7 ms·
I can't separate what actually happened from the sensationalizing in the article. It says the websites had Google cookies and others. OK, anybody using Google
by dangrover 7y ago
I can't separate what actually happened from the sensationalizing in the article.
It says the websites had Google cookies and others. OK, anybody using Google Analytics has Google cookies. Anyone using FB plugins has FB cookies. Yes, websites certainly have a lot of cookies these days, and the information inferred by use of these can be in a generic fashion to target and rank ads. That's worthy of scrutiny -- but this isn't what the article is about. What is the evidence of "mental health" being treated in some scary specific way?
The only substantial thing in the article supporting the headline is one charge that a site sent quiz answers to Player.qualifo.com -- which appears to be an unregistered domain.
OK, so what information was sold? When did money change hands? Is there any hard evidence that mental health information was "sold to advertisers", as is claimed in the headline? Or is this just bullshit they made up to get clicks?
For that matter, even if you wanted to do some evil psychographic ad thing, why would anyone sell that info to advertisers? What are they gonna do with it? Like, why hand them the literal data, when you could allow them to just bid on ads that may be targeted/ranked using your painstakingly collected psychographic data (a la Cambridge Analytica)? Why sell cow when you can sell the milk?
The fearmongering and disinformation around adtech and privacy numbs us to legitimately scary things being done that should be covered more.
Makes me think of this Blake Ross rant: https://medium.com/@blakeross/don-t-outsource-your-thinking-ad825a9b4653 https://medium.com/@blakeross/don-t-outsource-your-thinking-...
- SomeOldThrow 7y agoA greater problem is the divorce of collection of data and consent.
- umvi 7y agoThat's because not everyone agrees that observational data is something that can (or should) be owned by a person. When a human looks at another person, are they "collecting data without consent"? Most would say no. So at what point do you "own" observational data about yourself? When it's observed by a machine? So then CCTV should be illegal too then, and indeed any sort of security system that records audio/video without consent.
- tremon 7y agoWhen a human looks at another person, are they "collecting data without consent"? Most would say no. But if that human follows and looks at that other person 24 hours a day, would you still say that no consent is required? So then CCTV should be illegal too then It is, in many cases.
- the_snooze 7y ago>But if that human follows and looks at that other person 24 hours a day, would you still say that no consent is required? This. Scale matters. Scale matters. Scale matters. It's such an infuriating and intellectually bankrupt slight-of-hand when someone implies that because some small thing X is fine, then 10000X is fine all the same.
- umvi 7y agoWell, then quantify the scale at which data collection should become illegal with unambiguous terms. I don't see anything wrong with making observations about people, especially if it helps my business. I'm allowed to do so without computers: "Ah, sir, I see you are sunburned, did you know we have ointment for that on aisle 4?" (no one would say: "How dare you observe that I am sunburned! That's a privacy violation! You didn't have my consent to observe that!") So tell me how far I'm allowed to go with computers.
- jacksnipe 7y agoWell that’s easy — with computers, you need explicit consent to even “observe that the user is sunburned”, because there are no inherent scaling limitations with computers.
- umvi 7y agoSo you are saying if we remove some of the scaling limitations of the human brain with biotech (i.e. by enhancing memory detail retention, figuring out a way to serialize memories to computer-compatible storage, etc.) it could become illegal to look at a person without consent (since you would effectively become a walking, breathing CCTV)?
- msbarnett 7y ago> It says the websites had Google cookies and others. OK, anybody using Google Analytics has Google cookies. Anyone using FB plugins has FB cookies. It's not that complicated: certain websites, dealing in certain kinds of sensitive information, may be legally required to seek explicit user consent before even using Google Analytics or Facebook Plugins. Yes, Google Analytics use is damn near ubiquitous right now. That does not mean it is unambiguously OK to slap it on ever website under the sun. > What is the evidence of "mental health" being treated in some scary specific way? No evidence is required. The law is clear. That someone subject to GDPR regulations has the information that they were seeking information related to depression transmitted to google and facebook in the form of a Google Analytics and Facebook scripts on page, without their explicit consent to that, is in and of itself a violation of the law.
- kodablah 7y agoI'm not sure it's clear that generic page analytics necessarily means that ones presence on certain pages is any more sensitive than Google maps knowing that you zoomed in on a depression clinic. I can understand this is easy with third party analytics on specific-subject pages, but the waters may appear muddier on web server logs, dns lookups/caches, browser history, search results etc where generic approaches may only be illegal depending on what's visited or looked up. What if the analytics scripts promised not to collect URL or page content (not saying that's the case here)? If not already clarified somewhere (pardon my ignorance on the bodies/law involved), I think these common cases should be listed as clearly illegal not in canon, but as a helper to these services. Keeping a list containing things like "it's illegal for sites remotely related to health to use third party analytics of any kind sans prior consent" (or "it's illegal for sites remotely related to health to let the URL or content of the page be known to third parties sans prior consent") could help. I too struggled w/ some of the sensationalizing in the article, because I read: > Sensitive personal information about mental health is routinely being traded to advertisers around the web as a bold headline, only to read: > This was problematic because sensitive information could be broadcast to all of those bidding, PI said I couldn't really tell what was really being sold routinely, personal info or ad space. And I couldn't separate what "could be broadcast" vs what was.
- elorant 7y agoFor that matter, even if you wanted to do some evil psychographic ad thing, why would anyone sell that info to advertisers? What are they gonna do with it? Like, why hand them the literal data, when you could allow them to just bid on ads that may be targeted/ranked using your painstakingly collected psychographic data (a la Cambridge Analytica)? Why sell cow when you can sell the milk? Because you don't have the platform. Not every company in data brokerage out there owns an advertising platform so that advertisers/ad networks can bid on ads. Furthermore, data isn't only about direct advertising. You can also analyze trends. See what influences purchases. Correlate purchase habits with news events or various other sociopolitical indices. Make your product better. Make new products. Find out which area is hip so you can open your new shop there, or buy some real estate. And the list goes on. Advertising is just the tip of the iceberg. You can exploit such data in myriads of ways.
- godelski 7y ago> Why sell cow when you can sell the milk? Because you want to sell beef and not milk? This analogy breaks down for a lot of the same reasons people in real life sell cows and not just milk.
- TeMPOraL 7y agoIndeed. In particular, neither people selling beef nor people selling milk necessarily breed their own cows. Professional specialization is a thing.
- tripzilch 7y ago> Why sell cow when you can sell the milk? Because according to medical tracking data, they are lactose-intolerant? :)