If I understand correctly, youre saying my entire purchase history is shared with random third party marketing companies. Full transaction data, PII included, no anonymization.
How is that even remotely OK?
I don't use facebook but do use a credit card. Hard to opt out of that in the modern world. God these people are filth.
And all that for a cheaper (and cheap) bread-knife.
When I pay with cash, I usually don't present a card as well.
Been buying too much sugar? Dental insurance up. Too much butter? Health insurance up. Bought three times the median amount of headache tablets? That's a paddlin'. Bought more alcohol than normal? Car insurance up.
Opt out to keep off their radar? They assume the worst and charge you double?
Thinking from first principles lets us see incentives and probable outcomes before they are "substantiated" (adopted by the media).
I personally don't think shopper data is affecting insurance policies quite yet. But the groundwork is there (Acxiom etc), and the "great" thing about data is it stays around forever!
I'd guess a timeframe of 10 years, but does it really matter as to when?
Is this a response to my comment? I would guess that the answer is "nothing but the temporary protection of the law", but, assuming that protection is eventually revoked, it makes it all the more worrisome for me to have a random stranger's data taken as my own.
I'm not a tin foil hat type, but I really don't like filling my wallet with tracking cards and can't be bothered to claim the miniscule compensatory benefits provided in return for proffering my purchase (and also location, hygiene, etc.) information.
Saying 'no' is almost more hassle than simply submitting, however, which is probably exactly what the company would like to hear. Suggestions welcome for brushing off this nuisance without a) Avoiding their shops entirely (not practical) or b) Being rude to cashiers.
Lumping Apple with Google in terms of data gathering is misleading at best.
PII is not available, it is anonymized. There are laws around this. Purchase data itself is usually grouped into major purchase types, not amounts or actual goods purchased.
For that detail, it would be the CRM/ERP systems of the manufacturer that has that information tied to a serial number and this is why they ask you to register your product when you buy it. Some manufacturers might work with data providers to exchange this data (serial numbers in exchange for purchase histories) but it's rarely done at scale because of cost, complexity, legal/security risk and lack of options to benefit from it.
But we've seen how useless even apparently well meaning anonymisation is—think of the AOL search results. I can't imagine how utterly useless it becomes when it is done by people in whose interest it is to do it poorly, while remaining just within the law.
The protection of the law does add to the security. Also anonymization of the PII (scrubbing into just a serial number) combined with the dilution of purchases into larger categories provides lots of protection. Your google search history is lot more detailed and granular than most of the purchase data you can buy through data markets. You might be able to figure out a basic "profile" and maybe use lookalike modeling but it would be incredibly difficult to actually distill that to a discrete person.
There's also been a push to buy "insights" rather than just data to get more ROI with less effort/cost so instead of buying purchase histories you would just buy a segment of people interested in buying washing machines for example.
There is at least one company that has built technology that will monitor most all these purchases, monitor the IP's from them and the browser profile to identify a specific machine that you use. Then when you go to work, or are on your mobile they also will tag that traffic as you too. They have gotten so good they can serve ads that are relevant to your wife if she happens to be on your computer surfing the web for shoes say, but serve you different ads if you are on the same computer. They use data feeds from many sources, but ecommerce transactions, credit card transactions and companies like acxiom that let them match those with real people, incomes and household details make it very powerful.
In marketing we use Axiom and others a lot, their data used to be more vague and educated guesses about people. Now though, they have gotten it down pretty well, including how many animals, kids and your income/debt etc. They collect data from tax collectors offices, county records, city records, plus companies that will sell transaction data and other pieces so they can get a full picture. They of course work with Equifax, TransUnion etc too so they can build a whole economic profile on a person.
These companies are also what allow marketers to send you an email about their product/company after all you have done is visited their website. You don't have to enter anything or click on anything, but they will know who you are, who you work for and whether you fit their market profile in general. Poorly done it is extremely creepy, correctly done it can be an amazing conversion booster.
I am from Brazil, and I am openly dissident of our government, and here assassinations (And other unpleasant things) DO happen to dissidents (example: in the last year a couple anti-government bloggers all in the same region where "murdered", the police claim it was just normal murder, but the coincidence is too great to be just normal murder, they were obviously assassinated).
What happen, if some day the government decide to assassinate me? They can just waltz in with a market company, offer a lot of money (or if they refuse, a lot of pain), get my data, and know all that stuff about me.
Then, they can do with me, what they did with Toninho and Celso Daniel: intercept them on the street, kill them, and pretend it was a robbery gone wrong.
Toninho case was very obvious: He was intercepted while fetching some suits he had bought before, using the tech you mentioned, assassins would know for certain that he was there, since they could know he would need to eventually fetch the suits, and that once inside the building, you could intercept him at the exit, indeed as he was exiting the shopping mall that had the clothing store, another car drove by, shot him (not "at his direction", but at him, directly, Toninho died instantly because of direct hits), and sped away. The police claimed it was a random incident where random criminals randomly passing by got pissed off at him cutting them off in the traffic and killed him, beside all that being unlikely, Toninho had some days earlier said to the press that should "something happen" to him, stuff were already set for his successor.
So what matters to me is: How I don't get tracked, unless I go "off grid survivalist style" ?
That said, there are things people can do with companies like Acxiom to help reduce the data collection. At least in the US (not sure overseas) if you as a consumer submit a request to be removed from their lists they must honor your request and remove you, many US states have strict laws about this and I believe the Federal laws also have strict restrictions. The catch 22 to this is that you can wind up back in the collection at a later date because of activity you take or because of a timeout period (from what I understand). You can read about Acxiom's policy and opt-out here: https://isapps.acxiom.com/optout/optout.aspx
As a point too, you may check out the data collection from Acxiom, as I believe they actively collect and use data in your home country, as they do in many counties. Equifax, Experian and TransUnion all also work in the US and overseas and collect/sell vast amounts of data on individuals. The very fact they collect so much data does make people (including me) nervous because I personally feel they do not take security of the data nearly serious enough, as recent security issues have shown at most of them. But that I guess is a different issue/post.
We aren't there yet, but consider that Facebook wants to use your social network associations in your credit score[2].
[1] https://www.youtube.com/watch?v=lHcTKWiZ8sI
[2] http://www.theatlantic.com/technology/archive/2015/09/facebo...
I don't get often surprised by all that dystopian stuff, because I assume we already are quite fucked, but this one did surprise me. That's just crazy.
To be clear, I believe there is some disagreement as if this is one or multiple programs in China, but that doesn't really matter; we need to defend against the establishment of this kind of program regardless.
The trick where positive reinforcement is used to trick people into wanting to participate is utterly terrifying... because it will work. It's obvious that it will work, because it is effectively the weaponization of "high school clique"-style tribalism and carefully re-framed self interest.
But a state sponsored gamified social network where the incentives are all designed by the ruling class, and the penalties have the force of law, is pretty darn awful.
Hopefully the affected citizens prove to be as unpredictable and hard to control as others have in the past, because that's really their only hope.
It sounds like the system does not currently use politics and such, but the government would like to combine it with the existing citizen tracking system which is employer based.
And a BBC article: http://www.bbc.com/news/world-asia-china-34592186
I think the US system is fairly insidious as well and has more government influence than it might seem (look into "redlining" for instance and the role the government played). Creditors can know quite a bit about your private life (particularly if you significantly outside the mainstream) and I don't think it is that uncommon for individuals to share credit scores. In any case, I think it is worth considering how "social trust systems" work everywhere and not just in the worst imagininable case. It is harder to think about in the less obviously centralized cases.
European living in the US here. How do these systems assess recent immigrants who have no credit history in the US?
You will probably have to pay a rate premium unless you go through a lender such as a credit union that you have an existing relationship with. Your provable income will be your biggest asset.
As a non-US citizen, it makes sense that you will be perceived as a higher risk of absconding since you could leave the country permanently at any time.
Look at ways to establish at least some credit history sooner rather than later, as this will make things easier in the future. For example, even if you do not need a store credit card, you might get one and charge routine purchases and pay the full about each month. This avoids any extra costs and builds credit history.
Company A tracking my visits to Company A's website = OK
Company A using Google Analytics to track my visits (while also enabling Google to track me across multiple sites) = Not OK
EDIT: (replying here as we've reached max comment depth) - I was unaware that it is possible to use Google Analytics server-side only (is this true?) but I hope my original point is still clear, DIY tracking is fine.
You misunderstand. There have been several commentators here on HN saying that they are moving Google Analytics server side. They seem to think that people are only objecting to the cookie or the presence of the JS rather than objecting to the pervasive cross-site tracking.
You can also just host the ga.js file yourself. Or run a reverse proxy or any of a dozen other methods to collect data and pass it to GA. Using the standard 3rd party tag is just for convenience.
I'm pretty sure it's the same mechanism used for mobile/app non-browser tracking.
If you want to see a simplified version of what this log looks like, run 'python -m SimpleHTTPServer' and visit localhost:8000.
Ofcourse people can(and do) sell their server logs to 3. parties anyway...
I'm not in that particular market, but I know people who are and tbh more often than not I think it's an arms race the individual simply cannot win. Unless there's a conscious effort from browser-makers to actively counter tracking practices, you should assume everything you do on the web is public and can be tracked by multiple parties.
This can be as simple as hosting a copy of GA.js yourself but there are plenty of options like using the server-side API if you have GA enterprise or just using a reverse-proxy like Nginx with some rewriting logic.
3rd-party only means it's a different domain (with security usually implemented at the browser level) - it's not some magical wall of isolation.
That's unsettling.
The answers to this are twofold: Better national information security support* and regulation; Consumer action to chose vendors that demonstrate that they value personal privacy and prioritise information security.
* Which includes not deliberately, as a matter of policy, undermining security technologies and standards.
In a pure capitalist model it is okay if Facebook shares all your data with advertisers – if you don’t like Facebook, just vote with your money and go to Google+.
"Sweden's industry is overwhelmingly in private control; unlike some other industrialized Western countries, such as Austria, Italy or Finland, state owned enterprises were always of minor importance."
In fact I think I can make a strong argument that capitalism relies on property rights and therefore the rule of law, which tends to support individual rights in general including privacy.
Especially in the US the balance has been skewed since forever towards capitalism.
Historically, Social Market Economies evolved in countries where the population was supportive of socialist and communist uprisings, but the ruling class tried to keep the economy, and implemented the same benefits as in a socialist system in the existing market economy (See Bismarck’s Social Welfare model in Germany and the history of Bismarck vs. the Social Democrats on this).
But the banks already know where your paycheck comes from ...