‹ BackHN Continuity

Thread

ChatGPT now knows what you do on other websites via ad collector

764 points · 395 comments · lmbbuchodi

  1. thih9 · · focus · HN ↗
    I am once again happy that the EU is fighting practices like these via legislation.

    Some outcomes can be annoying, but the net result is still positive, for the consumers and their data privacy at least.

    1. surcap526 · · focus · HN ↗

      [dead]

    2. Joel_Mckay · · focus · HN ↗
      Unfortunately, most LLM companies always were naturally an intelligence operation on civilians, and determining if they are now state-backed seems like a irrelevant detail.

      Privacy has been dead for some time now. The fact is most business people never figure out how they are exploited. The modern intelligence campaigns just made it economical to hit almost everyone regardless of scale... often under some silly pretense like terrorists wanting our underpants. =3

    3. bko · · focus · HN ↗

      [dead]

      1. [deleted] · · focus · HN ↗

        [deleted]

      2. Avicebron · · focus · HN ↗
        > The outcome is that very little serious technology or influential companies come out of Europe. And salaries for things like engineer are about a third of that in the US.

        So your argument is abusive practices are required for the creation of influential companies, serious technology, and high paying salaries?

        1. bko · · focus · HN ↗
          No but overly burdensome regulatory bodies that are concerned about such things like how the top of my bottle cap functions and how low i set my ac temp leads to an incredibly hostile business environment and stagnant culture.

          But like I said, nice place to visit for the time being.

          1. imawakegnxoxo · · focus · HN ↗
            Beats companies and governments being openly hostile towards the people

            You know, the thing that actually makes a country/society

            Putting the needs of business over the needs of the people those businesses are actually supposed to serve is how you end up with America

          2. sailingparrot · · focus · HN ↗
            > nice place to visit for the time being.

            Yes, because it’s a place where culture matters and where trying to change everything as fast as possible for unknown reason and handing out unlimited power to corps to e.g. level half the country to build DCs is not seen as a good outcome. The specific mindset you complain about is what makes those place nice.

            1. bko · · focus · HN ↗

              [dead]

          3. mitxela · · focus · HN ↗
            You don't think all industrial countries have stuff like that? Do you really think the European economy is stifled by bottle caps being attached to their bottles by default? Even if it bothers you, it's a really weak attachment, you can just pull it off.
          4. c-hendricks · · focus · HN ↗
            > overly burdensome regulatory bodies that are concerned about such things like ... how low i set my ac temp leads to an incredibly hostile business environment and stagnant culture

            Like the US of A?

            Also various stars have introduced more bottle cap regulations. One such state is a hotbed for inflated software developer salaries.

          5. blauditore · · focus · HN ↗
            The obsession with ACs in some places (or rather people I guess) is something I will never sympathize with. Just wear reasonable clothes for the weather, no need to cool down below 20° C. And yes, I'm going to die on that hill.
            1. DavidSJ · · focus · HN ↗
              Sometimes the temperature is much higher than 20° C, and it is very hard to be comfortable or do productive work.
              1. the_gipsy · · focus · HN ↗
                I never set my AC to lower than 25°C. Why would you need below 20°C? Is it something about having only a single unit for the hole house/office, where it's then uncomfortably freezing in one area, just to have a normal temperature in the distant areas? Crazy.
                1. antonkochubey · · focus · HN ↗
                  > Why would you need below 20°C?

                  For example because I literally can’t sleep well above 20°C.

                2. DavidSJ · · focus · HN ↗
                  Why would you need below 20°C?

                  I don't, and I don't think the "obsession with AC" is from people who do, it's just people who want a tolerable indoor environment in the summer.

              2. blauditore · · focus · HN ↗
                That's true, although having 19° inside when it's 30° outside is bad for several reasons. My office (in Europe) gets cooled down in summer to like 23°, and that's already inconvenient when wearing appropriate summer clothes. And no one is expected to wear formal clothing.
            2. LoganDark · · focus · HN ↗
              Not everyone can tolerate 20C, you know. I know people who freeze at anything below like 25C, but I myself have trouble not sweating my ass off above like 18C. I don't wear additional clothes in winter (though maybe that's simply because winter here hasn't actually reached below freezing in years).
            3. bko · · focus · HN ↗
              175k ppl die each year in Europe due to heat death. But I guess if you ignore that being slightly warm is not a big deal
            4. encom · · focus · HN ↗
              What a shitty hill to die on.

              I don't know if this is a genetic thing, but as a scandinavian who wears shorts down to like 12C, I am unable to function in >30C humid weather. Anything more labour intensive than drinking sangria on ice is not getting done. This year we had up to 37C in Denmark. If you're able to tolerate heat well, I'm happy for you, but my sleep was ruined for months this summer. Not to mention the people who literally died.

              I'm investigating my options for at least cooling down the bedroom at night, because I'm not going through this nonsense again. Plastic straws are banned now and we're sorting garbage in 42 different bins, so I'm thinking that about evens it out, environmentally.

              1. 6510 · · focus · HN ↗
                I see the heat pump hype shaking my head thinking how people long ago use to build with mud and made walls 2-3 meter thick. It takes the entire winter/summer for the climate to get in.

                The Amish hang wet bed sheets in front of the window (with a tob under it to recycle the water) not sure how well this works in the Netherlands with 95-99% humidity, it certainly wont raise humidity but evaporation might be shit.

                Not every bathroom is fit for it but if there is no AC and things become unbearable I put the shower head upside down so that the ceiling and walls get wet and it rains everywhere. Then I daisy chain fans to "tunnel" the air into the bathroom. The temperature drops like a rock.

            5. johnnyanmac · · focus · HN ↗
              We're talking about mid 30's to low 40's here. I can only get so naked.

              But I don't tend to keep my AC below 24 personally. I don't need my room to be perfect room temper2

          6. [deleted] · · focus · HN ↗

            [deleted]

          7. croes · · focus · HN ↗
            > overly burdensome regulatory bodies that are concerned about such things like how the top of my bottle cap functions

            Better than a government that fears the word gay

            > and how low i set my ac temp leads to an incredibly hostile business environment and stagnant culture.

            You are quite a cherrypicker, aren’t you?

            How about the regulation to have USB-C as a standard or replaceable batteries.

            Or one of my favorites, the ban of ingredients that cause cancer.

            BTW ever heard of Frauenhofer IIS or ASML?

          8. [deleted] · · focus · HN ↗

            [deleted]

        2. throw10920 · · focus · HN ↗
          > So your argument is abusive practices are required for the creation of influential companies, serious technology, and high paying salaries?

          They never said anything remotely like that in their comment. Please engage in good faith, don't lie and pretend that others said things they didn't, and don't break the guidelines.

      3. [deleted] · · focus · HN ↗

        [deleted]

      4. josmar · · focus · HN ↗
        If it's any consolation, all other non-California regions in the world lack the privacy protections enjoyed in Switzerland and the EU, but they still don't produce many unicorn startups nor have fantastic salaries for coders.
      5. phatskat · · focus · HN ↗
        > The outcome is that very little serious technology or influential companies come out of Europe. And salaries for things like engineer are about a third of that in the US.

        Sure, but plenty of companies want to operate within the EU. While I feel any legislation will only affect their operations within the EU, having the infrastructure to operate under privacy laws there means it'll be easier if/when other jurisdictions follow suit

      6. thih9 · · focus · HN ↗
        > But I'm happy EU does this stuff as well, as it's a really nice vacation spot

        With no Flock cameras!

    4. altern8 · · focus · HN ↗
      I don't know if the destruction of many industries in the EU--including manufacturing--can be called an annoyance.

      All the EU bureaucrats can do is regulate, that's why it's so difficult to do business in the EU and that's why there is so little innovation over here. If Microsoft and Apple were started in the EU they would've been shut down within a week because you can't operate from a garage.

      I guess that every once in a while this might have a positive outcome for consumers, a broken clock is right twice a day.

      1. schubidubiduba · · focus · HN ↗
        I'm sure Microsoft and Apple could have been able to afford a cheap office given their parents' generous financing.

        And, regarding the original topic, we wouldn't have many of these privacy issues if the US had not strategically failed to regulate its obnoxious tech monopolies

      2. goobatrooba · · focus · HN ↗
        I don't see how that's relevant? Regulation might have limited some innovation in tech, but gdpr does not affect any of the dying industries. That's more from competition with china, companies with too much interest in giving payouts to shareholders than to innovate, and US financial industry buying most of the best players
        1. techpression · · focus · HN ↗
          GDPR is being changed to allow tracking and AI training without consent, EU only protects people if it’s the interest of EU companies, GDPR is now too costly so it has to be dismantled in certain areas.

          <a href="https:&#x2F;&#x2F;www.computerworld.com&#x2F;article&#x2F;4087347&#x2F;european-commission-moves-to-loosen-gdpr-for-ai-and-cookie-tracking.html" rel="nofollow">https:&#x2F;&#x2F;www.computerworld.com&#x2F;article&#x2F;4087347&#x2F;european-commi...

      3. [deleted] · · focus · HN ↗

        [deleted]

      4. tene80i · · focus · HN ↗
        What do you think US bureaucrats do other than regulate? The federal government drives people crazy. Have you ever tried to file taxes in the USA? It’s so complex you end up having to pay for the privilege.

        The innovation gap is real but it’s not just to do with regulation. It’s a lot to do with concentrated capital networks (eg Silicon Valley). And sure, the tech giants are in the USA but it’s not like there’s no innovation in the EU. Spotify in Sweden. Challenger banks in the U.K. (included as Monzo predates Brexit). And plenty of innovation - they just get bought by US companies. Which is a financial market weakness, not a regulatory one.

    5. fooker · · focus · HN ↗
      &gt; Some outcomes can be annoying

      I&#x27;d classify mandatory encryption backdoors as an industry crisis rather than an annoyance.

      1. dspillett · · focus · HN ↗
        Which has nothing to do with the stalking of the adtech industry, unless you are suggesting that the EU might sell access to the keys to the likes of OpenAI?

        [though you are not wrong that encryption backdoors are a backwards step on individuals rights to privacy]

        1. Llamamoe · · focus · HN ↗
          Encryption backdoors by definition mean everybody who wants it gets hands on your data. You can&#x27;t make backdoors only the &quot;good guys&quot; can access.

          And while, sure, adtech corpos maybe won&#x27;t due to the bad PR, what about the Kremlin, criminal organizations, or your insane abusive ex?

          1. Barbing · · focus · HN ↗
            Rather tragic that less-technical folks in positions of power can find this:

            &gt; You can&#x27;t make backdoors only the &quot;good guys&quot; can access.

            incomprehensible. I’m sure genuinely so, even.

            1. Avicebron · · focus · HN ↗
              &quot;It is difficult to get a man to understand something when his salary depends upon his not understanding it.&quot; -Upton Sinclair
          2. phatfish · · focus · HN ↗
            What can the Kremlin do that is worse than the tech bros? Leverage data to deliver people additive divisive content until it all boils over into the &quot;real world&quot; and splits society? Oh wait...
            1. bergkvist · · focus · HN ↗
              Or deciding where to send a drone attack to take out a political opponent
            2. StilesCrisis · · focus · HN ↗
              Pretty sure the Kremlin just murders folks that they have a problem with.
          3. djtango · · focus · HN ↗
            I care a lot less about the KGB knowing the ins and outs of my body than my health insurer...
        2. bko · · focus · HN ↗
          It kind of does. It&#x27;s like &quot;I want an all powerful regulatory agency that can impose rules by dictat, but I only want them to do this things I agree with&quot;
          1. pona-a · · focus · HN ↗
            That&#x27;s just what a government is. The idea is you elect it democratically and bind it with a constitution.
      2. patrickmcnamara · · focus · HN ↗
        When has the EU mandated encryption backdoors?
        1. buzer · · focus · HN ↗
          They keep trying it via e.g. chat control
          1. tensor · · focus · HN ↗
            The US has also tried it multiple times. So has Canada. It&#x27;s been shut down each time. This isn&#x27;t a unique to the EU problem.
            1. bayindirh · · focus · HN ↗
              Didn&#x27;t UK had &quot;The Snooper&#x27;s Charter&quot; as well?

              Encryption backdoors is not a case of extending reach for a government, but an effort to get the capabilities back.

              They were able to do that before. They just want to be able to continue now.

              Note: No, I don&#x27;t support the idea of backdoors. On the contrary.

            2. RHSeeger · · focus · HN ↗
              The fact that other countries have tried to do &lt;bad thing&gt; does not mean it&#x27;s acceptable for another country to do &lt;bad thing&gt;
              1. anigbrowl · · focus · HN ↗
                So why is the criticism about it disproportionately leveled at one jurisdiction?
                1. fooker · · focus · HN ↗
                  I am not sure if you replied in good faith, but here you go.

                  The reason is that they have been trying again and again to do this in various forms, slightly modifying tactics so any opposition to it has to start from scratch.

                  2015 - <a href="https:&#x2F;&#x2F;techcrunch.com&#x2F;2015&#x2F;10&#x2F;29&#x2F;encryption-rhetoric-untangled&#x2F;" rel="nofollow">https:&#x2F;&#x2F;techcrunch.com&#x2F;2015&#x2F;10&#x2F;29&#x2F;encryption-rhetoric-untang...

                  2016 - <a href="https:&#x2F;&#x2F;techcrunch.com&#x2F;2016&#x2F;08&#x2F;24&#x2F;encryption-under-fire-in-europe-as-france-and-germany-call-for-decrypt-law&#x2F;" rel="nofollow">https:&#x2F;&#x2F;techcrunch.com&#x2F;2016&#x2F;08&#x2F;24&#x2F;encryption-under-fire-in-e...

                  2017 - <a href="https:&#x2F;&#x2F;www.theguardian.com&#x2F;technology&#x2F;2017&#x2F;jun&#x2F;19&#x2F;eu-outlaw-backdoors-new-data-privacy-proposals-uk-government-encrypted-communications-whatsapp" rel="nofollow">https:&#x2F;&#x2F;www.theguardian.com&#x2F;technology&#x2F;2017&#x2F;jun&#x2F;19&#x2F;eu-outlaw...

                  2020 - <a href="https:&#x2F;&#x2F;www.consilium.europa.eu&#x2F;en&#x2F;press&#x2F;press-releases&#x2F;2020&#x2F;12&#x2F;14&#x2F;encryption-council-adopts-resolution-on-security-through-encryption-and-security-despite-encryption&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.consilium.europa.eu&#x2F;en&#x2F;press&#x2F;press-releases&#x2F;2020...

                  2021 - <a href="https:&#x2F;&#x2F;www.consilium.europa.eu&#x2F;en&#x2F;press&#x2F;press-releases&#x2F;2021&#x2F;04&#x2F;29&#x2F;combating-child-abuse-online-informal-deal-with-european-parliament-on-temporary-rules&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.consilium.europa.eu&#x2F;en&#x2F;press&#x2F;press-releases&#x2F;2021...

                  2023 - <a href="https:&#x2F;&#x2F;www.wired.com&#x2F;story&#x2F;europe-break-encryption-leaked-document-csa-law&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.wired.com&#x2F;story&#x2F;europe-break-encryption-leaked-d...

                  2025 - <a href="https:&#x2F;&#x2F;www.techspot.com&#x2F;news&#x2F;107408-europe-proposes-backdoors-encrypted-platforms-under-new-security.html" rel="nofollow">https:&#x2F;&#x2F;www.techspot.com&#x2F;news&#x2F;107408-europe-proposes-backdoo...

                  2026 - <a href="https:&#x2F;&#x2F;www.euronews.com&#x2F;next&#x2F;2026&#x2F;07&#x2F;10&#x2F;chat-control-10-passed-the-european-parliament-through-the-back-door" rel="nofollow">https:&#x2F;&#x2F;www.euronews.com&#x2F;next&#x2F;2026&#x2F;07&#x2F;10&#x2F;chat-control-10-pas...

                  1. anigbrowl · · focus · HN ↗
                    Isn&#x27;t that simply how politics works, though? People who are invested in security keep lobbying for their interests. Generally when political actors fail they dust themselves off and try again, on any issue. Also you haven&#x27;t shown how the EU is diffrent from any other jurisdiction in this regard.
            3. leonidasrup · · focus · HN ↗
              In the end, US doesn&#x27;t need encryption backdoors because most chat and email protocols are not end-to-end encrypted and the TLS data streams are decrypted in the datacenter owned by US companies.
              1. xorcist · · focus · HN ↗
                The protocols themselves are not important anymore. It&#x27;s all variants of http to Google or Amazon. What&#x27;s important is control of the end user device, and Google and Apple keep a remote root connection with &quot;their&quot; terminals at all time. Any data that is obtained remotely will be from the presentation layer, not the network layer. This is also harder to US adversaries to access, so an argument could be made that for the majority of normal people this is a net increase in security.

                If you wanted to make the corresponsing strong argument for Chat Control and its ilk, the EU just wants (the juicy part of) what the US already has. The remote root level control of most end user devices is not under EU juristiction. So they naturally want companies operating in the EU to give them one piece of access to the presentation layer, too.

                This argument is what one must be prepared for, the encryption itself is less relevant..

          2. [deleted] · · focus · HN ↗

            [deleted]

          3. fooker · · focus · HN ↗
            Exactly right.

            Chat control is merely their newest attempt at this, carefully navigating around the reasons it was opposed last year.

            They keep trying to legislate encryption backdoors by any means, and once they manage to get their foot into the door every other country will use that as a precedent to also mandate it.

    6. jampekka · · focus · HN ↗
      &gt; I am once again happy that the EU is fighting practices like these via legislation.

      As long as you manage to navigate all the dark patterns and not accidentally give your &quot;informed consent&quot;.

      1. dspillett · · focus · HN ↗
        Malicious compliance (or as it more usually is malicious noncompliance that has not been sufficiently punished so the slimy buggers feel free to continue) is something you should blame the stalkers of adtech for, more than the EU. The legislators could perhaps have made the definitions less wavy, and been harder with enforcement, but that doesn&#x27;t make it all their fault.
        1. jampekka · · focus · HN ↗
          These problems were quite widely foreseen during the legislative process, and partly had already been exhibited by the earlier ePrivacy directive. I don&#x27;t know whether it matters who&#x27;s to blame, but my trust in EU being very effective in these fights in the future either is not very high.
    7. soulofmischief · · focus · HN ↗
      Are you equally happy that the EU is attempting to mandate backdoors into technological platforms and outlaw private encrypted communication?
      1. dspillett · · focus · HN ↗
        Copypasting my reply to someone who made almost exactly the same point in a sibling comment earlier:

        Which has nothing to do with the stalking of the adtech industry, unless you are suggesting that the EU might sell access to the keys to the likes of OpenAI [though you are not wrong that encryption backdoors are a backwards step on individuals rights to privacy]

        Things could be worse. It could be like most of the US where there are both no (or at least far fewer) protections against invasive behaviour of private companies and the government actively trying to backdoor private comms.

        1. einpoklum · · focus · HN ↗
          &gt; Which has nothing to do with the stalking of the adtech industry

          It has a lot to do with the practices of the adtech industry. If privacy is protected and upheld vis-a-vis the government (or meta-government in case of the EU), it may be upheld vis-a-vis private corporations and other governments. But if the government likes to be able to spy on its citizens, it will not foster mechanisms, practices and a culture of private communications.

          But - I agree that it could be much worse.

        2. soulofmischief · · focus · HN ↗
          Sorry, you said &quot;Some outcomes can be annoying, but the net result is still positive, for the consumers and their data privacy at least,&quot; which warrants both of the replies you received given the massive, unacceptable breach in privacy which Chat Control and similar laws exercise. This is not a &quot;backwards step&quot;, this is throwing out the entire concept of privacy and replacing it with a shapeshifting doppelganger that can morph depending on the target.

          &gt; Things could be worse. It could be like most of the US

          Yep, it could definitely be worse, but your response ignored the obvious intention behind my question. Saying, &quot;but the US is bad, too&quot; doesn&#x27;t make your prior take of EU law being a net good for privacy any less uninformed.

    8. slig · · focus · HN ↗
      And the sane world is fighting the EU BS with geo blocking.

      Just set up your user agent to work as you wish, isn&#x27;t that simpler than have unelected, technologic dumb bureaucrats writing laws that are complex and don&#x27;t solve the issue?

      1. anigbrowl · · focus · HN ↗
        How is that going to prevent OpenAI snooping on you via adtech? Inquiring minds want to know.
        1. slig · · focus · HN ↗
          By blocking every request to their servers?
          1. anigbrowl · · focus · HN ↗
            I don&#x27;t see how, perhaps explain what you eman instead of handwaving.
    9. einpoklum · · focus · HN ↗
      Is it now? Are Alphabet, Microsoft, Yahoo and Meta&#x27;s platforms and call-home products illegal for exposure to EU residents? i.e. Google, Bing, Facebook, WhatsApp, MS Office and such? Are these companies&#x27; C-suite people wanted, to be charged massive breaches of user privacy?
      1. ljm · · focus · HN ↗
        Seeing some legitimate executive accountability would be lovely in this day and age, but even fines going into the billions of euros are still just the cost of doing business in a ridiculously lucrative space. That they also happen to dominate by oligopoly.
    10. dmix · · focus · HN ↗
      The adtech&#x2F;data broker business is still very lively in EU. The last time I read into it a year or two ago the consensus seemed to be the privacy gains over the last decade have been modest at best. There was a few big name trackers that were forced to narrow data collection but the general ad&#x2F;location tracking and data broker business is still mostly the same.

      <a href="https:&#x2F;&#x2F;arxiv.org&#x2F;abs&#x2F;2411.06862" rel="nofollow">https:&#x2F;&#x2F;arxiv.org&#x2F;abs&#x2F;2411.06862

      <a href="https:&#x2F;&#x2F;netzpolitik.org&#x2F;2025&#x2F;databroker-files-targeting-the-eu&#x2F;" rel="nofollow">https:&#x2F;&#x2F;netzpolitik.org&#x2F;2025&#x2F;databroker-files-targeting-the-...

      1. buzer · · focus · HN ↗
        There are multiple reasons for it. One of the major issues is that some DPAs pretty refuse to enforce GDPR (e.g. DPC in Ireland). Hopefully the changes to cross-border enforcement that are coming in force next year will help with this as it at least has some deadlines unlike currently.

        Another issue is that controllers generally do not need to change their behavior before the final lawful decision which can take a lot of time to go through the court system, especially if it needs CJEU referral. And once the decision comes in force they can often make small changes and restart the whole process.

        Also another issue is that DPAs do not often initiate the investigations themselves (unless breach is involved), they only happen at the request of data subjects and not that many people bother making complaints or follow them up. Just yesterday I had to follow up with 9 page reply to the controller&#x27;s response to the DPA inquiry.

        Additionally ePD and GDPR enforcement is sometimes split between different agencies. In those cases GDPR agency tends to wait for ePD case to be solved before investigating the GDPR aspects, often because the ePD consent validity will affects e.g. GDPR legal basis analysis.

      2. thih9 · · focus · HN ↗
        Perhaps, perhaps not. Big trackers reducing data collection is a win in my book. OpenAI is not doing ad personalization for the EU customers. There are no Flock cameras.

        It’s an ongoing fight for sure but it’s some fight at least.

      3. singularity2001 · · focus · HN ↗
        Do the big guys sell to the small guys? Like if I&#x27;m a shady small company trying to buy as much information as I can about a certain user, will I freely get the data from X and Facebook and Google?
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.