13 ms·
The problem of creeping commercial surveillance (2022)
- theonlybutlet 3y agoBeen using DuckDuckGo's app privacy protection, some of the requests are just crazy, and from applications I haven't opened in months.
- malfist 3y agoWhat does that do that using uBlock with a decent block list doesn't? Not trying to be contrarian here, genuinely curious and wondering if I should install it on my phone.
- ta988 3y agoI use a similar one called TrackerControl (from fdroid) it is just incredible the number of trackers inside a single app. Some have over a dozen, this is getting out of hand.
- stvltvs 3y agoIt blocks trackers in other apps, not just in its own browser. It does this by acting as a VPN last I checked, so it wasn't useful in my case because it couldn't run at the same time as my other VPN.
- theonlybutlet 3y agoA handy alternative, is to temporarily utilize the app over a week or two to see what's making requests and then go into app permissions on that app and prevent it from using mobile data in the background and running in the background.
- SoftTalker 3y agoIs there a good reason to ever allow any app to do these things?
- xethos 3y agoYes and yes: I use syncthing, and I just want it to make the changes in the background. My best case scenario is never opening the Syncthing app again, because it's quietly doing it's thing in the background, sometimes on data. Otherwise, my girlfriend, parents, and likely 90% of the people you know all use photo backup. Whether it's iCloud, Google Photos, or a NAS, we all want the option to use mobile data, and likely want it to simply run in the background.
- teddyh 3y ago> Don’t get hung-up on consent folks, it’s not needed if a business has what’s called a ‘legitimate interest’ – which can be a rather stretchy, elastic term when in the hands of less reputable businesses Less reputable businesses will simply do whatever they like, but claiming “legitimate interest” means something specific: <https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/lawful-basis/a-guide-to-lawful-basis/lawful-basis-for-processing/legitimate-interests/ https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-re...>
- horsawlarway 3y agoSure, but those guidelines are still "rather stretchy [and] elastic". That doc starts with the line "Legitimate interests is the most flexible lawful basis for processing" and that's the truth.
- ssss11 3y agoIt seems every website thinks they need your PII for legitimate interests though, i wonder how many have actually been taken to court, and actually lost. I bet close to zero, and zero.
- Nextgrid 3y agoThere is no will to actually enforce the GDPR even across the EU. Much stronger cases than auditing vague “legitimate interest” have been stuck in legal limbo for years. UK since Brexit is outright hostile to GDPR - not that they’ve enforced it in the past, but now they want to (and maybe already did) relax their regulation even further.
- dspillett 3y ago> “legitimate interest” means something specific “We see your preference, but fuck you and your preference we want to anyway.”
- afpx 3y agoWhat do they even do with this information? The ads they feed me haven’t become more relevant.
- bobim 3y agoInsurance companies are very interested by your workout routine and how you drive your car, so they can adjust their offering specially for you… We can’t get laws banning this soon enough.
- judge2020 3y agoThey do this without the help of third parties - by offering a hundred+ dollars off your policy every 6 months (or over 6 months) for having their driving habit tracking app enabled at all, more if you actually drive like they want you to.
- gausswho 3y agoWhich begs the idea: how would one successfully pollute insurance data. I am now a non-smoking vegan ironman.
- psd1 3y agoIt's not obvious to me that working out will reduce your car premiums. I can imagine a gym rat being more likely to crash than a saggy middle-ager.
- voidpepe 3y agoInsurance companies get these information from more direct sources. For example how you drive your car is sourced straight from the car manufacturers. And they pay big time for it. I can confirm this at least for one large automotive company that I cannot mention because of legal reasons, but they were founded by one infamous failed artist.
- nerdponx 3y agoDoesn't mean they should be allowed to. Or that your car should even be sending that data without your explicit consent.
- wsintra2022 3y agoIf you have the means, install a pihole on your home network and you can reduce some of the tracking that goes on inside your own walls.
- ThaDood 3y agoI mean, I know its not practical for everyone or every application - that being said I have made it my highest priority to go out of my way to not use services or products that require apps to be installed. Obviously I make exceptions for stuff I deem "required" but for coffee chains, fast food restaurants, grocery stores and other services if they need an "app" for me to use it. I just won't use it. Or I will go out of my way to use another service that does not require it. Or, if I need to use it, I will just install the app, use it, then remove it. Is it a hassle? Sure. Will the company still be able to access my data? Some of it. But it won't be a persistent install so I'm fine with it. I don't have many other choices. That being said, I am now running into what I call the "Non-App Tax". The most prominent example I can think of in my own experience is my towns local parking payment system. You actually don't need to use the app to find parking or pay. You can scan a QR code and pay via text. Then I looked at the prices on the app vs prices via text and the prices were a decent amount higher ($1-2 more) and less flexible than if I had just used the app. Kinda shitty and I can absolutely see this becoming the norm.
- cmilton 3y ago>That being said, I am now running into what I call the "Non-App Tax". The most prominent example I can think of in my own experience is my towns local parking payment system. You actually don't need to use the app to find parking or pay. You can scan a QR code and pay via text. Then I looked at the prices on the app vs prices via text and the prices were a decent amount higher ($1-2 more) and less flexible than if I had just used the app. Kinda shitty and I can absolutely see this becoming the norm. Or a "discount" for using the app. /s
- senadz 3y agoEventually, when the app reaches a certain amount of downloads, do you believe they will eventually regulate the prices as the one you have to pay for physically?
- hedora 3y agoIt says “this note is legal tender for all debts, public and private” on every dollar bill. I wish that was actually enforced.
- z_ack 3y agoI did an experiment: I deleted all the cookies using privacy settings of my browser then I avoid to click anything about cookies' authorisation, i.e. if a page present that kind of requests I immediately close the page itself. At the and, I verified that cookies are presente on browser's storage despite my absence of authorisation, even third parties cookies. So, yes, I agree: commercial surveillance is creepy and I guess is some organisation do effective control to avoid abuse from those actors.
- BurningFrog 3y agoThis could easily be automated and the results published.
- mixedmath 3y agoWhere would one publish such an experiment?
- hedora 3y agoEven better, there could be a list of garbage cookies that this experiment produces. As an anti-tracking measure, Firefox could put them into a global pool (shared with all other users), then randomly sample from the pool whenever making a request to the offending site. The effect would be severe breakage for any sites that set unauthorized cookies.
- gruez 3y ago>I verified that cookies are presente on browser's storage despite my absence of authorisation That doesn't say much. Even the GDPR allows for some cookies to be stored without consent. >Strictly necessary cookies — These cookies are essential for you to browse the website and use its features, such as accessing secure areas of the site. Cookies that allow web shops to hold your items in your cart while you are shopping online are an example of strictly necessary cookies. These cookies will generally be first-party session cookies. While it is not required to obtain consent for these cookies, what they do and why they are necessary should be explained to the user. https://gdpr.eu/cookies/ https://gdpr.eu/cookies/
- 3y ago
- 23B1 3y agoThey're not just storing and using this data for their own private/commercial purposes. They're also licensing it and selling it to third parties, which in turn will sell it to government(s) or other third-parties; the data ramifies and spreads throughout the digital panopticon. There is very little you can do as an individual to escape this. The privacy settings on your phone, in your apps, on your laptop, your router – they are the illusion of control. Heavy top-down regulation won't work, never has. All you can do is attempt to limit what you share. The work required to do it well is astronomical, high-friction, and essentially can exclude you from much of society and the economy.
- thfuran 3y ago>Heavy top-down regulation won't work, never has. That's utter nonsense. There will never be perfect compliance, but regulations absolutely can curb undesired behavior.
- 23B1 3y agoI wish you were right, but unfortunately 'regulations' always have carve-outs for the government itself, and they're one of the largest consumers of this data.
- thfuran 3y agoI work in medical software and I can tell you from first hand experience that regulations absolutely affect how companies gather and handle data. That regulations don't constrain what they don't regulate is sort of tautological. That's an argument against specific regulations, not against regulation. At any rate, it simply isn't true that all regulations have special carveouts for government.
- csydas 3y agoi think the idea is less that the regulations aren’t followed, but more that the companies are maliciously compliant. GDPR and the cookie banners are the perfect example. GDPR never says you need the gigantic banner, just that you cannot track without consent and it must be as easy to retract consent as it is to give it. somehow, this devolved into the cookie banners/walls, which are not required and in fact likely not compliant as very often there is no way to reject everything. i travel a lot in europe and asia and google is a clear example of a sort of malicious compliance. some countries in eu they show the reject all option easily. for others you have to log in and go through many settings pages. most other big companies are not much better or even worse. that is the issue in my opinion. the goal of the privacy laws is very clear but the companies just do not care usually. i am very happy when a site truly respects my choice on their cookie/tracking consent banner, and even more so if they just don’t collect anything in the first place or ask for telemetry data instead of assuming it’s their right. that is why i personally am not happy with the regulations from the US so far as they’re anaemic; the companies still treat your privacy and personal life’s details as if it’s their right to mine for data. until there is effectual law stopping all this and making such broad data collection something extremely rare and limited, nothing will change. and with how much of this data governments are buying, i’m not holding my breath that it’s going to get better. until then i guess we need to continue to teach people that the technology they buy and use often is actively hostile towards the users in favor of giving the companies more personal data.
- sircastor 3y agoOne of the effects of runaway capitalism of that consoles are pressured (either by stock holders or internally) to keep earning, keep growing, keep getting. And for a lot of businesses, they’ve already reached their market equilibrium. They don’t have room for more growth. So they have to start finding other areas to grow and to earn. Even if they have no business being in these areas in the first place. The promise of data as the next source of easy money is too hard to pass up. And because life is hard enough, a lot of customers are willing to give it up for free to save a few bucks.
- numpad0 3y agoI just assume everyone knows from who I am to how much coffee beans I have left in the jar, and I just try to be a non-factor when I don't need to and other times casually look for ways surveillances could be leveraged to bend things my ways. If you put an intelligent entity in a learning but otherwise nonintelligent feedback loop, the entire loop eventually becomes centered around that entity.
- Xeoncross 3y ago> I just try to be a non-factor That's the problem though. History on every continent is filled with normal people who were suddenly targeted as the slaves/villains/cause-of-the-recent-issue based on their language/skin/background/etc...
- jgeada 3y agoThere is an easy way to fix this: make the companies collecting the data be criminally liable for any misuse or leaks of this data. Something with teeth, such x% of total revenue, not our current “sorry, we leaked your data, tough for you” If this data is so important it should be treated with the same care & auditing that their income stream gets.
- wahnfrieden 3y agoDoes nothing to prevent state abuse when the state sets and executes the punishment for it.
- kibwen 3y agoIndeed, but this post is about commercial surveillance.
- omniglottal 3y agoCommercial surveillance, by definition, includes the context of a surveillance company's primary customer. When dealing with the sale of endangered animal furs, you don't just go after the trappers. It's no good to ignore the market effects of an eager customer.
- chaxor 3y agoDoesn't the state just use commercial sources for their data anyway? Corporations all have far more resources and power, so it's easier to just ask for it.
- amelius 3y agoTwo other potentially effective punishments: 1. Removal of all crowd-sourced data from their systems. Let's see if users will want to come back if there are zero network effects. Maybe sad for the users, but I'd feel safer if data-leak==data-removal. 2. Forced modification of their trademarked logos for some period of time. This will warn people to stay away from the company and their products. (Trademarks are all about trust, so this seems fair).
- osigurdson 3y agoI’m a raging capitalist, but o do think that all forms of surveillance need to be disclosed by regulation. This applies to government surveillance as well as corporate surveillance on customers and employees. Companies should be able to collect data on whatever they want but must disclose it. It must be possible for people to see exactly what is being tracked as well as the aggregations performed on the data.
- daft_pink 3y agoObviously, McDonalds is up to something. Whenever you go through the drive thru know they have a person actually harass you about using their app, and it's blatantly spying on you.
- deleted 3y ago[deleted]
- verisimi 3y agoCookies and advertising are, imo, the provided excuse for surveillance by the governance system. Understandably, people will object to this - after all what have corporations got to do with the governance system? I would say however, that we already live in a fascist governance system. No democracies exist. At best, we only have 'representative democracy' - not the same thing! This is as per Mussolini's definition of fascism: > "Fascism should more appropriately be called Corporatism because it is a merger of state and corporate power." I argue that corporations and states are 2 wings of the same bird.
- gwbas1c 3y agoWhat I worry about are future malicious actors. These are parties that will use today's harvested data to achieve a malicious agenda in the future. For example: The Dutch used to collect a church tax that was used to support your church, or temple. When the Nazis invaded, church tax records were used to track down and exterminate Jewish people.
- bradford 3y agoI've witnessed a general convergence towards monetization of user data over time. I'm bothered that the technical talent of our time is increasingly focused on this. No one seems to like it or want it, but every company engages in it, because it's lucrative. Companies that don't do it are missing out on financial opportunity, and we know what happens to such companies in our market system... I'm of the opinion that only policy/regulation can fix this issue (the playing field needs to be leveled across the board). I'm not sure what that looks like. Does anyone know of proposals/individuals that are being made in this area?