10 ms·
My team used to buy location data that we packaged up into reports for equities investors - the premise being the more foot-traffic your brand had, the more rev
by Cd00d 4y ago
My team used to buy location data that we packaged up into reports for equities investors - the premise being the more foot-traffic your brand had, the more revenue you're likely to have.
Tons of apps sell this info. I think a lot of the 3rd party weather apps have been the traditional worst offenders because everyone wants to know the weather where they actually are in the moment.
- kennywinker 4y agoI know the "best" way to stop this kind of privacy violation is good consumer protection and privacy laws, but I wonder if we couldn't also regulate the downstream market. I.e. make the sale and resale of personal data, as Cd00d is describing, illegal. It seems pretty proven that the humans doing that buying and selling aren't going to stop doing it out of civic responsibility or moral disgust
- amluto 4y agoI think the best way is to attack the market from all sides. - GDPR-like legislation to try to prevent the inappropriate collection of this information. - Ban the sale of or trafficking in illegally collected personal information. Apply serious monetary penalties to anyone who sells such information improperly. Additionally, anyone who sells such information and subsequently learns that it was improperly collected or was GDPR-deleted must tell their buyers, who must then delete it. - Buyers are liable if sellers are found to have violated the rules and don’t pay. They are also liable if they fail to honor delete requests. Buyers who consider this liability unacceptable may attempt to purchase or require insurance.
- jonhohle 4y ago> Ban the sale of or trafficking in illegally collected personal information. In the US isn’t the sale of illegally acquired data already illegal under 18 U.S. Code § 2315? I wonder if any existing stalking laws would cover existing data collection practices. Most people are upset when they learn there are records of their location down to a meter or so wherever they go that are sold to anyone who wants it. Does that meet the bar of “emotional distress”?
- minsc_and_boo 4y agoThat's still whack-a-mole. Even if you changed the rules to selling user data, these apps would just update it in their TOS that consumers agree to without reading. Even laws have this problem. There are so many cookie bars on websites that users just click through them anyways.
- mr_toad 4y agoYou can’t agree to something illegal. If the law makes it illegal for third parties to use location data then it doesn’t matter what the TOS are.
- l33t2328 4y agoYou’re saying it should be illegal for you to decide who can do what with your data? If I want google to sell my data in exchange for keeping Youtube free, that’s 100% my prerogative
- kennywinker 4y agoWhack-a-mole by the way the laws are written. You can write laws that aren't whack-a-mole. E.g. "it is illegal to sell or transfer user's data to another company without positive informed consent from the user within 1 month of the transfer" Every time a company wants to sell on your data, they have to email you and ask permission. Not responding to that message isn't consent. Find a loophole in that.
- runnerup 4y ago> Find a loophole in that. Enforcement.
- mattnewton 4y agoThey’ll just come up with some aggregated form of the data they claim doesn’t violate the letter of the law, sell that, and be in business for years before anyone finds out let alone tries to enforce the rules and find out of they are violating it. This would honestly still be a huge improvement imo, as even forcing data brokers to anonymize or aggregate the data, even if it is ultimately not actually providing privacy, is still a recognition of the problem over the current system in most states.
- Cd00d 4y agoHonestly, I'm not sure it needs to be illegal. I'm not sure it shouldn't be either. I wholeheartedly admit, some of our data providers are shady, and there's no way I would go work for them. I don't like the way they mislead people. That said, the data we get is anonymous. Sure, if I know enough about you, and you're in one of my panels, it's feasible that I might be able to figure out which panelist you are. I know there's been some kerfuffle there with less than upstanding "private investigators" and bounty hunters in the past. But, the data we deal with is far too expensive for those sorts. We find valuable consumer behavior insights the data at regional levels. That creates information that's valuable not only on Wall St, but to retailers and brands, who are desperate for anything to help them understand market share and loyalty. I dunno. It's a weird world. It's also a very commoditized world. Just having access to the data is no longer the main value add - you have to provide the meaning of it as well.
- ProjectArcturis 4y agoThere's no way to anonymize location data. Where does your phone spend the night plus where does your phone spend the weekday equals a unique identifier when cross-referenced with an address database.
- burnished 4y agoBin it until its anonymous again. Your route is too identifying, but is "people who appear to be driving away from a residential location between 9:30 and 10"? Fun to think about.
- Cd00d 4y agoThat's a fair point, and I'm guessing why my previous comment is being downvoted. I know our location provider did some things proactively - like they would not geofence hospitals, for example, but "home" is likely very visible. That's a dataset I didn't work on as much, so maybe I'm not being sensitive enough to the "this should be illegal" argument. I guess on reflection misleading you for the collection should be illegal, though how to do that isn't obvious. What I've worked on the most is people's credit card transaction histories, and that's quite a bit more naturally anonymous, though again, if you know enough about a person they would be discoverable.
- verisimi 4y ago> I know the "best" way to stop this kind of privacy violation is good consumer protection and privacy laws But I don't want any of my data collected or shared! The laws you are hoping for won't allow that - if they existed, at best they would only allow those companies to whom you have consented. Ie the mega-corporations. Local shops would be the ones without the data. Which would be pretty much exactly the opposite way I would choose to share my data, if I were forced to by law.
- rapind 4y agoEasy solution is to make user data toxic. Make it a liability. Poison the well. Make a law where if you ever sell a minor’s data, regardless of whether that minor lied about their age or agreed to a contract (wouldn’t be binding!), then you face steep fines. If you’re found buying data belonging to a minor, also steep fines. If you buy and then de-anonymize data belonging to a minor, really steep fines. To collect and hold data that may belong to a minor, you need to justify it (like GDPR). Obviously this doesn’t scale for aggregators, advertisers, basically SV, which is the point. A restaurant is responsible if they sell booze to a minor. A store is responsible if they sell cigarettes to a minor. Serving a minor that lies about their age does not get you off the hook! Problem solved. User data is toxic. You won’t want to hold onto it for any other reason than a legitimate use.
- toss1 4y agoRight direction, not far enough Steep fines are barely a speed bump to either a profitable business or a scammer. They take years to actually get implemented, don't survive bankruptcy and get reduced in court. Jail time. Mandatory. Zero room for judges and juries to go easy on the perps. Even this does not stop white-collar crime, but it maybe slows just a little bit of it.
- rapind 4y agoSteep fines for “each” occurrence. You can most definitely deter all but the dumbest companies from trafficking in toxic data. Are you going to buy shares in a company who’s entire worth is derived by it’s user data when it turns out that a significant but unknown amount of that user data is actually a very expensive liability? There’s always going to be someone searching for loopholes, like anything, so keep it unambiguous and straightforward.
- toss1 4y agoYup - also provide for bounty-hunting - anyone who finds a violation gets a share of the fines...
- 4y ago
- webnrrd2k 4y agoI wonder... Is there a way to overwhelm them with useless junk data? I'm just thinking out loud, but maybe send my own phone a bunch of fake GPS signals, say, within my own house? Or maybe, somehow 'trade signals' with someone else in a way that collecting the data is useless? Or store my phone in. Faraday cage when I'm not specifically using it? Im sure other people who know the specifics better than I do will flesh it out better that I have, but maybe this will get the ball rolling...
- Nextgrid 4y agoAdNauseam attempts to do that with ads: https://adnauseam.io https://adnauseam.io I was thinking the other day of setting up a bunch of VMs with some browser automation with the goal of aimlessly browsing popular sites with the plugin enabled in the background in order to have most ad providers blacklist my IP for ad fraud and thus not trust any data coming from me.
- addingnumbers 4y agoI only know one guy who used Ad Nauseum, two or three weeks later his gmail account was banned and to this day he has to complete a CAPTCHA every time he visits a Google site from his home IP.
- Nextgrid 4y agoThat would be a feature for me as I don't use any Google services. A Google ban would be more than welcome!
- BLKNSLVR 4y agoI'm wondering whether the opportunity to legislate consumer protection and privacy laws has long passed because enough companies have sprung up to take advantage of this covert surveillance data flood that there could be relatively severe economic impacts caused by any attempt at trying to dam it. ie. the political will to make any such changes just may not exist beyond pure lip service to minority who actually know and care. I've considered what the options would be for something like "privacy-as-a-service", but I get the feeling that such an industry would be more likely to be regulated to death than the one it's in reaction to. Ironically, "privacy-as-a-service" already exists to protect the financial records of those with big enough financial records to be able to afford said privacy protection service. One law for me, another for thee.
- Nextgrid 4y agoI think the opportunity has passed because companies who rely on violating privacy have effectively taken over humanity's social fabric. Any politician that attempts to regulate this can be thwarted by just shadowbanning any content that mentions them on social media - and he'd effectively disappear for a large chunk of people.
- 7speter 4y agoBecause political campaigns and parties use this data too.
- geysersam 4y agoThe opportunity absolutely has not passed. Widespread smartphone use is barely 3 election cycles old.
- robertlagrant 4y ago> One law for me, another for thee. That's not law, that's a service!
- ljm 4y agoThis is ostensibly the purpose of GDPR. Selling personal data is illegal unless the person opted in. It's opt-out by default. The problem is that it's the internet... the law works for honest websites and companies but not for anyone else.
- PeterisP 4y agoOn the other hand, the main source of the money for the industry - major advertisers - are legitimate above-board companies, who either are honest or are liable for enforcement. GDPR is not really about selling personal data but about using it; a big part of its effect is on buyers of data since GDPR effectively (there are all kinds of nuances) means that it's not legally possible for legitimate company to simply buy personal data for arbitrary purposes, since the data subject obviously did not opt-in to that particular purpose by that company when the data was collected.
- tremon 4y agoSelling personal data is illegal unless the person opted in That's not possible to opt in to under the GDPR, FAFAIK. People can consent to the purpose for which their data will be used, and any such purpose must be enumerated explicitly. "Selling the data" is not a processing purpose, and it would still be illegal even if the person consented (it does not meet the bar for informed consent). Under the GDPR, the only legal way for personal data to be transferred between companies would be for the "buyer" (processor) to use the data original data from the "seller" (controller) on behalf of the controller. The data, as consented to be collected, remains the liability of the controller for its entire lifetime.
- tlavoie 4y agoAlong with blocking commercial creepy behavior, I would love to see similar restrictions applied to governments that use commercial access to simply vacuum up large quantities of this information without warrants. (IIRC, ICE in the US is one well-known offender here.)
- raxxorraxor 4y agoAlso high retroactive fines because that data collection is illegal in some jurisdictions. People that sell this data aren't stupid.
- MaxBarraclough 4y ago> I know the "best" way to stop this kind of privacy violation is good consumer protection and privacy laws I agree such laws are necessary, but I'm not sure they're the best of the various solutions. Technical measures might be more robust, such as fine-grain permissions in mobile operating systems. I'd rather it not be possible to collect my data in the first place, than trust that some developer (in whichever jurisdiction) isn't breaking the law. An advantage of the web is that hostile code is more easily tamed than in native apps, but in itself this observation doesn't do the user much good. Apps are pushed in part because of their superior capabilities for user-hostile functionality. Similarly, Free and Open Source software is rarely this user-hostile, as few people have the nerve to publish their user-hostile code for all to see. Again though there's a sort of collective-action problem: if only the abstemious few like Stallman insist on not using proprietary software, things don't improve.
- bisby 4y ago"We need your location to give you accurate weather readings for where you are. We need internet access to fetch the weather data." Weather apps also have plausible excuses for requesting permissions.
- Scoundreller 4y agoThough I enjoy that apple at least let’s me give imprecise location to most maps. Would be nice if I could set it myself to X kilometres.
- deleted 4y ago[deleted]
- derefr 4y agoWeather data is so tiny that there’s no good reason to not just fetch the whole weather point-map for your country and then select from it client side.
- chongli 4y agoI just had a look at the per-app data usage on my phone. Out of a total of 5.7GB of data usage, the weather app used 12.1MB of data. Sure, that seems tiny. But I live in Canada where there are over 4000 weather stations. Multiply that by 12.1MB and you get 11.8GB of data usage for the weather app, dwarfing all other apps. Either the fidelity of weather data would have to be reduced, or the update frequency, or a smaller selection of weather stations would have to be downloaded from (those in my area), defeating the purpose of fetching the whole map (hiding my location info from the server).
- derefr 4y agoI have a feeling that weather data compresses together well — especially if stations 1. are ordered along a space-filling curve geographically, with read-outs of geographically-neighbouring stations in sequence; and 2. are stored column-oriented where each future time is its own column. Basically the same optimizations as you would use to store any other IoT time-series sample-cloud data. I suspect that, encoded this way, weather for 4000 locations wouldn’t be much bigger than weather for 1 location. Also keep in mind that half the reason the Weather app needs to use as much bandwidth as it already does, is that whenever you move even slightly, it can no longer give you accurate info without grabbing the point-forecast again for your new location. It uses far less data if you just stay at home all day every day. If it had a pre-cache of forecasts for the entire local area, it wouldn’t need to do that; it could just refresh once every few hours. Maybe even wait for you to be on wi-fi before doing so, if it has modelled you as usually connecting to wi-fi several times daily.
- benrapscallion 4y agoApple has the option of imprecise location for this very reason.
- blenderdt 4y agoThat assumes the location on the device is used by an app. But signals your phone is sending can and are also being tracked.
- dillondoyle 4y agoAnd they changed permissions to opt in. Different numbers for different categories, but I've read anywhere between 18 - 25% on the higher end opt-in success. But above example of weather app is a good trick though, probably gets more allow always on location than FB for instance. https://www.flurry.com/blog/att-opt-in-rate-monthly-updates/?__s=bht9zreccp3zxwi1nfut https://www.flurry.com/blog/att-opt-in-rate-monthly-updates/...
- xhrpost 4y agoI recently added AccuWeather back to my device. I didn't permit continuous access to location and it kept an incorrect city for the desktop widget. I was tempted to give full access but now I realize I'm best to just delete the widget at least and double check permissions.
- willstrafach 4y agoThey have some pretty bad past practices: https://www.zdnet.com/article/accuweather-caught-sending-geo-location-data-even-when-denied-access/ https://www.zdnet.com/article/accuweather-caught-sending-geo... And they have continued, off-and-on, to use other location-collecting SDKs.