- A web site logs traffic in a sort of defacto way, but no one actually reviews the traffic, and it's not sent to 3rd parties.
- A government website uses a standard framework and that framework loads a google subdomain. In principle, Google could use this to track you but there's no evidence that this actually happens.
- A website tracks user sessions so they can improve UI but don't sell that data to 3rd parties.
- A website has many 3rd party domains, many of which are tracking domains.
- Facebook knows exactly who you are and sells your information to real-time-bidding ad services.
- Your cell phone's 3G connection must in principle triangulate you for the cell phone to function, but the resolution here is fuzzy.
- You use Android and even when your GPS is turned "off" Google is still getting extremely high resolution of your location at all times and absolutely using that information to target you.
A LOT of the privacy folks would put all those examples in the same category, and it absolutely drives me up a wall. It's purity-seeking at the expense of any meaningful distinction, or any meaningful investigation that actually allows uses to make informed decisions about their privacy.Whether the one serving the content is exploiting data at the present moment has very little relevance. Because the end user has no means to assert whether it is happening or not.
Even if this sounds innocent, these must be turned over if you are provided a warrant or subpoena (which ever would be appropriate, IANAL).
Shitting on well-intentioned people who merely failed to be perfect is not a great way to get the most of what you ultimately want.
If you think intent doesn't matter then what happens when well-intentioned people decide it's not worth trying because no matter what they will be crucified as murderers even if all they did wrong was fail to clean the break room coffee pot. The actual baddies are still there and have no inhibitions and now not even any competition.
> it should be addressed, but it's not bad faith
I think this is the part that annoys me about the privacy community. There's nicer ways to deal with these issues and get them resolved rather than just leaping to the pitchforks. Raise the concern and observe the response. That is far more informative of how much one should trust. Because let's be honest, at the end of the day there is still trust. You have to trust that they have no logs. You have to trust any third party auditor. Trustless is a difficult paradigm to build, so what's critical is the little things.But jumping to pitchforks just teaches companies to ignore the privacy crowd. Why cater to them when every action is interpreted as malicious? If you can do no right then realistically you can do no wrong either. If every action is "wrong" then none are. In this way I think the privacy community just shoots themselves in the foot, impeding us from getting what we want.
Even if they don't, it opens up more attack vectors for malicious 3rd parties who want that data. That's why you can't be careless.
At any time any company could turn evil, and any free(ish) government could become totalitarian overnight. This is a fact, but also pretty useless one.
The real questions to ask are, how likely it is to happen, and if that happens, how much did all these privacy measures accomplish.
The answer to those are, "not very", and "not much".
Down here on Earth, there are more real and immediate issues to consider, and balance to be found between preventing current and future misuse of data by public and private parties of all sides, while sharing enough data to be able to have a functioning technological civilization.
Useful conversations and realistic solutions are all about those grey areas.
Is it isrlsss paranoia when it's happening around us as we speak?
It's strange how we call it "preparation" to spend trillions of dollars on mobilizing a military, but "paranoia" to simply take some best practices and not have the citizen's data dangling around. Its a much cheaper aspect with huge results, like much of tech.
I live in a good neighborhood and I have left my door unlocked once or twice to no consequence. That doesn't mean it's paranoia to make a habit out of locking my doors.
That's all I assert here. Care and effort. I don't know all the subtle steps to take since I'm not in cybersecurit, but we still shouldn't excuse sloppiness.
If data exists, it can be subpoenaed by the government.
Personally, I don't understand people's mindless anathema about being profiled by ad companies, as if the worst thing ever in the world is... being served more relevant ads? In fact I love targeted ads, I often get recommended useful things that genuinely improve my life and save me hours in shopping research.
It's the government getting that data that's the problem. Because one day you might do something that pisses off someone in the government, and someone goes on a power trip and decides to ruin your life by misusing the absolute power of the state.
On the other hand, if I'm making death threats on Facebook, there's a much more realistic path: view the threats from a public source --> subpoena Facebook for private data.
Treating the two risks as similar is madness.
- https://sls.eff.org/technologies/real-time-location-tracking - https://www.wsj.com/politics/national-security/u-s-spy-agenc... - https://www.brennancenter.org/our-work/research-reports/clos...
They don't need to subpoena anyone if they can just get it without the hassle.
If a government has the data there’s a chance it will stay in the government at least
You either
1) don’t want it stored
2) are happy for government to have it but not companies
3) are happy for everyone to have it
And that's even before malvertising comes into picture.
My takeaway from this thread is an increased amount of trust in OP. Not because they made a mistake, but because of how they handled it. Well done OP!
Web server logs were not tied to user credentials in any way, they were used for debugging purposes and could not have been used to identify users.
Front page says "zero logs"
Some logs, including specifically datapoints you have promised not to log, but you mean well (?) is pretty different from zero logs
Sounds like a clear "lack of a depth of understanding" to me.