Opted out, yet tracked: Are regulations enough to protect privacy?
arxiv.org
arxiv.org
The broader problem is that the government, courts, police and everyone else who is otherwise in charge of enforcing rights in this country does not know the first thing about technology.
We have dealt with this problem plenty of times in the past by setting up specialized bureaus and giving them broad authority to regulate players in the space and deal with infractions (the SEC is a great example of this), but there is no such tech authority. Imagine a world where the smartest programming minds aren't just joining Google but also the agency set up to regulate Google. Imagine if in a post-scandal hearing you don't have politicians who can't figure out an iPhone ask the questions but someone who knows how to set up a network firewall and what 2FA means. Until that happens, just passing more and more laws is going to be meaningless.
Unless the same rules get enforced on the big players, it's just a moat around the status quo. In Europe's defense, they have been fining the big players, but on the other hand at this rate the fines are starting to feel more like a kickback than actual punitive measures intended to change behavior.
It's now the game over state for personal and family privacy. All the sites and apps and even casio watches has telemetry always-enabled (via mobile apps). Even cars. No one in governments or agencies cares about privacy anymore. Call it whatever one wants: corruption or lobbying, the name does not matter.
The possible solutions are impossible for the non-software engineers (pihole and dns set in the home wifi, personal openvpn gateway set on all 4/5G connected devices). Younger generations don't care. Older ones just don't understand.
It's the dark age of privacy. Literally no hope.
I wonder what the consequences would be in the next 5-10 years when the collected data would be analyzed by AI and sold to anyone for a more and more cheaper price. What should happen for the people to push the unprivacy back hard enough to stop or revert?
Do you still think it's a negligible cost? These costs are also going up: in January 2023 Ireland issued two more fines for $0.4 billion.
[1]: You can check at https://www.enforcementtracker.com/
[2]: https://www.statista.com/statistics/745351/facebooks-quarter...
Ireland's data privacy serves as Meta's main regulator in the European Union because the company's European headquarters are in Dublin. Making it out as if Ireland's GDPR fines are "just one country" is disingenuous.
I'm old enough to have seen the internet evolve in the UK, and as usual the US dominates it and screws it up for the whole planet.
I'm surrounded by USAF, and pro American brits because they get employed by the US Mil, and their extremist mentality grinds you down.
So I really do hope the EU starts putting the US and UK in its place, and failing that Russia or even China because there are some very toxic people running these countries, getting away with murder.
Elizabeth Holmes was indicted 5 years ago. She was sentenced last year. She’s still walking around freely.
A normal person would’ve spent at least 4 of those years locked up, if not all of them. They most certainly wouldn’t be out and about after being convicted. These people simply have different rules applied to them.
Wow, I didn't know this, but you're right:
https://www.womenshealthmag.com/life/a39299534/elizabeth-hol...
She received an 11-year sentence last November but she's apparently a free woman until April 27th of this year.
Can someone who knows more about the American legal system explain this to me? Why is this possible? I assumed that when you're sentenced you get taken to jail pretty much immediately.
(Yes, I'm sure the short answer is just "because she has lots of money", but what are the details? What exactly did she spend it on to buy an extra 5 months of freedom?)
Politicians might not, but the government apparatus does. There's a reason 3GPP/ITU for years have built backdoors in telecommunication networks. It is simply that the IETF folks building atop Packet Switched Networks are putting up brave resistance: https://archive.is/iawrM
In the USA, doesn't know? Or doesn't want to know? Things like The Patriot Act are more effective (?) when there's an endless buffet of personal data available without the need for a wire tape, court order, etc. Probable cause? Much easier with phone meta data and CCT footage. Etc.
There's too little incentive for the gov to get it right. The current situation is no accident.
So you'd get a revolving door between Google and this supposed agency regulating Google where engineers and policy makers would work at the agency, be friendly to Google and then switch jobs into a cushy job at Google with a nice pay bump as a thank you for years served and services rendered.
There are many engineers (I'm one myself) who wouldn't even consider working for Google. It very definitely is not the case that all other options are second-bests chosen by someone who failed to get into Google.
It’s beyond that. It’s micromanaging. Regulation cannot and should not be able to keep up.
How do you know this?
>They don’t care if Amazon, Facebook, and Google know what they are doing online. They opt in to tracking by joining loyalty programs to save a few bucks. Privacy is just not a concern most people have.
I disagree. Most people have no idea what's going on behind the curtain.
Not based on scientific evidence, but we can infer this from several facts:
- The massive user bases of social media platforms. If most people cared, or were even aware of what's going on, they would choose not to consent to give up their personal data in exchange of using the service. Yet clearly they value the service over their privacy.
- Blind acceptance of cookie consent forms. Even with all the publicity around cookies and tracking on the web, if you've ever shoulder surfed a non-technical person, you'd notice that they blindly dismiss any consent forms by accepting the terms. There's a reason why most websites use dark design patterns on these: they work.
- Anecdata: if you've ever tried educating a social media user about privacy concerns, you'd be familiar with several dismissals: "I just log in occasionally for <minor use case>", the popular "I have nothing to hide", and flat out "I don't care". I've heard these both from non-technical and educated, smart and technically literate people. After many years of making an effort here, I've yet to convince a single person to change their habits, let alone abandon these services, and I'm still perceived as a radical technophobe.
You contradict yourself here.
Not being aware makes it impossible to measure whether they care.
Looking for studies just now, these are interesting:
- https://www.pewresearch.org/internet/2019/11/15/americans-an...
- https://www.malwarebytes.com/blog/news/2019/03/labs-survey-f...
So most people seem to "care", but apparently not enough to change their usage habits, or they feel powerless and lack the technical skills to protect themselves. So it could be a matter of education after all, but _most_ of the people I've talked about this, stop me much earlier than we get to the point of discussing what they can do about it.
No I'm pretty confident that the majority of people don't know what's going on because why would they?
Regulations (and consumer protection groups) are actually the right way to deal with this because it reduces the redundantly wasted time for dealing with such nonsense.
Your rights are likely not what you think, even if they seem cut and dry. They are determined by the court. Then you would also need someone to enforce them when they are violated. But often times nobody cares.
Do you actually have those rights if they aren't enforced?
It's not that nobody cares, it's that the people with the power to both pass regulation and enforce that regulation aren't affected when they don't use their power to help the people (even if the majority of their constituents/voters support it).
While you could put this all on the evil politicians, it could also be linked to two things: first, the culture of the country (countries) as a whole, in that voters aren't willing to give up voting for someone that doesn't protect them from harm in their daily life (or otherwise overthrow such politicians), and second, because there are a limited number of politicians they can vote for, meaning that both/all of the candidates on the ballot can be disinterested in solving the problems at hand. The only real solutions I see to this are things like ranked choice voting, or more likely, more laws and regulations being represented by having voters vote on those laws separately from their candidates.
Given this is all intrinsically linked to politics, the only real solution us consumers can adopt is by aligning ourselves with products and services (or people) that solve the problems we care about via either logistical or technological means. For example, we can't trust Facebook not to track us, so we enlist browsers and extensions to block ads. Importantly, we can't trust the government to enforce "if you hack a computer you go to jail" so we enlist multi-billion (or trillion) dollar companies to keep us safe, since we know their incentives (money) align with our need for safe and useful products and services that prevent bad things from happening in the first place.
Look at judges. I've personally witnessed judges and magistrates saying things that aren't true. Like thinking you're calling them prejudiced when asking to dismiss with prejudice. Or explaining that a trial de novo is a "complete do-over" and then turning around and saying they won't hear a motion because there's no record of it happening at the prior trial. I've even had a lawyer say that civil rights were violated but that the judges don't care and will see your case as a nuisance unless there was serious bodily injury or severe financial impact.
The politicians passed these laws. The people think they have these rights. The judges don't care. So the minority affected realize that they don't have those rights while the rest live in ignorant bliss.
One of the main problems is that the party basically tells politicians how to vote on a bill. Very few break with party lines. We're seeing a relative lot of that deviation on the Republican side, although maybe not in a good way. The main problem in this area is that you essentially end up with 2 diametrically opposed positions with no in between. Even the stuff pitched as a middle ground is usually just step 1 in a side's plan and doesn't legitimately address/protect the other side.
Anyone wants to start a trillion dollar/rmb trade war over cookies?
Not functionally, no.
It's worth noting that one reason that banks take AML regs so seriously is that the fines are so large, and regulators check compliance, that you don't want to get caught not delivering.
There are different senses of “have”. Practically, no. Naturally, yes.
Their framework is quite close, however, to something that really could do a good job here. Compare these cases:
* Visit some sites that do not indicate commercial interest, then compare bidding behavior opt-in and opt out. That's what they did, and you shouldn't see much of a difference.
* Visit some sites that indicate specific commercial interest, then compare bidding behavior opt-in and opt out. You should see higher bids and ads that are related to that commercial interest for the opt-in category. If you don't, something went wrong. If you see those same higher bids in the opt-out case, then consent is not being respected.
(I used to work in an adjacent area; speaking only for myself)
This was section 3.3.1; they did do it, but I don't think it was enough because they used pretty bland histories. Wrote up something more thorough as a post: https://www.jefftk.com/p/measuring-ads-opt-out-compliance
Ban unsolicited marketing entirely and watch as suddenly no one cares enough to pay money for this data. That's how you get rid of it. Put violators in prison.
Bonus: you'll be able to answer phone calls again.
It will never stop.
The actual impact of GDPR in Europe is hamstrung by the enforcement mechanisms. All enforcement happens via regulators or government agencies, just like how most CCPA enforcement in California must be undertaken by the Attorney General. Private citizens can lodge a complaint, but cannot actually force action. Despite their increased mandate, most agencies did not receive additional funding post-GDPR and effectively act as a bottleneck to enforcement actions.
(It's even worse because American companies are HQd in Ireland for tax haven purposes, so they get regulated by the Irish agency, which is strategically underfunded so as not to scare away the revenue streams.)
Regulating the widespread abuse of personal data for commercial gain is basically a prerequisite to other privacy improvements. Once you get such abuse under control, then other privacy invasive activity becomes more obvious.
Pop-ups and cookie banners have absolutely nothing to do with the regulations. At all. They're simply a mechanism to collect consent for the data that they do store, and they're intentionally obnoxious in order to push you towards accepting immediately rather than dealing with the faff.
EPrivacy is a stupid regulation, no matter how well intentioned. It’s ended up polluting everything with obnoxious garbage that everyone (except I’m sure the random HN privacy nerd) clicks through blindly and aren’t really adhered to anyways for the HN privacy nerd who spends more time reading popups about privacy than the actual content they were after.
Sounds like a lose, lose.