XSF Discussion - 2018-05-17


  1. Link Mauve

    jonasw, for you! https://shop.spreadshirt.com/imfreedom/

  2. Seve/SouL

    That's super cool

  3. edhelas

    so vintage tech t-shirts <3

  4. pep.

    For more motivation

  5. jonasw

    Link Mauve, I’ll take the ruffle shirt, thanks

  6. moparisthebest

    Wow is their logo mostly commas now?

  7. jonasw

    hah

  8. ta

    and a flying rat as mascott

  9. nyco

    Hey board, I am sorry, I am in a long meeting, I won't be able to join our weekly

  10. MattJ

    nyco, noted, thanks

  11. Guus

    o/

  12. Guus

    Martin's not here, I think?

  13. Guus

    ralphm?

  14. Guus

    I guess it's just you and me, MattJ

  15. Guus

    MattJ, is there anything you want to discuss, our shall we skip this week?

  16. Guus

    Is there anyone else that was waiting for a board meeting to bring something up?

  17. MattJ

    Here

  18. MattJ

    (sorry, was distracted a moment)

  19. MattJ

    I'm fine with skipping

  20. Guus

    okay - until the next time, then.

  21. Guus

    adieu

  22. Anu

    What is everyone else’s GDPR plan?

  23. MattJ

    Hide

  24. MattJ

    After burying all the data in the back yard

  25. mrdoctorwho

    I can't believe this thing got accepted

  26. Anu

    haha

  27. Zash

    Step 1: Don't be a company. Step 2: ??? Step 3: PROFI.. wait no

  28. Anu

    I’ve decide to just just block the EU

  29. Zash

    Thanks for encouraging our internal market.

  30. Anu

    The need for a data protection officer who is basically a lawyer killed it for me

  31. mrdoctorwho

    what if they use proxy and then sue you for storing their data?

  32. Anu

    Nah you can still get the source and compile it

  33. Anu

    im just not distributing it directly myself in the app store

  34. Zash

    This really shouldn't be an issue for client authors. Except mobile push cloud notifications...

  35. Anu

    Yup push

  36. Anu

    and crash logging

  37. Anu

    But regardless the burden is on you to prove you are compliant to regulators

  38. Anu

    thus the DPO

  39. mrdoctorwho

    it's the first time I'm happy I don't live in the EU

  40. Anu

    i spend a lot of time in europe

  41. Holger

    Well I don't think there's a requirement to have a DPO for a push service.

  42. Anu

    I believe there is, yes. You are processing data and the token can be combined with other info to uniquely identify a user so it is PII

  43. Anu

    also you need to set up a register and document data processing and retention policies etc

  44. MattJ

    mrdoctorwho, depends on your perspective. As a user, isn't GDPR great?

  45. Anu

    For me personally I felt it was safest to just let people compile it it they want it and block EU users from push

  46. daniel

    MattJ: depends. Time will tell if those ad tracking firms will go out of business

  47. Anu

    They won’t because they can afford to meet the letter of the law

  48. daniel

    Thus far I haven't experienced any differences from a user's perspective

  49. daniel

    Anu: it's complicated

  50. Anu

    If you have the money and development resources, its totally doable

  51. daniel

    They'd have to ask for consent

  52. daniel

    And that essentially breaks their business model

  53. Anu

    the two biggest advertisers are google and facebook

  54. Anu

    Both will be fine

  55. daniel

    Only if you are a costumer of them. And consented to them tracking you

  56. daniel

    But yes those companies will have fewer issues than the traditional ad companies

  57. jonasw

    daniel, actually, I’ve seen quite a few spamy things which asked for consent

  58. Holger

    Anu: http://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&from=EN#d1e3732-1-1

  59. daniel

    jonasw: sure they can try. But I don't think a lot of people will klick yes

  60. Holger

    Anu: I would've thought neither (a) nor (b) nor (c) applies.

  61. Anu

    funny thing, ive works with mobile advertisers they were already doing things that were illegal the US. I dont think a eu law change with modify that

  62. jonasw

    daniel, exactly

  63. Link Mauve

    Anu, we’re preparing to attack both Google and Facebook (and a few other ones), see https://gafam.laquadrature.net/ (use a translator if you don’t read French).

  64. SamWhited

    I'm loving it from a users perspective, all the companies that can't be bothered to even try to protect user data or that were selling it and don't want to admit it are shutting down or putting up notices about how itm'

  65. Anu

    I spend time in France, im familiar with gafam (a term ive never seen used outside btw)

  66. SamWhited

    …it's no 'onger available in the EU

  67. SamWhited

    *sigh* stupid phone keyboard.

  68. Ge0rG

    Anu: is https://monal.im/blog/gdpr-removing-monal-from-the-eu/ your plan?

  69. Anu

    yup

  70. Ge0rG

    That's... unfortunate.

  71. Anu

    At least until things clear up, id rather not get in trouble while in europe

  72. Ge0rG

    I was just going to recomment Monal to my iOSy family members.

  73. Anu

    sorry :(

  74. Anu

    I dont know what chat secure will do, ive asked chris

  75. Anu

    Hes going to have to deal with the same issues

  76. Ge0rG

    Everybody is going to.

  77. Anu

    yup

  78. mrdoctorwho

    MattJ: yes and no, I mainly agree with daniel

  79. Anu

    He might have more resources than me since I think he’s funded by something

  80. Ge0rG

    We should add that to our next GDPR meeting. pep., winfried: Cloud-Notify / Push servers are sufficiently on-topic

  81. Ge0rG

    Anu: I'm not convinced he has a regular project funding

  82. Anu

    ah

  83. Ge0rG

    Anu: ChatSecure development has slowed down in the last year or so, from what I can see.

  84. Ge0rG

    on iOS. And I'm not sure anything at all is happening on Android. They wanted to migrate to the Conversations code base.

  85. daniel

    i either used to or still has. i'm not really sure. i think it ran out at the end of last year

  86. Anu

    What sucks about GDPR is I am prepping the next monal version with OMEMO and push

  87. daniel

    he either used to or still has. i'm not really sure. i think it ran out at the end of last year

  88. Anu

    both on iOS and mac

  89. Anu

    Mac will have the binary on the website outside of the App Store so people could just grab it there and there isn’t a push requirement

  90. Anu

    Hah I should put text there asking EU users to not download it like in the old days where you could download the US version of netscape with better encryption or the international one

  91. Ge0rG

    Anu: is there a specific reason for you pulling out, or just lack of time to ensure overall compliance?

  92. Anu

    lack of financial means to ensure compliance on a regular basis.

  93. Anu

    Its hard to do with a non commercial, free app

  94. Anu

    GDPR is designed for institutions that can afford it. I dont know how everyone else will deal with it

  95. Ge0rG

    Somehow we will.

  96. Ge0rG

    BigCorps are paying millions to consultants to ensure compliance.

  97. Anu

    Yes, I do it as my day job

  98. moparisthebest

    Anu, yea if you don't target EU citizens you don't need to comply with the GDPR so I'd just do that 'EU users must not download this'

  99. Anu

    well no

  100. Anu

    Its anything that MAY be used by a EU natural person

  101. moparisthebest

    no it's not, looking for link...

  102. moparisthebest

    https://ec.europa.eu/info/law/law-topic/data-protection/reform/rules-business-and-organisations/application-regulation/who-does-data-protection-law-apply_en

  103. moparisthebest

    Provided your company doesn't specifically target its services at individuals in the EU, it is not subject to the rules of the GDPR.

  104. Anu

    i think we are in agreement on that part, thats why im removing it from EU app store

  105. Ge0rG

    Anu: will it also be auto-uninstalled from EU iPhones? :P

  106. Anu

    Nah since people can also just side load it if they want it

  107. Ge0rG

    I thought you need XCode and what not to sideload an ipa

  108. Anu

    there are a few ways to do it. Most of my users are enterprise users

  109. Anu

    They can deal with it

  110. Anu

    @Ge0rG, how do you plan on handling GDPR with yax.im?

  111. Ge0rG

    Anu: I'll extend the data processing policy according to what we figure out in the XSF GDPR meetings, and will hope nobody sues me.

  112. Anu

    GDPR comes into effect next week, going down to the wire :)

  113. Ge0rG

    Yeah.

  114. Anu

    Do we know if federation is legal anymore

  115. Zash

    Email isn't going to go away.

  116. Ge0rG

    Anu: we don't *know* anything. We only make informed speculations

  117. jonasw

    s/informed/uninformed/

  118. Ge0rG

    jonasw: only speaking for yourself

  119. jonasw

    also, this creates a loop leading to unununununununununinformed

  120. jonasw

    (and more)

  121. Anu

    Haha

  122. Ge0rG

    while (regex.matches()) do { regex.apply() }

  123. Ge0rG

    infinite loop of jonasw

  124. pep.

    > Ge0rG> We should add that to our next GDPR meeting. pep., winfried: Cloud-Notify / Push servers are sufficiently on-topic Gotcha

  125. Anu

    i would say xep-0080 and anything else that deals with lat/long

  126. Ge0rG

    Anu: I don't see how that's principally different from user content

  127. Anu

    true