Meta wants EU users to apply for permission to opt out of data collection
arstechnica.com
arstechnica.com
Privacy is a basic human right, and the strawman argument of "Well don't just use their services then" is ridiculous with their influence. Also them touting to "connected the world"
When in reality is "connecting to world, but only if we can record everything you do"
I disagree with your premise.
Whatsapp wasn't always owned by FB/Meta. It had a huge user base then got bought out.
Alternatives like Signal are popular, but it's hard to overcome inertia. Give them time.
I would rather say "Give time to decentralisation". It slowly became a standard. If more people abandon abusive software.
Another way of thinking of it is that the value that Meta/Mastercard/Virgin/other companies that fit that description provide is so substantial that they have become intertwined with society.
The reality is likely somewhere in the middle IMO
how's that working out?
asking for a friend who thinks that for-profit healthcare was a step in the wrong direction.
> for-profit healthcare was a step in the wrong direction.
Using the words "for-profit healthcare" is a distraction from the topic.
GP's have been private since the beginning of the NHS, they're the definition of for-profit healthcare.
On the flip side, Virgin operates many of the major healthcare provdiers as an NHS service provider. I'm not saying that they're incredible, but they're doing it.
The option isn't "public", it's public and sustained funding and investment. Given the govenment of the last decade in the UK, I'm not convinced the situation would be any better if the NHS was more public than it is.
Oligopoly.
It only works reliable for messages directly addressed to a person. Then people remember, oh he does not have WhatsApp. I will tell him via signal.
Or they won't and you will be left out of things.
Not even out of malice! Obviously your closest friend and family will adapt and keep you in the loop. Bigger looser groups are more dubious. I'm a member of a book club for example. There are of course the scheduled meets, organised well in advance. But also sometimes someone just feels like hanging and posts a message on a whatsapp group that they will be at this or that location and whoever is free is welcome to join. Schedules don't always permit it, but when it works out it is fun!
Now of course if someone from the group so want to meet with specifically you/me they will remember to send a one-on-one message, but there is a power in the broadcast nature of some of these things for organisation.
If I leave these, people are not going to reach out to me about them. I will just cast myself as an outsider and will be left out of the loop.
That's a big leap of faith.
I've encountered this everywhere, even with myself. I'm bad at keeping in touch to begin with. Anyone decided not to use normal means to communicate with me are likely to get missed among the hundred plus other people I know.
I'm not on Facebook, so I'm left out of the majority of my family's communication. The only reason I know anything is I regularly call my parents to get the summary. (It's also a good excuse to call. We always have something to talk about.)
My company asked me to install WhatsApp once, but I explained to them why I don't use it, and they didn't have a problem with it. Sometimes, all people need to know is 'no' and most of the time they don't even need an explanation.
Maybe some won't be, but the path of idealism isn't always the most convenient.
"Sorry kids, you aren't going to your friends parties or playing sports with them because my ideals conflict with your reality" is not a tenable position.
"your mileage may vary"
and bob's your aunty
Yeah, definitely. I'm just responsible for myself. The day I have to be responsible for others, I'll just immigrate to a country where everybody uses Telegram haha.
Telegram is a much better option that does not sell your user data and still has the best privacy options. Where most people like to disagree is the security part, but E2EE is not as important to me as long as my privacy is respected.
Signal is horrible to use and inconvenient for most people but with e2ee.
So it's not FOMO, it's just plain MO.
Missing out on conversations from my extended family, friends (only about 1/4 use Signal and all groups are on WhatsApp), work (the Health Service in Ireland literally runs on WhatsApp), voluntary undertakings (all of which are organised on WhatsApp), organising stuff for the kids (again all on WhatsApp).
So it's a valid fear based on the reality in my social circle and country. Unilaterally moving to Signal means self-imposed isolation.
This part is terrifying: does Ireland not have the equivalent of HSR (UK, in combination with a patchwork of other legislation) or HIPAA?
What do you mean? I live in Ireland and no health professional has ever contacted me via WhatsApp.
You just get added to the relevant groups by your manager (obviously there's also unofficial social groups) and that's where you'll get 90%+ of rosters, clinical updates, service bulletins, etc.
Even after making the effort to keep up with the ones that only wanted to use WhatsApps, through email or regular text message, they couldn't be bothered. I guess I have moved into the point in my life where I prefer the quality of friends who wanted me around for more than being an extra body to fill out their party guest list (and similar).
most informal social groups, parents included, now communicate mainly on whatsapp. You can naturally say no (i did) but then your kid is left out of most social events unless you're actively syncing with other parents every week to be in the loop (which is what i do and it's excruciating).
Whatsapp as a platform is extremely convenient, which is why other people will have a hard time understanding your reluctance to adhere, it's not uncommon to be seen as eccentric.
so again, congratulations on finding a great company, but there are real issues with the general social dependence on a single invasive platform.
Some didn't like it at first, but thankfully most of them now love Telegram. I have a “My way or the highway” kinda attitude when it comes to WhatsApp, it has certainly caused problems once or twice, but I'm very firm on my stance against Facebook apps.
- Privacy controls for each user.
- No hard requirement for a phone number.
- Cloud encryption.
- Open Source clients.
- Telegram's track record.
- Business model not revolving around selling user data.
WhatsApp is a black box and nobody has any good arguments for it other than 'supposed' E2EE that nobody knows anything about. The fact that WhatsApp's T&C forbid you from even reverse engineering the obfuscated binaries and Facebook being the force behind WhatsApp, I'm still surprised that people take their E2EE claim seriously.
It's like me promising you that I'm not looking at you, while I stand facing you, right behind you.
Only if you pay
> - Open Source clients.
Mautrix/WhatsApp
> - Telegram's track record
Which is?
> WhatsApp is a black box and nobody has any good arguments for it other than 'supposed' E2EE that nobody knows anything about.
With Telegram you have a guarantee that it is not E2EE in group chats and single chats if you don't opt into a way worse UX/features.
> - Business model not revolving around selling user data.
True for Whatsapp as well, it's funded by business accounts and perhaps other parts of facebook
I'm sorry, but that's not a good example. It doesn't even count as a legitimate client.
> Which is?
https://en.wikipedia.org/wiki/Blocking_of_Telegram_in_Russia
https://hongkongfp.com/2020/07/05/exclusive-telegram-to-temp...
https://www.vice.com/en/article/a3yavb/russia-blocks-telegra...
https://sensortower.com/blog/hong-kong-protests-app-download...
> With Telegram you have a guarantee that it is not E2EE in group chats and single chats if you don't opt into a way worse UX/features.
You're saying this as if you have a guarantee that WhatsApp's E2EE is 100% correct. At least with Telegram, I know what data the app is collecting, where it's going and how it's being stored on the device.
> True for Whatsapp as well, it's funded by business accounts and perhaps other parts of facebook
Assumption again.
why not? After all the client uses the multi-device API like the official client does
> You're saying this as if you have a guarantee that WhatsApp's E2EE is 100% correct.
I am not saying it like that. I am explicitly saying that with Telegram you have the guarantee that it is not E2EE, while there at least exist the possibility of WhatsApp being E2EE.
> Assumption again.
An observation, not assumption. WhatsApp wants to see money for business accounts: https://business.whatsapp.com/products/platform-pricing
Telegram on the other hand does not compromise on features and user experience and still is able to deliver a system that doesn't disrespect the user data.
I don't have special insight into either WhatsApp or Telegram, but I think given the founders and jurisdictions in which they operate, Telegram deserves at least the same level of scepticism and scrutiny as TikTok.
I don't think Telegram deserves scrutiny. Not after what they've been able to accomplish and follow.
> indeed it was _suggested_ by many of them, both technical and non-technical as preferable to SMS, so I don't think it can be that bad.
It's not bad of course, but it's extremely hard to get WhatsApp users to switch to Signal than Telegram. Both because of missing WhatsApp features in Signal and the additional hoops like PIN.
I'm Just speaking from personal experience. Signal was also my first choice.
Every communication channel deserves scrutiny according to the threat model of a given user.
Telegram is a good compromise. Yeah it's not e2ee.
Signal isn't even a good compromise for most people. I don't know anyone who has stuck with signal in my circles. They've nearly all reverted back their previous service or find a new one.
Personally I treat everything that is sent over networks as public data. So I would never comm anything that needed e2ee via a message service full stop.
That does not sound like a good compromise to me.
I wouldn't use a messaging app to send encrypted content in the first place. But I do want trusted privacy control which telegram provides
Their track record is excellent. Pavel moved away from Russia (and his team of 20 something members too!) only because the Russian government pressured them into giving access to their servers.
WhatsApp is anything but privacy preserving. You have 0 transparency. You can't even prove if the E2EE exists for 100% of the time or just 50% of the time because the binaries are obfuscated. On top of that, their privacy policy and being owned by Facebook says everything one needs to know.
Telegram, IMHO, is the only app that does not compromise on user experience and still provides fantastic privacy control and respects the user data. Sure, it's not E2EE, but no E2EE app can ever do what Telegram is doing at this scale.
In the US, I don't have Telegram and it's been ages since I sent a message on WhatsApp. Everyone I know just uses SMS.
But as op mentioned
> kids' sports activities and parent groups
Try telling your kids football team coach that you object to Whatsapp and your kids friends' parents that you will not join Facebook for privacy reasons, it's a much harder ask, they might say fine, but you can't expect other people to change their behavior based on your beliefs. No matter how right you are.
"I can't because my Facebook got hacked, and I got banned from Facebook. I tried multiple time to recreate an account but it was banned each time :('
IANAL but if this is on your personal device they can't compel you to do so. Otherwise they need to provide a company issued device.
Stop associating with clueless people
Everytime I've tried moving people over to Signal/Telegram, etc. we try it for a week and then go back to WhatApp because of so many other groups on there....
Ha!
I so don't trust Meta.
I wouldn't put it past them to double encrypt your messages and split it off at the server.
Edit: Clarification: Encrypt your plaintext twice, append it, split it off at the server. Send your message on to recipient and decrypt it themselves for their processing enjoyment.
After seeing the lengths various govts will go to for full text access, I highly doubt it. There is also no way to reliably prove the e2ee claims of WA, so I would remain skeptical.
I'm not on Meta side on this but I actually don't use a lot of services that I'd like to and have real inconveniences because a certain level of privacy is actually important to me.
> all of my kids' sports activities and parent groups
I thought you were going to followup with some anti-dictatorship or something. not parent groups lol.
And before anyone says "Well, sucks to not know basic tech stuff", consider the fact that in a world where no-one has privacy, the person using Facebook from a VM is eminently more trackable than in a world where privacy is enforced globally.
> Privacy is a human right, not a technologically-advanced-person right
Yeah I suppose it is, but I'm starting to give up on the idea because all the people who whinge here on HN and elsewhere about privacy won't actually do anything about it, like give up exactly the things that they are willing to pour their life's details into. TL;DR people have to put some effort into securing their privacy and >95% of people won't.
Stop blaming the companies for stealing your privacy when you're giving it away willingly.
Similarly, governments can and have pushed for privacy regulations. Not all of it has been successful, but we’re at the first wave of these efforts.
If people actually cared enough to do something this would be solved very quickly indeed but they don't.
> governments can and have pushed for privacy regulations.
Depends. The EU has done not badly at all on this, the American government on the other hand…
FB would be hurt so much more by this than EU users (market bigger than US, and other countries would follow), especially long term that they will quickly reconsider their uber-arrogant behavior. Really, who the f*k do they think they are, just another greedy corp run by sociopathic a-holes that will sooner or later be just part of history.
Remember when they got the biggest fine ever, like 5B (EUR or USD can't remember) and the moment this decision was made public the stock went up as traders had thought the fine is even bigger.
> They are legally required to keep EU users' data in the EU anyway.
It's not about what you are legally required to do, it's about what happens in practice when you don't. In this case, not much happens, so why would they bother complying?
It's not feasible to ask everyone to even understand how to do that.
> yet most sites still attempt to load FB tracking scripts.
(Emphasis mine)
So yes, they do, and all that's irrelevant victim blaming because it's really unacceptable that this is something the user should have to bother with. It also requires an unusually high level of technical competence just to not get stalked, which is likewise unreasonable.
I do not use any of facebook's apps or websites
But from what I can see from DuckDuckGo App tracking protection multiple apps load Facebook trackers. Basically there is no escaping facebook even if you don't touch any of their apps.
But how many are tech savy enough to have a separate device and run Aguard / Pi Hole all the time for privacy.
If you want privacy, seek it out, refuse those that take it from you. Incuding Meta.
> The right to privacy or private life is enshrined in the Universal Declaration of Human Rights
https://edps.europa.eu/data-protection/data-protection_en#:~....
The violations of these are not the responsibility of the victim. In this case they are the responsibility of Meta.
You seem to be talking about it more in line with if it was a privilege and not a right. Consider a passport, its a privilege and indeed not a right to get one. So you need to seek it out.
Rights however are not sought out, or require some kind of process to achieve them. They're available from birth.
These rights are written down and the law of the land.
Facebook is not required to provide their services for free.
And providers of toilets are not allowed to secretly film you and share those films, even if they make the toilets free.
IANAL but I'd add "blatantly", "brazenly" or some such here. This cannot be in line with things like "it must be as easy to opt out as to opt in" (paraphrasing GDPR) and they know it.
IMHO this (like, sadly, many examples before from Meta) could be a perfect occasion to pierce the corporate veil. Whoever signed off on this should never be left in charge of customer data again.
Generally speaking, GDPR violations won’t be addressed with a slap on the wrist, apparently
So, when they plan to actually start fining?
> "2% of its entire global turnover of the preceding fiscal year"
I'd like to see this fine in the case of Meta and Google, but we both know it'll never happen.
"The less severe infringements could result in a fine of up to €10 million, or 2% of the firm’s worldwide annual revenue from the preceding financial year, whichever amount is higher."
"The more serious infringements go against the very principles of the right to privacy and the right to be forgotten that are at the heart of the GDPR. These types of infringements could result in a fine of up to €20 million, or 4% of the firm’s worldwide annual revenue from the preceding financial year, whichever amount is higher."
> Background. The GDPR allows to process personal data if a company complies with at least one of six legal basis in Article 6 GDPR. Most of these six options are irrelevant for advertisement. While most companies require users to consent ("opt-in") for the use of personal data for advertisement, Meta (Facebook and Instagram) have tried to bypass this requirement by arguing that the use of personal data for ads is "necessary under the contract" when the GDPR became applicable in 2018. noyb has instantly filed a series of complaints and ultimately won them before the European Data Protection Board (EDPB) in December 2022. Meta got until April to stop the practice.
> One illegal practice replaced by next illegal practice. Now Meta announces to give in against the pressure by noyb, but instead of switching to an "opt-in" system, like Google or Microsoft, they now try to argue the next unlawful option, by claiming that their "legitimate interest" to process user data would override the fundamental right to privacy and data protection of users. This was tried by other companies before, but rejected by the regulators multiple times (see e.g. the Italian DPA on TikTok or the Belgian DPA on the IAB TCF at para 441).
Hopefully at some point the lever of big monetary sentences will be made use of from regulatory enforcement.
Last time WhatsApp was down for just a few hours it made international news.
Especially because WhatsApp _uses phone numbers as identifiers_. Switching to Signal or Telegram, which also use phone numbers, would be completely feasible: recreating the same groups would be the biggest annoyance, but you have all your contacts as soon as they install the app.
People will of course be very bothered by losing their chat histories (can you decrypt the backups it creates in Google Drive?), but it won't be an actual show-stopper. And it will teach a valuable lesson on relying on cloud.
I agree it's not great that this is all controlled by Meta but this is what it is now. It will take a long time, or some heavy nationalization, to fix the situation. This mentality of "let's break it and people will figure their shit out" is i.n.s.a.n.e.. You know that "move fast and break things" is a BAD thing when you're affecting the lives of so many, right?
For the sake of this argument, assume the premises that (a) Meta, a foreign corporation, controlling the private conversation of hundreds of millions of citizens is not simply "not great" but unacceptable, and (b) that it is necessary to put WhatsApp permanently offline (as opposed to making it somehow safer).
Steps to a post-WA transition:
(1) Publicly gather a list of messaging services that can be verified to satisfy the requirement to act as WA replacements:
- E2E encryption
- Interoperable under the Digital Services Act (critical)
- Phone number-based IDs
- Fully hosted in the EU and controlled by European companies
- Sufficient operational resources to serve > X number of users
(2) Mass send the message to all WA users "Due to new European privacy rules, WhatsApp will shut down on ${today + X months}. You will be able to continue talking with all your contacts through any of the following apps: [ list apps sorted by capacity, click to install ]. You will need to recreate any groups of which you are currently the admin.". Plaster the same message everywhere, send SMSs, etc.
Compared to switching to a whole new currency, or moving a shitload of bureaucracy fully online during Covid, this seems a very reasonable task for a European government.
The thing is most people would probably choose the wrong alternative, i.e. telegram, whose communications aren't endtoend encrypted by default, as a replacement instead of more decent alternatives. It wouldn't be a win over whatsapp.
Match and combine offline data sources: Always Active
Link different devices: Always Active
Receive and use automatically-sent device characteristics for identification: Always Active
Ensure security, prevent fraud, and debug: Always Active
Technically deliver ads or content: Always Active
If you don't open their "show purposes" window and "Confirm my choices" from that window, then you are also agreeing to: Store and/or access information on a device
Personalised ads and content, ad and content measurement, audience insights and product development
Use precise geolocation data
Actively scan device characteristics for identificationI won't even touch on doxxing Snownden's girlfriend and the amount of questionable, at best, political content they publish on a daily basis.
Shouldn't it be opt in?
Once you've bought a smart TV, it shouldn't really be any of Roku's business what you watch, but you basically have to airgap any brand of "smart" TV to avoid data collection.
Cars are much more computerized nowadays, so it would not be a stretch to imagine they have data harvesting software somehow (especially in light of Volkwagen's emissions test cheating); but if I've bought a car, it's mine, so why allow that? And then there's Ford's idea to have self-driving vehicles drive them back to the dealership if you miss a payment, which is a lot less time-gracious than missing utilities or anything like that.
The last time I paid for a laptop with Microsoft on it I still got ads shoveled in my face, and of course there's all the telemetry to deal with. Apple had that drama a few months back with people not being able to launch certain apps because some connection to their servers wasn't being made that would allow it, and Apple products go for premium.
It would seem rather prudent to assume that if you buy a product and it is electronic, there is probably some mechanism to transmit data to the manufacturer, because IoT and profit and why the fuck not.
While there is an argument for a product needing a revenue stream to survive, paying for a product clearly does not save you from ads and data collection. The company is there like Bilbo Baggins, holding the One Ring, and asking itself, "After all, why shouldn't I have both revenue from the customer and the ad revenue?"
This form lets people object to the use of their data for a legitimate interest.
Legitimate Interest is supposed to be used for thinks like fraud prevention, not for added value things like highly target advertising that requires building a profile of a user.
I don’t think it’s going to end well for Meta.
1. They want to show personalized adverts
2. So they collect and process the data to do so
3. And therefore because they've collected the data, they must be allowed to show personalized adverts.
Aside from it being complete nonsense, the contention is around the 2nd point. They should NOT be allowed to collect and process the data for that purpose without permission, which EU courts have repeatedly stated.
The dark patterns used to trick people into opting in need to end. I religiously opt out on every GDPR banner, but even I've accidentally opted in sometimes because the button layout is intentionally designed to be confusing.
Like I request people to just not use FB anymore, if they don't want to be tracked by them.
Might have the same effect.
The site itself I am visiting could do so and share it with FB and whoever, sure - but this would be a different scenario.
And like I said, if I use a adblocker preventing to load FBs add in the first place, then how can they meaningfully track me in any way?
At some point, a couple of years ago, I decided enough was enough (probably when they forced me to accept some new anti-privacy EULA which otherwise blocked me from using Messenger Lite).
There was no delete account option in the app that I can remember. I searched and searched for at least an hour. Facebook's support site was a labyrinth of circular links that edged around actually deleting my account. I had no Facebook account, so I couldn't log in to delete it on the website's account settings.
I just wanted an email I could send the request to. I finally found one for a data protection officer or some sort. Sent them an email, got another one back redirecting me to the website. Obviously that wasn't helpful, so I sent them one of those GDPR deletion templates.
Didn't hear back, and checking a few months later, my account was still accessible.
You can show up at one of their offices and tell their janitor, and they should still comply.
That's why most companies now train every employee how to handle users requesting deletion (usually by forwarding the request to someone whose job it is to action them).
[1]: https://medium.com/@sandeepbhalothia/a-b27d3f83ee73#:~:text=...
I've got some help from Sweden's IMY for a similar case, asked for the removal of my data by emailing a GDPR template, got no answer and no resolution by the company in a few months and contacted IMY who solved it (and fined them).
The cattle does not get to object, reject it or vote on it. The wellfare of the rancher is all that matters and any attempt to disucss that or just turn around, will just "never work out" because of unavoidable infighting. But dont worry, we are not in chicago yet.
Who could have imagined, that stripping your brain naked would make you hackable and controllable, thus turning you into a organic component with an API for behavioural crowd simulations.
deMoohCrazy has begone! And all that is a best-case-scenario.
https://github.com/jmdugan/blocklists/tree/master/corporatio...
Yeah sure I will fill a form to "opt-out" and I'm sure that the DP authorities will be fine with it
As long as Facebook can treat the fines as a cost of doing business they're happy. That, and as long as their (bullshit) value proposition of personalising ads by collecting as much personal data as possible is unaffected.
The same is now true of Facebook. Capitalists will always be against the convenience of users.
The reason those forms proliferated is because a few snake-oil vendors (TrustArc, etc) sell fake compliance solutions that merely look compliant but actually annoy most people into accepting which is preferred by their (scummy) customers instead of actually-compliant solutions (would put them out of business or force them to severely trim down the marketing/advertising teams).
Since there is no significant enforcement of the regulation, these practices persist.
In a world where Meta doesn't use cookies to run targeted advertising: Users see lowest common denominator boring ads. None of their life is different in any other way, there's no harm they avoided.
This whole issue is baseless. If the EU wants to purposefully degrade services that half of EU citizens use every day, that's their prerogative, but you're making the world slightly worse.
I don't want targeted ads. I'm not interested in anything they have to offer. I will search for things I think I need by myself when I think I need then.
So your argument is that you don't believe privacy has any value, and you only care about second-order effects. First: Since you believe that, can I install a camera in your shower? Don't worry, you won't experience any downsides. Second: Users would do in fact experience downsides, because targeted ads exist to get them to spend more money and distort their selection (i.e. if I'm shopping for cameras, I want the best/cheapest camera, not the one that paid the most to get shoved in my face).
Damn, I called it terrible but it worked. Oh well