9 ms·
It is not stealing anything because you get a dialog asking you for permission to do it. If you give someone permission to take something, they are not stealing
by vasdae 3y ago
It is not stealing anything because you get a dialog asking you for permission to do it. If you give someone permission to take something, they are not stealing it.
https://heise.cloudimg.io/v7/_www-heise-de_/imgs/18/4/3/3/1/0/1/1/outlook-warnung-e147ccf7fd4368f4.png https://heise.cloudimg.io/v7/_www-heise-de_/imgs/18/4/3/3/1/...
- logifail 3y ago> It is not stealing anything because you get a dialog asking you for permission to do it That dialog talks about sync but notably does not mention credentials at all. Surely this is instance where informed consent is needed, with full disclosure of what's going to happen. Something along the lines of: "this means your IMAP username and password will be passed to Microsoft where we will store it indefinitely so we can regularly log into your IMAP server to sync your messages". Of course, users are less likely to consent if you explain exactly what's going to happen...
- oaiey 3y ago[flagged]
- zelphirkalt 3y agoI am not so sure about that. Are they allowed to simply assume "expert" knowledge?
- c4mpute 3y agoNo, they are not. GDPR notices (which this is) must be understandable to the layman. Including all consequences like "this will also allow access to other services secured with the same university/company-wide password". This could also be a punishable crime in Germany: https://www.gesetze-im-internet.de/stgb/__202c.html https://www.gesetze-im-internet.de/stgb/__202c.html and other articles around that one.
- oaiey 3y agoThe German law you cite about getting a password is applicable if you plan to or actually access data they are not authorized to. Which is not the case (assuming they do not). GDPR deals with privacy. The user name is personal identifiable data. The password is only personal data. The emails themselves can be PII or just personal data. GDPR legally wise, the password is the least risky set of data here (as absurd as it is). Also it is a property of the process. Take a GDPR sheet of a club about giving photographies of your kids to the newspaper. You consent to the publishing of images and give the club data for it (first name, last name, restriction, name of parent, etc). And these properties are not mentioned in the consent but just are part of the process. This is nothing else, just that we are very worried about that the property is a password. I agree that they should ethically mention that they transfer your password. I also agree that there is no way a layman can understand any consent they grant on the Internet. There is a reason why informed consent in clinical trials (where this can be life and dead) is not just a checkbox but a conversation, quiz, explanations, etc.
- c4mpute 3y ago> The German law you cite about getting a password is applicable if you plan to or actually access data they are not authorized to. Which is not the case (assuming they do not). Usually this is the case. The user and Microsoft are not the only parties involved here. The Email provider is also involved in that they provide an email account, often e.g. for work or educational purposes. In those cases, handing over account credentials is forbidden by the workplace or educational institution, providing other people such as Microsoft with access is usually forbidden as well. Other commercial email providers often have similar rules. Therefore either Microsoft is doing unauthorized accesses en masse (since they do know that the aforementioned clauses are widespread common practice) or the users are illegally providing access to Microsoft. > GDPR deals with privacy. The user name is personal identifiable data. The password is only personal data. The emails themselves can be PII or just personal data. There is no such distinction in GDPR. There is only personal data according to GDPR article 4. A password is personal data because it is "personal" in that it can be (and is almost always) tied to a person. "PII" is something that only occurs in US law. The definitions are different, "personal data" in GDPR is far broader. > GDPR legally wise, the password is the least risky set of data here (as absurd as it is) Depends on what else is in that Inbox and what else this password can access. > And these properties are not mentioned in the consent but just are part of the process. This is nothing else, just that we are very worried about that the property is a password. Interesting idea, and yes, GDPR allows for not informing the user about what the user already knows, i.e. a kind of implicit consent. However, the surprise that even experts on HN show about this news demonstrates that the average user doesn't know. So this doesn't apply, Microsoft should have explicitly informed and asked about permission to use username and password.
- veqz 3y agoIt is not informed consent if people don't understand what is happening, though.
- oaiey 3y agoWell, they consent to the fact that data is "synced" to Microsoft. That is the use case and the consent-able item. The password is just a random property of that item. And that is literally on the screen. That is broad but that is how privacy topics are generally handled. I also do not like it.
- nolok 3y agoI genuinely don't understand how you can come to this conclusion. If I open the door to someone and allow them to take picture inside my house, there is no legal understanding that they are now allowed to make and keep a copy of my keys. The understanding is that I allowed to take the picture (make the sync), through the access that I gave (door opened / imap connection made). And the underlying understanding is actually that I remain in control of access later on, meaning they can't do it again without me opening the door / connecting again. Microsoft knows that, because they buried that information inside the webpage that the consent dialog links to, except the dialog doesn't say "important detail there" but "for more information see there" aka pretend the dialog's summary is correct. If anything, coupled with the awkward Outlook (but not Outlook) naming this is one more of their modern move that will piss off entreprise IT admins. Your employee opens the "wrong" outlook, type his office credentials and then Microsoft now has outside of your corp account a copy of all data of that employee AND its credentials. If there was any actual real competitor in their field they would never be able to pull such crap.
- oaiey 3y agoWell, the consent item is "sync" and that translates in your sample more to "you consent to let them take pictures of your house whenever they want". And for that, a key property is the username (or your house key). Otherwise, "sync"/"taking photos any time" would not work. You could argue that "sync" could be considered 1-time sync or permanent sync ... but honestly we talk about IMAP and a permanent connection to fetch Emails. Let us not assume we talk about a one time "sync". And yes, I agree that Microsoft buried the nasty password detail with the purpose of not disengaging the users. I also think that anything data privacy related, normal users are completely overwhelmed with no chance to ever understand the situation. I share your thought about replicating passwords. Not to the concrete worry you express but that it is a really bad practice compared to industry practice (see OAuth2 refresh token).
- pacifika 3y agoIs it asking for informed consent for a change when the ui encourages and defaults to not keeping the system quo
- jsiepkes 3y agoThe dialog talks about needing to synchronize your email account. It then goes on to tell that contacts and events are not synchronized. No one will reasonably suspect your authentication credentials are send to Microsoft. Such reasoning of this dialog will never fly in a German court.
- falqun 3y agohttps://www.law.cornell.edu/wex/informed_consent https://www.law.cornell.edu/wex/informed_consent
- bald42 3y agoWhen I saw that I immediately cancled my the "new outlook" tryout and wrote in the feedback form I don't want my mails in the microsoft cloud.
- estiaan 3y agoI disagree. I think that you can’t consent to something you don’t know about and certainly not something you don’t understand. This includes every single eula that everyone agrees to without reading. In my opinion that is not an agreement, as an agreement requires informed consent. Unfortunately our legal system strongly disagrees with me but that’s my two cents
- Fischgericht 3y agoAt least in the EU it is. Explained in detail, here. https://gdpr.eu/gdpr-consent-requirements/ https://gdpr.eu/gdpr-consent-requirements/ Consent must be specific, informed, freely given and unambiguous. The user must be able to revoke consent at any time, as easy as it was providing the consent before. Very clearly the Microsoft "consent" info does not tick any single one of those items. Illegal.
- Fischgericht 3y agoOr, in other words: There is much to criticize about the EU. But where the US has brought the world "By farting during installation of this software you consent to us stopping by and taking your first born child" kind of EULAs / "choices", EU's GDPR is forcing big tech to treat humans as humans again (instead of just data).
- deaddodo 3y agoI don't know why political entities are brought into these conversations other than for some sense of high-horsedness or a figurative pissing contest. GPDR is good. So is CCPA, COPRA, etc. Meanwhile, both the EU and the US have plenty of predatory legislation that allows companies to do all kinds of fucked up things.
- paledot 3y agoBecause nuance is valuable? "GDPR is good" doesn't remotely address its strengths and failings, nor the conflicting incentives and motivations that produced it. I agree that there's no room for home-team mentality here, but we should absolutely assign credit and blame where it's due, especially when those of us who don't live in a jurisdiction with such a law gain some halo-effect benefit.
- Fischgericht 3y agoMy comment wasn't meant as a pissing contest. It's not me who has created GDPR, I did not have a choice of getting born in the EU, it just happened :) But I am pretty impressed that in these days where most regulations for pretty much everything are defined by lobbyists, GDPR actually did happen, ended up to be a very reasonable set of rules, and actually gets enforced. It was written well, and unlike with other regulations it's not full of loop holes. Laws and regulations created to the sole benefit of your general population is just something you can't take for granted these days anymore. Therefore, for me GDPR is kind of magic.
- tzs 3y ago> It is not stealing anything because you get a dialog asking you for permission to do it Also, at least according to several comments on nearly any story about movie piracy, it is not stealing because all they have done is made a copy.