Doom Eternal Privacy Policy Allows Collection and Disclosure of Medical Records
wrap.bnet.idtech.services
wrap.bnet.idtech.services
There are categories of data per the California privacy law. This is a whole category called "Consumer Records" and because they collection some of it in this category they have to declare the whole category.
Tons of companies do the same - 4M for example:
https://www.google.com/search?q=paper+and+electronic+custome...
The statement is essentially meaningless. Which is bad, because if there is a bad actor out there collecting your medical information, they've got the cover of this law to disclose it to you and not look bad because everyone else is disclosing it just to cover their asses.
It just seems like a badly written law when a video game feels like it has to add this stupid disclaimer.
I am not a lawyer, but I think it is reasonable to assume that this when drafting the law, law makers had to:
- Choose a set of categories that were not to broad and not too narrow, and optimized for reader interpretability/clarity
- Mandate companies to use standard descriptions of these categories in order to prevent them from obfuscating what it was that was being collected.
It's sad to me how many people here immediately assume either malicious intent by iD or incompetence by their lawyers as the only possible explanations. Making something that is widely applicable, easy to interpret, and is meaningful isn't an easy task. Thats not to say that these categories are perfect, just saying there's not an objectively "right" answer.
In my defense, having lived on this corporate controlled earth for some time now, I do not think it is unreasonable to be at the very least mildly suspicious. Quite the contrary. The default approach should be cynical.
edit: Frankly, deeply cynical.
The "Consumer Records" category of data includes things like name and credit card number. So if doom eternal wants to be able to sell DLCs (a perfectly legitimate and not privacy invasive business model) then they also have to disclose that they may collector medical records.
I doubt Id software actually collects medical records, and I have no idea how they might go about that or what a game studio would do with that information. It's just something they have to say by law since they handle credit card info.
I think the parent meant profiles within the game representing players, and chat within the game between human players.
If your understanding instead matched mine, I don't understand your comment.
The category that includes medical information is "Customer Records", which is:
> paper and electronic customer records containing personal information, such as name, signature, physical characteristics or description, address, telephone number, education, current employment, employment history, social security number, passport number, driver’s license or state identification card number, insurance policy number, bank account number, credit card number, debit card number, or any other financial or payment information, medical information, or health insurance information
If they collect anything that falls in that category, they have to say "yes" to collecting "Customer Records".
Similar for most of the other categories they list. Your web server logs accesses? That's a "yes" on "Usage Data". You keep a list of purchases by each customer? "Yes" on "Purchase History and Tendencies". Oh, those web server logs probably have IP address, which gets you a "Yes" for the "Name, Contact Info and other Identifiers" category. Do you record support calls? "Yes" on "Audio, Video and other Electronic Data". If you use an IP to location mapping service, that might get you a "yes" on "Geolocation Data". Try to deduce things like what kind of games someone likes from their purchase history--"Profiles and Inferences" gets a "yes".
BTW, there are some categories that they have not listed: "Biometric Information", "Professional or employment-related information", "Protected Classifications", and "Education Information".
I'm kind of surprised "Protected Information" is not listed. You get a "yes" on that if you collect age. I'd have expected a gaming company to collect that.
The CCPA requires disclosure at the "category" level (https://oag.ca.gov/privacy/ccpa#collapse1d). The categories appear to be (https://reciprocitylabs.com/resources/what-are-the-ccpa-cate...). You can see that in that table, medical records are lumped under customer records category.
"Please use the original title, unless it is misleading or linkbait; don't editorialize."
https://news.ycombinator.com/newsguidelines.html
If you want to say what you think is important about an article, that's fine, but do so in the comments. Then your view will be on a level playing field with everyone else's.
https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu...
Is this not allowed? Usually I actually appreciate it when the link goes straight to the primary source in these cases rather than some intermediate news site.
edit: maybe I'm looking at an edited title?
On HN, being the submitter of an article doesn't confer any special rights to frame it for everyone else. That's why we ask people to express their opinions in the comments rather than the title. HN readers should make up their own minds about what parts of an article are important.
It's true that this policy can't just be applied mechanically and that there's room for nuance. In this case, though, the argument that reverting the title makes the submission a non-story is actually accurate. If the responses in the comments are correct, then indeed it is a non-story.
or this one: https://twitter.com/paulg/status/1282052801347100675
It's not editorializing. It's framing a discussion of a certain part of a web page that is not an article by using a title that is a factual statement about said web page. The obvious "workaround" is to publish some low-effort tweet or blog post or whatever, which further muddies the waters re: the other "guideline" which says you should submit primary sources if possible.
I get wanting to take a hard line on titles, but I think the "guideline" as written is confusing. The bit about editorializing should be taken out, to make it clear that actual editorializing isn't precisely what's prohibited.
If people start making tweets purely to put their spin on an article, HN users will probably notice and flag the post. I mean, who knows. People are welcome to try. We're not trying to stop anyone from expressing their view—but most of the time it's cheap and inflammatory when someone hijacks a title to do so.
Title dynamics are fascinating. It used to irritate me that people place so much importance on titles, but eventually I got it. One way of looking at it is, it's a power law: the first 1% of information in (let's call it) an article stream has 90% of the importance. Poof, now it makes sense why titles are so impactful. I suppose that many power laws seem paradoxical when not recognized as such.
I'm simply taking issue with the word "editorialize" in this context, because that's not what this is. There is no "spin" here. This title is solving the same completely innocent problem I'd have if I wanted to submit a link to apple.com after a new $PRODUCT was announced, i.e. that the interesting thing about the linked web page isn't obvious if my title is just 'Apple'. It's fine if HN doesn't want me to title that submission e.g. 'Apple Announces New 24" MacBook Pro', but that can't be because it's a case of editorializing, because it isn't. This does not strike me as substantially different.
I feel like you think I'm saying non-neutral editorializing and framing should be allowed in titles, which is absolutely not true.
I suspect most courts would consider a video game the very height of an optional activity - which would make it hard to suggest a contract, regardless of how onerous, would be something the person was "forced" into.
I'm not as worried about them collecting that data directly from me, but rather cross referencing the data they have on me, with other paid-for data sources, which would give them that information.
The preceding paragraph explains:
"Categories of Personal Information We Collect and Disclose. Our collection, use and disclosure of personal information about a California resident will vary depending upon the circumstances and nature of our interactions or relationship with such resident. The table below sets out generally the categories of personal information (as defined by the CCPA) about California residents that we collect, sell, and disclose to others for a business purpose. "
Bought Doom Eternal on the steam sale just recently and found this:
"Customer Records: paper and electronic customer records containing personal information, such as name, signature, physical characteristics or description, address, telephone number, education, current employment, employment history, social security number, passport number, driver’s license or state identification card number, insurance policy number, bank account number, credit card number, debit card number, or any other financial or payment information, medical information, or health insurance information."
This is explicitly listed as collected and disclosed
They also list browsing history:
"Usage Data: internet or other electronic network activity information, including, but not limited to, browsing history"
https://www.google.com/search?q=%22or+any+other+financial+or...
Motel 6: https://www.motel6.com/en/app/privacy-policy.html
Ritz-Carlton: https://www.ritzcarltonclub.com/privacy-ccpa.shtml
Starz: https://www.starz.com/us/en/privacy
Papa Murphys: https://www.papamurphys.com/privacy-policy
Somehow I doubt it does, though :/
Microsoft got a lot of hate (some deserved, some not) for pushing the Microsoft Store and UWP as a potential game distribution platform (originally with some exclusives from the Xbox side of the world), but for all its faults, it used sandboxing.
Perhaps the solution here is not to do personal/sensitive work on gaming machines, but then we're right back to having separate game consoles...
Perhaps an ideal scenario would let a player choose whether or not to enable a game's anti-cheat, but that it'd be required for certain matchmaking and (obviously) competitive features. So that I can opt out if I'm just trying the game casually or just playing with friends in a private room, but can enable it if it's something I intend to play seriously and am invested in enough to give deep access to my system?
The main weakness (other than code vulnerabilities) is the network: it's very difficult to guarantee that a remote computer is running the allowed OS & game code, and not a hacked version. However, technologies like Intel's SGX x86 extensions can make this possible: because of the added encryption in the core CPU, one machine can send a cryptographic challenge to another one, and it can only respond correctly if the remote CPU has validated the code it is executing.
So, the tech is there. But in reality, people really don't want to lock down their PCs so securely and effectively give full control to their OS vendor.
But, it could upload "suspicious" data to the home servers to be evaluated and fed into the signature database. Just like any other feedback loop in anti-cheat (and anti-virus) systems, only this one can access everything on your system.
So, yeah, they may have very well collected that data from your hard drive.
EDIT: Brain flatulance, s/DRM/anti-cheat/g
It's probable that Steam would not be remotely as successful if it interfered with DRM and anti-cheat strategies on privacy or security grounds.
It's why Sony's rootkit DRM (got it right this time) was so poorly received a decade and a half ago - because you, as the computer's owner, can't control what it does or isolate its access.
How is this normal or even in the realm of being accepted AND defended?
It's almost as someone planned to make it hard to read!
The only things that might make it a little harder for some people are one of them used green text on a black background, and for both of them if you browser window is wide the lines might be a bit too long.
Now this one isn't working for me and the original works.
For each HIPAA violation a company will be fined $10,000 dollars per customer. If ten million records on a database are part of a breach the company can be out of business.
It boggles the mind that anyone would want to take on that liability.
https://www.hhs.gov/hipaa/for-individuals/guidance-materials...
This means data harvesting companies can siphon up this stuff where they can find it. As long as they don't have a particular contractual relationship with an actual hospital, it's just like any other data, and they're not governed by HIPAA.
There may be some other ways to get governed by HIPAA, but that's the general rule. It's hard to do by accident.
They want millions of records with some kind of identifier, and some kind of predictive value. Eg. The number of ice creams I buy might be a good predictor of if I'll be buying diabetes treatment next year.
Without all 3, your data won't be used.
Doom Eternal is not a Covered Entity (unless they're doing something crazy) and would not be subject to HIPAA in any capacity. This is either an overly protective lawyer or in reaction to a different, non-HIPAA data law.
Hoarding customer data should be a liability!
That's why data minimization is so important, only keeping what you absolutely need.
The nature of the beast is that its nature can change. We need to stop thinking software is somehow special, we're just more careless and face fewer consequences following catastrophic failure.
I think it would be more accurate to say every field has figured out how to minimize liability from harm to customers. Data collection makes companies money, and there's little liability involved in most cases if you aren't in the health sector, so they grab all the data whether their core business needs it or not. The health sector needs some data because sharing it is vitally important, and they've shown that it takes a massive amount of time and money and complexity to do it to any acceptable level.
If we had some way to accurately value our data and privacy, and laws that made it the property of the individual, we would see a change very quickly.
So I've kept all that garbage on its own box. It's nicer that way anyway, since I don't use Windows as my daily driver it helps me keep a Windows machine around for other toxic software like Photoshop.
I previously did it in a VM with GPU passthrough, which worked quite well and I think is a decent option for people who can't afford the cost/space of a second machine. Nowadays, thanks to the death of Moore's Law, I had a perfectly capable older machine lying around that I could use instead. That's slightly less maintenance, since the GPU passthrough would occasionally need twiddling after qemu or kvm updates.
EDIT: I will add, for the couples years I was doing GPU passthrough, I didn't notice any difference in performance compared to when I moved the same GPU over to a physical box. In fact, there was this weird audio bug that I originally thought was because of the VM, but it persisted on the real machine and turned out to just be a bug in NVidia's audio driver. So besides the maintenance burden, GPU passthrough was great.
I do the same, I bought my box from Sony, it's called Playstation 4. Never had to worry about driver updates, incompatible games, sanboxing, anything. 5/5 would recommend.
It's not just the resolution, but the actual graphics/rendering capabilities are substantially better: shadows that accurately match the shape of what they're cast from, high detail even on distant objects, faster response to control input, etc. It makes such a difference in how immersive the games feel, which is a big deal for me. Going from Witcher 3 on PS4 to all-maxed-out settings at double the framerate on my PC was like night and day. IMO, you just can't go back. (comparison here for example https://www.youtube.com/watch?v=Wo5Nh9am3RM )
I spend a huge percentage of my time in games just exploring and looking at stuff, appreciating the immersive nature of the worlds people have crafted. This is even more rewarding now with a nice gaming PC setup :)
The same goes for very fine particle effects or extremely high resolution textures. You just won't notice it. That is not to say those things don't have a place, they are amazing and definitely look amazing at the close distances one sits from a PC monitor. Its just not an apples-to-apples comparison.
I also feel that past 60Hz+FPS, the higher numbers bring very diminishing returns, especially for controllers. Although I'd much rather see modern consoles go 1080p120fps than 4k60fps.
[0] https://www.hellotech.com/blog/wp-content/uploads/2019/10/sc...
You do realise that not everyone lives in a mansion? 2m is a fairly common distance from eyeballs to the TV here in the UK.
No driver issues though, but the frequent and sizeable updates are so bad.
After a 2 year hiatus, my Destiny 2 installation (60ish GB) needed to download updates... amounting to 60ish GB. On my current connection, that was a huge chunk of the weekend.
To use the YouTube app, it asks you to associate a Sony app to your YouTube account, that can track your video history (in or out of the PS4) and reserves the right to share videos to your YouTube channel, publicly.
Is the "Unity Analytics" thing? I'm just googling around but I can't find a good summary anywhere.
They also share:
> thermal, olfactory, or similar information such as, CCTV footage, photographs, and call recordings and other audio recording (e.g., recorded meetings and webinars).
I like olfactory a lot.
Once > X number of states have such laws, it will be the right economic choice for companies to make it the default for everyone rather than doing it selectively by state.
:P
So, it's entirely conceivable that this very "covered" data was collected and pushed up to their systems as a part of their "anti-cheat" detection, either from a HD sweep or from in-memory data in other applications (like the browser).
EDIT: Also, not being new doesn’t make it right, moral, or even desired.
They do memory scan, Hard Drive scan, and send suspect files to home server.
Also read the comments, they are really interesting. Especially the Gabe quote.
"Categories of personal information:"
"Customer Records: paper and electronic customer records containing personal information, such as name, signature, [...] medical information, or health insurance information"
I would give ID the benefit of doubt here and say this just boilerplate legal text.
Still, my gaming PC is also my tax PC, and minor projects PC and since I am no longer a kid, I have a lot of information floating on it I would not want other people to know. How is this normal state of affairs?
I will submit request for refund just in case. It might get denied, but maybe they will at least get the message.
I wonder if someone just copy pasted this form without actually reading, though perhaps that is giving too much benefit of doubt.
For example, Blizzard's anticheat software phones home with the title bar text of every open window on the computer. If I leave a browser tab open from my doctor's portal, I can totally envision how Blizzard would end up collecting some of my medical data.
Really sloppy work.