But what about following every dark pattern in the book to prevent people from actually opting out[1][2]? There was not even an option to opt-out indefinitely.
It seemed like an extremely carefully engineered effort to trick the users. How can something like this be considered "unintentional"?
(For those who wonder: that and the Buzz incident made lots of people hate or at least distrust Google.)
Why why why do companies do this?
During the last 6 months I've stopped logging into Stack Overflow. It is a nice resource but for me it is read only for now because they messed up so hard - and refused to come up with a real apology.
Same goes for Quora: they betrayed us hard by trying to tell everyone what we were looking at. (Edit: next sentence added later:) Now imagine you've been reading up about health issues and realize it is suddenly on your profile. Still now, many years later I shun them as they haven't as far as I see come clean.
In some cases, if it get caught early enough, just saying: "we messed up, sorry, here's what we will do:" can be enough.
In other cases - where there are layers of bad patterns, lies and contempt for users and volunteers I actively want to punish them until they start behaving.
Quora (broadcasting sensitive information), Google (trying to kill the web, insulting me with insanely misplaced ads for years, trying to kill Firefox), Stack Overflow all goes on my list of companies that I actively work against, but I guess only until I see real change ;-)
IIRC Monica asked if would be OK if she (or someone else?) wrote in a way that sidestepped the whole issue, for example by writing about "the user" instead of "he and/or she".
Again IIRC they leaked information to newspapers, misrepresented the case and issued one or more non-apologies before trying to pretend nothing had happened.
And why it became okay to compel someone to use a certain pronoun as opposed to compelling them to _not misgender_ is absolute lunacy. Monica wanted to write her sentences in a way that did not require pronouns period, and they decided that was not okay. Not to mention all the mud-dragging and character assassination they pulled.
I’m on mobile so won’t dig up the link but go find what Monica wrote on it
And then obviously Monica crowdfunded $25k to sue SE, they came to an agreement and neither party really talks about the incident any more.
There was really no need for the situation to escalate as harshly as it did and SE shot themselves in the foot repeatedly.
If the goal is to run after LinkedIn it seems a logical way to go, but they have a very strong head start on that.
I think LinkedIn is a massively privacy violating service, and alternatives are a very good and important thing to see. I would add one comment though perhaps helpful in the future:
One reason people here take such a vigorous stance against startups doing these kinds of "dirty tricks" is because they want real alternatives that treat them as more than a number of a row in a database. The incumbents will use opt-out techniques and consent walls, and dark patterns to grow.
But at the end of the day, they're being valued by the number of rows in their database. It seems there's a real potential to have lots of (but fewer) rows in your database, but for them to be actual valued users who get value from your service, and you make money from. Hyper growth scaling doesn't always have to be the only way. A curated network of a focused and high value verified demographic is likely worth orders of magnitude more than the incumbent, without any data selling or shenanigans.
And that's saying it gently.
Not sure if they're still doing it, but the way they were harvesting e-mails and then using them to spam the harvested contacts, they were no better than any other phishing site.
For people who use the same password on LinkedIn and their e-mail account, it was extremely easy to accidentally "consent" to this, and I've seen many an apology to the spam victims from someone who accidentally gave access. And they would spam everyone multiple times, with no way for the recipients to stop it. (They paid a $13M settlement for this; gladly, I assume).
It still boggles my mind that e-mail providers didn't both block LinkedIn's IPs from accessing contacts and spam-can everything from their mail servers.
Looking back at my email archives, I was still getting "X's invite is awaiting your response" emails in October 2018, after GDPR began.
Perhaps I am taking an overly strict view here, but given my email address is my personal data, no amount of consent (or indeed waivers/warrants from users that they have my consent, which LinkedIn has no genuine reason to believe true) can grant them permission to store and process my personal data.
It seems nonetheless unavoidable for LinkedIn to have carried out the process of linking my email to the person that sent the (unsolicited) request. This kind of behaviour is really rather scummy. I hope that invite spam could be a separate case on the basis of a GDPR violation, rather than the "accidentally going into people's email and getting their contacts" (as incredulous as it is to even write this!)
Ammon, the big money is going to be chasing cost savings as more remote workforces can now take advantage of overseas labor. The perfect storm of cost reduction pressure and remote workplace growth gives Triplebyte a great position to be the front runner in helping companies find less expensive overseas talent.
IMHO, that's the saddest thing about this. Triplebyte has a niche where they can provide value to companies and job seekers. But producing an objective analysis of someone's coding skills is expensive and doesn't scale well. They could make millions every year but it's not and never would be a billion dollar company. And it's too bad that millions is not good enough.
> The floor has fallen out on parts of our business, and other parts are under unprecedented growth. We've been in a state of churn as we quickly try various things to adapt. But I let myself get caught in this rush and did not look critically enough at the features we were shipping.
In fact that paragraph is what made me accept his apology. The reflection and honest answer of how he decided to ship this feature was more than any company apology I've heard in the past.
"Money got tight, so we decided to monetise your sensitive data!"
Riiiight. You didn't realize how big it was because you didn't care, until it was clear it was going to have a serious negative impact on you. You didn't care about the privacy of others or otherwise you wouldn't have made the choices you did.
Thanks!
- trust is a crystal ball, you can drop it and break it, patch it back together again but it will never ever be the same way it was before, it can only degrade
- if you plan on being a player in this field you will have to take the privacy of your users serious, this includes doing your privacy and security reviews by the book because if there ever is an involuntary disclosure what you've seen in the last couple of days will come back hundredfold.
In my opinion, in 2020, any company that releases software and has more than like 20 engineers should have at least one VP-level privacy approver who has the power to block releases.
Dude, you were going to use us to publicly endorse your new platform via usage and give it immediate legitimacy, without our consent. Don’t you get that’s what “critical mass through public profiles” means? People join because people are already there?
This is probably the post that disturbs me most of what I’ve read, for simply ignoring that the decision was problematic on multiple levels. Either you’re still not completely getting it or this is disingenuous, and neither option is comforting.
And trying to be charitable as possible here, it’s very easy to take your clinical recounting as being cavalier in its precision. I don’t think we’re all necessarily far enough from the situation yet that you should treat it as the distant past when discussing it. You still have my data, at least for the moment, and it’s still an ongoing concern.
Not that it would matter if they were. Other people doing nasty things is no excuse for doing them yourself as well.