HNHacker News
TopNewBestAskShowJobs

throwawyaaccoun

22 karma · joined December 22, 2021

submissionscomments
throwawyaaccoun··on Princeton researcher apologizes for GDPR/CCPA email study
I should have been more clear, so let me correct that. I am convinced. I agree that harm was done, and suffer from generalized anxiety disorder myself, so I empathize with the panic attacks that people received.

It is because I believe that harm was done, but also because I am a privacy nut myself, that I am trying to, for my own sake, characterize how I should approach sending emails like this in the future. The study may not go on, but individuals still will send these emails as long as CCPA/GDPR exist. (Just to add some color: It's my anxiety which is causing my to want to delete everything from the internet. If there's minimal info about me online, I can rest easy. It's why this is a throwaway that I will abandon shortly.)

Reading everyone's thoughts is what changed my mind. I now understand to have underestimated the emotional and legal effects CCPA/GDPR requests could have on small website operators, and will be more judicious in the future (like this study should have been) in pre-filtering and my wording. Reactions like kstrauser's (elsewhere in thread) were initially surprising to me (perhaps because of the faceless nature of the internet), so I hope you take my about face as genuine.

Where do you think this balance lies? I still believe consumers, in general, should have right to ask those with their data about their processes; to give it to them; and, to upon request, delete it. And further, in general, I think these interactions are the kinds of things that researchers might legitimately want to study. I found your other comments to be thoughtful, so I am curious what you think explicitly.

throwawyaaccoun··on Princeton researcher apologizes for GDPR/CCPA email study
Oh, our society, especially America's, is overly litigious. I agree.

But, pushing back a bit (in good faith), do you think asking an entity for your data, or asking them to delete it, should really be considered unusual and panic provoking? I said in another comment the same thing, but do you think this could be a moment of cultural learning?

throwawyaaccoun··on Princeton researcher apologizes for GDPR/CCPA email study
I mean this all in good faith:

What is the difference between 100,000 individuals emailing 3-5 websites on that list, with their real identities, asking for things to be deleted (such that all 350k are covered)? Where is the meaningful difference between this situation and the one here, ignoring the deception for a moment (unless that is the only issue)?

Could this be a moment of cultural learning for everyone? That's kind of how I am looking at it, frankly, but I am open to being wrong. That is, perhaps small entities will learn, in one or two instances, to just ignore this kind of thing?

throwawyaaccoun··on Princeton researcher apologizes for GDPR/CCPA email study
Interesting. Ok, so let's say the deception wasn't the problem, suppose for the moment. Would the study have been more palatable if the researchers had more properly vetted the email list to ensure, say, >95% or perhaps even 100% were corporations that did fall under the law?
throwawyaaccoun··on Princeton researcher apologizes for GDPR/CCPA email study
It's not intended to be whataboutism (sorry about that, I edited this in to clarify) -- I agree that the deception was wrong. But there seems to be something about this particular event that is riling people up, and that's what I am getting at. I am not trying to whatabout, to be super clear.
throwawyaaccoun··on Princeton researcher apologizes for GDPR/CCPA email study
[Throwaway for privacy.]

I know this was hashed out on the other threads a bit, but can someone please explain to me why folks are so up in arms about this, compared to, say, studies that scrape user data without consent (something the IRB allows all the time by saying that no human subjects are involved)? Is it simply because there is no visibility into this practice (i.e., no email sent?) Scraping user data from public profiles, aggregating it into a model, and publishing a paper or whatever -- that seems demonstrably more invasive to individuals, storing and keeping their user data, than an email quoting a statute.

I agree that the deception was unnecessary, but that's it. It doesn't feel any wronger than that.

Especially because these researchers really were acting in "meta" good faith trying to probe the privacy ecosystem, I fear there may be a chilling effect. Consumers deserve privacy rights and privacy knowledge in the asymmetric surveillance economy we find ourselves in, IMO.

I'm open to being wrong.