We’ve lost control of our personal data, including 33M NetProspex records
troyhunt.com
troyhunt.com
I use fake account information where it is legally permissible and the system is requiring some input to proceed.
When I get asked for my phone number, zip code, email address's etc... At checkout in stores, I give a polite "no thank you". Which usually results in a huff and/or an eye roll from the cashier, as if I'm expected to give this info for the privilege of shopping there.
If the information sources dry up or are of sufficiently low quality, the market value is significantly reduced, as would be the incentive to collect and store such information.
Point is, no one before me had issues with giving that info, no one bothered to ask. Unless many people start asking questions, nothing will change, and I don't think most people care.
At the high school level, kids should be taught topics like privacy, civil rights etc - that might help at least a bit
I find it fascinating the reactions I get, and the people who refuse to help me with stuff when I say I don't have a phone, or a number I can be reached at.
When push really, really comes to shove, I give them a number from somewhere I lived 10+ years ago.
I did the same thing a few years ago, drove from Alaska to Argentina over 2 years.
Best decisions I have ever made.
I'm http://theroadchoseme.com if you're interested in what I'm doing. Here are my thoughts on saving money: http://theroadchoseme.com/work-less-to-live-your-dreams
Good luck!
https://www.troyhunt.com/going-dark-online-privacy-and-anony...
Someone has ALWAYS registered it before me.. I have never had it not in the system..
Zip codes are often associated with social and economic status and Harbor Freight is in a really bad zip code. I wasn't about to tell everyone standing in line that I was getting in my $100k SUV and driving to my $500k home in the suburbs after they hear my zip code (none of that is true but that's what you'd expect from the city I live in compared to the city I was shopping in).
I consider myself a privacy nut but zip code is not something I care to get bent out of shape over. Give a fake one and move on with your life.
Are you really surrounded by thieves and killers, and the only thing keeping you safe is that they don't know that you live in a rich part of town?
They know where the rich part of town is... Right?
Presumably because police presence is less, or at least busy, in the less expensive zip code. There isn't just more crime in less affluent areas, it's rampant!
> Are you really surrounded by thieves and killers, and the only thing keeping you safe is that they don't know that you live in a rich part of town?
According to the news, yes, but even that expensive part of town is just a "you won't believe where" teaser away from being right next to you!
In all seriousness, as rational as you consider yourself, it's still an uphill battle against the signals we are bombarded with telling us about all the crime and suffering around us. Humans are great at finding and internalizing patterns from signals, and the pattern here isn't hard to see; the world is getting scarier and scarier every year. Doesn't matter if its true or not, that's still how it feels.
EDIT: I applaud the general paranoia, but I think it's just misplaced. You have more to worry from HF aggregating your P.I. than some guy behind you buying tools for his third job.
Yes, nowadays people can type that into their phones and find the corresponding neighborhood, but really? Most criminals steal what they can see, not what they think might be there from a zipcode. They're better off just driving to a nice neighborhood and casing the houses whose owners are away.
Of course maybe there are people following you around slowly acquiring your PII so they can steal your identity and drain your 401k.
Years later I discover to my dismay that I handed out that information voluntary, to my current standards I do consider it PII.
Unless I'm getting trolled, in which case, excellent satire.
You wouldn't walk into a store and shout out how much money you make, would you? Announcing your zip code is effectively the same thing.
All of which is to say, I think you're being paranoid and unwarrantedly suspicious of strangers just because you're in the "bad part of town".
Most British people would identify that as a London postcode — London is so large, it has several first letter codes.
Most people from London would identify it as a posh area, people familiar with South West London would know it's an extremely posh bit. (It's the Science Museum.)
Outside London and the densest cities it's less accurate, but usually still distinguishes urban and rural areas.
Example: https://en.wikipedia.org/wiki/LE_postcode_area
I wouldn't feel unsafe giving my postcode, but they have been used by some street gangs as part of their identity, and therefore define a territory. In cities, the "SW7" bit is usually printed on the street name signs.
But realistically, poorer areas = more crime
I don't believe this for a second.
People who have a decent income and stability aren't likely to be driven to crimes of desperation, such as burglary and robbery (among many others), so even without statistics you can imagine why it would be true.
"Persons in poor households at or below the Federal Poverty Level (FPL) (39.8 per 1,000) had more than double the rate of violent victimization as persons in high-income households (16.9 per 1,000)."
https://webcache.googleusercontent.com/search?q=cache:WrnC-F...
http://www.economist.com/news/science-and-technology/2161330...
This isn't my theory and it isn't new, so I'm not sure why you don't believe it.
The customer wrote on the back of the cheque (I said it was a long time ago) a minimal contract that said something like "By accepting this cheque RadioShack agrees that they won't send any junk mail to the provided address, if any is sent a fee of $100 will be payable" (paraphrasing).
RadioShack ultimately sent the guy junk mail, and the guy asked for his $100 which I think they ultimately gave him.
It's clear to the sales clerk that I just want to be on my way--conveying that I do not wish to share such information, that I don't have a preferred shopper card, and, most importantly, that I don't want to hear their sales pitch.
If required to provide a phone number, I just increment the last digit by 1. I feel for whoever has that number :-).
may or may not know that it is pretty universally applicable as a phone lookup for most rewards cards. Just prefix with a popular area code, e.g. 415 (Bay Area) or 212 (NYC).
Naturally, you won't get any of the rewards, but it does protect your privacy, and with some annoying retailers, still gets you the member discount.
"Thank you for shopping with <store>, Mister Mouse."
Critical thinking isn't going to take off in a country dominated by people who profit from its absence.
I asked if everything was okay and he said he'd never seen so many entries using the same phone number.
Couldn't help but laugh when I realized he had no idea why so many people had used it.
... except you are. It's an identifier that allows separate transactions to be correlated.
I never know whether to be sad or glad cashiers no longer catch on when I give my phone number as "[area code] 555-1212".
For the most part I don't even get the huff and eye roll anymore, they just hit cancel, input the store's postal code or something else and move on.
Though I once had a cashier insist I give her my postal code after giving the polite no, she gave me some "I need it... for the system" or something. When I started giving an obviously fake one, I got the huff and eye roll. I wonder how many people would have caved. Hopefully just a new cashier who didn't know the appropriate thing to do in the case that I didn't want to provide details.
One address, with zip code.
If you also happen to be someone who struggles in the social arena, it's a way to avoid even the most unlikely of conflicts.
Why do so many people online seem to need to demonstrate that they are some how persecuted (even if in the slightest, most inconsequential way) for taking a particular stance on something. It happens in this way so frequently that I honestly don't believe it at all. For years I've been doing exactly what you describe -- saying, "no thank you" to data requests at checkout -- and I've never noticed anyone appear to care in the slightest.
It doesn't make your story more believable or you more sympathetic nor does it make society looks any more crazy. It's just a weird detail that is probably not true and doesn't need to be included.
When I politely refuse to give out my personal information when buying things, I regularly (but not always) either get a confused look, an annoyed look, or additional pressure to give the information (i.e. "oh it's just for warranty, everyone gives it")..
Just because you've never had this happen to you doesn't mean it doesn't happen, or that OP is making it up.
This may be because I know that at least some companies incentivize employees to capture this information, so when you refuse to give it up, they are in fact losing out on some kind of compensation or bonus..
Thankfully, my new barbershop doesn't care in the slightest; they will put me on a chair, cut my hair, and take my money. That's all I've ever wanted out of that particular relationship.
The bigger concern for me is companies using the number to track me.
It was funny experiment and I tell you boy Victoria Secret is not in business of selling lingerie - they are in business of selling your data!
My wife wanted me to order something from them about year ago and I used my trick on them too. 3 months later all sort of companies start spamming my mailbox with all kind of stuff including Deer tractors (!!!) When I called to find out where they got my info from, they said they can't tell me because they cannot validate my identity as of if Im exact person who says I am. I even offer to send my ID via fax and eventually show up at their office and I was told "this is not how we work". The only thing they could do for me is to opt me out.
I'm simply waiting for the day when there will be a hack like this on the European continent, it's scary what sits in lightly protected databases, especially if you consider the probable sources of data like this and that - at least in Europe - it would be illegal to create such a DB without the consent of those whose information is stored in them.
We've lost control is the perfect way to describe things.
I guess the other side of that argument means that mentioning who sells it shouldn't be a problem either.
But you need a consent to collect that data in the first place.
Hah, there's one big assumption you are making there...
The German commissioner for data protection might be interested:
https://www.bfdi.bund.de/DE/Service/Kontakt/kontakt_node.htm...
In case you'd rather not do it through official channels (or in addition, just to keep them on their toes), may I suggest:
I can imagine such an entity, at least in Germany: the Schufa, a credit rating service. It's impossible to open bank accounts, get credit or phone/internet contracts without all this going into their DB.
Better hope they secure their systems. Credit rating companies are, from their model of business, rotten to the core - and pose an extremely high risk these days where everything is computerized.
Instead of risking their data in the motherlode of hacks occurring against Github they setup on-premise Github/Gitlab/Bitbucket/etc. then let the servers go unpatched, stay several versions behind, don't bother setting up authentication roles properly and give people more access than intended.
There are plenty of places doing on-premise right, but I definitely trust Github over the average undermaintained on-premise installation.
Having come up working on classified systems, it pains me greatly to see such lax security.
But I'm happy because no one visiting my site is getting a virus from shitty third-party ads.
Obviously it's bad for business to badmouth stuff we got for free, so we're actually pretty picky about what we accept. If I don't like eating at a restaurant, I won't accept free stuff from them on behalf of the business. I've been offered services by a hair salon in town but it doesn't line up with my demographic so I won't accept the contract because I wouldn't want to write about them. I've turned down two offers from the local bowling alley because I'm not going to have much nice to say about it.
But no one is guaranteed to get a good review. I've written some reviews I would describe as "hopeful", in that "I'm hopeful they'll get better soon" mostly with regards to brand new restaurants where the kitchen is still finding its groove. Everything that I write is my opinion and is clearly marked as such, even while it's also marked as something I was given for free in exchange for my honest opinion.
To maintain your credibility, you should review it pro bono; for bonus points, note that they previously tried to pay you twice. Otherwise it would be honest to clearly disclose that you mostly/only write positive reviews, albeit via selection bias rather than outright lying.
I've written product reviews before, always either for stuff I bought or stuff received via an intermediary (i.e. X sends me Y's thing, I send my review to X). The whole "sponsored content" model makes me long for the days of flashing banner ads.
It's funny to me that whenever I mention this side project on HN it always gets a lot of interest from people wondering if I'm being honest to my readers and giving advice of how I can be more honest. Guess it goes to show that there isn't a lot of honesty left in this world.
I respect that. But 90% of everything is crap, and this is a forum created to worship shameless hustling. Negative reviews are important.
Wat?
I guess? Maybe the records were exported one at a time and formatted for excel vs in an array for programmatic access
Its not great to work with.
What I'd love to see is a marketplace of "personal data banks" that would work like this:
- The bank maintains an isolated database of every major database vendor. The databases are isolated to a single consumer.
- The bank exposes API endpoints of every major database to companies like Facebook or new SaaS startups. Those companies now agree -- when requested -- to write your data not to their private database but to the bank's database that is private to you.
- You, the consumer, pay the bank a modest monthly fee to control who can access that data, and even optionally cut off access to the original "generator" of data.
I guess this still suffers from the need to trust that Facebook is abiding by your request that all data be written to the bank, and network latency becomes a real issue. So maybe it's not the right business model, but it's an important problem to solve.
It would require a massive paradigm shift in how the internet works in practice, but image a world where:
1. You sign up for some new social network/thing that requires your data
2. You point it at your own personal (or hosted) info server
3. The service promises/or the use of the personal info server stipulates states that the data should never be stored longer than the lifetime of a relevant transaction
4. The social network queries your data maybe once a day (or more depending on whatever kind of work it does), announces itself, and can be cut off when you want.
Of course, things don't sell these days with just privacy these days, but there's some upside to a service like this ironically due to it's centralization -- you could sell the user on "only enter your address/personal/credit card info once, have it available everywhere with one click, no long login forms"
Trust is dead; it doesn't scale. End of story. I don't like the idea of a "data bank" or "data brokerage" any more than I like the idea of facebook; either way, someone else holds the keys to my castle. But third-party servers aren't going anywhere, so we have to find a way forward.
I've come to the conclusion that the only possible way for someone (or something) to maintain control over data is to encrypt it at all times when not in use. It's exactly the idea of a "data bank" like you're describing, but you become the bank. One of the key struggles with this approach is that it requires a tremendous amount of client-side code; calling it a paradigm shift is a profound understatement. It doesn't matter how snazzy your encrypted-dist-web product is unless you present a compelling economic reason for companies to switch to it, to justify the extreme expenditure of capital necessitated by the technical switchover.
Even here, though, once you share something with eg. Facebook, you can only hope they don't fuck it up. That's just the way the world (unavoidably) works; once you share something with someone, they have every capability to do whatever they please with it. You have only the social expectation that they don't, and if they violate that expectation, your only recourse is to stop communicating with them. But I do think, in a world where we actually have autonomy over our data (partly, again, because it necessitates client-side code), it is possible to make the consequences of data misuse so disastrous for a company that it stops being economically viable for them to do so.
The key thing we've lost is that agency to make decisions about data. I've no problem with informed, consensual sharing, but in today's world re: data, "informed consent" is nonexistant.