5 ms·
Thing is, as an industry nerd i understand implicitly what FB are doing with their services, and yet i still use the messenger app to keep in contact with some
by ry_ry 10y ago
Thing is, as an industry nerd i understand implicitly what FB are doing with their services, and yet i still use the messenger app to keep in contact with some of my friends.
Ultimately I'm relatively comfortable trading some measure of my privacy for convenient communication with people whose friendship i value and might otherwise struggle to keep in touch with.
If I'd purchased myself a physical good, regardless of it being a sex toy, I'm not sure i would necessarily expect to be entering into the same agreement.
My fridge phones home, but my kettle doesn't, my TV is a CIA outpost, but my wallet is just made of cows and Faraday cages. Granted the app connectivity would be a red flag, but ultimately there needs to be some kind of 'privacy mark' in the same way films carry a cert to allow us all to instantly understand what using it will entail.
For me that is the key difference here, and something that needs to change.
- Stanish 10y agoI think the delusion you have fallen victim to here is that it all boils down to your personal choices. The issue is not whether--for you personally in the market--it makes sense to delete your facebook. The important point that outrages people rightly is that the system has evolved in such a way that the choice is not a reasonable one to have to make (between friends and privacy). We need policy changes that separate the choice to have privacy from state/corporate knowledge of our intimate lives from the choice to make connections with friends, advertise, reach out to the world, etc. The market as it currently exists is not an adequate mechanism to achieve these changes. The business model of people-farming and super-stasi state spying is the polar opposite of the utopian promises made by many in this industry at the emergence of the internet, and there need to be concrete proposals to stop it from every arena, because there will certainly be far more dire consequences as it evolves if it isn't checked in a comprehensive, thoughtful way.
- 33W 10y agoI like the idea of a privacy classification system, along the lines of movies or video games. With at least some public focus on privacy, perhaps this is the time to create an industry standard?
- svachalek 10y agoI've been wishing for something more along the lines of open source licenses. GPL might be a complicated contract but once you know it, all you need is 3 letters to describe it. You've still got the option to write up your Special Snowflake 1.0 license, but most products won't need that or want it, so a few common contracts emerge and then we don't all need to skim pages of legalese (subject to change at whim) every time we visit a new website.
- follower 10y agoA standard could certainly contribute to informed consent by the people who purchase/use devices. It's a complex concept to summarise and distill into iconography though. (See also my comment to parent post.)
- pdkl95 10y agoThe problem with discussions about "trading privacy" is the tendency to think only about known, temporally local risks. The actual risk from surveillance from the current "smart"-device manufacturer today or in the near future is probably low. We are used to information deteriorating over time, and the non-zero cost of distribution and analysis limiting how far information about you could spread. Our heuristics that estimate risk are not prepared to evaluate risks that extend indefinitely into the future. You say your are comfortable trading (some) privacy. Are you prepared for that data being sold/hacked/subpoenaed after 20 years? Are you sure you're comfortable with future machine learning tricks and other advanced analysis techniques reconstructing a detailed patter-of-life from several decades of data? The worst ways to abuse all this surveillance data probably hasn't been discovered yet. Nobody should be comfortable trading away their privacy, because we don't even know the risks. We only know that risk only increases with time. A "privacy mark" doesn't help (much). Instead, what we need is an education campaign similar to anti-smoking efforts that attempt to realign the common wildly inaccurate perceived risks to be a closer match to the actual risks.
- lovemenot 10y agoCompletely agree with your diagnosis. As for the prognosis, social policy may be a good idea, but it is not what HackerNews readers are best positioned to facilitate. Rather, we should be implementing technologies to faciltate the increase of entropy in information actually and unavoidably collected. Plausible deniability will be the best safety net against future risks unknown. If my dildo is publicly known to have reported its use whilst I was also known to have been watching Trump's Presidential Address (don't ask!), I would have an out in that all such data has long been known to have been poisoned. Spam is our friend.
- follower 10y ago> ultimately there needs to be some kind of 'privacy mark' in the same way films carry a cert to allow us all to instantly understand what using it will entail. That was the direction we were wanting to go with the Private Play Accord mentioned at the end of our DEF CON presentation: http://www.privateplayaccord.com/ http://www.privateplayaccord.com/ We got as far as drafting an initial star-based grading system but turns out writing code is easier... :) Was made aware of this earlier initiative today: http://designswarm.com/blog/2015/09/what-does-it-do-a-proposal-for-connected-product-labelling/ http://designswarm.com/blog/2015/09/what-does-it-do-a-propos...
- _audakel 10y agoThis is a cool idea. Having an independent rating company look at products and score them on privacy or security. May be hard to find back doors tho.
- codedokode 10y agoThere should be no privacy marks. The companies just should not collect any "anonymous" "analytics" without user's permission.
- brokenmachine 10y agoPlease define "anonymous analytics". Is a log of ip addresses and times that your smart toaster was used acceptable? What if said smart toaster really needs to contact a server to decide exactly how long to heat the toast for? It's difficult to have an internet-connected widget with an App that doesn't generate some kind of information in logs somewhere. I agree with you but I think it's something that needs laws around it, and unfortunately can't be simplified down to your one sentence solution. Unfortunately with the apathy of the general population and the flat-out corruption of our own untrustworthy governments, I think those laws are unlikely to materialize.
- codedokode 10y agoYes, there is some information that can be collected, for example, in server logs. But does the company need to keep those logs forever? And does it need to collect it all? But the problem is not only in the IP addresses. Companies just want to save everything they can collect. Remember Amazon Echo that was storing everything said to the device on the server. And almost every mobile app now has Google Analytics or similar system inside. It is obvious that companies do this for profit because the information could have some commercial value and could be sold later or used for marketing purposes. But the users want the device just to serve its purpose and not to be a modern implementation of a telescreen. I think this problem can be only solved by government regulation too. So for example a store owner that has a CCTV system would not be allowed to keep the records forever or recognize faces on the video and sell this information to marketers. A security system should serve just its purpose. > It's difficult to have an internet-connected widget with an App that doesn't generate some kind of information in logs somewhere. The server can be run on the phone or user's computer or router. Why should the data from the toaster travel across the world?
- 10y ago