EFF’s “Spying on Students” Report Highlights Tech Companies’ Data Collection
eff.org
eff.org
Something that guarantee's proper and fair usage, with privacy. The decision making of which I'm sure would be a long and deep debate.
If someone stuck an rfid tag in your ear, and tracked where you moved and what you did, I would expect some compensation for that information. Yet we get cookies attached to our browsers, we are profiled and tagged to watch everything that we do online.
The de-regulation of the consumer information protection is important in that it is bringing attention to a bigger issue. The ISP's just want to do the same thing other companies have been doing all along.
Now, the EU doesn't always get this right. Some of the rules already agreed at that level, which will in due course become enforceable in member states, are obviously awkward or outright broken to anyone familiar with the actual technologies involved. There are some obvious contradictions (a cynic might use the word "hypocrisy") particularly in areas around potential surveillance by government agencies.
Still, compared to the kind of laissez-faire attitude adopted particularly in the US, the EU is practically living in a different world, and the difference is getting wider almost by the day. Moreover, I suspect a significant fraction of the US public would prefer a more EU-style arrangement (witness the arguments in the EFF report here). Obviously a lot of US businesses would not, though others, particularly those whose reputations rely more directly on being secure or trustworthy in some sense, might disagree.
Unfortunately, given the lobbyist-centric and partisan nature of current US politics, it seems inevitable that this fundamental divide will cause increasing amounts of grief all round, and the unknowns are more about who will be hurt more.
In 1980 work began on a data protection directive[2] which would pass 15 years later after giving birth to 1981's Convention for the protection of individuals with regard to automatic processing of personal data[3]
At the turn of the 2000's through lobbying of various industries and government (including the french government) reversed direction and managed to pass a data retention directive at the European level. This got challenged at all steps from locals to the highest European Court of Justice which invalidated the directive for being contrary to fundamental human rights.
This didn't happened by chance, it took years of dedication and hard work to get there. And it got the attention of a bunch of very dedicated internet geeks who got themselves into politics to defend the internet and privacy. This gave rise to association of people such as la quadrature du net[4] who has been active at the national level up to the European level.
So now the politicians at the European level have a significant amount of backup from concerned citizens and netizens who provide all technical knowledge and background required to understand the significance of technical piece of legislation.
But a most significant difference with the US is World War 2 took place in Europe. (which kinda gave birth to the EU as to prevent Germany and France going to war again a joined union of coal and steel production deal was made which laid the foundation for the European union[5]. The point is Europe and in particular Germany one of the most influential country in the European Union has first hand experience of what the effect of mass surveillance can be and the importance of privacy. WW2 and nazism industrial attempt at genocide explains why the french were outraged by the government attempt at a centralized database of french citizen identified by social security numbers, and why Germany opposed the data retention directive.
The situation is a bit different in the US, when google or the like publicly oppose a bill they're defending their own interest not the general public. When an individual organize people to successfully oppose a bill, he gets pushed to suicide under government pressure probably using the data the govt agencies have on him as Aaron Schwartz story shows.
There's also the economic standpoint, most of the major internet companies are from the US so it makes sense for the EU to defend their population from those and maybe give an advantage to European companies while on the other hand the US has no foreign market dominant companies to defend from and instead has incentive to protect those companies and further extend their domination.
Different histories, different incentives hence different approaches to privacy.
[1]: https://en.wikipedia.org/wiki/Commission_nationale_de_l%27in...
[2]: https://en.wikipedia.org/wiki/Convention_for_the_protection_...
[3]: https://en.wikipedia.org/wiki/Data_Protection_Directive
[4]: https://www.laquadrature.net/en
[5]: https://en.wikipedia.org/wiki/European_Coal_and_Steel_Commun... and https://en.wikipedia.org/wiki/Schuman_Declaration
Oh and the good news is that such a declaration of human rights already exists so most of the work is already done.
I'm not aware of this deregulation of consumer information protection, can you provide context on this as a web search drives me to the FTC website.
I'm not sure what you mean by ISP wanting to do the same thing other companies have been doing, AFAIK ISPs have been involved is collecting data and exploiting it for profit for as long as commercial ISPs exist.
How many centimeters away from your ear is your mobile phone right now?
[1] http://www.un.org/en/universal-declaration-human-rights/
The Universal Declaration of Human Rights is a document which is globally accepted, therefore, to represent what human rights should be. The fact that the US, the supposed "land of the free", falls short of this, is just particularly sad.
However, the countries that belong to the UN do. If enough of them are willing to put their money where their mouth is, which is going to be a matter of local political pressures as much as anything, the picture changes.
https://www.washingtonpost.com/news/the-intersect/wp/2015/09...
"No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honour and reputation. Everyone has the right to the protection of the law against such interference or attacks."
That seems really broad. Does this apply to private citizens and firms or only governments? If the former it seems a great deal of journalism would be illegal.
A few recent examples. When Rachel Maddow released Trumps tax returns was that a violation of article 12? What about when that "grab her by the" tape came out, Trump clearly intended that to be a private conversation and it was a "attack upon his honour and reputation" wasn't it? I don't see a line that allows for truthful attacks.
I don't know if I want to live in a country where it is illegal to report on fact in such a broad and sweeping manner.
[1]: https://en.wikipedia.org/wiki/European_Convention_on_Human_R...
No, that standard would not apply to a small ISP. The premise is institutions that grow strong enough are able to unduly influence and capture the regulators more easily. Corporations need to be kept small enough to regulate effectively. The existence of "too big to fail" private institutions is a threat to democracy.
EDIT: National government, itself an institution, also needs to be kept small enough that it can be contained by the regulators on it, so this is clearly not a simple problem. The issue there (in my opinion) is that the check on national government is supposed to be the states, and they are too weak to do that effectively.
Human rights apply to humans. Firms and government are not human, not even alive or have any tangible existence.
I don't know about those Trump examples, but it seems to me that usually an elected official is a public figure and as such privacy laws do not apply. Then again human rights and legality are two different things, some human rights may be considered illegal in some places.
I much prefer the truth as a defense idea, which goes against the strict interpretation of the UN's charter.
And do not forget, "Grab her by the pussy" is now the presidential standard. there was some in this country that were that crude and direct about sexual assault, but those views are now given much more airtime..
The problem with truth as an absolute defence is that as the courts famously remind us, "the truth" is not the same standard as "the truth, the whole truth, and nothing but the truth".
The extra parts can be rather important when someone's reputation is at stake. For example, consider the difference between "John was accused of being a paedophile" and "John was accused of being a paedophile, though the investigation was soon dropped after no supporting evidence was found and it turned out that his accuser was an ex-girlfriend with a track record of psychiatric problems including making false allegations of serious criminal behaviour to get people she didn't like into trouble".
This is also why the EU "right to be forgotten" ruling wasn't nearly as crazy as some people have been suggesting, BTW.
I think corporations here in the US that are against it managed to set a pretty good FUD campaign about right to be forgotten, and I think a lot of people bought into it.
So what is an effective answer? Requirements: Short, high-impact, memorable (it must spread), crystal clear for the completely non-technical, not easily refuted.
Ten years from now, or tomorrow, People You Don't Like could be in charge of any given agency or company, and deny you things then based on what you did today that was perfectly legal or ethical.
There are more extrapolations from that but it should be enough to be short but get the gears turning.
In the 1930s The Netherlands recorded the religious affiliation of every citizen inside their resident register (stored on punch cards for use with Hollerith machines). After the Nazis invaded the Netherlands they were able to easily find out who was Jewish, had Jewish parents or grandparents. The consequences those people had to face are well known.
Source (german): https://de.wikipedia.org/wiki/Judenkartei#Niederlande
If they are concerned with racial issues (or similar), try pointing out how data analysis can hide institutional racism (or other biases) - even unintentionally - into the algorithms behind finance, criminal sentencing/parole, future employment opportunities, etc.
Even if none of that happens to apply, there are two big reasons they should care. First, the unknown. In the circus we call our current political environment, do they really want a future $POLITICAL_ENEMY to have a detailed map of who they are, what they do, what they like, where they move during the day and who was with them (COTRAVELER), and anything else modern machine learning techniques can find?
The final reason is... because it isn't always about them. Other people might be in worse situations and it's important to stand with them by normalizing sufficient privacy. In his essay[1] on why he wrote PGP, Philip Zimmermann said
>> "What if everyone believed that law-abiding citizens should use postcards for their mail? If a nonconformist tried to assert his privacy by using an envelope for his mail, it would draw suspicion. Perhaps the authorities would open his mail to see what he's hiding. Fortunately, we don't live in that kind of world, because everyone protects most of their mail with envelopes. So no one draws suspicion by asserting their privacy with an envelope. There's safety in numbers. Analogously, it would be nice if everyone routinely used encryption for all their email, innocent or not, so that no one drew suspicion by asserting their email privacy with encryption. Think of it as a form of solidarity."
This is similar to the concept of herd immunity[2] with vaccines. Vaccines are not 100% protection and some people cannot take them for various reasons. Those people still benefit from the general vaccine use producing fewer opportunities for infection. Similarly, when enough people protect their privacy, there is less incentive to abuse data thanks to lower profits and increased political costs.
[1] https://www.philzimmermann.com/EN/essays/WhyIWrotePGP.html
Do you know of any evidence where that has happened? I wanted to say that those things they blamed on Obamacare were actually because they were posting pictures of themselves at barbeques on facebook- but it's hyperbole to my knowledge.
The "getting rid of envelopes for mail" argument might work on some.
As kids we're exploring all kinds of ideas --some good, some regrettable, but we should be able to explore them without fear these crumbs of exploration will follow us in to the future as if we were fully mature and aware as we explored ideas.
Why shouldn't everybody be allowed to explore ideas without consequence?
Perhaps we should, at least more than we do in practice today. I'm not sure enforcing conservative views or limiting open debate on controversial subjects is good for either the individuals involved or society as a whole.
Negating the first is Animal Farm. Negating the second is the Panopticon.
In criminal law, that used to be the norm.
Right now we take ideological issue with statements of candidates past preachers or professors. Imagine when a simple leak will spill every horrible thing a candidate said during their teenage years to friends on Facebook messenger or aim. It will be a lagging indicator of privacy policy, but one that stands to influence American politics in a couple of decades.
So I doubt this kind of leak will have a significant impact.
It's a bit funny, I regularly argue for youth rights, but standard "for the children" arguments are purely rights-restrictive.
I can't imagine that will work out well for them :(