4 ms·
NOFI, just to understand if we talk the same thing here, you mean to say that a trace that traces the time it took the product you use to do a query that goes t
by bastijn 5y ago
NOFI, just to understand if we talk the same thing here, you mean to say that a trace that traces the time it took the product you use to do a query that goes through three different backend services is private data that is owned by you and can only be collected by your consent. Not so much because you are against collecting that information, you may very well accept it to be collected, but because technically the data is collected from your premises and under your usage and thus requires consent as it would otherwise not be generated if not for you. To protect your rights in situations where the data collected would be less harmless, the rules must be strictly enforced. Correct?
- robbedpeter 5y agoProtecting privacy and preventing the weaponization of private data is critically important. Recognizing what constitutes private data seems to be the difficult thing, so I'm trying to clarify it. I understand it seems extreme, but it's really not. Any data generated by or on a user's device is private data. Recording that data is surveillance. No matter how harmless it might seem, data collection should be consensual, transparent, and ephemeral. You should specify, explain, and obtain consent for any and every variable. Anything you do with the data should be reportable to the user. Anything less creates opportunities for abuse. Logging ip address connections is a great example. It's simple and trivial but how many RIAA piracy lawsuits do we have to see inflicted on innocents before we decide keeping those logs might not be a great idea? The misuse of metadata by law enforcement through plausible narrative crafting is ubiquitous. It's not about the developer's intentions, it's about collection of surveillance records that can be seized or stolen and weaponized.