7,710 karma · joined June 4, 2010
@jdp23 and http://facebook.com/jdp23 are the best ways to get in touch with me, or leave a comment somewhere on http://talesfromthe.net/jon
The over-optimism is indeed a really important takeaway, and agreed that it's not tool-dependent.
> Why not move the needle in the right direction and then lobby for additional things?
Two reasons. Preemption not only weakens some existing laws, it keeps states from passing future stronger laws -- so it caps protections. And, politicially, no privacy law in the US has ever been strengthened by Congress (or state legislatures) ... so, it's very unlikely that the lobbying for additional things will have an affect.
I htink there were three key sections that got cut out:
1) "A covered entity or service provider may not collect, process, retain, or transfer covered data in a manner that discriminates in or otherwise makes unavailable the equal enjoyment of goods or services on the basis of race, color, religion, national origin, sex, or disability." This was hugely important, it was sa major victory to get a bipartisan committee majority supporting similar language in APRA's predecessor ADPPA.
2) Requirements for algorithmic impact assessments by large companies (I forget the exact threshold).
3) A requirement to let people opt-out of consequencial automated decisions (with some exceptions), somewhat similar to California's CCPA.
Paul Graham, 2022: "Of 1277 students who graduated from Lambda School in 2020 and sought jobs, 950 got them, for a placement rate of 74.8%.
(Lambda's weirdly dedicated haters will be happy to hear that these numbers were audited by an accounting firm.)" [2]
https://secure.rightsanddissent.org/a/protect-liberty-act
It asks legislators to vote
NO on the Intelligence Community's fake reform bill, the FISA “Reform” and Reauthorization Act (which as the OP points out is actually an expansion of warrantless wiretapping)
YES on the Protect Liberty and End Warrantless Surveillance Act, which actually does include some significant reforms
Of course MHMD doesn't take effect until after the next legislative session, so I'm sure there will be attempts to weaken it. So I'm not counting any chickens quite yet!
It's true that California's legislation gets a lot of industry input, and they're not going to pass something puts the big tech companies out of business. On the other hand, there's a very effective coalition of privacy organizers there -- who are quite familiar with tech's tactics, and can be very effective at cutting through tech's spin with legislators. Plus, the California Privacy Protection Agency (which got established by a referendum, not through the legislature) has a lot of clout -- there isn't anything comparable in any other US state.
Washington state has similar dynamics, although with the CPPA equivalent. Microsoft and Amazon are hugely influential here; but, grassroots organizers had repeatedly stopped them from getting the very weak Bad Washington Privacy Act through the legislature. And this year, we passed My Health My Data -- stronger in some ways than California's privacy law.
Texas ... has been a disappointment. The privacy law they passed this year is based on the Bad Washington Privacy Act but significantly weaker.
In the US, it seems like it's mostly being driven by "child-safety" orgs, some of whom are well-intentioned but just don't understand the downsides, some of whom are anti-LGBTQ and appreciate the downsides. But others may well be active behind the scenes.
And, there's a committee vote on KOSA tomorrow, so if you're in the US please contact your Congresspeople -- https://www.stopkosa.com/
AcitivityPub's also meant to be extended, there are FEPs, and it's likely that the working group will come up with a new version as well. That said there certainly are differences between XMPP and ActivityPub, most people say the ActivityPub ecosystem is significantly farther along than XMPP was.
I could imagine Meta doing an open-source AP server (and with a fresh start it would be cleaner base than Mastodon). I also wouldn't be surprised if the release a app building toolkit / framework / whatever ... there isn't a good one now, they do that stuff well, and as they introduce proprietary AP extensions then they toolkit is a good way to get people to adopt them. But it's very hard to know at this point, it's also possible it's just PR spin and they won't really invest in it. We shall see.
Anyhow, good discussion, thanks much!
Agreed that if something's available encrypted on the web with no login required then usually the only protections you can put on it is security-through-obscurity like hard-to-guess links that don't show up on profiles (YouTube's "unlisted videos") or advisory like "noindex". But, although it's not something I talked about in this article, there are design choices. Mastodon (etc) could evolve so that a lot of what's currently "public" isn't available on the web with no login required.
https://heat-shield.space/mastodon_two_camps.html looks at tensions between people who just want a "better twitter" (which tends to lead to centralization) and people who focus more on small communities (a more decentralized solution).
"Of course, Meta's far from the only threat out there, but as I discuss in 'Threat modeling Meta, the fediverse, and privacy', looking at Meta-related threats also points to solutions that increase privacy and safety in the fediverse more generally."
Here's a link to the longer post (still a draft). https://privacy.thenexus.today/fediverse-threat-modeling-pri...
And agreed, it doesn't scale for Meta to infiltrate people into every single fediverse instance -- although threat actors who are targeting specific people or communities might well do this, so it's also something to take into account.
Personally I think it's more an "embrace, extend, and exploit" approach; a decentralized model could work well for Meta, for example if they do revenue-sharing on ads hosted by other instances (think Disney or LA Lakers).
Update: here's another good article looking at how Meta could embrace and extend -- again, not extinguish. https://darnell.day/heavy-meta-four-business-reasons-why-ins...
https://privacy.thenexus.today/fediverse-threat-modeling-pri...
"After gaining a large Twitter following in the spring as she baselessly accused LGBTQ teachers of being pedophiles and “groomers,” Raichik began criticizing children’s health facilities earlier this summer, targeting a hospital in Omaha in June and another in Pittsburgh in August. The attacks resulted in a flood of online harassment and phoned-in threats at both hospitals."
(From "Twitter account Libs of TikTok blamed for harassment of children’s hospitals" https://www.washingtonpost.com/technology/2022/09/02/lgbtq-t...)
...
"One former English teacher, Tyler Wrynn, told Lorenz for her piece that he had been harassed, sent death threats and eventually fired after one of his TikToks about supporting LGBT+ kids was posted by Raichik"
(From "How Libs of TikTok Became an Anti-LGBTQ+ Hate Machine" https://www.them.us/story/libs-of-tik-tok-twitter-facebook-i... )
"While the account doesn’t always explicitly encourage followers to do anything, its posts have sometimes led people to harass or physically threaten its subjects. In one instance, a group of five Proud Boys members disrupted a Drag Queen Story Hour at a public library, spewing homophobic and transphobic insults at attendees, which investigators believe was spurred by Libs of TikTok."
(from "Teacher targeted by Libs of TikTok sent death threats and lost his job" https://www.thepinknews.com/2022/04/20/libs-of-tiktok-teache... )