Tons of apps sell this info. I think a lot of the 3rd party weather apps have been the traditional worst offenders because everyone wants to know the weather where they actually are in the moment.
Even laws have this problem. There are so many cookie bars on websites that users just click through them anyways.
Every time a company wants to sell on your data, they have to email you and ask permission. Not responding to that message isn't consent.
Find a loophole in that.
Enforcement.
This would honestly still be a huge improvement imo, as even forcing data brokers to anonymize or aggregate the data, even if it is ultimately not actually providing privacy, is still a recognition of the problem over the current system in most states.
Your law as written would only cover company A doing the sale of data to B, but not the downstream intermediaries.
Alternatively, company A doesn't sell the raw data, and instead sells reports and anonymized data that can easily be joined with other datasets. As this is not a sale of "user data", but an aggregated, anonymous insight.
The data industry is full of scum - nothing less than scorched earth in advertisers and brokers is sufficient at this point.
Aggregation isn’t the real problem. Honestly it’s the crosstabs that are killing privacy. Remove the correlations, and no one gets hurt.
The problem is people are stupid and uninformed about giving consent. You're the one trying to loophole around that.
If you actually want to regulate this the way you describe, you have to do it by removing peoples' right to give certain consents. For example, nobody may give consent for more than 6 months for the use or transfer of their data.
This is a big deal! You're removing a free mode of contracting. But if you think about it, we do it all the time. That it has a higher burden of proceeding around new technologies is a large reason why American (where we are careful about rulemaking) and Chinese (no rule of law) tech companies are ascendant. But at a certain point, the usual rulemaking frameworks may need to be applied.
Not really. People have a limited amount of time to deal with issues and aren't trained legally. This doesn't make them stupid. Their inability to suss out all possible downsides of a set of EULAs across various products for a service they're looking for isn't stupidity; it's just an inherently complex space that requires a lot of time and specialist knowledge.
This is one of the main ideas behind consumer law; certain contracts are inherently slanted towards those who draft the contract, therefore we remove some of their freedom to abuse consumers by placing limits on the clauses we're willing to enforce.
That lack of willingness to place restraints on these types of freedom has less to do with the inherent difficulty of restraining freedom of contract and has more to do with the fact that the harm is distributed diffusely amongst a massive swath of consumers, vs felt acutely by specific data aggregators so one side advocates far more for their position - even if that position is antisocial in nature.
> "Their inability to suss out all possible downsides of a set of EULAs..."
This is the part I quibble with, however. This assumes folks even read legal-speak. Privacy laws have undermined this by forcing more text and more "I see, I agree, go away" links/checkboxes/buttons in front of people. The problem isn't the EULAs, the problem is that no sane person can (or should) keep up with it.
Yes, sometimes people can be surprising. My wife has an awesome t-shirt from MailChimp from a not-so-hidden "if you read this, you get a free shirt!" clause she found in their legal stuff. But relative to the amount of cheap "consent" given, this is a huge outlier.
That said, I also have to give kudos to some of the lawyers I've worked with in the GDPR/CCPA/etc era. At least at the point of purchase, there was no better corporate consumer advocate of "boil it down to two or three crystal clear sentences and link to the details, which must cut to the chase" to be found.
They obviously don't, but you're missing a key idea; why aren't they?
You can't benefit from reading without expert knowledge, and the cost is a massive time-sink. Even lawyers, with experience reviewing these types of documents, take a substantial amount of time to get through them and note them up.
If EULAs said: "In exchange for this free Solitaire App, we're going to reserve the right to inform your insurance company about which doctors you visit and the government about which abortion providers your phone keeps going to" you'd obviously read it because you can understand what's going on and you'd understand the exchange in a reasonable time-frame.
This situation doesn't exist because people are stupid. People are smart, which is why they aren't wasting their time trying to go to law school each time they need software.
I don't know the answer to this, but it would probably be a crisis of some sort, like cambridge analytica.
It's sort of amazing how far out of hand things have gotten, with phones, cars, televisions, and more collecting data and matching it with your "dossier(s) in the cloud"
If I want google to sell my data in exchange for keeping Youtube free, that’s 100% my prerogative
- GDPR-like legislation to try to prevent the inappropriate collection of this information.
- Ban the sale of or trafficking in illegally collected personal information. Apply serious monetary penalties to anyone who sells such information improperly. Additionally, anyone who sells such information and subsequently learns that it was improperly collected or was GDPR-deleted must tell their buyers, who must then delete it.
- Buyers are liable if sellers are found to have violated the rules and don’t pay. They are also liable if they fail to honor delete requests. Buyers who consider this liability unacceptable may attempt to purchase or require insurance.
In the US isn’t the sale of illegally acquired data already illegal under 18 U.S. Code § 2315?
I wonder if any existing stalking laws would cover existing data collection practices. Most people are upset when they learn there are records of their location down to a meter or so wherever they go that are sold to anyone who wants it. Does that meet the bar of “emotional distress”?
I wholeheartedly admit, some of our data providers are shady, and there's no way I would go work for them. I don't like the way they mislead people.
That said, the data we get is anonymous. Sure, if I know enough about you, and you're in one of my panels, it's feasible that I might be able to figure out which panelist you are. I know there's been some kerfuffle there with less than upstanding "private investigators" and bounty hunters in the past. But, the data we deal with is far too expensive for those sorts.
We find valuable consumer behavior insights the data at regional levels. That creates information that's valuable not only on Wall St, but to retailers and brands, who are desperate for anything to help them understand market share and loyalty.
I dunno. It's a weird world. It's also a very commoditized world. Just having access to the data is no longer the main value add - you have to provide the meaning of it as well.
I know our location provider did some things proactively - like they would not geofence hospitals, for example, but "home" is likely very visible.
That's a dataset I didn't work on as much, so maybe I'm not being sensitive enough to the "this should be illegal" argument. I guess on reflection misleading you for the collection should be illegal, though how to do that isn't obvious.
What I've worked on the most is people's credit card transaction histories, and that's quite a bit more naturally anonymous, though again, if you know enough about a person they would be discoverable.
But I don't want any of my data collected or shared!
The laws you are hoping for won't allow that - if they existed, at best they would only allow those companies to whom you have consented. Ie the mega-corporations. Local shops would be the ones without the data. Which would be pretty much exactly the opposite way I would choose to share my data, if I were forced to by law.
Make a law where if you ever sell a minor’s data, regardless of whether that minor lied about their age or agreed to a contract (wouldn’t be binding!), then you face steep fines. If you’re found buying data belonging to a minor, also steep fines. If you buy and then de-anonymize data belonging to a minor, really steep fines. To collect and hold data that may belong to a minor, you need to justify it (like GDPR).
Obviously this doesn’t scale for aggregators, advertisers, basically SV, which is the point.
A restaurant is responsible if they sell booze to a minor. A store is responsible if they sell cigarettes to a minor. Serving a minor that lies about their age does not get you off the hook!
Problem solved. User data is toxic. You won’t want to hold onto it for any other reason than a legitimate use.
Steep fines are barely a speed bump to either a profitable business or a scammer. They take years to actually get implemented, don't survive bankruptcy and get reduced in court.
Jail time. Mandatory. Zero room for judges and juries to go easy on the perps.
Even this does not stop white-collar crime, but it maybe slows just a little bit of it.
Are you going to buy shares in a company who’s entire worth is derived by it’s user data when it turns out that a significant but unknown amount of that user data is actually a very expensive liability?
There’s always going to be someone searching for loopholes, like anything, so keep it unambiguous and straightforward.
... but I feel like it isn't the ideal solution. I don't think we should make the perfect the enemy of the good, but what I'd really like to see is that people own their data about them.
I should be able to figure out what vendors have data about me. I should be allowed to be forgotten. There should be severe liability if they don't forget me.
I should be able to contract away my data, but in return for a real benefit, and that shouldn't extend to sale / redistribution.
I don't buy anonymization. De-anonimization is too easy, too good, and progressing too quickly.
I'm just thinking out loud, but maybe send my own phone a bunch of fake GPS signals, say, within my own house? Or maybe, somehow 'trade signals' with someone else in a way that collecting the data is useless? Or store my phone in. Faraday cage when I'm not specifically using it? Im sure other people who know the specifics better than I do will flesh it out better that I have, but maybe this will get the ball rolling...
I was thinking the other day of setting up a bunch of VMs with some browser automation with the goal of aimlessly browsing popular sites with the plugin enabled in the background in order to have most ad providers blacklist my IP for ad fraud and thus not trust any data coming from me.
ie. the political will to make any such changes just may not exist beyond pure lip service to minority who actually know and care.
I've considered what the options would be for something like "privacy-as-a-service", but I get the feeling that such an industry would be more likely to be regulated to death than the one it's in reaction to.
Ironically, "privacy-as-a-service" already exists to protect the financial records of those with big enough financial records to be able to afford said privacy protection service. One law for me, another for thee.
Any politician that attempts to regulate this can be thwarted by just shadowbanning any content that mentions them on social media - and he'd effectively disappear for a large chunk of people.
That's not law, that's a service!
The problem is that it's the internet... the law works for honest websites and companies but not for anyone else.
GDPR is not really about selling personal data but about using it; a big part of its effect is on buyers of data since GDPR effectively (there are all kinds of nuances) means that it's not legally possible for legitimate company to simply buy personal data for arbitrary purposes, since the data subject obviously did not opt-in to that particular purpose by that company when the data was collected.
That's not possible to opt in to under the GDPR, FAFAIK. People can consent to the purpose for which their data will be used, and any such purpose must be enumerated explicitly. "Selling the data" is not a processing purpose, and it would still be illegal even if the person consented (it does not meet the bar for informed consent).
Under the GDPR, the only legal way for personal data to be transferred between companies would be for the "buyer" (processor) to use the data original data from the "seller" (controller) on behalf of the controller. The data, as consented to be collected, remains the liability of the controller for its entire lifetime.
I agree such laws are necessary, but I'm not sure they're the best of the various solutions. Technical measures might be more robust, such as fine-grain permissions in mobile operating systems. I'd rather it not be possible to collect my data in the first place, than trust that some developer (in whichever jurisdiction) isn't breaking the law.
An advantage of the web is that hostile code is more easily tamed than in native apps, but in itself this observation doesn't do the user much good. Apps are pushed in part because of their superior capabilities for user-hostile functionality.
Similarly, Free and Open Source software is rarely this user-hostile, as few people have the nerve to publish their user-hostile code for all to see. Again though there's a sort of collective-action problem: if only the abstemious few like Stallman insist on not using proprietary software, things don't improve.
Weather apps also have plausible excuses for requesting permissions.
I suspect that, encoded this way, weather for 4000 locations wouldn’t be much bigger than weather for 1 location.
Also keep in mind that half the reason the Weather app needs to use as much bandwidth as it already does, is that whenever you move even slightly, it can no longer give you accurate info without grabbing the point-forecast again for your new location. It uses far less data if you just stay at home all day every day. If it had a pre-cache of forecasts for the entire local area, it wouldn’t need to do that; it could just refresh once every few hours. Maybe even wait for you to be on wi-fi before doing so, if it has modelled you as usually connecting to wi-fi several times daily.
This level of detailed information can't be pre-cached, either. I believe they are feeding the real-time weather recordings from the weather station into their supercomputer model to generate minute-by-minute high resolution forecasts over the next 6 hours.
KSEA 020153Z 34008KT 10SM FEW075 OVC090 18/14 A2997
Here's the local conditions at Sea-Tac at 7:15pm Pacific time. We have wind direction and speed, visibility, cloud conditions, temperature and dew point and barometric pressure in one small snippet.
The forecast data for the next 24 hours is given similarly. Radar data would be more complex but the basics for any weather app are only a handful of bytes.
For example, a full month of hourly weather data for a single Canadian station is 131KB (pulling from the Climate Canada site), meaning that if you wanted an hours worth of data for the ENTIRE country you're looking at less than ~800kb.
But if you just limit it to a geographical subset, say the lower mainland of BC, or even just a single town, then you can eliminate pinpoint data about yourself. Knowing that a person is in Abbotsford is far less invasive than knowing that they went to the Shoppers Drug Mart at 8:46 PM after searching for cold medicine.
This isn't a black and white thing, I wish that I had more control over my iPhone. I would love to be able to tell it to report a general location (somewhere random within a 10km of my actual location) to some apps, and a precise location to others. I get that Wunderground has server bills to pay, and I'm not paying them, but I would imagine that there is still a viable ads based business model that doesn't get quite as invasive.
The iPhone (actually iOS) allows you to do exactly this. You can choose precise or general location on a per-app basis.
I definitely can't do either, and ive been wrong enough times to know that
As for the next 30 minutes, I have tried AccuWeather and DarkSky. Both get the timing wrong about as often as they get it right for my location.
> As for the next 30 minutes, I have tried AccuWeather and DarkSky. Both get the timing wrong about as often as they get it right for my location.
Anecdotally here the met office is right far more often than it's not.
We were _fine_.
> 's forecast on TV after the evening news and/or today's forecast on the radio before the morning shower
I don't know about you but I certainly don't want to watch the news or listen to the news and traffic reports to get the weather. I'm _very_ glad we've moved past that
> And before that, it was mostly looking at the sky and listening to our intuition.
Really, your argument is that things were fine before we had instruments so we don't need them?
Sure, and I remember a time before internet (widely available public access) and smart phones. We were also fine.
Which doesn't mean these advances (including forecasts) aren't useful.
Different numbers for different categories, but I've read anywhere between 18 - 25% on the higher end opt-in success.
But above example of weather app is a good trick though, probably gets more allow always on location than FB for instance.
https://www.flurry.com/blog/att-opt-in-rate-monthly-updates/...
But signals your phone is sending can and are also being tracked.
And they have continued, off-and-on, to use other location-collecting SDKs.
It just doesn't stop.
In Pennsylvania for example, https://pennsylvania.staterecords.org/licenseplate
There’s a form to fill out. Looking at the instructions it’s E or F, so in theory if you can fulfill one of the reasons in F, I suppose you don’t need the owners information.
Outside of the US, you can also request similar information - Ontario for example.
> Vehicle records ordered online do not contain information about current odometer readings, collision information, driver’s licence numbers, owner names or personal address information.
It says it contains:
Vehicle description
Plate number of current plate attached to the specified vehicle and all other previously attached plates
Date(s) the vehicle was registered to each registrant
Vehicle status
So, not really equivalent or what the parent comment was looking for.The link to the exact area:
https://www.jtips.mto.gov.on.ca/jtips/orderPlSearchRecOwner....
After that, with the information you get about the current owner, you may be able to submit the paper form for one of the driver history requests that do include addresses.
https://forms.mgcs.gov.on.ca/en/dataset/023-sr-lc-112
I don’t live in Canada, nor do I really have a solid understanding, but it seems like for ~$40 and some time you might be able to obtain a lot of information from a plate.
They do say you need to be a business / approved entity, however, it looks like you could request it as the person as an uncertified record online.
http://www.ontario.ca/page/get-driving-record
While I’m sure that’s illegal, it doesn’t seem like it would actually stop someone who started at the plate, and wanted to get to name and address.
And/or
It does seem like you need the current address, but, you could probably abuse the system to confirm an address by seeing if your order is cancelled or not.
Once you have name and date of birth, you can probably begin to track most people down.
Edit: so it wouldn’t work quite that easily, you can get to name, but I confused license and permit on the one form. So barring trying the paper form for a 3 year check without the licence number, I’m not sure you can get beyond name from the plate.
And even if I did I don't exactly want to lead a trail of breadcrumbs straight to a title floating operation.
The tracking probably shouldn't extend to customer marketing uses, but the fact that VINs tie to plates tie to drivers' licenses is a system built out of hard decades of experience on the kind of damage people can do if the system isn't tracked and audited.
How does this data prevent either of those things?
The key is part of the sentence is tracked and audited. It helps to make people whole after-the-fact and minimize repeat harm.
To give a few concrete examples: commit a crime while operating a car? Your plate is, in modern times, now in the databases of multiple police precincts. You will now find it difficult to operate on public roads without getting pulled over (which also impinges on your ability to easily flee from the scene of the crime). Steal a whole car and ditch or replace the plate? Your VIN is now flagged stolen, so good luck getting any legit operator to do work on that car. Crash a car and try to repair it and re-sell it with a damaged frame? Again, the VIN is logged if you had any professional do major repairs on the car. And if the cops pull you over on a public road and you aren't licensed to operate a vehicle on a public road... Oh boy, hope you didn't have plans this week.
Your car gets stolen, you report the VIN and the plate to the police, they get a warrant. No Database required.
Your parent was talking about a load of historical data that's available via your VIN number.
> History of fines tied to person or vehicle. Dealerships and insurance have records tied to the VIN. Who financed loans for how much...
If that's all true, that's absurd. All that is required for what you're talking about is, at best, a database of current owners.
I think it's fine, if you're going that fast, you can't be anonymous. Airplanes aren't, missiles sure as shit aren't, the whole atmosphere is under surveillance for anything larger than a baseball.
The capabilities that the military/government pretend to have are VERY different than the capabilities they actually have.
Plus the whole thing is highly conspiratorial, like you talk about. Getting you to the bargaining table ie into the dealership. Then they work you, edmunds.com has an article about all the shitty little defeating tactics car dealerships do, at the direct verbal instructions of the dealership owner, and him directly under orders from the car companies.
Plus it's oil, American soldiers die every day for that oil in the Middle East, and many local people with them. It's no joke, in fact one time a military man I knew told me he just drove slower on the highway, like 30 mph under the limit, strictly because that oil is American blood, and you use much less driving slower to reach the same place. Like the lower speed limits of the 70's, but under his own volition.
In WW2, there was propaganda (not being negative, I don't consider it a negative thing, means words to be spread, spread the word) saying if you drive alone, you're driving with Hitler. Later, if you drive alone, you're driving with terrorists. There would be no war, at all, in the whole Middle East if it weren't about oil exploitation. That's the whole deal. Israel a little bit, but oil all the way. The Middle East had, up until I think 1947, including Iran, a very high opinion of America, blue jeans rock and roll, pizza, inventions, California, Cadillacs, what's not to love. Then came the Israeli War of Independence, then grossest of all the coup in Iran in 1953 which was just disgusting, and things changed very quickly.
We could dig it up in the US, we were a net exporter under the Trump administration. We just decided to dig it up a ocean away and use bunker fuel to bring it to us. Apparently for environmentalism, it's still unclear how that is better.
The numbers have to square up. That's critical. And the reasoning must be sound, no in-befores (inb4's) or soundbite explanations or silencing critics, in fact let the judge and jury decide for the most part, and if you are opposed, become a juror for the next time around.
I made a big fuss about it at every opportunity and is one of the biggest reasons I left.
https://www.nytimes.com/interactive/2019/12/19/opinion/locat...
> “It’s really, really hard to assign even what side of the street you’re on when you’re using this kind of data,” said Paul Schmitt, a research scientist and professor at the University of Southern California.
https://www.nytimes.com/2022/05/29/us/politics/2000-mules-tr...
> Mr. Phillips and Ms. Engelbrecht’s case is largely built on cellphone data. A report created by the group includes an appendix that claims to list “IMEI” numbers of the tracked devices — 15-digit codes unique to each cellphone. But each entry on the list is a 20-character string of numbers and letters followed by a lot of x’s. Mr. Phillips said new IDs had been created “to obfuscate the numbers.”
>"The same report says the group “purchased 25 terabytes of cellphone signal data emitted by devices” in the Milwaukee area in a two-week period before the 2020 election. They claim to have isolated 107 unique devices that made “20 or more visits to drop boxes” and “multiple visits to nongovernmental organizations” that were involved in get out the vote efforts.
>A number of researchers have said that while cellphone data is fairly precise, it cannot determine if someone is depositing ballots in a drop box or just passing by the area.
>“It’s really, really hard to assign even what side of the street you’re on when you’re using this kind of data,” said Paul Schmitt, a research scientist and professor at the University of Southern California.
Both are articles are perfectly consistent with being able to locate a person to within at best a 16 feet radius or so, and less accurate when in a built-up area. Hence the quote about not being able to reliably tell which side of the road someone's phone pinged on.
My point is one article uses the information to (rightfully) strike fear/discomfort in the reader. The other article uses it to dismiss an investigation that is inconsistent with the paper’s narrative.
It is easy to fuse with other sources.
Even so, a not-insignificant number of OS software is also a business strategy to buy B2B consulting services.
Science is stealing everyone's privacy and I stopped carrying a mobile years ago!
For example Visa has an exclusive deal with oracle. So only oracle can buy audiences with visa data, and visa has super strict requirements and only builds them in house. If you say “I want users who purchased x product” the size must be 5mm users minimum (I think) and visa models it up using lookalikes/etc to 20mm+ users (maybe slightly off on sizes). Then it’s like $4 cpm to use at a dsp. Brands/agencies etc have to go through oracle to get visa data.
Here's one example - http://www.dev.kbmg.com/services-solutions/data/data-solutio...
I've seen this, and many other similar data sets. You can easily look up yourself, your friends, etc.
The example I linked, Amerilink data set, I have a copy of (via my company), sitting on our internal corp NAS drive, and it is 100% raw data with PII. Can query on name, mailing address, DOB, etc. We have an unrestricted license that we pay a good chunk for annually.
1,000+ attributes on every US consumer.
I attended a presentation some years back from TMobiles marketing team.
According to the speaker, when you visit their homepage they pull up complete financial records on you, including how much your home mortgage is, if any, and use that to customize what products you see promoted first.
Matching a cookie to individual names is not instantaneous and would be very expensive for someone at t mobile’s scale to do every time a session started.
Some b2b companies do something similar where they can match your ip to a list of known corporate ips to find where you work in real-time, but that’s pretty expensive.
https://www.vice.com/en/article/m7vzjb/location-data-abortio...
> SafeGraph calls the location data product “Patterns.” In total, the data cost just over $160. Not all Planned Parenthood locations offer abortion services. But Motherboard verified that some facilities included in the purchased dataset do.
> SafeGraph’s data is aggregated, meaning it isn’t explicitly specifying where a certain device moved to. Instead, it focuses on the movements of groups of devices. But researchers have repeatedly warned about the possibilities of unmasking individuals[0] contained in allegedly anonymized datasets.
And related to [0]: https://www.nytimes.com/interactive/2018/12/10/business/loca...
Also, when digging, the data is heavily skewed in favor of low income. This was instantly noticed by the difference in data available for budget brands and models compared to the pricier lots.
Also, gross.
If they know you're looking at other dealers, then yes, they might think they need to play harder. If they know you're looking at accessories for this new car, then they can think you're more ready to buy. Every bit of detail they can get, they will use.
Tim Horton's sells donuts, so I doubt comprehensive data about where you are wrt donut shops all year comes close to that value even 35 yrs later