Thread · 6 tweets · 24 Mar 2020

Replying to @jyasskin

No, I did not ask for a policy that prevents data brokerage — I asked for a threat model that does. The risk of direct data harm to users from Google *today* is in part limited by Google’s need for goodwill — if only to retain employees.
But the threat is: how many bad quarters in a row before that stops mattering? What happens if your kids can’t get into college N years from now because Google is selling access to a model that shows they underperformed in Google Classroom? Or because you don’t buy enough books?
You can repeat with health, credit, etc. It’s a very long list of threats. The way to contain that is: limit collection, decrease retention, silo data processing, minimise, minimise, minimise. It’s very obvious, at every turn, that that’s not happening at all. Am I wrong?
Think of it as a maintenance problem: you’re not doing it for you and your nice coworkers now — you’re doing it for the vulture capital that’ll sell you for parts when a better search engine comes or search ads no longer make money.
And if you really want to go into equivalences that don’t work so well because scale and scope are just not commensurable: yes, that’s part of my threat model for The Times. We’re not at all perfect with it, but we’ve decreased collection a lot and sharing to controllers 90+%.