April 2019
187 tweets
Differently targeted ads can still go into the archive!
♥ 1
Oh yeah, a wee bit more complicated than that indeed.
♥ 1
I didn’t know they could achieve that level of video production quality in the 1950s, it’s really impressive! Well done @Discovery!
♥ 1
I'm not willing to leave it to them.
♥ 9
Happy to meet up if there's a chance, and feel free to drop by The Times if you want!
This thread has every reason why I liked "Captain Marvel". And the word "wankpuffin", which I also like a lot.
Quoting a tweet by @GeneticJen ↗
♥ 2↺ 1
The darker view is that this is driven by surveillance capitalism that can extract more behaviour from experiences than from (non-tech) objects.
♥ 1
YES!
♥ 1
Have you tried just feeding ads into a Markov chain generator, generating a bunch, and keeping all those that don’t fail syntax check? I reckon you wouldn’t fall far.
♥ 2
The Privacy Project: Our friends in @nytopinion are launching a limited-run newsletter about privacy.
I'd read it.
nytimes.com/newsletters/pr…
♥ 4↺ 2
I completely agree with @cwarzel: privacy isn’t about secrets, it’s about self-determination and the preservation of democratic exploration. As @WilliamsJames_ put it, "freedoms of the future are freedoms of the mind."
Quoting a tweet by @cwarzel ↗
♥ 21↺ 10
You should care about privacy not because you have something to hide, but because if I know more about you than you can remember — invisibly — then I can use that knowledge to influence, and later control, your behaviour.
♥ 9↺ 11
Publishers (and all first-party services) should care about privacy not only for ethics but to sustain their independence. Those who fail to grasp the massive reconfiguration of business through the data market over the past two decades will end up sharecropping for adtech.
♥ 3
The stakes of the privacy debate are not about finger-wagging at some big companies: they're about human autonomy, freedom of the press, and defending democracy. Hey, no pressure.
♥ 3
You know me, I could write about this until Twitter runs out of thread; but I'll let you all have your Friday back.
In case you couldn't tell, I'm really excited about this newsletter. Go sign up: nytimes.com/newsletters/pr…
♥ 3
Has anyone counted the number of ways in which our Universe might *not* conform to string theory? We might just end up with a smaller number.
Quoting a tweet by @LogicalAnalysis ↗
"The Privacy Paradox" — Seriously @axios, are you writing to us from the Nineties?
axios.com/consumer-data-…
♥ 5
Adtech has poured massive resources into making sure that privacy remains hard to understand, overwhelmed by deceptive design, uncertain, and off by default such that individuals are faced with an endless stream of choices in which the right choice is the hardest to make.
♥ 20↺ 8
Somehow, under those circumstances, people don't seem to be "voting with their fingers." Are we really wondering why that's happening?
Axios: "It's, like, a whole paradox! We might never figure it out!"
♥ 2
It's not obvious that fire is enough. Adtech often puts me in mind of the treatment given Robert-François Damiens in the opening of Foucault's Discipline and Punish. Why did that go out of style again?
♥ 2
WTF.
Here, @shoshanazuboff makes a good case that the 16th century Spanish conquistadors had in fact invented the @IABEurope's Consent Framework.
♥ 14↺ 5
Battle of the Fluffs Reaches Stalemate.
♥ 1
Yes, yes I am.
♥ 1
Next time I'll do the community a service and tag Johnny right away 😁
♥ 1
It's an editorial project, I'm on the business side 😊
Thanks 🤗 It certainly keeps me busy. How's things over there?
Yeah, that’s certainly a lot more like what we do!
Yeah. Someone wrote that on a slide. At a conference. That they organise.
♥ 7
"As with a politician railing against high drug prices while accepting campaign donations from big pharma, a news organization cannot talk about privacy on the internet without skeptical readers immediately, and rightly, examining its own practices for signs of hypocrisy." 👇
♥ 2↺ 1
News organisations have long been silent about their own privacy practices while reporting on those of others. Today, Times’ publisher A.G. Sulzberger explains:
nytimes.com/2019/04/10/opi…
↺ 1
Indeed. The way we explain it internally is that governance is ethics at scale.
♥ 19↺ 1
I can write about it at greater length, happy to share that when I’ve done it if you’re interested.
♥ 7
A great combo!
♥ 2
Maids are typically understood to be women (also supported by a dictionary lookup) — and in the context of this statement it’s hard to see them thinking of it any other way.
♥ 1
Yeah, pretty much.
♥ 1
I doubt it.
I think the point being made is that if you’re a privileged sexist slob then IBM and Google have got your back.
♥ 6↺ 1
I don’t know, I have a five year old and she doesn’t say “police cop”.
It would still be wrong, though.
Ha! Perfect.
♥ 1
Prison.
♥ 1
“Spon Cron” is a brilliant bit of interneting from @femalegazebot today. sponcron.glitch.me
♥ 2
I'm a fan of @superwuster's work, I've read two of his books with a third teed up, and I don't dislike the sentiment in this piece, but the argument feel (uncharacteristically) poorly grounded.
nytimes.com/2019/04/10/opi…
♥ 3↺ 1
First, the idea that privacy is the "right to be left alone" feels at best dated. Even Warren & Brandeis, who discuss a "right to be let alone" (attributed to Judge Cooley) in their 1890 classic only see it as perhaps a component of privacy.
It is more common for practitioners today to rely on @HNissenbaum's contextual integrity framework. ("Privacy in Context" is a great read, for a quick summary see @msalganik's section in the excellent "Bit by Bit": bitbybitbook.com/en/1st-ed/ethi…)
I think you're working from a limited definition of "ethics". Phronēsis is literally about decision-making, deontology is about rules, etc.
Tristan’s kinda joking, but… he’s not wrong. A voice assistant that’s just local (perhaps with the occasional specific query to the outside world). IoT stuff you can trust. A phone OS that works for you.
That’s become fucking fantasy. We need to take our dream back.
♥ 3
It’s on my (long) list of things to play with!
♥ 2
Mine doesn't get Britney Spears.
♥ 1
"Often, Google employees said, the company responds to a single warrant with location information on dozens or hundreds of devices." @jenvalentino on how Google's massive Sensorvault is used by law enforcement.
nytimes.com/interactive/20…
♥ 1↺ 1
This. You can be precise in an asinine measurement system, I'm sure pre-Revolution French pastry was fine. But Americans think pastry is about sugar when in fact it's about fat. It's like thinking that pasta is about tricycles.
♥ 3
I wonder if there's room for a collective working on adtech accountability.
♥ 2
The @nytimes's Sunday Review has been taken over by @PrivacyProject!
Privacy friends, this is just the beginning: send feedback, send ideas for what comes next!
♥ 25↺ 6
Lol, it's like you replied without reading or something.
The problem here is the word "necessary". If this limits the data selling to what is actually necessary, it's not bad. There's nothing wrong with eg. measuring impressions. Problems will come from defining behavioural, open programmatic as necessary.
But this could be tightened up into something that actually makes sense. It's not over yet.
It's on the other side of the Church/State divide. Like you I know how tech could be, so I'd be a fair bit tougher if it were down to me 😉
♥ 1
As do I, and that's fortuitous because it's also not what he wrote.
I won't comment for The Times, but you seem to be operating from a bunch of assumptions I'm not sure hold. Is local that much better than a service provider, if so why? Do you think publishers place most of the tracking?
If the solution were as simple as "look for a local analytics package" I'm pretty sure someone would have figured it out by now? In my view, leading by example isn't applying the solution that any beginner Web hacker could find and going out of business...
It's an unsolved problem for a reason. Which isn't a reason to give up - quite the contrary - but it's safe to assume one can't "just" fix it by wanting to.
By all means, if you have a solution I'm all ears.
♥ 1
I really liked this interactive article from @stuartathompson, “Where Would You Draw the Line?” It makes it very clear where preferences and expectations are, versus what is already happening or in progress. It also links to @ssnstudy’s Science review :)
nytimes.com/interactive/20…
♥ 5↺ 4
“What Women Know About the Internet” by @emilychangtv is an excellent view of privacy as a feminist issue. Her reasoning extends to other groups that are regularly targets for online harassment, too.
nytimes.com/2019/04/10/opi…
♥ 1
And as I said there, it’s unclear to me what problem you think that solves? Do you really think all of that is happening because news orgs can’t build a simple analytics package?
See
I won't comment for The Times, but you seem to be operating from a bunch of assumptions I'm not sure hold. Is local that much better than a service provider, if so why? Do you think publishers place most of the tracking?
If you’re talking about doing that only for the Project, sure, it could be done — but (again, personally) I would find that at best a gimmick and at worst disingenuous.
It would be like a news outlet doing a project about sexism with lots of women writers, but the rest of the site would still be just men. What would be the point? Would that not give a false sense that there’s an easy solution?
The heart of the matter to me is whether it’s even possible to operate a successful, affordable, expensive site un the way that the internet economy functions today without tracking. That’s where I’d like to get to.
Getting there requires starting from the ugly reality we’re dealing with. I evidently have no control over what the Project does but if someone had suggested running that subsite using a different configuration I’d have advised against it. It would be a bit of a lie, no?
Well, I’m sorry you feel that way but I don’t see how faking a solution that can’t scale to reality helps anyone.
Is there any reason why at-risk users wouldn’t use our Tor service? open.nytimes.com/https-open-nyt…
Sure — except that’s not what I said. I did not say that it had to be maximal to work, only that it had to not be a lie. I’m working to change things, not to make PR gimmicks that things have changed.
Indeed — and in my work I’ve made things more free today than yesterday, and I hope better tomorrow than today.
♥ 1
I suspect that @YalePrivacyLab is somehow not financed as a consumer-facing business, though, no? We can’t all run on sponsorships from [checks notes] Google and Microsoft.
Also, I see that you have New Relic in there! That’s (relatively) fine in my book since as a tracker they act as a processor and not a controller. Maybe that’s a distinction worth extending to others?
You seem to think that would make a huge difference, to me it seems hypocritical. We might just have to disagree on that.
Which isn’t at all to give up on incremental change, my job might just exist for a reason…
In fairness though, I have limited qualms about processors. It's imperfect but it's nowhere near the top of my list. Controllers are where the heart of the issue is at.
And when you asked if you could see her right away did she appropriately answer… “Not today, Satan!”
♥ 3
Unless I'm missing something, the page that @katienotopoulos talks about here has nowhere near all the data targeting you on Facebook. It only has audiences built from hashed identifiers. That's a *tiny* fraction of the targeting you're a subject of.
Quoting a tweet by @PrivacyProject ↗
♥ 1
Hashed identifiers are essentially a way for an advertiser to target people on Facebook if Facebook already knows the identifier (eg. an email address) but without revealing it if not known by both parties.
Facebook has A LOT more data that they get from pervasive tracking. Far more ad targeting is driven from that, which is a way more invasive and dangerous practice than hashed matches.
The fact that Facebook reveals advertisers who use the comparatively safer method but keeps those who work through tracking (which gives Facebook much more data, which they can reuse for other purposes) secret always struck me as highly disingenuous.
♥ 1
Agreed, this can't be done briefly, there's just so much!
I don't believe this is agency-related, it's when a brand (directly or not) uploads an audience directly. A typical way of doing that is through hashed emails, but it's not the only one.
It's possible that it also has segments generated in other ways, but normally not those that come from Facebook’s online tracking.
It's also possible that someone bought a spam database and is using that to sell advertising against... It's not like it would shock anyone in this space.
Right, and she would never know that she is promoting herself through a third party that's using a spam database...
♥ 1
Indeed! Well, that's where we need laws, and good ones too. I worry that people don't understand privacy enough and will take proposals from eg. privacyforamerica.com seriously.
Has anyone considered making the same appeal to Google for Android? 😅😂🤣
foundation.mozilla.org/en/campaigns/p…
♥ 5
Is there an explainer with the rationale behind some of these changes? What's the value of throwing in sharing when opting out of sales already nuked third-party controllers out of the picture? And reintroducing consent seems to just set us up for some TCF horrors again?
For all its many warts the CCPA has some basic architecture to align the interests of users and first parties in quite powerful ways.
♥ 1
No, no, don't let it go, this is both true and constructive, and the Privacy Project will run for a while. Please send feedback (to me if you want, I'll pass it on).
♥ 2
Much agreed! I think the series is promising but it needs to become tighter and harder-hitting. Privacy has become so complex that almost only academia has the time to investigate it properly and this needs to be surfaced.
I'm not sure that I would blame that community too much, though. A lot of the work is clear and accessible. People in business don't find their way to it because they don't see the problems.
♥ 1
"The Age of Surveillance Capitalism", by @shoshanazuboff. There are several reasons to read this book. It is very well documented and can serve as a reference for the slippery slope of the past two decades; she provides parts for a framework with which to understand...
♥ 10↺ 2
...the battlelines in today's data economy (in which privacy is but one flashpoint); and she threads a clear intellectual tradition on the side of the surveillance industry from totalitarianism to Pentland and through Skinner that is illuminating. This provides too rare...
...history and context. On the downside, the book is too long. I say that of most books, but particularly so here. The arguments are not better for being revisited. It's still worth reading, but be prepared to skim some parts.
♥ 1
Absolutely. Part of the problem is where to even start because the issues take a while to sink in. (We train people and it takes a good couple hours just to get awareness to a good place.) Tech or marketing conferences would be great venues though.
♥ 1
I don't know, I don't think I have ever listened to a podcast in full. Who has the patience to listen to some people who aren't there talking for an hour? 😊
♥ 1
It doesn't work for me, I just drift into my thoughts. It would work if they were there.
That would be a lot of tweets, and people would reproach me berating your employer again 🤗
Sounds cool, I signed up!
It is true that @HenrySternCA’s proposal is worrying and we can land on much better, but two wrongs don’t make a right.
The do not sell provision has very strong potential, why dilute it with nonsensical fuzzy language like “sharing” and a consent regime?
What is even “sharing”? If I host my site on someone else’s hardware does it count? A managed DB? A CDN?
And opt in regimes incentivise businesses against privacy. They only work with stringent enforcement. The second a publisher has to fire folks in their newsroom after being sued for insufficient consent everyone will blame privacy, and then we’re fucked for federal.
It’s on the @futureofprivacy site!
♥ 1
Given how hard I find it to focus on the tedium of driving, and how fast I drift when listening to a podcast, if I did both at once I would surely die.
♥ 1
Do they make a cape for that?
♥ 2
I think he might contend that that isn’t enough of an ontology to warrant the name.
“Philosophy of Physics: Quantum Theory” (the second volume).
♥ 1
I agree with points 1 & 2 in your reasoning. I would add a “tax residency” loophole: if you can’t reasonably establish tax residency (and how could you, accountants struggle with it) then you could argue the CCPA does not apply.
♥ 1
Point 3 does require more thought, it would be good to delineate better what’s acceptable to make user-first advertising work. Secondary reuse beyond the serving of a given ad could be ruled out without preventing various measurement requirements.
Point 4: I see what your concern is but that should be addressed by clarifying the extensive scope of sale and not by throwing in a poorly-defined extra term that’s been a staple euphemism of the tracking industry forever.
I don’t see how providing data to RTB could be considered anything other than a sale. The definition could be strengthened eg. by using the kind of language that would apply to considerations of bribery.
Well, unless I missed it the bill doesn’t even define “sharing”, that’s beyond too broad.
I think the switch from “sharing” to “selling” is actually a big win. It calls a spade a spade. It gets to the heart of the industry’s mechanism.
Ok that beats a cape.
♥ 1
I agree that it seems counterproductive — though it hasn’t stopped some folks from ascribing to that view!
That definition seems to grab, amongst many other things, using a CDN? What am I missing?
I also really fail to see how sending data for the express purpose of having people bid on it to give you money would not be a sale. It covers transferring data to a controller “just” to get lower CPOs. It’s pretty broad!
So you’re trying to catch provision of data to third party controllers (I stick to GDPR terminology for sanity’s sake) in cases that do not involve valuable considerations?
I guess I’m struggling to come up with a situation in which that happens.
“Why are you giving that data away?”
“Who, me? No reason!”
This might be better served by a notion of purpose proportionality? Don’t process personal data without a good reason to start with?
Oh that guy.
♥ 2
You know how the French are with using foreign words! It's clearly a neologism.
♥ 2
You shouldn’t need to reach for Perl, you can use the parity directly in the regular expression, no? Getting escaping right will depend on the context in which the regex is used (might need to double-\) but a global replace of \$\$?(.*?)\$\$? with \($1\) might be a start?
It's not that bad, if the mentioned typos are the full set I can make it for you.
Granted I'm a former Perl guy so I might be proving your point 😊
♥ 1
The Dø (live), Metric
♥ 1
So the @MTA is not using facial recognition, it’s only habituating people to it.
That must be okay, right? 🤔
Quoting a tweet by @natashanyt ↗
♥ 2↺ 1
Every alternative to HTML will increase in complexity until it matches HTML, only uglier.
♥ 1
The alternative to markup aspect is kind of in the name 😁
♥ 1
Yes, I've long suspected that the reason we know so much about Facebook misdeeds and not those of Google or Apple is employee satisfaction and internal politics, nothing else. FB stories often feature "as confirmed by 287 employees familiar with the project."
♥ 13↺ 1
You don't get that in a happy and cohesive company.
♥ 5
Yes, sold on mission and leaving, especially to an actual mission-driven place, means half the salary and a quarter of the benefits. Leaking must feel redeeming.
♥ 3↺ 1
It's OK man, we're all kind of there.
♥ 2
You are wisdom personified.
♥ 1
Well, the implementation comes to mind. How is it set up? Does the local machine have DHS facial fingerprints? Or is it sent over a secure network? Your face is harder to change than an ID.
♥ 1
This 100% matches my experience. Sleep-deprived, overworked teams consistently fail to deliver quality work.
Quoting a tweet by @hillelogram ↗
♥ 10↺ 1
Totally worth it.
Not at all - thank you! I don't work at the most unethical place by quite a margin but it'll still come in handy. And it's a damn fine read.
♥ 2
Hey @msantolini, this sounds like something someone you know would want to study? Anecdotally it matches what I would expect.
♥ 2
Genius. Well played.
♥ 4
It's sad that social networks have become such unaccountable cesspools that emergency censorship feels like something every responsible government should have in its toolbox.
Quoting a tweet by @__apf__ ↗
♥ 7↺ 1
Not fulfilling access requests properly.
♥ 8
I actually laughed out loud.
♥ 1
I believe they are fixed, but they might only be fixed for a given origin. Cc @Aaron_Krolik?
I'm keeping "liver ramp" as an excellent autocorrect though.
♥ 2
Our very own @aliceafung from the @nytimes data governance team now in the news for keeping the @MTA on its toes! patch.com/new-york/new-y…
♥ 1
I feel for Hertz here, but at the same time why would anyone go to Accenture for web work instead of, you know, actual professionals?
Quoting a tweet by @stopsatgreen ↗
♥ 8↺ 1
Evidence suggests otherwise.
♥ 1
TFW you rush to Amazon before your brain is done recalling that "pre-order" means "not now" 😵
That's deep archeology.
Not caring about privacy is privilege. Harming privacy is oppression.
Quoting a tweet by @evacide ↗
♥ 3
"Boobs don't work the way people think they do."
Don't laugh, read the thread, the odds are you don't know either! (And Dr @SarahTaber_bww does great threads in general.)
Quoting a tweet by @SarahTaber_bww ↗
♥ 2↺ 1
This is looking worse by the day for current @team_markup.
Also, who the fuck does Myers-Briggs personality tests at work?
Quoting a tweet by @JuliaAngwin ↗
♥ 2
Australia is... different. 🇦🇺 nyti.ms/2VsHhlt
↺ 1
I wonder how well it would fit in in Brooklyn.
Quoting a tweet by @Emma_Hollen ↗
Data deletion isn't radical or without precedent @cwarzel! The @CNIL has used it before as a remedial alternative to fines. And I don't think they shied away from creative solutions to end the Guilded Age.
Quoting a tweet by @PrivacyProject ↗
♥ 7↺ 2
No simulation would be deemed credible with that kind of idea.
Is there any reason to still buy Google’s claim that their products breaking in other major browsers is anything other than intentional?
I’m all for incompetence over malice, but this is adding up to a hell of a lot of incompetence.
♥ 6↺ 5
Not incentivising your teams to deliver products correctly, after the issue has been reported over and over again, is incompetent management.
↺ 2
Periodic reminder that if your business depends on apps you're basically serf to a behemoth with unpredictable mood swings.
"Apple Cracks Down on Apps That Fight iPhone Addiction" nyti.ms/2Wayu4O
♥ 7↺ 2
Yup! We're hiring for lots of positions, not just in tech but also data. It's a great place to work at!
Relatable.
♥ 1
Hey, look who published in Nature Scientific Data! Thanks to the reckless pace of scholarly publishing I am no longer associated with any of this work, but it's cool to see this!
doi.org/10.1038/s41597…
♥ 9↺ 1
I second that! Please make it so that we can stalk you at a distance. There must be some kind of tech that makes that possible.








