That would make businesses very quickly reassess how much data they need to keep, and how careful they need to be with it, without requiring any really radical legislation.
That would make businesses very quickly reassess how much data they need to keep, and how careful they need to be with it, without requiring any really radical legislation.
Without the auditing, compliance, and domain experts to verify and implement this, its going to be extremely hard to create and levy these penalties in any meaningful way. Using (legally) vague terms like "leak" "personal" "data" and "involved", a quick trip to the local courtroom will obviate a lot of the fines for well connected C-execs and legal teams.
Data integrity needs to be baked into the equation from the start. Until it is a business requirement to ensure proper system architecture practices, data integrity, and auditing, I don't see a snowball's chance of reaching sanity. Really, we've only barely defined the problem. Businesses have compliance departments that are totally subservient to business needs and would much rather resort to gaslighting stakeholders with silver-bullet checkbox security technology processes shaded in at the board room.
On the other side, we are now ushering in a fascinating golden age of the security rodeo. There is astonishing growth in this industry, enjoy unending contracts for Red and Blue alike. It could soon really begin to look like a Gibson novel.
Many regulations only apply to companies bigger than 50 employees, more than billion of turnover, data on over 1 million people, etc. Or in a spesific market.
Kaseya has a whole portfolio of services marketed to small, medium and startup business (as well as larger) that their customers bought in order to enable them to leverage this business model in the first place. They've since burned countless providers, torching their relationship with customers, shutting down countless businesses of all sizes all across the planet. What is the cost to them of this? Worst case scenario, they fold and change the sign. The people in charge of not screwing up will be snatched from doom by their network. I would hope they do better next time, but why would that be any more likely than just another over par round of golf?
I definitely agree that it is not easy to asses the security risk of small businesses in a cost effective way for insurance companies or to develop some kind of regulatory structure.
The alternative to not doing this is accepting this unstable chaos-monkey in perpetuity. If there is no business requirement for effective controls, there wont be any.
Kaseya's people can walk and start another tire fire and surely everyone else will sweep up and move on, but these problems are everybody's problems. There is no IT infrastructure that does not require effective controls.
If we don't improve this problem, things are gonna get weird.
That doesn't grant a GDPR exemption. The "shop" still operates in jurisdiction.
Ban monetizing data (no selling, no pay-for-access, no derived products) and make leaks guaranteed to be expensive, so companies only keep what they have to to operate, with some large multiplier attached to the leak fine if it was related to banned activities.
Done.
The advertising is a symptom, it's not the disease.
This! Exactly this!
Advertising also stimulates mass overconsumption.
If we want to save the planet, advertising is among the top things we should ban right away.
Separately, yes, I'd like to see practically all public advertising banned (billboards are blight), and while I'd have to think on it some more before supporting a blanket ban on all advertising (I'm not sure it's workable, for one thing) I'd also not be sad if I woke up one morning and learned that such a law had been passed.
Advertising causes a great deal of surveillance, but it causes a lot of other issues, many of which affect almost everyone, very directly, and in some tangible ways. At a basic level, we're being lied to constantly in ways that hurt our self esteem, break our concentration, introduce us to new fears and angers: the exact intention of which is to create problems for us so that it can persuade us that giving them money will solve our problems. Advertising tells us our partners aren't hot enough, we aren't cool enough, our houses aren't big enough, our cars aren't fast enough, that we aren't doing enough for X cause. It tells us that our financial future is insecure, that we're missing out, that we're at risk for disease, floods, and car accidents. If a parent or partner told us these things, we'd call it emotional abuse, but from advertisers it's both accepted and commonplace. And it affects us deeply: we're overmedicated, overfed, overworked, and over-indebted.
And that's just the direct effects. When you consider the kinds of content that advertising funds, it's almost universally harmful. News that prioritizes clicks over information by inciting anger and fear. Informational resources that avoid speaking truth to power because power advertises. Social media that courts flame wars, conspiracy theories, and echo chambers because they all provoke engagement. Everything advertising funds is fast, shallow and emotional, because slow, deep and rational doesn't promote clicks.
Why even look for a compromise here? Easy to spot ads aren't better: they're still people shoving a lie in our face. There's nothing of value here. Ads are a tumor: even if we can find some part of it that's benign, there's no part that shouldn't be excised.
Also, they distort the free market (not the best product wins, but the one with the biggest advertising budget)
And they often target young children.
The only reason ads exist is because countries measure the success of their economies by how much is consumed.
If I were writing the rules, I'd exclude anything that looks routing-like. "IP address A sees version 1, IP address B sees version 2, with some amount of ephemeral data involved to support pinning" is fine. Basic hit-counter type stats are fine. (though I think A/B tests are abusive crap and would love to see them go away, on a personal level, I don't think they necessarily qualify as spying, though the way they're practiced right now probably does tend collect & retain enough information that they absolutely are, but might not with some modification)
> Show you products that they think you will want to buy based on your purchase history?
No. Maybe with some kind of opt-in or otherwise making that something the user has to intentionally ask for. But if you're not using others' purchasing data to decide what those might be (and that would definitely be off-limits) then that's not very different from just having categories your users can browse.
[EDIT] FWIW I don't think these kinds of rules should only apply to tech companies. Physical stores ("loyalty" cards, tracking shoppers' cell phones, that stuff) and banks and similar also shouldn't be able to spy on people, nor to sell or otherwise use data collected as a necessary part of their business against people. A store may reasonably have surveillance cameras, but ought not be able to sell the footage to another company to train & test its gait-recognition software, nor use facial recognition to track how often I visit the store or what I look at. That kind of thing.
(On the other hand, I think the law as you're proposing it would cover them)
I'm not sure many customers will miss it, if they really notice. Yes it can be a bit helpful, but many other things in the world would be "a bit helpful" and yet are nowhere near justifying their cost and effect (e.g. we stopped using radioactive chemicals in substantial amounts for everyday products very, very quickly).
What they do have is a giant corpus of behavioral data spanning everyone on the planet. Companies can (statistically) detect that you are going to get a divorce, or that you are going to be pregnant. They know everyone who has been to jail, our sexual fantasies, how likely it is that our children will go to college.
Right now we say they sell ads, but you could just as correctly say that they take advantage of this incredible, unprecedented information advantage to directly change the world in their favor and in the favor of whoever can pay. It used to be used to sell clothing and frippery, but already SM is plastered with ads for political campaigns and brain-altering drugs. Their cultural hegemony will only increase over time, as the data gets better and the methods become more effective.
In this regime, what does it even mean for Facebook to “leak my data”? If anything I’d rather it was out in the open. (Although I’d much rather it didn’t exist!)
My feeling is that surveillance states are more or less the norm, and it tends to become controversial as a sort of stand-in for other issues. So, for instance, the DDR's extreme surveillance apparatus becomes a sort of explanation for why this relatively bland state was actually a historic example of evil.
In england, there's a (very mild) controversy about the use of secret police to surveil activists - it became controversial because several of them had sexual relationships, and even children, while in their undercover role. One of the curious features of all this was who merited attention. One group of vegan restaurant connoisseurs, who met on fridays to review welsh vegan diners, discovered that one of their members was a police officer, for example.
This surveillance, which really had no bounds, including the surveillance of sitting government ministers (always labour, fwiw), is actually very typical, historically speaking.
So, while I'm broadly in agreement with you when it comes to the dangers of surveillance, I think we've all had and lost this argument in the past, and the fact is, if the state historically wanted to destroy or persecute a specific group, paper records were always enough. That means that if you want to make meaningful progress in the face of this information asymmetry, you have to find wedge issues.
Obviously, people don't like invasive data collection. People don't like wars either. People generally have the kind of common sense that institutions and businesses lack.
My feeling is that you don't win fights like this by making a principled stance, then trying to get the public on board. You do it by finding wedge issues, where the argument is so strong that opposition is very difficult, then using victories there to build momentum for the next fight. That's what the civil rights movement did. That's what you have to do if you're fighting from a weaker position, and I think privacy will always be a weak value in western-style democracies because there are just so many compelling incentives for actors to erode privacy, and the threat of losing privacy is generally abstract, and only felt by already marginalized groups.
A few years ago the Norwegian Spy Chief was taking questions from the media. He actually pointed out that we should be more worried about the data collection of private companies than that of the Norwegian state. Their data collection was regulated and small in scope. Big tech data collection is seemingly neither.
Data collected by Big Tech can be misused by others. In many ways this is a significant security risk. Not just from data breaches, but also that people can be manipulated in groups. This is a significant problem and the easiest way to resolve it is to stop the tracking and ban surveillance-based ads.
Personally, I think dividing between the state and business is simplistic. Most businesses and most states have a symbiotic and codependent relationship, that is more or less explicit depending on the country you're talking about, but that's by the by. In practice, states generally have access to collected data through subpeonas.
In any case, I think mixing the two is not helpful in any shape or form. What we need is to regulate what private companies can do. I think that is enough scope for this particular discussion and I think this is such an important matter that it needs to be addressed.
Companies like Google are probably secured like fortress and will probably not leak data anytime soon (lets hope) so your idea wont have any effect against giants that takes security seriously.
However, I really like your point and you'll probably have a good side effect on middle size companies. But giants are a giant part of the problem.
If you can build a big coalition of people for whom privacy is something important, then you can start making ambitious policy proposals because you'll have the voters to back it up. Before that point, I think you have to try for easy wins.
Any time someone who's not me or a direct party to a transaction or conversation learns something about me then that is a "leak".
> Do you consider it a leak when a data transfer to another company is intentional?
If I do business with my bank then the bank should have no right to sell my information to a third party for any reason whatsoever.
If I do business with my hair stylist then the credit card processor should not have any right whatsoever to do anything with the facts:
- where was the hair stylist? That's private.
- who was the hair stylist? That's private.
- when was I at the hair stylist? That's private.
- what did the hair stylist sell? That's private.
- why did I go to the hair stylist? That's private.
Nobody except my hair stylist and myself should have this information.
It sounds to me like this definition strongly promotes consolidation. The bigger a party is, the more information it would be allowed to have and the more ways it can use it to cross-sell.
> If I do business with my hair stylist then the credit card processor should not have any right whatsoever to do anything with the facts...
Should the credit card company be allowed to use the information about your transaction to assess how likely it is that someone has stolen your card?
I've been called by the credit card company many times for failed transactions that I've authorized. When fraud did occur then I was not contacted by my card company and I had only noticed the fraud because I actively monitor my card.
The credit card company should be able to determine what it wants without providing the information to any other entity. No, I do not think that the credit card company should be permitted to sell the information about my transaction under the guise of determining how likely it is that someone has stolen my card.
Yes, credit card antifraud has both false positives and false negatives. It's not clear to me whether you're going from there to saying that it is useless?
> I do not think that the credit card company should be permitted to sell the information about my transaction under the guise of determining how likely it is that someone has stolen my card.
I think I misunderstood you earlier. When you wrote "the credit card processor should not have any right whatsoever to do anything with the facts..." I thought you meant that they shouldn't be allowed to use the credit card data to do anything, including fraud prevention, not just that they shouldn't be allowed to sell it?
Not only am I saying it's useless but I am also saying that privacy is more valuable than the anti-fraud measures that can be gained from data mining.
Are customer reviews going to be illegal?
As he eloquently explains there, and in detail, RTB auctions "broadcasts private information about what you are doing online, and where you are, to many other companies in order to solicit their bids for the opportunity to show you their ad."
Every time there is a leak, you have to prove you've suffered damages.
That's hard to prove: even if someone commited massive fraud with your identify, you dont know if the data came from this leak, or from 10 other leaks.
Setting a minimum would mean thay you can immediately fine conpanies for loosing millions of records in one lawsuit, instead of a million suits proving that each particular claimant was harmed
Companies like Google and Facebook already leak.
Proof: start an ad campaign on e.g. Facebook targeted at people who have trait X, but sell a product Y not related to X. For people who click on the ad and buy your product Y, you now know they have trait X. And you can now also link that to their address info.
(Disclosure: I work on ads at Google, speaking only for myself)
As a (sometimes) "consumer", I personally don't mind companies I'm doing business with gathering some data to better serve me as a customer. It's actually kinda their job. And I don't even mind when they advertise related products/services at me (but not the product/service I just bought please). And I don't mind one little bit bein' advertised at (respectfully) when I'm on a site where I'm obviously lookin' to buy something. My main problem is that too often there's a degree of uncomfortable overreach with building (and worse yet, sharing around) a detailed profile of my travels on the web that is beyond unnecessary and unreasonable. I don't honestly trust most personal friends with as much information about me as some freakin' advertisers would seem to want to database and index about me. It's gotten honestly out of control, and I don't know what else to do anymore except use every tool my browser has available to block as much of it as I can actively.
By the way, scale matters too.
Doesn't this just consolidate power among FAAG even more? They can pay these fines and they don't often leak data- if ever. That's another thing- define leaking data. Sharing with 3rd parties? It's vague enough for them to beat that in court.
We do somehow need to get back to advertising the old fashioned way rather than this surveillance capitalism arms-race.
Old fashioned ads were targeted based on the thing they were attached to. For instance, if you read the sports pages of a newspaper sold in your city, you probably got ads of presumed interest to people in your city who are interested in sports.
To restore that kind of system, you would need to focus on those kinds of issues: making advertising first party, distinguishing between parts of a site without distinguishing between users.
But once you've done that, you're still left with first parties that can spy on you and use that data in non-advertising ways, or even presumably for direct marketing (if you have some kind of an account).
I think it's better to focus on the surveillance. If they can't surveil you, then they can't use surveillance advertising. As you point out, focusing on leaks is irrelevant because I don't really feel better that only Google knows everything about me. Focusing on advertising doesn't stop them collecting data, it just limits how they can use it. If we don't want the data to exist, collecting it should be prohibited.