10 ms·
When the business model is the privacy violation
- ianstallings 8y agoWith new regulations like GDPR coming online FB's business model is basically kaput. They're going to need to rethink their whole stance if the world follows EU's lead. Given that Zuckerberg was called to testify in front of congress, I think we're probably going to see much more action.
- mysterypie 8y agoI wish you were right, however, just because a Congress called a hearing doesn't mean a sea-change in laws and practices. Congress looked into personal information collected by the NSA (post Snowden) and consumer credit reporting agencies (after numerous hacks and leaks). Did their business models go kaput? Did anything change in a big way?
- rhizome 8y agoCongress essentially spent two days begging Zuck to do their jobs for them, asking the fox to design the henhouse. His testimony is not required for passing privacy legislation.
- lotu 8y agoSeveral of them also were asking what chickens where and why one would desire to own chickens in the first place. The whole thing is very sad the point of this is for each congress person to get to feel special by getting to look down and act tough against Zuckerberg. They didn’t even spend the effort to do basic research so they didn’t waste time answering questions that could be answered by using facebook.
- idoh 8y agoOn the contrary, the GDPR helps Facebook. As background, I am a product manager dealing with GDPR issues right now. The requirements are quite onerous, but they are not intractable. I am sure that Facebook, with their army of engineers and lawyers will be able to find a way. Facebook already has traction, and if push comes to shove can anonymize their data so it is at least still somewhat valuable. However, the window is closing for any new social networks to get started, because the startup costs are simply too high and you can't growth hack like you used to. What I am saying is that it is quite reasonable to assume that Facebook will be the last social network out there, that they will survive and no new competitors can emerge. If any hope of competition gets removed, then that benefits FB.
- lotu 8y ago100% to this. I’m an enginer also working on GDPR and you sound exactly like my product manager. GDPR is likelly to result in the number of advertising technology companies going from thousands to dozens. One of the requirements is that you inform users who you are sharing the data with. If you have a list of ~10 companies is allowed under GDPR, but a constantly change it list of 500 companies is not. The result massive consolidation. This is very ironic because one the the complaints of the EU against companies like Facebook or Google is that they are monopolies in the advertising space, and then they passed a law that will have the effect of force it their competion out of the market place. It’s a real shame that no one is really covering this aspect of GDPR.
- forapurpose 8y ago> One of the requirements is that you inform users who you are sharing the data with. If you have a list of ~10 companies is allowed under GDPR, but a constantly change it list of 500 companies is not. The result massive consolidation. Are you saying that GDPR puts a limit of between 10 and 500 on the number of companies you share data with, or are you saying that it's impractical to share a constantly changing list of 500 companies with the user? The latter seems easy to do: Just create a webpage and keep adding the names of new companies. Email a link or the list to the user as needed. Do I misunderstand?
- PeterisP 8y agoAs the adtech data sharing usually doesn't fall under any other legal reasons that would allow you to use that data, you need to get consent for the new companies. If the user ignores your email and takes no action (doesn't opt in), you don't have their consent, and can't share their data with the new companies. But IMHO that's the whole point, the legislation is a response to users saying that they don't really want such companies to exist - the business practice of taking my private data and sharing it to the world 500 companies will now require my explicit opt-in freely given consent (i.e no "we'll refuse service if you don't consent"). The expectation and intent of this law is that I and pretty much every one else will simply not provide that consent, and that business practice will become impractical and die out, as it should.
- return1 8y agoPeople are bound to be disappointed by the effects of GDPR. FB can reasonably claim that its tracking is necessary for its function , because it is. The stuff they ll have to get rid of is marginally profitable anyway. GDPR is not hurting facebook, instead it's legitimizing its model in the eyes of the consumer by giving it the "stamp of EU approval".
- seanhunter 8y agoI agree with your assertion that if GDPR expectations are high, they will be disappointed, however the "legitimate interest" claim doesn't trump the data subject's right to privacy in GDPR. As I understand it, you can only really claim legitimate interest if you're not doing any kind of direct marketing and are able to show that there is not undue impact on the data subject. There's a lot of conflicting information about this on the web but the actual language of the directive is pretty straightforward. “The legitimate interests of a controller, including those of a controller to which the personal data may be disclosed, or of a third party, may provide a legal basis for processing, provided that the interests or the fundamental rights and freedoms of the data subject are not overriding, taking into consideration the reasonable expectations of data subjects based on their relationship with the controller. Such legitimate interest could exist for example where there is a relevant and appropriate relationship between the data subject and the controller in situations such as where the data subject is a client or in the service of the controller." If you don't have a facebook account for example, you don't have a relationship with them and therefore have a reasonable expectation that they would not be tracking you. Edit: Granted, the language is somewhat ambiguous and we won't really know how this shakes out until there is established case law later in the year.
- nemothekid 8y agoAFAICT, there's nothing in the GDPR that technically prevents Facebook from existing. At worst I'd imagine that the GDPR will just kill the Facebook developer platform (or more likely, neuter it beyond usability). All the GDPR does is prevent companies from being fast and loose with user personal information without their awareness - they are still free to monetize it, and I bet the vast majority of the world will still be happy to use Facebook despite what warnings the EU gets to put on FB. I'd imagine most new social networks (if any, the last large social network I can think of Snapchat is 6 years old), will simply try and prove out their network in US first, then hire regulators to figure out GDPR, if the US pass their own GDPR. Honestly, despite the good intentions of these laws, which I think are good, I think they will just further cement the Google/FB digital advertising duopoly. If you are starting a new social network today, I'd imagine your business model is "capture $demographic that fb poorly serves and get acquired into fb before you become viral in the EU"
- textmode 8y agoOne argument he raised in the House hearing was that collecting data on users allowed more targeted ads which in turn made ads more efficient and therefore more economical, which levels the playing field more for small businesses versus large ones in terms of advertising. However, that is an argument favoring the customer, i.e., the advertiser, not the product, i.e., the user. During the Senate hearing, he was asked about Ms. Sandberg's comment that if there were no ads then users would have to pay. Mr. Zuckerberg pointed out that users can opt-out of ad targeting/data collection,[1] making the ads they receive more generic and less "relevant", but currently Facebook offers no option for users to pay not to receive any ads at all. The still unasked question is, "Why not?" If some users could not afford to pay, as Mr. Zuckerberg suggested in both hearings, then they could opt-in to advertising. How would this affect the business model? Further, if those users were disappointed at how the ads they were being shown were not "relevant", then they could opt-in to ad targeting/data collection. 1. The default setting is opt-in. As we know, most users do not change default settings.
- return1 8y agoi m kind of surprised that they have not asked these questions to google. Also: - Making ads relevant means less ads overall for the user - It would cost $20 / year and no studies show that users would pay anywhere near that. It reasonable to assume its impractical - Subscription-premium services rely on a small number of fans to pony up (usually significantly) for the rest of users. afaik facebook does not have such a mass of hardcore, passionate fans. - More generally there is no evidence that subscription users are happier.
- default-kramer 8y agoI have been thinking about what would happen if all browsers had perfect ad blockers enabled by default, starting tomorrow. I think years later we would look back and decide that it was the right thing to do, despite the immediate short-term economic damage.
- return1 8y agoadvertising would just shift to product placement in the news you get and affiliate links everywhere. not better. people tend to forget that advertising covers a real need.
- IBM 8y agoI think this op-ed is very relevant to this [1]. There's no doubt the internet companies will aggressively oppose any attempt to pass privacy legislation in the US, but there's no reason why that needs to be all tech companies. Apple, Microsoft, IBM, etc could play a major role in balancing their influence. [1] https://www.nytimes.com/2018/04/11/opinion/silicon-valley-lobbyists-privacy.html https://www.nytimes.com/2018/04/11/opinion/silicon-valley-lo...
- DesiLurker 8y agoI just wanna say one thing about this, when I found out that FB was looking to find healthcare data from hospitals and other providers to like to peoples profile it sent the chills up my spine. that is seriously creepy. if something like is available then probability of it being abused is almost 1. right now my facebook usage is fairly low but I'll delete my account for sure if there is any truth to that.
- lotu 8y agoThat sounds like an explicit HIPA violation and is very much against the law for both the hospital to share the data and Facebook to do that linking. It sounds tin foil hat conspiracy to me.
- pwinnski 8y agoThere is no evidence that any hospitals agreed, but it is no fantasy or conspiracy that Facebook tried. https://www.theverge.com/2018/4/5/17203262/facebook-medical-data-sharing-plan-healthcare https://www.theverge.com/2018/4/5/17203262/facebook-medical-...
- spacehome 8y agoFacebook isn't a healthcare provider, so they're not bound by HIPAA.
- DesiLurker 8y agoits most definitely not a tin foil hat conspiracy, refer [1]. a quick google will yield many more. regarding the HIPAA violations it is true that hospitals cant share the data, that may be the only saving grace for now but are you certain there is no loophole that can be exploited? or may be introduced in next budget? Also its definitely not illegal for FB to do the linking should they come across such data. I'd accuse you of naivety if you assume that not the direction they want to head into. there are many scenarios I can think of that make the problems exponentially worse especially for people in countries without a well functioning justice system. IMHO the best course of action is to starve the beast. 1. https://www.theverge.com/2018/4/5/17203262/facebook-medical-data-sharing-plan-healthcare https://www.theverge.com/2018/4/5/17203262/facebook-medical-...
- yuhong 8y agoMy Google DoubleClick Mozilla essay talks about this exact topic: http://yuhongbao.blogspot.ca/2018/04/google-doubleclick-mozilla-essay-final.html http://yuhongbao.blogspot.ca/2018/04/google-doubleclick-mozi...
- lotu 8y agoAn interesting if rather long read. However I’m not sure if your solutions of voluntary donations and cryptocurincies have viability. Voluntary donations have high friction to get a user to start donating (You don’t want to donate to a site you only visit twice and who knows if you will visit the site in the future). Cryptocurincies are unproven at this point. You also don’t mention how targeted advertising is critical to many small business. If you have niche or specalized product it can be very difficult to find people that want to buy it, you are limited to only places where those people are in high concentrations, it is quite reasonable to expect that the elimination of targeted advertising would quietly erase these business as they are no longer able to find their consumers. Diffrent payment models don’t address this.
- yuhong 8y agoIt is unfortunate that it is not more famous. I did mention that there are sites that depends on targeted advertising that would be affected in the final version of the essay, though there is not much detail about it. Feel free to come up with other solutions BTW. I have a Google Group you can join: https://groups.google.com/forum/#!forum/google-mozilla-problems https://groups.google.com/forum/#!forum/google-mozilla-probl...
- CryptoPunk 8y agoA more accurate title would be: the government revenue model is the privacy violation. Governments cannot be genuine allies of the people against corporate surveillance, and for example, encourage privacy technology like public key cryptography, and client-side encryption, when their primary sources of revenue: the income and sales tax, depend on rampant and overt criminalization of privacy (KYC laws, income disclosure laws, record keeping mandates on the private activity of private citizens, etc).
- zmmmmm 8y ago> Thus, hashing completely fails to address the underlying privacy concerns I don't understand their argument against pseudonomous identifiers (well, part of the problem is they present it without a lot of argument). Are they arguing that companies will reverse the hash, or that they will de-anonymise it using additional data? Otherwise it seems harmful to me to tell people that using a different identifier per web site is useless (a bit like telling everybody that locking your car is useless because a determined thief would break in anyway...)
- BadassFractal 8y agoIs it fair to say that privacy violation as the business model is generally more profitable than privacy as the business model?
- manjushri 8y agoIf information is power, then that is like asking if having more power is more profitable than having less power.
- known 8y agoI think every website should comply with https://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Security_Standard#History https://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Sec...
- throw2016 8y agoSpyware and adware 10 years ago were considered extremely shady and unacceptable and certainly not in the mainstream like now with Google and Facebook. Who would have thought then it would take these shady practices a mere 5 years to transition into the mainstream. Advertising via textual context and immediate location is ok. Everything else is a dark pattern and incentivizes uncontrolled surveillance, profiling and data hoarding and should automatically be disallowed in a civilized society.
- crowbots 8y agoFunny story, i have never seen any ad anywhere in the internet or never clicked on any one for sure. i wonder why product makers pay so much for advertisement to google n fb. i have seen advertisement in tv when i used to watch tv a lot and am sure i have never bought those stuff jus because they advertised them, most of time we will just swap channels for few mins and advertisement wud b gone away. And in internet it is very effortless to jus scroll past stuff that we are not paying attention to, i guess i most of the time ended up scrolling thru ads, thats y i dont remember buying anything because i saw some ad.