3 ms·
I think the point we disagree on is the idea that accountability by a singular department is an indication that it's sufficient for vendor to avoid regulatory a
by paimapi 2mo ago
I think the point we disagree on is the idea that accountability by a singular department is an indication that it's sufficient for vendor to avoid regulatory action. in terms of privacy protections, the strategy should be defense in depth. I think about the audits that happen in health tech for eg on the software side, both at the request of regulatory agencies and their clients
any platform that enables people to be stalked, harassed, tracked, and so on should face the same level of scrutiny in the form of auditing and open access to internal policies around data sharing
- akerl_ 2mo agoYou're correct that we disagree on that point. Flock is providing a tool; if we think the tool can be used in problematic ways, we ought to regulate users of the tool (in this case, government entities). This has the added benefit that the burdens on the government around their treatment of citizens have a higher bar for transparency and conduct than we place on private entities.
- paimapi 2mo ago"it's not the gun, it's the person that holds it" is not a philosophy that's tracked with me given the probabilistic, population-wide outcomes. the same applies here - tools should build in strict data and privacy protections as part of their UX. you lower the probability of abuse wherever you can because you know a bad actor will find a way, regardless, but the point is to add enough friction that even the worst of the bad actors has a difficult time getting what they want