7 ms·
How to poison the data that Big Tech uses to surveil you
- mikece 6y agoOne idea is to use active disinformation such as receiving mail in your own name at a UPS Store or PO Box and ordering things to your home -- magazines especially as they aggressively resell subscription lists -- in the name of an alias or the former owner (once mail forwarding has expired). These are just a couple ideas I picked up from listening to the "Privacy, Security, and OSINT" podcast. An episode dedicated to Advanced Disinformation can be found at: https://soundcloud.com/user-98066669/105-advanced-disinformation-telephone-archives https://soundcloud.com/user-98066669/105-advanced-disinforma...
- amelius 6y agoHow would you pay for those magazines?
- mattmanser 6y agoYou can buy subscriptions with a different card. This sounds like a pretty old trick though, not like many people get magazines delivered anymore.
- reaperducer 6y agonot like many people get magazines delivered anymore. I was surprised to learn that this is just one of those things that people say on the internet. The whole "print is dead" meme. I ended up in a conference room with a magazine circulation manager in 2019 and asked him about the state of the industry while we awaited the next presentation. He told me it's rebounded quite a lot since about 2005, and some magazines are doing better than ever. Unfortunately, I didn't have a chance to ask him anything further because the next speaker came in.
- mattmanser 6y agoYes, seems you're right, a look at some random publishers in the UK and they're all making more money than previously.
- tablespoon 6y ago> How would you pay for those magazines? A few years ago, I think you used to be able to sign up for free subscriptions to magazines like Sports Illustrated at Best Buy. I'm not sure if that's still happening, but I think it was part of a strategy to keep circulation up.
- reaperducer 6y agoHow would you pay for those magazines? It's not uncommon for people to buy a magazine subscription for someone else. Half of the magazines to which I subscribe send me letters offering half-price gift subscriptions. For payment, you could use a pre-paid card. If the magazine company doesn't take that, you can send a check. Checks with no name or address on them are stupid easy to get. And I've never seen a magazine that didn't take checks.
- mikece 6y agoEither with a prepaid debit card paid for in cash or with a money order.
- tamiral 6y agohave you read the books ? great stuff
- wayoutthere 6y agoFWIW, I changed my gender, first and last name, e-mail address, phone number and moved states and they still connected me. It doesn’t help when every company you have an account with sells your information to the ad networks and DMPs. Ending 3rd party cookies should help to wind this down however.
- phreack 6y agoIf I may ask, who found you, and how did you figure it out? Do you have anything you'd have done differently to avoid it?
- wayoutthere 6y agoI started getting junk mail under my old name at a new address. No idea how they figured it out. I wasn’t explicitly trying to avoid being tracked — I got a new job in another state at the same time my legal name change went through — but I was surprised at how quickly they were able to connect the dots.
- cyberlurker 6y agoSame SSN or other identifier I would guess.
- inanutshellus 6y agoWow, that's an impressive amount of change. I'm curious how you think you were linked. Also, how you have identified that you were successfully linked? Perhaps you still have the same social media accounts somewhere? Perhaps you used your same PC you'd formerly used when creating new ones? Perhaps your friends merely updated their phone's contact information for you rather than deleting the contact and adding new ones?
- wayoutthere 6y agoI’ve been off social media for a very long time; kind of a hipster about it :) I wasn’t able to identify where it came from, but I do suspect it’s the latter — which is really hard to deal with because it’s other people leaking info about you. But the same could have happened with facial recognition at an ATM or checkout. Personally, I’ve accepted that being an American in 2021 just means being under constant surveillance. The fantasies of going off-grid will run into the realities of your human relationships.
- astuyvenberg 6y agoI'm interested in learning if there are alternative credit cards available that do not track/resell your purchase history. [1] To me, that seems like a major aspect of surveillance economy which can't be easily disrupted by something like Ad Nauseam or pi-hole. [1] https://www.fastcompany.com/90490923/credit-card-companies-are-tracking-shoppers-like-never-before-inside-the-next-phase-of-surveillance-capitalism https://www.fastcompany.com/90490923/credit-card-companies-a...
- mikece 6y agoYou can buy prepaid debit cards in cash and load them with up to $500 at almost any Walmart (and probably a lot of other locations). I like the OneVanilla prepaid debit cards because I can use them online (but only with US-based vendors -- no international transactions) and put anything I want (such as "Hacker News") as the cardholder name. Another great alternative is privacy.com which allows you to create anonymous credit cards (your bank is then debited). While the vendors won't know who you are privacy.com certainly does and they use Plaid on the back end so they likely know as well. VISA just tried to buy Plaid; someone eventually will acquire them (maybe Google?) so keeping your financial info private via privacy.com might not be something that works long-term.
- astuyvenberg 6y agoThat's a good point! And Privacy.com does offer a product that lets you generate temporary credit cards for this type of thing, which seems like a more elegant solution.
- mikece 6y agoSorry -- was editing my comment to include Privacy.com while you were replying!
- deleted 6y ago[deleted]
- reaperducer 6y ago
- termau 6y agoIs this just an American thing? I dont get this real world spam in AU much and defs not targeted.
- Daho0n 6y agoNever seen anything like it either (in Scandinavia). Sounds strange and worthless.
- clankyclanker 6y agoIt’s encouraged by the US postal system, as spam mail is one of the most reliable income sources (which is necessary given how Republicans are trying to kill the public postal system). This has led to the postal system taking legal action against startups that tried to shield people from spam. It’s all exactly as stupid as it sounds.
- termau 6y agothis sounds exhausting, move dude :)
- Semaphor 6y agoIn Germany it's pretty tightly regulated. Cold personal mail is not a thing you get, and for unnamed mail you just put a no ads sticker on your mailbox and repeat violators are strictly punished
- tpmx 6y agoI think that with any measure any real individual can do - the adversaries can easily counteract it. I'm a believer of building many separate complex systems to feed manufactured data into these systems. Let's make it an arms race, and a competition.
- retrac 6y agoYou're probably right, sadly. I think there's a great deal of merit to this idea. To but to actually take on the companies and start messing with things like AdSense revenue meaningfully, probably millions or millions of us would have to do this consistently. And if it had that level of broad social support and motivation, perhaps we should channel the energy into legal regulation of the industry.
- tpmx 6y agoAt some point, if it's successful, there will be pressure to make something like this illegal - heck, in many countries it's probably already illegal.
- jandrewrogers 6y agoThe techniques outlined in the article are naive and generally will not work. Robust methods exist for both detecting and filtering sophisticated data poisoning, and the kinds of organizations we are talking about here will already have that capability. Defense against data poisoning isn't just about ad tech. State actor threats routinely engage in sophisticated data poisoning operations that require robust mitigations for system integrity purposes. A "simple" strategy is not remotely at the level of sophistication required to have a chance of bypassing these defenses, which need to withstand state actors.
- SeanLuke 6y ago"You need to enable JavaScript to view this site." Very bad.
- Epitom3 6y agooutline.com
- Threeve303 6y ago> Data poisoning, which involves contributing meaningless or harmful data. AdNauseam, for example, is a browser extension that clicks on every single ad served to you, thus confusing Google’s ad-targeting algorithms. Wait a minute, if every ad is clicked on won't that give an enormous amount of money to the companies that created the problem in the first place?
- chickenpotpie 6y agoMaybe the ideas is that advertisers would see a horrible conversation rate on google and stop advertising to you?
- FalconSensei 6y agoYes. But there are a couple advantages: 1 - the goal is so google doesn't know which ads are interesting for you, so it helps you with that. 2 - in the short term, you are making google earn more, but if more people do it, ads are going to start being way less effective, as the companies pay google per click, but they don't actually get any signups (or whatever their goal is). Maybe that could make google ads less relevant
- nickvincent 6y agoThe "Why" section of the AdNauseam FAQ has some good thoughts on this: https://github.com/dhowe/AdNauseam/wiki/FAQ#does-the-project-oppose-all-advertising-or-only-advertising-you-believe-is-abusive-eg-tracking https://github.com/dhowe/AdNauseam/wiki/FAQ#does-the-project... e.g. "We believe obfuscation is an important form of resistance to data tyranny. It can frustrate surveillance, help users to express their discontent, and act as a communal, rather than merely individual, practice." I believe the general idea is that by contesting targeted ad technology in general, the eventual goal is move away from that model (which arguably, Google is doing with their big ad "reframing", although I realize this is contentious)
- jjk166 6y agoIn the short term yes, but in the long term most of their customers won't pay for expensive ad space with very low conversion rates.
- nickvincent 6y agoHey all, I'm the one of the authors of the conference paper discussed here and was quoted in this. Glad to see it's interesting to HN! Wanted to briefly highlight a couple points that I think will be interesting to the HN audience. One of the major goals of the paper is to describe a framework of three "data levers" (ways a group of people can hurt or harm a data-dependent technology). Data poisoning (well known to ML people for a long time) is one of the three "levers". The other two are "data strikes" (withhold future data and/or delete past data via deletion request) and "conscious data contribution" (ala conscious consumerism — give data to a firm you support and want to compete with incumbents). A major point in the paper is that there are some big differences in terms of barrier to entry, legal considerations, ethical considerations, and ability for a data lever to be impactful. Basically, for any given company + technology, there's probably a particular data lever that's a "best fit". It might hard to organize a large enough "data strike" that will meaningful hurt a huge company's search engine, but conscious data contribution could help improve a competitor (esp. if that competitor focuses on search verticals). On the other hand, data strikes could be really great vs. facial recognition, because there's precedent of forcing companies to delete actual model weights ([https://www.theverge.com/2021/1/11/22225171/ftc-facial-recognition-ever-settled-paravision-privacy-photos](https://www.theverge.com/2021/1/11/22225171/ftc-facial-recognition-ever-settled-paravision-privacy-photos) https://www.theverge.com/2021/1/11/22225171/ftc-facial-recog...). Another point is that there's some nice connections between levers. On the topic of data poisoning defenses: if you've been feeding poisoned data, and get caught (quite likely for naive attacks, as noted below), the company deletes your poison and you've just been "reduced to a data strike". A final point: the paper discusses implications for folks who work in ML, design, HCI, and policy. There's great opportunities to build to tools to support data leverage, and for ML researchers to "bake in" data leverage (e.g. compute a performance v. dataset size learning curve to characterize how "vulnerable" a system is to data strikes). Also, there's huge potential for win-wins with privacy regulation: data deletion and data portability both enhance the public's leverage. I'll end this long comment now, curious to see what others think (and appreciate all the comments already here!)
- nickvincent 6y agoShould also add, here's the pre-print link for the full paper: https://arxiv.org/abs/2012.09995 https://arxiv.org/abs/2012.09995
- pengaru 6y agoFYI if you remove the mailbox from your residence, the USPS will silently return every attempted delivery to the sender. You can then get a PO BOX, setup your important things like property taxes/dmv/utilities/banks with it as the mailing address, and carry on supplying your residence as your physical address to whoever appropriately asks without even lying. Most places are just assuming your physical address receives mail and send unsolicited spam to it. Critical services must support a mailing address distinct from a residence address, as it's common for those living at the end of a dirt road without mail service; a perfectly legal way to live. I currently do this, and my PO BOX receives practically zero mail, and I must say it's a glorious signal:noise ratio. There are some frustrations though, some places do refuse to send to a PO BOX, and some shippers which claim to use FedEx or UPS will then go on to use USPS and your purchase doesn't arrive. Non-USPS deliveries will still arrive at the physical address without a mailbox, but USPS deliveries will not - those must go to the PO BOX. YMMV
- MaxBarraclough 6y agoHow easy is it to cancel the PO box and get a new one with a new address?
- dogma1138 6y agoAt least in the UK it’s very easy to it’s costly if you use the Royal Mail one there are others but I wouldn’t trust them all the ones I’ve seen look rather dodgy. https://www.royalmail.com/receiving/po-box https://www.royalmail.com/receiving/po-box
- pengaru 6y agoTrivial, and you must pay to renew it in either 6/12mo intervals. The PO BOX number will be reclaimed automatically if you fail to pay.
- MaxBarraclough 6y ago> The PO BOX number will be reclaimed automatically if you fail to pay. Does that mean that if you get a 'new' PO box, you get spam right out of the gate due to the previous owners?