Wait until the BBC finds out how many of us are giving Amazon user data. (I mean, it's s3 and RDS, but that clarification would be overly pedantic)
Wait until the BBC finds out how many of us are giving Amazon user data. (I mean, it's s3 and RDS, but that clarification would be overly pedantic)
Facebook and Google on the other hand make their money from stalking people and developers are giving them data in a nice standardised format.
Amazon is very much the latter and that would seem to provide plenty of incentive to do dig through data / recognize the value / use it as they wish.
I'm sure they do plenty of analytics on data from their own platforms and that considerable effort could easily be extended to include any other data that they have access to.
[1] https://www.geekwire.com/2019/amazon-gaining-google-search-a...
Yet React and Angular are quite popular
they definitely do this for physical goods so i'm not naive enough to think they aren't talented enough to do it digitally.
But I don't think Amazon will try to dumpster dive your encrypted S3 buckets in the process of doing the above. At least, not yet.
Google and Facebook only have advertising; they have nothing to lose by being unethical and/or breaking privacy laws like they do with the GDPR.
Do we know that the privacy policy/terms of service for these services allow Google/Facebook to use the data in the way that the BBC article seems worried about?
And before you say that "it doesn't matter what the ToS says", it does very much matter, breaking a ToS would paint a very big target no these companies, there are tons of lawyers out there that would love to catch companies at this, easy money.
There are thousands of companies breaking the GDPR (Facebook and Google included) and yet I have yet to see the tons of lawyers going after the easy money. Companies keep doing it because they know the regulation isn’t enforced.
Tracking everything you can about your users so advertisers can better target you is evil.
Capturing all the local variables during some unexpected Exception (that might happen to include some user data) for the purpose of debugging is not even remotely evil.
User-data is totally fine to have, it's what you _do_ with it that matters
Unless the user explicitly opts into having that data recorded, it isn't ok to stockpile it, regardless if the intent behind it.
The path to hell is paved with good intentions.
I agree that using user-data outside of some agreement is bad (and illegal under the GDPR), but I believe that an implicit agreement exists between web-server provider and user that their data will be used for the mechanical operation of the website, including logging stack-traces. Otherwise TCP/IP wouldn't work.