The FBI Just Admitted It Bought US Location Data
wired.com
wired.com
If that goes too far, do something like the UK's Data Protection Act of 1998 that insists almost all PII is subject to review by the individual and they can demand erroneous data be fixed. They can also demand deletion in various scenarios.
But personally, I like the copyright idea. If a copy of a song can be protected from being made legally, even if I personally make the copy, I see no reason why my most personal of details cannot be similarly protected.
I fully understand laws are not written by computer scientists and that nuance is involved, I'm just saying that the idea that PII could be copyrightable doesn't seem THAT crazy to me.
Perhaps PII for commercial use could be treated differently than for private use?
A recording of a song (even if it falls under fair use) is not a “fact”, it’s information that took creativity to produce, multiple people working independently would not produce the same exact song - unlike going around and measuring the height of bridges where if multiple people did it they would arrive at the same measurement
Talking about the order of words in text X is not the same as a reproduction of text X.
Example:
Original: The quick brown fox jumped over the lazy dog
Reproduction: The quick brown fox jumped over the lazy dog
Talking about the order: In the sentence beginning with the following fair-use excerpt "The quick brown", the word "fox" precedes "dog".
> I'm just saying that the idea that PII could be copyrightable doesn't seem THAT crazy to me
It would be awesome, because then I could license out my address and collect royalties any time it is used or mentioned.
Eight facts. Would replicating an entire book like this violate the copyright? The entire text is reproduced in order, there's just a bunch of junk added. I suspect courts would rule that it is a copyright violation.
Since I am my data and my data is me, I already own all my PII.
We just want the legal system to honor this simple reality.
If you work W-2, the payroll processor for your company likely gives your payroll details to theworknumber. This is ridiculous.
Under proposed order, GoodRx will pay a $1.5 million civil penalty for failing to report its unauthorized disclosure of consumer health data to Facebook, Google, and other companies
https://www.ftc.gov/news-events/news/press-releases/2023/02/...
GoodRx Response to FTC Settlement
https://www.goodrx.com/corporate/business/goodrx-response-to...
FWIW, I used to work in healthcare IT, mid 2000s. At the time, it was understood that sharing data for the purposes of marketing and advertising was illegal.
Also, being a geek somewhat familiar with stuff like tracking pixels, I'm still not sure what to make of GoodRx's response.
If I can't make head's or tails of this case, what hope does a layperson have?
This is just plain wrong. There are privacy violating services where people are not given a choice. I don't have a Facebook account, but they bought tons of data about me from brokers and used to it to create a shadow profile that they continuously update using any scrap of information on me that they can find including what they can get out of the conversations held by my friends and family members who do have facebook accounts. What choice did I have in any of that?
Critical services and even government websites force you to hand information over to privacy hostile companies. You can't even go to irs.gov without pinging Google's servers, allowing them to collect data on you. Sorry, but "never use the internet again" isn't really a viable option and as long as you use the internet your data will be taken from you without your consent, or even your awareness. Choice, isn't really a factor.
What hope do we have of our government protecting us from their own actions?
Facebook (and others) make profiles of people that have never agreed to it, nor visited facebook in their lives.
So do the credit reporting agencies, to a different extent.
Even people who are aware they are giving up their information are often willing to do so since they know the only alternative is to go without such service all together.
GDPR is the prop65 of privacy, and there was no chance of any other result.
If this is true, then why do the pop-up dialogs have meaningful choices? And if the dialogs are the fault of the GDPR, why does there exist GDPR-compliant websites without the pop-up dialogs?
You can levy your criticism at the earlier Cookie Law, for its failing to anticipate its nullifcation via terms of adhesion and general lack of technical aptitude. But the GDPR addressed those flaws.
Very few of them do. Typically it’s “accept” and “x”.
> why does there exist GDPR-compliant websites without the pop-up dialogs?
Because GDPR doesn’t make those other sites have them. It’s perfectly possible for GDPR to force some websites to have popups and not force others to. It’s still GDPR forcing the ones that it forces to do the thing it’s forcing them to do.
> But the GDPR addressed those flaws.
As you can clearly see from being on the internet for more than about 5 minutes, it in fact does not.
This is not a comment on GDPR one way or the other; my point is that we shouldn’t engage in political word games to try and avoid the inevitable consequences of actions.
The general fallacy with the rest of your argument is that you're pointing to imperfect enforcement as a reason to indict the law. This is essentially defeatism and acceptance of whatever might be commercially lucrative.
As to your strange fallacy paragraph, I’m not sure what you mean by imperfect enforcement. Perhaps you should explain in an amicus brief to the courts that decided those banners are compliant?
You're treating the surveillance activity as a constant. One could also just stop surveilling, and then one wouldn't need to display a banner either.
What you're saying is akin to saying that the law makes muggers wear masks to hide their faces. If you take the mugging activity as a given, and then compare how muggers act with the law to how they would act if robbery weren't illegal, then sure it's technically true. But unless you're making some larger constructive argument, then that characterization isn't particularly enlightening.
> I’m not sure what you mean by imperfect enforcement ... courts that decided those banners are compliant
Can you point me to these court decisions that say putting take-it-or-leave-it nag walls on websites suffices for obtaining consent to process personal information for non-necessary purposes? Because that would seem to run directly counter to the wording of the law.
The rights grante by the GDPR cannot be signed awy by a licensing agreement, but the can be overruled by other laws (e.g. mandatory retention times for tax purposes).
Or are you saying the existing advertising surveillance industrial complex couldn't possibly be repurposed to also track who's abusing our PII?
The FBI here is merely a symptom and the tip of the iceberg. The US sorely needs something akin to the GDPR, to prohibit this unaccountable shadow government that is the surveillance industry. I personally think passing the GDPR verbatim and letting the courts sort it out would be a decent approach given how our legislative process otherwise undermines regulation by letting corporate lobbyists buy exceptions that destroy the intent of the law while leaving only the bureaucratic red tape intact as an anticompetitive warning. But I do think that if the GDPR were to be translated into the US legal concepts, it would take the shape you've started to lay out.
I like this idea in concept. The catch is how to define "PII". The current definition of it is incredibly inadequate, as it omits a great deal of information that is personally identifying.
I do object to the expansion of copyright that this would require, though. Copyright law is already overly oppressive, and I fear this would make that worse. Perhaps make a distinct property right over PII instead?
I used to add a copyright notice to the bottom of my resume, to prevent distribution. Don't know how well this works practically speaking, especially in this electronic day and age.
When I read that, I though “duh, of course, everyone buys data.”
I assume you're implicitly referencing that the FBI is skipping getting a warrant, but why do they need a warrant? Your information is already publicly for sale.
As other's have mentioned, it's not really an FBI issue, it's a general privacy issue - that companies are collecting, compiling, and selling this information and it's all legal. Which is darned hard to get people to care about - because it's convenient to give your information away. I know about these things and still use google for almost everything (I finally moved my business email to fastmail... but didn't yet bother to move my personal email.)
That's an interesting point. Wonder how foolproof/incorruptible the chain of custody is supposed to be for the provided data?
We've probably all worked on IT systems at one point or another that the outside world regards as really good, but the admins / ops staff know is really held together with sticky tape + bubblegum. Sometimes with data not quite being stored as it was entered (heh MySQL springs to mind).
Not enough any prosecutor would prosecute someone based on that data alone. However, I do see a case where the data provided could be used to further an investigation. And in some ways, that makes sense. The data is a clue, but it's not what is going to put someone away.
It's a log entry. A log entry is only as good as your logs and provides a clue for further investigation, but it's not where you stop the investigation.
I'm not commenting on the legality or whether access to this data is right, merely my assumptions on how this data could be useful in one aspect that doesn't necessarily need it to be foolproof or incorruptible.
The right to privacy isn’t exactly even a right in the US constitution, it’s a construction out of a combination of many of the amendments in the bill of rights. And as such anything that doesn’t specifically conflict with a part of the bill of rights is fair game for data collection on citizens. And, because the bill of rights was created such a long time ago, the idea of the government being able to buy such a massive amount of data on you from third parties that it would be a violation of your privacy isn’t exactly written in as a problem. The constitution is getting to the point where it really needs amendments to clarify things for the digital age.
"The powers not delegated to the United States by the Constitution, nor prohibited by it to the States, are reserved to the States respectively, or to the people."
So what you’re talking about it more relevant to the question “should the FBI be allowed to exist at all.” Is a federal bureau of investigation something that the federal government is allowed to make under the constitution, and if so what sorts of situations and crimes are they allowed to investigate? If you don’t believe the FBI should exist at all, then the sort of argument you’re giving makes sense.
But what the rules as to the Federal Government’s allowed sphere’s of actions don’t say is how they are to go about pursuing those actions. (“To constitute Tribunals inferior to the supreme Court;” is a right of the federal government, but no mention is made of how those tribunals should be structured or how they should function.) So we get to the question of “If the FBI is allowed to exist, what sort of methods is it allowed to use to investigate.” And that’s where the bill of rights comes in, excluding certain types of actions.
Or the general question could be stated “Is it disallowed for the federal government to purchase data about its citizens from private entities in pursuit of the rights it is granted by the constitution.”
So while the FBI buying data causes great harm for a few thousand, everyone else buying data causes moderate harm for pretty much every other human.
Is it already forgotten that the FBI used to spy on King and the civil rights movement?
The question is what is on the market, not whether or not the cops are going to buy it if it's there.
So... what is on the market? It's not in the article!
Having a blanket ban is easier to enforce than a special law just for FBI. You’d also want to prevent other law enforcement. And you’d want to allow some stuff like user feedback data, etc etc.
Am wondering the size of the privacy market. How much extra are you willing to pay each year to have your top-10 apps not collect and sell your data?
The FBI can stand outside your house and look in the windows without a warrant. That’s not an end-run around laws.
Which brings us to another point.
If I was to meticulously stalk and document the activities of one individual that would obviously be stalking -- but if a group does that to everyone that's a successful business?
How does that work?
Is that true, though? I certainly don't believe any Google employee has the ability to read my email without consequence.
I hope you re right, but I ve worked at a company that had very sensitive data on individuals and I could see it all. We were even GDPR compliant: Im a french citizen working in China and I can ssh to a finland database no problem: the data never left Europe ... that was our interpretation of it anyway and an audit would have had trouble to fault us, for various reasons.
I had a girlfriend working at a giant telco... showing ME proudly the graph of all calls for the day she had to browse for something... and she was remoting on the private vpn all good and compliant... but nobody controls who else is behind the screen.
Best is not to commit crimes on public spaces, and not assume public spaces are private: even letters can be intercepted by the mailman, so... I think you can reasonably expect that it would be hard for one of your enemies to access your data for nefarious reason, but I always assume random access by an employee is possible.
Assuming that backdoor exists, at best there's some kind of oversight committee that has to review and approve a request to read an email. Meaning the door is there and someone has the keys, it's only process that tries to remove the risk of a unilateral invasion of privacy.
Sure, but as is "Anyone at the FBI", per the comment I was replying to...
This purchase is just a proof that privacy protections given by US law are totally ineffective.
As soon as the data is on the open market, no GDPR, and no US law protects the customer, since public prosecution is not interested in blatant violation of privacy here.
This is also the main reason why EU continuously threatens US with withdrawing _safe harbor_ provisions.
As soon as the data enters US, the open market assures it will be widely available contrary to all regulations.
safe harbor was invalidated in 2015, replaced by "Privacy Shield" which was overturned in 2020. Now "Trans-Atlantic Data Privacy Framework" is being worked on but i suspect it won't hold up either because muricans can't even protect their own citizens from governmental spying let alone foreigners.
https://en.wikipedia.org/wiki/Trans-Atlantic_Data_Privacy_Fr...
Perhaps not, but the FBI using one method to get their hands on data without a warrant, while a different method to acquire that same data would require a warrant, is definitely a sign that something is going wrong.
Do the police need a search warrant to lookup who owns a property, or leverage the white pages?
It would be very useful to the FBI to identify whether they're looking at a solo criminal enterprise or a multi-state organization.
I'll gripe about intel community abuses as much as anyone else, but it's a lack of imagination to say there are no valid, privacy-preserving uses for this.
Historically, Google rightly identified PII as the goose that lays golden eggs, and so voluntarily put safeguards in place around it to prevent individual abuses from killing it.
The FBI could do the same. I doubt it'd be effective, given political pressure from threats and constantly changing leadership, but it's technically possible.
Which is to say that if I have {personally identifiable information}, I have no innate {dollar risk} to holding it, outside of specific protected classes like personal health information (PHI).
If we wanted to fix this in one swoop, we could just... quantify that risk in $ terms. It largely worked as intended in healthcare via HIPAA.
- If you store PII, you are required to submit to a yearly audit by an independent third party
- If you have a breach that exposes PII, you are penalized order-of profits (or equivalent measure) for a year
- If you are a US company that obtains PII from a source outside your company, you are required to obtain and retain a full chain of custody of the source of that data. If you originate or sell PII, you are required to furnish a full chain of custody of that data. If you are found with PII without a valid chain of custody, you are dissolved as a company
That this would make some businesses like Experian or Facebook/Google's ad targeting products unprofitable to run is intended -- they're only profitable now because they don't have to pay to violate people's privacy.
https://magarshak.com/blog/?p=169
As a left-libertarian I am concerned about not just states but corporations too
The wording of this comment specifically excludes a conclusion on private intel firms. Private Intel middle men would still evade application of the Carpenter decision, and it is obviously superior for the government to work with an agency like that do to human rights and what-not.
[1] https://www.vice.com/en/article/qj454d/private-intelligence-...
“What I wanted to see is if you could give me a yes or no answer to the question ‘Does the N.S.A. collect any type of data at all on millions or hundreds of millions of Americans?’ ”
[. . .]
“Not wittingly,” Clapper replied. He started scratching his forehead and looked away from Wyden. “There are cases where they could inadvertently perhaps collect, but not wittingly.”
https://www.newyorker.com/magazine/2013/12/16/state-of-decep...
His answer makes perfect sense to me.
After telling Congress that the National Security Agency does not collect data on millions of Americans, National Intelligence Director James Clapper has issued an apology, telling Senate Intelligence Committee Chairwoman Dianne Feinstein that his statement was "clearly erroneous."
https://www.npr.org/sections/thetwo-way/2013/07/02/198118060...
And in the real world nearly every major telecommunications company in the US was granted (by Congress) retroactive, blanket immunity for the years and years and years they spent actively participating in the domestic wiretapping that the NSA was performing that was clearly prohibited by FISA.
Doesn't seem clear to me.
https://www.csis.org/analysis/fact-sheet-section-215-usa-pat...
> Section 215 has been reviewed and renewed by Congress twice since 2006. The Supreme Court has held that phone records are not considered private or privileged information for Fourth Amendment purposes because they are voluntarily provided to telecommunications carriers for billing purposes. As of July 31, 2013, the FISC had reauthorized the program 34 times under 14 different judges. More recently, however, two federal judges came down on opposite sides of the issue. Judge Richard K. Leon of the District of Columbia District Court ruled the 215 collection program illegal, while Judge William H. Pauley of the Southern District of New York upheld the legality of the programs.
Here's DNI Clapper in a 2013 interview, talking about that very question:
> First, as I said, I have great respect for Senator Wyden. I thought though in retrospect I was asked when are you going to start--stop beating your wife kind of question which is, meaning not answerable necessarily, by a simple yes or no. So I responded in what I thought was the most truthful or least most untruthful manner, by saying, “No.” And again, going back to my metaphor, what I was thinking of is looking at the Dewey Decimal numbers of those books in the metaphorical library. To me collection of U.S. Persons data would mean taking the books off the shelf, opening it up and reading it.
(via: <https://web.archive.org/web/20130614222820/https://www.dni.g...>)
And here's Schneier talking about the topic: <https://www.theatlantic.com/politics/archive/2013/10/why-the...>
And here's some random dude on the internet also discussing the topic: <https://ethanheilman.tumblr.com/post/99480839105/definitions...>
Again, according to DNI Clapper, wiretapping and recording the results isn't collection. It's only collection when someone pulls the information out of storage and reads it.
Starting with "to my knowledge" gets him off the hook, then he names a very specific type of data and a very specific source, he doesn't describe what kind of "court authorized process", and he only says the unspecified pilot project has been inactive for "some time" (decades? years? days?)
Or they're buying data from cell carriers unrelated to ads.
Cingular/AT&T had a program for LE back door access already in 2002, no doubt scaled way up by now.
The switches support it.
If I were to impose my will as a dictator of a nation or crime organization with an unlimited budget, it's what I would do too.
All that said, I don't think this sort of information should be for sale to anyone. If the police agencies actually need such a thing, they should have limited scope and a warrant. The larger the scope, the more folks should have to sign off on the warrant. Police - because of their power - shouldn't have free access to such things even if the criminals have them. Following "rule of law" doesn't mean folks are doing immoral or wrong things as the laws aren't always just - and often, the methods of change include illegal things, hopefully nonviolent.
Do you know anybody who works in law enforcement? I do and they've told me that if they screw around and don't follow procedure or don't get a warrant then the perp will walk.
Junkyard News: https://www.youtube.com/channel/UCMCSd9ZNL0nshOhXwtfIJBA
Indisputable: https://www.youtube.com/@IndisputableTYT
There are many, many other channels, most of them local to where the person lives. It's gotten so bad an entire industry has spawned reporting on it. I have hope though, now that all this is out and body cameras are almost everywhere, you're starting to see prosecution of some of these bad police.
Generally I agree, though "It isn't overreach if you have a warrant." is (forgive me) wishful thinking. If real courts with real judges were considering a real right to privacy that would be true. But we are well past that. And that's without considerations for things like Parallel Construction...
I know overreach still happens and I truly think we could do better - but I'd rather have it than not.
The US IS running just such a state. And democracy is in peril.
But the US does NOT use it for the only upside it might bring: less serious crime.
The US has created the worst of all worlds. Maximum risk, minimum benefit.
Is that clear?
That is about 90% of my point. Everything ELSE is tangental. What I have written is basically the key point on mass surveillance. Everything else is at best extra and at worst irrelevant to the actual points.
With just slightly different ChatGPT query prompts, extremely different, conflicting narratives for a given event can be produced, and each of them sounds/seems perfectly reasonable, and True.
For someone to be invulnerable to this sort of thing, they would have to have fairly substantial background in several different obscure domains (none of which are taught in school, quite conveniently), as well as violate several strongly enforced social norms (ie: engaging in "pedantry", thinking in ways we've been trained to pattern match to conspiratorial thinking, falling for Russian propaganda, etc).
It does not surprise me in the least how much polarization there is in society over what is actually going on, and how each side genuinely believes that they are take on it is correct. It seems (to me) almost like the system has been deliberately designed to produce this output, because it certainly isn't that hard to figure out how to vastly improve on it.
It's not that no one cares. It's that the people who care are powerless, and those empowered don't care.
In principle, it should be far more concerning to see private entities getting access to personal data - because they operate without any opportunity for the public to be involved (their pure tyrannies in a sense) and are completely opaque, but the government is far more transparent and the one institution which you can change by democratic involvement.
Of course, this type of data gathering is concerning in any case, but the government is the last on the list of entities we should be worried about having it.
The solution to the problem is to go down the EU route of reducing the rights of anyone to collect all this information and make it harder to access that which is collected. It's by no means perfect but it is the right direction.
> taking testimony from all the principals, including Rockefeller Sr., who testified that, even after knowing that guards in his pay had committed atrocities against the strikers, he "would have taken no action" to prevent his hirelings from attacking them.
Corporate surveillance is a different beast because people can choose which corporations they do business with, absent market consolidation. We are not absent market consolidation, but it's that which is the scandal, not what would otherwise be voluntary associations between private parties.
This is the crux of it, it's not voluntary association to be a participant in the surveillance economy. If I didn't live in the EU this would be my train of thought: I didn't choose it, I just accessed a website that had trackers and eventually that data is sold, I wasn't willing to do it and the contract for it is buried somewhere and simply by accessing it I've implicitly given the system tacit agreement to get my data scooped up.
That's why I believe GDPR was a major advancement for data privacy, I can actually choose to block trackers or to not access a website if they make it hard to not be tracked.
In here though I talked explicitly about GDPR and data privacy in the surveillance economy sense.
I'm not discussing encryption or government overreach on privacy matters in the EU in general, unsure why it is brought up in this thread, care to expand?
I still don't get why you brought this up when I'm specifically talking about one case of data privacy where I believe the EU has done right, I believe it's doing wrong with encryption and I'm actively contacting MEPs to share my view.
Again, what's your point? They're different issues, why are you conflating them and creating a strawman?
The EU doesn’t care about protecting you from “surveillance”.
No, invasive government surveillance is supposed to require a warrant. Invasive is defined as a search of your 'person, house, papers, or effects'.
A third party's records on you aren't your person, house, papers, or effects. They are records concerning you, but they are not your records.
The government (just like every other government in the world) doesn't need a warrant to receive a tip, to ask your neighbour if they want to volunteer/sell any information about you, or to surveil you when you go about your public activities.
I'm sure you didn't consent to be the subject of that tip, or to your neighbour snitching on you. That still doesn't mean that it's not a legitimate form of surveillance.
Being surveilled by private entities is non-consensual and hardly ‘choosing to do business with them’.
Corporate surveillance is different because corporations can't throw you in jail, can't send police and such at you. That's all.
A high profile example, though there are many others: https://www.nytimes.com/2021/10/27/business/energy-environme...
The fact that government involvement is needed is really semantics. No one affected by this decision could hold the officials responsible for this decision accountable, so the government is really an arm of the corporation at this point. This is inevitable when consolidation of wealth/power isn’t limited.
There are other examples too, like when Hertz gets you arrested for GTA because someone else was late returning the rental car you're driving.
Exactly, and all it needs to keep people calm is to create a puppet advertising company that does its job and covertly pass the data to govt organizations, or infiltrate an established one. Problem is that personal data mining has become vital for our modern toxic economy, so I don't see how the practice could go away anytime soon, especially when those making the laws and those taking advantage from it are essentially the same entities.
The govt has an army, police, and jails. The govt has legal means to use violence against people and deny them their freedoms. Any company that could do that would be doing it with the blessing of the govt first, which kinda just makes them a govt contractor.
Govt having information is not the same as a company who just wants to pre-approve you for a loan or show you a YouTube ad.
Equifax can use it to alter my credit score and could have implication on a future credit application.
The FBI can use it as justification for a federal investigation that they may have otherwise had no justification for. They also have the ability to work with other branches of the government to file criminal charges and throw a person in prison for the rest of their life. I'm well aware that's a huge jump, but the point is the level of risk between a private company buying data and the FBI buying data is entirely different.
1. Equifax collection is more or less voluntary. It's triggered on taking out loans, carrying debt, etc. The reason I said more or less is people need to do these things to live these days.
2. The FBI can abduct you, put you in a cage, and/or kill you.If the data can be bought on the open market, law enforcement should have access to it.
If the police need to purchase such information, they should have to get a warrant like they do for other things. Someone (or two) not involved in the investigation should have to agree that it is necessary. Law enforcement should be somewhat hobbled because the opportunity for abuse is much greater, especially to general society because of its reach.