Hank Asher turned Americans’ private information into a business
nytimes.com
nytimes.com
I think the solution to data privacy is to require companies to provide the receipts of where they obtained the data. Know my age? I didn't tell you. You bought it? From whom? Follow up with them. No receipt? Fine paid directly to the individual. Make PII data property.
In the article, Asher and presumably the rest of their industry has many legal avenues for acquiring data. Such as directly from the government:
> the Department of Highway Safety’s trove of vehicle registrations, an untapped resource held separately from M.V.R.s. These the department sold for a penny a record, a low price (relative to those $2 M.V.R.s)
No, PII should be treated as toxic, radioactive waste.
If you lose it, you should get MASSIVE fines--multiple years of revenue level massive fines.
This incentivizes companies to not even collect it and to dispose of it promptly. It also places a dollar value on it that is high enough that you have to understand the profit amount that it is worth. You won't collect it "just in case" since there is such a risk associated with holding it.
After some time the drugstores realized that the government had no resources nor interest to enforce such law and now they simply don't comply any longer.
I'm afraid this is the sort of decision which average people is not really well-equipped to make by themselves. Companies should be forbidden to collect and sell certain sorts of data, period.
in the Brazilians drugstores case, it's absurd, it's like, a $400 drug sold for $300 (mumbers in local currency) if you agree to disclose the equivalent of your SSN. how can your data be worth so much?
truth is that they don't expect so sell a single unit for $400 - the price difference in this case is enough for, in practice, providing your PII is mandatory
That would definitely help, but I think it wouldn't be enough. Drugstores would promptly come up with some app-related trick, like "just scan this QR-code to redeem your discount", and personal info would be acquired indirectly.
Legislators started to elaborate a bill recently, addressing the case of drugstores in particular, but I suspect they will end up delivering something full of breaches, just like they did in the State of Sao Paulo.
Moreover, drugstores are on the spot currently, but there are plenty of companies doing exactly the same nowadays.
> in the Brazilians drugstores case, it's absurd, it's like, a $400 drug sold for $300
Indeed. And I've seen even more scandalous differences already. Psychiatric drugs are the champions, in my experience.
It used to be that you'd get a 1% cashback (in vouchers), but they realised people weren't bothering when just spending a few quid, so they hiked the prices from £3 to £4.50 then offered a 50p discount for your PI.
That would definitely help, but I think it wouldn't be enough. Drugstores would promptly come up with some app-related trick, like "just scan this QR-code to redeem your discount", and personal-info would be acquired indirectly.
They started to elaborate a bill recently, addressing the case of drugstores in particular, but I suspect they will eventually deliver something full of breaches, just like they did in the State of Sao Paulo.
Moreover, drugstores are on the spot currently, but there are plenty of companies doing exact the same nowadays.
>
You can just think of how complex it is from a technical perspective to implement this. Sync all those systems, databases and vendors if a user on my website deletes his data or account. And in case one of those vendors or sub vendors fail to delete (let's say their API responds with an error or I had implemented it wrong or it stopped working due to an API change). It gets hairy quite fast.
I mean, that's not theory or some hypothetical proposal, that's the established practice of how handling private data works for more than 5 years for almost half a billion people and all the businesses in EU; that's how (for example) Salesforce works with all the many EU companies handling data in Salesforce systems.
In general, the process for handling actual business data for all kinds of companies from manufacturing to retail is quite clear, and the only disputes we see are for the (relatively few) global online consumer service companies handling the exploitation of online customer data. If you're e.g. a flower shop (even with online ordering) or a dental clinic (even with online appointments) and you don't want to explicitly stretch the limits with some shenanigans, then you just follow the same standard practices as all other shops in your country, all while using whatever online services you need - it's very rare that some global B2B service doesn't handle GDPR compliance, all that I wrote above is what almost every cloud company will do for you because they do that for so many customers for years already.
If you hire Salesforce you generally disclose to your users that you use Salesforce. But you don't tell them all of Salesforce's processors, and all of their professors, and so on down the infinite loop.
Edit: also the original comment was seeking consent, presumably affirmative. The GDPR system is a model that only provides (some but not all) notice, not affirmative consent.
There is a difference between data controller and data processor. AWS FAQ on GDPR [1] has actually a good paragraph on it, see "Is AWS a data processor or a data controller under the GDPR?".
In your example all cloud providers and SaaS businesses like Splunk store data on your behalf and you own and control it. For them it's just a blob of data and they are supposed to be agnostic of its business meaning. With more targeted SaaS business like Salesforce, it might be more nuanced, depends if they want to do any kind data mining / processing themselves, but if they want to, then yeah, they need an explicit consent. A law like this forces SaaS companies to remove any ambiguity from their service agreements to make sure they are strictly designated as data processors when it comes to user data their customers supply them. This AWS GDPR addendum [2] exists for this reason. Otherwise, as a small business you rarely can negotiate a tailored agreement with a large SaaS company to make sure that the data you pump into it aren't going places.
[1] https://aws.amazon.com/compliance/gdpr-center/
[2] https://d1.awsstatic.com/legal/aws-gdpr/AWS_GDPR_DPA.pdf
This would work if everything would be done in bulk and by officials. It wouldn't work if it was just something citizens would have a right to know but would have to do all the legwork in order to uncover (sending out dozens of requests) and then would have to sue entities in court.
It seems simpler to regulate PII based on consent and strict need-to-know principles.
Correct. Specifically, establish personal sovereignty over one's data.
If someone's using my data, I get my cut. Pay me.
--
I'll have to ponder the notion of receipts (provenance).
I can imagine how the provenance of my data probably matters. Prescriptions, test results, reading list, etc.
But PII is so ubiquitous now, it's part of the public record. Which, counter intuitively, is a good thing.
Establishing a stable universal identifier unlocks the ability to encrypt our personal data at rest.
In our current world of no universal identifiers, linking personal data data across systems requires it be stored as plaintext.
The book Translucent Databases (2nd ed) explains the techniques.
Er, so anyone can keep your 'property' (data) without your consent by just paying you the statutory fee?
Make it easy to file a claim and set the fine at $100 per occurance and things would change rather quickly.
End outcome is the same - peoples privacy already has a price. That price is just currently only represented by FAANG profits.
Feels like an area that could be handled better.
The easiest way to deal with people like this is by putting it in 'the language' they speak. While I'd love, personally, to see some direct regulation, legislation, etc. that doesn't involve turning this into yet another line 'in the books' / in the annual reports etc. of companies ... and feeds, arguably, even more into that sort of thinking ... for multiple reasons there are extensive practical issues with doing that in the US currently. It'd certainly be helpful in the longer term if we could get some people away from viewing everything through the lens of numbers - especially conflating OTHER PEOPLE with "format strings" in Excel (effectively). But, I believe in being practical along with strategic. If such metrics are needed, private-party lawsuits are needed ... if government (outside of perhaps putting some basic accounting in place &/ the justice system and current tort laws) is not an option for sorting out disputes and correcting bad behavior, particularly some forms of traditional government regulation, and the bottom-line is king ... then let's use what is available or might be put in place, ultimately speaking the 'language' necessary to push things in a more reasonable direction.
* Not uniformly distributed, for sure, but increasingly visible on average - in part, thanks MBA programs, but also, somewhat relatedly, decades of work and marketing from people who really want to turn the clock back ... wannabe robber-barons (https://youtu.be/DqgvHUg_vxY) and even those with plantation 'wetdreams'
** Incidentally, this is related to the kind of "mob rule" that outright dangerous politicians like Trump represent. Importantly, dangerous to EVERYONE, even those in the cult, though they almost certainly don't know the true extent of the danger, even remotely. In essence, without any principles / rule of law established in notions like actual justice, truth, fairness, equitable treatment, etc., any forces driving large systems involving people will tend to devolve into forms of mob rule. Whether it's markets for goods and services, the "marketplace of ideas", etc.
What is more and more absent in America, in particular, in public discourse especially, but also in certain business sectors of, in some cases, outsized importance in this entire 'picture', is the kind of principled viewpoints, ideas, thinking, etc. that have repeatedly re-formed this country at those critical moments when it might have broken / not become the exemplar that it often has been. Whether that happens this time as well remains to be seen, I think.
That's a massive topic ... all of this is ... and I am really no expert in much of this, so caveat there, but, I have enough of a sense and of the details of history and the differences in outcomes at different times and in different places to offer the commentary I am right now. More importantly, regardless of some of the background / mechanisms, the actual behaviors are clear enough in recent times / events / data. I.e., what I've written outside of these footnotes.
If you shoplift and get caught, you don't get to keep the stuff.
Moreover, have you seen how some people (generally wealthier, but not always) treat, say, paid parking? They just don't pay at all, because it's not worth the hassle for them. Sometimes even with the occasional enforcement, they come out ahead compared to just paying the original fee. But even if it isn't worth it financially, it's often worth their time, so they do it without really caring one way or the other.
Anyway... the penalty for shoplifting (assuming they bother to go after you) isn't generally a "pay this fine and return what you stole". It's being subject to everything that comes with crimes... dealing with law enforcement, tarnishing your personal record, potentially getting jail time depending on the severity, etc. Any civil case that you might get filed against you for damages, attorneys' fees, etc. is just icing on the cake, and hardly the meat of the punishment.
If they get caught it's $100 and they need to delete it. Caught with the same data its $1000.
Furthermore, if they are caught storing data in a pattern, say 100 people catch them within a year of the first, the fine retroactively becomes $1000 per incident over the time of the pattern.
With a Judge having discretion to raise fines, retroactively and inclusive of new violations, for companies that simply refuse to comply.
I feel like this could work.
In fact, I would think most companies would start designing their systems to ensure they didn't violate by accident. Which is what they are supposed to be doing, but not.
Why though? You need to give a good motivation for avoiding the obvious and direct solutions in the first place before anyone sees any reason to go through the effort of strongmanning an alternative. If I was proposing a $50 fine as the penalty for random people caught squatting in your house would you be interested in strawmanning it just because it makes for fun argumentation? I sure wouldn't.
And anyway, I already commented on the merits of this idea in my earlier comments: you're not at all considering the fact that $100 (or even $1000 or more) might be well worth it for certain people's information. It just might not be the entire population, is all. You're just picking winners and losers with this approach, on both sides, is all.
They wouldn't even have to store that info in their regular systems.
But making it unsustainable for them to make a habit of it, which is something that impacts millions of people, is possible, with escalating fines.
Also, it doesn't make sense to say a business will just take fines as a cost of business, without taking the size of fines into account. Clearly there is a number that they will respond to, because that is what they do. Respond to hard currency numbers in whatever objective way will let them maximize what they keep.
Were they British or American?
The best advice I got from someone who knew Hank was, even been on his boat down at Ft Lauderdale, was if you dont want to get hacked, dont put your computer online. Even that is virtually impossible now, one has to become an expert in everything.
There is alot of data sharing going on, not just official businesses like this, but media & news outlets. Journalists have the law on their side as well!
Court records for instance
“On display? I eventually had to go down to the cellar to find them.”
“That’s the display department.”
“With a flashlight.”
“Ah, well, the lights had probably gone.”
“So had the stairs.”
“But look, you found the notice, didn’t you?”
“Yes,” said Arthur, “yes I did. It was on display in the bottom of a locked filing cabinet stuck in a disused lavatory with a sign on the door saying ‘Beware of the Leopard.”
I use neither email (for years now, a blessing!) nor have my own phone number (VOIP outbound, only). Anything requiring either gets a burner.email or my numeric pager.
A recent civil court action requested both of these obsolete (to me) technologies, and the judge's clerk required that I sign an attestation upon leaving them unanswerable.
Court records are public in my jurisdiction, and I choose to be "unreachable."
----
Regarding the linked-to article, a harrowing read (certainly)! US citizens are allowed, by law, to request a FREE COPY of everything LexusNexis has on them in their private consumer file.
I have a numeric (ONLY #'s allowed) pager — pagersdirect . net (coverage available nationally, paid for each metro area you will use pager). I have no affiliation with PDnet, other than as a customer.
If you wish to reach me, you text me your phone number (or a "code" if we have arranged such)... I then call back from an unregistered VOIP calling service (no phone number, so cannot receive calls).
----
As for not using email, this was simple: just stop using it! Paul Graham has a great lectures (decades old, now!) wherein he complains that "email is just a to-do list, which other people can place tasks onto." Incredible how we haven't implemented a solution for this yet (e.g. now-depricated hashcash authentication).
say what?!
Beyond that, sometimes it's begging that does it, sometimes it's threatening. I've discovered that some companies appear to have a rule where if a customer even utters something along the lines of "I will sue you" they're just obligated to escalate it without trying to waste your time -- bingo!
Thinking back on it, when I heard "calls are answered in the order they are received" I never asked myself "what other order would they be answered in" xD :'<
The lines were not obvious, or there were simply fewer segmentations, when I was a kid.
Now, you see it at the airport with 3 different levels (regular TSA/precheck/clear), based on how much you pay.
You see it at theme parks like Disney world / six flags, and even there, there are multiple levels of priority you can buy.
And I went to my county fair for the first time this year, and I was somehow surprised that you could pay more for skipping ahead on simple carnival rides, even for toddlers.
The regular line is self explanatory. Precheck is solely run by the TSA, and they politely ask the airports to set up dedicated lines for precheck. Sometimes they do, sometimes they don't. Until passengers are in the checkpoint though (i.e. beyond the id check), the TSA has fairly limited authority. The airport is ultimately responsible for getting passengers to the security checkpoint, subject to some minor conditions by the TSA. Clear pays the airport/airlines a kickback from the subscriptions to let their agents manage the queues, which includes putting their subscribers in front of the other lines. One thing they can't do is give you special perks inside the checkpoint like precheck does.
So, 3 lines because 2 different parties get revenue from one each.
The point is, you pay more, you save life time. The government could have chosen to make it free so everyone can access these time saving measures, but our leaders did not, deeming it acceptable for further tranches of society to be publicly displayed.
Paying is an easy way to select for those who value it the most, which are the frequent fliers. If you’re a business traveler or otherwise someone who travels a lot, the price is small compared to the flights and the time saved is very large. That will be the inverse for those who need it least, the infrequent travelers.
Yes some people who travel infrequently will choose to pay for the faster line, but then they are also subsidizing the extra cost of staff to run the other systems.
The idea that this is meant to put tranches of society on display is ludicrous.
Knowing a number of people who have to travel a lot for work, I might even say that most of the poor shlubs in the precheck lines who have to travel monthly or more frequently are the real losers in the grand scheme. Traveling in flying sardine cans to make a living is no fun.
Or you can increase staffing.
> The idea that this is meant to put tranches of society on display is ludicrous.
It may or may not be meant to put it on display, but it shows it for what it is. People who can afford to pay to save time get prioritized through public infrastructure, and people that do not pay have to wait.
At my local airport, all security lanes except for one for precheck, are well staffed and move as fast as the passengers allow. The space is already used maximally, however lines are exceedingly long. Switching the precheck lane to regular would have almost no effect on wait times.
Queuing theory is rather complex.
Which would increase the cost. You could pay for that by charging everyone more, but many people on their annual trip don't think that the extra $10 on the ticket is worth the 20 minute saving. More importantly they'll choose the airport which is $10 cheaper as they have fewer agents so the peaks aren't smoothed.
Also, security screening is partly and can totally be paid by marginal income taxes, it does not need to come from each passenger.
Oh sure, that's great. How many have bought it?
Oh everyone on today's flight, it's such a good deal
I assume all the biometrics for Clear aren't just to prove your the person who paid for Clear?
The rest of us toil to make them happy. This unjust system should be razed to the ground.
It is a state of mind, a man can be free on a jail.
I'd recommend a read to Marcus Aurelius Meditations if you fancy that kinda thing.
Maybe the 8 billionaires you've in mind are less free in their day to day to do whatever the fuck they want than the billions of poor people that barely gets by and survives.
how many rich man have you met which aren't happy?
If you read Discourses, you would recognize your error in believing that a man can be free in jail, for he does not have the ability to choose where or how to exist, those are both limited directly by the existence of the jail. He can tolerate it, but not be free, as a stoic would tolerate a broken arm rather than claiming the broken arm makes them stronger.
Will read Discourses.
There's my disgust at your trivializing of incarceration. There's the eye-rolling disbelief at being told to read stoicism in response to the naked avarice of the wealthy.
But what really galls me is this:
> Maybe the 8 billionaires you've in mind are less free in their day to day to do whatever the fuck they want than the billions of poor people that barely gets by and survives.
What? What nonsense did you just string together here? You're purporting that the people who have quite literally everything are the ones trapped by the system? So then they can change the fucking system, which is an ability they posses the rest of us do not.
How many poor people have you met who are happy to be poor? Have you actually met and talked to any poor people?
And the dozens of people who own most of the wealth in the world can still pretend they're filthy rich after they have been taxed to hell and back. What is the problem?
"Hicks, how come you're not working." / "There's nothing to do." / "Well, you pretend like you're working." / "Well, why don't you pretend I'm working? Yeah, you get paid more than me, you fantasize. Pretend I'm mopping. Knock yourself out. I'll pretend they're buying stuff; we can close up. I'm the boss now, you're fired. How's that?"
-- Bill Hicks
> how many rich man have you met which aren't happy?
So? Tell them it's just in the mind.
How many people who are struggling, who are as happy over a 5€ discount like others would over a new car, do you know? Who will remember the tiniest of gifts and the smallest amount of help for years? Who do what they can to help others, even when nobody is helping them? Who complain so modestly, if at all?
The idea that people people should just accept what isn't fate, but simply being exploited by other people, just so those other people can continue a lifestyle of sociopathy and addiction, is something I could not reject more.
It was time 30 years ago.
Its not just data broker removals- Its alexa recordings, youtube search history, your mailing preferences, and like 9999 other things. Data brokers are just one part of it.
I enjoy the work we do but it also sucks having to do it. Each endpoint is its own challenge and doing something as simple as automating removal from one database can take days of a developers time. It will be a beautiful day when this stuff gets outlawed eventually.
But to follow your lead, credit ratings go back to the 1880s, my favorite episode of "Backstory with the American History Guys" covers the topic:
"figured out" is misleading. He just built upon existing infrastructure.
127.0.0.1 nytimes.com
127.0.0.1 wsj.com
127.0.0.1 washingtonpost.com
127.0.0.1 cnn.com
127.0.0.1 foxnews.comBased on your report, I plan to stop informing people about the issue.