5 ms·
I mean this all in good faith: What is the difference between 100,000 individuals emailing 3-5 websites on that list, with their real identities, asking for th
by throwawyaaccoun 5y ago
I mean this all in good faith:
What is the difference between 100,000 individuals emailing 3-5 websites on that list, with their real identities, asking for things to be deleted (such that all 350k are covered)? Where is the meaningful difference between this situation and the one here, ignoring the deception for a moment (unless that is the only issue)?
Could this be a moment of cultural learning for everyone? That's kind of how I am looking at it, frankly, but I am open to being wrong. That is, perhaps small entities will learn, in one or two instances, to just ignore this kind of thing?
- rectang 5y agoYou seem extremely unconvinced that any harm was done to the people who were sent scrambling by this alarm. It's as though no matter how convincing the email was, no matter how much of the recipient's time was wasted, no matter how many thousands of dollars they spent on lawyers, you ascribe all blame to the recipient for not having realized they were being deceived — and ascribe no blame whatsoever to the email's author for being deceitful. This whole discussion was had in the old thread, and there was one person who used the same rhetorical device of belaboring the same question over and over again. It was tiresome.
- throwawyaaccoun 5y agoI should have been more clear, so let me correct that. I am convinced. I agree that harm was done, and suffer from generalized anxiety disorder myself, so I empathize with the panic attacks that people received. It is because I believe that harm was done, but also because I am a privacy nut myself, that I am trying to, for my own sake, characterize how I should approach sending emails like this in the future. The study may not go on, but individuals still will send these emails as long as CCPA/GDPR exist. (Just to add some color: It's my anxiety which is causing my to want to delete everything from the internet. If there's minimal info about me online, I can rest easy. It's why this is a throwaway that I will abandon shortly.) Reading everyone's thoughts is what changed my mind. I now understand to have underestimated the emotional and legal effects CCPA/GDPR requests could have on small website operators, and will be more judicious in the future (like this study should have been) in pre-filtering and my wording. Reactions like kstrauser's (elsewhere in thread) were initially surprising to me (perhaps because of the faceless nature of the internet), so I hope you take my about face as genuine. Where do you think this balance lies? I still believe consumers, in general, should have right to ask those with their data about their processes; to give it to them; and, to upon request, delete it. And further, in general, I think these interactions are the kinds of things that researchers might legitimately want to study. I found your other comments to be thoughtful, so I am curious what you think explicitly.
- jwagenet 5y agoBased on reading https://news.ycombinator.com/item?id=29611139 https://news.ycombinator.com/item?id=29611139 the other day, my impression is for a small website operator the email template used some potentially threatening language in the line "I look forward to your reply without undue delay and at most within 45 days of this email, as required by Section 1798.130 of the California Civil Code." There is some discussion that for large websites or gov entities this kind of language may be necessary to communicate your sincerity with the request, but lone operators doing their best probably dont have any sort of legal to ensure they follow the letter of the law. From my perspective maybe its best to approach a small website with a more casual tone that you just want your data gone and "make it serious" if the request is ignored or the response is noncompliant.
- adolph 5y ago> how I should approach sending emails like this in the future Don't. It's that simple. I look forward to your reply without undue delay and at most within 45 days of this email, as required by Section 1798.130 of the California Civil Code.
- rectang 5y agoWhat I hope to see is a popularization of business models where no personal data is kept, because that is less expensive in terms of compliance costs, more beneficial to the consumer, and hopefully more attractive to the consumer as well. We can see the dawn of a new age in other comments in this thread where people talk about not collecting any data on their blog visitors! Right now it is difficult to build businesses under such models because most institutions, frameworks, and tools shunt you towards hoarding all data. Over time, I hope that better tools will emerge so that building better businesses becomes easier. There are people elsethread bemoaning not only the unfortunate artificial costs created by this email experiment, but the compliance costs of privacy-protecting legislation in general. But businesses should be paying those compliance costs, because it's an iron law at this point that business-collected personal data will leak yet individuals bear the costs when the data leaks. To my mind, this experiment went awry in the same way that privacy-abusing businesses go awry: the organization reaped a benefit while the externalized costs were borne by outside individuals. However, I'm inclined to forgive the researchers, as I think they will learn from this and find ways to collect data which cause less alarm and imposition. Similarly, I would hope that individuals pursuing their rights under privacy legislation would start off gently but firmly, giving small entities time to adapt. But simultaneously, I have an appreciation for those with bulldog tenacity who go after recalcitrant businesses (e.g. the heroes who have gone after Equifax in small claims court).
- s1artibartfast 5y agoIs about the impact on the humans involved. Imagine the study where are you put police lights on your car and drove behind people on the highway to see how they would respond.
- kstrauser 5y agoThing is, I would cheerfully process a deletion request, even though I don’t have to because I don’t meet the criteria to be subject to the CCPA. For me, part of the deception was quoting a law and incorrectly saying it obligated me to reply to their information request by a certain deadline. The law says no such thing, and getting a letter from someone who quotes specific legal codes almost never ends with “…and then they went out for dinner, newly found lifelong friends.”
- Beldin 5y agoIt may have felt like a deception, but there's plenty of bad legal takes on the Internet. For this to be a deception, the sender would have to know for certain that the statute doesn't apply in this case. Could be they did, but then I missed that. Just as likely, they genuinely thought this correct. The deception was hiding that this was a study, not a genuine request. Lying about or misrepresenting the goals of a study is deception research. There's strict guidelines for that... in the "soft" sciences (APA guidelines). CS is a bit behind and seems intent on reinventing the wheel :s.
- kstrauser 5y agoI'm not a lawyer or trained in legal jargon, so I'm using "deception" in the colloquial sense: I believe they lied to me and the other recipients.
- Luc 5y agoI am having a learning experience right here about reading the meandering thoughts of throwaway accounts.
- blululu 5y agoFirst, this is an altogether improbably scenario (the odds of winning the lottery are good compared to this scenario ever happening). Site traffic follows a power law. A site at 200k down the list is almost never going to get such attention. It is not someone's full time job. A uniform density of information requests is incredibly unlikely and places a very unfair burden on the smaller sites. Second, the difference is pretty obvious: 100,000 individuals seeking a legal right implies a potential benefit to a large number of people. 1-5 people abusing the system implies a bad faith actor whose benefit is pretty minimal.