FTC: Vast Surveillance of Users by Social Media and Video Streaming Companies
ftc.gov
ftc.gov
It is insane to me that I can be notified via physical mail of months old data breaches, some of which contained my Social Security number, and that my only recourse is to set credit freezes from multiple credit bureaus.
It's like if you go to an AirBNB and the owner sneaks in at night and takes photos of you sleeping naked and keeps those photos in a folder on his bookshelf. Would you be okay with that? If you're not directly harmed, what liability would they have?
Personal data should be radioactive. Any company retaining it better have a damn good reason, and if not then their company should be burned to the ground and the owners clapped in irons. And before anyone asks, "personalized advertisements" is not a good reason.
If the answer to them ends up being "Well, it's illegal to take non-consensual nudie pictures.", then my follow-up question is "So, why isn't the failure to protect my personal information also illegal?".
To be perfectly clear, I do believe that the scenario kibwen describes SHOULD be illegal. But I ALSO believe that it should be SUPER illegal for a company to fail to secure data that it has on me. Regardless of whether they are retaining that information because there is literally no way they could provide me with the service I'm paying them for without it, or if they're only retaining that information in the hopes of making a few pennies off of it by selling it to data brokers or whoever, they should have a VERY SERIOUS legal obligation to keep that information safe and secure.
Just want to point out that the company is usually also doing what it can to get other information about you without your consent based on other information it has about you. It's a lot closer to the "taking non-consensual nudie pictures" than "fail to secure data" makes it sound.
Sure. In those cases, there are damages and that creates liability. I'm not sure what damages I've ever faced from any leak of e.g. my SSN.
The problem here is because of all these little data leaks you as an individual now bear a cost ensuring that others out there are not using your identity and if it happens you have to clean up the mess by pleading it wasn't you in the first place.
It's not like there's a "conservation of blame" law.
I think a better example would be You (AirBnB Host) rent a house to Person and Person loses the house key. Later on (perhaps many years later), You are robbed. Does Person have liability for the robbery?
Of course it also gets really muddy because you'll have renting the house out for those years and during that time many people will have lost keys. So does liability get divided? Is it the most recent lost key?
Personally, I think it should just be some statutory damages of probably a very small amount per piece of data.
It's kind of like the idea of robbing a minute from someone's life. It's not every much to an individual, but across large populations it's a massive theft.
Right now they probably get some near free rate to offer you credit monitoring and dgaf.
This is not a direct analogue, a closer analogy would be when the guest creates a copy of the key (why?) without my direct consent (signing a 2138 page "user agreement" doesn't count) and at some later point when I am no longer renting to them, loses the key.
Just the Robber? Or are any of the key-copiers (instead of losers w/e) also?
What I will say is the guy that has copies of 20000 people's keys should get in trouble if he loses his horde.
1. I have no control over what was stored 2. I have no control over where the storage is
The liability in this case is the homeowner/host, as you should have and had full ability to change out the locks.
To make it more similar, I think you'd need one of the guests to have taken some amount of art off the wall, and brought it to a storage unit, and then the art later was stolen from the storage unit, and you don't have access to the storage unit.
It's not as good as the naked pictures example because what's been taken is copies of something sensitive, not the whole thing
this is outrageously incorrect analogy.. you ASSUME property ownership in the first statement. Where are personal legal records analogous to owned property? by whom?
The good reason is growth. Our AI sector is based on, in large part, the fruits of these data. Maybe it's all baloney, I don't know. But those are jobs, investment and taxes that e.g. Europe has skipped out on that America and China are capitalising on.
My point, by the way, isn't pro surveillance. I enjoy my privacy. But blanket labelling personal data as radioactive doesn't seem to have any benefit to it outside emotional comfort. Instead, we need to do a better job of specifying which data are harmful to accumulate and why. SSNs are obviously not an issue. Data that can be used to target e.g. election misinformation are.
No, I'm saying it's a common with a benefit to utilisation. A lot of discussions around data involve zealouts on both sides. (One claiming it's the god-given right to harvest everyone's personal information. The other acting like it's the crime of the century for their email address to be leaked.)
Most people here have thought more about the the topic of privacy in the modern era far more than what some 70 year old politician has.
I think both of those are debatable.
It's better to to think of it in terms of prevention. This fits into a category of things where we know they create a disproportionate risk of harm, and we therefore decide that the behavior just shouldn't be allowed in the first place. This is why there are building codes that don't allow certain ways of doing the plumbing that tend to lead to increased risk of raw sewage flowing into living spaces. The point isn't to punish people for getting poop water all over someone's nice clean carpet; the point is to keep the poop water from soaking the carpet in the first place.
People from less dense areas generally saw this as draconian nanny state absurdity. People who had spent time living in dense urban areas with high rise residential buildings, on the other hand, were more likely to think, "Yeah, duh, this rule makes perfect sense."
Similarly, I've noticed that my fellow data scientists are MUCH less likely to have social media accounts. I'd like to think it's because we are more likely to understand the kinds of harm that are possible with this kind of data collection, and just how irreparable that harm can be.
Perhaps Americans are less likely to support Europe-style privacy rules than Europeans are because Americans are less likely than Europeans to know people who saw first-hand some of what was happening in Europe in the 20th century.
An able bodied person can fully make complaints against any business that fails their Americans with Disabilities Act obligation. In fact these complaints by able bodied well-doers is the de facto enforcement mechanism even though these people can never suffer damage from that failure.
The answer is simply to legislate the liability into existence.
Lack of liability is screwing up the incentive structure.
Section 230? Is it the platform or the originating user that's liable?
Protection of personal data? Is there a standard of care beyond which liability lapses (e.g. a nation state supply chain attack exfiltrates encrypted data and keys are broken due to novel quantum attack)?
Minors viewing porn? Is it the parents, the ISP, the distributor, or the creator that's liable?
I'm not here to argue specific answers, just saying that everyone will agree liability would fix this, and few will agree on who should be liable for what.
It might be solvable with some kind of ID escrow, where an independent international agency managed ID as a not-for-profit service. Users would have a unique biometrically-tagged ID, ID confirmation would be handled by the agency, ID and user behaviour tracking would be disallowed by default and only allowed under strictly monitored conditions, and law enforcement requests would go through strict vetting.
It's not hard to see why that will never happen in today's world.
Lawnmower manufacturers said the same thing about making safe lawnmowers. Until government regulations forced them to
Specifically, 1970.
One of the reasons it's so expensive to build a house is safety regulations. They exist for a reason, but they nevertheless add a substantial cost to building a house. If you had mandated such a cost to people living in 1870 then a lot fewer people could've afforded a house.
Just about every regulation that exists for every product or thing or way of doing something was written not even after a death, that's usually not enough, it needs to be a substantial number of deaths that can be directly linked to the thing the regulation covers and only then does it become law.
It still adds an enormous amount of cost. Despite that buildings (and even bridges) still collapse. What is often not asked is how many people lack housing because those building codes made it unaffordable for them.
Or... maybe that line of reasoning isn't super strong.
But my point was that you asserted that regulations can overcome claims of impossibility. I was just illustrating that is not always true, and therefore we can't assume it is true here.
There absolutely should be, especially for personal data collected and stored without the express written consent of those being surveilled. They should have to get people to sign off on the risks of having their personal data collected and stored, be legally prevented from collecting and storing the personal data of people who haven't consented and/or be liable for any leaking or unlawful sharing/selling of this data.
So me trying to do the right thing, am now scrambling for work, while the offender pretends nothing happened while potentially violating the entire customer base, and will likely suffer no penalty unless I report it to PCI, which I would get no reward for.
Why is it everywhere I go management is always doing shady stuff. I just want to do linuxy/datacentery things for someone who's honest... /cry
My mega side project isn't close enough to do a premature launch yet. Despite my entire plan being to forgo VC/investors, I'm now considering compromising.
I agree with this statement.
This isn't a judgement, we all have to make choices; the "right" choice (the one that aligns with integrity) is usually the one that will be the least self-serving and even temporarily harmful. They did what was right for them, that's okay, but it was not the choice of integrity.
How it plays out after is another matter entirely. But the choice was what they seemed to think was right, for them, at the time. Thus it was the right choice for them. It doesn't mean it was the right choice in terms of integrity, or the right choice for me, or you or anyone whose data got caught up in it. Nor was it right choice in receiving a paycheck the next week.
But the way it was explained, it doesn't seem like they went out of their way to pick a "wrong" choice, specifically. They picked what they felt was the right one, for them, at that time. There were less ethical options to choose as well, and those were not picked either.
You appear to be talking about the external consequences of choices, while I am talking about them making a choice based on what they believed was the inner rightness of their choice. They did not want to be associated with a company like that, so they made the choice to not be -- because it aligned with their inner knowing of not wanting to be a part of that company. The right or wrongness in terms of external consequences is not what makes the choice, right or wrong -- for them
Again, I am talking about -- them -- not anyone one else or what anyone else thinks of it outside of them. I am not talking about "inner rightness" in general, I am talking "what they believed was the inner rightness of their choice" -- Their inner rightness. You seem to be talking about what -- you and/or others -- may believe from an outside perspective. My outside perspective is they made the choice that did not align with integrity. But that does not mean that was not the right choice for them.
And again, they made the right choice, for them -- at that time. How that plays out after is neither here nor there and in your labeling it a "bad" choice for them is akin to saying that they have no real agency over their choices, and we outside of them are the final say in what is good or bad for that person.
You are trying to focus on what they believed in that moment, but I see no reason to use that in an analysis of whether their actions fit their own morals. Sometimes people make mistakes even by their own rules. If we only care about what someone thought right in the heat of the moment, that category of mistake would be impossible, and it's not impossible. Saying that mistakes are possible is not overriding agency.
The core of it is in this line "the choice was what they seemed to think was right, for them, at the time. Thus it was the right choice for them". I don't agree with that logic at all. Humans are not good enough at following their own motivations and principles. They are impulsive and bad at analysis. You can't assume that their choices will always be consistent with their personal parameters of right and wrong.
Also, saying I think someone made a mistake is not denying agency. Don't be so melodramatic. Nowhere am I claiming to have the final say. I merely have the right to an opinion.
I took the little information they gave and from that the only true logical conclusion was they made the right choice for them at that moment. Full Stop.
You’re the one bringing the extra opinions into the matter and reading into a simple thing far too much. Most of the above I agree with you on outside of this particular thread. It has nothing to do with the very narrow scope of my original comment and attempted clarification.
Neither of us can know 100% what was right or wrong for them in that moment, but based on the information of A. no longer feeling right about being associated with a place for reasons that they deemed important enough to come to this conclusion — and B. aligning actions with that inner knowledge; makes it the right action (choice) for that person. If they changed their mind later, it does not change the immutable facts of that moment. It simply provides a new set of choices and options that is outside the scope of my original comment.
When I say mistake here, I specifically mean "mistake as far as their goal of making the right choice". And I mean that in the moment, using knowledge they have at that time, just like you're defining "right choice". Nothing after the fact nor outside the scope.
> I took the little information they gave and from that the only true logical conclusion was they made the right choice for them at that moment. Full Stop.
I don't see how they gave enough information to be sure, but more importantly you seemed to make a generic statement that anyone making a choice like that would be making the right choice, and that's what I really object to.
> You’re the one bringing the extra opinions
I am not! Please stop misreading me! Why won't you listen to what I'm saying about my own argument?
> Neither of us can know 100% what was right or wrong for them in that moment,
Please explain how "neither of us can know 100%" can be true at the same time as "only true logical conclusion was they made the right choice for them at that moment. Full Stop."
> A, B
Remember that not reporting the company was also part of the choice they made. The basic description of the choice was to report, quit, both, or neither, and they chose to quit.
> If they changed their mind later, it does not change the immutable facts of that moment. It simply provides a new set of choices and options that is outside the scope of my original comment.
I'm not talking about whether someone might change their mind later with new information, per se. I'm making the objectively true claim that people don't always think things through, meaning their choice might fail to represent the knowledge and priorities they had at the time.
https://www.justice.gov/criminal/criminal-division-corporate...
>As described in more detail in the program guidance, the information must relate to one of the following areas: (1) certain crimes involving financial institutions, from traditional banks to cryptocurrency businesses; (2) foreign corruption involving misconduct by companies; (3) domestic corruption involving misconduct by companies; or (4) health care fraud schemes involving private insurance plans.
>If the information a whistleblower submits results in a successful prosecution that includes criminal or civil forfeiture, the whistleblower may be eligible to receive an award of a percentage of the forfeited assets, depending on considerations set out in the program guidance. If you have information to report, please fill out the intake form below and submit your information via CorporateWhistleblower@usdoj.gov. Submissions are confidential to the fullest extent of the law.
Well here's a cynical take on this - management is playing the business game at a higher level than you. "Shady stuff" is the natural outcome of profit motivation. Our society is fundamentally corrupt. It is designed to use the power of coercive force to protect the rights and possessions of the rich against the threat of violence by the poor. The only way to engage with it AND keep your hands clean is to be in a position that lets you blind yourself to the problem. At the end of the day, we are all still complicit in enabling slave labor and are beneficiaries of policies that harm the poor and our environment in order to enrich our lives.
>unless I report it to PCI, which I would get no reward for.
You may be looking at that backwards. Unless you report it to PCI, you are still complicit in the mishandling of the breach, even though you resigned. You might have been better off reporting it over the owner's objections, then claiming whistleblower protections if they tried to terminate you.
This is not legal advice, I am not a lawyer, I am not your lawyer, etc.
If the GP's story is true (and I have no reason to suspect otherwise), then there are clearly differences in the degree of "badness" between people. GP chose to resign from his job, while his manager chose to be negligent and dishonest.
So, even if we're all bad people, there are less bad and more bad people, so we might as well call the less bad end of the spectrum "good". Thus, there are good and bad people.
The argument that profit motivation is the origin of shady business practices ignores the existence of those businesses which pursue profit in an ethical manner. The company I work for, for instance, is highly motivated to produce a profit, but the way we go about obtaining that profit is by providing our customers with products that have real value, at fair (and competitive) prices, and by providing consistently excellent customer support. Our customers are *very* satisfied with our products and services, and they show their satisfaction with extreme brand loyalty. The profit we make year over year allows us to increase the quality of life for our employees, and keeps our employees highly motivated towards serving our customers. We pursue the good of our customers alongside our own, and we avoid shady business practices like the plague.
Or is it supposed that hating each other, lying to one another, stealing from one another, murdering one another, failing to fulfill contract, covenant, and commitment to one another are things that should be considered good?
as it is written:
None is righteous, no, not one;
no one understands;
no one seeks for God.
All have turned aside; together they have become worthless;
no one does good,
not even one.
Romans 3:10-12As nice as this is on paper, it will never happen, lobbyist exists. Not to be tinfoil hat but why would any lawmaker slap the hand that feeds them.
Until there is an independent governing body which is permitted to regulate over the tech industry as a whole it wont happen. Consider the FDA, they decide which drugs and ingredients are allowed and that's all fine. There could be a regulating body which could determine the risk to people's mental health for example from 'features' of tech companies etc. But getting that body created will require a tragedy. Like why the FDA was created in the first place. [1]
That's just my 2cents.
1 : https://www.fda.gov/about-fda/fda-history/milestones-us-food....
I think ideas like this is why it's not going to happen.
Our understanding of mental health is garbage. Psychiatry used to be full of quackery and very well still might be. Treatment for something like depression boils down to "let's try drug in a random order until one works". It's a field where a coin-flip rivals the accuracy of studies. Therefore any regulating body on that will just be political. It will be all about the regulators "doing something" because somebody wrote enough articles (propaganda).
Problems like this are why people aren't interested in supporting such endeavors.
this argument reduces mental health to medication, which leaves aside everything from the history of mental health (asylums, witch burnings to today), leaps in medicine (from lobotomies, to SNRIs, bipolar meds and more), to simply better diagnoses.
There are certainly tons of people here who have benefited from mental health professionals - overextending the flaws in psych simply to dismiss the idea of a watchdog is several unsupported arguments too far.
There are some non-medication treatments for some psychiatric symptoms such as those caused by trauma (Prominently, EMDR) that some hail as actual cures, and even maybe depression (I am clearly not a doctor.) but in the case of depression I think you'll find its quite medication-heavy.
The reason for this is that psychiatrists are Medical Doctors and Psychiatry is a medical field which is of course bounded by the means of medical science. This is not to say there is some "magic" at work which science could never understand--not at all. It is merely the case that medical doctors are a research paper oriented bunch, and most of the medical research which makes it into practice is either relating to anatomy or pharmaceutical interventions.
Most of the treatments we have are pharmaceutical medications because most of our research dollars have gone into pharmaceutical research.
I decided to edit this comment to add: In my personal opinion, is probable that psychiatrists et all, writ large as it were, have already figured out how to cure depression. Only, we cannot really manage to employ it because it isn't a pill, therapy, device or surgery.
There a whole host of 'sciences' that are kind of 2nd tier like this, Psychiatry being one of them. Once we understand enough Neuroscience, it's likely to me Psychiatry will get consumed by Neuroscience which will splinter into more useful for day to day life categories as it grows (like a psychiatrist)
Super book on the subject and also talks about the rising bar for individual culpability as we understand more about the brain: https://www.amazon.com/Incognito-Secret-Lives-David-Eagleman...
I don't think it would take much to convert real IDs into a national ID, they are as close to as they can get without "freaking people out".
People could even generate their own number (private key), which they never gave out, and appeared differently to each account manager verifying it, and still replace them.
When you choose your own number, it's only the Mark of the Beast if you are the Beast! * **
* 666, 13, 69 and 5318008 expressly prohibited.
** Our offices only provide temporary tattoos.
Most of our population is still living in a headspace where transactions are effectively private and untraceable, from the cash era, and has not considered all the ways that the end of this system makes them potential prey.
The fact is that the market is demanding a way to identify you both publicly and privately, and it will use whatever it needs to, including something fragile like a telephone number 2fa where you have no recourse when something goes wrong. It's already got a covert file on you a mile long, far more detailed than anything the intelligence agencies have bothered putting together. The political manifestation of anti-ID libertarians is wildly off base.
Are you correct in what's going on? Yes. Are we placed in this with no option to resist? For the most part yes.
It’s not just that you or I will be inconvenienced with a bit more fraud or email spam, but rather that large nation state adversaries having huge volumes of data on the whole population can be a significant strategic advantage
And so far we typically see email+password+ssn be the worst data leaked; I expect attackers will put in more effort to get better data where possible. Images, messages, gps locations, etc
— George Washington.
https://www.facebook.com/dwight.crow/media_set?set=a.1010475... “#Weaponry and morale determine outcomes. The 2nd largest city of Iraq (Mosul) fell when 1k ISIS fighters attacked “60k” Iraqi army. 40k soldiers were artifacts of embezzlement, and of 20k real only 1.5k fought - these mostly the AK47 armed local police. An AK47 loses to a 12.7mm machine gun and armored suicide vehicle bombs. Finally, the attack was personal - soldiers received calls mid-fight threatening relatives by name and address. One army captain did not leave quickly enough and had two teenage sons executed.” #violence #Iraq #daesh
of course the americans used this kind of personalized approach extensively in afghanistan, and the israelis are using it today in lebanon and gaza, and while it hasn't been as successful as they hoped in gaza, hamas doesn't exactly seem to be winning either. it's an asymmetric weapon which will cripple "developed" countries with their extensive databases of personal information
why would a politician go to war in the first place if the adversary has the photos and imeis of their spouse, siblings, and children, so they have a good chance of knowing where they are at all times, and the politician can't hope to protect them all from targeted assassination?
the policy changes needed to defend against this kind of attack are far too extreme to be politically viable. they need to be effective at preventing the mere existence of databases like facebook's social graph and 'the work number', even in the hands of the government. many more digital pearl harbors like the one we saw this week in lebanon will therefore ensue; countries with facebook, credit bureaus, and national identity cards are inevitably defenseless
imposing liability on companies whose data is stolen is a completely ineffective measure. first, there's no point in punishing people for things they can't prevent; databases are going to get stolen if they're in a computer. second, the damage done even at a personal level can vastly exceed the recoverable assets of the company that accumulated the database. third, if a company's database leaking got your government overthrown by the zetas or daesh, what court are you going to sue the company in? one operated by the new government?
consider https://en.wikipedia.org/wiki/1943_bombing_of_the_Amsterdam_...:
> The 1943 bombing of the Amsterdam civil registry office was an attempt by members of the Dutch resistance to destroy the Amsterdam civil registry (bevolkingsregister), in order to prevent the German occupiers from identifying Jews and others marked for persecution, arrest or forced labour. The March 1943 assault was only partially successful, and led to the execution of 12 participants. Nevertheless, the action likely saved many Jews from arrest and deportation to Nazi extermination camps.
to avoid partisan debate, imagine a neo-nazi group takes over the us, which presumably we can all agree would be very bad. after they took over, how hard would it be for them to find all the jews? not just make a list of them, but physically find them? (much easier than it was in 01943, i'm sure we can agree.) how hard would it be for them to find all the outspoken anti-fascists? where could those anti-fascists hide?
now, step it up a notch. how hard would it be for them to find all the jews before they take over? it wouldn't be that hard if the databases leak. and if you feel safe because you're not jewish, rest assured that neo-nazis aren't the only groups who are willing to use violence for political ends. someone out there wants you dead simply because of the demographic groups you belong to. the reason you haven't been seeing widespread political violence previously is that it hasn't been a winning strategy
the situation is changing very fast
Do note, that this isn’t just an Americas problem.
Your data is probably on DBs in other nations.
Plus - the playbook is to target weaker nations and then use them for staging grounds to target stronger nations.
https://www.nerdwallet.com/article/finance/how-to-freeze-cre...
Since moving overseas 15 years ago, I tried numerous times and it simply is not possible. All the forms require a U.S. mailing address to register. Same for online access to your Social Security account.
There are an estimated 10 million Americans living overseas. Taken together, we are the equivalent of the 11th largest state. All of us completely blind to what is happening with our credit record and Social Security account.
At this point I think the only way this gets fixed is massive fraud/exploitation by organized crime, so these organizations finally address the problem.
Curious how you found this number, have a source?
This made me pretty curious, but I couldn't find any official numbers. The closest 'official' numbers that I could find are from the Federal Voting Assistance Program [0] and that lists 4.4 million people, but only 2.8 million of those being adults.
[0] https://www.fvap.gov/info/interactive-data-center/overseas
> Curious how you found this number, have a source?
I don't have the source handy but have seen the estimated 10 million figure cited repeatedly. But maybe it is about a million too high, as the US Department of State estimates nine million in this 2020 publication: https://travel.state.gov/content/dam/travel/CA-By-the-Number...
This Wikipedia page has a lot more info for those interested: https://en.wikipedia.org/wiki/Emigration_from_the_United_Sta...
Using FVAP stats to me seems problematic, because just like the general population, many US citizens do not bother registering to vote (though they do acknowledge this on the page you linked to and try to control for it).
State likely have a more accurate estimate from knowing how many passport renewals originate from overseas addresses. I am sure some Americans renew or replace their passports while merely travelling overseas, but I cannot imagine this is a routine practice.
The first time would have been a tragedy, from then on it has been farce after farce.
Imagine a world where companies would have to prove the necessity of storing specific factoids. It would only take 1 security researcher to prove it being unnecessary, invalidating that class of "legitimate interests".
Today this value judgement happens in human brains, like the (correct) judgement in your comment. If we want to scale it objectively we would have to switch to formal verification. A whole industry of compliance checking could come to exist where a company wants to get its operations screened for compliance issues, so as not to suffer criminal negligence penalties.
You are not being harmed by the storage or leakage of a few bytes, that's ridiculous. You are being harmed by the financial industry and government's insistence that knowledge of these bytes is sufficient to take your property or hold a debt against you.
googletagmanager.com googleapis.com fontawesome.com addtoany.com
sigh
Next please reign in the CRAs.
Chase tells Experian I opened a new line of credit with them, but it later is demonstrated that it was a scammer with my SSN? Congratulations, $5,000 fine.
Of course this all gets priced in to the cost and availability of consumer credit. Good! Now the lenders have an incentive to drive those costs down (cheaper, better identity verification) to compete.
If a lender wants to be repaid, then they need to show the borrower all the evidence they have for proof that the borrower entered into the contract.
If all a lender has is the fact that a 9 digit number, date of birth, name, and address were entered online, then the borrower simply has to say “I did not enter that information”, and the lender can go pound sand.
Guarantee all the lenders will tighten up their operations very quickly, and consequently, so will the loans that appear on one’s credit report.
They call it "Identity Theft" instead of what it should be called: Bank fraud. The term "Identity Theft" 1. needlessly pulls an otherwise uninvolved person into the mix, suddenly making it their problem too, and 2. downplays the bank's negligence.
If someone uses my name to take out a loan, and the bank stupidly lets them, this shouldn't even remotely be my problem. I shouldn't even have to know about it. This is the bank's problem from their own stupidity.
Imagine saying "put all of the consequences of getting robbed onto the bank, not the robber"
Why are we subsidizing lenders’ by putting this ridiculous burden on people who have nothing to do with the lender’s business?
The lender can pay to appropriately verify their borrower’s identity, or go to court and sue for damages like everyone else has to.
In actuality some not-well-maintained systems owned by <corp> were hacked or exposed or someone perpetrated fraud on a financial institution and happened to use information that identifies me. It's really backwards.
PSA: If you haven't already, go freeze your credit at Experian, TransUnion, Equifax and Innovis. It will make the perpetration of this type of fraud much more difficult for adversaries.
Put otherwise if a bank asks experian to look at my credit report and experian tells them to take a hike because my account is frozen, that’s not worth much money to the bank. But that’s the only credit account configuration that has any value to me, so I’ll insist on it.
I think “freezing” and the dynamics thereof are established by federal law, while “locked” is a think the companies made up so they had an account setting that they could provide that would give the illusion of security, while maintaining the ability to sell information associated with the account.
In other words: evil people do evil things when we aren’t paying sufficient attention. It’s our job to hold them accountable.
I was also informed you can freeze opening checking accounts here.
https://www.reddit.com/r/assholedesign/comments/udy8rz/exper...
https://www.ftc.gov/news-events/news/press-releases/2023/08/...
All the propagandists said he was a Russian asset, as if even if that were true, it somehow negated the fact that we were now living under a surveillance state.
>Snowden pointed and everyone looked at his finger.
This is a great way of putting it.
There's long been surveillance programs and also numerous laws outlining the responsibilities of telecom provides to enable wire tapping.
There's really nothing new from Snowden besides the names of a bunch of people to go kill cause they're spies.
FISA [1] isn't a private law either.
https://en.wikipedia.org/wiki/COINTELPRO
https://en.wikipedia.org/wiki/Mass_surveillance_in_the_Unite...
Note: 2006 (Klien) predates 2013 (Snowden)
https://en.wikipedia.org/wiki/Room_641A
[1]: https://en.wikipedia.org/wiki/Foreign_Intelligence_Surveilla...
https://en.wikipedia.org/wiki/2010s_global_surveillance_disc...
Now instead, imagine in 1978 [1] a government authorizes "United States federal law that establishes procedures for the surveillance and collection of foreign intelligence on domestic soil" and in 2008 [2] amends it to not be a big deal if they're foreign or not and then 5 years later it turns out they're doing just that.
These bills are not secret. Were not secret. Have never been secret. It's not my fault you didn't read them but it doesn't make Snowden novel.
[1]: https://en.wikipedia.org/wiki/Foreign_Intelligence_Surveilla...
[2]: https://en.wikipedia.org/wiki/Foreign_Intelligence_Surveilla...
Well, maybe you're one of those propagandists. If you can't attack the idea, attack the person, right?
Hand waves, nothing new to see here, carry on.
The bills aren't what were exposed, it was more the techniques and scope. Like PRISM and XKeyScore and circumventing laws by sharing intelligence on US citizens with allies who aren't restricted by US laws. Spying on allied governments, etc. You know, that stuff.
You should really click on the link.
https://en.wikipedia.org/wiki/2010s_global_surveillance_disc...
https://en.wikipedia.org/wiki/Martin_and_Mitchell_defection
https://en.wikipedia.org/wiki/Church_Committee
https://en.wikipedia.org/wiki/ECHELON
Et cetera. These aren't new issues. The obsession with Snowden as a messianic figure is unhelpful in contextualizing the information.
Damn the gall, give it a rest. Again, methods and scope. Which one of those exposes PRISM, XKeyScore and the NSA infiltrating Google servers? Which one of those exposes the companies that willingly "integrated" with the NSA?
Which of those exposes US government spying on allied governments, recording private conversations, etc?
Saying Snowden didn't reveal anything is a silly hill to die on. What is your prerogative in minimizing the exposure? Do you work for one of the companies implicated in participating in prism or something?
Microsoft joined PRISM on 9/11/2007 (fitting)
Yahoo joined PRISM on 3/12/08
Google joined PRISM on 1/4/09
Facebook joined PRISM on 6/3/09
YouTube joined PRISM on 9/24/10
Skype joined PRISM on 2/6/11
AOL joined PRISM on 3/11/11
Apple, the last holdout on the list, joined PRISM 10/12 (after Jobs died).
OP, this is why it seems nobody cares, there's plenty of people trying to sway public opinion on the matter by minimizing it. Nobody wants to believe their government would do things like this, so when someone offers that, "hey it's not so bad," they want to believe it. We've always been at war with Eastasia.
I'll give you the benefit of the doubt, maybe we weren't communicating well, but I felt you were certainly minimizing it by claiming what Snowden revealed weren't "new issues," which they certainly were, and anyone who thinks different has an "obsession with Snowden as a messianic figure," which is an attempt to discredit. Was that your objective?
Laws which the telecoms were knowingly and willfully breaking for years.
You do remember that Congress gave them retroactive immunity? [0][1] You do know that this was only granted because people COULD sue (and were suing) them because of the information made public by Snowden and others?
[0] <https://www.aclu.org/news/national-security/retroactive-tele...>
[1] See Title II of the this bill <https://www.congress.gov/bill/110th-congress/house-bill/6304>
There was a big cultural shift from the default assumption in polite company being "They're spying on Middle Easterners" to "they're spying on everyone, everywhere" when talking about US spying.
I've seen no evidence of this. People mostly either don't understand it for feel powerless against it.
I think people don't really understand what an enormous sleeping dragon the entire thing is.
Isn't that what I said? Mostly we're debating semantics. My deeper point is that it's counterproductive and borderline misanthropic to argue "People just don't care about evil being done!" whereas the argument that "People seriously have no idea yet what they're 'agreeing' to" opens the door to actual solutions, for one inclined to work on them.
Over 99% of Americans point a camera at themselves while they take a shit.
They use the front-facing camera of their phone so often that the temporary inconvenience of removing a shade outweighs the long-term inconvenience of malware snapping an exposing photo.
My gut says that for most people is the reason.
Extremely few decisions that people make are deeply calculated with cold logic. Most decisions are primarily unconscious, automatic, and emotional.
Example: A persons hears it's good to have a webcam cover, so they get one. Nobody mentions doing it for their phone, so they never even think about it. Then someday a friend does mention it, but that would be an inconvenient change, so the person's gut puts up resistance against considering it too strongly. They give in to their emotional response, instead of doing the hard work of changing their emotions based on the knowledge they have.
At no point in the above scenario would the person state "I don't think mass surveillance is a bad thing." For me, that's why I mean when I say people "aren't ok with it."
If one's definition of people being "ok with mass surveillance" just means they tolerate it, that they don't sufficiently resist it (and what level of resistance is sufficient? For a person with a webcam cover but no phone cam cover? Does adding a phone cam cover mean they've declared their opposition to mass surveillance?), then how can you say people aren't okay with literally everything evil or wrong? Most people just won't summon enough activation energy to fight any given injustice around them, no matter how egregious it is. That's not a reflection of their morals and values, it's a reflection of how fucking tired we all are.
I would challenge you to offer up in detail how strongly you have worked to resist mass surveillance in your life. You're logged in and posting on HN, so my guess is, you haven't worked hard enough at it according to someone's metric. Do you have a cover on your phone camera? Just the front one or both? Do you have a cover on the microphones? Do you let others add your number in their contacts or do you refuse to ever give out your real phone number?
The rest would probably use the extra free time to raise their kids/be with family.
If people only did one change per year, even that would be enough to change the winds pushing our mass surveillance.
You can advocate for limiting govt. power ("LGP") without leaking any NSA docs. I don't think a single story about "LGP" changed due to the leaks. Everyone knows the government can do a lot of violence on you. So it's very hard.
If you're a high drama personality, yeah you can conflate all these nuanced issues. You can make privacy mean whatever you want.
(EU is trying to implement chat control again...)
We need more real-world analogies... "see, this is like having a microphone recording everything you say in this bar"... "see, this is like someone ID-ing you infront of every store and recording what store you've visited, and then following you inside to see what products you look at. See, this is like someone looking at your clothes and then pasting on higer price tags on products. ..."
> I've seen no evidence of this. People mostly either don't understand it for feel powerless against it.
Isn't feeling powerless and being ok with it, ultimately the same thing: Complacency
The more people faff about and fight for privacy as a misguided absolute, the less discussions we can have about ethical, safe and managed uses of surveillance. Privacy advocates have this weird habit of thinking they speak for everyone, which they don't.
"Federal civil rights watchdog sounds alarm over Feds use of facial recognition"
https://news.ycombinator.com/item?id=41603698
The mentality of people in tech has drastically shifted into "o well... "
And here is a libertarian solution: https://qbix.com/blog/2019/03/08/how-qbix-platform-can-chang...
Why do people keep saying social media is just a database?
All of the UX of online consent forms exists to misinform, trick, and get users used to agreeing to sell their digital soul.
Even if you've never visited their site.
Where's the consent there?
I do think the situation is dystopian though. Sharing data without explicit case-by-case consent should be disallowed.
Meta, Google are much better stewards of their users data. One misconception I see is claiming these companies sell user data. I'd instead say that they sell user attention.
When you think about it - initiatives are kind of aligned with user privacy (kind of, as there’s much more to the story than this simplistic point of view)
>Two billionaire Harris donors hope she will fire FTC Chair Lina Khan
https://www.reuters.com/world/us/two-billionaire-harris-dono...
>Kamala Harris’ Donors Privately Urge Firing of FTC’s Khan, SEC’s Gensler
https://www.bloomberg.com/news/articles/2024-09-06/kamala-ha...
> many companies engaged in broad data sharing that raises serious concerns regarding the adequacy of the companies’ data handling controls and oversight.
>>> But these findings should not be viewed in isolation. They stem from a business model that varies little across these nine firms – harvesting data for targeted advertising, algorithm design, and sales to third parties. With few meaningful guardrails, companies are incentivized to develop ever-more invasive methods of collection. >>>
[0]: https://www.ftc.gov/system/files/ftc_gov/pdf/Social-Media-6b...
Instagram Teen Accounts
As a non-user of many social media platforms, is there anything I can do to prevent companies from collecting data about me? It feels wrong that companies you do not sign up for are still finding and processing data about you.
I suspect it will break in the direction of the narrative that "data wasn't that valuable anyway", regardless of how disingenuous this sentiment is. Nothing else preserves the economic machine while simultaneously dismissing the concerns of consumers. Perhaps we'll get special protection for stuff like SSNs to make it seem like politicians are acting on the behalf of their constituents (even though a competent manager of a rational society would simply ban use of ssn as a form of identification as this is basically public information.
How are data deletion requests supposed to be handled in practice, when the only way to be sure is to physically destroy the hardware that data was stored on ? (Especially the case for transistor-based storage, and even more so when wear leveling is being used.)
Or is this is actually a "pinky promise" by the company to not restore the data (or else they will have to face legal consequences) ?
It’s also not true that it’s an irresolvable conflict. Yes the cops can and do buy your phone location data, but even if we said that was fine and should continue, that doesn’t also mean that any schmuck should be able to buy real-time Supreme Court justice location data from a broker.
[1]https://www.theverge.com/2013/12/12/5204196/how-advertisers-...
I'm not making any other implication.
It is social media where only the end users' devices can decrypt the posts and comments. Then surveillance is not possible. Targeted ads are not possible.
One arm: "everyone is a criminal; spy on everyone"
Other arm: "hey you shouldn't really harvest all of that data"
The EU: Unlike the barbarians across the pond, we actually protect people's privacy rights.
Also the EU: ChAt CoNtRoL
On one hand, there's a lack of clear leadership, unifying the societal approach, on top of inherently different value systems held by those individuals.
It seems like increasingly, it's up to technologists, like ones who author our anti-surveillance tools, to create a free way forward.
I don't like corporations spying on me, but it doesn't scare me nearly as much as the government doing it. In fact the principle risk from corporations keeping databases is giving the government something to snatch.
Even right here on HN, where most people understand the issue, you'll see conversations and arguments in favor of letting companies vacuum up as much data and user info as they want (without consent or opt-in), while also saying it should be illegal for the government to collect the same data without a warrant.
In practice, the corporations and government have found the best of both worlds: https://www.wired.com/story/fbi-purchase-location-data-wray-... Profit for the corporation, legal user data for the government.
that’s how we first arrive here (all of us). Time pass tho and most around fail then we become proper people capable of reasoning
However, that's not at all a cognitive dissonance. Fundamentally, there's a difference between governments and private companies, and it is fairly basic to have different rules for them. The government cannot impinge on free speech, but almost all companies do. The government cannot restrict religion, but to some extent, companies can. Etc.
Of course, in this case, it's understandable to argue that neither side should have that much data without consent. But it's also totally understandable to allow only the private company to do so.
There are plenty of cases where the same rules apply to both the government and corporations.
Once you say some vague demographic and bodily autonomy stuff: you know, if you’re going to invoke “voters,” I’ve got bad news for you. Some kinds of hate are popular. So you can’t pick and choose what popular stuff is good or what popular stuff is bad. It has to be by some objective criteria.
Anyway, I disagree with your assessment of the popular position anyway. I don’t think there is really that much cognitive dissonance among voters at all. People are sort of right to not care. The FTC’s position is really unpopular, when framed in the intellectually honest way as it is in the EU, “here is the price of the web service if you opt out of ads and targeting.”
You also have to decide if ad prices should go up or down, and think deeply: do you want a world where ad inventory is expensive? It is an escape valve for very powerful networks. Your favorite political causes like reducing fossil fuel use and bodily autonomy benefit from paid traffic all the same as selling junk. The young beloved members of Congress innovate in paid Meta campaign traffic. And maybe you run a startup or work for one, and you want to compete against the vast portfolio of products the network owners now sell. There’s a little bit of a chance with paid traffic but none if you expect to play by organic content creation rules: it’s the same thing, but you are transferring money via meaningless labor of making viral content instead of focusing on your cause or business. And anyway, TikTok could always choose to not show your video for any reason.
The intellectual framework against ad telemetry is really, really weak. The FTC saying it doesn’t change that.
Ex-NSA Chief: 'We Kill People Based on Metadata'...
I don't know. Ads are meant to convince you to buy something. Are they "behavioral manipulation?" Are all ads harmful?
> ...economic harm via price discrimination...
Should all price discrimination be "illegal?" This is interesting because it makes sense for the FTC and for anti-trust regulators to worry about consumer prices. Price discrimination in software services - the thing I know about - helps the average consumer, because it gets richer people to pay more and subsidize the poor.
> reselling of the data via monetization to unscrupulous aggregators or third parties
"Unscrupulous" is doing a lot of work here.
> ...general security reduction...
Gmail and Chrome being free ad subsidized has done a lot more for end user security than anything else. Do you want security to be only for the rich? It really depends how you imagine software works. I don't know what APT stands for.
> chilling effect of being tracked all the time in this way?
Who is chilled?
I guess talk about some specific examples. They would be really interesting.
You’ve already signaled that you’re ready and willing to dismiss any of the many obvious reasons why this is bad. But let’s flip it. What intellectually honest reason do you have for why it would be wrong if I’m watching you while you sleep? If I inventory your house while you’re away, and sell this information to the highest bidder? No bad intentions of course on my part, these things are just my harmless hobby and how I put bread on the table.
In my experience literally everyone who argues that we don’t really have a need for privacy, or that concerns about it are paranoid or that there’s no “real” threat.. well those people still want their own privacy, they just don’t respect anyone else’s.
More to the point though, no one needs to give you an “intellectually honest” reason that they don’t want to be spied on, and they don’t need to demonstrate bad intentions or realistic capabilities of the adversary, etc. If someone threatens to shoot you, charges won’t be dropped because the person doesn’t have a gun. The threat is extremely problematic and damaging in itself, regardless of how we rank that persons ability to follow through with their stated intent.
This is an interesting idea, but it's a pretty far analogy from app telemetry or ad data collection. If you're really saying, "would it be wrong for me as a camera app developer to collect the videos end users record?" I suppose the answer would really be, "It depends." Like that's what Instagram does, it collects videos end users record. But without their permission? I guess not, no, but that's pretty obvious. The same would be true if you made firmware for security cameras, which happened to be pointed at my bedroom. I suppose if you asked for permission, and I granted it, go ahead - if you didn't ask for permission, I would be surprised why you would need to collect the videos as a firmware developer. The house inventory thing is the same tack - are you talking about, does it make sense for Amazon to sell my purchase history, or something? I guess they asked for permission, go ahead... Nobody forces me to use Amazon or whatever.
Instagram, Amazon, etc. do the things they do with permission. And I don't think anyone who is fully educated is surprised what the idea is for the transactional attribution data it collects. There's lying by omission, which is bad, but that is an issue of leadership and education. Everyone in the EU still chooses telemetry and free over no telemetry and paid service, when it is spelled out to them. It's too bad that leadership has to be taken in that form, but there's no alternative in the regime they built there.
If this is just a competition over the leadership and education of laypeople, so be it, but this real life experiment keeps happening, and the people who try to inject drama into ad telemetry keep losing, so I really don't think it's just about lying. There is a real lack of harm.
> reason that they don’t want to be spied on
Nobody forces you to use Instagram. If you think ad data attribution is a form of spying, go for it. Delete the free social media apps. I don't use them. I don't have Instagram, TikTok, etc. I spend less than 10m a week watching something on YouTube. I don't even have a TV in my house. Do you see? They are not enriching your life.
> In my experience literally everyone who argues... well those people still want their own privacy, they just don’t respect anyone else’s.
In my experience this is pure projection. I respect when people don't want to give permission to Instagram to collect ad telemetry when they choose to not install the app. Of course, you say these things on the Internet, but you, you personally, are not going to migrate off of Gmail, which does all the same things. This is all really about vibes, about vibes being vibesy against social media, but not vibes being vibesy against Gmail, which would be a major inconvenience to say no to, and it would suck to have to pay $35/mo for e-mail - at the very least!
You can’t even rent a hotel room without giving them an email and a phone number they don’t need, and are looking to sell. If this works for you.. the person at the counter probably faked it rather than arguing with you. Some people will be happy when menus disappear and you need to install an app. What happens when you can’t check out of the grocery store without the requisite likes-and-subscribes? What happens when your flashlight app has 37 page ToS that says they reserve the right to steal your contact list for the purposes of selling flashlight apps? All is well because you can see in the dark, and no one makes you choose anything? Well I hope there’s healthy competition amongst the manufacturers of your pacemaker, and they don’t inform your insurance company that your health is deteriorating..
If you’ve got no sense of right or wrong beyond what is legally permissible, just exercise your imagination a bit to look at the likely future, and ask yourself if that’s how you really want to live.
The harm is the privacy violation. App telemetry needs to be "opt-in", and people should know who can see the data and how it's being used.
People really need to learn to say “NO” even if that means an inconvenience “Your personal information might be shared with our business partners for metrics and a customer tailored experience” no thanks, “what is your phone number? so I can give you 10% discount” no thanks, “cash or credit?” Cash, thanks, “login with google/ apple/ blood sample” no thanks
In fact, many such things fall into that category.
Should the state do surveillance? Maybe some? Probably less? But the hypocrisy isn’t the problem, the overreach is.
This is for getting votes from the undecided.
Everything will be back to normal (surveillance, data collection and censorship) after the election.
It is disingenuous to accuse the FTC of election pandering when they've been doing stuff like this for the past four years consistently.
This is just what Kahn's FTC does.
There is a long trail of blood behind google and facebook, amazon... Etc...
Should ad prices be lower or higher?
Should YouTube be free for everyone, or should it cost money?
Most companies can't afford to not do this when their competitors are. Hence the need for regulation.
What is the minimum level of privacy that a person should be entitled to, no matter their economic status?
If we just let the free market decide these questions for us, the results won’t be great. There are a lot of things which shouldn’t be for sale.
This is an interesting question: maybe the truth is, very little.
I don't think that user-identified app telemetry is below that minimum level of privacy. Knowing what I know about ad tracking in Facebook before Apple removed app identifiers, I don't think any of that was below the minimum level.
This is a complex question for sort of historical reasons, like how privacy is meant to be a limit on government power as opposed to something like, what would be the impact if this piece of data were more widely known about me? We're talking about the latter but I think people feel very strongly about the former.
Anyway, I answered your questions. It's interesting that no one really wants to engage with the basic premise, do you want these services to be free or no? Is it easy to conceive that people never choose the paid version of the service? What proof do you need that normal people (1) understand the distinction between privacy as a barrier to government enforcement versus privacy as a notion of sensitive personal data (2) will almost always view themselves as safe from the government, probably rightly so, so they will almost always choose the free+ads version of any service, and just like they have been coming out ahead for the last 30 years, they are likely to keep coming out ahead, in this country?
Yes I want YouTube to be free, but not if that requires intrusive surveillance.
People who pay for YouTube aren’t opted out of surveillance as far as I can tell. So I reject the premise of your question, that people are choosing free because they don’t value privacy. They haven’t been given the choice in most cases.
On a tangential note, you previously asked if ads should be more expensive. It’s possible that ads should be less expensive, since they may be less effective than ad spend would suggest: https://freakonomics.com/podcast/does-advertising-actually-w...
Is there any evidence that any of these things have ever happened as a result of this sort of data collection? I'm not talking about data posted to social media, I'm talking about the specific data collection described in this FTC press release.
The impossible part is proving the abuse. All of these companies keep their database, access controls, and everything they possible can about these data lakes secret. The simple fact of the matter is that you will never have any evidence someone looked you up in a database.
It is really easy to walk the line, but be obvious enough to intimidate.
If nothing bad happens for decades, and that is inconsistent with your model of danger, then the model is probably wrong
It's more like a flashlight than a gun
I disagree, and again, implore you to use your imagination. If private messages (not just yours but someone elses) were to suddenly be public or institutional knowledge, what damning things might happen? What influence might some have over others? What dynamics could or would shift as a result?
I'm comfortable making the claim that you aren't really thinking this through, at all, in any meaningful way.
1. Your full name
2. Your home address
3. Your social security number (if you're American)
4. Your mother's maiden name
If you're right, then you have nothing to worry about.
My full name is Michael Graczyk, I live in San Francisco, none of these companies know any more detail than that about the questions you asked
I suspect you mean that you haven't provided these companies with these details. What reason do you have to think they don't know those details?
I respect that you are willing to stand behind your claim. Best of success with your current venture.
ummm, WTF?
10x increase in teen suicide doesn't qualify as "bad"?
or repeated DOJ lawsuits against Facebook because their advertising practices result in highly effective racial discrimination?
Do a bit of googling, but ADINT and RTB tracking will get you there for search terms.
Or, continue being confidently dismissive of something serious people are taking very seriously. I am sorry if this FTC report targeted the source of your RSUs or otherwise motivated set of incentives, but there’s no free lunch. The consequences are finally landing of your viewpoint, done collectively, over the last decade.
I don't currently have any financial interest in any of these companies
> but ADINT and RTB tracking will get you there for search terms.
These are good things, do you have any examples of harm that has been caused by ADINT or RTB? Prosecuting criminals doesn't count for me
The FTC chair is complaining that companies "monetize that data to the tune of billions of dollars a year," but all this means is that this service is tremendously valuable.
The Internet's targeted advertising system is a major achievement of modern information technology and data science, and we dismantle it at our peril.
You join a Facebook group for fashion? Ads for fashion.
You join a Facebook group for woodworking? Ads for tools.
See how that doesn't require any personal information?
> Targeted ads based on knowledge about protected categories can be especially distressing. One example is when someone has not disclosed their sexual orientation publicly, but an ad assumes their sexual orientation. Another example is when a retailer identifies someone as pregnant and targets ads for baby products before others, including family, even know about the pregnancy. These types of assumptions and inferences upon which targeted advertising is based can in some instances result in emotional distress, lead to individuals being misidentified or misclassified, and cause other harms.
If this is one of the biggest harms the FTC can come up with, then honestly as a consumer I don't really care. Having free youtube is worth getting a few mistargeted ads, or I CAN JUST TURN TARGETED ADS OFF. Advertising isn't someone harassing you, its an ad that I can close or just report as not being accurate. I'd really be interested to hear from someone who thinks getting a mistargeted ad is in top 10 most stressful things in their life.
What I would really be interested in is the raw responses from the companies, not this report.
The only reason you have the option to do this is because of groups pushing back against advertising companies. Ad companies have no incentive to offer the option to disable targeting.
If you like having this option available, then you should like this FTC report and the position they are taking.
I can like other positions and actions the FTC has done, like requiring the ability to turn off targeted ads, and not like others, like this one. This is among the biggest problems in politics right now. Supporting a political party doesn't mean you need to 100% back all their opinions and policies, thats how change is effected in successful democratic systems.
They weren't saying that was the case I think you're misunderstanding them here. But they are 100% correct, you are benefiting from other people fighting against this mass surveillance and yet speaking against it. I think you should do some research on why privacy is important and challenge yourself and your potentially entrenched beliefs.
"Profound Threats to Users Can Occur When Targeting Occurs Based on Sensitive Categories"