Go Ahead, Sell My Data
kevinjcurtin.com
kevinjcurtin.com
My main problem is that they actively try to get their hands on data I don't want to give them. Like, my constantly actualized GPS coordinates, or my browsing history. And that they store it. And process it. And store me into some kind of box.
Oh, and it candidly considers that Facebook, or any other person to whom it sells the data, won't do anything nasty with it. Just serving ads might be okay. But ultimately, they could do much more.
Do you want to know who the gay people are around you ? We could sell you that list ! Do you want to know who votes for your opponent ? We could sell you that list ! And so on.
The day Facebook, or Google, or anyone with a comparable database actually decides to do something evil, it will look ugly. Will they ? Don't know. Don't want to find out.
As a side note, I might pay for Facebook. Or I might have paid. Now, they will just get my money and sell my data anyway, so why bother ?
For instance you do not usually opt-in to a group by yourself. Instead somebody else includes you in that group, without your permission. This is bad because opt-out of a group is an explicit statement that you don't want to be in that group, versus just ignoring a request which could just say that you don't have the time for that or you missed the invitation ... and people know you in those groups and opting-out is just rude.
This is not how real-life works btw.
I also got tagged several times in pictures that I do not like. Those pictures automatically appeared right on my "enhanced" profile page. When I untagged myself the person that did it thought it was some kind of technical problem and tagged me again. Then I untagged myself again, and got tagged again. Then I told that person that I don't like that picture and she got upset. I don't want other people tagging me - I want to tag myself in pictures that I approve of and this is something that Facebook won't allow me to do.
And talk about automatic tagging -- fortunately Facebook allows me to deactivate automatic tagging (for now), but this feature is just plain evil IMHO, as it encourages people to tag other people, even though that's not something they really want to do.
This list could go on and on and yet Facebook provides no means for me to automatically download the contact details of my friends. How fucked up is that? These are my friends, and many of them I invited to Facebook myself.
Basically these days I'm only using Facebook when I want to get in touch with somebody and I have no other way at my disposal OR if I want to spam people I don't care about ... but the real social networking that I'm doing these days is through my phone or through my email address.
Facebook itself may be pure as the driven snow, but I can guarantee the FBI is NOT.
Citation needed (Especially for the obligates part). If Google requires a warrant to share data then please explain why Facebook is obligated to do differently?
http://en.wikipedia.org/wiki/National_Security_Letter
Also: "Note: According to facebook’s privacy policy, messages on facebook can not be deleted anymore. If you click on ‘delete’ the messages will only be invisible to you. US law enforcement agencies can access this information at their own liking, without judicial review."
http://europe-v-facebook.org/EN/Data_Pool/data_pool.html#Mes...
That is until someone wants to actively query it, then it can be made human-friendly, and like you said, we don't really know just what details they are storing and how they are profiling us.
It doesn't ever escape my mind that whichever country I live could just well suddenly suffer from a state coup (or in some cases are already under dictatorships) and right then I could become a political target for the sum of all my recent activity.
Right now I'm living in a democratic state and have my civil rights, and so I act accordingly. But that's all stored somewhere and if things change, the state can simply gunpoint a service and have them disclose all my personnal data. Said service doesn't even need to have a secret agenda for my info, but they are its holders so they might be targeted.
That also brings a different point which is the security in which my information is being held. Can a big service like Facebook's or Google's be hacked? It most surely can. And then, just how much data will be compromised before it's in the wrong hands. Cyberwarfare is here.
Even if they don't they can get hacked (c.f. psn). This is the worst problem IMO.
To elaborate on this a bit, it might not even be necessary for them to get hacked from the outside. It's certainly not impossible for a malicious Google or Facebook employee to acquire (and sell) data.
http://www.wired.com/threatlevel/2010/09/google-spy/ http://gawker.com/5445592/why-you-shouldnt-trust-facebook-wi...
Yes, they will. And when they do, it won't be evil, it'll just be business. Which is evil.
That's both wrong and incredibly short-sighted.
First, Facebook collects way more data than necessary. In fact, they try to collect data of people which aren't Facebook users. And what's more, in some cases (facial recognition), there's nothing you can do against it. But wait, you can! Guess how? By registering on Facebook, to remove tags. I don't know what to call this, but it feels awfully similar to extortion.
Second, the unnecessary data that Facebook collects is dangerous by virtue of existing. Yes, that data might be safe now. We cannot guarantee this to be true tomorrow, next month or in five years, actually, we cannot even be sure if it is safe right now (which is a matter of transparency again). Besides, I don't see how a detailed (which might be an understatement) biography of my life is necessary to sell targeted ads.
Third, as rwolf pointed out in another comment, it's not like targeted ads are the only option. Yes, it might be the best alternative in terms of making profit, but we cannot ignore the side effects.
Besides, I seriously ask myself when in the hell "profit" became an argument to infringe on basic rights and liberties (of which privacy and control over your own data is - or at least should always be - part of). To present a hyperbole: slavery was very profitable as well. I don't see people arguing that we should allow slavery again.
For one thing, services fail to properly inform their users of what they're doing. It's quite common for ordinary users to either not know that their data is being collected and used in those ways, or the extent of the data which is being collected (e.g. Location, Phone Identifiers, and sites visited across the web).
For another, opting out is generally designed to be quite difficult. Unless you're vigilant enough to know which hosts to block (among other things) it's almost impossible to keep your browsing history out of the hands of the hands of third parties (especially with all the different ways browsers can store information, see, http://samy.pl/evercookie/). This is the case even if you do not sign up for or use a service like Facebook.
Also, as someone noted below, there is an issue with the simple fact of the data's existence, since from that point on it is out of my control, and can be used by anyone who can get their hands on it, in any way, which may well be harmful to me.
Maybe not next year, but what about 30-40 years from now? Facebook or Google might not even exist then, but you can be pretty sure that your data will exist, along with your social graph. That's a tangible asset that can be sold, no matter what happens to these companies. Or seized by some government, for that matter.
Is this just being paranoid and obsessed with privacy? Lets hope so.
A german friend put it this way: Most jews in pre-nazi Germany didn't mind having their religious affiliation listed in their passport. Many were indeed proud to be jews.
Would anyone of them have been able to imagine what this information would be used for just a few years down the line? Wouldn't anyone worrying about this collection of data have been laughed at and called paranoid?
In the Nazi Germany example, it was a government entity that was using the information. In that case no amount of privacy controls will protect you - if the information is available they can use the law to retrieve it. Even if Jews didn't have their religion listed on their passport, a government can retrieve that information in other ways (not least compulsory questioning).
In Facebook's case they are selling information to other companies. If the government wants they information they can legislate to get it from anywhere at all (including active surveillance), and so the fact you have shared it on Facebook merely minimises friction for them.
Friction is the only shield we have ever had to protect against invasion of privacy.
YES!!
Far from downplaying it, I was wondering if anyone would pick up on that! It's a really important point - many "privacy invasions" are things that were possible before, but inconvenient.
The truth is, though, that complaining about it is roughly as useful as the RIAA suing Napster. The internet reduces friction, and aren't privacy controls just another form of censorship that the internet will route around?
And I think your example is a bit extreme.
The problem is, extreme eventually happens.
Nazi Germany has been such a commonplace rhetorical device on the Internet for so long [1] that we end up easily dismissing it when it's indeed a useful comparisson. This, for many reasons, would be one such case (we can debate that through email if you want), but let's dismiss it anyway.
The important fact here is that bucket loads of (your) personal data are being processed, correlated with each other and stored into centralized server clusters — which have become very tangible assets.
If someone ill-intentioned — a government, an interest group, a company — gets a hold of these assets — through power, through craft, through acquisition — they can use it to target you for whatever their purpose.
In a warfare scenario, that could mean targeted, granular misinformation; targeted terrorism through AI-generated blackmailing, tailored on an infividual level; mass identity hijacking. It could make war a personal matter like it has never been before.
(And on the other side, there's the Nazi Germany scenario where, unbeknownst to you, you are being blacklisted for a genocide to come — after all, the first step is classification. [2])
The fact that we're living rather peaceful times doesn't mean that a potential weapon like these databases should go unregulated; and the fact that we see no storm in the horizon doesn't mean we shouldn't care about the possibility.
As long as you can imagine what sorts of bad things could be done with that personal data, the argument is: you should care because you don't know for a fact what tomorrow will look like.
[1] If Wikipedia is to be believed, it's been 20 years now since Godwin's Law was first formulated!
[2] http://www.genocidewatch.org/aboutgenocide/8stagesofgenocide...
Then you don't understand the concerns. What is perfectly routine today may be damning tomorrow. Yes, Nazi Germany was an extreme event, but it happened, and there's no reason something like it couldn't happen again. It might not even be anything you posted, maybe you are friends with a lot of people that have radical political ideas. Maybe something you posted could be taken out of context. If you think that all people would be able to get out of this data is "lol, had eggs for breakfast today", then you are seriously underestimating the value of this data.
Facebook now has that information forever and I played no part in them obtaining it. They could launch a feature tomorrow where you can take a picture of a stranger at a bar and be given their 'closeness' to you, or their name. Or that data could be stolen, or misappropriated.
This is about companies over-reaching and then either the data accidentally leaking or intentionally being used without user permission. Most people don't have a problem with it, until something goes wrong.
I'll make it easy - you're not an oracle on the identities of 500 million people, no matter how many camping photos you look at. When you are, we'll be uncomfortable about you as well.
That strikes me as a pretty weakly supported argument. Facebook is in a position where they could do something very similar to Github. Free accounts that are publicly searchable and paid accounts with strict access controls. Many people would in fact pay for that, probably to the point that they could ditch ads on the free version.
Now, they would have to stop rewriting the code that manages access permissions every six months, but I would bet they could totally do that if they stopped treating ad revenue as the only way.
Nothing new under the sun, just bigger and worse.
However, there's nothing that says Facebook has the right to become a $100B company through extreme invasion of privacy and other distasteful tactics (whatever they may be - I sure don't know what fully goes on over there). Send me some targeted advertising if you have to, but I will protest against you if you make new "share-with-others-additional-information-about-yourself" features a confusing opt-out hassle.
Just recently my wife shared a photo album via Picasa and Google+, and she couldn't figure out how to restrict who could access the album, though it was very simply prior to Picasa's integration into Google Photos. Do you think Google+ engineers couldn't keep the same Picasa privacy functionality as before or is it because they want to force people to share more than they're comfortable with?
No one is saying that social networks shouldn't make money through advertising and most people are probably okay with some personal data being used for targeted advertising. But given past invasive practices and privacy concerns, there are definitely valid concerns with regards to the extent to which social networks are commoditizing/selling users' personal information in an effort to maximize profits. Furthermore, who knows what happens to sold personal information down the line?
Simple question: If changing social networks was as simple as changing your online shopping preferences, do you think Facebook could get away with what it does? Facebook can obviously take advantage of the fact that its users cannot easily leave to appropriate user data that other sites could not.
If you ask a HN-reader to choose either 1) less intrusive data collection or 2) more profits to the website, I think it's clear why the user prefers door #1.
Some people don't like simple remarketing, but I do. It's not so bad that Bonobos reminds me to buy pants from them every once and awhile... I like their pants ;)
And I'm not sure of the brand effect display ads have had on me but I know I'd rather see something relevant to business, finance, or tech, as opposed to feminine products or entertainment magazines.
Yes, I'm speaking the advertising industry party line, but I do kind of agree with it.
Do you think everyone likes these ads, and the ones who are complaining are just whining without really thinking about what great pants they could be buying?
Do you think some other people may not like these ads? Is it odd that those people would try to pressure companies into not showing these ads?
Do you think one side of the other is in the majority here? Can either side speak "for" the masses, who don't talk about/understand ads one way or the other?
When in reality the question is: "Do I want a thing with good and bad attributes, or another thing with good and bad attributes?" - this reflects the reality of the situation
If there's no injury, there's no standing, and therefore there's no case.
You last sentence starts with "If there's no injury," which seems to be the topic of discussion here.
Facebook settled that particular lawsuit, so no judge had an opportunity to determine whether there was an actual injury or not. Facebook itself admitted no wrongdoing - settling this sort of thing usually means you've done a cost-benefit analysis and it's cheaper and easier to just pay off the lawyers.
As for the independent privacy foundation that Facebook was required to fund - anyone here heard from it lately? (Anyone here heard of it at all?)
And as for Beacon itself being closed - well, it certainly doesn't look like it slowed down Facebook much, did it?
The Beacon lawsuit did nothing for anybody, aside from the plaintiffs' lawyers. Arguing that 'users won' is delusional.
I do think that being more upfront and more transparent would be a good thing, there are alot of misconceptions out there.
I did not expect that when I visited cnn.com, after having logged into Facebook a week earlier, Facebook would log which articles I read. There was no reason for me to think that clicking "remember me" when I logged into Facebook also implied "and also remember my browsing history on all of your partner sites."
That's the behavior that pisses me off, not the targeted ads that you mentioned.
(I assume it's obvious why logging a subset of my browsing history without my consent pisses me off, but let me know if that seems odd and I'll explain more.)
The reason it pisses me off is that my browser history reveals things about me that I'd rather keep private. Facebook is taking that from me without my consent. I would feel approximately the same if I discovered they were stealing stuff out of my garage without my consent-- it wasn't part of the deal I thought I agreed to.
Without getting into the details of my particular situation, I'll just say that I have political and religious views that I think are unpopular, and I don't trust the rest of the world to treat me fairly were those views made public. Also, even my views weren't unpopular now, I want to be judged for what I do, not what I read about on the web.
(I should also add that I don't think any of the private stuff that I mentioned is creepy; it's just my private business. For example, I might feel the same way if I were gay and lived in Mauritania (see http://en.wikipedia.org/wiki/LGBT_rights_in_Mauritania).)
Seem reasonable?
As to who is doing the deception, I think you're right that (in the example we're discussing) cnn.com is being deceptive. That's a good point; I hadn't really considered the complicity of the partner sites.
But in the end, Facebook is producing widgets, building a system to receive data from those widgets, and working with their partners to deploy those widgets. This system of data transmission is in no way obvious to normal people; if I weren't a web developer, I'd just think I was seeing a "like button image," and that's it. That's the part that pisses me off-- I think it's sneaky, not just me complaining about something I originally agreed to.
Just out of curiosity, and assuming you actually have a Facebook account, this really doesn't bother you at all? Should it be obvious to me that buttons I'm not clicking may be transmitting data to other sites?
The good news for me is that I'll probably be dead by then, or at least most of my friends will be, so Facebook will be of no interest to me.
I'm curious about why you describe your belief as idealistic. Specifically, what is ideal, or even good, about Facebook logging a subset of my browsing history? I understand it's potentially profitable for them and their partners, but that's not a benefit to me.
My idealistic view, which is substantially in conflict with yours, I think, would be that Facebook just serve me targeted ads and forget about the rest of it. Why would your ideal future be better? (I'm assuming you don't work for Facebook or one of their partners.)
I never want to meet you, if you see nothing wrong with snooping around my life and sharing all my secrets with everyone.
It's harmful because it's abusive.
Next year they will want more revenue, so how deeper will they go for that, will they break my windows open and storm the house?
I know it's an exageration, but it ilustrates my point.
In your example, those people breaking into your home is wrong. Watching you when you are in public or on their property would not be.
It does happen without the knowledge of many people today, and the surprise when they find out what's really going on has led to a lot of backlash, but the solution to that is to educate people better about technology and what it can do, not to limit technology so that it can only do things the average person can conceive of.
What about the people who haven't signed up to Facebook, but who still have data about them logged? I see nothing mutual about that relationship.
I'm not a heavy Facebook user, but what you said certainly does not apply to google.
What was once unobtrusive ads now are just ads cleverly disguised as search results in a very faint slightly different background-color box. They wanna pass the ads down as search results and that certainly impacts user experience.
These guys are wise enough not simply through the ads in there altogether, they let you grow accostumed, than just enlarge then a slight bit every now and then. That is not a mutually beneficial relationship, that's an abusive relationship.
1) Oh, what a cool service! For free!
2) Huh, they're showing me ads for stuff I'm interested in... what's up with that. Oh! They're selling "me" to these companies! OMG! Privacy!!!
3) Ah... well if I know exactly what they are and are not selling, and I get the free service, I guess that makes sense and I'm ok with it. It beats paying, and I do like using it.
The writer poses the question "what's the alternative?" to this business model. My answer, "Stop being lazy about it and come up with a new model. I have."
It might work it, it might not, but we all have to keep trying if we don't want what there is now - and the implications.
We are uniquely positioned to come up with another avenue of generating revenue so it doesn't have to be this way.
I'm sure if you work at Facebook or Google you see no harm in gathering and cross-polinating the data, I can see the sheer power of what you can do must be quasi-orgasmical, and it must almost have a life of it's own. Just how much can you gather, from how many different methods? It's like a college project with no limits but it won't last forever, someone somewhere with something different, will come and take that crown, and maybe, just maybe, it won't be as clandestine as it is now.
Eric Schmidt's "If you have something that you don't want anyone to know, maybe you shouldn't be doing it in the first place" and Randi Zuckerberg's "I think anonymity on the Internet has to go away" are some choice quotes that should give anyone pause.
"Go ahead, sell my data" doesn't bother me. "How come you aren't putting yourself out there and letting your data be sold like the rest of us" bothers me.
There's no arguing about this subject with people who believe that people should not have the right to control their own data, just as there is really no arguing with people who don't believe in the value of free speech or the right to vote.
This is not meant as an insult. Believe what you believe. But if you want to argue the reality of negative consequences, please pick up some history books first. And if you do business in my part of the world, respect the local law.
There's no inalienable human right to data about you unless you want to argue that it's somehow your property. (Or that it relates to life, liberty, or the pursuit of happiness). More likely data about you is just information on a public stage.
If I see you walking around town and write it down, is that illegal? Am I steeling something from you? Is that illegal search or seizure? I'm creepy, yes, but I'm not infringing anyone's rights.
So we're all just creeped out by Facebook. As yet no one is being harmed.
> There's no inalienable human right to data about you
Eh...yes there is. Maybe not for you, but I, and others who were born in the EU have quite inalienable rights to data about us.
EU laws quite explicitly state that, yes, I do have an inalienable right to data about me, unless I explicitly (and possibly temporarily) grant a company access to it.
A company is legally obligated to provide me a list of all data they have on me, plus the ability to change this data, including me demanding all of it to be deleted.
Is this relevant in dealing with US based companies? No. But of course the EULA of Facebook specifies that European users have an agreement with Facebook Ireland, meaning all these EU laws apply to this relation.
> If I see you walking around town and write it down, is that illegal?
No, but writing down and storing that you saw me walking is...
Now, maybe you don't care about what right you have to your data. But I do, and I endorse any action forcing big companies like Facebook and Google to comply with the EU law, which firmly puts me back in control about my data.
Oh wait, aren't they doing something similar in Italy?
What if your boss checked which sites you visited before hiring you? What if you wanted to keep something from your wife or your children? What if the person you just met at a bar wanted to find out all the pages you visited? What if a stalker wanted to know where you shopped and what you bought?
All of the above can easily be done with just the tracking information the Like button has.
A good rule of thumb is to just assume that anything you post could be made available to any company.
If you want to show your life on the Internet, you have to expect some people taking interest in it, whatever the intention.
What I can't understand is how we are all upset about Facebook, Google, Apple, Microsoft and our privacy when we have NEVER given a damn about how credit card companies profile their client.
And credit card companies are so much worse because they first sell you credit card (via flat fee or interest rates) and then profile you and use that information to sell you even more stuff.
I don't see what's funny about them complaining about privacy when their information is shared with people they did not intend it to be shared with.
(I'm a heavy social network user, but I mark everything public and don't trust or expect facebook or google to keep anything private)
what is the username and password to your online banking account?
When you access a bank you are publicly trading the information between you and the bank. That means that if somebody on your LAN sniff your cookies (and SSL wouldn't be used) you could use their account on their bank website.
So yeah, bank info is public as well.
You cannot use the internet and expect things to be completely private like you can't go in a bar get naked in the middle of the dance floor and expect nobody to notice it. (Ok, this is far fetched but still.. I thought this was funny :P)
But I use SSL when I connect to facebook. And its not the data facebook collects as it files over the wire that is being called into question here, it is the actions of Facebook once they have the data.
The point the parent post was driving at is: Is it OK for the bank to do anything they want with my personal data just because they (like facebook) happen to operate on the internet?
In the world we have, though, I'll take what I can get.
I say bring it on. I look forward to the day when an algorithm tells me my taste buds prefer extra spicy beef panda express, order now and have it air delivered to you in ten minutes
On one hand, I think "I can find my own products thank you" while on the other I understand the crowded space and targeting advertising does reduce the signal to noise ratio. (this is debatable I guess?)
Privacy laws and rules provide some projection, but that only goes as far as they are enforced. Nonexistence of data cannot be subverted and is a much more robust protection against the data falling into the wrong hands.
The issue isn't necessarily who has the data now. It's who might get it later.
Intruders count as the "wrong hands". A future buyer/board/CEO with fewer ethical scruples than the current managers of a given data set may count as the wrong hands, or allow it to fall into other wrong hands.
Maybe they will never sell your data, but maybe they will. There's unlimited potential for abuse from the corporate sector. What the FBI knows about me doesn't worry me much.
I'm sorry to be blunt, but that's degenerate, plain and simply. If the day arrives when people give up thinking for themselves, we've truly arrived at an Orwellian society, and your friends are damn right - we're not very far away from this.
Although it's not necessarily a discussion of their own willpower but rather whether the masses will lose portions of the power to think for themselves. Not always the same or hyperspecific portions, but we're slowly giving away more and more of our decisions to advertisements.
/Disclaimer: not sure whether I paraphrased this correctly./
Hopefully we can also use the same technology to liberate ourselves from the magnetic attraction of ads and the media and do something positive. I'd look to recent events (Arab Spring, #OWS) as a possible glimmer of hope there.
Facial recognition is shortly going to render every digital photo and video ever uploaded to the net FULLY IDENTIFIABLE as to all of the people pictured. Coming in 2020: a startup (or Facebook plugin) that traces your entire life through publicly available photos and videos.
Kevin Curtin has a very limited imagination regarding the privacy apocalypse that is upon us. The data shadow that follows every person around is already huge, and will become gargantuan. It's already inescapable and out of your control.
That uber-detailed personal profile used without your consent worries me a bit less - while we'll get to the same place, it'll be completely because of voluntary sharing of information. You'll want that profile, because it'll save you lots of money.
People tend to worry that negative things will happen to them if information about them is used without their consent - for instance, your example might worry that his insurance premiums will go up because he's buying Wild Turkey in bulk and surfing pages on alcoholism.
This will never happen.
In reality, positive things will happen to people when they freely consent to share positive information about themselves - and as those people are rewarded, the pool of people who don't share becomes riskier and is therefore economically punished for not sharing.
Two examples that are with us today:
-- Car insurance. Students with better grades tend to have less accidents, so you can get a better insurance policy from your provider by voluntarily turning over your grades. Since turning over your grades is a simple thing, the result is predictable - if you don't turn over your grades, it's safe to assume you have bad grades (and therefore are an accident risk). You've kept your privacy, but your premiums are still going up.
-- College tuition. To qualify their kids for student loans and aid, parents have to supply full documentation about their income. Parents do so voluntarily, because it can only benefit them - but this means if you don't submit documentation about your income, the college can safely assume you have a lot of money, and you get charged the highest possible tuition. Keeping your income private could cost you tens of thousands of dollars a year.
When personal information starts being used for things like insurance premiums, Blue Cross won't be creeping through your credit card receipts without your permission - instead, they'll invite users to voluntarily share their web, purchase, or location history, and they'll use it to reward them with a discount. As more and more users do so and are rewarded for the healthy lifestyles reflected in their data, the body of people not bothering to share will get riskier, and their premiums will rise.
Same outcome, no privacy violations.
Or rather - I see the problems, but I think they are overstated. Just saying "PRIVACY GRRRR!" doesn't make sense - it is much, much more subtle than that.
The poster explicitly addresses this:
I understand the instinctive philosphic reaction that "we own our data" but when I dig beaneath that initlal gut response I come up empty. I do think there is an important distinction between privacy and security that sometimes people miss. There is certain information (address, account numbers, ss #, etc.) that if obtained by a third party, could result in some real world problems that will negatively impact my life. But information social networks sell to advertisers doesn't fall into this category.
Your comment simply fails to address this. You seem to be stating "Technology is powerful! We should be scared", but without addressing the very real points the poster made it doesn't really add a great deal to the discussion.
The so called privacy apocalypse is far from it. "Nightmare" scenarios like you spend 15 minutes every day at the local coffee shop during working hours plainly aren't as bad as you seem to think. It's trivial for a company to track how long a person spends in their office already - companies that care about it already do it.
Given that commercial consumer databases already exist, please explain why the worst thing to come from it is annoying unsolicited mail and phone calls? If that is a privacy apocalypse then I feel it is a small price to pay for using services that don't charge us money.
But what of the more specific nature of some of the things you and your friends discuss on Facebook?
What if bosses or potential employers could pay to look at your timeline? What if they could ask to see your GPS tracking data? What if Facebook could rent out user info to advertisers based on like button activity? Ever 'liked' anything pretty dodgy?
The point isn't that, obviously, they can't and probably won't at the moment. The point is how far down this route do we want to go and at which point should we draw the line.
We should be focused on limiting the 'evil' applications of personal data, regardless of the source. If an employer, bank, or insurance company discriminates against you on the basis of personal data they purchased from Facebook, Facebook isn't the offender.
We regulate the credit rating agencies and how credit scores can be used. That's sufficient. Why wouldn't a similar model work for personal data?
To be clear: Gathering too much personal data, and holding it (even when the user has asked for it to be deleted) is itself an evil application, and that is why the EU has laws about it.
And surprisingly, seeing what they are and are not capable of, I don't have a problem with that.
We represent top 1% most aware users here.. most users do not understand they are exchanging their data / attention for a social networking service.