5 ms·
Interestingly there seems to be a loophole in that they can collect the data regardless of consent, but can't use or share it without consent. So chances are th
by devindotcom 10y ago
Interestingly there seems to be a loophole in that they can collect the data regardless of consent, but can't use or share it without consent. So chances are this sensitive data will be recorded and put in a database anyway, even if they're not lawfully allowed to look at it without anonymizing first - but a future law could also add an exception, keeping things for law enforcement for instance.
I'm triple checking with the FCC on this though.
- wmf 10y agoIIRC that's what AT&T did; I guess it was too complex to feed an opt-out blacklist to their DPI boxes. ISPs are still in denial that this data is toxic waste. https://www.schneier.com/blog/archives/2016/03/data_is_a_toxic.html https://www.schneier.com/blog/archives/2016/03/data_is_a_tox... If the FCC allows ISPs to collect data as long as they swear it will never be used, the ISPs can then sell it to law enforcement with a contract that says they will also "never use it". https://www.theguardian.com/business/2016/oct/25/att-secretly-sells-customer-data-law-enforcement-hemisphere https://www.theguardian.com/business/2016/oct/25/att-secretl...
- joering2 10y agoI don't think that would fly if they are being sued? How would LE defend money being spent on something that they cannot use? I mean any judge will see it, no?
- JadeNB 10y ago> How would LE defend money being spent on something that they cannot use? I mean any judge will see it, no? The common-sense interpretation is not always (and, much as I hate to say it, probably sometimes should not be) the interpretation arrived at by a judge.
- csydas 10y agoI appreciate healthy skepticism, but evidence has been thrown out on far flimsier premises by even the lowest of courts. It would be very surprising if evidence of this manner continually survived through the court system on appeal after appeal. This isn't saying it can never happen, but it would be in contrast to the multitude of times that evidence was discarded for less. I haven't had a chance to read the fcc's reasoning on why the ISPs are allowed to collect the data in the first place, and I do agree it seems like a ruling that's just can't wait to show off all its loopholes; but I think this would be pretty difficult to bring as evidence in trial. Though I do agree and think it'll be used as a cudgel for other purposes outside of the courts, for threats or for discriminatory justice.
- DanieI 10y agoparallel construction
- dragonwriter 10y agoA contract violation by LE is not a constitutional violation that triggers the exclusionary rule, it's a matter between LE and the party they have a contract with. Even if enforcement of the contract happens at all, the result is likely a damage award for the breach.
- JumpCrisscross 10y agoAny idea why? Do they need Congress to do that (or give them the power to do it)? Or are these FCC politics.
- revelation 10y agoThere is no need for any sort of future law, that data is open to law enforcement already. That is the fundamental problem in all of this: decade old court decisions that determined you have no "reasonable expectation of privacy" in data you shared with a company. AT&T turned this into a product: http://www.zerohedge.com/news/2016-10-27/us-taxpayers-pay-att-millions-year-privilege-being-spied-upon http://www.zerohedge.com/news/2016-10-27/us-taxpayers-pay-at... That may have been a useful policy in a time where you yourself could decide what data you shared, now that devices share data on your behalf that can be stored forever, aggregated, analyzed and what not it is clearly no longer acceptable. We desperately need a whitelist approach to companies storing and handling cleartext user- and metadata.
- ez_psychedelic 10y agoThis will probably just turn into a line in the terms and agreements that everyone just clicks "yes" because they have to in order to use anything.
- mcs_ 10y agoIn some cases it is already like that. The choice will be share or stay offline.
- btown 10y agoFrom christianmunoz's comment: Copied this from another comment of [his] on this post, but it answers part of your question. From the FCC fact sheet[0] on the decision: > The Order prohibits “take-it-or-leave-it” offers, meaning that an ISP can’t refuse to serve customers who don’t consent to the use and sharing of their information for commercial purposes. So at least they can't cut you off entirely if you don't consent/opt-in. [0] http://transition.fcc.gov/Daily_Releases/Daily_Business/2016.. http://transition.fcc.gov/Daily_Releases/Daily_Business/2016....
- daveFNbuck 10y agoBut can they charge a lot more if you don't consent?
- gergles 10y agoAs AT&T already did until right before the FCC started talking about this decision (and I'm sure they'll go right back to now that it's OK), charging $30 to opt out of their spying program, plus a bevy of one-time fees that are "waived" if you let them spy.
- Something1234 10y agoWill you post the response to HN?
- devindotcom 10y agojust did, fcc confirmed.
- devindotcom 10y agoThe FCC confirmed that yes, regardless of consent, the ISP can collect 'sensitive' information if it is anonymized/de-identified before use or sharing. The ISP does need to make it clear to the user what information is being collected, but there's no way at present to prevent them from collecting it at all. They're also barred from attempting to de-anonymize the data, though a third party probably could. More info here: http://transition.fcc.gov/Daily_Releases/Daily_Business/2016/db1027/DOC-341938A1.pdf http://transition.fcc.gov/Daily_Releases/Daily_Business/2016...
- bitJericho 10y agoIt can be prevented through the use if a secure proxy.
- thaumasiotes 10y agoA proxy between you and your ISP? How do you talk to the proxy?
- Veratyr 10y agoThe proxy is outside your ISP. The connection between you and your proxy is secure, so your ISP cannot gain anything useful from it.
- bitJericho 10y agoIt sounds complex but it can be had for around 5 dollars a month and a good setup guide if you don't know Linux well.
- shostack 10y agoWhy do you need a good setup guide though? Is there no solution of similar efficacy that I can have my mom, who still uses AOL, install?
- twblalock 10y ago> Interestingly there seems to be a loophole in that they can collect the data regardless of consent, but can't use or share it without consent. So chances are this sensitive data will be recorded and put in a database anyway, even if they're not lawfully allowed to look at it without anonymizing first - but a future law could also add an exception, keeping things for law enforcement for instance. I'm not all that worried about law enforcement. I think it is much more likely that the database will be hacked and the data will just get shared that way. The only way to protect private data is to prevent the ISPs from collecting it in the first place. Otherwise, everyone knows the ISP has the data whether they share it or not, it's a big juicy target, and it's probably not that difficult to get to.
- Drakim 10y agoOr it will be sold without permission in secret, and when it comes to light, the ISP will get a slap on the wrist much smaller than what they gained from selling the data.
- adrianratnapala 10y agoOr simply the stakeholders in the ISP who suffer from the fine and bad publicity are not the decision makers who benefited from the sale.