8 ms·
Indeed. During the pandemic, restaurants in Germany were required to track customer's information including addresses, so people could be informed in case of a
by Cu3PO42 2y ago
Indeed. During the pandemic, restaurants in Germany were required to track customer's information including addresses, so people could be informed in case of a confirmed CoViD infection of another customer who was there at the same time. Of course, this information was never to be used for any other purpose whatsoever.
In one case, however, there was a capital crime near a restaurant (or similar venue) and police and prosecutor used this information illegally to track down witnesses. They were sued after the fact and lost, but got nothing more than a slap on the wrist.
Once information is available, it will be used for purposes other than the intended one, even by the "good guys".
- HPsquared 2y agoBetter to simply not collect the data in the first place. It's like the hierarchy of controls used in risk management, from most to least effective: - Elimination – physically remove the hazard - Substitution – replace the hazard - Engineering controls – isolate people from the hazard - Administrative controls – change the way people work - PPE – protect the worker with equipment Only with hazardous data, or things like moral hazards rather than physical hazards.
- moring 2y agoOfftopic, but do you know some good sources to read on that matter?
- 3D30497420 2y agoHere's a nice OSHA doc on this: https://www.osha.gov/sites/default/files/Hierarchy_of_Controls_02.01.23_form_508_2.pdf https://www.osha.gov/sites/default/files/Hierarchy_of_Contro... Might want to save it locally though.
- Y_Y 2y ago> Might want to save it locally though. The real hazard is the infohazard of knowing how to deal with hazards. Hopefully some genius will eliminate it and increase efficiency.
- DrillShopper 2y agoOh is it being done by the same genius that built electric cars with no way to get out of the back when the power is out so if there's a fire and you're in the back you'll burn to death?
- sitkack 2y agoI used the following query in your favorite ai powered search engine, "what knowledge would I need to able to make an intelligent post similar to <insert above comment>, please give me some high quality reading sources" https://en.wikipedia.org/wiki/Hierarchy_of_hazard_controls https://en.wikipedia.org/wiki/Hierarchy_of_hazard_controls https://en.wikipedia.org/wiki/Data_minimization https://en.wikipedia.org/wiki/Data_minimization https://www.ccohs.ca/oshanswers/hsprograms/hazard/hierarchy_controls.html https://www.ccohs.ca/oshanswers/hsprograms/hazard/hierarchy_... https://epic.org/data-minimization-is-the-key-to-a-meaningful-privacy-law/ https://epic.org/data-minimization-is-the-key-to-a-meaningfu... I won't shovel the rest in here, but this is a good start.
- andrepd 2y agoDamn, you used an LLM to tell you that to learn more about "hierarchy of hazard controls" you should google "hierarchy if hazard controls" :) Truly a revolutionary technology!
- sitkack 2y agoYou don't know what you don't know! Did I open myself to a sweet hindsight bias attack, luckily my saving throw worked. I used a search engine in a high dimensional space, not a fax machine.
- deleted 2y ago[deleted]
- nxobject 2y agoThat’s a good way of thinking about it - it’s fun to think through how everything digital security-related from privilege separation (engineering controls) to mitigations (PPE) fits in that framework.
- FirmwareBurner 2y ago>restaurants in Germany were required to track customer's information including addresses Ironic they went along with this considering how chest-pumping Germans are about their government being all about protecting their citizens' "privacy". >They were sued after the fact and lost, but got nothing more than a slap on the wrist. Government workers don't care about doing a good job since if they break the rules they won't get fired and the fines are not paid from their pockets but from the taxpayers pockets anyway so there's no incentive to be competent at your job.
- brookst 2y agoIt’s always a mistake to generalize about a population as large as “employees of the German government”. Some people are meticulous about their jobs. Some are not. Both types are present in any large organization.
- Cu3PO42 2y agoI'm not really all that surprised. Public opinion is easily swayed with good marketing. The government mandated contact tracing, but not how it was to be implemented. There was a publicly developed open-source app for contact tracing that was perfectly privacy preserving. Unfortunately, many restaurants instead used a commercial solution that was none of these things. What it did have was support from a mildly famous German musician and great lobbying. Most people didn't care, they just wanted to go to the restaurant.
- bitwize 2y agoThe German government, and maybe to a lesser extent the EU more generally, feels that the privacy of citizens from corporations (especially foreign ones, especially American tech ones) is important to preserve and protect. Privacy from the government is a different matter. The government, due to its being duly elected by the people, has an implicit right to pry into people's affairs if such prying can be justified as serving the public interest. It's quite a different attitude than the USA. The USA is almost unique in being individualist to what some might consider an extremist degree, to the point where if the government intends to violate someone's fundamental rights, they may do so only under very limited circumstances and must document everything and prove that those circumstances had been met. In most of the democratic world, individual rights are just one factor that needs to be balanced against public safety, public order, etc. and the government has much wider latitude to violate even constitutionally protected rights on its own say-so. This is how you get German prosecutors on 60 Minutes, grinning and laughing as they describe the shock people undergo as they are arrested and their computers confiscated and searched over literal mean tweets. For the Germans, it's normal -- necesssary, even, to have a functional society. To Americans it's abhorrent.
- calmoo 2y agoI remember reading a similar story in Ireland on Reddit, where a guy started receiving newsletters and advertising texts that he only ate at once during the pandemic. Turns out the restaurant were using the contact details for Covid tracking for advertising purposes… diabolical stuff.
- bayindirh 2y agoI visited US once, for a week. I went through an E-ZPass controlled interstate once as a passenger, and gave no e-mails to anyone. Yet, I received "Pending E-ZPass payment" scam for a year. I have no further comments.
- c0wb0yc0d3r 2y agoSo how do you think the connection was made? The best I can think was your location data was sold by a company behind one of the apps on your phone.
- bayindirh 2y agoThey might have correlated my shopping data plus with my location (the state/shop I'm in), and possibly went from there. Some of my phone apps might have betrayed to me, too, but I have no idea what I had installed at that time.
- ctrlp 2y agoPossibly sold by an insider through unofficial channels?
- gruez 2y ago>I went through an E-ZPass controlled interstate once as a passenger >Yet, I received "Pending E-ZPass payment" scam for a year. I think you're overestimating how precise scammers' targeting are. They're playing a numbers game, so they're going to spam every who might have used ezpass, not carefully curate their spam list by buying real time location data from data brokers. I received phishing texts for banks that I don't have accounts for, so next time I get a phishing text for a bank that I do use, I'm not going to think my bank got breached.
- manojlds 2y ago> was a capital crime > track down witnesses Am I too naive that I think that's a worthy use of that information?
- quest88 2y agoI'd agree that is a good case. But I'd still object to this tracking. It's a slippery slope. Who determines what is worthy? We might like one government administration and highly expect them to respect the privacy. But what about the next administration? We've just seen Trump say he will withhold funding for universities with "illegal protests". I'd fully expect his administration to abuse this tracking, in the name of law and order.
- andrepd 2y ago> It's a slippery slope. Who determines what is worthy? Who determines if a wiretap is worthy? Or a search and seizure? Or a simple arrest? We have an answer for this, it's called Law and an independent judiciary.
- quest88 2y agoYou're right in theory but history shows us it's not black and white and rarely has an effect after the fact.
- Cu3PO42 2y agoIt probably was. It was also illegal. As much as you, I, or even public opinion may agree that something is right, we can't have public servants knowingly violate the law when it is convenient. To accept that would be to forfeit many of your liberties.
- andrewinardeer 2y agoIn my state the law said that this checking information could only be used for contact tracing. So when the law says this and the cops drive over it in in a bulldozer, it's a bit shit. That said, in my state the cops recruited and flipped a criminal lawyer who then back doored her high profile clients and gave confidential and privileged information to them them in order to build cases.
- andrepd 2y agoWell. That's actually a good example. Because contact tracing can (and was) implemented in a completely anonymous way, at a technical level, storing no personally identifiable information. You can do this, just like you can do e.g. video surveillance, in a secure and privacy-respecting way. There is just no political will.
- sieabahlpark 2y ago[dead]
- josephb 2y agoSimilar happened in Australia, collect the data to keep everyone safe, it's private, but next minute... https://www.abc.net.au/news/2021-06-15/safewa-app-sparks-urgent-law-change-after-police-access-data/100201340 https://www.abc.net.au/news/2021-06-15/safewa-app-sparks-urg... https://www.smh.com.au/politics/federal/breach-of-trust-police-using-qr-check-in-data-to-solve-crimes-20210903-p58om8.html https://www.smh.com.au/politics/federal/breach-of-trust-poli...
- defrost 2y agoNot quite the same: Queensland Police gained access to the Check In Qld app in June through a search warrant after the theft of a police-issued firearm, which led to an officer being stood down. Western Australian Police has used its data twice without a warrant, which led to the state then banning police from accessing the data, while Victoria Police has tried but been rebuffed on at least three occasions. The police gained no advantage, no prosecutions were carried through, and in WA Quigley (then WA Attorney-General ) rebuffed the police and strengthened the fines for breaching. He is not (now) a fan of the police, despite having once been the police unions bulldog lawyer of choice .. he's seen too many breaches too close to ignore. In 2007, his life membership of the Western Australian Police Union was withdrawn after his parliamentary attack on police involved with the Andrew Mallard case, where he named a former undercover policeman who had a role in Mallard's unjust conviction. He planned to melt down his life membership badge, have it made into a tiepin with the words Veritas Vincit— "Truth Conquers", the motto of the school he attended—and present it to Mallard. ~ https://en.wikipedia.org/wiki/John_Quigley_(politician) https://en.wikipedia.org/wiki/John_Quigley_(politician)
- HexPhantom 2y agoExactly. No matter how well-intentioned a system is at the start, once the data exists, it will be accessed for purposes beyond what was originally promised