Skip to content

Comment on Californians' data deletion requests, DROP, become enforceable Aug. 1

Comments

Why is there a time limit on deletion on this site?

Because someone commenting leads to others spending time and effort responding. Deleting the comment breaks the chain. Don't comment if you feel that it's something you might want to delete. Think of commenting as like sending an email, but you get a short window to delete in this place.

Do you believe the same about search results not being able to be deleted? I also assume this means you disagree with gdpr?

Do you not see the difference between a person volunteering to broadcast a post, vs a bird party scraping the web to index it for searching?

You believe volunteered information must stay on internet forever?

If you knew those were the conditions when you joined? Yes.

Ok. Luckily people who make the rules don’t have such ideas.

You might want to check again, the people who run this forum certainly do, and no aspect of any existing US or EU law does either. Remember your personal interpretations and feelings are just that, they aren't the law or the rules of the places you choose to participate in.

GDPR doesn't require that a participant on a discussion forum be able to erase their entire history. Article 17(3) covers this. It is reasonable for a user to ask that their posts be anonymized.

This comment [0] from dang might be relevant:

In case it's of interest, here's the standard language from emails I send people:
We try not to delete posts that got replies, because doing so would be unfair to the other commenters in the thread. What I've done so far is reassign it to a random user ID, so it's as if you'd used a throwaway account to post it and there's no link to your main account. Does that work?

[0]: https://news.ycombinator.com/item?id=40734348

And it’s utterly useless, because your username and all comments get THE SAME random user ID. So once someone identifies that ID as you, it does nothing.

When I asked dang to do better after me and my family got death threats online, dang told me “tough luck”

To this day thousands of my comments from my old username are on this site and trivially east to link to my real name. (Links to my website, etc)

dang told me “tough luck”

He (nor I) would never write that or anything like it. What we always say is that we aim to find a compromise between a user's wish for their entire history to be erased and the rest of the community's expectation that when they participate in discussion threads, those threads will persist unadulterated into the future.

We are always willing to redact PII and do other things to prevent people's real identities from being recognized from their HN activity. We help people with requests like this all the time.

Edit:

Now I can see the email in question, I can confirm that dang did not write “tough luck”. We were, and still are, happy to work with this user to redact material that reveals their identity or location from their old comments.

Dang said exactly that. What’s your email, I’ll forward it.

Changing my username to something random doesn’t help, because it’s trivial to find a comment or two that make it clear that random user ID is me, and then you can see all my comments.

There are two much better approaches.

1. Make every single comment of mine a new random user if so they’re all separate.

2. Make the user id of everyone who has ever asked for deletion ”deleted-user” so my comments are lost in the sea.

Either of those approaches would make it impossible to find all my old comments and know they all belong to the real me in the real world.

Please help. Death threats are not fun, especially when you have a 2 year old daughter. There is a 100+ page forum thread of people betting on when I (real name, real person) am going to die. Just saying that somewhat Doxxes me.

My email is the same as Dan's. hn@ycombinator.com. Yes you can forward it and I'll read it straight away.

We can't necessarily do the exact things you've asked, because it makes all the discussion threads you participated in incoherent. We can take reasonable steps to disassociate personally-identifying comments from others.

Please help. Death threats are not fun, especially when you have a 2 year old daughter. There is a 100+ page forum thread of people betting on when I (real name, real person) am going to die. Just saying that somewhat Doxxes me.

This sounds terrible, and of course we don't want anything like that for you. It's just not clear (and I still haven't received an email from you so I can't look into the details of the case) how the actions you're specifying that we need to take on HN will fix this issue on some other website. I don't know any details other than the limited information you're sharing here. I can't find any emails about this matter linked to the username you're commenting from here.

It seems like you should be able to do a middle ground that preserves the commenter identity in each individual thread, while destroying the links across different threads.

For example, reserve the usernames 'deleted-xxxx' where x is a number. Then when someone wants their history obliterated, loop over every thread they have commented in. For each thread, choose a random number deleted-xxxx and assign that username to every comment of theirs in that thread.

Thus comments in the thread remain linked with one another, other deleted users in the thread remain distinct, and comments in one thread aren't linkable to a user's comments in another thread (perhaps lamentable, but required for unlinking spilled personal info in the general case)

(I chose random numbers rather than incrementing so that one can't start making inferences about users based on deletion order)

It should just be randomly generated when the page loads. "Oh, this user has the 'dormant' flag set? Generate a uid on page load" so all their comments have consistency for that one viewer for that single page load. Then if you click that user to see all the posts by them, you get an empty set. (Have the search queries return nothing for dormant users.)

Both the null search and dynamic generation per pageload (or any other randomisation across accesses or sessions) would reveal which comments/posts have been anonymised. That might be a cue to an adversary to dig deeper.

That information might be possible to determine from a comprehensive archive of HN, but it would be much harder to obtain.

The ability to disown a specific set of content (I'm not sure HN permits this) would avoid that issue. The associated account would just have a limited history, not an empty one. That would be equivalent to an after-the-fact throwaway account, which is much less attention-grabbing.

HN will not do this.

The only thing they do is change your username on every comment you’ve ever made to something else. But they’re all the same , so you can still link all the comments to one identity, and if even one comment makes it clear it’s a real person, then they all are.

Requesting anything more results in them saying “oh yes, we respect users wishes, blah, blah” and no action.

The ability to disown a specific set of content

We are willing to do this.

Requesting anything more results in them saying “oh yes, we respect users wishes, blah, blah” and no action

We gladly work with users to redact any material that identifies a person or reveals their location, or that otherwise poses risk to their welfare.

As a third party observer, it feels like "work with" could still be hiding a lot of thorny differences in judgement over what constitutes material that should be removed. That's why I was outlining a broad-brush mechanical policy that would cover most of the cases (unlinking a user's contributions across different threads from each other).

The problem is that each case is different, and there's no one approach that would cover all of the cases. Indeed I can see that it doesn't actually address the concern in this case, now that I've been able to find out what the account is and investigate the issue.

More broadly, this is why it's extremely unfair to make public accusations the way this user has done in this thread. The way we handle these cases actually takes far more time and involves more effort and care than it would take to implement the approach being advocated here.

So then you should implement the approach being advocated here.

You said yourself it would take less effort, and the outcome is better.

Win, win.

My first BBS handle was my full real name, and I barely managed to purge myself from DejaNews before Google bought it, so I empathize. The modern internet has been a severe learning experience and, given how many replicas of HN exist, the cat is well out of the bag. Teach others to be more careful, as I do.

100%

In 2012 when I started commenting here I had no idea it would lead to death threats and I’d have a two year old daughter.

What kind of topics/comments did you make that got you death threats? Really want to make sure I stay away from such topics.

I don’t want to doxx myself.

There is a 100+ page forum thread of people betting on when I’m going to die. Redditors have commented in public “I wish he did die”, etc etc

I've gotten several death threats for saying, at one point, that Destiny 2 year 1 was enjoyable because it pivoted the game away from loot-box gambling and FOMO addiction-driven player hours.

No topic is truly safe from other sociopaths getting their jollies from writing anonymous hatemail. Yeah, sociopathy makes it difficult to feel something, I empathize — but that's no excuse for them abusing their people-toys. Imagine Sid as an adult on the Internet if he'd never been scared straight: it doesn't matter what topics you play with to a Sid, they're adaptable and will find ways to issue death threats for personal pleasure, on whatever topics they find in the sandbox.

https://www.youtube.com/watch?v=kjKuMCJqdW4

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.