The EU’s Digital Services Act is now in effect
theverge.com
theverge.com
So if an AI decides that I'm likely to buy something LGBT if they offer it to me, despite using no label for the category, rather a token in the net, then does this break the rule? If so, can I ever responsibly use any form of AI-based targeting?
EDIT to add ref: [https://www.bbc.com/news/technology-66472938]
Where is the line I wonder?
If Netflix effectively says “you seem to like watching gay stuff, here’s more gay content”, is that wrong? Because it seems like that’s not Netflix targeting a user’s sexuality, just their viewing preferences.
OTOH it’s pretty harrowing to hear about people in (for instance) Uganda who are outed by an algorithm and (whether it is correct or not) find themselves ostracised or worse.
There was a period when, for some reason, it would recommend playlists related to getting "tarted up", "makeup on", being a "powerful woman" etc and recommending lots of music it thinks is for women.
Though I do listen to a wide variety of music, there's nothing notable I'd say could encourage it to believe that.
Generally I play metal and rock, grime, rap, hip-hop; but also classical, some pop and indie, occasionally "UK Top 50", "Coding Mode" and "Jazz Vibes" playlists and lots of children's bath time songs.
I had to have a purge and its much better now but I still avoid the auto-playlists.
I wonder if it had something to do with my location; I was living in London and now live in the North.
Even if Netflix's intentions had been perfectly benign - and even if they didn't specifically target this category but only did so emergently through some unsupervised algorithm - they now have a way to find out for all of their customers whether they are closetted gay.
Imagine someone like Trump or Desantis or even worse coming to power. People like those will certainly find such databases helpful, and they won't care at all whether the data is ostensibly about viewing preferences or directly about sexual orientation.
I mentioned Uganda because I listened to a story earlier in the week about a man being thrown out of his mother’s home because she saw his Tik-Tok feed and it was full of very openly gay content. So we don’t necessarily have to imagine it - in some places this is already happening.
>"how i can use Tech XYZ to do behavioral advertising now?"
you don't.
So I can still apparently, for example, target running shoes to people who like running, for example.
One way to do that would be to advertise to everyone, and.allow to opt out. Thus the advertisers would build up a database of users who don't mind such advertisements. It will be an overwhelmingly female audience, but it's not going to be targeting based on gender (gleaned somehow), it will be based on revealed preferences of users.
But then if that's allowed, you can claim the AI model is just correlated with gender or whatever and not using the field directly and thus also OK.
That genererally doesn't work on protected classes even in the USA (a privacy laggard). Look up the history of redlining.
That's how basically all advertisement worked until just over a decade ago, and it's how a lot of advertisement is still done today.
The people who see them have already bought the product (a Netflix subscription) so the recommendation isn't trying to convince them to buy something.
If people don't see content they want to watch when they start Netflix they will eventually stop paying for it.
Netflix is not there for you to watch your favorite movies when you want. It is there to encourage you to watch as much Netflix as possible. So it makes sense for them to advertise as much content to you as possible.
Not sure when the DSA will impact smaller platforms but you won’t see it for some while.
(Numbers are obviously made up :))
I work in medical device development, stuff like GDPR our regulatory team has for breakfast without much drama. It is normal for us, as it is for airplanes, cars, food processing, financial services, etc.
If there is a discrepancy between what is legal offline vs. online, and you feel you must correct it, then you can strip down the laws that govern the offline. There, solved. The threshold between governments and privacy on, and control of the Internet has been worn down low enough, and has been for over a decade. The only laws we need that have to do with the Internet are to curtail the power of law enforcement and intelligence agencies. Anything other than that betrays all the things the EU says about privacy and fundamental rights as the marketing bauble it is.
And an EU Commissioner saying "we're bringing our European values into the digital world" should scare people. It's a good time to remind everyone that part of these values is letting the Europol do whatever and then rewriting laws to reatroaticely protect them when they've found to be systematically violating them. And for Ursula specifically, those values are what drove her to try over and over again to curtail online freedoms regardless of having it made clear to her that her ideas are unwanted. The Commissioners might be democratically elected -- if you're willing to take the concept of representative democracy to its 100000000th degree -- but they're undemocratic in spirit.
But sure, lets all focus on protecting ourselves from the fucking ads again.
And if you assume the internet should find its own kind of technical solutions, then the solution will look like trusted computing. Then is removing freedom of violating the law, which is worse than having a restrictive law.
What are the reasons of that? I wonder.
With the IETF still working out MIMI and MLS, that's not necessarily a bad thing in my opinion.
What's extremely important is how modular is the technical interop, and above all modules (and not 748397498324 modules) must be reasonable to implement by one individual normal developers (well, for the crypto module, "normal" is not enough). Hope we don't get a remake of the "semantic web" which end up pushing forward the current abomination of web engines (including their SDK).
MLS is a standardised encryption standard for messages, including a protocol and an architecture, to ensure that MIMI can be implemented securely.
MIMI and MLS are still being worked on by the IETF taskforce so you probably haven't heard of it because it's not even sure how it works exactly yet.
The difference between these protocols and the semantic web is that people from actual chat apps actually got involved in its development rather than just being a good idea by a bunch of ideological people.
Because signal or whatsapp, same same to me, I don't want them, but I would need to interact with some people there: namely create an account, and use a light open source client (not using any of those grotesquely and absurdely massive and complex web engines... and their SDK).
I have a very bad feeling about this. EU regulators seems to miss the point: in this very case, it is the client protocol which should be open, stable in time and super ez to implement by even a normal individual dev (not the TLS part ofc).
Then, there is the account creation or guest account, etc. A friend told me EU started to emit user specific certificates.
The EU does not state specifically how gatekeepers must open up their services. For all we know, iMessage will open up a web API that offers the same functionality rather than sticking to MIMI. The IETF called for a unified protocol and people from several projects started laying down their requirements and suggestions, that's it.
In my personal opinion, an open server-to-server system would be better than an open client. An open client protocol would pretty much limit messengers in their functionality for the next ten years, because WhatsApp couldn't possibly alter their image upload API unless they're willing to risk an EU investigation. You'd also end up with ten different APIs, all in various states of feature support and implementation details, and if someone does manage to make a unified app, you'd end up with ten different contacts for the same person.
You're never getting a simple client API with modern chat messengers. E2EE is practically a requirement these days, and E2EE is hard to accomplish. Requiring a simple client would actually make the situation worse, allowing the EU to basically force chat apps to break their E2EE properties because of "API compatibility" reasons. I don't think anyone but the worst politicians want that.
I don't know anything about user specific certificates. There are some EU countries that permit authenticating to government services using a smart card, but that's got very little to do with this whole system. It's certainly not something we use to authenticate with chat services.
What's need to be done is to clearly defines the various URIs to navigate between the various clients (with/without TLS): IRC client, voice/video conf client, email client. For the voice/video conf, it is still a slipery slope as I don't think there is an actually simple voice/video conf protocol yet: no, webrtc is not reasonable, I am talking about a brutally simple protocol namely direct TCP IPv[46]:port (signal, video stream, audio stream and the client will have to deal with UPNP IPv4) with optionaly a DNS name (like SMTP where the DNS is optional).
and again, it is missing the web: noscript/basic (x)html, 2D semantic HTML documents.
Whether this is 'better' is the debate. But that you a person is a product who's manipulation of is current is not. The new current is that of false agency.
Also, has there ever been a time without censorship. Please keep in mind I am not interested in shallow right wing ideology crap.
Big boys/gals always censor. Otherwise they wouldn't be big
Private "censorship" is localized and fairly harmless.
That, again, is a bold claim with nothing to back it up.
Here's an example of private censorship with a political motivation: https://www.businessinsider.com/twitter-leaked-internal-mess...
Nobody elected Musk, and yet he just autocratically controls a major medium of communication now, with no democratic control mechanisms in place. Better not upset the owning class or you, too, will be silenced!
Like it or not (and I don't) Twitter is Musk's property, it's his 44B toy and he can break it if he wants.
This distinction between "elected", "appointed", etc.. people comes up pretty often in criticism of the EU and its institutions.
The electoral collage does follow a process that is election, even if there's one (or more) layer of abstraction between that and initial ballots.
Consider, for instance, some of the key “disinformation trends” listed in the EDMO’s recent 2023 briefing on disinformation in Ireland. They include “nativist narratives” that “oppose migration”, “gender and sexuality narratives” that touch on drag queens and trans issues as “part of a wider ‘anti-woke’ narrative that mocks social justice campaigns”, and “environment narratives” that criticise climate-change policies and Greta Thunberg.
https://dailysceptic.org/2023/08/25/the-digital-services-act...
This gives the EU an extraordinary amount of power. The regulation of the DSA will be overseen by the Commission itself, not an independent regulator. What’s more, the DSA includes a ‘crisis-management mechanism’, added last year in a last-minute amendment. The Commission argued it needs to be able to direct how platforms respond to events like the Russian invasion of Ukraine. Apparently, in a crisis, the ‘anticipatory or voluntary nature’ of obligations on tech companies to tackle disinformation would be insufficient. Under the DSA, the Commission has given itself the power to determine whether such a ‘crisis’ exists, defined as ‘an objective risk of serious prejudice to public security or public health in the Union’.
https://www.spiked-online.com/2023/03/23/the-eus-censorship-...
I would welcome measures that go a lot further than this.
europe has been backsliding on hard won freedoms for a while. this is just part of the trend.
i guess you don't live in europe.
> I guess I know which industry you work for…
your guess is wrong.
yes, there is a lot of fake news out there, and i'd rather see it go away, but i fear that the barrier to decide if something is disinformation is to low. if someone claims that something is disinformation, it is not enough to show that it contradicts some other information, but once such a conflict exist we have to go the next step and show actual evidence that one is right and the other is wrong. and the source spreading the disinformation has to be given the chance to present their evidence as well. if they can't then they may be denounced accordingly, but their spread should then only be limited, and not outright blocked so that there is still a chance to critically evaluate it.
* there must not be a single entity that is the arbiter of truth, but we need multiple independent institutions that evaluate sensitive topics and give their recommendations.
content providers may then follow any one of these institutions at their choice. (most practical would be to have regional institutions to give diversity, but content providers may follow any of them. if the french one says something is ok, and the german one says it's not, then the content may still be unrestricted even in germany)
* content must not be completely blocked but should come with a warning or be hidden. like on hackernews.
i can, if i want to, access all the dead content. it's just an extra step, and the majority won't bother with it, but the ones curious can check, and if there is something wrongly hidden they can share that.
Every single regime that has ever censored anything did it in their mind for the "good" of the people to protect them from negative influences.
The summaries are entirely accurate. Here are some quotes from the document itself:
(p12) The narratives propagated by right-wing extremists in Ireland are broadly aligned to a nativist ideology. Nativism is a particular construction of nationalism that advocates protecting the interests of native or indigenous inhabitants over those of immigrants. Nativist narratives have circulated for many years in Ireland, rising to prominence in tandem with wider events that are ripe for exploitation by extremists ... Some of the key narrative themes that are prominent in the current protest include: Inauthentic claims: References to “economic migrants”, “fake asylum seekers”, and “fakeugees” imply that refugees and asylum seekers are lying about the dangers they face and attempting to scam the state.
(p14) Climate change is often viewed through a conspiratorial lens that seeks to “expose” the ulterior motives behind climate action and downplay the evidence for climate change (see Figure 9). Greta Thunberg is a frequent target for abusive language and humour relating to climate change while Met Éireann weather warnings are viewed with suspicion.
(p17) Some notable characteristics of disinformation campaigns in Ireland are summarised below: Participatory memes and content templates ... Attacks on the credibility of mainstream media and journalism.
* Nick Dixon and Toby Young Discuss Virtue-Signalling Men Pretending to Love Women’s Football
* Official Guidelines Reveal Anti-White Racism of Sadiq Khan’s ‘Branding’ Campaign
* How woke colonised Mexico
* No, Brexit is not the cause of our economic turmoil
It doesn't really seem worth engaging with those articles.