EU launches probe into Google-Fitbit takeover
bbc.co.uk
bbc.co.uk
This is THE most problematic part.
I am trying to make people understand this match made in hell for last 20 years and it has finally started to happen.
People will finally start to pay for their open sharing of their lifestyle and this is just the beginning.
Really, really bad.
Maybe we as a society want to rather "subsidize" or "protect" unhealthy individuals by giving them money for higher premium insurance rather than hiding the actual cost of their healthcare by making it illegal for insurance companies to deny them based on their unhealthiness. To me that seems like a better, more explicit and transparent model that doesn't rely on physical reality being "hidden" from the people determining the cost of your insurance, even though we all know that unhealthy people cost more to insure because they have more health issues.
People with more problems pay more to get insurance because they cannot afford not to. Insurance companies are not run at-cost.
By giving them more excuses to scrutinize your lifestyle, you are just exposing yourself to the risk of them, one day, objecting to anything in it to raise prices on something you cannot afford not to pay.
On the face of it, this doesn't seem terrible. It encourages people to stay active. So far it seems to be limited to an airmiles-type scheme where you can get bonuses like Amazon Prime for free if you meet certain fitness targets. With Vitality you would need 5.3 points a day (160/month) - you get 5 points for 10k steps so you actually have to exceed that every day.
The problem with these systems is that the incentives are poor relative to the amount of effort you need to put in. Amazon Prime is nice, but it's valuing you exercising daily at around £8/month. If you can afford Vitality in the UK, either you're already well-off or you work for a company which can afford it. Why not offer free fitness club membership if you go regularly?
The other issue is that tracking workouts sometimes fails, and you lose your bonus. That sucks and it's an easy way to lose people who can't be bothered to put in extra effort to make up it (for the sake of £8, for example).
Probably we'll go to the automotive model (black box trackers). Some insurers will offer lower premiums to people who can demonstrate they're healthy, others might refuse people who don't submit their data, and others will charge a bit extra, but not require it.
Be careful viewing this with a US lens. In Europe even in countries like Switzerland where you need private "public" health insurance there are strict minimum requirements. Insurers can't refuse you for pre-existing conditions, there are mandatory caps on premiums/deductibles and certain expensive treatments like cancer therapy must be included. Most people don't need health insurance because it's provided through the state.
[1] https://www.vitality.co.uk/rewards/partners/active-rewards/
The industry in Europe pushes for adults being treated like schoolchildren. In Germany the polite form "Sie" (you) is universally replaced by "du" (thou), which formerly was reserved for children and friends.
Websites are infantilising people with their cuddly pre-school logos and childlike names.
Google concerning Fitbit: For its part, Google has explicitly denied its motivation is to control more data.
To organize the world’s information and make it Alphabetically accessible and useful.
but I still feel they have a lot of interest in organizing all the world's information.
According to the article they made the same promise about Nest, but have begun "asking" users to merge their logs.
Nest heavily prefers using a Google account now and integrates with using a Google Home's "household" members for giving access to your nest home.
1) They don't support GSuite accounts, and Google Home doesn't support linking other accounts when your main account is a GSuite account, and
2) They've shut down all API access to them (people still on old Nest accounts are grandfathered in... for now), so even if I did manage to set it up on a separate non-GSuite Google account, I wouldn't be able to monitor them with openHAB.
I do like them, especially how it warns vocally shortly before it's about to go off, so I can preemptively temp-disable it before it deafens everyone just because I'm cooking and forgot to turn the hood fan on. And the motion-activated nightlight is perfect (there's one in my bedroom right near the entrance to the bathroom). But Google's product support strategy here really makes me uncomfortable, so I'll probably end up replacing them.
The reasons not to want Google to take over Fitbit go beyond Google's control over data.
The above statement from Google only refers to a specific subset of data that Fitbit collects: "health and wellness data". Moreover, it only refers to a single limitation: use for Google ads. Any non-health and wellness data can be used for any purpose. Any health and wellness data can be used for any purpose except Google ads.
Consider an alernative statement such as: "We will only collect and use data for the purposes of providing the services, i.e., health and wellness services." This eliminates the loopholes.
From Fitbit's current privacy policy, below is a list of the Fitbit data. As one can see, most of this data is arguably not "health and wellness data".
When viewed in isolation, some of this data might seem routine and innocuous. However when combined with all the personal data Google has collected and obtained from other sources, including other Google devices or services a person might be using, the Fitbit data could be quite useful in profiling users.
Of course, in the future Google Fitbit could collect more data than what is listed here. It depends on what Google chooses to do with the devices and the services going forward.
1. Account data
(required:) name, email address, password, date of birth, gender, height, weight, and in some cases mobile telephone number.
(optional:) profile photo, biography, country information, and community username.
2. Additional data
(optional:) logs for food, weight, sleep, water, or female health tracking;
(optional:) an alarm;
(optional:) messages on discussion boards or to your friends on the Services.
friends' email addresses, friends' social networking accounts, contacts in the contact list on person's mobile device.
(in the case of a survey, contest, or promotion:) name, contact information, and message.
3. Payment and card data
(for certain devices:) name, credit, debit or other card number, card expiration date, and CVV code.
a token containing the last four digits of your card number and your card issuer's name and contact information
(for purchases of Fitbit merchandise via their website:) shipping address
4. Live coaching data
(if the person uses live coaching:) the plan, goals, and actions the person records with the coach, calendar events, communications with the coach, notes the coach records about the person, and other information submitted by the person or the coach.
5. Device data
number of steps taken, distance traveled, calories burned, weight, heart rate, sleep stages, active minutes, and location.
6. Geolocation data
precise geolocation data, including GPS signals, device sensors, Wi-Fi access points, and cell tower IDs. approximate location from your IP address.
7. Usage data
usage or network activity information, for example, when the person views or searches content, installs applications or software, creates or logs into account, pairs device to account, or opens or interacts with an application on the Fitbit device.
data about the devices and computers the person uses, including IP addresses, browser type, language, operating system, Fitbit or mobile device information, device and application identifiers, referring web page, pages visited, location (if settings allow), and cookie information.
8. Data from 3rd parties
(if person connects FitBit account to an account on another service, e.g., Facebook or Google:) name, profile picture, age range, language, email address, and friend list.
(optional:) exercise or activity data from another service.
(in the case of employers and insurance companies that offer Fitbit Services to their employees and customers:) name, email address, or similar information (like a telephone number or subscriber ID)
Wouldn't this be more like saying "if you do this, we will make things painful for you"? Am I completely missing something here?
My guess is Google/Fitbit could only proceed without the EU's approval if Fitbit stopped operating in Europe and deleted all Europeans' data.
In short, this acquisition is already harming everyone, and the EU is trying to prevent the most consumer harm.
I think most of the terminated services were fairly predictable (i.e. North)
Without knowing this, there's no safe bet in buying a Fitbit right now.
To be fair, that's generally how law enforcement and regulation enforcement usually works.
to the point that it may end up having some countries treating fines and such as tariffs of a sort.
If Google doesn't want to do business in the EU then EU has no say in it.
Google Ads policy: "“Google Entity” means Google LLC (formerly known as Google Inc.), Google Ireland Limited or any other Affiliate of Google LLC"
Fitbit Privacy Policy: "Fitbit International Limited, an Irish company, is your data controller and provides the Services if you live in the EEA, UK or Switzerland"
So, the EC has teeth they can use to enforce here - but more importantly google also wants to minimize how much they piss people off. Hence a PR stance of "Hey, we're sorry you feel that way - is there anything we can do to make this go away faster?"
1. I'm not saying this is likely or makes any sense for this particular probe.
Paranoia claims suggest unfounded concerns but Google's misuse of private information is well known.
The accusations are certainly well known (https://en.m.wikipedia.org/wiki/Privacy_concerns_regarding_G...).
Whether anything here constitutes misuse is a matter of both personal opinion (yours being very well known of course given your thoughts and comments about Google) as well as various laws but that doesn't make any of it a universally accepted truth or standard.
In my case I'm much more worried about security than privacy, and far more willing to trade off the privacy (more targeted ads) for the increased security - Google's infrastructure is way more likely to be properly secured vs. Joe Random wearables startup, or even Garmin, as a recent example...
There are economies of scale to security just like with anything else.
[0] https://www.washingtonpost.com/technology/2020/07/31/google-...
See https://www.androidauthority.com/blue-mail-play-store-114347...
This is called an "oops". Mozilla is well aware of how Google "accidentally" harms other companies repeatedly to gain an advantage: https://www.zdnet.com/article/former-mozilla-exec-google-has...
They might not use it maliciously today, but they could create a pretty good clone given the details of your life they have collected and continue to collect.
I want to ask the inverse of this question. What can Google do to make you comfortable with their services while still being primarily an advertising company?
Some ideas I can think of:
1. Delete your data once it is no longer relevant for advertising (I think they already offer an option to delete data after some time)
2. Not sell any data to third party, and make strong claims about this that can be legally challenged.
3. Keep data encrypted so that data breaches or even malicious actors within the company can not access the data.
4. Anonymize user data so that a business who acquired a customer won’t know why a {name, shipping address, product, price, credit card, email} was targeted for this advertisement and was successfully converted to a sale through that advertisement.
5. Not offer suggestions/data/feedback to advertisers on how to exploit vulnerable target audiences (Example: help Casinos target gambling addicts 5% more efficiently by doing X,Y,Z changes)
6. Build a track record of legal challenges and pushback against governments to show that when they claim that data is deleted, it really is deleted.
I am not sure how many of these Google already has done - but if they are doing any/all of this, they aren’t being loud enough about it. If one has to read through 200 pages of terms and conditions to determine what they do, people will just assume the worst and be paranoid.
The entire point of advertising is to emotionally manipulate people into making purchases. Targeted advertising requires gathering and abusing data about people.
If they wanted, they could create or destroy businesses based on the data they have. Let's say they want to create a competitor to a small pop-corn stand. They could see the profiles of all people who go to that existing stand and make it look like something they wanted (eg. based on their YouTube history). They could check the paths they take daily, or the route they take to that stand and put their own in a better spot (eg. based on location history). They could only open the stand or promote it when people are really craving, for example after work or after a gym workout (eg. from the Fitbit data).
You get the point, the idea is that once you have all those insights into a mass of people, you can easily control them into buying your product or doing what you want them to do, while they think it's their idea to do that.
In general, people are very easy to influence. If I just mention the words "FIFA 20 on PS4", you are very likely to have all those thoughts about gaming and maybe actually want to start playing FIFA, even though before you had absolutely no intent to do so.
I like the idea of tracking stuff for myself, but it doesn't seem possible without evil cloud at the moment. Maybe with apple watch?
With Fitbit you also get heart rate, active times (gym, sports), combined with the optional phone-enabled location you can know person X goes to gym Y twicer per week and spends 1 hour doing HIIT. You can also get data such as sleeping hours, sleep patterns, at what floor a person lives or works (if he climbs the stairs).
I mean, there is "corporate talk" but this is on another level.
Not with that wild period ruining your grammar! Grammar is important to corporate doublespeak
on edit: although, really, bad grammar is important to corporate doublespeak as it lends an element of plausible deniability when you get called in front of committee.
System Preferences > Keyboard > Text > Add period with double-space (disable)
... the soul of <pause> a weasel.What it’s saying is that Google would desperately love to use the US‘ anti-trust standard of concentrated market power being a-OK as long as consumers aren’t obviously being hurt right that second rather than the (better) European standard of considering the prospects of competitors and potential competitors as well.
Advertising is already creepy enough trying to determine when, for instance, someone is pregnant via related purchases (and sometimes guessing correctly ahead of the person's own knowledge, per famous anecdata), just imagine how much more creepy it can get when it is data being sold to advertisers from your own wrist?
Google already pledged not to use user health data for ads:
https://www.reuters.com/article/us-fitbit-m-a-alphabet-eu-ex...
It's just acknowledging the situation, beyond that it's not deceptive or anything IMO.
"I'm happy that the IRS has selected me for audit. I am eager to assist them in their efforts to evaluate whether I have committed a wrongdoing. I love spending money on lawyers."
I don't know what folks want in a news bit about this 'OH WOE IS ME?!?!'
> on an approach that addresses consumers' expectations of their wearable devices
Parsing word by word generic corporate statements seems pretty silly at this point.
But for some reason, it's especially susceptible to specific triggering topics that cause complete forfeiture of critical thinking ability and intellectual honesty among a big chunk of the commenters (and voters).
There are plenty of valid criticisms of Google, but criticism is worthless if it isn't based in at least an attempt at intellectual honesty.
But it doesn't mean they don't have the corresponding data.
Edit: as per comments, Apple Watch data is encrypted. But fitbit data isn't
[0]: https://support.apple.com/guide/security/cloudkit-end-to-end...
[1]: https://support.apple.com/guide/security/icloud-keychain-rec...
From our writeup: "So what are the benefits for companies and insurance firms? Fitbit Health Solutions (FHS) provides a platform that offers insights and guidance to make employees healthier. But the benefits go beyond health. The FHS platform can improve productivity, reduce on-job stress and accidents, detect causes of absenteeism, and improve job participation.
The company has already released a premium membership subscription for enterprises and customers, especially since the release of its Versa 2 watch."
https://www.medgadget.com/2020/02/fitbit-health-solutions-in...
"We appreciate the opportunity to work with the European Commission on an approach that addresses consumers' expectations of their wearable devices," blogged Google's devices chief Rick Osterloh."
Let me translate that, for those who don't read between lines yet, as I am fluent in corporate BS lately due to a project I'm involved. Here it goes the translation:
"We're giving exactly zero f*s about your inquiry, and we will do 100% to actually BS you all the way to December, while making you look good in front of your European constituents. Also we'll definitely try to bribe anyone in your committee if, by mistake, they actually will try to do their job."