a similar minimum cost to ours just to review everything and dot the i's and cross the t's to ensure compliance with the new letter of the law, that alone would represent a cost of billions of pounds for little if any benefit to anyone in many of those cases.

The fact that the typical response from many posters on HN was to dismiss that cost as being somehow necessary or justified, with no regard at all for the very direct effects it would have on many small, bootstrapped businesses, showed an astonishing lack of perspective. The number of people in various forums around that time who just straight-up accused me of lying about my businesses being privacy-conscious already, for no other reason than that I run tech businesses and they treated all tech businesses as the enemies of privacy, was also pretty disappointing. There was very little objectivity in the discussions then, the much-lauded benefits to individuals faced with privacy intrusions by certain big players have almost entirely failed to materialise, and the costs and legal ambiguities for everyone are still there two years later.


> I see this argument every so often but I'm wondering, what did we actually lose?

All the old comments on Raymond Chen's Old New Thing blog for example.


We didn't lose that much because I suspect big business in Europe is largely ignoring the more difficult parts of the GDPR. I work for a large bank that is totally non-compliant with GDPR and does not really even have a strategy for getting there. My impression is that we (the bank) looked at the draconian requirements of the bill, realized that, with the total mess that the IT of the bank is in, implementing GDPR would cost billions, and just sort of gave up. It looks like we wait for the regulators to fine us and hope that it won't be a nine figure fine.


Which parts are so difficult? Trying to find all the data about a user in the system?

I have some sympathy for an giant mash of databases like that.

I have no sympathy if someone claims that adding a tracking toggle to a single web site is too hard.


Normally it's hard enough to ensure that you have retained an authoritative copy of data, but now it's even harder to ensure that you have destroyed every incidental copy throughout the org on short notice. Then there's the bureaucratic "prior consultation" that will delay launches by months


Two major issues that I can remember offhand:

1. Deletion/rectification of all copies (that includes backups!) of personal data on demand. We currently are not sure where (in which systems) we store all that data, not to mention adding features to delete/update all data on request in each of those systems.

2. The requirement to complete description of all processes within the bank which touch personal data. That involves creating a fuckton of documentation, a lot of it for systems where required knowledge is missing (i.e. no one is quite sure how they actually work).


>Nasty social media that makes their money on outrage and exposing people to scam ads?

Last I checked Facebook and friends still exist.

>what did we actually lose?

* Many europeans lost access to various publishing sites (another win for the big guys)

* Collectively who knows how many millions went to lawyers to reverse engineer the vague GDPR standards


> Last I checked Facebook and friends still exist.

Last I checked there are studies that suggest the current social-media solutions have a negative effect on mental health, and those effects are likely because of the platforms' efforts to drive up "engagement" levels. Regarding the ads, I have first-hand experience of my non-technical friends falling for outright scams (requiring a chargeback), dubious snake-oil being advertised or malware on major online ad networks (not an issue anymore thanks to an ad blocker).

> Many europeans lost access to various publishing sites (another win for the big guys)

This doesn't seem to significantly impact me or anyone in my network. If this was a big problem we'd notice it and/or a EU-based, compliant competitor will step in to fill the void.

> Collectively who knows how many millions went to lawyers to reverse engineer the vague GDPR standards

Somewhat agreed but this seems to be a side-effect of companies trying to lawyer their way out of the law, and the reason this works is because of the lack of enforcement. If it was enforced it would be a clear message that these efforts don't work and should be stopped.


Somewhat agreed but this seems to be a side-effect of companies trying to lawyer their way out of the law

Not necessarily. One of the main criticisms of the GDPR was that it was vague and ambiguous on several very important points, and in theory deferred to more concrete guidance from the national regulators, which in turn was then either inconsistent or absent in some of the most important areas anyway.

The GDPR penalty regime was also heavily stacked against smaller businesses: for a large business, the costs are capped at the 4% level, but for any business earning less than half a billion each year, the absolute cap takes precedence and means that a regulator can literally threaten the very existence of any business earning less than probably 100M.

In that environment, you need proper legal advice on interpretation and possibly, as absurd as it seems, just to show that you have made a serious, good faith attempt at compliance, as a preemptive defence if a regulator does subsequently take a different view to yours.


My entire point of my facebook comment is that GDPR gave us nothing, and people paid by losing news site and lawyer salaries.

I don't care if you aren't personally affected by this. That isn't the argument you should be trying to make. How did GDPR improve your life? AFAICT Facebook may still have your shadow profile


> How did GDPR improve your life?

People are more aware of privacy violations and even though companies don't fully comply with the regulation, many are at least trying.

I've personally had success in getting multiple EU-based businesses to delete my data and/or fix issues with their marketing infrastructure sending me spam despite not opting into it.

Facebook still has a shadow profile for me but between Facebook having it or Facebook plus a hundred more bad actors having it too I'd still prefer if it was only Facebook.


>This doesn't seem to significantly impact me or anyone in my network. If this was a big problem we'd notice it and/or a EU-based, compliant competitor will step in to fill the void.

Access to fewer news sites is access to fewer news. The new site isn't going to replace the old. Also, we're not getting replacements for them in the EU because the business model for these sites doesn't work with GDPR. Making their life financially more difficult just pushes them more into clickbait and yellow journalism.


> Making their life financially more difficult just pushes them more into clickbait and yellow journalism.

Clickbait is explicitly caused by advertising - it's right there in the name, it's there to drive clicks, the content itself is secondary.

If advertising becomes unsustainable then other business models will take over. At the moment subscribing to news websites is too expensive because 1) we don't have an easy to use micropayment system and 2) they are greedy and charge way more than what they would get in ad revenue.


I've also seen a ton of people complain about it on this website alone [0, 1].

[0]: https://hn.algolia.com/?dateEnd=1590782149&dateRange=custom&...

[1]: https://hn.algolia.com/?dateEnd=1590782149&dateRange=custom&...


  Ever since i have had a kid, I have started asking the reverse question; Is my career dragging my parenting down?
I always wanted be a good dad, whatever that means to each one of us, my career choices started showing up in conflict. I had to make choices. Overall, over the past few years having a kid really made me think about my priorities. It made me focus and plan more and improved my ability to do more in less time. The first few years are hard and you will not be able to give as much time to your career if you want to spend that time with your child and spouse in constructive ways. Which is fine because the career is 40 yrs long. My conclusion is that I chose to have kids and now I will work on maintaining that relationship because at end of the day you can change jobs, go to a place that recognises people have lives, do something else in your life apart from your current career (you never know), but your kid is your kid and not someone else's and the early years will not come back again. As for my experience with my manager - As long as i get the work done, my place of work doesn't care about being seated in office. With Work From Home now taking off there are plans of making this semi permanent even if things go back to normal. Edit: formatting


Thank you. I definitely try to strike a balance. As the primary earner, I feel there is a lot of pressure on me to deliver. It is definitely a difficult balancing act to balance being there for my family and providing for them. I look forward to this being only a few difficult years like you said.


The principle of non-violent communication (NVC)[1] completely changed my approach in life to stressful situations. Practicing the same with my family, friends, work colleagues changed my life. Changed the way I approach situations. Allowed me to also apply it in reverse where I am now able to lead those stressed with me towards a NVC path. I am trying to understand their fundamental base need rather than just focus on what they are saying. This allows those around me also to become in tune with themselves and I can see it on their faces when they get the aha moment. I've received simple thanks sometimes for this so I know it is not just me that finds it useful. Works wonderfully well with toddlers as well! The whole premise that kids are stupid or don't understand stuff also gets upturned when you apply NVC to communicate with them or help understand their point of view.

It wasn't easy, took months before it became habit, just had to keep it going. Even now sometimes I forget and my lizard brain pops up from years of conditioning that will take some time to undo. But am I so happy I found out about it.

[1] https://baynvc.org/key-assumptions-and-intentions-of-nvc/


My guess is that they test it in chambers with lowered air pressure and composition to match 100k feet?


Just because you are small does not mean not doing the right thing is something you should get away with. I see lot of comments of how doing the right thing can be a burden. However, I see it the other way. Not doing the right thing is a burden you have to carry with you everyday. GDPR is helping you with guidelines on how to shed that burden. I do not know how and won't imagine it is easy, but I wish something in our existing socio-economic systems would slowly edge towards making 'doing the right thing' a significant variable that everyone has to care about for their own wellbeing and prosperity.


Having interviewed 100+ candidates in past 2 years for my own startup and a similar number before in my previous job, I completely understand what the author is trying to say. Believe me when I say that 90% of my interviews simply stop at the first question (Can you write a function in C which given an integer array and its size as arguments, returns the number of zeros in an array?). My interview then turns in a small career counselling session telling them to learn and how learning to learn is important because it breaks my heart to see the young ones come out with no ability. Most of them though dejected at not clearing the interview thank me and tell me in the past 4 years that they were getting their degree nobody told them what I did. Shows really that there is nobody guiding them out there and the mindset is wrong.


Software can have jobs where the work involved is "crank the handle, produce output", but the majority of them do indeed require the ability to solve problems.

I interviewed one candidate several years ago, and the question was: "How do you ensure that your program works as intended?". Hoping to get answers like "I write unit tests, integration tests, test scaffolds" or even "I exercise it with different inputs", what I got was "I use Visual Studio". After rephrasing my question a couple of times and getting more or less the same answer each time, I came to the conclusion that the candidate felt that Visual Studio doesn't allow you to write bugs.

Crank the handle, produce output.


I actually blame the people who hire such idiots. Their lack of knowledge is not the problem. Their lack of curiosity is. Their lack of self-motivation is.

Even for "crank the handle, produce output" type of jobs, it's a bad strategy to hire idiots since they will not be doing such jobs for the rest of their lives. Projects change. clients change. Technology changes, and only people with at least a minimal amount of adaptability wlll thrive.

And to answer your generic interview question: By running it. If you probe further, things like unit test coverage, integration test coverage, debugging, seed data etc can come into the picture but that depends on your specific question.


Right - the question is pretty open ended, with lots of potential areas to explore after getting a basic answer.

As a potential employer, I'm happy to help them learn, but I'm not going to spoon-feed them. If someone is profoundly incurious, maybe they'd be better off working somewhere else. Or in another career field.


Right-o.

Good to go with open ended questions. It's hard for candidates to memorize answers.

Sadly i see lots of these kinds of idiotic strategies on their part :-)

When i started my first company in 95 or thereabouts, i remember a person who just would not open his mouth during the entire interview. I didn't know what to make of him. I then asked my receptionist to talk to him, find out if i was being too rough or intimidating etc.

Turns out that the interviewee did not trust his own command over english enough to answer back.

Once i learned that, i just handed him a free PC, told him to try writing whatever program he wanted in the next few hours and did not set any time limits.

When i came back after lunch, i saw that he had written a complete game ( This was in the DOS days where writing a game was really difficult since there were no high-level game engines around )

The guy eventually turned out to be one of my best programmer.


Are you really programming in C? If so, good for you and your organization. If not, i suggest not wasting time becoming a career counselor and try finding a faster way to eliminate idiots.

I don't buy the crap that they have not been taught in collage. In the age of the internet, there are so many damn resources on every language possible on the internet that a person claiming that they know how to code in c should have a much, much higher bar set.


That was presumptuous on your part. First I shall talk about C. 2 reasons. 1.Any engineering graduate in India should know C. It is the first language they learn and use in curriculum. 2. We work in embedded and kernel domain. Welcome to a world where C is important.

Also it is not about deep understanding of pointers and stuff like that. The sad part is that most of them can't even write it in pseudo code.

As for the question of you not buying it, I can't convince you except that there are other commenters in this thread who have pointed out the same problem. This problem does exist.


>>Any engineering graduate in India should know C.

A big assumption.

When I finished my engineering, I was pretty good with assembly language programming. I could do anything with 8085 and 8086.

It took a good deal of time to learn ALP, and I'm glad I did it before learning C as I got all necessary low level details correct and complete.

But I agree your point on pseudo code.


Wow. Dude, you really need to learn how to parse english.

1) When i said, "i don't buy that..." i was referring to people blaming the collage or university for their own lack of knowledge.

In today's world where the internet is available to everyone with a net connection, i would expect people to use some initiative, go online, search for C sources or tutorials, download free compilers and linkers, learn them thoroughly etc. ie The real blame for their lack of knowledge is with them not with their collages.

2) Why would you claim, on the one hand, that the blame for kids is with their collages and poor teaching, and then claim that i expect everyone to know c cause that's the first thing they learn in engineering?

And, lastly, don't get huffy with me, dude. If you make generalizations like "Any engineering grad in India should know C" good for you. I don't care. I really don't give a damn.


You have serious anger issues all over the thread. Calm down a bit.


Really.

I guess you are entitled to your own imagination.


Your aggression and quips do nothing but reveal your insecurity and obviously degrade a rather sensible thread into a showdown of your ego. Kindly refrain.


Passive aggressively imagining things and projecting it on others is going to get you nowhere.

If you have something useful or even your own opinion to contribute, do so. I see that you have nothing to contribute except with your imagination


I'm in the process of converting my team of 50ish programmers in Chennai into a DevOps and "legacy apps support" org because finding people with the necessary current skills is proving too difficult. And by "current" I'm talking basic stuff like javascript competency, an understanding of what MVC is (versus dragging toolbox controls onto a webform and writing a couple lines of databinding), and the impossibility of hiring people who have programming experience in anything besides .Net (and to a lesser extent, Java, but even Java is hard to recruit for) and SQL Server or Oracle. My "low cost" (which, as a result of demand and globalization, has turned into "US light" rather than "developing world") country of choice now is Mexico, and -- judging from the recent recruiting challenges there -- I'm not alone. In the Guadalajara area, HCL, Tata, Infosys, HP, Dell, Oracle, and a raft of others are all gobbling up freshers who really can code themselves out of a box, who have good communication skills with at least passable English, who are able and interested in learning new skills, and generally speaking have much more in common culturally with the US.

I am certain there are both bright spots and bright futures ahead for the Indian IT economy (and education system), but for now I'm either putting my creative work in other countries or hiring [much higher cost] consultancies to augment the local skills in my captive team there. The cycle mentioned by other commenters here and in the blog post of finding employment solely for the sake of certification or learning a new skill to support jumping to a new employer is a huge turn off for two reasons: 1) a lot of the incoming freshers literally have zero skills and it's a huge time sink for the experienced folks to get them to the point where they can contribute, and 2) by the time someone is contributing they're already either looking for a new job or expecting promotions and salary hikes in the 20-50% per annum range. This is untenable and quite ridiculous, even with the recent inflation/currency issues. My company, like many others, have a different job code/title scale for India than everywhere else in the world, just to support the concept of having a dozen steps in between fresher (literally zero skills) and senior engineer/architect... not to mention similar things on the management side.

I could write a book on this crap and, frankly, I'm already feeling riled up just thinking about it so I'll stop here. I'll just leave it at this: I truly hope the Indian education system and cultural issues surrounding employment, family, corruption, and financial stability are worked out in the coming years, but the stress dealing with this mess through the past ten years has put me off enough to abandon ship. The cost savings is just not worth the productivity hit (not to mention subjective issues like time difference).


As a person who started one of chennai's first product development org. in the mid 90's, let me add my two cents here:

1) Hire people for their interest in programming, their core problem solving ability and the fun they have with the process.

There are lots of such people, just learn to look beyond what everyone else does. For instance, i once hired a person who could not speak much english, and who did a BA or something like that. He, later on, turned out to be one of the stars of the organization writing a core part of a VoIP solution.

2) Invest in long-term training. By that, i mean don't hire some crappy institute to come and train your people. Here from experienced folks in other organizations to come in over the weeke-end or other timings to help your team.

I remember having to train almost every member of my team in assembly, c, win16 and later on win32 among others. Some of my team members then went on to train professors in IIT, chennai. :-)

3) Mentor your team members. Show interest in them beyond what they can deliver today. Build good relationships with them and help them, both technically and otherwise. When they see you sincerely reaching out to them, they will do the same.

4) Be patient with people. If they know zilch, be frank with them and let them know that they are currently not contributing anything to the organization. However also lay out a plan for them, along with HR, to bring them up to speed in core areas; viz problem-solving, algorithm design, data structures etc Don't allow them to waste time on fancy courses from idiotic institutes. Make your senior programmers take classes some of the time. That's also part of their job.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: