How to poison the data that Big Tech uses to surveil you
technologyreview.com
technologyreview.com
You can then get a PO BOX, setup your important things like property taxes/dmv/utilities/banks with it as the mailing address, and carry on supplying your residence as your physical address to whoever appropriately asks without even lying.
Most places are just assuming your physical address receives mail and send unsolicited spam to it. Critical services must support a mailing address distinct from a residence address, as it's common for those living at the end of a dirt road without mail service; a perfectly legal way to live.
I currently do this, and my PO BOX receives practically zero mail, and I must say it's a glorious signal:noise ratio.
There are some frustrations though, some places do refuse to send to a PO BOX, and some shippers which claim to use FedEx or UPS will then go on to use USPS and your purchase doesn't arrive. Non-USPS deliveries will still arrive at the physical address without a mailbox, but USPS deliveries will not - those must go to the PO BOX. YMMV
Nope. A whole lot of official stuff (like drivers licenses and bank accounts) will now refuse PO Boxes.
I believe this stems from the RealID crap.
I did have a problem with E*Trade because they partner with a banking provider. Despite having the PO BOX as the mailing address, their bank insisted on sending the debit card to the residence address. This was resolved by them sending it via FedEx, no mailbox required, still fulfilled their requirement of confirming the card goes to the residence on file, done.
I haven't had to get a new license in this mode yet, but the vehicle registration has all been frictionless with separate fields for residence and mailing addresses. Maybe it will be a mess for the DL, but I'm pretty confident there's a way. Even retirees who sold their home and are living exclusively in their RV have an escape hatch at the DMV AIUI.
Does that mean that if you get a 'new' PO box, you get spam right out of the gate due to the previous owners?
It's not uncommon for people to buy a magazine subscription for someone else. Half of the magazines to which I subscribe send me letters offering half-price gift subscriptions.
For payment, you could use a pre-paid card. If the magazine company doesn't take that, you can send a check. Checks with no name or address on them are stupid easy to get. And I've never seen a magazine that didn't take checks.
A few years ago, I think you used to be able to sign up for free subscriptions to magazines like Sports Illustrated at Best Buy. I'm not sure if that's still happening, but I think it was part of a strategy to keep circulation up.
This sounds like a pretty old trick though, not like many people get magazines delivered anymore.
I was surprised to learn that this is just one of those things that people say on the internet. The whole "print is dead" meme.
I ended up in a conference room with a magazine circulation manager in 2019 and asked him about the state of the industry while we awaited the next presentation. He told me it's rebounded quite a lot since about 2005, and some magazines are doing better than ever. Unfortunately, I didn't have a chance to ask him anything further because the next speaker came in.
I'm a believer of building many separate complex systems to feed manufactured data into these systems. Let's make it an arms race, and a competition.
This has led to the postal system taking legal action against startups that tried to shield people from spam.
It’s all exactly as stupid as it sounds.
Defense against data poisoning isn't just about ad tech. State actor threats routinely engage in sophisticated data poisoning operations that require robust mitigations for system integrity purposes. A "simple" strategy is not remotely at the level of sophistication required to have a chance of bypassing these defenses, which need to withstand state actors.
Wait a minute, if every ad is clicked on won't that give an enormous amount of money to the companies that created the problem in the first place?
e.g. "We believe obfuscation is an important form of resistance to data tyranny. It can frustrate surveillance, help users to express their discontent, and act as a communal, rather than merely individual, practice."
I believe the general idea is that by contesting targeted ad technology in general, the eventual goal is move away from that model (which arguably, Google is doing with their big ad "reframing", although I realize this is contentious)
1 - the goal is so google doesn't know which ads are interesting for you, so it helps you with that.
2 - in the short term, you are making google earn more, but if more people do it, ads are going to start being way less effective, as the companies pay google per click, but they don't actually get any signups (or whatever their goal is). Maybe that could make google ads less relevant
I'm curious how you think you were linked. Also, how you have identified that you were successfully linked?
Perhaps you still have the same social media accounts somewhere? Perhaps you used your same PC you'd formerly used when creating new ones? Perhaps your friends merely updated their phone's contact information for you rather than deleting the contact and adding new ones?
I wasn’t able to identify where it came from, but I do suspect it’s the latter — which is really hard to deal with because it’s other people leaking info about you. But the same could have happened with facial recognition at an ATM or checkout.
Personally, I’ve accepted that being an American in 2021 just means being under constant surveillance. The fantasies of going off-grid will run into the realities of your human relationships.
You mention contact linking being a possible cause of advertisers figuring out your new address, but it also wouldn't surprise me if at some point during the legal process credit industries just got notified about it. Although if that was the case you'd think that advertisers would have had the courtesy to use your correct name when sending junk mail, so... shrug.
It's a weird system that is so ridiculously good at tracking people, but still messes up so many basic details.
Name changes seem to not have been frowned upon generally if they had significance. Often they were recorded as part of a rise of status whether formally like say becoming pope or a Norse deed name style like being known as Shieldbreaker because you struck the blow that split a foe's shield in two.
As for tracking - many buggy but functional systems linger at good enough for generations with a weirdly stable whole. Even if you can get a "NULL" vanity plate you shouldn't unless you like taking the chance of receiving every ticket for cars without plates and having to dig your way out of that mess.
That may or may not be the case. It's enough to have a friend of yours who (unknowingly) posts a picture on FB with "Me with X. He/She changed his/her name and move to ...". The chances are you'll never discover where the "leak" comes from.
To me, that seems like a major aspect of surveillance economy which can't be easily disrupted by something like Ad Nauseam or pi-hole.
[1] https://www.fastcompany.com/90490923/credit-card-companies-a...
Apple Card is a start: https://www.goldmansachs.com/privacy-and-cookies/Apple_Card_...
"The types of personal information Goldman Sachs Bank USA collects and shares depend on the product or service you have with us. This information can include: Social Security number and account balances account transactions and purchase history transaction history and payment history
For Goldman Sachs Bank USA's marketing purposes: to offer our other products and services to you Does Goldman Sachs Bank USA share? No
For joint marketing with other financial companies Does Goldman Sachs Bank USA share? No
For Goldman Sachs Bank USA's affiliates to market to you Does Goldman Sachs Bank USA share? No
For nonaffiliates to market to you Does Goldman Sachs Bank USA share? No"
Apple issued this statement in response: “We apologize for any confusion or inconvenience we may have caused for this customer. The issue in question involved a restriction on the customer’s Apple ID that disabled App Store and iTunes purchases and subscription services, excluding iCloud. Apple provided an instant credit for the purchase of a new MacBook Pro, and as part of that agreement, the customer was to return their current unit to us. No matter what payment method was used, the ability to transact on the associated Apple ID was disabled because Apple could not collect funds. This is entirely unrelated to Apple Card.”
https://9to5mac.com/2021/03/03/apple-card-apple-id-unrelated...
Another great alternative is privacy.com which allows you to create anonymous credit cards (your bank is then debited). While the vendors won't know who you are privacy.com certainly does and they use Plaid on the back end so they likely know as well. VISA just tried to buy Plaid; someone eventually will acquire them (maybe Google?) so keeping your financial info private via privacy.com might not be something that works long-term.
While they certainly do track many things (I was an employee for several years), American Express does not provide information to credit reporting agencies (Equifax, TransUnion, Experian).
While that doesn't help with more mundane tracking (although you could buy Amex gift cards for cash, but that would be the same for any other gift cards), it does impact some of the more insidious tracking that's been going on for decades.
Actually selling your data (as opposed to selling a derivative which is lazily conflated) they could manage to abstain from. The other party could also sell their transaction data which happens to contain you (although retailers tend to be cagey about what sells and keep their use internal they are infamously one of the things sold upon bankruptcy by their debtholder heirs).
Wanted to briefly highlight a couple points that I think will be interesting to the HN audience.
One of the major goals of the paper is to describe a framework of three "data levers" (ways a group of people can hurt or harm a data-dependent technology). Data poisoning (well known to ML people for a long time) is one of the three "levers". The other two are "data strikes" (withhold future data and/or delete past data via deletion request) and "conscious data contribution" (ala conscious consumerism — give data to a firm you support and want to compete with incumbents).
A major point in the paper is that there are some big differences in terms of barrier to entry, legal considerations, ethical considerations, and ability for a data lever to be impactful. Basically, for any given company + technology, there's probably a particular data lever that's a "best fit". It might hard to organize a large enough "data strike" that will meaningful hurt a huge company's search engine, but conscious data contribution could help improve a competitor (esp. if that competitor focuses on search verticals). On the other hand, data strikes could be really great vs. facial recognition, because there's precedent of forcing companies to delete actual model weights ([https://www.theverge.com/2021/1/11/22225171/ftc-facial-recog...).
Another point is that there's some nice connections between levers. On the topic of data poisoning defenses: if you've been feeding poisoned data, and get caught (quite likely for naive attacks, as noted below), the company deletes your poison and you've just been "reduced to a data strike".
A final point: the paper discusses implications for folks who work in ML, design, HCI, and policy. There's great opportunities to build to tools to support data leverage, and for ML researchers to "bake in" data leverage (e.g. compute a performance v. dataset size learning curve to characterize how "vulnerable" a system is to data strikes). Also, there's huge potential for win-wins with privacy regulation: data deletion and data portability both enhance the public's leverage.
I'll end this long comment now, curious to see what others think (and appreciate all the comments already here!)