frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Samsung's Processing-in-Memory (PIM)

https://chipsandcheese.com/p/hot-chips-2026-samsungs-processing
102•ingve•4h ago•29 comments

Europe's last regular standard-gauge steam passenger service

https://parowozowniawolsztyn.pl/?page_id=2141
47•GungulSurm•2d ago•15 comments

GUIs should be fully keyboard-driven

https://ckardaris.com/blog/2026/08/28/keyboard-driven-guis.html
819•ckardaris•19h ago•414 comments

Boot a Virtual iPhone via Apple's Virtualization.framework

https://github.com/Lakr233/vphone-cli
275•hentrep•11h ago•78 comments

Hunting Down a Go Runtime Bug on 32-Bit Embedded Systems

https://sigma-star.at/blog/2026/08/go-runtime-netpoll-bug/
22•birdculture•2d ago•2 comments

TurboKV: Insanely fast Rust key-value store

https://github.com/kingroryg/turbokv
106•rgbimbochamp•8h ago•39 comments

Htmx 4.0

https://four.htmx.org/announcements/2026-08-28-htmx-4.0.0-is-released
668•rmsaksida•21h ago•166 comments

U.S. sanctions against the A/I Collective

https://www.inventati.org/
609•exiguus•21h ago•593 comments

I accidentally turned LLM memory into program analysis

https://pwning.systems/posts/llm-memory-program-analysis/
161•matt_d•11h ago•35 comments

StemDeck, a free, open-source and local AI stem separator

https://github.com/stemdeckapp/stemdeck
105•thclpr•9h ago•22 comments

Just the rumour of a bug is enough to find an exploit these days

https://anil.recoil.org/notes/rumour-is-the-exploit
328•avsm•18h ago•113 comments

Inception-style curved map for turn-by-turn directions

https://www.orbify.eu/demo/
510•smoser•22h ago•174 comments

Does the Sumerian King List Align with Paleoclimate Events?

https://www.vectorian.be/articles/2026-06-07/sumerian-king-list-paleoclimate-alignment-explorer/
101•dev_l1x_be•11h ago•46 comments

Our decision on Cursor following its acquisition by SpaceX

https://openai.com/index/our-decision-on-cursor-following-its-acquisition-by-spacex/
540•meetpateltech•8h ago•293 comments

Autistici/inventati: Manifesto – who we are and what do we want (2002)

https://www.inventati.org/who/manifesto
64•wise_blood•3h ago•37 comments

Monzo Stand-In

https://monzo.com/blog/tolerating-full-cloud-outages-with-monzo-stand-in
86•coffeefuel•5d ago•23 comments

Queen Caroline turned King Arthur into an 18C royal PR strategy

https://theconversation.com/how-queen-caroline-turned-king-arthur-into-an-18th-century-royal-pr-s...
19•samizdis•4d ago•1 comments

Experiments with Plotter Art

https://sometimes.digital/posts/experiments-with-plotter-art/
55•surprisetalk•4d ago•2 comments

9th Circuit sides with states in Kalshi gambling fight

https://azmirror.com/2026/08/28/9th-circuit-sides-with-states-in-kalshi-gambling-fight-potentiall...
132•hungryhobbit•11h ago•109 comments

Kumander Linux – A Linux Distro with a Windows 7 Desktop

https://www.kumander.org/
57•linuxkernal•8h ago•30 comments

Box of 300 Love Letters Showed Up, What Whimsical WWII Soldier Who Wrote Them?

https://www.smithsonianmag.com/history/this-box-of-300-love-letters-showed-up-out-of-the-blue-who...
21•gmays•4d ago•6 comments

Time complexity of operations on Python's built-in types

https://docs.python.org/3.16/library/time-complexity.html
10•theanonymousone•3d ago•0 comments

Curvature Beziers: Improving on a timeless recipe

https://acko.net/blog/curvature-beziers/
122•leephillips•4d ago•14 comments

The Twelve-Factor App (2025)

https://12factor.net/
270•jxmorris12•1d ago•151 comments

EasyEffects can improve laptop speaker sound quality

https://www.osnews.com/story/145883/easyeffects-should-be-part-of-every-linux-distribution-and-de...
157•birdculture•19h ago•60 comments

GLM-5.3 is now open-weight

https://huggingface.co/zai-org/GLM-5.3
704•jeudesprits•19h ago•234 comments

Verschlimmbesserung: The Word Your Software Updates Need

https://geekyschmidt.com/post/2026-08-25-verschlimmbesserung/
141•speckx•20h ago•96 comments

Visual Analysis of Binary Files

https://binvis.io/#/
86•vismit2000•3d ago•22 comments

Autonomous Mathematical Discovery in an Open-World Multi-Agent Environment

https://arxiv.org/abs/2608.23691
108•stephenchung•17h ago•30 comments

You Know GDPR Is Good Based on Who Hates It

https://matduggan.com/you-know-gdpr-is-good-based-on-who-hates-it/
69•latexr•1h ago•74 comments
Open in hackernews

You Know GDPR Is Good Based on Who Hates It

https://matduggan.com/you-know-gdpr-is-good-based-on-who-hates-it/
67•latexr•1h ago

Comments

seydor•54m ago
Cookie banners are already obsolete in the age of AI. Who is wasting time defending it? People don't even care to hate GDPR these days, it's an anacrhonistic regulation from a different era that some EUrocrats like to boast about
bgarbiak•48m ago
The point of the article is not that banners are good; it’s that they would not be needed at all if websites didn’t share all the possible data about their users with hundreds of vendors.

Fun fact: the OP blog doesn’t display a GPDR banner.

whatsThisBtn4•21m ago
But did it do anything? I get fingerprinted anyway. I'm geolocated anyway.

I'm a "deny all cookies" if it's an option, but I won't waste time on "customize".

Reminds me of 9/11 security theater

dgellow•44m ago
> Who is wasting time defending it?

I do! It’s one of my favorite regulation ever. I find it very well researched and designed, in a world where it often feels we cannot change the status quo it’s really impressive that a community of countries as messy as the EU has been able to design, pass, and actually implemented such a complex and citizen-centered set of rules

IanCal•31m ago
Often complaints about it boil down to either not understanding what’s in it, or annoyances that would be solved if sites stopped doing all this shady stuff. “We value your data, our 1644 partners…” yeah you definitely have a value you assign to my data.
DarmokTanagra•54m ago
I hate the banners, and I am a major privacy advocate.

The web has gotten so much uglier as a result of GDPR.

intothemild•44m ago
The cookie banner isn't actually specified in gdpr, it was just how everyone else tried to build the solution to the problem at the last minute.

I remember thinking "ok once this hits an actual web spec, we should see this built into browsers, and sent as headers or something"

Nope

brainwad•40m ago
Browsers already had a way to consent to cookies, since the invention of cookies themselves. But the EU didn't consider that _real_ consent.
9dev•34m ago
Treating the browser's "disable cookies" feature as a way to reject consent is not real consent. That cripples many legitimate use cases outright; it's neither accessible nor understandable by normal users; it's a technical defence measure, not a way to consciously reject contractual consent.

In contrast, the GDPR demands that you properly ask for consent if you want to process somebody's personal information, inform them why that is necessary, and only process the data if they agree to the processing.

There is clearly a difference here, and IMHO the EU is quite correct here.

intothemild•29m ago
Correct.. the gdpr isn't the anti cookie law. It's the data privacy law.

If it wasn't cookies it would be something else.

larodi•47m ago
GDPR has one single goal - to allow aggregated presumably anonymous data markets. Period. Everything else surrounding it is diversion in a plain sight.
9dev•32m ago
Sure buddy. And it's all orchestrated by the Rothschilds, right?
ChrisSD•47m ago
Note that GDPR did not mandate the cookie banners we see everywhere today. Those are a form of malicious compliance. Their goal is not to conform to regulation but to undermine the regulation itself in the eyes of the public.
brainwad•42m ago
The cookie banners come from the earlier ePrivacy Directive, and while it was possible to comply by not storing cookies at all, if you want to store data on the user's browser you do need to get their consent, hence the cookie banner.
maccard•38m ago
They do come from the ePrivacy directive but;

> if you want to store data on the user's browser you do need to get their consent, hence the cookie banner.

No - you need consent for storing cookies that are not “strictly necessary”. I can implement an offline app that stores data in cookies without consent. The current usage of the banner is overly litigious US focused simplification combined with malicious compliance.

brainwad•37m ago
No cookie is strictly necessary, you can encode it all into request tokens in the URL, so this is a meaningless exception.
jampekka•29m ago
The law is not about cookies specifically, it's technology neutral. The law doesn't even include the word cookie anywhere.

https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A...

throw8484949ii•43m ago
US companies like Meta or Google __LOVE__ GDPR. It is quagmire of complicated rules, and small startups will get burried under this quick sand. Large corporations can maintain departments of lawyers, and navigate this legal minefield. Small fines are cost of doing business, bribe that goverment would not force monopolies to spkit!

Try to do marketing ad campaign as small eshop owner in EU!

Barrin92•38m ago
>US companies like Meta or Google __LOVE__ GDPR

If that were the case they'd have spend money on supporting GDPR rather than sending armies of lobbyists to Brussels in an attempt to prevent it, or attempting to turn the US president in an attack dog on their behalf.

This generic libertarian talking point "companies love regulations!" is routinely disproved by how companies behave. As the article points out, you know what is good by who hates it.

throw8484949ii•28m ago
Microsoft also hated windows piracy and "fought" against it, later they admitted it helped their business.

As for "libertarian talking point", it is survivor bios. There are very little tech compenies left in EU. Heavy regulation burden is one of the reasons.

All EU companies that could hate GSPR are gone, and their would be owners are just random people on internet.

scott_w•37m ago
As someone who worked on GDPR compliance just last year, in a company that is deeply affected by it, no, it’s not that complicated.
9dev•32m ago
jampekka•40m ago
GDPR itself is quite a good law. It's implementation and enforcement are not.

E.g. the nag problem would have been solved simply and effectively with something like do-not-track header (probably as OS setting, as apps are often even worse than websites with tracking). Also enforcement of obvious violations taking years and years, especially against large corporations, means it's just violated all the time.

EU also failed to give good interpretation guidelines early on, causing massive piles of overjealous lawyer CYA red tape and just silly stuff like removing names from apartment buzzers.

foldr•8m ago
The do-not-track header is a nice idea but could never have worked. The GDPR is based on the idea that you can only store certain data about users if you have their consent to do so. Bearing in mind that most users have no idea what a header is and no idea how to configure their browsers, a user simply not sending a particular header does not imply consent to store information beyond that which is absolutely necessary for use of the site.
scott_w•40m ago
As someone who, until recently, worked in a company heavily impacted by GDPR, it’s a good thing. It forced the mindset away from “just do whatever is easiest,” to considering how it affects where our customer’s data is stored.

Was it a PITA? Sometimes, yes.

Was it stressful having a conversation with Legal to determine whether we had a PII leak under the GDPR terms that would mean we had to reach out to customers? Definitely.

But you know what? That’s the cost of doing business. The outcome for EU citizens was that their data is in a better place than it otherwise would have been. And that’s a good thing.

Razengan•33m ago
Same as with Apple's In App Purchases and low-friction refund process, that scummy companies like Match.com (the parent of Tinder etc) loudly opposed.
roenxi•32m ago
Given the relatively recent European experience (Nazis and Communists, among others) there is a reasonable argument for data privacy even if it hampers economic growth. However...

> If the rules are so terrible, why did nobody choose market exit?

Because major players don't particularly mind such rules; the public doesn't care about their data all that much and everything will tick on as usual with some nag banners and compliance officers.

The problem is the major players aren't going to be European because it is no longer legal for EU companies to get started by doing what the US companies did to get started. There is a reason the EU is backseat driving US software companies - EU industrial policy killed off the EU ones in the crib (to be fair that wasn't the GDPR, the GDPR is just part of the same anti-growth regulatory pattern). They died so young we've never really even learned what their names would have been.

EDIT I'll point at companies like Uber. It looked pretty illegal for most of its early years, until it could afford enough lobbyists to legalise its business model. Never would have worked in the EU.

bryanrasmussen•14m ago
>The problem is the major players aren't going to be European because it is no longer legal for EU companies to get started by doing what the US companies did to get started

essentially finding ways around the law and its spirit to screw people over and degrade the quality of life for the citizens to one's own benefit. Your edit pointing to Uber never working is pretty much making the case here.

blfr•31m ago
Banner gets a lot of attention because of the never-ending annoyance it's causing. It's like being surprised that someone would care about something so small as a little rock in their shoe. Yeah, you care about these little things.

It is also definitely true that the regulations are largely written by people who do not understand the tech they're regulating and its potential. Again, not some weird controversial point.

With every next leak where my full name, PESEL (that's like SSN here in Poland), email, phone number become semi-public and... nothing happens, I am becoming more convinced that we are annoying ourselves for nothing. Just degrading our digital lives and generating tons of legal digital text no one reads for no benefit of anyone involved.

At the same time, the very people who pretend to defend my privacy, oppose Tor, Signal, anonymity online, and other tools that definitely benefit me.

ezst•13m ago
> It is also definitely true that the regulations are largely written by people who do not understand the tech

I kind of switched side on this after the silicon valley made it clear that they are in the king making business, and the kings they want are of the fascistic and not benevolent kind. Also, a big aspect of the "tech culture" (beyond the silicon valley itself) has been about focussing on what could be done rather than whether it should, and this "restraint" must come from "outside the tech bubble".

varispeed•11m ago
The purpose of GDPR was never data protection or privacy. It was designed to legitimise data trade and give corporations legal basis for selling and processing the data where before that it was a grey area. If you look at it through that lens, it will make sense.

Regulators are just a potemkin village thing to make it look like the law is serving ordinary person.

Semaphor•9m ago
sourcecodeplz•31m ago
there is a whole campaign online about hating on the EU & its regulations.
whatsThisBtn4•23m ago
I made a physical product and upon learning European regulations, I quickly decided I was going to spend 0 time designing it for Europe.

If I made millions, sure, pay someone to figure it out.

But I was not going to waste design time early on.

I can't imagine how much this affects small business in Europe.

foldr•14m ago
These are just general barriers to international trade, though. Small manufacturers in Europe may likewise decide not to design for US regulations.
leokennis•20m ago
Especially Gruber is getting really tiresome. Almost devolving into a “look at them there fruity Yuropeeans with their healthcare and holidays”-level of tech commentary about any minor roadbump big-US-tech encounters in the EU.
Sharlin•12m ago
There are many powerful actors in whose interests it is to spread FUD about the EU, and none of those entities have the average citizen’s best interests in mind.
unsupp0rted•3m ago
[delayed]
sajithdilshan•19m ago
I worked in a small startup in Berlin and I remember we used to have a person dedicated to handle GDPR stuff. She had to go to Berlin data authority periodically and report status. I was really surprised given how small the company was, why we needed a dedicated person to handle all the bureaucracy. Apparently it was the law.

Also with the new package law in EU. I believe all these laws are how EU creates employment for their citizens. With almost every law they introduce, another new position is created in private as well as government offices and in a slowly aging continent that’s a good way to keep people employed when there isn’t much of a prospect

em-bee•4m ago
except the package law as it stands is going to force many small businesses to close because they can't afford the cost.
bryanrasmussen•18m ago
I feel that this must be logical error related to ad hominem and fallacy of composition, instead of this is bad because bad people like it, this is good because bad people dislike it.

That said I am generally happy with GDPR.

nonethewiser•4m ago
It might have sounded clever but if you aren't concluding GDPR is good/bad based on what it is you are not reasonable.
marcle•17m ago
Tobacco control advocates sometimes referred to a "scream test": the more vigorously the industry opposed a measure, the more likely that the measure was effective.
nonethewiser•7m ago
Yeah but don't tobacco control advocates want to kill the tobacco industry? We don't want to kill the tech industry - surely the tech industry's pain is widely felt sometimes.
stephantul•14m ago
Cookie banners are made annoying on purpose. This has nothing to do with GDPR itself.

The entities forced to show them would rather not, and thus make it as annoying as possible for you. They then use this to weaken support for the GDPR.

Shame on the people making stuff like this.

varispeed•13m ago
GDPR is good for corporations because it legitimises data trade. Population trained to agree to cookies now also agree to data processing just to get the banner go away and corporations have legal basis to process and sell the data.

It is all working as intended.

The tell tale is bodies like ICO being powerless when it comes to enforcing it. You've been screwed by big corporation? ICO will shrug.

amriksohata•6m ago
If someone hates something doesnt mean that the other thing is good, thats a bizarre assumption. Im all for GDPR but has it helped stopped our data truly getting out? No just look at social media companies using subversive tactics.
DarmokTanagra•19m ago
Correct in principle, completely ineffectual and annoying in practice.
brainwad•9m ago
Most browsers in the 00s had a "always ask" option for cookies. Nobody used it, because it's as annoying as gdpr dialogs now are. But it existed.
gmerc•31m ago
It's a case of industry malicious compliance
sourcecodeplz•29m ago
i was thinking the same thing. it could be like an actual element of your page.
gruturo•37m ago
Shaka, when the walls fell.

I hate the banners and the ugliness too but they are designed precisely to do that, and adtech maneuvers to ensure the hate is directed at the wrong source - the lawmakers instead of the people doing all the spying.

GDPR 1.1 should address all that - no legitimate interest exclusion of any kind, ONE SINGLE CLICK to reject all, no witholding service at ANY degree unless consent is granted, a 3rd option (I offer to pay to not be tracked), and a mandatory disclaimer on the cookie banner saying in clear terms: "Tracking is spying. If we were not tracking you and invading your privacy, this banner would not be necessary at all". Maybe even revive the "do not track" header by mandating that websites react to it accordingly, obey it 100%, not even show a banner if the header already tells them what to do, and ask users if they want this set or not, without a default value which would give an excuse for complaint from the people spying on you.

DarmokTanagra•30m ago
I also read the post, and have handled multiple GPDR adjacent migrations in Asia.

The end result is still the same, even with GDPR 1.1, another interstitial barrier between the user and whatever site they are trying to reach imposed by a poorly planned attempt to protect user privacy while simultaneously enabling the predatory companies who violate said privacy to continue business as usual.

The cookie banner will remain on the vast majority of sites, and users will spam click past it as they have been trained to do.

Symbiote•23m ago
My employer's site has no banners, since we decided not to use any tracking.

We measure our success based on enquiries, orders and so on, not the number of hits to the website.

DarmokTanagra•17m ago
so you don't track your bounce rate or effectiveness of your advertising?
9dev•37m ago
It was always possible to ask the user for permission when you actually want to store something on their device, ie. go for an opt-in model.
andai•37m ago
So I've seen some companies do it in a way that's not a pain in the ass. I'm wondering if that's legal.

Because if it is, I also want to do it that way.

IanCal•34m ago
It is. It’s also often not necessary at all. You can’t do things with people’s data without either getting consent or basically having a good reason to. I like the ICO pages (uk regulator) for explaining a lot of things like this.

If I’m shipping an item to someone I don’t have to ask them if I can keep their address for long enough to send them the item. I do need their permission to use that data to send them marketing though, or sell it on. If you have to legally keep records for X years that’s fine.

Keep only what you need, for the time you need to keep it, in an appropriately secure way.

jampekka•27m ago
I don't understand why this was downvoted. It's informative and factual.
speedgoose•37m ago
No you don’t need a cookie banner or consent to store normal data in the user browser.

You do if you want to track your users. Very different thing.

jampekka•34m ago
The ePrivacy directive did/does not require the nag for "necessary cookies", i.e. most of the cookies that are serving the user's interests.
snackbroken•34m ago
You don't need explicit consent for functional cookies, e.g. a session cookie or to store what preferences the user has selected on your settings page. It is implicitly given by the user telling you to treat them a certain way. For that you just need a notice somewhere on the page that reads along the lines of "this website uses cookies". It can be an unobtrusive note in your footer.
amiga386•5m ago
The banner is not needed for the website to work, otherwise how would the "decline" button work? They can store cookies, otherwise how would they remember your choice? They can track a functional session just fine, full shopping cart and checkout if they want.

What they can't do, not without your opt-in consent, is track the fuck out of you. Non-functional tracking. Analytical tracking. Behavioural tracking. Tying that tracking to an identity. Selling the data about that identity's behaviour to advertisers, to data brokers, to whoever pays.

The banner gets in your face and loudly prefers you press "accept" because if you do -- $$$$ CA-CHING!!! $$$$ -- they now have your opt-in consent to sell visitor data.

petcat•35m ago
Even the EU's own government websites are polluted with the same cookie banners. Are they "maliciously compliant" with their own regulations? Are they trying to "undermine the regulation itself"?

https://european-union.europa.eu/

orwin•31m ago
Yes. Basically the shop they used to make their website are shit, with shit incentives.
maccard•34m ago
I’ve posted this before. I was working on a website where we used a single cookie for an auth token, and we logged absolutely _everything_ on the server side (we didn’t sell it FWIW). When it came to publishing the site, we went to legal for our parent company and filled in their form. One question was “do you use cookies”, to which we answered truthfully. That site has a cookie banner, and absolutely 0 mention of the piles of telemetry we gathered.

The ePrivacy directive is a waste of time, money, attention and resources and I wish we spent that effort on complying with GDPR instead which is much much better.

DarmokTanagra•27m ago
Everyone understands this, it doesn't matter.
I'm responsible for GDPR in a small European company that processes fairly sensitive data. It's not that complicated as people like you make it out to be - if you're willing to actually try to do the right thing.
throw8484949ii•22m ago
I am trying to run profitable business, not to "do the right think"! My shop had 5% profit margin and fimal net profit was bellow minimal salary! I do not have a money to hire "ethical compliance officer!"

GDPR is easy to implement once, but it is constantly changing every year. Keeping up with regulations is constant energy drain. And small mistakes are punished by heavy fines (thousands of EUR). If you compare fines Meta is getting by revenue, small business should get maybe 10 euro fine for violations (not thousands).

I disagree with several points, but you already made clear that you are right and I'm wrong, and so there's no point in debating anything. Must be nice to know everything
mft_•5m ago
Meta, but what’s the point of engaging in a discussion forum and writing a comment only to back out of actually discussing the points you disagree with?
nonethewiser•8m ago
You know GDPR is bad based on what it is