At this point, technology has enabled this sort of behavior at mass scale, now revealing far more personal and useful information about individuals.
A feasible model to work from may be go look at the healthcare industry and HIPPA requirements/liabilities and adapt as needed. Certainly not perfect but it's a good starting point for widespread data laws.
The question is, will our representatives actually give teeth to real data protection legislation (not a facade with no teeth only enacted by name) in the US or are they too deeply in bed with industry that they'll protect business rights over real people who suffer real direct damages.
I believe US govt will always be at the mercy of corporations.
Now some things are great. Like CCPA, California’s version of GDPR. But getting it accepted throughout the US is a mammoth task.
I have hope though.
Why not ban targeted advertising altogether?
Targeted advertising is like the difference between spam and spear phising. The person being advertised to rarely (if ever) benefits.
Of course the abuses are also plentiful and dangerous. We probably do need a lot of regulation. But in general targeted advertisement is a useful thing to have.
This, like TV, doesn't require tracking of individual people who haven't consented to such.
That's a stretch. How do you think they determine any information about the "known" audience? Obviously, they do all sorts of research to determine more about the audiences watching certain shows and channels, likely by sifting through social media, show reviews (IMDB, etc), and elsewhere to determine who's watching what shows, then looking into their profiles to determine their interests. Aggregate that data, find what they all have mostly in common, and cater to those interests. It's just a more generalized and difficult process of the same thing, and eventually it's going to become more narrowed and specific to individual targets.
I can also have a discussion with my friends about My Little Pony and how amazing the last episode was without an algorithm picking that up, unless I publish it to the world or explicitly send it to the advertiser.
Instagram has gotten so good at targeting me that I probably click on at least 1/2 the ads because I find them interesting. I've purchased things because of those clicks too, and have enjoyed the purchases. Things I would have never known about were it not for the ads.
And so targeting didn't work!
Yes, "targeting" can put stuff in front of your eyeballs that may occasionally have marginal utility, but for sales? Nu uh.
In the baby/bathwater metaphor, you saw some ads for strollers. Still no baby.
Ads targeted to an individual without that individual's consent should probably be banned. In addition, the law should make it clear that when a company does hold data about individuals, the individual should have some rights to that data including the ability to block the sharing or transfer of that data.
So, when Google buys FitBit, every user of FitBit should have to explicitly opt-in to their data being transferred to Google.
If you want to inform me, just give me a website I can visit where I can enter my needs and provide perhaps some context information, and which deletes/forgets this information when I leave. There is no need AT ALL to figure this info out behind my back.
For software, it feels like we're only at the beginning of understanding the dangers and consequences of the software, business models, and technology our industry has created. Unfortunately, if it follows the same path as other engineering disciplines, we likely will experience decades or centuries of bloodshed before it is regulated appropriately.
No. The majority of them don't even understand what data is being collected, how it can be used, or the technology behind any of it. Until the people in office change, the idea that our representatives can or will protect us is toothless and spineless.
In fact I would say that it's impossible to expect anyone to understand enough to know what they're legislating. Aside from being a powerful libertarian argument against the excessive involvement of government, I think it shows that we have to figure out a way to work around the fact that congressmen don't understand everything that they're in charge of, rather than trying to remedy it.
I'll leave you to find your own references to get a detailed picture, but in short two basic forms of organizing do a lot of the work: big teams/staff for each congressman to help out, and special interest committees and caucuses. On top of that at least some take the idea of "representation" somewhat seriously, so if they need to know about a topic they're not experienced in, they tend to meet with supposed experts in those topics (which can come from a dedicated pool, lobbyists, state university department, and occasionally private industry owners or high level employees) for information and sometimes policy recommendations.
The only way to make these chameleons (pretend to) care about an issue is to make the general public (aka voters, source of their wellbeing) care about the issue.
I mean, I already request credit reports for my husband without issue, for example (with his permission! - he finds it much easier to just ask me to do those things for him rather than doing them himself).
In this case, since email address is part of the report they could only send the report to the email address on file for "security," which would be a big improvement over what the big three CRAs are doing with annualcreditreport.com.
A bank makes a lot of money, but in theory, it's doing an important job which benefits society. That job is independently assessing creditworthiness. Of course, it's hard to assess creditworthiness if you don't know if someone is making a lot of loans at different places. So, there needs to be a system for credit monitoring. But credit monitoring is not credit rating. Credit rating is the one job a bank is supposed to do. Letting someone else do it undermines the whole purposes of the independent financial system. We might as well just dissolve the banks and move to a centralized planned economy if that's what we're doing, so that at least the centralized rating agencies will be democratically controlled.
So, to begin with, CRAs shouldn't exist and undermine the basic purpose of the financial system. On top of that, they are incredibly incompetent and corrupt as seen by the Equifax breach. It was clear in the early 2000s that the old system in which people would present a few pieces of relatively obscure personal identity to open a line of credit was no longer workable because the data was now subject to trivial duplication. Instead of fixing this, the industry created the concept of "identity theft" in order to falsely shift blame onto an unrelated third party.
I "had my identity stolen" a few years ago. The event had nothing to do with me, so all of the language around this is wrong. What actually happened was first a criminal learned some information about me, then Verizon chose to give the criminal a line of credit on a cellphone, then the CRAs reported that I was profligate to anyone who asked. Saying "my identity" was stolen makes it seem like I was somehow a party to any of this. "My identity" is not a property of mine; it is a property of the reliability of the CRAs' data. What actually happened was the CRAs had their data polluted by the combination of a criminal and lax identity checking at Verizon, and then the various guilty parties forced me to do their data cleanup for them.
What should have happened in the mid-00s was that the credit monitoring agencies, created systems where you can prove your identity to a notary public and get some sort of signed certificate gizmo that you can use to get a cellphone or make a car loan. But because the whole US financial system is corrupt, it instead outsourced all of the liability onto consumers.
Say you open a credit card, then try to say it wasn't you..... what would a bank need to do to prove it was you? The things they would provide are already the things they have... your signature, your information, etc. What EXTRA bit would they start collecting that would prevent fraud?
Currently, banks ARE on the hook for fraud.... if you dispute fraudulent credit opened on your behalf, they have to eat the cost.
I don't quite see what the difference would be in this alternative world... currently, someone applies for credit, the credit issuer decides it is legit, and issues the credit. That would still be the same. Say it was fraudulent; the fraudster doesn't pay it off, so the issuer tries to collect... at that point, you say "hey, I didn't open this credit!"
Well, the issuer is going to say "yes you did, here is the information I have saying it was you"... how would that be different in your alternative world? Maybe you would require more verification steps... but what? Picture of you holding a sign saying you signed up for the credit? Video? What could you possibly provide that couldn't be faked for fraud? What could the issuer require?
At this point, things are no different than now. The issuer says it was you, you say it wasn't, and then someone has to arbitrate and decide who was correct.
I guess I just don't see how we can do it better (although I would LOVE to do it better!)
A) you have money to keep a lawyer on it; No problem.
B) you don't have money for a lawyer; Tough shit.
Nothing beyond real unilateral enforcement of the system already in place is required.
In the history of central planned economies, never have they been “democratically controlled.” Despite the name, places like the Democratic Peoples Republic of Where-ever are never democratic nor are they republics.
> because the whole US financial system is corrupt
Is that actually true or just hyperbole?
Note that I never joined the club, so my theory of the unwritten rules is pure speculation. No one ever sat me down and said, "Look, son, this is how it is..." But I did spend ten years of my life on this, and during that time I accumulated a lot of evidence that I have a very hard time explaining in any other way. It eventually led me to a serious existential crisis.
BTW, it's not just the financial system. Academia is corrupt in much the same way, and in that case I did join the club so I can speak to that with some authority. That experience is one of the things that allowed me to recognize what I was seeing in the financial industry. But both academia and finance are centuries-old industries. They have become very skilled at hiding their corruption from prying eyes, and a big part of the strategy is making it appear that anyone who accuses them of corruption is a crackpot. (Which is, of course, exactly what a crackpot would say, and that, too, is part of the strategy. It's a horrible catch-22.)
So you have to decide whether to believe me or not, whether you think I'm a crackpot or not. Before you jump to a conclusion I invite you to look up my record. My life is pretty well documented on the web.
How would you define it?
Order a Big Mac - does it look like the ad? Probably not. Drink a Cola, does it feel like your life has turned around, probably not. is advertising dishonest - of course, but we all know that and we learned to deal with it. Is advertising corrupt, I would not say that.
Thus for something to be truly corrupt it needs to go beyond a certain level of illegality.
There are plenty of small banks and credit unions out there thus the point that you cannot open a bank is not quite valid. Are some of the rules onerous, probably. Are some of the rules unfair and ridiculous, probably ... does it mean it is corrupt I don't think so.
The cost to consumers of financial corruption runs into the many billions of dollars.
> There are plenty of small banks and credit unions out there thus the point that you cannot open a bank is not quite valid.
I did not say that you couldn't open a bank. I said that if you tried you would see firsthand evidence of the corruption of the system.
The problem is not that the rules are onerous. The problem is that the rules are not applied evenly and transparently.
Of course not. Never are, again you are not saying much here. Also with the billions of wasted dollars. Of course, but that is a natural consequence of dealing with immense scope - it is going to be very inefficient and stupid. Still a far cry from actual corruption.
I feel that people tossing around the word corruption don't really understand what it means and it is a hyperbole - only undercuts the message.
A bit like the Soup Nazi in Seinfeld - he is not really a nazi in any shape or form - don't even mention real nazis in the same context.
I see. So your position is: I "don't really understand what [corruption] means" -- but you do. And because you possess the true understanding and I don't, nothing in my personal experience can possibly be evidence of corruption because you alone possess the true understanding.
Have I got that right?
> > The problem is that the rules are not applied evenly and transparently.
> Of course not. Never are
This is normalization of deviance. It might be true that the rules are never applied evenly and transparently anywhere and never have been, but it is one thing to posit this as a fact, and quite another to dismiss it as being inevitable (and hence acceptable) by saying, "Of course it's that way." No, it's not "of course." It's corruption, not just because the rules are not applied evenly and transparently, but because this is done by a group of powerful people for their own benefit at the expense of everyone else. Its inevitability is a self-fulfilling prophecy. By accepting it, you have made yourself part of the problem.
hence the logical and reasonable assumption that the poster is misusing the term, obviously I can only comment on what is stated here,
It is so hard to put into words how these systems are corrupt, because these systems create an enculturation / religion around themselves. By the time you see how the entire system works, you are powerless to simplify the mechnications that make that system corrupt (if you even choose to recognize the corruption). You can't "just start an alternative," because the system exists at a local maxima and will crush your alternative or assimilate it into the existing system.
When people are taken advantage of by these secular religions, it is so normal and engrained in the societal fabric that we almost don't have the language to expose the fundamental dishonesty and fraud of these systems. Victims will say that there may be some bad actors at the edges, but on the whole, "this is the way it's supposed to be."
Right -- and really, that should be some class of negligent libel on behalf of the CRAs.
Even small regional banks have their own internal credit rating algorithms. Credit ratings from CRAs are generally consumed either in aggregates (a buyer on the secondary markets wants a traunch with an average credit rating of X) or by less sophisticated parties such as landlords.
I don't have a business relationship with any CRA. If they have my e-mail it isn't because I gave it to them intentionally. Nor is it guaranteed that they have a valid email that I still control.
The situation has gotten slightly better recently because of the widespread deployment of chip cards, but these only protect POS transactions. They don't help with e-commerce or non-financial transactions like credit report requests.
One requested a copy of a photo ID or passport and were happy to accept a partly redacted copy with 'FOR PROOF OF ID ONLY - (company), (date)' over-typed on the scan in red.
Another requested I email them from an email address they had in their records, or log in to change it and resubmit the request.
Most of the others sent the data without any ID checks whatsoever.
Curiously the one who did the most ID checking used an exemption (I forget the specific GDPR Article number) to redact nearly everything which wasn't shown on their web portal. Their position was that "revealing this data (specifically messages on trouble-tickets and their staff's internal notes) would adversely affect the privacy of our staff".
Amusingly I could just log into their portal and view the trouble-ticket history (but of course, not the internal notes). I can only assume their refusal was because there were comments in the internal notes (on my or other tickets) they weren't comfortable disclosing.
My goal was to make certain that if it leaked, the overtyped expiry date should make it useless after a certain point, and the company name should make any company other than that one question the source.
As a side effect, it'd also clearly identify the source of any leaks - but that wasn't my primary goal.
I moved the text so the name and address (which they already had) and date of birth (which isn't really a secret) were clearly readable.
>As a side effect, it'd also clearly identify the source of any leaks - but that wasn't my primary goal.
Wouldn't a malicious actor just add block text over your text saying "only for identity verification for SomeOtherCompany" ?
They could do the same for the expiration date, although I wonder if any company actually bothers to check the expiration date
Wow. They didn't mail it and require confirmation of receipt, they just required a (trivially forged) mail with that email address in From?
more likely just following an established policy that applies to all such information, to take personal judgement out of the equation. almost certainly absolutely nothing to do with your “file” in particular.
so our email providers can get all this data? They can DKIM sign such a mail and simply never have the relevant emails show up in your emails.
https://www.theregister.co.uk/2019/08/09/gdpr_identity_thief...
* Scan of ID
* WebID - video call where they take screenshots of ID and your face
* Cookie - kind of makes sense since 3rd party web trackers Quantcast rely on cookies to identify
The victim might be able to sue for damages incurred by the identity theft.
In my experience, some companies place high dilligence on the process. A bank I requested information from sent a postal letter containing a code to my mailing address. The Germany Postal Service has a special service to allow identifying people, so the letter contained the code and then I had to bring part of the letter back to the next postal station along with my ID card.
Once they got the confirmation of the ID card along with the code sent to me, they sent a CD-ROM with the information encrypted and the password via mail.