16 ms·
How my sexual health searches ended up in the hands of big tech companies
- jlangenauer 8y agoFurther proof, as if any was needed, why other countries require something like the GDPR, backed up be significant penalties, and well-resourced enforcement. It won't happen in Australia though, as we are governed by fools who barely understand technology, and if they need to, rely on the representations of business to make any decisions.
- humanetech 8y ago> we are governed by fools who barely understand technology This is an argument heard all around the world with regards to similar issues. I wonder to what extent it actually applies, and it is not your latter statement - that lobbying and commercial interests are at play - that is prevailing (so they are 'willing fools'). Hard to know, of course, but I'd say these lawmakers need not have to know the intricacies of the technology themselves, but can rely on accurate reports detailing their implications in layman's terms. They can have expert advisory groups do the hard work for them.
- eigenvector 8y agoProviding knowledgeable, disinterested advice to politicians is what the civil service is supposed to do. In Westminster style democracies, anyway.
- brokenmachine 8y ago"Any sufficiently advanced incompetence is indistinguishable from malice".
- 52-6F-62 8y agoI caught some brief clip on the news last night about Canada looking at introducing something similar to the GDPR. Can’t find any details in a quick search though.
- nihonde 8y agoHas GDPR meaningfully changed enforcement of rights? I’m familiar with the law itself and the details of it. (IAAL who practices in this area.) I’ve seen these regulatory pushes toward consumer-oriented privacy in the past, and they seem to serve the consulting industry above all. The consequences of breaking the rules are laughably impotent so far, despite more or less well-meaning words passed as binding legislation. Even the reputational damage of having your company featured in headlines about data leaks has fizzled. People don’t even seem to punish the offenders by shifting their spending habits. Am I wrong?
- guitarbill 8y ago> People don’t even seem to punish the offenders by shifting their spending habits Well, if that was viable, we probably wouldn't have needed such high fines in the GDPR. Two scenarios: A) It's hard to move away because of dominance, e.g. Google. You either have to buy an offensively expensive iPhone, or root an Android phone. Even then living without the Play store is hard. Moving e.g. email providers takes years nowadays regardless of the provider. Google Search and Maps can be replaced in theory, but it's quite a chore - Google didn't get big on bad products. B) What spending? How do you stop spending on something you aren't paying for with money? Yes, ad and tracking blockers, but for Joe Bloggs that isn't obvious. And Consumers weren't paying Equifax directly, otherwise they probably would have been bankrupted. > Has GDPR meaningfully changed enforcement of rights? We don't know yet. (I'm assuming this isn't a rhetorical question.) On the one hand, the fines now have business impact. For example, before the GDPR, the UK's ICO could only hand out a laughable max fine of £500,000. On the other hand, ICO has been toothless, only handing out the max fine once. ICO was severely underfunded, so this is almost by design. Germany is pretty privacy conscious, but unfortunately data protection is also handled on a state level. So there are 16 data protection agencies and one federal one (Datenschutzaufsichtsbehörden, the federal one being the BfDI). From experience, that kind of bureaucracy doesn't help with speed. While this isn't enforcement, it has had some meaningful effect. Having worked for a big multinational, there was a lot of money and hours spent on GDPR compliance. This reduces e.g. data retention, which could help limit damage in future. Before that, data retention was basically endless. We've seen some minor cases, but being a lawyer, I'm sure you know we're at least a few years off the really big cases, especially if the European data protection authorities need to work together.
- chongli 8y agoFrom the perspective of a casual, non-European observer, the only effect of the GDPR that I've witnessed is the explosion of websites being extremely aggressive about forcing me to consent to their tracking cookies. Where is the real benefit to Europeans' privacy?
- MaxGabriel 8y agoAre you potentially confusing GODR with the EU cookie law?
- guitarbill 8y agoGDPR is just the newest privacy law, a lot of EU countries had privacy laws before GDPR. So it isn't that radical, but the fines are bigger. We've already seen quicker reporting of breaches. Web trackers are down [0]. Telemetry without an off-switch has been ruled in violation (Microsoft Office [1]). In smaller cases, apps that don't secure passwords properly have been fined [4]. I'm sorry for linking to el Reg so much, but there just aren't that many English language news outlets covering these things. As for "forcing me to consent", it violates the GDPR (e.g. [2], ICO "consent cannot be freely given and is invalid"). This is largely websites trying to see how far they can push it, because the data protection agencies aren't handing out fines straight away. This is actually very frustrating in obvious cases. If you'd like to help getting rid of them, but aren't a European or can't be bothered reporting them to the relevant data protection agency, Max Schrems has founded https://noyb.eu/ https://noyb.eu/. Privacy international has also done some work in this area [3], but Schrems seems to be focussed on the "smaller" violation such as popups, and has a great track record. [0] https://www.theregister.co.uk/2018/10/12/gdpr_helps_google/ https://www.theregister.co.uk/2018/10/12/gdpr_helps_google/ [1] https://www.theregister.co.uk/2018/11/16/microsoft_gdpr/ https://www.theregister.co.uk/2018/11/16/microsoft_gdpr/ [2] https://www.theregister.co.uk/2018/11/19/ico_washington_post/ https://www.theregister.co.uk/2018/11/19/ico_washington_post... [3] https://privacyinternational.org/topics/general-data-protection-regulation-gdpr https://privacyinternational.org/topics/general-data-protect... [4] https://www.theregister.co.uk/2018/11/23/knuddels_fined_for_plain_text_passwords/ https://www.theregister.co.uk/2018/11/23/knuddels_fined_for_...
- 13of40 8y agoI had a related thing happen a couple of months ago: I started getting some lower back pain that I thought might be kidney stones based on a couple of Google searches. Went to my doctor, who prescribed a muscle relaxant, which I got at the pharmacy across the street. It went away. Over the next few weeks I got several robocalls on my cell phone from a pain clinic offering me relief for my "chronic pain", so it was either triggered by my online searches or my doctor's office or pharmacy sold off my private information.
- ianai 8y agoI’ve had similar recently. Only it’s been an extended period of time (months) since I last searched for what started coming up. Led me to believe something was sold to someone recently.
- dwaltrip 8y agoDoes anyone know how effective incognito mode is at preventing data and privacy abuses like this? I've been using it more and more, but I imagine there may some clever ways of tracking even across incognito sessions (or between incognito and regular).
- chronid 8y agoIf google is the issue maybe - but I seriously doubt they are the issue: they sell their ability to target you, and selling your data to third parties would essentially be against their interest. This kind of FUD has been repeated ad nauseam here and everywhere in tech sites (against Facebook too usually), but that's not the way their business model works. If it's your doctor or your pharmacist, or the shop you bought online (or offline) something once, incognito will not help at all. They have your personal information already, the only thing that can stop them is law. The cause of the robocalls may also have been his medical insurance, if you want to go full paranoia. :) Note those shops, the sites you created an account on, the companies those shops sold your personal data to, all of them can target you with ads on both facebook and google by using your PI (essentially donating your data to facebook and google in the process).
- 013a 8y agoOne of my "wake up" moments was when I searched for the phone number of a local physical therapy office on Google. Within the day, I started getting Youtube video recommendations for massage techniques to relieve shoulder pain. Google and all of its employees who make products like this are on the absolute wrong side of history. Society will only take so much before breaking; they need to figure out their business model, and fast.
- tw1010 8y agoThis seems like a fairly easy thing to test rigorously (in a statistically significant way). Just create a fake account and do a search and see what the effect is on other places on the web. Are there services that does this automatically, so we don't have to rely on anecdotal "I searched for X here and now I see recommendations for that on Y, and I think it was because of X, but maybe it's just coincidence"? A site that rigorously confirms secret data links between e.g. google search or gmail plain text and other places (e.g. youtube or even amazon recommendations). If it doesn't exist, it seems like a cool thing to create, as a sort of service to the world. It'd probably reveal a lot of hidden data links that aren't obvious (or which companies promise doesn't exist).
- Cyphase 8y agoThat could turn into an arms race of the target companies trying to detect when it's a fake account versus a real one, and the analysis service trying to make the accounts seem more real. Of course, if it became public that the target companies were trying to dodge the analysis, that could be damaging to them. Then again, automated accounts would likely be against the TOS. The analysis service could work by watching the traffic of real people who download a browser extension, but then privacy from _them_ becomes an issue. Perhaps some kind of distributed data-collection system could be created, where an extension will analyze your own traffic, strip out as much personally identifiable information (PII) as possible / as you'd like, and then submit that to a central repository for aggregation or further collective analysis.
- FloatingVertex 8y ago
- cbanek 8y ago> Indeed, large sections of the site's privacy policy were updated overnight. So basically you get caught, so you change the rules. Companies shouldn't be able to violate their own privacy policy, or say they can change it at any time without any warning, especially retroactively - which usually these things are covered in the privacy policy. What use is that?! Why bother having a policy at all?
- nitwit005 8y ago> Why bother having a policy at all? Because it's legally required.
- wagutina 8y agoIf you block 3rd party cookies, can the (exact) scenario described in the article still happen ?
- rm999 8y agoPretty sure yes; after Safari started blocking third party cookies by default a few years ago, Google, Facebook, and Microsoft have all started supporting the option to use first party cookies to get around this. As I understand it, they deploy code that stores tracking information on-site using first party cookies, then access that data directly. https://digiday.com/marketing/wtf-what-are-facebooks-first-party-cookies-pixel/ https://digiday.com/marketing/wtf-what-are-facebooks-first-p... https://searchengineland.com/google-analytics-adwords-response-apple-intelligent-tracking-prevention-282233 https://searchengineland.com/google-analytics-adwords-respon... https://searchengineland.com/bing-ads-apple-intelligent-tracking-prevention-response-conversion-tracking-290763 https://searchengineland.com/bing-ads-apple-intelligent-trac... Someone please correct me if my understanding of this is incorrect, I've been out the ad world for awhile (thankfully!)
- wagutina 8y agoThis is terrifying, thx for the answer
- marcosdumay 8y agoYes. There are many ways to identify a person beyond cookies.
- beagle3 8y agoAlso, 90% of sites these days try to access canvas, and don't break if disallowed - which probably means they try to fingerprint; this fingerprint is a '0-party' cookie, in that it correlates but isn't even stored on your machine. Firefox has a setting to stop that in about:config, if you are interested.
- donjoe 8y agoLast week, I got hit by a car while riding my bicycle. You won't believe in how many colors an upper arm can shine. Anyhow, I took a picture of the arm, shared it to a friend on WhatsApp and promptly got a newsletter from Pinterest promoting tattoo posts. I do not have the Pinterest app on my phone, barely use it otherwise and would never search for tattoos since I'm just not interested. I've been trying to find out since then where and how Pinterest might have gotten my blue/red/yellow/green arm picture from to analyze it, interpret it and link it to my account. They might be able to search my friend's phone's pictures (in case he's got the app which I'm not sure) and link the picture back to my account. Spooky though.
- vadym909 8y agoI haven't used Pinterest in years and may have accidentally clicked on a Pinterest result in Google search results and suddenly started getting all kinds of desktop popup notifications from them and don't know how or why.
- CJefferson 8y agoThis is probably chrome desktop notifications. The box to enable them on a website looks quite a lot like one of those "do you want cookies?" Boxes, so it's easy to click without thinking about it. They are (to me) one of the most user-hostile features chrome has added, because it's non-obvious what they are, and how to disable them. You can configure them somewhere in settings (I am on my phone right now).
- azza2110 8y agoI have the below address bookmarked - easier than digging through menus! chrome://settings/content/notifications
- rapnie 8y agoSamsung phone? I found out that standard Image Gallery contained Foursquare adware in it, just after GDPR kicked in and they popped up a consent dialog.
- seba_dos1 8y agoI use DuckDuckGo, XMPP, ownCloud, Firefox with bunch of privacy enhancing extensions... My main phone is Maemo based, and I keep one with LineageOS and microG (so no Google Play Services) around as well. I access Facebook and Twitter only via webapps, with isolated wrappers like FaceSlim on mobile. Not only I feel somewhat safer about my data - battery usage, speed and user experience is so much better! Win-win :D
- jamaicahest 8y agoDid you read the article? Author says he searched using DuckDuckgo.
- seba_dos1 8y agoWhat this article tries to tell is that using DuckDuckGo is just a one small piece of bigger puzzle, not that DuckDuckGo tracks you.