Montana Standard newspaper plans to retroactively unmask anonymous commenters
washingtonpost.com
washingtonpost.com
"We will not share individual user information with third parties unless the user has specifically approved the release of that information. "
Further, they have even explicitly stated that they cannot retroactively change the privacy policy to affect old comments:
"Of course, our use of information gathered while the current policy is in effect will always be consistent with the current policy, even if we change that policy later."
Given that, I don't see how this isn't a violation of their privacy policy. The FTC suggests that they are willing to enforce companies that mis-use personal information [1]. Given all of this, I highly encourage anyone who has posted anonymously on the MT Standard to report them to the FTC using the following form: https://www.ftccomplaintassistant.gov/Company#crnt
[1] https://www.ftc.gov/news-events/media-resources/protecting-c...
Is there actually any possible CMS where this problem cannot be solved in one line of code? It's either a terrible excuse/lie or one of those examples of why I'm so happy not to be working at a large organisation wrangling ancient legacy systems.
I remember one programmer that worked for a fairly popular newspaper telling me it was "simply impossible" to change the color of their navbar. They were on wordpress.
The news business doesn't think about their CMS that much; it's just a box for them to type into most of the time.
It's really simple too.
All you need to do is use a software package like wordpress and not employ any actual developers. CMS packages nowadays allow even large operations to run entirely on point-and-click configuration; but the kind of special case they're being asked for here would very likely require a programmer to actually write code. Note how the quoted person says "content-management software experts" and "configuration", not "developers" and "feature".
Welcome to software in the new millenium.
Case in point: the situation detailed in this article.
My sympathy is essentially at zero level here. In this situation their privacy policy, a legal contract, guarantees they won't reveal the names of contributors even if the privacy policy changes. There is no excuse whatsoever to violate such a legal document. If they find their software cannot handle what they want to do without violating this legal contract, what this means is they cannot take the action that will violate it.
Should the MT Standard take actions to wilfully violate their privacy agreement, then they open themselves to lawsuits. In some cases I wonder if a court might grant an injunction forbidding them from implementing their new policy?
Yes, doing this will cost you money, but it will be much, much cheaper than dealing with the inevitable shitstorm that is going to follow if they go through with this change.
It's probable that he or she was just simplifying things for you, and that you're just unaware of the actual underlying complexities; although changing the color on the wordpress site's navbar sounds pretty clearly trivial at first glance, the full spectrum of places to which that change would have to be manually copied might be extensive, undocumented, and tedious enough to alter that "No, that's impossible" is the go-to answer instead of spending time explaining why something sounding so trivial might actually amount to many hours of effort.
Imagining the logic and code is not hard. But if you are a non-programmer, this is not how you think about things. Most people are trained to use a CMS, and every other computing interface. They don't understand that computer software can be changed. For them, hearing that it is impossible to reconfigure a CMS is like hearing that it is impossible to reconfigure a 1998 Honda Civic to become a hovercraft -- that is, it sounds completely reasonable because "that's the way these things are".
Edit: Another factor...it seems that the Standard uses a hosted CMS solution...which yeah, would pretty much make it impossible for this fix to originate in-house: http://www.townnews365.com/
This is, unfortunately, not uncommon at all.
BLOX is advertised as "Cloud-based" with "No hardware or software to install & maintain".
This all suggests that they actually cannot make such a change, by virtue of using an SaaS solution they have no control over.
But do they really need those comments on old articles? Why not just delete them? This is a community paper. How often are people reading old articles and how often are those people reading the comments? I have to question if the management of the paper are motivated more by unmasking certain shitty commenters than by anything else.
UPDATE user SET realname=screenname WHERE screenname IS NOT NULL;
Done!
But remind me never to ever use BLOX. This seems like the MOST basic thing you'd want to be able to do.
It's not hard, however, it complicates the software leading to subtle non-obvious bugs, and then you need to support this features with all the other features you're adding, etc.
PS. What happens when they turn if off? ...and then back on? And then the 20 other subtle bugs that this feature introduces... And how many other features that lots of customers want are we delaying while we implement this?
All this work for $24.95 a month... yeah... no, 86'd.
If it's anything like most small town newspapers, there are probably about a dozen people with nothing better to do, who argue and snipe at each other in the comments section of every story, and rarely add any insight or additional newsworthy information. Just deleting them would be the safest way forward and cause no loss of anything really important.
The mistake here is assuming that the news organization has
a) a developer
b) access to the code
Quite simply, most are far too cash-strapped and rely on third-party services.
Here's one option:
UPDATE Users SET Secret_RealName = Avatar_ChosenName WHERE 1=1
If they run that on their CMS database's Users table (with appropriate adjustments for actual column names)They destroy the old users' real name by replacing it with their Avatar name.
This would preserve all old comments' anonimity. Active users could edit their names back to "real" if they wanted.
There's no way there's a CMS where a fix is impossible.
The result in this case might be a little unsavory but its far from the only option... Just the cheapest guaranteed one that I can think of.
"[x] Display Screen Names [] Display Real Names"
http://docs.townnews.com/kbpublisher/Comment-Manager-Setting...
So what? If it is impossible, then your privacy policy was clear you will protect the identity of posters.
Heaven help journalistic sources if they apply the same policy to anonymous sources!
Here are your options:
1. Tell the CRM writers the situation is unacceptable, and force them to fix the issue
2. Get a new, sane CRM that can actually do something that should be a complete no brainer: allow previous posts to remain as-is. Then fire the person who chose the unbelievable bad CRM you actually forked over money for.
3. If neither of those options are possible, then do not proceed with you new policy until which time you make the impossible, possible.
Frankly, you have Paul Levy on your tail. Be prepared for some substantial lawsuits from an incredibly tenacious and effective lawyer.
In any other case the answer is like in the real life: it depends.
[1]: My bet's on people who can barely use a computer stood up a wordpress or joomla site, and only really understands how to edit configs, not actually change the programming.
What's your name, btw?
Threats on the other hand should suffer exposure. Being politically incorrect isn't hateful or mean but there many who will claim in. The danger is we are basically going to silence some who have real reason to fear persecution.
2) If you think that ONLY mean/hateful stuff needs to be attached to a real name, who gets to be the arbiter of this policy?
3) What about the legally binding promise made in the MT Standard's privacy policy where they said they would NOT share that information with third parties? And they further said that updates to the privacy policy could not affect comments retroactively? Are we willing to let a company get away with flagrantly violating their privacy policy so that we can win the war against "mean/hateful" stuff that is said online?
Edit: I also notice that you are posting here under the anonymous screenname "killface", while I'm posting with my first initial and last name. Ironic.
Not that I consider your comment mean (it has some merit), but for the MY Standard they gave certain legally binding guarantees around anonymity. They can make new posts applicable to the new privacy policy (which I actually think is a good idea - if you want to be anonymous, contact the reporter and request anonymity, if it's important then they can report on it and you become a news source), but you can't retrospectively change the old comments.
The language in the old privacy statement is pretty ironclad!
Not that I necessarily think these comments are so wrong that you would remotely deserve such an outcome for thinking or saying them, but that's the point: if it came down to it, that wouldn't be my judgement to make. And would you have unreservedly said all the things you have, if they were going to be permanently and publicly tied to your real identity?
In fact, after a few more pages of your history, applied to some leet cyberstalking skills, I know your real identity and where you work and live. How would you feel about being outed, even over such nominally innocuous things?
I would never do that, because it would be wrong.
You commented with the assumption of a certain degree of anonymity. So did the people you're saying there would be nothing wrong with stripping a similar anonymity from.
Says killface?
That said, I agree that (some) online communities profit from real-name policies. C. f. the difference between youtube and Facebook. But that is no argument for retroactively changing the policy.
How about it? What's that? You don't want to give your real name? Why not? LOL.
The irony. You think that this will only applies to others. You don't seem to realize that, others WILL use this against you too.
Overall, this is a very bad idea.