5 ms·
Once again we continue to look at data privacy and identity theft in the wrong way in my opinion. To me the solution is very simple. If you are reselling my dat
by Thriptic 7y ago
Once again we continue to look at data privacy and identity theft in the wrong way in my opinion. To me the solution is very simple. If you are reselling my data, allowing access to my data, or deriving data / servives from my data that identifies me in any way and then selling that to a third party for a profit or giving it to them as part of a license so that they can generate profit from it (including ad targeting or analytics) then when I visit your site or use your service there should be a big box in simple to understand English, not legalese or a lengthy EULA, that says "we [do one of the things listed above], are you ok with that?" If I say "no", then you cannot descriminate against me and you cannot do those things. You still have to let me use your site or service; you still have to provide me with identical services; etc. You can still show me ads (non-personalized), charge me a bit more money commensurate with the value of my data, or introduce a different monetization method, but you can't deny me service all together.
Further, if you collect my data, YOU are liable for it. Breaches should not be the user's problem. Meaning, if someone walks off with the contents of your database containing my PII using anything less than a crazy number of zero days, you are liable for a set financial penalty per user's info lost (in the way HIPAA does it) and / or you are liable in perpetuity for protecting against identity theft with an insurance policy. I don't need to prove attribution. If I ever have a problem that could plausibly be linked back to the data exposure, you are liable for damages.
Finally, it should not be the user's problem to clean up identity theft, ever. If a bank opens an account in my name without properly authenticating me, that is the bank's problem, not mine. It should be up to them to conclusively prove it was me that did it, not up to me to prove that I didn't. Does this mean it will be more complicated to open up various accounts and credit? Yes. Does it mean that there will be lost business for these institutions? Yup. Tough luck; that is the price we have to pay.
The entire point of this should be to heavily disincentivize collection of PII unless absolutely necessary for core business function.
- adamc 7y agoRun for office.
- deleted 7y ago[deleted]
- analog31 7y agoIn my view, there should be an automatic penalty paid to the victim. There is something like this for copying of music recordings. If you are caught with my information, you owe me 10000 bucks.
- ftkudtkfkl 7y agoI don't see why people who opt out of paying the toll should be allowed to use the service. Nobody complains if a walled garden membership fee costs dollars why should data be different as long as you're aware up front of what is collected and that it's the method of payment?
- kulahan 7y agoAt that point, they can simply charge their users a small fee. I remember reading once that Facebook makes something like $12/yr/user by exploiting their privacy. I'd gladly pay $15/yr to use that service if I knew they weren't tracking my personal info and the service was ad-free. As it stands, I haven't been on the platform for nearly a decade now, and I'd return tomorrow if this were truly an option (and I actually knew I could trust them to honor the agreement). IMO, that's how you strike a balance - use for free and we exploit your privacy, or pay a fee (preferably regulated to be similar to the average profit made on a user's private information) and no data will be collected or stored on you, except as is necessary to make the site work (for instance, setting times to your local timezone).
- ftkudtkfkl 7y agoYou sidestepped my question though, why shouldn't they be allowed to refuse service if the toll is clearly explained? There are plenty of users who are content to receive $free services in exchange for their data, why shouldn't they be allowed to spend their data if they want to and why shouldn't services be allowed to cater exclusively to them? I'm not trying to come off aggressively so I apologize if I have, but to me this just seems like you're unhappy with how other people are choosing to transact. If $free services are so dominant in the market, not saying they are but now I'm speaking hypothetically, that people like yourself can't find alternatives then isn't that really just an indication that the traditional business model has been thoroughly outcompeted and should be moved away from since it's nonviable by comparison?
- catalogia 7y agoYour shitty business model isn't morally entitled to be viable. If you can't figure out how to operate a business without hoovering up tons of PII, then your business deserves to die.
- Proziam 7y agoThis the same line of reasoning I've used in the past. I just wish more people would get on board, to be honest. It's a painfully hard battle to get people to adopt the mentality of minimal exposure, and to see the real value in it. It's always AFTER they get slammed by some unfortunate event that it becomes a priority. People don't realize the real value of their own information, I suppose. It's probably the same reason there are so many people who say they don't mind being surveilled because "they have nothing to hide." It's only after they've seen their freedoms restricted that they realize they should have cared more. "Arguing that you don't care about the right to privacy because you have nothing to hide is no different than saying you don't care about free speech because you have nothing to say."
- munk-a 7y agoI'm not super on board with that disclaimer, as I think it weakens the argument that widely reselling PII is a socially unacceptable action. There are some rational reasons to resell PII to a different party (usually inter-subsidiary data sharing) but I am absolutely on board with reinforcing the liability. Maybe the law needs to be shifted to a point where if a company collects some PII information from a user and that information is found in a breach then it is incumbent on the company to prove they were not the source of the breach to avoid being legally exposed. I think it'd be nice if we all started viewing PII as dangerous, companies could invest the risk in collecting data on users, but it should be the default that companies try and avoid collecting as much data as possible.
- greggman2 7y agoSo it sounds like you're okay with Google collecting all your data because your description doesn't cover them > If you are reselling my data Google doesn't resell data > allowing access to my data, Google doesn't allow access to user data > or deriving data / servives from my data that identifies me in any way Google doesn't let people be identified from the data they collect. > and then selling that to a third party for a profit or giving it to them as part of a license so that they can generate profit from it Google doesn't sell data to a third party for profit. I'm 100% for a law that prevents that scammier companies who do all the things above to stop doing those things. Just pointing this doesn't cover HN's most hated company.
- zajd 7y agoThis is why Google should be broken up. If you let giant megacorps keep vertically integrating into insanity, of course this sort of thing will happen. Google is like thousands of companies in one. Youtube, Android, Search, Ads, Cloud, Drive, Gmail, etc should all be separate businesses.
- Thriptic 7y agoFair enough. This is why we have lawyers and subject matter experts (which I am not). I am just expressing a general sentiment. Codifying that into an actionable set of laws and regulations requires much more work.
- chipperyman573 7y agoI would argue that makes what they're doing ok. I know this is a really unpopular opinion on HN but I think google is actually a really good example of ethical data collection. Sure they scrape up just about everything they can get, but they hold onto it themselves and have repeatedly demonstrated that (unlike facebook etc) they try hard to protect it and won't let an arbitrary 3rd party access it. They just let advertisers target demographics, so long as you don't actually click an ad your data is never accessible to advertisers. Someone has to pay the devs to make their services, someone has to pay for the server farms (and the electricity to run them), someone has to pay for their open-source efforts, etc. They have to make their money somehow and people have demonstrated over and over again that they're unwilling to pay for services like gmail (remember when hotmail used to charge a monthly fee for email service if you wanted more than like, 500mb or something?) (I don't and have never worked at google)
- Darth_Hobo 7y agoSorry, but I don't get why you must be entitled to having me serve you if I happen to have a server that serves other people. Just because I allow some people to visit my server does not imply that I am obligated to let you in. Because this a private property and owner have a right to decide who gets in on his private property. Unless you advocate for abolishing private property that is.