Study claims Amazon, Apple, Google, Meta, Microsoft work to derail data rules
theregister.com
theregister.com
Another issue is this: breaking some of these privacy laws both in force and proposed, is really quite easy to do - as easy as a misconfigured logger or a developer including the wrong field in a query.
Yeah, that seems to pretty well describe most all legislature these days.
Indeed and I don't see how that changes _structurally_ when people "in the know" are always going to be a tiny minority — they say that about 3% of the population has the profile to work in tech, and I tend to agree anecdotally.
I feel it's comparable to the inception of medicine for instance, and the solution was auto-regulation of the field by itself through the application of a loud (public and transparent) set of deontological rules of practice ("Primum non nocere", etc).
Awareness of society about these issues re. privacy and information sanctity in a democracy will not come naturally, structurally as time goes by. Just like they don't really know how doctors make life-or-death decisions on the spot. Nevertheless, the right principles should eventually exist, be known, and abode to, by those who work in the field. It should be loud and clear that we all have ethics (rules, implementing guiding principles), and which exactly.
A deontology of information technology and its practice in relation to human beings is one big "TODO" of this century, and it should concern anyone even remotely skilled to understand the problem.
Besides, private companies don’t have the force of law to force people to do anything.
Giving the government more power over your freedom is never the answer.
As more and more consolidation happens I'm not so sure this is still true. If all grocery stores become zero-human Amazon markets and their AI decides your long forgotten, hobby EC2 instance is past due then can you buy food?
Rent an apartment?
Fly on a plane?
Elections in the US need reformed, no doubt. And governments have a monopoly on legal violence. The answer isn't to keep handing the keys to the government over to whomever/whatever has the most money.
https://accelerationeconomy.com/cloud/amazon-shocker-ceo-jas...
The grocery store market is definitely not a monopoly
https://www.statista.com/statistics/818602/online-and-offlin...
And Whole Foods makes up less than 2%
There is definitely not a “tech monopoly” on renting an apartment. On the other hand, the government can and does take away peoples property through both imminent domain and civil forfeiture.
The government already controls who can fly and who can’t via “no fly lists”
https://www.aclu.org/issues/national-security/grounded-life-...
So no, I have no desire to give government more power.
A company can only “violate my rights” if I choose to use those services. It’s much easier not to for instance use a phone with an operating system controlled by an adTech company than it is to not have to deal with a government.
Do you really think a government that always pushes the limit on being a surveillance state cares about your “privacy”?
Prior to 1983, nearly everyone in the US and Canada had to lease their physical telephones (wired and wireless) from Ma Bell, and if you didn’t like the phone Ma Bell gave you, tough luck. Your other choice was to simply not have access to the PSTN.
https://www.encyclopedia.com/finance/encyclopedias-almanacs-...
If you want to have rights in any meaningful sense, people's actions must be limited such that they don't violate them overmuch.
>A company can only “violate my rights” if I choose to use those services.
That's complete nonsense. But even if it were true, how do you suppose that would help you if you don't have a handy oracle that provides you perfect information about every company's actions past, present, and future? It's not as if a company is likely to advertise practices they don't want you to know about. And there's nothing (aside from the government) preventing them from deciding the day after you purchase goods from them that, for example, they're not going to honor warranties anymore. And, of course, you don't have to buy from a company for them dump industrial waste on your property.
>It’s much easier not to for instance use a phone with an operating system controlled by an adTech company than it is to not have to deal with a government.
Is it easier to purchase all your goods and services from companies that have no objectionable practices? You probably don't have many choices of ISP and it's increasingly difficult to find a TV without some manner of integrated as tech.
>Do you really think a government that always pushes the limit on being a surveillance state cares about your “privacy”?
"The government" is not a single entity with only a single goal. Do I think that well-written legislation aimed at protecting privacy would, in effect, tend to protect privacy? Of course. Do I think that would stop the NSA from violating citizens' right to privacy? Of course not.
The last law related to tech that I can think of that was user friendly was phone number portability.
This isn't just about revenue. People are assassinated by the US government without trial based on metadata.
/s
This is an oft repeated argument that makes no sense. The point of privacy legislation is not to increase competition. The point is to increase privacy. The government has other legislative tools to increase competition should it wish to do so.
> With sadness, StreetLend was shut down in April 2018, after five years of operation.
> Unfortunately the European Union's new GDPR (General Data Protection Regulation), introduced on 25th May 2018, creates uncertainty and risk that are impossible to justify for small non-profit websites.
It looks more like someone who does not like the GDPR (because it affects them in some other way, because they are mislead, out of principle or who knows what reason) who then chose to sacrifice their pet project to make a statement.
It's so nonsensical that occasionally I wonder if this is an argument made primarily by the incumbents themselves in order to maintain the status quo.
There is no point without a person to have one. This is your point. It's absolutely impossible to generalize it to everyone who works to pass "privacy" legislation, and simply incorrect. Sometimes you try to pass privacy legislation to reduce privacy. Sometimes you try to pass privacy legislation because you have a product that would sell more if it passed. And yes, sometimes you try to pass privacy legislation because it adds so much red tape that you need a full time employee, a team, or a department to comply with it, and you know potential challengers can't afford that yet.
Nobody is unseating social incumbents. The industry is out of the growth phase and needs a firmer hand.
So if I drive accidentally over the speed limit I should not get a ticket? That's a weird argument isn't it? Moreover, we are talking about companies with billions of revenue, they can afford to pay people to make sure things work. If you are worried about large incumbents using the laws as barriers (a weird argument, should we not protect people first, not companies?), just lobby for fines to be a fraction of revenue.
Moreover, the behavior of the big companies in Europe shows that they have and continue to intentionally skirt and break the rules as much as possible until they get hit with fines. I really have very little empathy with Google, Meta et al.
Privacy regulations can make it very difficult to for competitors to start up with abusing information.
Summarised such a complex topic in 12 words.
And I can't even summarise my function refactoring changes in less than 20 words.
I've never heard of it and I don't think it's common where I am (Canada). Sometimes people coin terms and they get picked up in some places, but not others.
When I lived in Germany and the Netherlands, it was often surprising to me which foreign terms/concepts/artists get elevated to mainstream relevance. There's a lot of imported culture from English speaking countries, but it's through a specific filter.
Here's an English source from the article you shared though: https://www.theguardian.com/technology/2018/may/27/jaron-lan...
"All of the companies cited by The Markup – Amazon, Apple, Google, Meta, and Microsoft – have dominant or emerging online ad businesses, which rely heavily on data collection."
Nope. Apple does not have an "dominant or emerging online ad business". Apple has no ad business at all, let alone one that "relies heavily on data collection".
Is it too much to ask to have some professional editors vetting these articles before publishing?
Understanding the ways this is different from, say, Google Ads, AdRoll, or TowerData, is nuance beyond most journalists.
Not that it’s hard to research. Consider:
Apple Search Ads doesn’t buy or share users’ personal information with other companies. We don’t track people by linking user or device data collected from Apple apps with user or device data collected from third parties for advertising targeting or measurement. And we don’t share user or device data with data brokers. — https://searchads.apple.com/privacy
Pro-tip to journos: the story is in what comes immediately after “which rely heavily on data collection”.
Data is collected. Then where does it go?
Do you think there's equivalence between selling user data to a marketplace of 4,700 third parties, and an internal machine-learning-sized A/B test?
https://themarkup.org/ask-the-markup/2021/09/02/what-does-it...
Or put another way:
> So the argument is, because they ... don't share with anyone else they are vastly different?
Yes.
> Even though companies like Facebook and Google aren’t directly selling your data, they are using it for targeted advertising, which creates plenty of opportunities for advertisers to pay and get your personal information in return.
https://appleinsider.com/articles/22/04/07/apple-leaves-priv...
But even otherwise, the links between the companies and legislation are weak to begin with (IMO). Its a lot of lazy connect-the-dots type reasoning that turns "may be" "could be" "seems like" into "must be" and "is".
i.e. it's 'easy' for a individual (even a smallish similar group). But in society-scale? difficult.
Tech has the most impact on user privacy, but there's no financial incentive to uphold privacy and so the slow political stick is required.
Meanwhile users can do their best installing ad blockers, navigate the snake-oil fields of VPN vendors, estrange themselves by quitting social media, set a different search engine on all their devices (which probably still use Google/Microsoft), maybe look into TOR and Whonix, ensure they use email masks and unique usernames for every service, buy Twilio numbers for account sign-ups, get their contacts to use E2E-encrypted messengers and PGP, get a dumbphone that doesn't have GPS enabled at all times, a laptop with camera/mic killswitches. It's not clear which of these steps are excessive or impractical for the layman, aside from ad/tracker blockers.
So the tooling to uphold user privacy is there, but it's nuts to think the solution is for everyone to adopt better privacy-preserving habits rather than slowly killing the business model of the personalized ad industry. A great byproduct of this is that governments will see less surveillance tech vendors to buy from.
Right to the heart. The personalized ad industry has exacerbated the issues of privacy, because it's in their interest to do so.
Having enforceable ground rules in place, in the form of laws, will be difficult because of the money involved; and also the sizeable number of software engineers feeling like they're above the politics.
I remember when both Intel’s CPU ID and Microsoft’s system updates (because it sent your info to their systems) caused an uproar.
Now we don’t blink when talking about telemetry.
If you want E2E encryption, you sacrifice good full-text search, because you have to build the index on a computer that has access to the plaintext, which means doing it on an endpoint. It’s not as nice as doing it on the server.
If you want to hide metadata, the state of the art is onion routing, and that adds a lot of latency. The only other way that’s even been attempted is Enclave computing, which basically just moves the trust from the service operator to the enclave vendor. Enclave computing is better than nothing, but it belongs in a defense-in-depth approach, not a privacy strategy in itself.
And if you want to avoid fingerprinting, you lose responsive design. Those two things are just directly in conflict here.
I'd argue it's better than on the server. Bring me back local computing, please. It's more private, more performant and more energy efficient. The attempt to centralize computing into central server nodes is not reasonable.
Engineering is about trade-offs; understanding which trade-offs are acceptable means understanding what it is you're trying to solve; then assessing whether the problem is being looked at from the correct point-of-view (and for that matter whether it's even a technical one).
For example: Journalists within hostile nations are risking their lives every day. Because of this, they're keen on keeping their communication private and away from prying eyes.
So far, the compromises largely involve zero-days and social engineering. The former is really due to the shaky foundation of software today. Every single best practice I see is just awful. Whereas social engineering is an on-going problem and is a policy/procedural/cultural problem, not a technical one. The union of bad software and tolerant social protocols make privacy difficult.
Going back to your objection: For use cases where your life is on the line, is a few seconds or even minutes of latency really a problem? Extend the question, for cases where it's not life-threatening but life-altering. What trade-offs are most users willing to make then?
If you're not willing to make any trade-offs no matter what, then it's difficult or even impossible; and also a sign of a poor engineering process.
I think the example the guide gave was "bowlers in the upper midwest" .. it was made clear that we could make a job submisison and be sold data on those people. Someone asked if law enforcement was a customer and the answer way "yes we do business with all branches of law enforcement".
Choosing to work there today means choosing to hurt society for personal gain, full stop.
I would accept friends and acquaintances recognizing their participation, as well as my own as a user of some products, and observe plus work together to figure a way out of this mess (regulations, break up of big tech?)
One also must recognize the philanthropic arms of these companies. They may be some attempt to balance the shit they're doing.
if they don't, then who does?
Google with Android and ChromeOS has put computing devices in the hands of people who could never afford the alternative and YouTube has allowed anyone to publish video.
I myself find Google’s products second rate and I prefer business models where I give the company money and they give me stuff. But I realize that a $1200 iPhone Pro Max is an indulgence that many walking around with a $35 unsubsidized phone can’t afford.
There were video sites besides YouTube. YouTube cornered the market. That doesn’t make them special. All the examples are one brand cornering a market without having done any exceptional innovation that would be incredibly missed without them. Cornering markets is almost never a net positive for people. I should probably say it never is.
WebOS was also much slower than Android at the time.
YouTube costs billions a year. Few other companies could operate at that scale.
> Facebook has allowed anyone to spread video capturing police misconduct that the mainstream press has ignored for decades.
Facebook didn't allow that, they enabled it, as well as many other places. In fact, if it's on Facebook, I can't see it. Smartphones in general created the glut of police misconduct videos, because everyone started carrying video cameras 24/7.
> Google with Android and ChromeOS has put computing devices in the hands of people who could never afford the alternative
I do not believe this is true. I don't think they put computing devices into anyone's hands, and that there are also cheap alternatives. Android and ChromeOS crowd out (real) FOSS alternatives, and iirc ChromeOS started by crowding out Linux on the trendy tiny laptops that were being marketed in the mid/early-oughts.
Having a monopoly on the low-end market isn't charity work.
As far as Android vs the alternatives, Linux was no more ready for the phone than it was ready for “the year of the Linux desktop” to happen.
The Linux desktops that it crowded out, didn’t offer the backend server components that make ChromeOS desirable to the target audience.
These companies do a lot and I do not think you should trivialize all that they have done by saying that they've done something bad in the past and not even say what they have done. Have you considered the people who want to work their want to actually improve people's lives working on these different projects. Have you considered that large compensation can make people ignore issues. Have you considered that people are just interested in working on the stuff that's available there.
All those things you mentioned are great, sure. But to my mind, something can be useful, fun, loved, enjoyed while actively making your life worse. The obvious example being addictive drugs.
My smartphone, for example, has definitely made a lot if things more convenient. It use it all the time, for all sorts of useful things. Marvelously useful piece of technology, the smartphone. Has it improved my life? I'm honestly not sure, but my gut reaction is no, because it's ruined my already limited ability to focus(I have ADHD). It actually makes me far more productive having my phone turned off, despite how useful I seem to think it is.
My point is that something can be useful and do all sorts of things for you, but that can still be true while it's actively harmful to you. And you might not even be conscious of this about yourself, let alone most of the global population.
I would argue none of these are free, because they use/sell your data. If it wasn't so google could not exist.
> Facebook allows you to connect with your friends, talk to people about your interests, a marketplace, entertainment from photos, videos, streams. Meta also offers Insta for sharing photos or stories and they are investing heavily
For facebook and instagram there are at least studies which have shown the harm they are doing to teenagers and children, so there is at least some established facts that show the bad influence (lets not even get into the political bits).
> These companies do a lot and I do not think you should trivialize all that they have done by saying that they've done something bad in the past and not even say what they have done.
That's a slippery slope though, at some point you can justify working for anyone because you don't want to consider their actions of the past to judge them. What about continued action though, e.g. meta burying their own studies on their affect on the mental health of teenage girls just to continue making their profits. At some point someone has to take responsibility to continue working for them (and some people are even actively involved in these decisions).
In a technical sense sure, but from the user's perspective it's equivalent to being free since the user doesn't have to do anything different compared to if it was a free service.
>meta burying their own studies on their affect on the mental health of teenage girls just to continue making their profits
Are you referring to the study that said that Instagram on average improved mental health in 12 out of 12 categories for teen boys and in 11 out of the 12 categories they were surveying for teen girls (the exception being that 32.40% of teenage girls with body image issues felt Instagram made it worse)? It was internal research which is why it was initially kept internal.
... They think exactly the opposite. Google even has an estimate of how many lives their services save per year on average.
Privacy concerns become extremely secondary when you're stranded in the woods and all rescuers have on your location is the last time your GPS-equipped smartphone pinged. Googlers think of themselves as working on systems like that.
intentions: Holy! effects: annoyed consumers, legal maze for smaller companies, more job opportunities for lawyers
But they were impacted by billions once Apple did one 10 line rule change strengthening privacy and pop up on apps. It didn’t take a 11 chapter 99 section law.
If there were one federal set of guidelines it would be better.
But then again, the GDPR made a shit show of the web and made it less usable with cookie banners on every page.
Sites aren't required to have banners - the intention of the legislation was to encourage and nudge companies towards more straightforward business models, based around what users reasonably expect etc. You only need banners and consent where cookies are used for purposes the user didn't request (adding an item to a shopping basket doesn't require consent, but profiling a user and sharing that with third parties for retargeting isn't something reasonably expected, so it would require consent and disclosures of the companies involved).
Going slow though, but that is hardly surprising (and the opposite would be alarming)
It has given users tons of options regarding exporting and deleting data. Changed the defaults and limits use of personal data. These are all huge and goes way beyond internet.
Users now have an ability to more easily see how their data is being abused and which companies are too greedy to not ruin their own websites.
For the first time in a very long time there is hope.
Then again, we have people who still believe GDPR is about banners, we have long ways to go but it is the first step in the right direction in forever and it is a huge step at that, we have barely started reacting to it.
But no, I don't have any numbers for it. You'd might consider having an open mind though. I'm for one is done with this "discussion".
I’m very willing to have an open mind when given facts and statistics with citations.
it’s built-in on Safari actually
https://www.statista.com/statistics/1150709/ecosia-search-en...
In contrast, the rest of us got a worse user experience.
the users are now more aware of unethical business models and have more control over which third-parties can access data
Consumer end up clicking accept all on every single webpage, after the equivalent of an attention grabbing popup, something we were happy to see disappear when organisations ( and not governments ) decided to pretty much ban them from browser.
What has improve my privacy:
- Disabling third party cookies via a browser setting (than you Mozilla and Apple). I can understand why websites that I visit might put cookies on my computer. I am even Ok with them tracking me when I visit their websites, but I do not feel why the need to track me outside of their websites
- Deprecating some api used for fingerprinting (thank you Mozilla and Apple). These API were not designed for those reasons, but where abused. What works here is technical expertise to maintain their general usefulness, while preventing the abuse. The various laws had close to 0 impact.
- Apple private relay (thank you Apple), preventing even more tracking, again through *technical* means.
Things that do not help : - Clicking a button on every single website I visit. I would love to be able to put a setting in my browser to tell what I feel is OK with regard to cookies, and have my browser handle those since cookies are managed by my browser anyway. But the law won't allow me to do that since consent must be "specific", meaning that I need to express my consent for every single domain I visit. Note that this makes private browsing almost unusable since I have to repeat "consent" again fr websites that I already visit quite often. This has *reduced* my global privacy.
- Asking a website about my data. I did once for the lolz and never did it again. In my company, we get an average of one query every 3 month for thousands of daily users. But it justified some lawyer salary while we did a "project" out of it. So I guess it payed some suits guy a new BMW.
As a citizen on the web, GDPR et al. have made my life worse, while Mozilla and Apple made mine better. As a professional, these law have directed a small part of my revenue to lawyers, but haven't changed a thing about what we were doing and how we were conduction our business.There are better use of taxpayer money.
GDPR wasn't written for technical users but for all citizens of EU. By having banner they have at least possibility to reject tracking.
Also there was a DNT header initiative. Simple and elegant, serer would get the header from browser and would stop tracking you. You wouldnt even see it. Did it work?
There are no good methods to block cookie banners.
It seems to me that Apple - a private company - had a lot more of a measurable effect than the government. Major companies like Facebook have explicitly said that Apple’s new policy had a material effect on their earnings.
Third party browser disabling is now enabled by default in firefox and safari, so no operation needed. API used for fingerprinting alternations require no operation on my side. The only thing that require activation is private relay, which needs to be done once and is much simpler than all the legislation around GDPR, cookies etc.
> Also there was a DNT header initiative. Did it work?
It didn't because honouring it was a server side choice. Just like honouring the EU cookie law is a server side choice and doesn't really work either. If you don't want a cookie to be used to track you: don't send it.
Anyway, if you are so annoyed by cookie banners, you can use this (and few others), works like a charm. Just a warning to website owners, this doesn't mean you got a valid consent from a user of this addon, and as you didn't, it means you cant track them or you are in violation of GDPR. https://addons.mozilla.org/en-US/firefox/addon/i-dont-care-a...
It would be so much easier if DNT would be honored. Now we are having a law that penalizes the violation of PII (which is defined so broadly, that you cant workaround it - even unique id in a cookie signalizing you are rejecting cookies is PII; nice try, next time read GDPR before trying futile tactics) to the point where you need to take care what you are doing. And GDPR is just the beginning, it is only most widely known but currently 17 countries are having similar legalization and new are coming.
Or maybe a more simple to understand: chlorofluorocarbons (and other ozone depleting substances) were a good business for decades. They were recognized as harmful to ozone and life in general and were forbidden to use. Some companies went bankrupt, some adapted, some were lobbying and complain for another decade. Today we no longer use/produce ODS or at least in minimal quantities.
And the same will happen with user tracking.
Also: I really don't care about analytics cookies, I think they are fair game and can genuinely make many websites/tools better when used correctly. So how can I express this measured and informed consent globally ? (Answer is: I cannot due to how the law is written). And with ton of added legislation, the user life won't get any easier.
I don't understand the parallel with chlorofluorocarbons. Banning that substance stopped its production and thus its harmful effects. PII on the other hand are - as you mentioned - defined so broadly that they are everywhere. Simply having a login button means you deal with PII. Having access to the user IP (aka: replying to an HTTP query !!) means dealing with PII. Sending an order confirmation by email means dealing with PII. You can legalise all you want, but these data are still going to be there: their production will not stop the slightest. In almost all the cases their usage does not cause any problem, unlike chlorofluorocarbons.
That is why you should be happy about GDPR as it covers all your use-cases.
GDPR is actually great but no one reads it and only listens some scaremongering by companies that are hurt by it. The problem of mass surveillance and abuse of personal data is also huge. But again no one thinks about it outside some cookies and ads.
Enjoy watching about GDPR: https://www.youtube.com/watch?v=-stjktAu-7k (best done presentation that I was able to find on internet, you might notice in first few minutes that is not about you having access to PII but about using PII - or: I have access to a gun. But I wont use or abuse it. As I might end in jail.)
And reading about privacy and business abuse of it: https://www.amazon.com/Age-Surveillance-Capitalism-Future-Fr... (you will love Pokemon part).
There are more, but those two are best sources I am aware of to get you up to speed.
Then we can talk again.
Have you read the entire 11 chapter 99 section GDPR.
Anyway, check this beauty of simplicity: https://youtu.be/-stjktAu-7k?t=402
"Be nice and you wont go far wrong"
Or maybe this one, also very nice: https://youtu.be/-stjktAu-7k?t=1464
I consider GDPR very fair. The only "issue" (only for corrupt companies) with it is that it takes 'Wild' out of the Wild West of Internet.
Unfortunately most sites have scummy business models and this just exposes them.
It opened a market for untargeted ads again (based on the general interest of site visitors) which would never have happened if it was left to the market.
Google is actively working against these untargeted ads because targeting is their #1 market advantage. Nobody has a bigger tracking network than them.
But especially in Europe other players are taking off with them now.
How many of these companies in Europe have even a fifth of Google’s ad revenue?
I don't care about the intentions of the law. I care about the effects. No one is trying to update/fix the law within a feedback loop. It's a one time process.
I don't find it obviously wrong to have a problem with this.
You might be interested in this:
https://noyb.eu/en/more-cookie-banners-go-second-wave-compla...
Actually NOYB has also provided website owners how to make cookie banners GDPR compliant:
https://wecomply.noyb.eu/static/app/pdf/OneTrustGuide.0afba7...
The problem is not in GDPR. The problem is in the website owners. They are the one who are trolling you with banners.
It’s called free will.
What we really need is the principled and ever consistent hypocrisy (that always seems to be benefit the person) of most libertarians/sympathizers. When they are doing well…no regulation or taxes or safety nets. Someone else does something wrong because the system sucks? That person is at fault. Oops something doesn’t go well for the person. Now they want action. Make things whole.
A quirky recurring example of this are grifters like Mark Cuban following this to a tee with crypto. Or even funnier, the reversal of Eth after the legitimate DAO attack or wanting FDIC sort of insurance any time things don’t benefit them! I understand the desire to want to fuck. All the time. Yet never wanting to be fucked.
When companies overreact to legislation in ways that negatively impact society, stop blaming the law, because that's entirely what the tech companies are trying to do. They're trying to turn you against the very lawmakers who are protecting you from them.
And you’re claiming that every website that chose to use cookie banners was doing so for political reasons? Do you think that is the simplest explanation - and not that a bunch of lawmakers were incompetent?
You really want the government policing web content?