24 ms·
When I asked Tinder for my data, it sent me 800 pages of my deepest secrets
- midgetjones 9y agoThis is terrifying
- thestephen 9y ago"Some 800 pages came back containing information such as my Facebook “likes”, my photos from Instagram (even after I deleted the associated account)" It's going to be interesting to see how Tinder tackles the 2018 EU General Data Protection Regulation in 2018 and how things will play out in courts and practice. For example, are you allowed to store information that I have chosen to unlink? Will Tinder have an easy way to export the data without having to settle to long email conversations, as there is a right to data portability? If so, in what format will this data be presented?
- Legogris 9y agoDamn, the right to data portability had completely passed by me. This has the potential of being way more of a headache for existing services than the right to be forgotten. It's great, though - I can't wait to see when this gets tested in court.
- slamdance 9y agoI think worst case (best case?) scenario is that they will 'copy' the data they're not supposed to keep off to another country, maybe anonymize it but otherwise the data will still be there. Its too important - even in anonymized form. Its capable of helping sociologists, medical researchers, advertisers, etc... They don't need to know that "James. T. McLovin' of 123 Happy Lane, went on 15 dates and slept with 3 women, prefers brunettes", but knowing that a "John Doe, M, 27, income of $50k, likes rugby, etc..." is good information to have.
- nicktelford 9y agoThe country the data resides in is irrelevant. If the data is about an EU citizen, that's all that matters. I believe the company in question would also need a legal entity in the EU in order for the EU to prosecute them, as I don't think you can take (e.g.) an American company to an EU court. IANAL though.
- slamdance 9y agoeh. Maybe. If they copy the data to a 3rd party in America (i.e. sell the data a marketing company, for "research" purposes), then the EU can't really go after the marketing company. I'm not saying it's right. I don't see why they couldn't anonymize the data (morally or ethically). But, I don't own a marketing company.
- vidarh 9y agoIf a company based in the EU is transferring the data to a 3rd party in America without appropriate safeguards to ensure said data is treated in a way that complies with EU law, then the transfer itself is unlawful, and the EU can go after the company for that.
- stordoff 9y agoThey don't need to. By selling the data on without ensuring the requirements continue to be met, the original company can be taken to court.
- 9y ago
- dogma1138 9y agoConsidering that they've managed to gather all of the author's data in a short time they would fare pretty darn well, for most companies that is the hard part. The GDPR isn't nearly as scary as people set it out to be, and it gives companies a huge amount of wiggle room.
- ATsch 9y agoCould you give some examples of this wiggle room?
- dogma1138 9y agoThe GDPR replaces the right to be forgotten with the right to erasure. But article 17 also gives the following grounds for refusal: Paragraphs 1 and 2 shall not apply to the extent that processing is necessary: 1) for exercising the right of freedom of expression and information; 2) for compliance with a legal obligation which requires processing by Union or Member State law to which the controller is subject or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller; 3) for reasons of public interest in the area of public health in accordance with points (h) and (i) of Article 9(2) as well as Article 9(3); 4) for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) in so far as the right referred to in paragraph 1 is likely to render impossible or seriously impair the achievement of the objectives of that processing; or 5) for the establishment, exercise or defence of legal claims. The first example is effectively a carte blanche to argue nearly any request for refusal in court. The second one allows member states to pretty much tell companies not to delete information, whilst this was set up with compliance in mind, the wording has likely been formatted to also fit other needs such as security and state monitoring. The third one pretty much allows you to keep medical records and insurance information. The forth one is similar to the first with celebrities, public figures and major events in mind (the Gawker clause). The fifth one has been singled out by dating sites and other services such as ride sharing apps as the reason for them to keep data. I am not a lawyer this isn't a legal advice, speak to a legal firm or an auditor for proper advice. I have been working on a few GDPR compliance projects internally for the past year and I've had to speak with quite a few lawyers and they all pretty much said it's actually far better for most companies than the existing framework as long as they can automate data discovery and know where they data comes from and where does it go. You can fight the right to erase the data of a user pretty easily, what you cannot cockup (Art. 15, 20 and 21 of the GDPR primarily) is the ability to disclose what data you have on them and what is it used for which is like I've previously stated the tricky part for most cases. And as far as I can see Tinder pretty aced the tricky part.
- vectorEQ 9y agowhat can i say... welcome to the internet? ;D
- hexadecimated 9y agoI think the more interesting question would be, how much data do they retain on you if you close your account?
- imron 9y agoAll of it?
- adrian1973 9y agoIt sucks that you are probably correct. My own biggest issue with data retention is not that these companies collect all this data (they need to for their business models to work) but that they keep all of it, forever, regardless of whether it could possibly still be relevant to any business purpose (such as chat conversions from a decade ago).
- sanxiyn 9y agoI actually think chat conversation from a decade ago would be quite relevant. One baseline recommendation system is "people who bought X also bought Y". Consider "people whose conversation is in cluster X generally liked people in cluster Y". If chat conversation can be usefully used to cluster users for better matching (and I think it can), it would be valuable to keep even if content is of no interest.
- adrian1973 9y ago> even if content is of no interest. Can't they just keep (at most) the metadata?
- sanxiyn 9y agoAs a data scientist, I think losing actual words would be a loss. Words would be only used by word embeddings like word2vec, but actual words let you switch to better word embedding later.
- 9y ago
- fny 9y agoWow--there's some pretty intense SEO in the slug for that URL: tinder-personal-data-dating-app-messages-hacked-sold
- vanderZwan 9y agoThey're all keywords relating to the topics discussed in the article, aren't they? I wouldn't be surprised if it was auto-generated from keywords that the author can assign to their article.
- js8 9y agoI believe Guardian generates the URL from the title of the article. It is possible however that the title was later edited.
- grecy 9y agoI assumed everyone used a fake FB profile for Tinder... is that not the case?
- isatty 9y agoObviously not.
- wingerlang 9y agoI doubt even 0.1% of their users does that.
- dEnigma 9y agoI certainly didn't when I tried it. Every Tinder user I know uses his actual FB profile.
- sbierwagen 9y agoYou have to have a minimum number of friends, and the account itself has to be older than a certain amount, in order to use it for Tinder.
- anc84 9y agoI wonder what Snapchat would return. All the messages ever? Regardless of their pretend volality? Someone please try it, I don't have an account.
- cdancette 9y agoYou can request your data here https://accounts.snapchat.com/accounts/downloadmydata https://accounts.snapchat.com/accounts/downloadmydata. The data is : Data Available In-App · Username · Email Address (current) · Phone Number (current) · Birthday · Name · Snapcode/Profile Picture · Snap Privacy Settings · Stories Privacy Settings · Friends (Contacts) · Blocked Friends · Snapcash Transactions Data Available for Download Account History and Information Snap Count Local, Live, and Crowd-Sourced Content History and Information Purchase History Snapchat Support History Content and App Engagement History Demographic Profile
- gourou 9y agoTheir position is: "Snaps are deleted from our servers after they have been viewed by the recipient".
- ronnier 9y agoRumor is that snap keeps messages in google cloud compute encrypted. When messages are expired or read by the user, they just delete the encryption key.
- emodendroket 9y agoWhy would they do that? Keeping around a bunch of blobs nobody can decrypt seems like a huge waste of resources.
- avenius 9y agoI'm somewhat curious about the verification process here. Wouldn't this be a prime target for would-be blackmailers?
- spodek 9y agoI can't believe Eben Moglen's FreedomBox isn't a bigger project. It would help solve a lot of these problems. https://en.wikipedia.org/wiki/FreedomBox https://en.wikipedia.org/wiki/FreedomBox https://freedomboxfoundation.org https://freedomboxfoundation.org
- mynewtb 9y agoWhile I love that project I don't see how a tinder-like dating app would work on it.
- zoltaan 9y agoI always felt a bit silly logging in to Facebook in a private browser window in every other week, many times through a VPN. Also not sharing much more than jokes and cartoons or memes. Not to mention my absense from the hip social web, including Tinder, but many more as well. I don't feel silly anymore. :) (btw: my name is not zoltaan ;) )
- beager 9y agoOutliers such as yourself won't do much to curtail the practice of companies amassing identifiable, weaponizable, and often undersecured data about their users. And because the data is valuable and there have been few regulations put in place to balance that value with the burden of responsible handling, those companies will continue to collect more and in more creative ways, whittling away at your creative maneuvers to avoid it. In my estimation, this is a good first step, but privacy has to be a feature of the system, not just a heavy shield you carry through it.
- lordCarbonFiber 9y agoI just don't see the doom and gloom. You say "weaponizable" but even the worst offenders for oversharing aren't giving facebook information that seems that bad? Compare the data talked about in this article (likes, jobs, dating preferences) to data that already is public knowledge and avaliable to everyone: (assuming US) how much you payed in property taxes, where you live, what your phone number is, which political party you're registered to vote in (depending on the state this might also be linked to your telephone number or even last 4 SSN), all documents related to any companies you may have incorporated. Your public data footprint is far more expansive than the tiny slice companies like tinder and facebook have. The only reason they don't bother linking to the public realm is that personal data (unaggregated) is worthless from the prospective of "building models to sell adds".
- eksemplar 9y agoThey still build profiles on you though. When you phones wifi is near someone with an android phone or a Facebook app they'll handshake and tell the interwebs where you are and with whom.
- wakkaflokka 9y agoHow would an individual get access to their data without a lawyer?
- pdehaye2 9y agoEmail Chommy, the data protection robot: Chommy@PersonalData.IO
- donquichotte 9y ago> A few months earlier, 70,000 profiles from OkCupid (owned by Tinder’s parent company Match Group) were made public by a Danish researcher some commentators have labelled a “white supremacist”, who used the data to try to establish a link between intelligence and religious beliefs. The guy's name is Emil Kirkegaard and the paper and data is still available. I skimmed the paper and have no idea why he was labled a "white supremacist", or by whom. ("some commentators", really? Is this journalism?) [EDIT] paper: https://openpsych.net/files/papers/Kirkegaard_2016g.pdf https://openpsych.net/files/papers/Kirkegaard_2016g.pdf dataset: https://www.reddit.com/r/datasets/comments/4jj53i/here_is_a_mirror_for_the_okcupid_osf_emil/ https://www.reddit.com/r/datasets/comments/4jj53i/here_is_a_...
- vijayr 9y agoIs there any tool (chrome extension or whatever) that'll take an article and give thumbs up or down depending on crap like "some commentators", "anonymous sources", "allegedly" etc? So people can simply skip over such articles?
- aaronhoffman 9y agoI tried to create one once that would do this and follow the author around to other articles. Could not figure out the go to market strategy. Still have the domain betweenTheBylines .com
- pdehaye2 9y agoHi, I am the person who is cited in the article and who helped Judith get access to her data. If you are interested in the OKCupid story, Judith also wrote about this in more details, also with my input. https://www.letemps.ch/sciences/2017/04/07/laboratoire-fake-science https://www.letemps.ch/sciences/2017/04/07/laboratoire-fake-...
- donquichotte 9y agoThanks for the clarification. Just a brief look on the titles of the Kirkegaard's other publications seems to confirm that he appears to have a deep interest in immigration, genetics, crime and IQ. One of his independent papers even mention cranial volume, which sounds vaguely familiar: https://en.wikipedia.org/wiki/Scientific_racism#Craniometry_and_physical_anthropology https://en.wikipedia.org/wiki/Scientific_racism#Craniometry_...
- zokier 9y agoI think Tinder specifically has far better grounds for having all this data than most tech companies. After all it is their core function to try to match people, and to do that well you need to know the people.
- emodendroket 9y agoI wouldn't go so far as to say they need all this data. The service could work fine with just self-reported preferences and profiles if you wanted it to.
- throw-away-8 9y agoSelf-reported preferences and experimentally observed preferences are not the same.
- emodendroket 9y agoI agree, but I don't know that that is such an impediment that the app wouldn't be usable.
- sanxiyn 9y agoThere is actually lots of business value in this data. One research https://arxiv.org/abs/1401.5710 https://arxiv.org/abs/1401.5710 found: "There is significant discrepancy between a user's stated dating preference and his/her actual online dating behavior." For how much discrepancy, read the paper.
- 201709User 9y agoBesides "western girl had lots of Tinder sex and some of it was kinky" is hardly a secret, more of a default.
- doktrin 9y agoIn theory, sure. In practice, Tinder seems to be a pretty blunt dating instrument. I'd be surprised if A / B testing a data-driven vs. non-data-driven match would yield significantly different user experiences.
- Overtonwindow 9y agoDating websites are, quite possibly, worse for our privacy than any social network ever invented. Consider this: A website like OkCupid can go much deeper than Facebook in understanding who you are, and what makes you tick. This is invaluable to marketers, and the government for that matter. I avoid dating websites because whose to say this data can't be used by others, such as insurance, employment, or the police? The following exchange from the television program "Person of Interest" I think is quite telling, albeit tongue in cheek, as to this threat: https://www.youtube.com/watch?v=DPirWp2oAJ4 https://www.youtube.com/watch?v=DPirWp2oAJ4
- NiklasMort 9y agotip for starters: never ever use your real identity for online services if not absolutely necessary
- emodendroket 9y agoThat seems a little hard to navigate on a dating app.
- NiklasMort 9y agoWhy? Lot of people use aliases or nicknames. I never had issues doing that.
- emodendroket 9y agoI'd have to imagine it'd put some people off.
- goialoq 9y agoIt's just another factor in computing compatibility. There was a time when attaching your real identity online was considered a major safety risk. That time hasn't past.
- NiklasMort 9y agoNever had that, actually lot of people don't use their real names on dating sites or even FB. And if someone asks you say its for privacy reasons, people do understand. Look at Okcupid, its all nicknames there ;) same goes for other sites. Same goes for Apps.
- aaronhoffman 9y agoIn the EU, when I ask for my data, do I have rights to "views" of my profile?
- forgottenpass 9y agoAside form the ethical considerations of long term storage, what is tinder doing with all this data if they can't even keep the bots off the service?
- deleted 9y ago[deleted]
- emodendroket 9y agoWell, for instance, if your chat log still hangs around if you message the same person then it has to be on the server. A lot of stuff might be similar (don't show people you've already seen, etc.). The chat geolocation stuff though who knows.
- colecut 9y agoI think they just don't try to keep the bots off...
- deleted 9y ago[deleted]
- calimac 9y agoThis is why I love the legislative petri dish over there in the EU.
- turc1656 9y agoIt just dawned on me that Tinder is basically the new and improved version of Zuckerberg's original creation - Facesmash. Except Tinder can do so much more than that. And amusingly, Tinder is hailed as a great app while Facesmash was decried as a way of dehumanizing and objectifying people. My, how far we have come.
- blevs 9y agoI think a big part of that is people consent to being on tinder.
- dopamean 9y agoAbsolutely. That also says something about the difference in the times. Zuckerberg forced people onto Facemash probably because he thought it would be easier than getting people to sign up voluntarily.
- ZoeZoeBee 9y agoDo people forget HotOrNot?
- colecut 9y agoI actually know a couple who met on hot or not, and are now married. I didn't even think this was possible, but it turns out there was a comments section...
- teetermld 9y ago880 matches holy shit, that has to be 8x as much as the average guy. Life must be so easy.
- thunderman10 9y agoThat's around 220 matches a year since shes had the app, so like 18 matches per month for four years... She matched with a new guy every two days basically, and he mentioned she only sent 1700 messages since she started. That's almost two average messages per match before getting bored and moving on. With that much abundance of choice, I guess you could say life is nice and easy for the author.
- emodendroket 9y agoWell, you could say that, but is it true? Perhaps the post-match experience isn't necessarily very good, and anyway I'm not sure raw quantity maximizes anything normal people care about.
- doktrin 9y agoThe going stereotype about Tinder is that most men (all but the most attractive) match poorly while most women (all but the least attractive) match well - but that (again, most) women nonetheless experience a lack of communication post-match.
- emodendroket 9y agoWell that makes sense since you hear about men just indiscriminately saying yes to everyone. And you also have to imagine that some of the comments are just obscene catcalls rather than attempts at conversation.
- michaelchisari 9y agoWomen have more matches, but a worse experience. Men have less matches, but the matches they get are better. Which is better, getting 1,000 matches in a day, when 999 of them are people who just swiped right no matter what, or who are downright rude, aggressive or poor communicators? Or getting 2 meaningful matches in a day from people who actually want to meet you and might be a good fit for a relationship or friendship? The first is just a bunch of noise with no signal. The second is preferable. And plus, I'm a guy and I would easily get 3 or 4 matches a day when I was on Tinder. It's not like men are completely ignored on it. I'm hardly a supermodel, but nice pictures and a well-written profile can go a long way on online dating. Plus living in a high-population city.
- Jdam 9y agoTl;dr Tinder stored her messages and pics and she was embarrassed reading them again.
- npsimons 9y agoShit, if I dig deep enough in Usenet or my email archive (going back to the nineties!), I can easily find some cringe worthy things written by me. It's actually rather humbling and enlightening.
- y04nn 9y agoI just downloaded a 16GB archive from https://takeout.google.com/settings/takeout https://takeout.google.com/settings/takeout I'm impatient to see what it contains. Update: I have forgotten to unselect Google Photos and GMail, that's what takes most of the space.
- dejawu 9y agoI got fed up with Tinder's Android client and reverse-engineered their API (this was back when the Android security model let you use mitmproxy). Two things stood out to me: 1. The AI was kind of hacky. Updates were done by polling rather than push. There were a lot of unused fields - for example, "remaining likes" would hang at 100 until the likes were used up, then it would go straight to 0. 2. They tracked absolutely every action you took and sent it to a different server from the API requests. Opening settings, opening your own profile, opening someone else's profile - it was all logged. They knew exactly what you were doing in the app and for how long. It wouldn't surprise me nowadays if this is standard practice but it was eye-opening to see it happening firsthand.
- trollopTheJope 9y agois it feasible to do this protocol reverse engineering without mitmproxy?
- bitexploder 9y agoYou would have to tear apart the Android app itself. If it isn't obfuscated, it usually comes out pretty clean. Depends on how they implement things from there, but you could in theory reconstruct all their calls to their backend from the code. If they have an API/HTTP client that wraps it up nicely it often simplifies this chore from a static analysis perspective. You can still use MiTM HTTP proxies pretty easily. If they don't pin certificates it is trivial. If they do pin certificates you have to understand how they are doing it and break that. Often trivial to easy, but requires an app-specific approach. We haven't met an Android or iOS app using HTTPS that we could not MiTM yet. Usually without a lot of effort. Some times with a small to moderate amount of effort (a couple hours to a day of poking the app/code/certs).
- majormajor 9y ago> 2. They tracked absolutely every action you took and sent it to a different server from the API requests. Opening settings, opening your own profile, opening someone else's profile - it was all logged. They knew exactly what you were doing in the app and for how long. Are there always-connected apps that don't do things like this? It's always seemed like an obvious source of usage research data that the product team isn't going to want you to forego. A lot of apps are A/B tested for new features, I would assume this is where the results come from.
- spullara 9y agoIt seems really dangerous that you can ask for and get this data en mass. How do they really verify it is you? Can that be easily social engineered?
- jacquesm 9y agoThe Ashley Madison hack [1] will look like a walk in the park if and when Tinder gets breached. [1] https://en.wikipedia.org/wiki/Ashley_Madison_data_breach https://en.wikipedia.org/wiki/Ashley_Madison_data_breach
- kristianp 9y agoIt's scary that this data can be kept for years without the user being aware of it. If this data was breached it would be worse than Ashley Madison. I suggest there should be laws that say users should be given the option to delete data older than x months selectable by the user. It seems obvious that sensitive data should not be kept indefinitely after following https://haveibeenpwned.com https://haveibeenpwned.com .
- nomoarcookies 9y agoTinder is like GNU social, no actual conversations. Fake news