Tax preparers that shared private data with Meta, Google could be fined billions
arstechnica.com
arstechnica.com
Internet archives to the rescue
What data did they share, and why did Google or Meta want this data?
Are we only talking Google Analytics or are we talking about for profit data brokering.
Seems that they provided the data to get Meta to target customers for them.
These companies are out of control
https://www.forbes.com/sites/alexandralevine/2023/06/21/tikt...
If you're talking about Trump, he's possibly the worst example you could pick for your case, as his treatment has nothing to do with his wealth and everything to do with the fact that he is the previous President...
But if ya disagree with that, that's fine. Can take a quick Google search and find hundreds of instances were wealthy people committed serious crimes and received no substantial punishment for doing so compared to their less influential counterparts. I could list some, but I trust you can do that for yourself.
> and started a proxy war over what appears to a place of great interest of corrupt politicians
Putin does not sit in the White House in Moscow, that's where Russia's Prime Minister sits :)
Who's the prison guard whose watching from a sniper tower while the prisoner rampages?
Both of those are the American President. The war in Ukraine was fully preventable, and could probably even be stopped immediately, if the President wanted to do so.
But that would require a living person in the Office, and the military-industrial complex not desiring another 20 year proxy war.
I don't understand what you are saying, there's no explanation of how the war was fully preventable, just a statement as if that was a shared fact between you and me (it isn't). No explanation of how to stop this war without Russia annexing a huge chunk of another sovereign country. No explanation on how a Russian invasion is actually a proxy war created by whatever you are saying.
I feel dumber by reading this...
Bush the Younger: Started two wars, threatened at least two more, and ended none.
Obama: Ended one of those wars and continued the other. Had a third start under his watch.
Trump: Didn't start any wars, and didn't end any either.
Biden: Ended the other Bush war, and saw that third war continue.
And the Afghanistan pull out is one of the most embarrassing and sad things I have seen for my county. It was a travesty, and almost anyone with a brain could've handled it better.
It was probably also another item on the list of green lights to Putin that Biden couldn't stop or defend against a Russian invasion of Ukraine.
If he doesn't actually have diplomatic papers, then he's fair game. And if he does, he can still be kicked out of the country at the very least.
What profits were derived from the "sharing" of "millions of taxpayers' data?"
I had to do a technical audit of this issue to find out if my company had also been placed at risk. What happened is this:
1. Facebook asks advertisers to place some javascript on their website to help with general measurements (i.e.: whether viewing an ad on a Facebook property ultimately led to a purchase)
2. This javascript may also gather user interactions on the website so an advertiser can see what users engage with, what might be relevant to ad performance measurement, etc
3. These stupid tax prep companies placed the script on pages where users might view, interact with, or submit very private information
4. When users clicked around, tracking data was sent to FB
5. A security/privacy journalist spotted this and said, "gotcha."
Ad Tech companies don't want your SSN, and they really don't know to know if you purchased Plan B. But when tax prep sites and online pharmacies place a tracking script on all their webpages, everyone ends up with egg on their face.
There were no profits here. The journalist's privacy investigation should be appreciated and celebrated, but Elizabeth Warren is just raising a boogeyman so she can keep sticking a knife into the hearts of these large, corporate entities. Election season is coming up, after all.
Who receives the fine?
* The Tax Prep companies? That would be fair: they are obligated to handle private user data in a responsible manner
* The ad tech companies? That would not be fair: they didn't want the data, didn't know it was being sent, and almost assuredly didn't use it for any kind of ad serving, measurement, or optimization.
If I send you a video camera and tell you to put it in your retail store and stream me the video and you put in your changing room and send me the data and I don't tell you to stop, am I free from liability?
More to the point, if companies are required to forensically analyse the hashes sent to their API endpoints to check they haven't received anything sensitive, the internet in its modern form would essentially cease to exist.
Alternate analogy: an IoT thermometer vendor sells you a device to track temperature in your room, but you decide to stick it up someone's butt. Will the IoT vendor know the temperature reading is personal and rectal? Should they be held liable for not proactively attempting to scrub-out numbers which may represent gluteal climate?
Try telling a cop that you didn't mean to buy fentanyl with your other illegal drugs.
This stuff happens because there isn't an exec approval process...
Here’s my take which happens to agree with the parent commenter: the incompetent executive is responsible for the actions of this engineer and (in this hypothetical) the incompetent executive allowed their business to be destroyed by something which was easily avoidable.
People calling for companies to be dissolved are pretty likely to be calling for an orderly process (if they weren't interested in an orderly process they'd likely be talking about using violence on the executives or shareholders or whatever).
It's not like I have secret income the IRS isn't aware of. And for people who do have secret income, they'll either voluntarily report it or won't.
do you not make mistakes, or do you not work with anything that matters?
the US criminal justice system, which isn't very popular, seems to be more tolerant to human error than you.
I’d say what you described at least comes close to being negligent. I’d hardly call that a “boogeyman”. It’s a serious issue that shouldn’t have occurred and there should be some repercussions for that.
Where do you get that idea? All they doin the background is to deanonymize as much data as they can get. Why do you think they would not actually want this ultimate deanonymizer of US citizens?
Your feelings on the matter are quite irrelevant -- they want every bit of data about your financial life as possible. Including your mortgage, income, etc. The SSN it the ultimate primary key. You can't even get a new one if your identity is stolen. The more often they can link that to an email address, phone number, etc, the stronger the signal they get from sources that only have those bits.
The reason an SSN exists is the same reason why it is one of the the best identifiers of a person in the US.
Nation state and domestic hackers look for these as a highly prized commodity for this reason as well. They can be used to find other records containing people. You may recall the Chinese hackers who exfiltrated the SSNs of US military personnel not too long ago.
I don't. What I do have faith in us companies to have a profit motive and work in favor of self preservation. And that comes with reducing risk for the company.
An example of a local company with bad security practices due to negligence or malice is no evidence of a publicly traded big tech company wanting to do the same.
Hence, the dictum "don't ascribe malice where incompetence would suffice" doesn't carry across these two different classes of organizations.
Equifax is absolutely adtech. Their data is sold used by advertisers all the time. You can make changes to elements of your credit report using techniques widely available on YouTube and watch the spam and junk mail you receive change.
Maybe your local company was collecting it out of ignorance, but if they uploaded it to google adsense, alarm bells would go off, the data would be purged, and you'd seriously risk having your account shut down.
And in this case, it's a huge toxic liability that adds almost no value over an email address.
I agree with others that adtech companies want to proactively avoid SSNs. Too much liability and not at all necessary.
for a fun "challenge", here's my md5 hashed SSN: 46fdccf9acc38d13321b0c13cf541ec9 (spoiler: not my real SSN, but since they're sequential it could be someone's. And, hint, I'd be jealous of them.)
There is literally no evidence what you said is true. There are no details what information was shared. Can you avoid making stuff up?
Do you mean this in the autoantonym sense? Because literally Meta did exactly this.
I would expect they’d be eager to have this information and would not consider it to be a liability in the slightest.
I wasn't a developer but we already had income estimate by looking at past purchases, location, sites that the person looked at, etc. It wasn't super accurate but enough to know whether someone should see a Fendi bag
:
> 3. These stupid tax prep companies placed the script on pages where users might view, interact with, or submit very private information
I think you're being far too easy on Facebook.
I can certainly see how they could have profited from data contained in certain forms that customers submitted on non-facebook websites, potentially confidential data which would be used to flesh out hidden user profiles and thus increase the prices for highly targeted ads.
1. This isn't just a gotcha. If you're storing private data, be a fucking responsible human being and do the work to store it securely. Stop downplaying this.
2. Ad tech companies don't want your SSN or to know if you purchased Plan B? Ad tech companies want to know everything about you, especially things that are private because other people don't know that stuff and that's where the competitive advantage lies.
> There were no profits here.
There were cut costs, which amount to the same thing.
Essentially, the "secure in their persons, houses, papers, and effects" part of 4A is interpreted literally. Since that third party has your data, you're still secure in your papers and effects, but the bank doesn't have 4A protection.
That made some sense when information meant either you had a piece of paper, or you had given it to somebody else. But ever since information is cheaply copied and distributed, it really doesn't work so well.
(This is why I believe any literalist interpretation of the constitution is bullshit. It just doesn't translate well over a 200 year distance)
It's currently a somewhat debated legal concept - Sotomayor had an opinion that amounted to "maybe we should rethink that" a while ago, and there have been a few cases saying "nope". But nothing's reached SCOTUS so far.
(If you want to find out more, "third party doctrine" is the keyword. Or buy a constitutional lawyer a beer, it's fun :)
The bank still has this right and uses it to its advantage. In this case, it seems the bank deemed the value of cooperating with government more than customers’ privacy.
The description of the data that was shared is quite vague in the article. But If this is the result of tax prepping companies putting Meta pixels in pages containing personal data so they can show ads (shouldn’t these be only accessible by the user anyway so they can’t be scraped by Meta?), or manually adding personal data to analytics parameters (so they could check time on app by income etc), then I think the fault lies with those companies rather than Meta and Google
Or will they never miss a chef prepared meal in their glass castles, with no chance of ever being held responsible for the great ‘responsibility’ of being in charge?
But yeah, I'd love it if this was the kick in the pants that is needed to get people to see how ridiculous it is that taxpayers need to pay a third party just to submit their information to the IRS.
We know this because when you e-file if your tax return is one of the ones for which they don't actually need any information you provide and you made a mistake they tell you right then what your mistake is and reject the filing.
for example, accessing the the California DMV website not only uses google analytics, it will log you into google.
Ultimately, it's the decision makers that must pay, not the janitors and cleaners.
What will they actually be fined? History would suggest very f'ing little if anything.