Tech companies are profiling us from before birth
thereader.mitpress.mit.edu
thereader.mitpress.mit.edu
Google's Eric Schmidt suggests that young people should change their name upon reaching adulthood: https://www.telegraph.co.uk/technology/google/7951269/Young-...
Of course, a better way may be to introduce new right-to-be-forgotten laws like in the EU.
A child born since Facebook's inception will be approaching 18 soon, and might have had parents who posted the child's entire life on Facebook from the ultrasound all the way to (maybe?) high school graduation.
When that child turns 18 and the child does not consent to tracking, what happens to all those photos, behavior, and YouTube videos that kid has watched? Maybe the kid starts as a clean slate since they've reached an age of majority, but how can you technically even keep track of that?
https://www.usatoday.com/story/news/nation-now/2016/09/16/18...
https://www.independent.co.uk/news/world/europe/facebook-fin...
Search for: "child suing parents over facebook photos" and you'll find plenty more.
Seems a little "too late" to retroactively remove consent some years later. That being said, I can see arguments either way that make sense. :/
And the parents do consent when the photos are taken.
Lets take a run at this one. I did specifically mention a couple exemptions above, which include expectation of privacy - a crowd in a public space don't have an expectation of privacy.
(In the US this goes further, where you can photograph anyone in public, with or without their consent, so long as it is within the nebulous "community standards" - but the US is not the norm.)
However, that's not the case for a wide variety of other photographs.
For example under the Australian Privacy Act:
> Images of individuals in photographs or video (images) are treated as personal information under the Privacy Act 1988 (Privacy Act) where the person’s identity is clear or can reasonably be worked out from that image. [0]
Similarly, in the EU, photographs or video of someone who can be reasonably identified within that work, is to be treated as Personally Identifiable Information under the GDPR, and thus requires consent. GDPR also requires you notify anyone in a public space ahead of time that you may be filming or photographing in the area.
I think it's fair to say that it is _not_ normal in most of the world to require no consent if you're not doing something commercial. Consent is the norm.
[0] https://www.oaic.gov.au/privacy/guidance-and-advice/posting-...
The GDPR doesn't directly include photographs as protected information, unless the are attached or connected to other info.
And it's worth noting that this is not about collection of data but use of data - if the legal basis of the processing was consent (perhaps there was a different legal basis, then consent isn't relevant) then withdrawing the consent does not make the earlier processing illegal, but it does require the controller to stop processing (using) the data they collected while they had consent and ensure that any processors to whom they delegated data processing do so as well.
Additionally, the child will usually not know every site their parent has consented to tracking use.
I'm more interested in how decentralized platforms might impact the current trend of verified accounts and use of real names. I can see a couple potential outcomes with decentralized platforms:
1) The use of pseudonyms grows further and speech gets even more divisive as people can speak without it coming back tarnish their real-life identity.
2) The use of real names grows more popular as people want to own their speech without fear of being de-platformed.
Won't work for: Google/Facebook tracking you across the web, probably not even 10 years ago when this article was published. You're still the same person.
I do not know how this particularly works in the USA, but in most reasonable countries I know of, the ways in which anyone (company/government/etc) can interact with anyone who isn't a legal adult are limited. For good reasons too, I believe. I think it even is dictated by signed/ratified international treaties/declarations, but I don't recall any details right now.
I'm pretty sure that the tracking of minors (or the unborn), essentially surveillance, is actually in violation of the legal protections those are supposed to have. I've heard plenty people argue that this tracking is somehow admissible, if their legal guardians sign off on it. Often based on the assertion that legal guardians are responsible for those under their care. However, the legal protects of minors are a thing on their own. As far as I know, guardians can not "give away" the legal protection of minors. No more than any person can "give away" their inalienable human rights (also not by consent), which is what makes them inalienable.
So here we have an industry that in all likelihood is seriously violating the legal protections that minors (and arguably unborn too) are supposed to have. Instead of demanding that governments address these rogue corporations, which considering the systematic nature of their violations probably even warrant to be classified as criminal organizations, we instead listen to what key people in this industry say in an attempt to justify their actions, or suggest as remedy for their behavior.
I'm not really all that shocked about people like Schmidt saying such things. About as predictable as a politician talking any kind of bullshit that will sell their agenda. However, I am appalled that this industry gets away with what it currently does. To me, that says a hell of a lot about the system, and how it apparently prefers to protects these interests instead of protecting the people it legally is supposed to protect.
This also happens to adequately describe how it feels to live in Brooklyn, NY these days...
The problem is not individual bad people or bad companies. Take out the ones that exist now and a sea of new adtech startups will take their place.
Can you not imagine a scenario where we didn’t leave everything in the hands of a completely unregulated market?
We have (kinda) world wide copyright laws. We have world wide drug laws. We have world wide sea and war laws. Why don't we have world wide privacy laws?
... which get flouted all the time
> We have world wide drug laws.
... And the war on drugs has been a huge success.
> Why don't we have world wide privacy laws?
The Internet makes trying to enforce world wide privacy laws much harder than physical laws: anyone in the world can reach you and collect data about you.
> Just make it outright illegal and fine heavily per violation. You have profile information that a user didn't explicitly give you? $10k fine, each.
How do you propose to discover violations? Self-reporting won't ever happen. If you then propose to give draconian sanctions to trying to cover up such issues, congratulations, you've killed the ability of people to build anything and share it with the world.
Not really. European Union services are more regulated towards user rights (GDPR) and services from other big countries are usually targeted towards domestic or regional market (typically East-Asian apps for example).
Is robbing ok, because if you don't do it, someone else might?
I never gave it particular thought so maybe I’m in the tiny minority though.
This is akin to saying: if you desire privacy, you can just clear your cookies.
There will always be a way to find these "name reset" folks - the privacy policies if services will have sentences like "to combat fraud..." "to protect the service..."
This will seem reasonable because one person desiring privacy shouldn't be able to skip out on a utility bill!
Without regulation - strong regulation - this won't change anything. Unfortunately it seems like anti-business regulation rarely works - if bills progress, they are defanged at the last minute.
The reason the EU has these laws is they remember people being put to death, even with minimal data collected in the pen-and-paper era.
Even though the US had pearl harbor, they haven't had their data pearl harbor moment.
I worry that we might have passed a "point of no dissent", where groups and even individuals in favor of privacy regulation can be surgically removed from dissent.
No problem, you just need simultaneously to change your name, your address, your bank account and credit card, your friends, your hobbies, and your biometric properties. Of course, also buy a new computer with different hardware, and install different applications.
Then hope you didn't forget anything, otherwise you need to do the whole thing again.
Your right to be forgotten does not out weigh my right to remember and share what I remember with others.
You have no right to tell me that I can't tell someone else I was in a hacker news conversation with Flowerlad on HN in January 2021 where he wrote "....whatever you wrote...." and that includes writing an article on my blog, tweeting about it, publishing it in the NYTimes, etc... and the idea that some law would prevent a search engine from indexing my content because your name happens to be in it seem wrong to me. You'd have effectively de-platformed me to talk about you or even my own memories.
You are correct that right to be forgotten does not outweigh you right to remember and share what you remember with others. The law does not restrict this right - GDPR, including that clause, does not apply to private persons personal activity.
However, that right is more narrow than you imply. First, you personally have the right to share your memories with others, but companies and businesses do not have such a right. Second, you do not have a right to have your content indexed by a search engine - your right to talk about these things in everyday outweighs the other persons right to privacy, but their right to privacy outweighs your privilege to publish your memories in mass media. Yes, you would be effectively deplatformed, but that does not violate your right to speak about this - the right to privacy is a fundamental human right, the right to a platform is not; any rights to free speech does not include a right to be widely disseminated.
no it is not.
In combination with flipping Data Ownership laws to where a person owns the data about then, and Right to Know laws where companies are required to (on request) give you all the info they have about you, and allow you to correct that information. Basically expanding on the Credit Rating agencies laws where (in the US) you are entitled to a free credit report and the ability to dispute info.
Hmm, I wouldn't be so sure. Ancestry, FamilySearch, and other genealogical databases may yet have him in there, along with tons of information that ancestors literally voluntarily supply, including photos (for posterity). I see that as a good thing though. I can learn about my ancestors and see pictures of them and read stories about them.
What's on those sites is based off source materials. And those are generally disparate: oral witnesses, family members, documents found in private archives,... but also public records found in your city archives.
Where I live, different offices kept population records through out time e.g. city hall, the Church,... You can easily walk in, and access records from the 18th century and figure out when someone was born, who they married to and when they died.
However, legal provisions prohibit access to those public records pertaining to births, marriages and deaths which are less then 100 years old. Meaning you don't get access to lists of names of all everyone were born in 1936.
Why? Privacy for the living. e.g. someone could walk in and assert that your parents aren't your real parents.
Moreover, privacy legislation states that you need consent from living people before you can publish personal information regarding their names, addresses and so on. It means that even if someone passes away, you can't just publish that they were married or about their children if any of those are still alive.
Publishing pictures is even more fraught. You need consent from the person depicted, and consent from the photographer. That means ascertaining whether they are still alive, or getting consent from their estate in the case of the photographer. In the latter case, it might mean you may have to wait for 70 years after their death before those pictures enter the public domain. Genealogy websites allowing people to simply upload pictures without constraints expose themselves to copyright liability in that regard.
... and then there's the issue of how those legal provisions are upheld on the Internet. For instance, any ancestry/genealogy site who wants to operate in the EU has to comply with EU legislation including GDPR, copyright, right to be forgotten and so on.
For sure, being able to dig into your own ancestry and being able to rely on other people's work through digital technology is awesome. But, as with anything digital, it does come with the same challenges that confront any business case leveraging personal information.
TL;DR: Genealogy is fraught with legal challenges. You don't just get to publish, let alone scour and use those data without consent.
How about this for the plot: Witness a high profile crime & then get a witness protection just to avoid getting tracked by FAANG! :)
https://www.itv.com/news/2021-01-18/woman-ruled-dead-in-2017...
Only if you don't violate the copyright of the dead person - which, depending on the country, can last 50 to 90+ years after the person's death. Thus to publish you'd have to get the right to do so from said person's estate.
There are many instances where private correspondence, etc. has been banned from publication/the public domain for this reason.
There are some resitcitions there, for example the Private letters and Diaries would still be covered under copyright and the estate of the person could come after you for Copyright violations if it was with in 70 years of their death.
Also the Estate of a person could absolutely sue you are defamation provided the Estate has a person actively working to police that activity and the resources to hire a lawyer to do it.
So your position that "dead people have no privacy" is really false as they have just as much privacy as people alive it is just most dead people do not have anyone around that will expend the resources to enforce it like a live person
The relatives of the deceased can sue you for defamation damages to their reputation (e.g. the widow might assert that the claim about her deceased husband damages her own personal reputation, and if so, perhaps she would have standing but only as far as her own name was slandered). The relatives or the estate can not successfully sue you for defamation of the deceased him/herself.
This is a decent precedent - https://law.justia.com/cases/massachusetts/supreme-court/vol...
The situation in UK seems to be the same - https://www.holdthefrontpage.co.uk/2012/news/mps-rule-that-y...
This article lists many interesting famous situations from history - https://jonathanturley.org/2007/08/18/defaming-the-dead/
It's even possible that defamation that happened while the victim was alive gets ignored if they die before the case is settled - for example, Ohio code (http://oh.elaws.us/orc/2311.21) explicitly asserts that libel and slander cases (unlike pretty much everything else) should end in this case.
A famous case is Michael Jackson and the 2019 documentary "Leaving Neverland"; when he was alive, he successfully won a defamation case against Victor Gutierrez with a pretty much equivalent case, however, as this happened after his death, those managing his estate were not able to bring a defamation suit for this documentary because those defamation laws did not apply any more.
Law stackexhange has a quick summary at https://law.stackexchange.com/questions/28842/can-you-libel-...
I wonder if at some point we'll see deep fake profiles being made like that for obfuscation. 40 accounts with my name on facebook, all with similar but different histories and similar but different friends and travel histories. One of them is the real one and the rest deep fakes. Instead of being lost in silence, we can lose ourselves in noise.
This "fascination" from the author is unhelpful IMHO.
I am not surprised that the pregnant mother was upset - in the UK it is now drilled into you that you need to keep track of kick data for your child and that you must - must - call the hospital as soon as you notice any change at all in kicking from your unborn child (1).
They are deliberately very vague and unclear about what a "change" constitutes - just that if you feel something has changed at all or in any way then you need to call. From experience, these calls always end with a request that you go into hospital for a check from a midwife. So 55 kicks today, but 60 yesterday? Come in and a midwife will hook you up to keep track of your baby's vitals for an hour just to be sure with lots of reassurance that you did the right thing by coming in and getting it checked.
So no shit if you've entrusted this data to an app and they've dropped the ball, no wonder you are angry: this is not just data for data's sake - not having it potentially endangers the life of your unborn child because you don't have your historical data to compare against any more, so you can't know anymore if today's kicks are changed from yesterday's or the day before etc.
I am sure many people will scoff and call this an overreaction (including apparently the author of the article) but this is the current recommendation from the NHS here, and not everyone has a totally normal medical history or otherwise-textbook pregnancy where it is all skipping through meadows of wild daisys and baby ducklings quietly nuzzling at your feet followed by the perfect stress and pain free delivery. People can and do have medical circumstances that influence pregnancy. It ain't all plain sailing.
People have reason to need to trust that their medical data is stored safely and reliably. To insinuate that is is odd is deeply unhelpful.
1 - https://www.nhs.uk/pregnancy/keeping-well/your-babys-movemen...
These apps are a fucking cancer on what should be an enjoyable and natural time.
https://www.frontiersin.org/articles/10.3389/fped.2017.00202...
My wife took maternity leave from 3 months before her due date for this very reason. I understand not everyone can, but it baffles my mind that often those who are able to, choose to continue to work rather than taking time off to care for themselves and their unborn child.
From link: “You do not need to count the number of kicks or movements you feel each day. The important thing is to get to know your baby's usual movements from day to day.”. I am guessing you are repeating what you have heard outside of the NHS recommendations (the NHS link appears well written to me, although I have zero experience).
Quotes from https://www.nhs.uk/pregnancy/keeping-well/your-babys-movemen...
“Call your midwife or maternity unit straight away if: your baby is moving less than usual; you cannot feel your baby moving any more; there is a change to your baby's usual pattern of movements. They'll need to check your baby's movements and heartbeat. Do not wait until the next day – call straight away, even if it's the middle of the night.”
“It's not likely your baby can move too much. The important thing is to be aware of your baby's usual pattern of movements. Any changes to this pattern of movements should be checked by a midwife or doctor.”
What kind of issues could a change in kicking indicate?
If there were an issue what, if any, interventions do doctors have at their disposal to make things better?
We desperately need modernized data rights and regulations. Companies can afford it.
That's why the GDPR is so great: It's only legal if the user has willingly and independently given consent to your data processing. So as soon as you force or coax someone into ticking that box, it's invalid and you can be sued for it.
Facebook learned that the hard way :)
ToS popups need a textarea field where I can submit my terms.
From their side, they also offer a well-defined interface to sign up to their service with the standard set of terms. Now, whether you use a tool that conforms to this interface is up to you. You don't have to use a tool that will conform and you won't get the offer.
Likewise, you can offer a well-defined interface to sign up to your data and everyone else can just choose not to use it and they won't get your offer.
What about shadow profiles in that case? I assume companies track a lot more data on people that just what you put into your account explicitly — photos of friends not on platform, 3rd party sites using Pixel etc.
It's one thing that's really missing from GDPR style controls — if I have an account, I can request that my data is deleted (but not validate it really). What can I do if I don't have an account?
They got slapped on the wrist, you mean.
- from the book "Big Data" mentioned in the article
Meant to inform rather than to explain. Words of caution for "data scientists". We get more useful data from our senses each day than we ever will from a company conducting surveillance over the internet.
But what data are they collecting? Things available via JavaScript, tracking pixels, phone characteristics - most definitely. But the raw data about their pregnancies that users enter into tracking apps? While that’s entirely possible, Citation Needed.
In my opinion, the OS should let you deny the "internet" permission on any app, no reason why it should need it if I don't want to risk my data being uploaded without my consent.
Do you mean sent via https or encrypted in JavaScript before transmission? If the former, that’s pretty par for the course.
it would be very time consuming to try and determine what that data actually is.
It would be easy for a researcher who wants to answer the question: what data is it?
JavaScript debugger + breakpoints.
https://www.wsj.com/articles/you-give-apps-sensitive-persona...
Populating a variable based on the current user so as to segment them in analytics or advertising - regardless of whether it’s that the user is pregnant or they said their favorite color is blue - is different than “sharing” structured pregnancy data or favorite color data that a 3rd party can inspect.
If this sort of wide-scale actual sharing of data exists, then I’d expect to see job postings for the role of coordinating data exchange, schemas for pregnancy data in XML format, API documentation for transmitting ‘sensitive’ data to 3rd parties, leaks containing this sort of sensitive data in unexpected places, etc.
That said, the title of the article says “profiling” and not “sharing”, so maybe Facebook and Google can derive that particular theoretically opaque segmentation values from particular apps represent pregnancy status.
Or maybe an opaque, trained model outputs that for certain users with certain segmentation values in certain apps, those users are more likely to click on ads relating to pregnancy.
Edit: The WSJ article notes that Facebook has acknowledged that the latter is possible via a filed patent. FB say it doesn’t use that technique.
Is that where we are now?
But I think Hyperion Cantos by Dan Simmons would fit better.
Only in the terrible prequels written by Frank Herbert's idiot son, who decided that a rejection of machines replacing humans = literal Terminators.
One of the more interesting things about the Butlerian Jihad is that in the end, without thinking machines, they instead turned humans into machines.
Yes, and this is often overlooked.
The question if we should turn machines into humans or vice versa, and that there is no third option.
It is probably why companies like reddit push their app so hard that it almost makes using the web page on mobile impossible.
I've been trying to find a meal tracker that store everything on my phone and phone only but it doesn't exist so I am considering writing one myself, but I feel like I am the crazy tinfoil hat person sometimes since I want local data!
Nobody is holding a gun to our heads.
Many today argue that the internet is largely unusable if we block all the FAANG hostnames, and for many this may be true, but it's becoming less and less of a sacrifice every day to disconnect from these massive centralized blobs.
I understand many people feel an unquenchable urge to legislate these kinds of things into being, but we really cannot "will" things like this into existence. It's, actually, much easier to incentivize and promote a practical means towards adoption. In our case, we need to begin promoting technologies that promote decentralizing and owning our own communications protocols.
You know how some people are just complete fucking assholes, and people let them get away with it to avoid conflict?
Yeah, if you say your name is Bog Saget and your email is bob@gmail.com, nobody's gonna raise a stink. They'll know you're full of shit, but if you can deal with their disapproving glare nobody will stop you.
The "indoor play area" thing has not been an issue for me, personally.
- had a whiteboard/design/brainstorming session
- decided or was told to develop a feature involving data hoovering, with whatever justification
- not enough of the team said "no", or were replaced by those that said "yes", that the feature made it to production
- decided to sell/buy/run analyses over said data to increase profits (ostensibly)
now, if there were a handful of companies doing this consistently, that'd be one thing. however, if all these apps, web sites, etc. are engaging in this, then it's clear there's just zero fundamental ethical force to stop data hoovering, and we ought to expect that the data collection will increase up to and until government regulation of this stuff.
anyway, from where i sit, the engineers, vendors and data scientists involved in surveillance capitalism must share some of the blame, if not a lion's share.
"We use cookies to provide a great experience. If you're happy with this, continue browsing"
Apparently that counts as an "explicit, freely informed, permission given" consent now?
I have found countless examples of websites sending data to facebook (including PII), simply by using XHR/fetch and a POST request, sending entire page URLs every time you navigate the website. I've noticed tens of requests to several domains that could be hijacked at any time and peoples information collected by a bad actor is they get the domain "totallynotspyingonyou.com"
If the GDPR was serious platform changes would've been implemented - similar to Apple's coming tracking permission - which should be standard on every OS inside the EU. Instead of relying on websites/providers to the right thing, the upstream systems (browsers, OS) should be designed around the laws instead. As it stands, Google allows their OS to collect an individuals entire address book, apparently that data structure can be parsed, uploaded and freely traded once somebody taps "accept", and if my data is included...Well tough shit for me I guess. Asking Google whom has got my phone number saved onto their accounts yields no response, yet if somebody puts my PII onto Google, I have no rights over it.
The "rights" the GDPR enshrined are nothing more than a empty, hollow promise - how many have had success trying to get information deleted? All I get told is it's "legal" as there's a "public interest" or for any number of reasons.
Regulators simply can't and won't keep up. Reporting Google is a waste of time, a regulator is unlikely to touch them, even if there is data Google won't provide in a SAR and take months to provide a response.
We need to embrace and accept data is going to be collected on all humans and kept for as long as the collector wants, and it can be sold, leaked, used and abused without you having any way to control it.
We're all just numbers in a database somewhere, your feelings don't matter, how it affects your life on earth is disregarded, ads must be sold, data must be harvested.
Welcome to 2021.
It is written: 𝓣𝓱𝓮𝔂 "𝓽𝓻𝓾𝓼𝓽 𝓶𝓮" / 𝓓𝓾𝓶𝓫 𝓯𝓾𝓬𝓴𝓼 [For screen readers: They "trust me" / Dumb fucks]
It's a problem, for sure, but I don't think we're totally helpless... yet... and it frustrates me to see this level of learned helplessness, and mistaking convenience for necessity. Being used to using your phone for everything, doesn't mean you cannot do something else. It's inconvenient, and not impossible, to go to a library[0] instead of Google and BabyCenter.com for answers to your questions. It's inconvenient, and not impossible, to momentarily disappoint your kids to protect their data forever (which is the kind of long-term concern that you understand and they don't, because you're the adult, which in turn is why you, and not they, are in charge).
[0] RE libraries & books, that's the method most people used up to and past the 80s when PCs started appearing in many homes. That's the method by which enough knowledge was transmitted through millennia to enable the invention of smartphones. You don't even have to borrow the book; you can read it on-premises. But if you need to borrow it, you should still real-quick make sure the library isn't selling you out to anybody either. Most libraries have enough money and are pretty popular when it comes time to levy a tax or issue a bond. But some are just strapped enough that they "could really use the extra cash" that comes from providing borrower data to somebody who has convinced them it will be "anonymized."
For example, if you see a car that tracks your movement and sells it so some third party, you can either say "lets make cars that don't do that" or "lets go back to horses". I'm not excited about going back to horses, we can fix the damn car :/ Turning our back on modern technology is a depressing and limiting action in the long run.
Seeing how much we focus on lowering the friction to onboarding, landing pages and just working in software for a while, i think the private solutions have to be every bit as convenient as the commercial option, otherwise they are not viable. That is just table stakes for mass adoption by a broad audience. Technical users may vote with their feet even when its slightly inconvenient, but its not enough to make a dent in the world.
For example, i cannot even imagine how much longer everything would take if every google search i made was replaced with a visit to the library. It would be 5-10x the time, maybe much more. A ton of information would be completely unavailable even given infinite library time. Luckily, I can (and do) just use DuckDuckGo instead.
There's lots of encouraging progress in these kinds of solutions that are both just as convenient AND private - decentralized web, pinephone, linux adoption, end to end encryption on messengers, personal clouds like NextCloud etc.
Frankly, given the average driver, I think reducing max speed and adding another set of eyes & brain to the mix would be a pretty good thing :)