24 ms·
I was part of a human subject research study without my consent
- Tomte 5y agoWe've had a wave of almost exactly the same mails (GDPR instead of California law) some time ago: https://news.ycombinator.com/item?id=26845102 https://news.ycombinator.com/item?id=26845102
- jcrawfordor 5y agoI have pretty mixed feelings on this. On the one hand, I agree that the researcher's actions (particularly the use of a false identity) were inappropriate. I am hesitant to engage in "victim blaming" by calling the targets of the email naive. But I hope this has been a learning experience for everyone, as it seems to have revealed a lot of knowledge gaps that were surprising to me. I am not at all surprised that it was not subject to IRB review, but only because I've had a bit of involvement in the IRB process before and know that the specific legal mandates that drive IRBs (45 CFR 46) have a surprisingly narrow definition of human subject research that is driven primarily towards medical interventions, so generally speaking any research that consists of just asking questions and then anonymizing the results for reporting gets waved past IRBs (45 CFR 46.104). You might disagree with the situation (there's plenty of reasons to) but it's the law of the land. IRBs were developed pretty specifically in response to a spate of incidents in the mid-century, but especially the Tuskegee trials, involving non-consensual drug and toxin trials. The IRB process is directly designed to address these kinds of medical research, and so IRBs I've dealt with are not even very interested in looking at proposals coming from departments other than life sciences. The idea that IRBs are a general-purpose ethics review seems to be a pretty recent idea and it's not something the IRBs themselves are that into, at least from my experience hearing professors gripe about having to go through a stack of pre-reviews for information assurance studies on the off chance they qualify as human subject research. On the other hand, though, I operate several websites for small organizations, admittedly in a politics and public policy-adjacent space, and receive emails of this type as a matter of course. I'd be surprised if there are many people operating websites that get a meaningful amount of traffic that don't get an email of this type from time to time. It's sort of background noise if you're doing anything that's of much public interest. In some of these situations I benefit from having retained legal counsel that probably wouldn't even bother to bill for this kind of thing, but it would still be a rare situation that I referred such an email to counsel unless it was something about a more obscure corner of city political financing regulations, which I have gotten once before. The "legal threat" here honestly doesn't read to me as much of a threat. Part of this is because in my hobby work I write emails very much like this one on a weekly basis... mostly citing FOIA or similar state sunshine/open records/open meetings laws. Many guides on transparency laws coming from this same community clearly advocate a similar sentence citing the response deadline, and I wouldn't be surprised if this researcher copied and pasted that from such a "consumer rights" guide. It's considered a best practice to state the deadline and citation with this kind of request. There are basically two reasons for this: first, some people, especially smaller organizations, may be totally unaware of the deadline and you will be telling them about it for the first time. They may not believe you on it if you don't provide some sort of backing. The second is that there's a perception (from my experience I'm skeptical this is frequently true but I'm sure it is occasionally) that especially federal offices may be aware of the deadline but feel comfortable ignoring it if they don't think the requester knows. So providing the deadline and citation is sort of a "savvy customer" indication that encourages them to at least issue an extension letter on time (even then it's very common, even before COVID but especially now, for federal agencies to run past the deadline without any response. Oddly, state and local agencies are usually much better about this). Another part of why I have a hard time taking it as a threat is because it is the first in a rather long chain of actions that would lead to legal action. It does indicate that the requester is aware of the law but it's quite a few steps from the requester's intent to file a lawsuit. Most people that include a line like that never even bother to follow up with a nag when the deadline passes. What was in the email is basically a "I copied and pasted this from an online howto" level of effort, and there's a pretty big ramp from there to filing a lawsuit (especially from a far away place). Really, in my experience, people who are a serious legal risk (i.e. lawyers and people who use them) cite statute less often than slightly crazy internet randoms do. So I suppose what I mean to say, is that I feel bad for the people who were alarmed by this, but I hope it has been a learning experience: when you operate a website, you are putting yourself out in public and exposing yourself to both legal obligations and dealing with random people that have weird ideas about your legal obligations (there tend to be more of the latter than the former). There are a lot of risks and responsibilities entailed in running a website, most of them fairly minor, and this kind of thing is one of them... just something you have to deal with when you make the decision to be a public entity. Or maybe a better takeaway is this: if you get at all involved in politics, government, civil rights, or the public sector in general you will get a lot of stuff like this (and some of it will actually require action, but usually not especially difficult action). One result of increasing online privacy concerns is that just operating a website is starting to enter the civil rights realm, so I suppose over time every website will get more of this.
- dqv 5y agoIt is very much about experience. Now that I’m an old man in my late 20’s I can tell when it’s BS, but I empathize with the fear of the less-experienced. The first time I had a personal legal experience, I was confident about what the law was, and then got blown the fuck out. The second one was someone threatening some sort of criminal action to which I responded, “have the prosecutor reach out so we can put our lawyers in touch.” My heart beat irregularly for a few weeks whenever I thought about it; first because, despite having done nothing criminal, I was scared, but second because I didn’t actually have lawyers. It turned out to be nothing. They never contacted me again. Maybe a “scam” email about CCPA would have been a better learning experience ;)
- vasco 5y agoSame experience here, I can't understand someone who's reaction to a totally random email without any credentials or actual lawsuit is to spend thousands of dollars on lawyers. Maybe I was lucky to not have the privilege to even consider paying for lawyers when I got my first ones of these and always defaulted to just emailing the person back which in 100% of cases cleared the issue.
- omgitsabird 5y ago"In order to be considered a covered business, the organization needs to have annual gross revenues in excess of twenty-five million, possess the personal information of 50,000 consumers, or derive 50 percent or more of its annual revenue from selling consumers' personal information."
- ethbr0 5y ago> or derive 50 percent or more of its annual revenue from selling consumers' personal information Wouldn't that cover most blogs that run ads?
- deleted 5y ago[deleted]
- TedDoesntTalk 5y agoMost blogs don’t have consumers’ personal information, do they? How many blogs have you registered with? I can’t remember the last time I did that. If I read a blog, the most they can do is cookie reading/writing, which is not PII.
- sgentle 5y agoYou've made several claims in your comments that don't hold up to even a few minutes of basic research. You can Google the definition of PII in the CCPA. You can Google whether emails can be legally binding. If you don't bother to check whether the things you're saying are true, you burden everyone else with the effort of correcting you. https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?sectionNum=1798.140.&nodeTreePath=8.4.45&lawCode=CIV https://leginfo.legislature.ca.gov/faces/codes_displaySectio... > (v) (1) “Personal information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household. Personal information includes, but is not limited to, the following if it identifies, relates to, describes, is reasonably capable of being associated with, or could be reasonably linked, directly or indirectly, with a particular consumer or household: > (A) Identifiers such as a real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, social security number, driver’s license number, passport number, or other similar identifiers. > (aj) “Unique identifier” or “Unique personal identifier” means a persistent identifier that can be used to recognize a consumer, a family, or a device that is linked to a consumer or family, over time and across different services, including, but not limited to, a device identifier; an Internet Protocol address; cookies, beacons, pixel tags, mobile ad identifiers, or similar technology; customer number, unique pseudonym, or user alias; telephone numbers, or other forms of persistent or probabilistic identifiers that can be used to identify a particular consumer or device that is linked to a consumer or family. For purposes of this subdivision, “family” means a custodial parent or guardian and any children under 18 years of age over which the parent or guardian has custody.
- darkwizard42 5y agoThe Institutional Review Board doesn't seem to be much of an "ethical board" given they don't consider the stress this causes the human side of the website operators. How did they conclude this doesn't count as "human subjects research" given the expectation is to measure a human response to an email (framed as from a person)?
- PeterisP 5y agoIn particular, to an email which: 1. does not disclose that this is a research survey; 2. does not inform the recipient that they can decline to participate without any adverse consequence (as they state in their study FAQ), instead doing entirely the opposite - ending the mail with an assertion (untrue for most recipients) that they have a legal duty to respond; 3. lies about the origin of the email, inventing a fake persona; 4. lies about what the responses will be used for.
- et2o 5y agoYou are the first person in this thread to concisely state the major ethical failings. These 4 things are universally required in human subjects research (or IRB-exempt HSR) and it's black-and-white unethical to omit them.
- ImaCake 5y ago>does not disclose that this is a research survey Yeah this is the big one for me. Coming from the context of medical research it is shocking to me how many commenters think this is okay. If this happened to be a disguised medical research survey the ethics board would never have let this past. And if they did it would bring down some serious bureaucracy on their heads. I guess software and law just think they can test whatever they want and get away with it. Who cares if a few people end up emotionally scarred?
- yjftsjthsd-h 5y agoand, 5. which caused people harm, in the form of time, stress, and in apparently a fair number of cases, money spent consulting a lawyer in the belief that they were about to be sued.
- COGlory 5y agoYeah this is pretty bad. Not really sure what to say beyond that. I'm extremely confused how anyone thought this was OK.
- lpage 5y agoAnother subject, posted yesterday: https://news.ycombinator.com/item?id=29599553 https://news.ycombinator.com/item?id=29599553
- walrus01 5y agoHow did anybody think it was appropriate to distress random human subjects by sending what appears at first glance to be a thinly veiled legal threat?
- morpheuskafka 5y agoThe problem I have with saying this is a threat is that a best the threat of a lawsuit is at best hypothetical--if and only if some response is required by that law, and that response is not given, then you could see it as a threat. And most people writing that would have no reason or resources to dedicate to some frivolous lawsuit as a result. Obviously no one would sue for getting a response a couple days late, it would take at least months for it to be remotely worth it. I wouldn't be surprised if most boilerplate CCPA request templates out there included the same wording. It's like when I send a FOIA request and put at the bottom, "this law says you are supposed to respond in X days," everybody knows that's the law already its just there to sound a bit more formal and like I actually care about the outcome. Obviously there is not going to be time or money for the vast majority of such technical violations to go to court. Would a study not be able to send out FOIA requests and study how long the responses took after including that verbiage because it's a "legal threat"?
- walrus01 5y ago> the threat of a lawsuit is conditional- It reads to me like the first message as a toehold in the door, from somebody who intends to litigate frivolously against the person they're sending it to.
- dudeman13 5y ago>threat of a lawsuit is at best hypothetical Every lawsuit threat, including "I'm suing your ass next Tuesday", is hypothetical. It takes being used to communication that randomly quotes the law, or extreme lack of social skills to not consider randomly quoting the law a threat. Individuals don't often randomly quote the law for the funsies. We could, of course, argue all day whether they should have just immediately dismissed it as junk email, but coming from what looks like junk email just lowers the expected threat.
- TedDoesntTalk 5y ago> My name is Maya Mishina, and I am a resident of Novosibirsk, Russia. If i received such an email, I would mark it as spam and move on with my life. Why did this blogger take it seriously? Does she take other forms of spam so seriously? I do feel for her stress and anxiety, but I also have to question her mental ability to filter noise. Life must be quite stressful for her overall.
- dannyobrien 5y agoI was contacted by my system administrator about this email, even though we chat roughly once a year; we get a lot of spam too but a legal threat is something you need to keep an eye on.
- TedDoesntTalk 5y ago> legal threat is something you need to keep an eye on. Yes but you still need to be judicious and critical.
- dqv 5y agoThe things I would look for in an illegitimate email are not there. Where are the typos? The poor use of language? It is a very well-crafted email. The address is maybe a little off, but tons of my legitimate clients have weird emails like this. It would have gotten my response... probably an hour of my time explaining how our policies work and how, yes, we would comply with their request even if the laws don't technically protect them. There isn't really a prefilled template you can respond to questions like this (if you actually care about responding inquiries like this) so I would have genuinely spent time thinking about the questions and giving them more than a yes and no.
- akersten 5y agoFully agreed. I'm shocked she gave a random unsolicited emailer the time of day. Most problems are ones we create for ourselves. Responding to spam and then feeling like you've been the victim of some injustice that the spam didn't say "hey, I'm not really spam, I'm grad-student flavored spam" is quite a take. Here's a tip for anyone not running a business: If your response is legally required, it'll come in the physical mail. Don't take legal advice from spam, me, or your sysadmin.
- ericabiz 5y agoI received one of these as well, but the wording was different. From reading this, it sounds like the one I received was the one they send when they aren’t confident they have the correct email address. I didn’t respond. Here’s the email (I redacted my domain name and replaced it with [mydomain].) To Whom It May Concern, We are researchers at Princeton University conducting a study of how websites are implementing the EU and UK General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). We are reaching out to you because this email address is provided as a contact on the website [mydomain]. Your website may be required to implement one or both of GDPR and CCPA, and we would appreciate if you would answer a few brief questions about your privacy practices. 1) Does [mydomain] implement GDPR or CCPA? If not, could you please explain why? If you are uncertain about whether [mydomain] is required to implement these laws or answer questions like ours, we have included informative resources at the end of this email. 2) If you implement GDPR or CCPA, do you process data access requests from individuals who are not residents of the EU or UK (for GDPR) or who are not residents of California (for CCPA)? 3) If you implement GDPR or CCPA, do you process data access requests via email, a website, or telephone? If via a website, what is the URL? 4) If you implement GDPR or CCPA, what personal information must a user submit for you to verify and process a data access request? 5) If you implement GDPR or CCPA, what personal information do you provide in response to a data access request? Thank you in advance for your answers to these questions. If there is a better contact for questions about privacy practices on [mydomain], I kindly ask that you forward my request to them. Sincerely, Ross Teixeira ---------- We offer these resources about GDPR and CCPA for your convenience. Please note that we cannot provide legal advice about whether [mydomain] is required to implement these laws or respond to our questions like ours about GDPR and CCPA practices. * Article 3 of the GDPR, which specifies coverage: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&from=EN#d1e1455-1-1 https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL... * European Data Protection Board guidance on GDPR coverage: https://edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-32018-territorial-scope-gdpr-article-3-version_en https://edpb.europa.eu/our-work-tools/our-documents/guidelin... * California Attorney General guidance on CCPA coverage: https://oag.ca.gov/privacy/ccpa#sectiona https://oag.ca.gov/privacy/ccpa#sectiona * Section 1798.140 of the California Civil Code, which specifies the businesses that CCPA covers: https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?sectionNum=1798.140.&nodeTreePath=8.4.45&lawCode=CIV https://leginfo.legislature.ca.gov/faces/codes_displaySectio...
- Zababa 5y ago> Wanna know why there's no comments on this blog? I don't want to have to deal with storing user data and doing moderation! I've thought about starting a blog a few times, and I had the exact same thought. While it's very easy to make a static website and store in on a CND to make it scale to billions of requests, it's very hard to create a moderation system that scales.
- dcow 5y agoCan someone help me understand the ethical problem here? If I as an ordinary citizen contacted the webmaster with a similar worded email, the result would have been the same. The fact is that this “experiment” did not create any more or additional stress than is created for normal citizens/businesses simply engaging in normal legal activities. If submitting such a request has the potential to cause such undue stress, shouldn't society create protections or disallow such requests? Edit: It's not that hard to see that there are potentially some social problems here e.g. "the message is easily construed as a legal threat" or "the message was mass mailed in a spam-like nature". However, my comment is in response to the title of the blog post which implies that the webmaster believes there's an ethical problem that this "experiment" was even run in the first place. For the purpose of this thread, assume the email was worded perfectly and the university was very thoughtful and deliberate in who they contacted. I'm interested in discussing the ethics behind how a perfectly legal and reasonable thing can in one case be ethical and another case be unethical simply by virtue of the context in which the action was carried out.
- analog31 5y agoIn my view the academe can't control how people treat one another in general, but they can refuse to support research based on abusing people.
- jameshart 5y agoThis argument amounts to "If something can happen, then it's okay for a researcher to cause it to happen in order to study the result." I hope it's obvious why that is a poor ethical standard for what constitutes acceptable research practice.
- mjfl 5y agoThis is going to be disagreeable, but as someone who was blocked from starting a COVID surveillance program at my uni due to the IRB constraints on "human subjects" - would need to buy special, expensive software in order to prevent test results from being 'deanonymized' - I think this space is too regulated already. In some cases, people with apparently legitimate ethical issues should have been told to shove it, in my opinion. Innovation is being destroyed to protect people's feelings.
- et2o 5y agoCould you post your study proposal and the IRB response? This does not seem realistic.
- shadowgovt 5y ago> Innovation is being destroyed to protect people's feelings. Yes, it is. This is not a bad thing. A lot of the calculuses that conclude it's a bad thing are fundamentally dehumanizing.
- mjfl 5y agoCalculus: Having campus-wide COVID surveillance running (before any alternative testing options had sprung up) is more important than preventing ANY RISK of someone experiencing stigma for having had COVID. I think this calculus holds up and is not that dehumanizing. I'm not saying we should get rid of all protections, but that pendulum is too far on the regulatory side right now.
- shadowgovt 5y agoIn that case, just cut out the middle man and start reading their medical records. Who needs privacy? (... And then people rationally respond to such an invasion by no longer going to the doctors and lying about their medical history...) We can't interpret people's desire for privacy as damage and route around it. There's decades of history of scientists interacting with the public to show why that has negative consequences for society.
- 5y ago
- renewiltord 5y agoLmao I periodically troll my friends by sending them GDPR and CCPA notices. If you did this to my blog, I’d let you take me to small claims or whatever. The probability of you making it all the way to prosecution and the total harm is so low that I’m not going to CCPA or GDPR enforce on my blog. Bite me.
- yjftsjthsd-h 5y ago> The probability of you making it all the way to prosecution and the total harm is so low that I’m not going to CCPA or GDPR enforce on my blog. I hope this line would get included in discovery; I would... actually pay money to watch you explain to a judge that you explicitly decided to ignore the law. (IANAL, but I'm pretty sure the real defense would be that the law actually doesn't apply to you)
- deleted 5y ago[deleted]
- Ekaros 5y agoWith GDPR you can't even take it to court. That is not your option. And the agencies have lot bigger things to do. So unless you did some extremely blatant I would evaluate risks to be non-existent.
- MattGaiser 5y agoI have a not at all popular and rarely used blog. I still get dozens of stupid spam emails and comments a day and often some phone calls too. This would not have caught my attention for more than 10 seconds, if I even read it at all and it did not get filtered out by various spam tools. I am quite perplexed at the people who panicked over this. It would probably rank 4th in the scariest things I have received today and seems on par with a call from the tax man claiming you owe them money and need to send them iTunes gift cards.
- TedDoesntTalk 5y agoExactly. Maybe we need better internet safety education like my 13 year old gets in school. One of the topics is “ways to identify spam”.
- iudqnolq 5y agoBut in retrospect you guess this was spam would have been incorrect. It was a carefully crafted action by a researcher. Maybe their intuition was actually better?
- TedDoesntTalk 5y agoIt is spam. Whether or not the author is a researcher or scam artist is irrelevant; it is still spam.
- nullc 5y agoImagine I dig a dangerous deep pit in my front lawn by the sidewalk. 99 out of 100 people are going to safely avoid it. 1 in 100 fall in and get severely injured. I'm still at fault even though the injury only happens rarely. And a "rare" effect can harm a lot of people when you scale up the exposure far enough. Those scam emails also cost a lot of people time and we rightfully outlaw them. In this case, it didn't fit the modality of the common scam messages, it looks a lot more like a professional litigant trying to set the recipient up for a lawsuit.
- jollybean 5y agoPut a PO Box mailing address on your website and mark any email that you don't want to read as spam. If someone is serious about getting a hold of you, they can buy a stamp.
- avalys 5y agoI don't see anything unethical about sending an email asking website operators how they comply with their obligations under various privacy laws. If you are not subject to those laws, you can reply as such. And if you are subject to those laws - it is a valid question! If you find the prospect of receiving this email so horrifying, perhaps your real problem is with the laws themselves?
- s1artibartfast 5y agoSo you see nothing wrong with the deception of pretending to present an honest inquiry when in fact you are not? If this came from a real person and was a real question then of course it would be ethical, but it wasnt
- Ekaros 5y agoNo not really. Might have been better to hire someone in these legislations to send the email, but I don't think that would really have changed the ethics. These unethical businesses have not followed the laws and now are crying...
- deleted 5y ago[deleted]
- pkrotich 5y agoInteresting - we received the same email but requester was a resident of Roanoke, Virginia. And the request was in regard to GDPR. It smelled like SPAM enough for me to check the email headers - SPF and DMARC passed and was sent from potomacmail.com servers. Another odd thing was - the request was for a customer using our SAAS application - so their targeting is not exactly accurate. I wanted to ignore it but we get emails all the time meant for our clients - so we simply replied that they should direct the request to the party in question.
- perihelions 5y agoIt looks like multiple people consulted lawyers because of the implied legal threat. OP isn't the only one who took this somewhat seriously. Attorney: "is this Princeton privacy study email that one of my clients received legitimate?" https://twitter.com/jdigiacomo/status/1470756584435249152 https://twitter.com/jdigiacomo/status/1470756584435249152 "Wow. I actually contacted my attorney over this email inquiry to see if I actually needed to respond and if so, how." https://twitter.com/NerdPress/status/1472340768933113859 https://twitter.com/NerdPress/status/1472340768933113859 "our clients have spent around $10k aggregate trying to understand what these requests related to, and whether this was a coordinated mass phishing attempt" https://twitter.com/FDTaisce/status/1471970527132618757 https://twitter.com/FDTaisce/status/1471970527132618757 An attorney in Switzerland: "Wir wurden von Mandantinnen und Mandanten gefragt, wie sie auf diese E-Mails mit Fragen nach ihrem Umgang mit datenschutzrechtlichen Anfragen reagieren sollen." ("We have been asked by clients how they should respond to these emails with questions about how they handle privacy-related inquiries." (DeepL)) https://steigerlegal.ch/2021/12/16/datenschutz-gefaelschte-anfragen-dsgvo/ https://steigerlegal.ch/2021/12/16/datenschutz-gefaelschte-a... Three *different* attorneys in this thread report having clients reach out to them: (1) "As outside privacy counsel, these are so frustrating. First one I saw cited being a CA resident so more alarming. Now for those interested\able to learn it's more time and education as they think any request must be scams now. Plus how many clients won't reach out next time?" (2) "As in-house counsel, my initial gut instinct was that it was someone who was trying to entrap us - hoping we would make a mistake so they could sue. (I don't have much faith in human nature, I suppose.) So I sent it to outside counsel to be safe. Waste of time and resources." (3) "Same here. We deal with a lot of professional litigants and I was looking for the angle (it was GDPR not CCPA, so was worried about a private right of action being brought)" https://twitter.com/JFuchsKC/status/1471921893758443526 https://twitter.com/JFuchsKC/status/1471921893758443526 https://twitter.com/DanielleVEsq/status/1472105731474137094 https://twitter.com/DanielleVEsq/status/1472105731474137094 https://twitter.com/SOliverLaw/status/1472288392889073665 https://twitter.com/SOliverLaw/status/1472288392889073665 (Sorry for the spaghetti comment: I got a bit carried away).
- perihelions 5y agoOne more attorney (I'm past the edit limit for the parent comment): "I got this. It took time out of my day, but thankfully my French employer hired an American lawyer with CCPA experience (*cough* me) so it just ended up being a brief distraction." https://twitter.com/jkosseff/status/1471816212732596227 https://twitter.com/jkosseff/status/1471816212732596227 He says he sent back a GDPR demand letter.
- quadrifoliate 5y agoA lot of people mocking the author or others for being scared and worried are basically blaming the victim here, and I would like them to stop. The nature of legal practices in the USA is such that the answers to "Are you totally in the clear legally?" and "Will you lose significant amounts of money proving in random courts that you are in the clear legally?" are often both yes. As a result, any researchers who send out thinly veiled legal threats as a "research experiment" are firmly in the wrong ethically, and should be called out by all the people to whom they have issued these veiled threats. Review boards that approved this experiment should be themselves subjected to an audit and potentially dissolved.
- walrus01 5y agoAbsolutely agreed. In the present USA legal system, even if you win a resounding "victory" against an absolutely frivolous civil litigant, you are often left with significant legal costs and wasted days of your own time that you could have spent doing something else with your life.
- 0cVlTeIATBs 5y agoWhat specifically is there to fear from an email like this? For one the sender opens by admitting they are not protected by the CCPA, and a quick reading about this law shows it does not apply to an individual's personal blog. If a Russian were able to file suit in California, wouldn't the defendant have a chance early on to ask a judge to dismiss it? I'm trying to sound naive because I want some gory details.
- walrus01 5y ago> If a Russian were able to file suit in California, wouldn't the defendant have a chance early on to ask a judge to dismiss it? a particularly foolish or over-confident defendent might represent themselves, but otherwise, I would not budget less than $2000-3000 to hire a lawyer to draft and file a response to statement of claim and show up in court to attempt to get it dismissed before it gets started.
- 5y ago
- JamesCoyne 5y agoGoing back to study homepage here https://privacystudy.cs.princeton.edu/ https://privacystudy.cs.princeton.edu/ there is another update, now from the lead investigator, that includes the following paragraph: "Second, our team is prioritizing a possible one-time follow-up email to recipients, identifying the academic study and recommending that they disregard the prior email. If that is feasible, and if experts in the email operator community agree with the proposal, we will send the follow-up emails as expeditiously as possible." Did this study send automated emails in such volume that they can't work out how to send an apology without triggering spam protections? Or did they send email and not record it? What is he saying here?
- desdiv 5y agoThis is my interpretation of their dilemma: "We screwed up by spamming a lot of people. We like to apologize and fix our mistake. We currently have two options: 1. apologize by sending a second email. This second email will contain an apology and the phrase 'disregard the prior email' 2. apologize by some other method (e.g. this website) Option #1 pro: reaches everyone we're previously spammed Option #1 con: we will be spamming people a second time. If the first round of spamming puts us in legal/ethical jeopardy, then this second round of spamming could make it worst We have not performed Option #1 yet. We do not know whether we should perform Option #1 or not. We are taking the temperature of the 'email operator community' to see whether we should performed Option #1 or not. If Option #1 gets the green-light then we'll do it ASAP."
- deleted 5y ago[deleted]
- shadowgovt 5y agoWhat are the legal requirements for a blog run out of American servers by an American to be GDPR compliant these days? I'm sort of wondering whether you can get away with responding to such a request these days with "I am not in a jurisdiction that is obligated to comply with that law, and if you choose to charge me with violating it I am not under obligation to defend myself in court nor render myself for judgment?"
- jahewson 5y agoAs long as you’re not collecting the personal data of Europeans, there’s basically nothing you need to worry about. Your location and jurisdiction are mostly irrelevant - you’re obliged to comply with that law when you offer a your website in Europe. Of course the only possibility of enforcement is also in Europe, so there’s not much going to happen. I suppose if you ran a rogue business then in theory credit card funds from European customers could get frozen by a court or something - but let’s be clear, GDPR is aimed at regulating big business primarily. Nobody is coming after your blog
- shadowgovt 5y agoThat's what I'm thinking. If you're not European, it basically boils down to the realpolitik of whether your home country would render you up to European judgement or other private businesses you deal with would choose not to deal with you because you don't bother to say whether or not you comply with the GDPR.
- TedDoesntTalk 5y agoWhy would it be different than the rules of jurisdiction for any other civil law?
- omgitsabird 5y agoDoes anyone know an actual case of an individual blogger getting fined under the CCPA?
- Godel_unicode 5y ago> This scared the shit out of me This is satire, yes? Come on.
- TedDoesntTalk 5y agoThink how he must react to those “you owe the IRS $20,000 in gift card” emails or “we have your personal email archives and will post them for all to see unless you send 2 bitcoins by Friday 8:00 UTC” Some people need to look at what insults them and maybe reflect on why such things are insulting, or what it even means to be insulted in the first place.
- beervirus 5y agoA human research study? Give me a fucking break. >someone asked me a question and it scared me
- yjftsjthsd-h 5y agoIt's a research study on humans, so... yes?
- beervirus 5y agoIt’s a survey question.
- idiocrat 5y agoIf there were a contratial agreement before the start of the study, the participants could have negotiated the monetary re-imbursement for the work done. (including data processing fees and the legal consultation). By coercing the participants into study the university has in fact waived own negotiation rights. The university should compensate the participants for the actual work done, at the a fair market rate, and reimburse the legal fees. (I am not a laywer).
- ebcode 5y ago#metoo
- varelaz 5y agoThere is a logic error in this email. If this is not a request they cannot claim 45 days to response. So refernce to CCPA 1798.130 was clearly just to scary.
- throwaway600090 5y agoWould it make sense to pursue a class-action claim against Princeton and the researchers to recover everyone’s legal costs and business disruption costs? Probably wouldn’t be that difficult to get the contact information of every business that was contacted during discovery, right?
- Ekaros 5y agoI wonder if there really is a case. I don't think you can sue anyone for your needs of fulfilling your legal obligations. After all, if these people had fulfilled their legal obligations they could have given response with minimal cost.
- dawnbreez 5y agoNot a lawyer, but I'd imagine the most useful point to make is that the researchers misrepresented their identity while sending these threats. Lying about who you are while trying to sue someone is a pretty big no-no.
- 5tefan 5y agoI think you need some basic legal understanding to sort that kind of stuff into valid, unsure and invalid. It then depends on your confidence level if you require legal advise. Easier said than done. From my point of view 45 days is plenty of time to read into the topic. On the other hand: Referring to 45 days was shooting way beyond the target here and unnecessary. Scaring the author was wrong and by definition always happens without consent. That's what the author can blame the researchers for. This was turned into a 'without consent' situation and I find this to strong. The email is rather clear but is also weird enough to feel like scam.
- dawnbreez 5y agoAs has been pointed out elsewhere: "Consent" here is the correct term. This was a study, and studies are supposed to gather consent from participants before they start (barring certain very specific examples).
- noduerme 5y agoThe study was disgusting; I've commented about it in another thread. But I think there's something else here that explains the strong reactions people are having to this. We as software engineers are not used to being told by a government how to build our code. If China passes some law saying that you can't directly search a database without routing the call through a government server, I don't care. I'm not going to research their laws and make sure my code conforms to that. It's not my problem. It's the people of China's problem. If a company I'm working for has a legal team that says they need to accommodate that, they'll tell me they need to write some code to do it. I'm free to write it for the money, or tell them to fuck the CCP and themselves. But if I happen to know that a client is using my code in China without meeting some regulation there, it's not my obligation to inform them. Best of luck. I'm not personally liable for that. And so what happened here is, they went after developers and small self-coded sites. They intentionally went after the people writing the code, not the companies that have legal compliance departments. So the big question it presents, that I think has some people hopping mad and other people too sanguine, is: Does this herald a wave of assault and blackmail against developers, where bad actors (or dumb actors, like Princeton undergrads) will use supposed infractions of local laws to try to extort settlements from makers of software? I mean, show me a piece of software, and I'm sure it would be illegal somewhere. But the question of threatening small developers this way is new - it's a new form of trolling, like patent trolling but potentially even worse. The novelty of it and the potential for abuse is why I think a lot of people have been outraged by it, more than the question of whether someone should have just ignored this particular email. It presents an entirely new chilling effect that changes the bar for anyone looking to start a website, among other things. If any newbie coder had to make sure their code conformed to every legal requirement around the planet before putting it online, their chances of being successful with new code would be nil, and our livelihoods and creative capacities would be severely diminished. Our entire culture of making things would be crushed. An entire category of artistic creativity and originality that most of our lives are based upon could be shut down completely by a blizzard of emails like this one. I don't think it's overreacting to be alarmed by it, nor to be furious at this approach being pioneered by a supposedly liberal institution.
- silisili 5y agoI'm so confused by the comments here. Californian consumers regularly, and rightly IMO, laud the CCPA. Then when on the receiving side, view it as a threat and freak out. Note: I'm ignoring the whole lying aspect for now, because it isn't pertinent to my argument. So it sounds like it's good for consumers, and a nightmare for producers. Seems the crux of the problem is the law itself.
- ehsankia 5y agoI must've read the phrase "thinly veiled threat" at least a dozen time in this thread, yet honestly don't understand where the threat was. Maybe the last sentence where they put a deadline on it, but that part was strange anyways since they explicitly said this is NOT a CCPA request, so that deadline doesn't even apply to this email. The person seems to just be asking questions about the process and came off to me more as curious than threatening. Whatever veil there was most definitely was not thin in my opinion.
- dawnbreez 5y ago> Maybe the last sentence where they put a deadline on it, but that part was strange anyways since they explicitly said this is NOT a CCPA request, so that deadline doesn't even apply to this email. That's the threat, yeah. And yes, it's not technically correct--but, as many others have pointed out, you don't need to have a correct legal claim to inflict thousands of dollars of legal fees on a target. Hell, part of what those legal fees pay for is an expert to explain whether or not that deadline applies. More than that, most people simply do not have the time to memorize laws, or to get the legal background required to understand whether a law applies. This is partly a problem with laws being complex and having their own jargon--but that doesn't excuse what's going on here.
- UncleMeat 5y agoYeah this one is weird to me. How many "I sent GDPR requests to all the services I use and this is what happened" blog posts did we read when GDPR first went into effect? Should academic research be held to a high bar? Yes. Did this cross a line? From the response and subsequent apology, clearly. But the outrage here feels at least a little disproportionate.
- a-dub 5y agoam i missing something? i don't see anything about research or studies in the original email. maybe it's a legitimate inquiry? maybe it's performance art? (does the blog post have to be taken down if a right to be forgotten request is filed?) does the ccpa even apply to hobby or non-revenue generating endeavors?
- dawnbreez 5y ago> am i missing something? i don't see anything about research or studies in the original email. That is, in fact, the entire problem. The researchers doing the study lied about who they were and where they were from (in another case, they claimed to be from France; in this case, from Germany) and did not tell anyone it was a study until after some subjects contacted lawyers. Also the CCPA isn't supposed to apply to hobby/no-revenue sites, but one of the things that qualifies you for CCPA is having PII from 50k Cali residents, so if you log IPs in just the 'right' way and Hackernews finds your site you may end up qualifying overnight.
- a-dub 5y agoi see. it appears the post has been updated. last night it had the title and reference to the university of minnesota kernel security study, but no actual reference (unless i missed it!) to the fact that this was a princeton study.
- lisper 5y agoMy take: yes, a researcher misrepresented who they were. But that misrepresentation had nothing to do with the alleged harm. I see no reason to believe that the writer's reaction would have been any different if the request had been a completely legitimate one, which it very well could have been. The actual substance of the request was polite, non-threatening, and potentially legitimate. If the writer had bothered to do even a few minutes of research, she would have realized that the cited law did not apply to her and the requester was simply wrong when they said that it was. A panic attack was IMHO an extreme overreaction. Solicitations are sent out under false pretenses all the time by people with far more sinister motives. I think it's reasonable to expect adults in today's world to be able to take such things in stride and not freak out about them (or at least do a little bit of homework before freaking out).
- lysium 5y agoWhy did the university not disclose this is a research study? For their own gains, on the back of their research subjects. This is a shitty thing to do, even if it might be legally allowed. You cannot expect everyone to take that email easily.
- jeroenhd 5y agoOn the one hand, I think this research is done with bad ethics. Proper science requires consent of the people involved in experiments. An organisation like this should know better. I think that's the reason this research needs to stop and go back to the drawing board. On the other hand, anyone in California could send such an email legitimately. If you're offended by the contents of the email rather than by the research itself, I have bad news for you: the text itself is perfectly fine. Someone can, and should be able to, exercise their rights regarding data collection. That goes for Big Tech which these laws are aimed at, but also for any other party our there collecting data. If you're afraid of someone exercising their digital rights, you should probably not host anything public. The real problem here is not the research itself and not even the laws the research is about, but about the litigious nature of some countries. Bad research happens, turning this research attempt into a spam campaign. Everyone gets spam, it's not a reason for panic. It's only a problem when you think any email you receive can actually be the basis of a life-altering lawsuit. If you are someone who got spooked by such an email, I can't help but think you might not want to publicly host anything. Attaching any kind of data collection to the web has come with legal implications for years now, even before the GDPR was a thing. This time it was a malevolent researcher; next time it might be someone who demands that their IP be purged from your logs. Look at this shoddy research as a training exercise, and consider if you're prepared when a real version of this email comes in, before it's too late to do anything about it!
- grouphugs 5y agowe all were, you're not fucking special
- verisimi 5y ago[flagged]
- johnchristopher 5y agoThis really feels like the long consequences for "it's just a prank bro" and "it's a social experiment (to totally misguide you into a behavior and claim it's a prank")". Anyway, 127.0.0.1 - - [18/Dec/2021:04:04:57 +0000] "GET /security.txt HTTP/1.1" 404 2110 "-" "Go-http-client/2.0" I suppose there are no IP anyway and the reverse proxy doesn't forward them.
- xena 5y agoAuthor of the article, I replaced an actual IP address with 127.0.0.1 because I didn't want to list some random AWS IP on my blog without knowing who it is related to.
- johnchristopher 5y agoAny reasons why you keep them (beyond blacklisting I guess) and can't do without logging them ? That'd be one less pain point. Love the look of the site btw :).
- irthomasthomas 5y agoSaid everyone with a facebook account.
- stavros 5y agoI got an email from them too, asking about GDPR compliance. Isn't unsolicited mass email illegal under the GDPR? Maybe I should threaten to sue them.
- fsh 5y agoGDPR is about storing personal data. Why should it be illegal to send emails to whatever address you like?
- Ekaros 5y agoDepends on where you got it. For business email it is unlikely to be personal data. Unless it is something like name.surname. And even then I think this is reasonable use case. So not really problem with GDPR.
- mission_failed 5y agoAt this point all outgoing email from Princeton should be flagged as potentially malicious. Their ethics committees seem to have no problems with using deception against non consenting test subjects, or actively trying to sabotage software projects, because 'using a computer' seems to be their catch-all for 'approved'. Maybe then their executives will seriously review what their researchers are doug9.
- dqpb 5y agoSo, I think the question is: Can recipients bring a class action lawsuit against Princeton?
- Abimelex 5y agoI don't know about US, but GDPR request in EU is something totally common and nothing to worry about as long as not you locally data protection officer get's involved ;) I do detailed GDPR requests from time to time, especially to companies that annoy me with personalized marketing, just to mock them.
- hermitcrab 5y agoI got 2 of these emails. One CCPA and one GDPR, but the exact same boilerplate. So I knew it was sketchy. But I still wasted an hour of my time deciding whether to reply. Several of my colleagues in other small comapnies also received these emails. Multiply that by the thousands of emails they must have sent and that is a lot of time wasted. I believe some people even paid laywers to respond. So potentially a lot of money wasted as well. The senders either they didn't realize the sort of time and waste of money this would cause, in which case they are idiots, or they did, in which case they are arseholes. How did this get past the Princeton ethics board? What if every researcher started spamming thousands of businesses without their consent?
- xena 5y agoI am the author of this article if anyone has any questions.
- 6chars 5y agoNo question, but I just want to sympathize with your distress over receiving the original email. It's impossible to say for sure because I didn't receive one, but I think I would have reacted the same way. I am also very frustrated on your behalf with the way people in these comments are talking about you and others who read this email as a legal threat. It's telling about many HN users' capacity for empathy that they think their reaction, real or hypothetical, has anything to do with whether this was a bad thing. Regardless of how any of us would react, it's clear from the many people who lawyered up or experienced anxiety because of the emails that this study had victims. Not seeing them as victims because you would have disregarded the email reveals what I'd consider a solipsistic mindset that causes them to regard others' experiences as less valid than their own.
- kstrauser 5y agoHey Xena, I’m glad your post is getting seen, too. I’m dismayed at how many people seem unable to imagine why you and I freaked out when we got letters from someone who sounded like they were a professional litigant. I’m glad to see the researchers, lawyers, and such talking about the ethical implications. This is a messed up situation, but it’s comforting to know I’m not alone in it (although I wish for your sake that you weren’t involved).
- muraiki 5y agoApology from the PI, permanent suspension of sending emails, possible follow up emails telling people to disregard the original emails, and commitment to a formal research ethics study: https://twitter.com/jonathanmayer/status/1472427321047101442 https://twitter.com/jonathanmayer/status/1472427321047101442
- pueblito 5y ago> I go out of my way to ensure that this website handles as little user data as possible. I have gone so far to do this that the only unique identifiers I deal with are IP addresses… This page uses Cloudflare so they’re offloading data collection but it’s still being done, right?
- xena 5y agoI use Cloudflare because I've gotten DDOSed over my blog before. Being openly not male on the internet is a great way to get people DDOSing you and sending nasty letters to your employer about your moral character. Sorry I have to do this, but I don't really want to be DDOSed over my tech writing.
- EGreg 5y agoI went to their website, and it says: Note from Jonathan Mayer, the Principal Investigator Hi, my name is Jonathan Mayer. I’m the Principal Investigator for this academic research study. I have carefully read every single message sent to our research team, and I am dismayed that the emails in our study came across as security risks or legal threats. The intent of our study was to understand privacy practices, not to create a burden on website operators, email system operators, or privacy professionals. I sincerely apologize. I am the senior researcher, and the responsibility is mine. The touchstone of my academic and government career, for over a decade, has been respecting and empowering users. That’s why I study topics like web tracking, dark patterns, and broadband availability, and that’s why I launched this study on privacy rights. I aim to be beyond reproach in my research methods, both out of principle and because my work often involves critiquing powerful companies and government agencies. In this instance, I fell short of that standard. I take your feedback to heart, and here is what I am doing about it. First, our team will not send any new automated inquiries for this study. We suspended sending on December 15, and that is permanent. Second, our team is prioritizing a possible one-time follow-up email to recipients, identifying the academic study and recommending that they disregard the prior email. If that is feasible, and if experts in the email operator community agree with the proposal, we will send the follow-up emails as expeditiously as possible. Third, I will use the lessons learned from this experience to write and post a formal research ethics case study, explaining in detail what we did, why we did it, what we learned, and how researchers should approach similar studies in the future. I will teach that case study in coursework, and I will encourage academic colleagues to do the same. While I cannot turn back the clock on this study, I can help ensure that the next generation of technology policy researchers learns from it. Fourth, I will engage with the communities that have contacted me about this study, which have already offered valuable suggestions for future directions to simplify, standardize, and enhance transparency for GDPR and CCPA data rights processes. I very much appreciate the earnest outreach so far, and I will be reciprocating. If you have questions or concerns about the study, please do not hesitate to reach out. I gratefully acknowledge the feedback that we have received. Thank you for reading, and again, my sincere apologies.
- Ekaros 5y agoI don't really see any issues with this. If you are subject to any of these rules you and your business should be ready. If not they shouldn't be a concern. Absolutely nothing unethical going on here. Apart from crap business not wanting to follow the legistlation.
- jollybean 5y agoLying about one's identity is unethical.
- Ekaros 5y agoSo is not following laws... Or being certain that they don't apply.
- jollybean 5y agoIt's not clear that anyone was breaking laws, and it's absurd to suggest a random person with a website in the middle of nowhere is going to have insight into the laws of 165 different national jurisdictions.
- juanani 5y agoSimilarities of what FB/Meta was caught doing. 'human subject research without consent'. I spos the difference is they threw a ton of money on PR and it was swept under the rug, but universities cant afford it(surprisingly those tuition fees havent been diverted to PR). FB would be dispatching teams of lawyers/shills/other dirty tacticians on these blog writers. Thankfully universities havent seen much decline in sheep desperate for a framed piece of paper so they dont see really lose from this negative PR. I wonder how many non-consensual studies(swept under rug) we go through in life these days.
- skrebbel 5y agoWe got this email at my startup. We freaked out too, we're not from California (or even the US), we're not end-user facing so usually privacy stuff goes to our customers. We'd never received a mail like that. We responded with a kind reply, but had a lot of internal discussion. Our nice response included questions which never got answers. Because screw real people, right? Experiments like these are training well-meaning people to ignore real privacy requests.