• 2 Posts
  • 7 Comments
Joined 1Y ago
cake
Cake day: Jul 30, 2023

help-circle
rss

Why this ensures the account is deleted, I wanted to convince the company to improve their policy so that other people will have an easier time to delete their accounts, should they wish this. That is also why I wasn’t talking “legal” and mentioned the company benefits from this.


It’s easy to say “Del my account per Article 17 GDPR”. I wrote this whole template so that other might have an easier time than I do. I posted the template here so it inspires other privacy-aware individuals to do the same. If 1 website changes their account deletion policy because of it, it’s still a win.


GDPR Account deletion
Hello, I wrote a mail template which I send to websites that don't have an easy process of deleting an account. Maybe it helps you, maybe you will use it too for when you want to delete your unused accounts and maybe you can contribute to it. The better the message gets and the more websites offer an easy way to delete accounts, the safer we'll be online. ----------------------- If you can influence the deletion policy, please read on. Otherwise, please forward this to someone that can influence this process. It's better for the business to offer an easy way to delete an account. Ideally, it would be good to delete accounts which weren't active for more than say 5 years, with a mail notification beforehand. Why? Here are the main reasons: * There are higher operation and maintenance costs because you have unused accounts in your databases. * The services load slower, with a performance penalty, because each user-related query has to go through many unused users. * The people opinion of your services decreases, because you don't offer an easy way to delete accounts * People might change their mail to a throw-away address and leave the account open, thus producing more waste than necessary. * In case of a security breach, the amount of compromised data is higher than in case you regularly delete accounts, which might lead to financial penalties. * The information you get out of a database with active accounts is much more precious than the information from a stale database, or one with obsolete data. I hope this information helps and that you will change your policy of deleting accounts. Each website that does this, contributes to a better, safer ecosystem.
fedilink

Before I wrote this thread, I ran for a couple of minutes a browser from a docker container. I couldn’t browse any website because of the missing CompanyName CA certificate. So, I stopped because it was too freaky.


Thank you for sharing this info. It’s very convincing and well argumented.

I won’t try anything else and will use my personal device.


I tried opening a browser in a Docker container and but couldn’t browse any site except google because it didn’t recognize the CA authority.


Yeah, I’ll use my own device, log on to the guest network and start Wireguard on my laptop. Seems a fair choice both for the company and myself.


It’s good to know that they can’t bypass wireguard or Tor. I was a worried about that.

As others have suggests, I will probably use a separate device to check my mail. That seems the safest and fairest option both from the company and my perspective.


I work on a corporate laptop that has an infamous root CA certicate installed, which allows the company to intercept all my browser traffic and perform a MITM attack. Ideally, I'd like to use the company laptop to read my own mail, access my NAS in my time off. I fear that even if I configure containers on that laptop to run alpine + wireguard client + firefox, the traffic would still be decrypted. If so, could you explain how the wireguard handshake could be tampered with? What about Tor in a container? Would that work or is that pointless as well? Huge kudos if you also take the time to explain your answer. EDIT: A lot of you suggested I use a personal device for checking mails. I will do that. Thanks for your answers!
fedilink