Gmail and Instagram are training AI, and there’s little you can do about it
washingtonpost.com
washingtonpost.com
The mass media and blogs love to present Big Tech's tactics as a fait accompli. Instead they should be making the point that "defaults" are used to deceptively "gain consent". We need legislation to stop this practice.
The paragraph begins "Unless you turn it off,...", then it states "And when you opt in ..." and then it ends with "You can't say no."
Well, which is it. Can they say no by turning it off or not opting in. Or is it impossible to say no.
Of course they can say no. And when they do, it complicates matters for Google. If saying no were useless, then privacy-eroding "defaults" and so-called "dark patterns" would not exist. Why bother tricking people into saying yes or not saying no, if saying no was meaningless and consent is an afterthought. Before you cynically conclude, "there's nothing anyone can do" (watch the replies), ask yourself why dark patterns exist and why Google pays billions to multiple companies to be the "default search engine". Big Tech and smaller so-called "tech" companies put a lot of effort into these tactics. Why. Because they are bored and enjoy manipulating people? No. (Well, maybe. But that's another topic.) It's because people can say no, and when they do, it can have potential repercussions.
Anyway, no problem with the rest of the article. Although it's more about what the companies are doing versus what computer users could be doing, namely, objecting.
IMO simple objections will not sway tech platforms from the status quo of free-for-all data hoarding. We must vote with our feet and move away from the data-hoarding incumbents towards user-centric alternatives. Where suitable alternatives don't exist, we'll need to create them.
I think the statistics around organ donation are what got me started on it.
We really should have legislation mandating minimum consent by default options, and then additional legislation that creates allowances for non-minimum consent on a case-by-case basis. So we can allow, if we want, for organ donation to be consented to by default if the general public feels it is more ethical to default to consent on that option than not. And if harvesting everyone's data for AI is going to be default, then we would need a similar public consensus
The more work a company needs to do to get consent from its users, the less bullshit they are going to create and try to get away with because they'll need to actually convince people to care enough to change their defaults.
It will better align incentives between consumers and companies imo
As the article points out, because there is no regulation and no clear definition of where the “privacy” line is being crossed - companies will do everything they can to get a competitive edge.
I am also a little baffled with how many editorials have blocked GPTBot but probably couldn’t explain why they did it, because once you hit that publish button - the very next day it’s going to be in a dozen different datasets, not to mention being passed around by data broker’s that rather stay secretive.
All this is setting such an insane precedent for the future of the web and how content will be created, I guess AGI is just that close and it’s going to be that great that it will solve all of our problems.
I've been doing this with bane of the internet "captcha" for ever, where I pass it with incorrect but plausible answers. I'm pretty good at doing this now.. and although it's probably a drop in the ocean, it gives me a warm fuzzy feeling knowing that I will have made their weights ever so slightly more shitty if they try to use my input as training data.
This has some interesting implications. The more conspicuously-racist and DIE-noncompliant you appear to be, the more resistant these companies are to including you in their training data.
Maybe tomorrow we'll be counted as three.
A more meaningful stance would be to refuse using these tools, and advocating for using other more ethical and privacy friendly alternatives such as hCaptcha or Cloudflare's Turnstile.
> [x] Turn on smart features and personalization - Gmail, Chat, and Meet may use my email, chat, and video content to personalize my experience and provide smart features. If I opt out, such features will be turned off.
> [x] Turn on smart features and personalization in other Google products - Google may use my email, chat, and video content to personalize my experience and provide smart features. If I opt out, such features will be turned off.
There are two 'learn more' links that go to the same place:
> The control covers smart features in Gmail, Chat, and Meet that may use your data to improve the models that power smart features, including [list omitted, emphasis added].
> Smart features in other Google products that may use your Gmail, Chat, and Meet data include: [another long list omitted]
This could be a bit clearer about what happens if you have 'said no.' If the reporter had actually gotten someone to clarify that, it would be helpful. As it is, they've added no value over just quoting what it says.
How would you describe the issue briefly to someone who doesn't know what machine learning is? Sure, a lot of people know about it now, but I think much of the general public still has only the vaguest idea, and that was much more true a couple years ago.
This doesn't appear accurate. The article linked in the above paragraph states that there were 3 occurances of Samsung employees giving ChatGPT sensitive data, but does not mention it returning sensitive data.
The paragraph quoted seems to imply some level of fine tuning or persistent memory keeping this information, which I don't believe OpenAI products do?
Email is basically public as far as I treat it. I'm fairly careful about what I say in an email.
I suspect that even if everyone could be convinced that encrypting everything was a good idea, the moment gmail couldn't collect and profit from the contents of people's private messages they'd shut the service down. It exists only to exploit us.
If the user has to copy/paste a blob from gmail into a file and then run gpg on it, well Microsoft Windows is scanning everything on your hard drive and maybe even in RAM so they'll get the decrypted file.
A handwritten letter is probably the most private way to communicate with another person who you can't talk to directly.
You have to control not just your behavior, but everyone else's. It's exhausting and frankly, impossible.
USPS has this great service called Informed Delivery that gives customers scanned images of all our mail. In fact, USPS has been scanning, OCRing and electronically processing mail for a long, long time. I would say that their elaborate surveillance capabilities are on a par with Google's in some respects. They absolutely have social graphs available for anyone who corresponds with anyone else through the mails.
Not to mention the rampant mail theft that's being reported these days; I'd say that email has gained an edge and is safer in most aspects than putting it all on paper, unless you're going to walk it into the IRS on foot.
The USPS scans envelopes. They don't open them and scan the contents.
Intercepting, opening and reading postal mail that isn't addressed to you is a rather serious federal crime. Email? Google does it every day, all day long.
I mean, if people as a whole stopped using Gmail, then this would stop being an issue.
Hype a short name like "hnmail" with a fancy UI. Setup an invite system and you could be the next email provider.
Just as Canonical hyped with free Ubuntu cd's.
I've stopped using gmail ever since they disabled my account wolfcub@gmail for no reason. never will and won't tell me why. Apparently it's "inclusive", whatever that means.
Way to disgruntle a 17 year old me, so I've been hosting my own ever since.
This is not easy.
The only thing that stops is that Google has resources to splash on engineers to build such a product. Thats all it is, money.
Everything that google can do, exists in the opensource space.
If someone takes a picture of you and posts it on Instagram, they are still using your data.
The only solution here are new laws about retaining ownership of your data even if it's been uploaded to a third party.
But also, laws can be changed, which is my point.
IANAL
https://codes.findlaw.com/ca/penal-code/pen-sect-632.html
In fact I doubt there's fully relevant case law, as I think the case would be that the trained model is the recording device, and it could be demonstrated that verbatim strings from presumed confidential communications are regurgitated by the model when appropriately prompted.
Wouldn't this also be a violation of the same Two Party Consent law that you're trying to apply here?
You can stop using those services.
>It’s your data.
As soon as you decide to upload it somewhere else, it's not.
you do not under any circumstances actually need to use these services for them to use and collect data points on you.
Sure, it's all publicly available info, but I don't want services I haven't signed up for having my info without my consent. I don't like that my friends and family can just give them access to all of that data without me being involved in any way.
I don't think that's true. Users could be allowed to enter addresses individuality or ideally, when apps ask for permissions to a person's contacts phones could allow users to select what the app can and cannot see (only certain contacts, or phone numbers but not email addresses, etc)
There are ways phones and apps could handle contact data while preserving privacy, but nobody is interested in helping people keep their data private. Phones are designed to leak your data like a sieve and apps are designed to collect every scrap of data they can get their hands on.
Still, it annoys me that most people probably have my personal email address, phone number and real name tied together as a contact and provide this information to at least one online platform. Back when I used to use Google and Android, I would try to preserve my contacts’ privacy by storing their names using some mixture of first name, nicknames, initial for surname and context, e.g., “Alan F”, “Fid”¹, “Alan (football)“, “John (work)“. I’d also keep their number and email address as separate contacts — though that might only have worked in the early to mid 2000s. At some point, Google started getting too clever at determining which contacts could be “merged”.
¹ short for Fidelma
At some point things turn from you can avoid to they are ever present.
Kind of like avoiding cameras and license plate readers, you going to lock yourself in a hole and avoid people?
I cannot avoid every contact I have not using these services, unless I have no contacts. If whatever point you’re making is “who cares you can’t avoid it anyway,” that’s not only intellectually very lazy, it’s untrue - Lots of countries have regulated their way around these issues. The fact that one of the biggest producers of tech in the world (US) has this space fairly unregulated is not some excuse to capitulate to things that are fairly easy to regulate sensibly, if there is political will and knowledge. With uninformed takes like the parent I’m replying to still floating around out there, I guess it really is inevitable and unavoidable.
But they can't stop using you.
Even if you stop using Gmail, chances are that the other party is using Gmail. (Today even e-mail addresses with non-Gmail domains are often using Gmail behind their custom domain.) So, your emails go to train AI for Google even if you deliberately stopped using their service.
In any event, as the other poster mentioned, your original post claimed “You can…” and now you are moving to “You can’t” out of an apparent relish for being contrarian. This is not good-faith discussion on your part.
That may be how everyone is treating it but that isn’t the only or even the obvious way for it to be. Mailing something doesn’t give the mailing service a right to open and scan the contents of your letter, even if it could do so without damaging anything. Parking your car with a valet service does not grant the service the right to drive your car to make deliveries while you’re not using it. Sending photo film to be developed doesn’t give the developing service a right to make their own copies of it. And so on.
It’s not unreasonable for a user to think of their emailing something as just granting the mail service the minimal privileges necessary to transmit and deliver the message to the explicitly intended recipient.