Microsoft AI spying scandal: time to rethink privacy standards
spectrum.ieee.org
spectrum.ieee.org
We live in a regulated "supermarket" economy. What surfaces on a screen is entirely analogous to what surfaces on a shelf: People check the price and make their choices based on taste, budget etc. They are not idiots, they operate under a simplifying assumption that makes life in a complex world possible.
The implicit assumption central to this way of organising the economy is that anything legally on sale is "safe". That it has been checked and approved by experts that know what they are doing and have the consumer interest as top priority.
People will not rush back home to their chemistry labs to check what is in their purchased food, whether it corresponds to the label (assuming that such a label even exists) and what might be the short or long term health effects. They dont have the knowledge, resources and time to do that for all the stuff they get exposed to.
What has drifted in the digital economy is not consumer standards, it is regulatory standards. Surfacing digital products with questionable short and long term implications for individuals and society has become a lucrative business, has captured its regulatory environment and will keep exploiting opportunities and blind spots until there is pushback.
Ultimately regulators only derive legitimacy from serving their constituencies, but that feedback loop can be very slow and it gets tangled with myriad other unrelated political issues.
A fault I see in Bruce Schneier's article, and the general hypothesis of "frame/baseline shifting" - it's not that people have been conditioned or forgotten the value of privacy, but that we're looking at the world through ever smaller lenses. The story in the article is that science is guilty of that too. The decline has been around education and perspective in general, not just attitudes to a small issue like "privacy". We thought the internet would widen our scope. It narrowed it.
In the UK we have a great travel and culture show by Romesh Ranganathan. (I highly recommend it, so get on your VPN to watch BBC or find it on the torrents). It will cheer you up [0]. He's a funny guy. But also the cultural vista is breath-taking. Looking at life in central Africa it's great to be reminded of the diversity of humankind. Watch for the little things - like a whole bus queue of people, none of whom are on mobile phones.
What the Internet promised - the great "conversation of mankind" - never emerged. Instead we got cat memes and social control media that forced people into ever smaller parochial silos. HN is no different. Here it's cool to have a bleak outlook on humanity and technology. "Oh it's too late... we're doomed... oh woe is me!" C'mon hackers... what happened to the joy of shaping the world? :)
Bruce Schneier appeals to a macro systems theory metaphor, and mentions Daniel Pauly [1]. But he neglects some of the more profound lessons that Forrester, Meadows and actually Norbert Weiner gave us about feedback and the empty dream of cybernetic governance. Nothing as big as humanity will fit in bottle that small unless you're willing to destroy it in the process. And what you're destroying is the very innovative base that gave you the technology in the first place. This is why they should teach history, geography and other cultures in schools.
https://en.wikipedia.org/wiki/Norbert_Wiener
Otherwise, I completely agree.
> What the Internet promised - the great "conversation of mankind" - never emerged. Instead we got cat memes and social control media that forced people into ever smaller parochial silos.
The internet economy enabled browsing on a global scale and, because no kind of agency could keep up with its development speed, pushed everything into an "on demand" culture - what evolved with it is the higher responsibility for consumers. I feel the state of economy before the internet was on a scale of "everything is possible" (in the western hemisphere at least), only to discover years later that "our greed has consequences we just couldn't see before". Our cognitive load feels higher than ever to just cover the basics of survival and not get screwed over, or screw someone else over, constantly.
> This is why they should teach history, geography and other cultures in schools.
I think system thinking should become a thing in schools early on too. Every defined system is a mere conceptual view with artificial boundaries - a system without boundaries isn't a system, but a universe. It's good to enable new resources to think about new systems, or rethink existing systems, but we also should discuss the boundaries required for its concept to make any sense. I feel that this understanding gets sometimes lost, and its naivety gets regretfully relabeled as "innovation".
There are no "leaders" with MBAs
Good observation. It gets blamed on globalism, liberalism, post-modernism, capitalism, and a bunch of other things, but somehow we got the wrong idea that all boundaries are bad. Boundaries must be broken!
I think that came from the language of science and technology. We made "Smashing barriers!" a synonym for progress. But it is a childish, iconoclastic and directionless notion of "progress", for its own sake.
Psychologically at least, a lack of boundaries is a kind of madness, it's disinhibited, intrusive, lacking self-control - and to the extent there's a political theory of mind it leads to wars and internal unrest.
We raised "connectedness" to supernatural hoodoo, but connectedness for it's own sake is a catastrophe to systems. It violates the principles of modularity, decoupling and appropriate cohesion.
We were vastly outnumbered and overwhelmed by sociopaths who exploited the tools to make our lives better by capturing everything of value in the market, and subsequently enshittifying it. Our cynicism has been well earned and deserved.
Your perspective is cute business school brain washing but the real fact is that businesses like the FAANGS have realized that they can tap into fascist daddy's money faucet and sidestep the shelf-joke analysis you portrayed. Why worry about stocking shelves with good products to maybe sell units to individual consumers when you can sell to one big monstrous entity who can sign a billion dollars' large contract to ingest and process everything against the masses who barely have $100 to pay for a piece of software.
We have a U.S. military problem here.
People will not rush back home to their chemistry labs to check what is in their purchased food, whether it corresponds to the label (assuming that such a label even exists) and what might be the short or long term health effects. They dont have the knowledge, resources and time to do that for all the stuff they get exposed to."
What you describe is a feature of a high-trust society, where you don't have to double-check every single transaction or interaction you enter into, but can take most statements on trust. This allows people to get on with the fundamental task at hand, rather than dealing with the overhead of checking their food in the chemistry lab, or whatever the equivalent is for the specific transaction.
I have read suggestions that this was a major contributor to the growth of the Western economies, relative to other low-trust societies. If this was the case, we are in for a bumpy ride, as we seem to be rapidly changing from a high-trust to a low-trust society.
Not everyone's goal is to progress a society though. If one's goal is to live a quiet life and do what makes them happy, what's wrong with living in a cabin in the woods?
That would only be a fundamental problem if everyone owes something to society. That's a much different conversation though, whether everyone is born into a debt that must be paid back to society.
Even once these basics are sorted, you will only live happily outside society as long as you are lucky enough to stay healthy.
The second sounds like a separate goal unto itself. There's absolutely nothing wrong with that goal, or with having multiple goals, but if you start by saying doing X makes you happy then it doesn't really make sense to say doing X won't actually make you happy because you aren't doing Y.
Presumably if one is actually living alone in the woods they wouldn't be dependent on the larger societal systems like money, security, manufactured goods, etc. How would the get the money to start with without having a job that interacts with the outside world?
But you can't do that if your passion is making music, or mathematics, or computer programming, or electrical tinkering, etc. There just isn't an option to follow the vast majority of pursuits except if you also engage in society.
That's actually where it gets really interesting though. Progress isn't absolute, it's relational and requires first defining the goal. If one's goal is to live a quiet life where they minimize their dependence on others, living in a cabin in the woods and finding their solution for food and water is progress. That obviously doesn't fit for a larger society where the goal is generally increasing dependence and trust on the larger society, but neither is right or wrong.
This has to be negotiated with the people who would want to take your cabin in the woods and throw you out.
Responsibility is a fundamental requirement of freedom though, there's no way around that.
Thank you. That was my initial thought too. Why is progress the goal? Not everything has to "progress" at all times. What progress needs to be made anyway? And towards what end? Who decides that?
There's an inherent good to stopping progress and spending some time in a cabin in the woods.
If we never stop and enjoy now, then why bother with tomorrow?
The idea seems to be that starting with what we have today and taking another step forward is always the right move. Never go backwards, and its okay if we don't define our goals beforehand as long as we keep moving our feet.
In the common sense where progress is little more than moving our feet, there's no end unless civilization collapses.
If one goes at it from the angle of the goal bring "enough", the end really is just getting to a point of maintaining what we already have. Wanting to secure the basics like shelter and reliable access to food and water is met with much less than what we have today. Surely there's some level of convenience and enjoyment that make sense beyond just the basics, but are we not there yet? And if we are, would progress best be focused on the goal of maintaining what we have that gives the most people an enjoyable life while minimizing our impact on the rest of the environment and everything that allowed humans to be here in the first place?
That's the government actually doing its job for once, but you can't check at home for data safeguarding.
Look at the graph here on the wallet study, should give you an idea. China is a good example.
Though, for Israel that is changing for the worse - less trust in the government and each other.
Meaning you believe Biden leans towards the extreme left?
string from Wiki: "Thoreau's philosophy of civil disobedience later influenced the political thoughts and actions of notable figures such as Leo Tolstoy, Mahatma Gandhi, and Martin Luther King Jr."
but the point is: maybe going off-grid can be relevant? changes also can also occur in "small bubbles of reality" and their impact can be extensive or narrow, still, they are a change..?
Then you go use linux and everyone copy-pastes commands other people wrote straight into the terminal.
This is exactly the same bias in action. When I started using Linux nobody was doing that, and even if somebody gave you a script, its actions were verifiable by reading the relevant man pages.
I still don't run install.sh files I didn't read or at least skimmed, for example.
Since all the repositories are signed there must be a big breach to compromise these packages since the infrastructure is generally distributed. Different servers, keys, etc.
> What makes the shell script so special that it must be audited with care...
Because I need to know what changes I'm incorporating into my system(s), and plan accordingly, or prevent any change which is not in line with my system administration principles.
> ...but the binaries are fine?
They are not fine, but they are signed at multiple levels and checksummed, so they are a lower risk.
It’s trust all the way down and always has been. You just have a different idea of how you formally signal and convey trust than someone else.
I paste commands into the terminal because I can read exactly what they do and they are delivered over a connection where my user agent has verified the TLS certificate of the server. In fact I’m electing to trust directly rather than transitively the source of the software.
The only thing signed files prevents is modification in transit (and at rest on macOS/iOS and Windows, Linux doesn’t do that). Linux is ripe with time of check vs time of use race conditions.
For example, a well maintained APT repository contains multiple levels of signatures, and these signatures are stored in a keyring. You import the keyring, and it contains public key of every package maintainer, plus the repository manager. So, package maintainers sign their packages, and repository maintainer signs the repository, plus the packages via their checksums. Packages' own signatures and own checksums provides consistency and authenticity checks, and repository maintainer's signature makes sure that nothing in the repository moves after the repository is signed and published.
So, you have to compromise at least two private keys (or two people) to compromise a repository. If you're working with a critical repository, you can use "m of n" scheme for the repository signing keys, so you need to compromise m+1 people to do something nefarious.
> So if I send you a signed script that checksums itself before running will you run that without audit?
Hard no. You don't have a verifiable chain behind that script. Even if you do, scripts are always read and examined. Period.
> I can read exactly what they do and they are delivered over a connection where my user agent has verified the TLS certificate of the server.
Yes, a TLS certificate guarantees that MITM is impossible for now. But it doesn't guarantee that server has not been compromised and the file changed at rest. We have seen that happened in the past.
> The only thing signed files prevents is modification in transit ...
No. Both RPM and APT repositories' signature chains ensure that files are not modified at rest or at transit, plus the files are put into the repositories with an approval of a real human being.
These signatures are tip of a "web of trust" iceberg, and not mere automated signatures.
Moreover, if a software doesn't inspire confidence and doesn't pass the smell test, it doesn't get installed on my system anyway, regardless of its form.
If I have to install it, I install it to an isolated VM, and destroy the VM as soon as my work is done with it.
Sounds like a very small internet.
I know a lot of people that use Linux and not many of them operate this way. Most care about their software sources. "Everyone" is certainly not the case.
A github author just has to put up a repo and hope that their fanbase aren't too versed in the language
Anyone who's like "well I don't copy/paste shell code into my terminal" is just virtue signaling. I'm willing to bet their editor Vim/Emacs/VSCode is overflowing with plug-ins and code written by just some guy on Github. I bet they've ran containers that are written by just some guy too.
It's a really cool feature that you can just download a random binary off Github, run it, and not really have to worry about it.
It is such a shame. It is a shame that phones are intrusive, smart tvs are intrusive, commercial home automation systems ... etc
This applies to certain producs only and even in the EU where these laws are more strict some products are regularly withdrawn from sale (these are mostly quality issues, not intentional actions), even as far as drugs are concerned. It's one of the reasons I tend to buy fresh products and from bio shops mostly - to increase my chances.
Interesting choice wrt. bio foods. I'm the opposite: I don't trust organic/bio food at all. There is a lot of vanity products clearly meant to pay more to make yourself feel you're choosing a healthier alternative. Plus, I trust the established industrial processes more - they're thoroughly regulated and tested. A devil I know. Bio/organic stuff, who knows what they're doing - and what poisons they're spraying on their produce, that let you keep "organic" label but are otherwise more toxic than industrial pesticides.
That has basically not happened. It sometimes seems that the situation has got worse in terms of public debate, due to the usual bad-faith actors. For example, the TikTok discussion is not framed around privacy in general but focuses on "China bad". With the implication that an algorithmic megacorp controlling political sentiment through feeds is completely fine so long as it's Americans doing it. And the voting security discussion: there were questions about voting machines long before 2020, but partisan attacks focused on discrediting valid results.
TikTok is messed up for many reasons. One being it’s a waste of everyone’s time. Two, foreign nations getting a treasure trove of video footage on a massive populace in the age of AI. This WILL lead to a faked mass-casualty event using real identities of people to cause political unrest. Just a matter of time—and data.
Going back to the article though, the social media baseline needs to be fixed as well. The OG Facebook platform was actually GOOD—lots of good-natured value in human connections. Then they started cutting in the bad shit reducing its purity.
TikTok took that to a whole new level and put in some home grown Singaporean crack. Ironically, the Chinese and Singapore have hefty penalty’s for drugs—and yet they thrust it onto the western sensibility. After all, it’s the WILD WEST.
One almost wants to say, revenge for the opium.
it's just not that compelling.
How is this not relevant to the base post? A shifting baseline toward the worse.
I think it will have to be something large-scale and obviously concerning to consumers. Something like voice calls leaking and being used to create a mass deepfake campaign targeting consumers.
I don’t think people will care until it’s a problem on their doorstep, sending them phone calls and notifications and what not. Identity theft is too abstract, and too “something that happens to old and other people, not me”.
That's the premise of the Brian K Vaughan/Marcos Martin comic "The Private Eye." Unfortunately, the premise is more of an aesthetic than anything else. Still, it's a beautiful aesthetic and a fun read.
It's exhausting and a real nuisance to my quality of life but I equally refuse to knowingly consume excess additives unless completely in a pinch.
Needless to say I'm also very suspicious of online businesses. Although I'm actually getting a bit fatigued/defeatist by privacy issues. We're all so overwhelmingly in this ship that I don't know what I really stand to gain by constantly hamstringing myself digitally...
If we wake up in the worst case scenario, I'm sure I have enough of a footprint I wouldn't be able to meaningfully hide much from a determined bad actor...
I hear that and I will admit that lately it does seem to get in the way a lot more often than expected ( my bank in my recent interaction removed branch connection for a specific application and moved everything to an online process, to which direct link is an ad tracker ). Still, wife now has gotten used to no ads ( almost ) anywhere and is starting to see what the benefits can be.
<< determined bad actor
Sadly, if I am targeted, there is no escape. I am privacy conscious, but I also have a family and try to live in a society in a sufficiently comfortable manner. It is a tough balancing act. In a sense, it is not that different from guerrilla warfare. There is no defense against sufficiently motivated entity that is not exhausting. My only solace is that I am a low value target so it does not seem that likely. Still, what are the odds of me pissing off someone sufficiently important? Non-zero for certain.
Why not? Unless you have severe allergies the excess additives will probably do very little to your health. And the quality of life and exhaustion wins probably make it a net win for you. Is it a principled stand?
When I lived in London I quite enjoyed hunting down niche grocery stores that would serve fresh British produce
But why do you _want_ to live forever? Frozen Pizza tastes good every once in a while.
Don't mistake me for someone who doesn't enjoy food or eating. My lifestyle is impractical and annoying but it also pushes me to do things like cook properly and I've really discovered the joy of eating high quality fresh produce.
Also my guilty pleasure is a good old fashioned beef frank and it's going to be a struggle getting one of those free of additives...
Tech bros never faced the same scrutiny as regular industries do (or at least there were no consequences).
For many years on HN I have seen comments that constantly try to shift the focus away from articles like these and place blame on computer users. This is old hat. We are past that nonsense.
This article is addressed to the "security community". But some HN commenter is trying once again to shift the focus to computer users, making sweeping, generalised, incorrect, and ridiculous assumptions about them.
There is a commercial motive for destroying privacy and collecting data. Computer users are not voluntarily "giving up on privacy", or "trading away their data", with informed consent, to enrich software developers. It is being taken, without notice, often unbeknownst to the victims. There is no "contract".
Regulation will continue to gain momentum as it is obvious to anyone outside of the so-called "tech" companies and their supporters that this is a bad deal for society.
The problem is not the behaviour of the victims, it is the behaviour of the perpetrators.
"Until fish start caring about being caught and changing their natural behaviour, ..."
Even in the (almost) mainstream media with shows like John Oliver, you can see just how deep the degradation of all our regulatory entities really is.
In today's world, almost everything we purchase is pure garbage. The food is overly processed and with excessive use of chemicals and added sugar, the furniture is from cheap material and shoddily built, the building we live in was built cutting corners and skirting laws as much as possible, the software we use is mostly garbage thrown together to "ship fast and break things", the doctors we go to are uninformed and trained to dismiss you as fast as possible, the car repair service wants to rip us off based on our lack of knowledge. I could go on forever here.
It's honestly a joke. We are all the proverbial boiling frogs and allowed everything around us to fall into ruin (and continue to do so).
This assumption you presented only works for the uninformed masses. If you investigate for 5 seconds into anything we purchase, we pierce the veil and see how it's mostly utter garbage. Most of these regulatory institutions became a facade where big corporations get a pass and we pretend they are doing a good job.
Regulators can't ever win this battle. Even if they aren't corrupt, they can't be insulated from the influence of big corporations and they are, and will always be, underfunded because regulation inevitably means less profits. We can't have that, can we?
Supermarkets and this kind of regulation hasn't necessarily stood the test of time. It's hard to say if it will considering how every system that gets built seems to slowly get corrupted or bent in somebody's favor.
Some mushrooms are poisonous. They evolved to protect themselves from being eaten. On the other hand, some plants evolved so their fruit will be eaten and spread their seeds.
And then there are diseases and parasites.
Everything that existed in the past is still being made and is available for purchase. You just have to pay the price. If you are a commoner with a job, your real income is a tiny fraction of what a worker was paid in the past, thanks to inflation. So mass produced garbage is what is available within your budget.
More than half of the working age population in industrialized nations do not work (including many who are employed). A good part of the population have never worked a day in their life and will grow old and die without ever having done anything useful. Everybody else has to pay for their sustenance, and one way is the general decay you see.
But I find that even expensive items are not guaranteed to be of quality. As one example, take luxury cars with defects and horrible build quality from Tesla. The other day we had a whole thread about how bad sofas are today, even the expensive ones. In the service front, I've spent crazy amounts of money on doctors out of pocket after failing to get good answers from the health insurance folks (here it's different compared to the US) and got the same type of incompetence.
Selling mediocre products/services is simply more profitable.
Even if you spend the extra money, the incentive for luxury items is many times to still sell you similarly bad products/services and pocket the difference for even more profit. It's so frustrating.
But it's easier to sell that billionaires should not exist than it is to sell that we shouldn't seek to profit over each other, given how profitable it is for a few and how much some people hopelessly seek wealth.
https://www.dranniesexperiments.com/laundry-experiments/my-l...
Anti-privacy interests are completely aware of this and avoid triggering the viceral response. For example, the spy agencies always give the example of "no-one is listening to your calls" as if the risk of surveillance was the guys transcribing from reel-to-reel tape recordings, not the dossier available to the powerful on each citizen. But the guy listening to our words on the tape is the one we have a viceral response to. Similarly facebook advertising terms (and presumably that of other companies) are careful to ban advertisers from showing the targetting and giving the impression that there is a person at the other end who knows all about you.
I think the upshot of this is that we need to personalise it for the wider public, not just talk about abstracts like privacy. Bring out the fact that your next employer has that data when negotiating your salary. That companies spend thousands of hours figuring out how to manipulate you based on your data. That at the press of a button, the security services could assemble a dossier on you, and make it available to anyone powerful that you have annoyed.
At a minimum, the guy transcribing the tapes is an accomplice to the surveillance effort.
As a society, we desperately need privacy regulations to catch up to the digital age. Legislation will take years (decades?) to catch up, though. In the meantime, as tech industry professionals, we have a responsibility to not be the guy transcribing the tape.
Right now, there's a lot of incentive to be that guy, and good data ethics regulation will remove those incentives from our industry. Until those incentives go away, it's up to us to make good moral choices, even if that means turning down a fat paycheck. How do we, as an industry, self-regulate while legislation catches up?
I guess this is what the shifting baseline argument refers to..
Having said that, I think it's rational for almost all people to not care to give up privacy for all these (addictively) amazing tools. Most people don't do anything worth privacy protecting. Having worked in data/engineering at bigtech, it's not like there's a human on the other side reviewing what each user is doing. For almost all people the data will just be used for boring purposes to build models for better marketing/ads/recommendations. A lot of the models aren't even personalised, the user is just represented by some not-human-readable feature vector that again nobody looks at.
Hell, I have multiple Google Home devices that are always on and listening, and the thing's internal model is so basic and not-personalized that after multiple years it still has trouble parsing me when I say "Play jazz" and "Stop", even though these are the 2 commands I exclusuvely use. Sometimes it starts playing acid rock, and when I say "Stop" it starts reading me stock quotes.
With LLMs looking at all this data if you want to persecute or narrowly propagandize those who are X (X = pro-israel, anti-israel, pro-trump, anti-trump etc) it can be done much better than before. The "humans on the other" side will be using all this data to narrowly find people.
Half of people are pro-Trump, half of people are pro-Isreal/Palestine.
Same with abortion/anti-abortion, guns/anti-gun, and any of thousands of other topics.
Historic attempts to apply that theory have been broad-brush to say the least [0]. With LLMs and access to enough data the authoritarians can get really fine-grained about when they take people out the next time they seize enough power. Anyone attempting to do something politically uncomfortable for the incumbents will be at serious risk in a fine-grained way that has not previously been possible.
> Half of people are pro-Trump, half of people are pro-Isreal/Palestine.
I don't think it is 50-50, more like 20-30% for Trump and I don't have a read on the Israel/Palestine stats. Trump has a dedicated core of supporters but I'd suggest a lot of the people polling for him just don't see a better option.
[0] Eg, I was reading up on https://en.wikipedia.org/wiki/Intelligenzaktion the other day
While polls generally show that roughly half of US voters plan to vote for Trump, that's in the context of only being given the option of Trump or Biden. Most polls I remember seeing since 2016 show roughly 1/3 of the US really consider themselves Trump supporters.
The Israel/Palestine question has similar problems. A binary poll question sets the context that a respondent needs to be on one side or the other, and that supporting or opposing both sides isn't an option. It also puts respondents in a position to have to pick a side regardless of how much or little they may know about the situation. With no more context, a 50:50 split could mean simply that most people don't know enough to decide and randomly pick a side instead.
Start there.
Disagree with this. self hosting email is notoriously difficult. Gotta give the data to somebody. Plus, your work email is either going through MSFT or GOOG, 99% of the time
You can't even ask tech people to make a choice for you because they all say different things.
Other domains like cars, medicine, construction, whatever have established standards because they have recognized that individuals simply _cannot_ make an informed choice, even if they want. I'm eager to say that only information technology likes to call the user "unwilling" and "lazy" instead, but actually individuals from other domains do that too. Luckily, the established standards are mandatory, so their opinion doesn't count.
Yet people do it anyway. It's not an impossible task like you're making out.
You can have DMARC, SPF and DKIM all correctly configured on a clean IP and some mail server at Microsoft will still drop your mails because it's having a hard day and it feels like it.
That place in particular (which I use and can recommend) even have a (permanent?) free tier. ;)
If you're serious about this than go talk to a non-tech person and tell them to self-host email and see how they do. Look at their challenges, build a solution and then offer it.
That's not at all what the conversation is about, and routing through an external place removes a whole bunch of hassle compared to setting up and maintaining outbound email.
You might not like it for some reason, but that's on you.
What's the point? At that stage you've already conceded the deliverability problem so now you're just wasting time administrating dovecot and keeping up with security patches.
Obviously yes. Not sure why you're trying to pretend otherwise.
Good luck with that. ;)
It's one of the big criticisms of Microsoft Recall: the database is locally generated and encrypted at rest, but practically, any user in the same home with device access can probably access it, and bypass any efforts you've made to delete your browsing history or messages.
Remember that abusers are often controlling and suspicious, so disabling Recall, denying them access to your devices, or changing your passwords is enough to set them off because you appear to be hiding something (maybe making plans to leave or report them).
Plausible deniability can be an important feature for activists and regular people alike. You can't always predict when a relationship goes south like this, or get out of it as soon as it does, or afford and hide a burner phone.
One of my friends remarks (edit) that tech companies should have a social worker and a public defender on staff for threat modeling these things.
Is that what is being discussed? The biggest issue with Microsoft's new AI announcement was that their system was going to take screenshots of your computer every second and process them with AI. That means they could have way, way more data about you than LLM prompts.
https://arstechnica.com/ai/2024/06/windows-recall-demands-an...
I'm pretty confident if the NSA or whatever asks MS for those screenshots, they've got a way of making them non-local. The EU is already pushing for mandatory local scanning for CSAM, do you think they wouldn't also extend this to Windows Recall snapshots once the technology is there?
This was like a 3rd or 4th generation one, I think. I was really excited to finally get my hands on one because they were supposed to be really good.
TL;DR it was mediocre-leaning-bad judged as a laptop, and a terrible tablet. I can’t figure out how they got anything but bad press for the things.
Until it isn't, due to future changes or malicious 3rd party managing to make use of bad security decisions & bugs.
There is a reason they give you Free stuff like video, email, chat, search etc.
People have forgotten the only way (in the past) to solve the Info Explosion that results when networks grow, is trying to understand Peoples needs better. That was the intention behind data collection. But ofcourse the story went off the rails when advertisors and marketers and politicians found value in all that data.
But there is an upper bound to how much value there is, just like there is an upper bound to how much milk you can extract from a cow.
Once you build huge ever scaling infra assuming there is no upper bound and then an upper bound is hit, what happens?
Nothing good. Excess cows start getting slaughtered. Larger the system. Greater the over run. More slaughtering. Dont expect what you got for free to stay free. Expect all your data to be sold off at fire sales.
I hear people saying things like that occasionally, and have to wonder... why did you do that to yourself?
And why are you assuming everyone else was similarly unwise?
"Companies like Google" certainly haven't had that kind of info from me, nor from several people I know, as we've avoided the vast majority of their products.
Do you use any search engine? Then yeah, your data is funnelled to google/microsoft.
Which is why I don't have a Google account.
Their search is OK, but their other services aren't that great.
Self host
That may be true, but most people still benefit indirectly from the actions of the few who do have something to hide (e.g. protestors, journalists, whistleblowers).
If we want the masses to continue to benefit from the actions of those few, then we need to find a middle ground. Someplace where the masses are private enough that a truly private individual can hide among them without sticking out like a sore thumb. You don't need to hide, you just need to be able to hide.
Well, but that's sort of the point of the article. You're comparing against a baseline where our privacy is already eroded. If you compare to an earlier (say, pre-web) baseline it's quite different.
I don’t begrudge Microsoft, I think they are a fantastic IT-business partner from an enterprise perspective. They are one of the few tech companies in the world that actually understands how an Enteprise Organisation wants to buy IT and support, and they’ve only ever gotten better at it. As an example, when I worked for a Danish city, someone from Seattle would call us with updates on major incidents hourly. Which is something you can translate to a CTO being capable of telling their organisation that Microsoft is calling them with updates on why “e-mail” isn’t working. So I actually think Microsoft is great from that side of things.
I don’t think we should’ve put all our data into their care. We live in a post Snowden world, and even here in Denmark we recently had a scandal where it was revealed that our government lets NSA spy on every internet point leaving the country. I get that’s the way it is when you’re a pseudo vassal state. We’ve always had our government secrecy regarding the US and Greenland. It also makes me wonder how secret anything we’ve let Microsoft have access at really is.
The issue is how impossible it is to exit Microsoft, and this is where I’m completely onboard with your scary part. We can exit Azure painlessly from the digitalisation perspective, well not financially painless but still. IT-operations will have fun replacing AD/EntraId though, but all our internal software can be moved to a Kubernetes cluster and be ready to accept external authorisation from Keycloak or whatever they have planned to move to.
But where is the alternative to Office365? Anyone on HN could probably mention a bunch, but where is the alternative for people who don’t really “use” computers as such? The employee who basically think a pc “is” Office365. As in we could probably switch their Windows to Linux and they might not notice if they still had Office365.
This is where the EU currently doesn’t really have an answer. We have a strategy to exit Office365, but I’m honestly not sure our business would survive it.
If those plans exist and there is even a tiny chance you can pull that off i'm impressed. In most organizations it would be a almost impossible challenge to even upgrade all their servers to a new OS in a month. I don't think i've ever seen a organization of more than 100 employees that could reasonable migrate their cloud provider, identity source and operating system in a month. Endpoint operating system upgrades often take a year (or more).
https://blog.documentfoundation.org/blog/2024/04/04/german-s...
By contrast my last cohort of masters students worked on things like critical infrastructure, national security, long-term resilience, hybrid interoperability... everything that Microsoft is not and makes worse.
So there's a schism between academic understanding and industrial reality that makes cybersecurity really rather hard to fix.
So I have to walk into a classroom and say:
"Heads-up! We're going to be learning about 365 administration this
week, about Active Directory, and this and that... which are all
okay products and make a lot of admin tasks easier. BUT!! The only
reason is so you can walk into a job. Because this US company has
the UK tech sector by the balls. As soon as you're working, forget
everything you hear in these lectures, because it's dangerous
BigTech mono-culture that's antithetical to the real values of
cybersecurity. Take the principles. Reject the products. Look at
other tools that do the same, Have a backup plan."
And I hope they took enough from Ross Anderson's SecEng book, and from
the BSD/Linux classes and my the other lectures to go out there and
start undoing the harm.This is exactly it. Execs want to sound in charge of situations, even if it's just a person who can be shouted at. Microsoft can employ very expensive, individualised call centre staff in expensive suits to read out to you a service status page.
Sure there is ego, but a lot of C types are frankly good enough to work beyond that part of the equation.
maybe they should have used their skills to have it continously work rather than put up a huge organisational structure ensuring they will give you hourly updates on WHY they screwed up :) but I get it, the government-customers do not care AT ALL about the services to the citizens, rather their objective is cover-my-ass and to provide explanations up the chain
That rationale sounds great (albeit dismissive/invalidating) until something you've done (and have provided ample digital evidence of) becomes illegal or is otherwise used against you.
Oh actually, what's your email password? I mean, since you're not doing anything worth keeping private, right?
You think there isn't a human reviewing the data of what each user is doing, but there absolutely could be, and there's no reason there can't be, like when Tesla employees were viewing and exfiltrating footage/imagery from customers' vehicles. Not just one or two people but apparently disparate _groups_ of employees. https://www.reuters.com/technology/tesla-workers-shared-sens...
A counter-argument: people already do all sorts illegal (misdemeanor?) things every day, tracked by big tech, and nothing happens. Some examples:
• speeding: your smart phone knows what road you're on, what the speed limit is, and that you're over it
• movie piracy: Chrome knows, your OS knows, your ISP knows, your VPN provider knows, any device that is listening can tell you're watching a movie that you shouldn'be able to watch at a non-cinema GPS location
• ..
I'm not sure there is a solution to this problem, unless we accept to lose a lot of features in our products and switch to E2E services.
the only alternative I can think about is some required audit about the measure in place to prevent employees from accessing data, but I'm not sure how effective that would be
I'm not so sure.
Based on the figures I could find for 2021, Google's ad revenue was about $60B with approx 3B users (I asked various chat bots...).
So, if you extrapolated and did some slightly dodgy maths (there were other factors but I can't be arsed typing them) it would cost about $6-$7 per month per user if Google stopped all ads, and by extension, tracking & data mining - This is for Google to maintain their current figures.
Take these figures with a big pinch of salt though...
That $ figure is across the whole of Google. So that is for every single product they have but if you just use Gmail then it might only be $2 a month.
So, if Google wanted to make the same money without tracking, ads etc, they could but the temptation to sell your data and mine it would be strong!
Anyway, my point is that it's possible to do it but would people pay for it? I pay for my email with Fastmail so there is a single data point for you :)
n+2
It’s not about privacy, it’s about having control of your own destiny. Not having some shitty OS maker think they are God in a 1984 world.
This is the warped kind of stuff which happens to companies who join the NSA Prism program… give it a few years and all they care about is power and money and playing spy.
There’s probably an NSA agent rubbing the higher ups at these companies off and telling them they are God as they finish. Or taking them on tours of the office and showing their cool exploding pens and other James Bond tech. Whatever it is, Microsoft is more than just invested.
Recall? Give me a break. That is the most in your face global surveillance tech I have heard of to date.
Eg: was reading recently in WSJ how various insurers are using satellite and drone imagery of customer's roof conditions and using it to deny them coverage. However this has been abused where even brand new roofs have been marked as bad even despite evidence provided and push-back. The insurers were collecting imagery and making decisions but not providing evidence on their end. According to someone working for an insurer they're expecting soon to take images daily for such purposes.
Here various incorrectly affected parties have done nothing illegal/bad/wrong but they're losing control and insight into processes that are affecting them in real ways. These aspects are part of what Daniel Solove outlined in their privacy taxonomy, where they broke down privacy into different things that comprise it (where information collection is distinguished from processing, etc).
> much of the data gathered in computer databases is not particularly sensitive [...] Frequently, though not always, people’s activities would not be inhibited if others knew this information. I suggested a different metaphor to capture the problems – Franz Kafka’s The Trial, which depicts a bureaucracy with inscrutable purposes that uses people’s information to make important decisions about them, yet denies the people the ability to participate in how their information is used.
There are lots of reasons why you don't hand your personal information to everyone, why you wear clothes even though it might be warm enough not to, etc.
But the key point for me, is that knowing you are being watched, or even suspecting it, changes behaviour.
You cannot be you online. You do things differently, edit yourself. It is a form of manipulation. Which was always the point. The panopticon was conceived as the perfect prison to control others.
The reason why people care about privacy is not necessarily because giving up privacy has some directly observable negative effect. But, simply, living without freedom sucks.
I don't want you to know my personal information not because you could/would do something nefarious with it. I don't want you to have it simply because it's none of your business.
The flip side is false positives.
Have a scanned photo from when your grandmother bathed you as a baby? Google may identify it as child porn and shut down your account. https://timesofindia.indiatimes.com/city/ahmedabad/google-la...
"Gujarat high court has issued notice to state govt, Centre and Google India Pvt Ltd after the tech giant blocked an engineer’s account citing “explicit child abuse”. The engineer had uploaded a photo showing his grandmother giving him a bath as a two-year-old."
"... his client could not even access email and his business was suffering. The blocking was like a loss of identity for Shukla, a computer engineer, most of whose business depended on communication through the internet. Shukla had requested Google to restore his account, but in vain."
Are you confident that the state will always be friendly to people like you? How about the people you support politically?
This is blatantly wrong, If i'm a large corporation i can use the information you think is worthless against you via first degree price discrimination and countless other targetted mechanisms. You simply haven't thought about it enough, and as soon as you do, you will realize when no privacy exists people will and have been developing mechanisms to take advantage and capitalize on this state of affairs.
If big data were not lucrative, they could not sell your data. If your data was not valuable Facebook and Google would immediately remove it from their servers without hesitation.
Mantra.
- I don't care about privacy
- I don't care big tech has access to all my data
- I don't care that Google has access all my politicians data
- I don't care I am building a worse future for society
- I don't care that I am being recorded while having sex in Tesla
- I don't care I am building surveillance state
- I don't care that my data are being sold to China, to India, to wherever highest bidder lives
- I don't care how my data are being used. I don't care if my data are being used to train military robot dogs that will be used for wars
- I don't care that I will not receive insurance because my medical data are sold wherever
- I don't care about privacy
- I don't care about privacy
- I don't care about privacy
Now literally everything you do is captured, repackaged and sold. Corporations also are more creative when it comes to selling your data. They have more data, they sell more.
Every drama is adding more to the privacy nightmare.
Sorry, but you cannot say that "nope nothing has changed for privacy in last 10 years".
No wonder you don't care too much about privacy, but this is not normal for everyone.
I can only describe this take as disgusting. Saying you don't care about privacy because you have nothing to hide is like saying you don't care about freedom of speech because you have nothing to say.
Privacy is a fundamental pillar of society, for without privacy there is no freedom. We already see the chilling effects across many situations, we have seen them for the past decade+ at least. It's only the beginning.
Absolutely, its very rare for people to have things Like passwords, bank accounts, confidential documents, secrets, fears, weaknesses.
And as we know, everyone applies good infosec practices, none of us have a txt file sitting in a folder with all our passwords.
So on average, there isnt a growing collection of confidential data that our models are getting trained on.
Matter of fact, if everyone who reads this were to randomly start loudly talking about “EAR-WAX REMOVAL” or “LOW LIBIDO”, in close proximity to a friend’s phone or Smart TV, theres no impact. They dont end up seeing some interesting and potentially embarrassing ads.
It’s not like we live in a world where bad actors exist, maybe in some distant country, who try and take resources away.
——-
EDIT: I came back to edit this because I felt I was perhaps too snarky and as a result having fun at expense to your argument.
For what you said - it should be understood that it is easy to end up in a situation where privacy or PII is converted into a “problem” which has to be minimized.
This is a position that then leads to many other far too complex failure states.
Our future selves are better served by thinking of data we generate, as default private, and that all private data is “heavy”
Do you feel the same way about TikTok?
Except for people whose employer does not approve of their politics, or whose family does not approve of their religion, or whose community does not approve of their sexuality, or whistleblowers, or journalists, or people who support causes the government disapproves of, or........
That covers an awful lot of people.
Pretty much anyone living in, or with any links to anyone living in an authoritarian state too.
One of the worst takes I've ever read. There is something called metadata. Even if you don't do anything that is worth protecting explicitely, the data about your 'worthless data' enables perpetrators to see the patterns of your daily life. You can reconstruct so much by just gathering metadata over a certain time span, knowing when someone usually interacts with devices, social media etc.
I don't want everybody to be able to derive when I'm sleeping, going to work or when I'm going on vacation. Hopefully, it is obvious to you that even a simple thief could use such information (if leaked) to know when it is the best time to go on a heist in your aparment.
There is a nice 3c presentation by David Kriesel called SpiegelMining available on YouTube. It is in German, but the autogenerated subtitles are good enough to understand everything. He downloaded Spiegel Online newspaper articles over a certain period of time and was able to derive lots of information about the authors based on the article's metadata (publishing timestamps, author initials etc.)
I won't disclose why Russian government considers me a part of three different terrorist groups. But they also tried to call people who watched anime a terrorist organization. And they tried that at least 3 times in last ten years. Sooner or later they will succeed.
Also, wasn't there a recent problem in USA where women were uninstalling period tracking software, because it could report someone as pregnant for having irregular period? I know at least 4 causes for missed period, do judges know that much?
We don't protect our privacy because we are imperfect, we do it because assholes and|or stupid people exist. It's like a middle school. You might not be ashamed of having a crush, but you wouldn't tell everyone who they are, because some of our classmates are assholes that would care too much
There was a celebrity infidelity scandal in Japan where such app was allegedly involved too.
Bringing back the same argument in favor of protecting privacy:
"Saying you don't care about privacy protection because you have nothing to hide it's the same as saying you don't care about protecting free speech because you have nothing interesting to say"
I killed my social media accounts because I disagree with my pictures being used for training AI models. My friends, who aren't tech savvy people, keep mocking me for caring about it, and when I confront them about big tech knowing much more about our private lives than ourselves, they simply respond "well, I don't care anyways, it won't make a difference in my life".
How many clients has my team helped when it was just too late? Many if not most.
One fundamental flaw humans have is not to care until it's too late.
Why should I care about my gutters? Until the day the basement is filled with water because of these "ridiculous" gutters...
Also, lots of people use other email services than Gmail, don't share their location information, don't share their photo roll nor share their internet history with Google. And a lot of video viewing is obviously not done on YouTube.
How do we know this? They may claim this, however their incentives as an advertising company would provide strong pressure against this.
This is true of many fundamental rights. Most people don't say anything worth speech protecting either. The catch is that when you do need to say something worth saying or do something worth privacy protecting if the right wasn't there all along you're kind of screwed.
You say that like it's a mundane and acceptable use, but this is the primary thing I want to avoid my data being used for, and is a huge part of why I get very concerned over privacy issues.
There doesn't need to be a human inspecting stuff, just a computer doing the filtering and reacting to it. The example that the article is using is already mentioning that they found the nefarious purpose. Given the current trend of politics, notably in the US, its not far-fetch to draw a future where searching for things like, say, abortion, becomes illegal, and tech companies get coerced into sharing that kind of information.
The fact that MSFT found that co-pilot was being used by hackers suggests that they already have the entire set of tools to already do that.
This is the weakest of the privacy arguments to me. If we are in the "evil government" hypothetical future, why do they need my real searches? They can just as easily lie, make something up, use some other piece of data to persecute who they want, or do away with all of that pretense because they don't need it.
Define "worth." Is a poor person's social security number not "worth protecting" because they don't any money to their name? What about the strife this would cause them? Is there not innate worth to that person's personal data simply by virtue of them being a person?
No one "opted in" the removal of 3.5mm plugs on phones. Companies unilaterally decided on that and there exist very few phones today that sell them. While consumers can share some of the blame put the blame squarely where it belongs on the big tech companies.
speak for yourself
> Hell, I have multiple Google Home devices that are always on and listening
yeah, doesnt mean everyone has
Big tech is a bit like tobacco companies at some point - we’ve convinced people and ourselves that certain things are good, even healthy while they’re actually the opposite.
We, the people who build and maintain these services, are in a position to offer pushback to ensure the humans and their privacy is higher than any other concerns.
Speak for yourself. Most people in tech do not work for Google or Microsoft. Working in tech alone doesn't give you some kind of power to offer pushback in these tech companies, just like being a random worker in the agriculture sector doesn't give you power to offer pushback against the tobacco companies.
“The boss” often doesn’t know or care about the implication of involving data brokers. We’re not just code monkeys.
But how common is that choice?
The choice is something that everyone has, and people (tech and non-tech) exercise that choice every day. Usually, though, it's people refusing to use one Big Tech service in favor of a different one: look how many younger people now don't use Facebook, but instead use TikTok.
unfortunately most engineers I've seen (i come from an engineering background) care mostly about technical stuff and lack the EQ to see the bigger picture.
Most engineers are engineers, not company politicians. That doesn’t mean they don’t see the greater picture, it’s just not worth it dealing with corporate bullshit (or even endangering).
So, a Hollywood-style strike with the aim to do so?
Now, apps and services are integrating AI like crazy, penetrating just about every type of information, and much of these integrations are sending data to OpenAI, voluntarily. People are sending their private thoughts to OpenAI as they brainstorm, as they write, before fully fledged ideas are even formed. NSA must be enjoying this transparency now.
But as for infinite data and definitely smart enough people to have ten SOTA LLMs in flight?
I don’t think TAO/EG needs any help from fucking Microsoft.
The disclosures of Snowden should have brought about profound change in this entire debate (> 10 years ago).
Instead he is a refugee with not much more to do than to shill crypto.
But it's too late. The frame shift is too great for most people. Getting people to care about this let alone vote in a manner that would cause actual change is so far out I have a better chance of winning the lottery.
I don't know what to do other than to support and educate where I can.
I do hope I'm wrong.
But the Impossible Burger did more than talking ever did
Government tried antitrust for decades w telcos
But the costs of long distance calls dropped to practically zero when open VoIP protocols came out
The Web disrupted AOL, MSN, CompuServe, TV, Newspapers, Magazines etc.
Wikipedia disrupted Britannica and Encarta
The answer: open source must get good enough that people can switch from big tech corporation-controlled solutions and then they will be in control of their own software !! :)
A basic cloud host that can take care of a whole family can be had for $5/mo. Perhaps that's still too much for your exemplar poor to spend on a hope. But the amount extracted by the surveillance industry is always increasing, and eventually that levee will break.
I'd say there are much bigger impediments - needing to invest time for setup, needing trust a given solution won't turn out to be a lemon or even backfire, and lack of straightforward packageable solutions to many of the technical problems.
I agree with you. Time poor is a definite problem, even (or especially) among people that aren't money poor, and it comes with its own Vimes's Boots analogy. For example, the many articles we read here about the centralized service of the week creating some kind of problem for their users, which could have been dodged with a little outlay of time to make better tech choices in the first place.
Given that, who's more likely to look into free alternatives to apparently free services online? The middle-class person with a spouse that works part time and takes care of many of the chores and that pays for a handyman or contractor or repair man to fix appliances and household problems or the poor person that works full time, their spouse works full time, and when they're done working they're busy doing the chores that life requires because paying someone else is not feasible for them?
Time is money, and the working poor have neither.
The point isn't to discount anyone's struggle, but rather to look at the actual mechanisms that hinder adoption of libre software. And apart from some relatively affordable table stakes, I don't think the financial cost is really one of those. The attention cost of self-actualizing and the ambiguity of using a non-advertised solution are though.
It's not that they're paying for all of them, but that they have the option of paying for them and I would hazard that a good portion of middle class families with both parents fully employed opt for offloading at least some of that some of the time if they live in a portion of the country where middle class means you actually have disposable income. E.g. many people pay for larger landscaping projects, or hire a handyman to do cleanup around the outside of the house or even might have a maid come in once a month. This might be less common now that the middle class has eroded to some degree, but I think that's a problem of a shrinking middle class, not of those being things the middle class doesn't do.
> And apart from some relatively affordable table stakes, I don't think the financial cost is really one of those.
I'm not sure I agree with that. Having spare hardware to run something, a stable place to put it, and paying the power for it (a minor but increasing cost) all play a part.
> The attention cost of self-actualizing and the ambiguity of using a non-advertised solution are though.
I agree, and I think the working poor have less attention to spare because of less free time, but also that they generally have more and larger worries that make this problem seem insignificant by comparison. If your major worried are making rent, having enough money for food, repairing your car so you can effectively get to work and take kids to school, spend quality time with your family, and set up a solution so that your privacy is protected from companies that want to monetize you, which one will get the least attention? Middle class families probably have at least one less of those concerns, and every major concern that's more important than using free software to avoid a small but persistent exploitation is something that competes for attention.
Sure, all of those dynamics may be slightly harsher if you're financially poor. But it's not like once someone reaches "not poor", time for self-actualization abounds. And from the other perspective, it's not like libre software is not taking off merely because the lack of adoption by poorer people. So what is your actual point from tying the topics together?
Well, part of it was that a sibling reply[1] was already present, and the idea that "oh, we can all just run our own AI models at home" seemed ludicrously costly in both money, and time to me. It's not that I was trying to shoehorn it in as much as juxtapose it against what was already being stated.
> But it's not like once someone reaches "not poor", time for self-actualization abounds.
I have no idea why you you are interpreting the inverse of my statement that being poor makes this harder to mean that not being poor makes it easy or trivial, which is how it appears to me you're interpreting my statements.
Privacy is hard in the current climate. It takes time and effort or money to alleviate some of the privacy concerns, to different degrees depending on the specific concern. Those are all things the working poor have less of than other economic groups, so solutions that require them will likely be less used by them. That doesn't mean don't offer them, but we should keep that in mind when advocating for people switching to open source solutions, so we make sure the solutions actually solve the needs of the people intended to use them, and not just the needs of a subset of those people.
It would be a real shame if what I think is one of if not the best option for solving this problem in an egalitarian way failed to take into account the needs of that economic group and we actaully ended up with a solution that many are protected by, but disproportionally not the poor for multiple reasons. A world where 90% of people out of poverty are protected in some manner but only 50% of people in poverty are isn't necessarily better IMO, and may actually be much worse, since I'm not sure there will be much incentive to fix it at that point.
No, I wasn't very clear in my initial comment (and wasn't really going this deep), I just wanted people to consider that running your own LLM for your own needs isn't really feasible for most people and in a more general way than a reply to that person specifically might have communicated, and I was slightly inebriated when I wrote it, so didn't think it warranted much explanation.
The web is “open”. But Google and to a lesser extent Apple control the browsers to access it and they can control the platforms.
Meet the new boss…
Ben Thompson talks about “Aggregation theory” all of the time. The companies that have the power have that power because that’s where the users are.
How do you compete with “free with advertising”?
We talk about how the web killed TV networks. But streaming services are making deals with cable companies to bundle their ad supported tier with regular TV and with their internet only packages. Oh and the largest cable company owns NBC.
When “cord cutters” get rid of pay TV and use YouTube TV where most of the money still goes back to the same providers - how is this any different?
TBH, nah, I don't believe the impossible burger has really done anything truly notable, as far as vegan causes go.
Now, if you were to end beef subsidies leading to something like 25% of beef farms changing over to a more vegan friendly or environmentally friendly alternative uses, or developed protein alternatives that reduced food costs for the average person, then yeah.
Impossible Burger isn't a bad product, but as far as the big picture goes, it's a slightly tastier virtue signal than black bean burgers.
I think many people here on hackernews live in a bubble and just don't understand what is an average human being. They surround themselves with like-minded tech savvy individuals and fail to comprehend how there isn't stronger support for privacy.
Plenty of us understand, but it's depressing and usually trying to explain to others that have a rosier view of how people will react feels a lot like trying to get the people themselves to care, which is to say it's hard, thankless, and depressing, so few people bother.
I don’t even browse in “private mode.” Not because I don’t care, but because I assume it won’t really change anything.
My experience is that people not only do not care about privacy but look at people who care about privacy as having something to hide or paranoid about something that simply doesn't matter.
What's the alternative anyway? Give up and suck Google's tit every day? It's "fine" if people who don't have the background to understand this issue do so. But if you, having the background and belief to object to such corporate control still choose to look away and do so, then you have willingly demoted yourself to a pathetic Google tit sucker.
It's the same reason why it's taken decades to take serious action against climate change. It's only in recent years with extreme weather events and record breaking temperatures that people are finally starting to care because they're finally experiencing the negative effects of climate change. But only to a certain extent, you're still not going to see many people trading in their vehicles for ebikes anytime soon.
and create apps to scan all your receipts, your retinas and then track your movements and sell the data to the highest and the lowest bidder in exchange for a slightly newer Maserati.
i mean its not too complicated to get to a desired privacy standard for the most part so it seems like the privacy conscious in general get angry for other people, who dont even care.
its because of those people that we can even use these products for free. i mean they arent making ad revenue off of us....
Many times, I’ll discuss the issue with less tech literate people and when they learn all the spying that’s going on, they feel really bothered by it, but not empowered enough to do anything about.
IMO it’s a bit like organic, unprocessed and local food. My personal experience is that I only started caring about it after really learning about agriculture.
The capacity for the current crop of privacy advocates to make a cogent case it lacking. Peoples’ capacity to recognise and rearrange themselves in defence of a novel threat is not. If anything, our present malaise is one of allergic reactions to phantom threats.
Yet the two major topical events one could easily point to escape you.
Sure, as with you the trend line.
Your wit would be stronger with substance. Which events do you cite, and how?
It would be wasted on you, as you are clearly acting dishonestly.
At least in the EU (I'm told) they are required by law keep logs to ensure that their AI services are not being used to do bad.
I'm glad that their system worked.
[1] https://learn.microsoft.com/en-us/legal/cognitive-services/o...
[1] https://learn.microsoft.com/en-us/azure/ai-services/openai/c...
[2] https://customervoice.microsoft.com/Pages/ResponsePage.aspx?...
And, no, burying it in the ToS isn't being "very open" either. "Very open" would be putting a big visible banner on every page of the UI.
... and the abuse still wouldn't be acceptable even if Microsoft actually were being forthcoming about it.
Did this violate the legal definition of an "expectation of privacy"?
In most WIPO countries, you can't legally record other peoples conversations unless both parties give you prior consent (hence the quality assurance disclaimer on phone services.) Single-party-consent does not mean what most people think it means, and has launched many lawsuits.
I usually recommend this list after a windows 11 "offline" install:
https://github.com/StellarSand/privacy-settings/blob/main/Pr...
They sure don't make it easy to un-dork your PC for sure, but it works if you need to run the OS for that one legacy application that people refused to port to Mac/Linux.
Good luck, and make sure to sue them in a jury trial... They won't change their behavior unless there are fiscal disincentives. =)
Forget these legal grey areas. These organizations actively deal with corporate espionage and no one does anything about it.
I was working on a specific thing in university so without illegally probing my devices they probably wouldn’t have found a good job match.
The related item was on my Linux laptop though. So extremely illegal regardless.
You can see if it happens, because after your first two comments (always exactly two) you can go to your profile page in a logged-out browser and get a 404. This is a standard Reddit shadow-ban.
An easy way to demonstrate it is to create an account via Tor Browser, without a verified email address.
Even *if* that happened, as long as you provide nothing tangible, you should keep that for yourself.
It's turning into a total disaster.
And there are viable options these days...
It's a pretty smooth experience for me these days; it can run all the software I need, is easy to keep up to date and works great on most hardware.
I am not a big fan of advertising because its purpose is to manipulate thoughts. But I also like the idea of having a less formal form of paying for services. So, having ad-driven businesses should be okay as long as the thought manipulation machines have limits.
However, modern ad targeting has become so sophisticated and powerful that it creates problems on a global level (remember Cambridge Analytica). All the big ad companies have to play the targeting game because the others will eat their lunch if they don't.
If we want to protect users from ad companies' total exploitation, we need regulation. And if the rules change for all the players equally, it should stay a fair game.
That doesn't mean it should be the norm though. If enough people actually care about their privacy there is the possibility for cheap, privacy invasive and expensive, privacy respecting products to live in the market.
Shameless plug: I launched Cognos[0] a few days ago that encrypts your AI Prompts and Outputs. No risk of leaks/hacks/being used for training.
If you like generative AI but are worried about putting all your data into ChatGPT and don't know how/want to run inference infrastructure yourself it could be something for you.
> Sending a message involves transmitting the message to the server in plaintext over TLS encrypted connections. Your plaintext message is encrypted with the conversation public key and saved before being forward to your AI model of choice, again in plaintext over an TLS encrypted connection. When the AI model has generated a response, this is returned to our server. This response is also encrypted with the conversation public key and saved before being forwarded back to you.
The model operator still gets everything, just not trivially traced back to the user and not collected in one place; in addition you get everything and there’s no way to verify you’re not inspecting and/or storing clear text user info, or hacked to do so. It’s basically a pinky promise from an unknown entity (no offense but you can see that from the user point of view) whose main value proposition is that pinky promise.
Yes I try to make it as obvious as possible that this is not end-to-end encrypted. Using provider APIs over their products (e.g. ChatGPT) does already offer some privacy benefits and I do give the user transparent choice over where to send their prompt.
But I am (currently) an unknown entity. How could I improve my offering to build up that trust?
I'm happy to even have a video call to answer any questions if that would help :) I see myself as offering a similar service to ProtonMail so perhaps I also need to look at how they built up trust in the early days too.
> How could I improve my offering to build up that trust?
I don’t know, it’s a hard bootstrap problem. With ProntonMail, even if the privacy promise isn’t upheld, at least they’re another email provider, and ProtonMail to ProtonMail emails probably doesn’t end up with Google, so it could still be slightly better. Here your service is a middle man, so if the privacy promise isn’t upheld it’s sort of strictly worse.
Maybe you can play up the multi-provider aspect? But that market has fierce competition from existing, often deep-pocketed alternatives, e.g. Quora’s Poe. They’re more convenient too since they don’t try to be private.
With this MVP I wanted to see if there was demand for something where privacy and encryption were enough of a USP to attract some early adopters. Maybe to also cross that hurdle I need to go fully transparent and open-source as well so that those with the technical knowledge can verify themselves that I am doing what I say I'm doing.
I'll also write up a long-form article with more details on the security and the encryption.
Mid-to-long term (and if there was demand) I could also get security audited & certified and hopefully build an increasingly trustful relationship.
Side note - somebody else replied to me drawing my attention to DuckDuckGo also releasing a Beta AI chat recently. It offers no storage, client or server, so if you refresh the page your chats are gone. I would imagine they are also testing the market for something like this.
the linked sources don't really talk about any kind of user activity logging.
i suppose the point stands though: modern tech is kinda like 70s and 80s wingnut nightmares come true. the tv actually does watch you now, and when you read something in the standard way, detailed information about your demographics and behavior are shared and then stored within milliseconds across tens of parties.
how many entities with an ein get notified when you read that ieee spectrum article? too many!
User-community owned services/infrastructure could reasonably be the way towards services that run well, recoup costs and prevent abuses (both of the service and of users). Are there any examples of this kind of thing for AI yet?
A very nothing article. It amazes me people think some private company owes them anything like privacy or free speech. That’s not how that relationship works. It’s an exchange relationship. Transactional. Not an ethical relationship. The only motivation for ethics here is PR. That’s the best you can do.
A lot of people care, enough that Apple thinks running major ad campaigns on the issue will move the needle
I mean, no successful computer system is sold based on just one single feature. So, I suppose skimping on this particular feature out wouldn’t kill Apple. But I think they’ve identified somewhere where they have a fundamental advantage where their main competition, Google, an ad company, has trouble responding.
> The most important thing in their ads isn't exactly what they're touting (privacy features), but that they're keeping themselves in peoples' minds and making them feel good somehow.
I don’t really see the difference… I mean, making people feel good about their products and buy them is the intended outcome of most companies’ moves. The features are how they so that. They can’t be ranked in terms of importance, one is the goal, the other is the means.
No, they really aren't. Only technical people would think such a thing; obviously, you don't work in marketing. What's important is the emotional response people have to an advertisement. Watch TV ads sometime, and see how many tout specific features, vs. how many just have a feel-good message. Sure, they might throw in a few words about some features here and there if you're listening, but the real message is the emotional feeling you'll have by owning that product, which they show you with smiling, happy people using it.
Great for ad campaigns, but when push comes to shove it always becomes a secondary or tertiary concern.
Privacy International: https://privacyinternational.org/
IAPP (International Association of Privacy Professionals): https://iapp.org/
noyb: https://noyb.eu/en
Purism: https://puri.sm/
Proton: https://proton.me
Murena: https://murena.com/
etc. etc.
1990's: we all wanted the Internet
2000's: we all wanted social networks
2010's: we all wanted mobile devices
2020's: we just want to get rid of shitty search and AI surveillance
I wish there would be an incentive for vendors to ship with Linux.
...aaand as usual mr tech commentator was right up until this point. There doesn't need to be a balance. People are always talking about "balance". What balance? TV/radio didn't spy on you to operate a profitable business in the broadcast days. I can do anything on an Amiga computer with probably not bad UI compared to the latest versions of Windows, and it will never have to phone home for anything. This opinion itself, ironically, is just a shifting baseline. You are talking about "balance" (translation: compromises) because the 3 maintained pieces of software for your domain (such as camera in your house) are by two scum corporations and the 3rd is some garbage quality open source software. Nothing stops someone from making actual good software/hardware, closed or open.
Both programs are a terrible invasion of privacy installed in all of their computers, but the backlash against Microsoft seems much larger than the one against Apple.
Additionally, you can and should encrypt your data which Apple allows to do using FileVault.
Again, the encryption key never even reaches Apple‘s servers except if you use the iCloud Keychain. And even if you do and you store your key there, Apple wouldn’t have the key for your iCloud Keychain and thus couldn’t do anything with that data.
Microsoft is not breaking new ground in killing your privacy. Customers already don't know or don't care that $bigcorp is watching everything you do and choose to give them all their data.
I like to use Proton Mail even though other options have more features and convenience. I strongly favor running LLMs locally using Ollama, even though APIs like those from Groq, Mistral, OpenAI, etc. are more convenient if I have an Internet connection. I enjoy and find Duckduckgo useful and pleasant to use, but Google and Bing are flashier. I also run in Apple’s Lockdown mode, and prefer private browser tabs even though there is a delay getting auto-logged in.
If you have time it is well worth books like Privacy is Power and Surveillance Capitalism.
I don’t advise non-technical friends and family to go down the privacy rabbit hole, but I personally choose to do so.
the same ideas was brought forward when windows 10 launched with cortana and telemetry. or during snowden/wiki leaks.
yet again you often have only a small section of the audience that really tries to make an effort.
to me it all boils down to what we are getting in return. despite search issues, i will not find it in me to pay for search. same way, since others use the known email providers anyway, why bother paying for having your end of messages private?
web3 came and left (imho). unless we have an ergonomic way about this, while battling the big tech like filing taxes is in the US, we will have this conversation in another milestone.
Nobody Cares
(at least 95% does not)
We can say M$ tried to fight the spy-system (you can see that with the scroogled campaign) but learnt that - say - 95% didn't care...
so why couldn't they get rich as Google and Facebook was getting?!?!
Problem solved!
everyone is eating what they ordered.
Bon Appetite
800 upvotes, though. Huh?
Next round is AI killer robots and It's already happening with AI people. After it's done, each engineer will worth at least $10Million and we will have great killing robots choosing people based on algos.It will be algo that kill people and not them for sure. :) Can't wait that future. Great dystopia here we build. Thank you AI people too.
step 2 - blame something vaguely coherent
step 3 - ?????
step 4 - profit
The modern idea of standas is, a ridiculous imposition that only benefits a little group of people
Edit: in fact, before widespread TLS practically everybody could see them…
Calling this espionage is just a misuse of language because espionage is done with malicious and intent and without knowledge of the subject.
There's never a real argument in these articles about privacy that addresses the fact that most users, not because they're all trapped in some false consciousness, accept tools that give them some safety in exchange for privacy. If you ask people, do you want Microsoft to scan your stuff if it finds some malware most will just say yes. None of this is a scandal to the majority of users. Which is why there's never any outrage.
And COINTELPRO and MKULTRA were supposedly for the good of the country/public.
Always be skeptical of anything being justified as ‘for the greater good’.
Espionage against citizens in violation of the constitution is immoral, but spying on other countries is fair game. It’s a huge part of U.S. military dominance.
And was done by the CIA.
And while in hindsight it was pretty dubious if it was going to be effective, given the mindset and knowledge of the time? Plausible.
It fits under the umbrella of dirty tricks well enough to hang it at the feet of espionage to me. It was certainly gov’t sanctioned (by some definition). What else are we going to call it? ‘Frat boys misbehaving’ doesn’t give it the proper weight.
State-based intelligence is not "malicious", and so you are misusing language yourself. State-based intelligence can be roughly divided into three sectors: Civilian, military and counter-terrorism. In peacetime, strategic civilian intelligence is by far the biggest, and is used to back trade agreements, various political decisions and so on. It's simply about preserving the country's interests.
With "malicious" out of the way: Most technological espionage is absolutely done with intent and without the knowledge or at least informed understanding of most subjects.
... and damage the interests of those being spied on. Which is the whole reason they didn't just offer up the information to begin with.
If I steal your car to "preserve my interests", it's still malicious.
A whole lot of "modern technology" has been deliberately architected to "need" more sharing than is actually necessary to achieve its function.