momentsmusicaux: (Default)

[personal profile] momentsmusicaux 2018-05-18 01:01 pm (UTC)(link)
Oh absolutely. I've been telling clients for years that they have no damn need to hoover all this data up, and they don't bloody listen to me!

The point I am taking issue with is just that it's no big deal to comply with this. It's not necessarily.

> As for technical debt, it's like any debt: some is fine, if it means you get what you need faster, and you can then pay it back at your leisure. It's if it becomes unmanageable that you have a problem.

Yeah, well most websites are built on bit of glue and string and fly on sheer blind hope and luck. I should know, I build them. GDPR doesn't expose this. This gets exposed any time there is any kind of major security issue, and we see that most sites just aren't keeping up to date (e.g. Panama papers, where the site that leaked them hadn't applied a security patch that had been released something like a year previously). But then that's not just websites -- all aspects of software are glue and string and luck. Look at all the things that were in trouble with the SSH bug that came to light about a year ago.