November 2019
386 tweets
I'm old enough to remember that, at least for investors, it's evidently boo.com.
♥ 1
I've been wondering if there would be fingerprinting-specific GDPR enforcement, it would seem like a good topic for a DPA to hit on.
I'm curious about your ad fraud limitation. Is it because you're worried that the fingerprint wouldn't be purpose-limited?
♥ 1↺ 1
I think invasiveness depends on implementation. Also, I'm not sure it's realistic to expect ad campaigns to run without fraud prevention. What's the alternative to LI? The bots would never consent...
♥ 2
Of course, but I would think that for fraud prevention à fingerprint on a seven day retention plus local IP from WebRTC will get you a long way. You really shouldn't need the whole graph BS for that purpose.
My concern would be the possibility of cheating with purpose limitations. There might be a case to prevent fraud protection companies from being involved in targeting.
♥ 1
Brilliant 😁
♥ 1
Have you heard this one before? I've never heard this one before.
Quoting a tweet by @b_fung ↗
♥ 11↺ 2
Typical examples include:
• “There can be only one!”
• “Eat lead, motherfucker!”
• “And I… am Iron Man.”
• “LinkedIn is cool, just sayin’.”
♥ 1
Google in the insurance space, especially health insurance, is probably one of the most dystopian outcomes our current world could lead to. Irrespective of whether you think Google is malicious, insurance is structurally user-hostile. Now think of what Google knows about you...
Quoting a tweet by @natashanyt ↗
♥ 41↺ 43
I would see similar issues with them though. Alexa can know if you’re having a party or if your throat is sore, Prime Video knows how much time people spend watching TV… There are clear conflicts of interest.
♥ 3
It's true that they are more about obliterating the competition than about monetising the destruction of democracy, but I would worry about their behaviour once they dominate the market. They've raised prices when cornering a market before.
♥ 1
That's because you're stuck in the classputing world. Join the revolution! 🔥 🔥 🔥
Google also say everywhere that they don't sell your data 😉
♥ 4
Is there a reason not to do this (other than that it's hard)?
I expect our understanding of DNA to change quite a bit.
Oh wow, fighting words! There's only, like, a whole area of metaphysics dedicated to explanation, and I get a sense they might expect a bit more than just predictions. See also: quantum foundations.
♥ 1
Oh, you can know those are bullshit from the word "grand".
It's a bad take, Manu, but I'm not mad.
♥ 1
Just like the cache.
Quand tu veux!
Juste je te préviens, c'est le tome 1.
Makes it more nutrious.
♥ 1
In which @natashanyt asks a rather salient question: "Why are Americans protected from hazardous laptops, fitness trackers and smartphones — but not when hazardous apps on our devices expose and exploit our personal information?" nytimes.com/2019/11/02/sun…
♥ 138↺ 72
A beautiful observation. We dehumanise data to forget we're doing these things to people, we humanise AI so it's not us doing it.
Quoting a tweet by @rajiinio ↗
♥ 8↺ 1
It's not so much that we need more privacy professionals, rather we need a better collective understanding of what privacy is. Very few people can cogently tell you what it is, and yet make decisions involving data.
Quoting a tweet by @can ↗
♥ 17↺ 2
On this I actually disagree. I think we can build a solid practice atop Nissenbaum's definition and garner broader consensus from that.
Haha, Fahrenheit makes no sense whatsoever to me 😁
I find the notion of protection too negative. It's arguably appropriate for a regulatory framework but I don't think it is powerful enough to help structure the data economy.
The best short intro is probably @msalganik's:
bitbybitbook.com/en/1st-ed/ethi…
I'm all for @nytopinion encouraging healthy debate, including of ideas I disagree with, but it's very unclear to me what this victim-blaming piece that's nothing more than "kids these days" painfully puffed up to 800 words contributes to that. nytimes.com/2019/11/02/opi…
♥ 6
The list of pieces better than @maureendowd's is long, but this thread has a few excellent examples.
Quoting a tweet by @LAM_Barrett ↗
♥ 3
The reason people increasingly hate the web is because you're keeping it a privacy cesspool. Every way you ask, 85+% people expect their browser not to share their data with third parties. Who wants new features when you can't trust the user agent?
♥ 7
So instead of pointing fingers, have you considered bringing your laggard browser up to speed with everyone else? Because to bystanders like me it doesn't look like you're in the best position to speak from any kind of moral high ground.
♥ 1
I am well aware of the issue with iOS, anyone who wants to be there is forced to be in the App Store because the browser is missing a few key features that enable the alternative. Given where App Store policies are headed, that's a real problem.
♥ 1
It's a path that leads to lock-in. That's pretty clear! But what I'm saying is that it's not more lock-in than that which comes from being locked into a very specific approach to ads sustained through pervasive tracking, or from AMP.
We're all a bunch of small folks caught up in the middle of this Great Game. If all parties are open to coming to the table and map out a path ahead with less collateral damage I'll be happy to host! Meanwhile, much as I do ❤️ Alex, I'm not sure the finger pointing is warranted.
This is true, though one advantage here is that it's persistent essentially forever because people keep the same profile across devices. Default would be way better, but numbers I've seen show a pretty high volume of users with LAT turned on.
All it takes is one article/tweet/friend/whatever to flip the switch and it's done. The web was supposed to get that too!
On Android, side-channel attacks for this sort of thing are common. I haven't seen research for iOS, I wonder if the same is true.
I'm not sure that the dynamics of AMP are producer driven. It's that way or no traffic. I don't think it's whataboutism to point out that Chrome is at least as big a problem for the freedom of people making web stuff as iOS is.
Hmm, no, it's not hyperbole. And consumers aren't locked into iOS (but producers are).
♥ 1
Safari sucks in a way that unfairly benefits Apple. Chrome sucks in a way that unfairly benefits Google. That's not whataboutism. However this thread feels like it could use some whateverism.
♥ 1
Well then don't choose iOS.
Sorry but your argument has a nonsequitur. Is the problem consumer lock-in or hurting the web? The two are not synonymous. If the problem is consumer lock-in, iOS sucks but there's worse. If the problem is hurting the web then Chrome is more harmful than Safari.
♥ 1
As I said above, I am not claiming it is not a problem. Just that it's not a bigger problem than other self-preferencing behaviour. Again, just ask the Afghans what they think of the Great Game.
🔥
Pack up on 🍿 for later this week!
Quoting a tweet by @duncan_2qq ↗
Seconded!
♥ 2
Privacy in Context, perhaps Bit by Bit if they need to understand data
The Market for Lemons
Complexity (the @MelMitchell1 one)
Ruined by Design (or Design for Real Life if they're easily shocked)
An intro to network science
Goliath (or Lina Khan or Dina Srinivasan if shorter)
♥ 3
The Obama conservatives are worried.
Good.
nyti.ms/2PNm0jk
♥ 1
Dismembered tech giants, no shale fracking... I can't wait!
If the goal is to avoid nasty reviews, there are other ways. For instance, have the reviewers work as a group to produce a single review from their individual ones.
I haven’t read Petronio so I can’t help much I’m afraid. At a cursory glance it looks like there is substantial overlap, but CI seems more detailed in how you would go about operationalising it.
♥ 1
Note that this view may be coloured by the fact that I use CI in the trenches. So it naturally feels easier to me from practice, YMMV.
♥ 2
Can I get that too, please?
♥ 1
Well duh!
I mean... who would consent?
Would go great with the Bacon API though.
♥ 2
We should have a club or something. The tales that are my trademark font of wisdom have been credited as "a colleague" and "a spokeswoman for The Times". The stuff of legend.
♥ 1
They'll change them again by the end of the week.
♥ 1
I don't think that what we do is particularly advanced or special, we basically parse down situations into actors/attributes/tx principles, and then talk about whether it seems appropriate and what we can improve. We use it for our Data Review Board (a lightweight IRB).
One aspect I've found useful is how it helps incremental approaches. I can't single-handedly overturn two decades of Internet crazy but it's possible to plot steps in that direction. One such aspect has been acting on data controllership as a transmission principle.
I wanted to come! But I found out too late and summer can sometimes prove tricky. I hope to make the next one.
Ça va être le cas en Californie à partir de juillet. Ça reste une option possible pour ePrivacy.
♥ 4↺ 1
Si tu insistes 😁 oag.ca.gov/privacy/ccpa
En juillet CCPA va être complétée d'une série de réglementations précisant la loi (des décrets d'application). Pour l'instant c'est en draft mais il y a une clause qui instaure le respect des privacy settings.
♥ 2↺ 1
Pour le Web c'est DNT, mais il y a aussi LAT et équivalents pour les apps.
♥ 1
Oui, navigateur plus légal ça empêche les sites d'être sous pression pour obtenir ton consentement. Le risque c'est qu'on se retrouve avec trop peu de données parce que les sites ont fait nimp pendant trop longtemps.
♥ 1
En vrai, il n'y a pas nécessairement obligation de consentement. Les sites le font parce que 1) leurs pratiques data sont réellement pourries (souvent) et 2) parce que les régulateurs ont une vision un peu étrange des cookies. Mais on pourrait s'en passer!
♥ 1
If the SameSite change matches what's in Canary it's pretty underwhelming. The cookies aren't all that dead yet.
What is however maddening is that the writing has been on the wall for a while but precious few seem to use the intervening time to innovate.
♥ 4↺ 1
Data driven advertising is an industry ripe for disruption.
♥ 3
On peut tenir la position que des analytics en first party c'est légitime, en tout cas si tu ne fais pas nimp.
Those are only blocked because they haven't set the SameSite flag. That's a trivial fix. And then unless there's something new it's back to normal.
♥ 3
Oooh! I need to make sure I don't miss that one.
Ça dépend de ton autorité compétente, les régimes varient. La CNIL est un peu plus souple que l'ICO sur ce point. Aussi, ça peut évoluer plus facilement que la loi, et tu peux arguer de raisons de t'affranchir (mais il faut de bonnes raisons!).
Do you have a specific case in mind? This is at worst a fourteen character change, you'd have to be pretty shady to fail at that, no?
Ça pourrait se défendre tant que les options de lien avec la pub sont off. Après, ça reste du third party, il est probable que ça soit mal vu.
Hmmm, ce passage n'invalide en rien ce que j'ai dit.
GA en même temps c'est pas first party. Après entre GA sans les fonctions pub et Matomo, je ne suis pas sûr que ça fasse une grosse différence?
GA sans fonctions pub est un data processor, ils ne sont pas sensés faire quoi que ce soit avec tes données autre que de te donner des analytics. Après on peut avoir confiance ou pas, mais s'ils trichent et se font chopper, ça serait très sérieux.
♥ 1
"unduly". Ça ne fait que dire que si c'est pas légitime c'est pas légitime. Et, pour référence, j'ai dit: "On peut tenir la position que des analytics en first party c'est légitime, en tout cas si tu ne fais pas nimp."
Pas sur un contrat de processeur. Ce que tu dis est vrai pour la pub par exemple où ils sont contrôleurs et où tu es responsable pour eux (en partie).
Hmmm, non.
Évidemment, mais là on parle du cas où ils font *autre chose* que la finalité que tu leur as donnée. Tu passes du coq à l'âne.
Évidemment aussi, et c'est bien pour ça qu'on s'est battus contre l'interprétation GDPR de Google pour ce qui concerne la pub.
Encore une fois, évidemment, mais il n'y a ici aucune évidence de ce genre. GA existe depuis très longtemps, sans leak majeure, si Google triche sur ça ça ne se voit pas.
Généralement, la vérification est déclaratif, il y a rarement un droit d'audit. Je ne fais pas confiance à Google pour grand chose mais force est de constater qu'ils savent faire de la sécurité. Après, s'ils trichent, je n'imagine pas un juge le reprochant.
Euh, citation needed.
Mais Nicolas ne parle pas de GA...
Non non, je ne vois pas comment cette interprétation tient. IMHO ton problème sur Matomo c'est que ça reste du 3P. Après, s'il est bien configuré, que tu as un opt out clair (pas planqué) je pense que tu es plutôt en bonne position.
L'ICO a dit qu'ils ne regarderaient pas de ce côté là, par exemple, alors qu'ils sont stricts.
Tu recites le même passage qui ne dit pas du tout ça...
Mais pas de du tout, c'est n'importe quoi, il y a même un recital qui dit clairement que le marketing est en LI (évidemment avec tout ce qui va avec). Du funnel en 1P c'est clairement LI. Les gens passent au consent parce qu'ils ont tous des solutions tierces.
Le consentement est automatique quand tu passes d'un controller à un autre, or en 1P le problème se pose assez peu.
Devant un juge tu peux te prévaloir d'avoir suivi les conseils de la CNIL. Il n'est pas tenu d'être d'accord, mais le contraire serait déraisonnable.
Je ne suis pas ton avocat hein. J'ai juste lu GDPR, la plupart de WP29, et les guidances de plusieurs data authorities, et ça me paraîtrait raisonnable.
Par ailleurs, le consentement à toutes les sauces est une approche particulièrement débile et toxique pour les utilisateurs, si tu peux démontrer un traitement raisonné par défaut et un opt out clair/facile/joli tu es sur la ligne de WP29.
♥ 1
Les risques sur les rights and freedoms sont plus faibles, tu connais tes mesures techniques, il n'y a pas d'autre controller, tu gères tes DSR, tu es mieux aligné sur les attentes utilisateur.
Et le texte cité ne dit pas du tout ça.
Mais pas du tout. J'hallucine de voir des conseils comme ça donnés avec cet aplomb.
Le consentement n'est pas du tout au coeur du GDPR, c'est juste l'interprétation la plus paresseuse. Il y a beaucoup de notions de "reasonable" et la clarté pour l'utilisateur est toujours un aspect important.
Je n'ai certainement pas dit ça. Mais il y a beaucoup de variables sur lesquelles on peut intervenir pour améliorer les traitements. Tout passer sur du consentement c'est juste entraîner les gens à croire que leur pref météo et du RTB c'est pareil.
C'est vraiment, vraiment très mauvais pour l'utilisateur.
Hi! But I reckon I'll see you at All Tech?
Perso je trouve que c'est une très bonne loi mais souvent mal interprétée. Le focus sur le consentement est une erreur de lecture et un manquement au design.
Je bosse sur un doc pour penser la suite. DMez vos comptes gdoc si ça vous dit.
EPrivacy bosse là-dessus, mais je pense que ton idée de penser à l'avance à comment faire ça bien est bonne. Il faut plus de gens du Web là-dedans, je suis souvent seul.
Le problème du consentement aux cookies est plus un mix inopportun des lois cookies et du consentement niveau GDPR. Le résultat est inutile pour la privacy, et effectivement résulte en plein de conneries. Il y a mieux à faire dans le cadre GDPR.
♥ 1
Les experts ne le vivent pas bien, ceux qui ont besoin de pub et de marketing pour tourner cherchent des options. Beaucoup de mauvaises mais pas que.
Il y a du bon, mais c'est limité à d'autres niveaux, notamment manque le cadre intellectuel ancré dans la tradition de pensée privacy que GDPR a.
Je suis sûr que ça va venir en Europe aussi, reste à ce que ça soit bien fait. Le CCPA prend le parti intéressant de forcer au respect de DNT mais avec une interprétation différente de celle de DNT (et, je pense, meilleure).
♥ 1
"Structural competence > cultural competence" and many other great ideas in @CourtneyCogburn's talk at @AllTechIsHuman.
♥ 24↺ 9
Now my most excellent colleague @chrishwiggins goes beyond dumpsterfireology (important science as it is) to talk about how data science rearranges power, ethics at the intersection of philosophy (define) and sociology (design).
♥ 1↺ 1
@tracyadennis recounts her research on the impact of mobile devices and the attention economy, comparing using a device in front of your kids to the Still Face experiment. It's gut-wrenching. #AllTechIsHuman
♥ 8↺ 4
They were great, as first talk on a Saturday conference it really snaps you into gear, arguably more than coffee. I wish I had captured more, I think there'll be a video.
@ellecortese describes harassment in social VR as "what if YouTube comments could chase you around". An excellent if terrifying characterisation. #AllTechIsHuman
♥ 8↺ 4
I like @Cennydd's idea of building "temporal literacy" to help us make decisions that are more democratic and less technocratic. #AllTechIsHuman
♥ 3↺ 3
"Design has to get more into the consequences business, and not just the interactions business."
"Anyone who believes that design is a science definitely doesn't understand design and probably doesn't understand science either." @Cennydd, #AllTechIsHuman
♥ 8↺ 4
"The future of technology is not going to be in the Silicon Valley, it's going to be from places a lot more interesting than that. We're going to have to move away from empathy and into radical inclusion." @Cennydd, #AllTechIsHuman
♥ 16↺ 4
Interesting question from the #AllTechIsHuman audience about how designers can help not bring consent as understood in privacy law into the future. It's true that it's a total wreck and only related to consent in name.
♥ 3↺ 3
has a good answer about using quick gestures in VR to signal lack of consent. It could translate to data in that data sharing should only be through express user action (to accomplish something) rather than through dark patterns.
♥ 3↺ 1
Oui, c'est une bonne blague cette excuse. Comme si les navigateurs n'avaient pas déjà ce pouvoir.
This is an excellent depiction of what @chrishwiggins called "W-2 Bias" at @AllTechIsHuman yesterday.
Quoting a tweet by @TomValletti ↗
♥ 2↺ 2
Is that really ruled out though? Under the form "What set of beliefs/preferences would lead me to do X?"
I'm assuming, perhaps wrongly, that the explanation being sought here would be of a similar tenor as one used to render an account of your own self. Only in very rare cases would you resort to a hyper-specific preference for an exact X at this exact moment.
♥ 2
I'm further not convinced that our explanations of our own behaviour isn't underdetermined as well!
♥ 2
I was about to nod... but I'm not so sure. Do those people really know themselves well or do they just know the restricted parts of themselves they let themselves roam well?
Dear God, what have I grammarred.
♥ 1
I'm curious: isn't there a point at which being too predictable might make you susceptible to manipulation?
♥ 1
I think Nietzsche is a complicated and variable case (which Nietzsche?). I don't know Yudkowski. But that's where I think I trip up on the notion: how can you know yourself and not those unlike you given you will be unlike yourself very soon and introspection has limits?
I think this returns to limited self-roaming. Maybe the class of people you describe do not change much? (That would rule Nietzsche out though.)
🔥 🔥 🔥
It's a little bizarre: over the past few weeks I've been pitched a series of pretty senior adtech positions. Is it that there's a change of mentality there or is this just a fluke?
♥ 7
It's basically running her campaign for her. Rather brilliant.
♥ 2
It might not be what you use but just in case: on Android you can schedule the Do Not Disturb mode, it's pretty neat. Search for "disturb" in the settings, it should come up.
♥ 3
I don't know, they're pitching me things like VP Eng where I guess it's not so much about buying credibility? I mean, it's not like Chief Ethics Thinkrupter or some such. It might just be that I somehow fell into some recruiter's DB.
Not that I'm interested, but it struck me.
♥ 4
Yeah, I'm still mad I didn't get to be Boss-Level Unfuckering Imagineer. I mean if I ever had vocation or trade that's it.
♥ 2
Hahaha 😂 Well, who better would know how to circumvent tracking prevention? 👾 👹
♥ 3
PCM proposal?
Oh! I missed the rebrand/pivot!
TFW you use automated systems to make life-altering decisions without controlling for even the most basic fairness issues.
This needs to be treated as what it is: negligence.
Quoting a tweet by @fatemehx2 ↗
♥ 9↺ 2
♥ 1
Nature is so beautiful this time of year.
Couldn’t agree more — I had a wonderful time with this panel and learnt a huge lot from co-panelists & moderator.
Data governance is such a rich topic, I could listen to perspectives from @madhumachi, @mary_madden, and @wuster12 all day.
Let’s indeed take this show on the road!
Quoting a tweet by @sampswu ↗
♥ 3
TFW you’re trying increasingly contrived ways of removing a character from a 281 character tweet but you’ll surely DIE before getting rid of that final period or an Oxford comma.
♥ 16↺ 3
Wait, are quote-tweets replies now?
♥ 1
I know, but I mean: I made a QT and it shows up both as a top-level tweet for me and as a reply to the other tweet. I had never seen that before.
I know that, but I meant: I made a QT and it also showed as a reply. Weird.
You control what data gets saved, unless, you know, we happen to want it. twitter.com/sarahkliff/sta…
♥ 4↺ 1
Tweetbot, but I can’t repro. But I know I couldn’t have hit «Reply» either because then I would have had to embed the tweet manually and I’d recall that.
I might have triggered a bug, or a weird A/B test.
♥ 1
And it seems pretty clear that so did Google Plus, but no one seems to have managed to look more closely into that.
♥ 2
Honestly? Because they actually could be doing the good many of them think they are doing. But they’re too technocratic to stop themselves.
♥ 1
Especially in healthcare data — that’s about nothing but curing cancer.
♥ 1
The money people are clearly trying to get away with as much capitalism as they will be allowed to, but I don't know if I blame them for that, I mean it's their job? The nerds, though, are supposed to be smarter than that.
♥ 1
Totalitarianism is a system, what its intentions are does not actually matter to whether it is a good one. It produces harm simply because no one is smart enough to be safe at that scale. Thinking otherwise is dangerously arrogant, IMHO.
♥ 1
And technocracy is, indeed, a branch of totalitarianism. It never sets out to do evil, either!
♥ 1
Up to the task of doing it, or of doing it ethically? For Apple I would yes the former, no the latter!
♥ 1
You think they would do it ethically but badly? I reckon they would do it ethically by their users (mostly, at least within "don't get caught") but they would screw over every doctor and progressively control every hospital by gating access.
♥ 1
It might be inspired by what they're doing to the press 🤔
♥ 1
Oooh, 🔥 🔥 🔥
Oh fuck now I'm depressed.
♥ 2
Yeah, I mean it's depressing because it's true. Hard to get rid of that kind of thought.
Well, I'm not saying I see it as a done deal, but it certainly feels like a plausible fucking future, if "future" is even the right word for such a state.
Do you have a cat? They make that weird sound where it really feels like they just threw up in their mouth but they maintain a dead stare.
I just did that.
♥ 1
Beats his vintner carrier from that West England winery he established, you know, The Grapes of Bath.
♥ 1
Quelle espace?
Clearly you must have been in that meeting, Sean, I can’t see how you would have guessed that otherwise.
♥ 1
Ew. Rare contender for worse neologism than “phablet”.
♥ 3
That Google is getting its hands on a lot of data they probably shouldn’t have won’t surprise many, what I do however find interesting is the emergence of a whistleblower. Higher general clarity around privacy is likely to correlate internally as well. theguardian.com/technology/201…
Be careful what you wish for 😉
♥ 1
Everyone is posting their "there's only one month left in the decade" memes but somehow none of them are getting replies from drive-by pedants pointing out that there are, actually, thirteen months left in it.
I mean, do I have to do everything my-fucking-self on this site?
♥ 34↺ 1
I think the logic is that Safari prevents cookie persistence but it does load the code.
Oh well problem solved then.
I know, we fucked up many many years ago and now we have to maintain compatibility. But yeah, there was no Year Zero!
♥ 1
Glad I'm not the only one paying attention!
We would pontificate at each other in blog comments and IRC, though!
♥ 1
I'm going to move my decade retro to the end of June.
Maybe in furtherance of Erik's point, the whole world changed much more before this decade than inside of it. We do get lots of innovation theatre, but not much new.
Quoting a tweet by @erikphoel ↗
♥ 2↺ 2
Do you know how it was served?
Yes, that’s a good question. How this thing survives on anything other than blind faith is unclear to me.
♥ 3↺ 1
Yup, my point exactly.
♥ 3
That melancholy feeling when you realise that the @ICOnews’s DPPC2020 conflicts with the @PrivacyPros’ GPS2020…
♥ 1
Sorry, forgot: blog.google/products/adman…
♥ 1
I'm looking for book/article recommendations about technocracy, especially (but not only) if studied in relation to authoritarianism. ⚙ ☠
Any good suggestions my friends?
I do hope that @DPCIreland is not so naïve...
♥ 1
Yes, and the idea in general too.
♥ 1
Whoa, and his other books seem kind of wild too! Thanks!
♥ 1
Thanks, this is *super* helpful!
The conclusion alone is noteworthy, thanks!
♥ 1
Thanks, will check!
♥ 1
Everything about the name, the titles, the topics sounds invented, I love it, looking forward to digging into it.
♥ 1
I generally enjoyed this column from @fmanjoo as I believe he draws stark and clear attention to a real issue, but like much that is written about privacy I feel it falls just short of teasing out the source of the tension. Thread!👇
nytimes.com/2019/11/15/opi…
♥ 27↺ 9
The heart of privacy is about *appropriate* flows of data. It's not about collection or control, though they impinge on the issue. An example helps:
If I've invited you over to hang out, and you observe what I'm doing in my living room, that's fine: no privacy violation.
♥ 13↺ 3
If however you observed the same behaviour by peeking through my window — same people, same data collection, same level of control (I can't erase inside your head) — this would now be very clearly a privacy violation. You don't need to hire an ethicist, that's inappropriate.
♥ 10↺ 1
Thank you 🤗
The French Revolution actually tried that 🙂
Wait? Did I hear say you were doing the regs too? That's amazing 😁
♥ 2
Why is not all law like this?
♥ 2
I put it straight on Slack, too 😉
♥ 1
Such burn 🔥 🔥 🔥
Thanks! And indeed, that is where we are. But it doesn't have to be this way!
♥ 1
Thanks! I would be delighted to sit down and chat, anytime! In fairness though, I'm mostly channelling small bits @HNissenbaum, she's definitely on to something!
But that control is often distinct from people's individual control. The reason people don't peep through your window isn't just because you'd punch them. Law and shame matter.
Thanks!
Ha, that's a very kind thing to say! I can talk about privacy for a long time, probably longer than is reasonable, however there is (well-justified) reluctance to mix things up between business-side people and opinion folks.
I'll bug them next time they're in the NYC office 😉
♥ 1
Any time! I am annoyed that so much is being said about privacy but so little is even a bit cognizant of CI. I've been rambling on about it at work for a couple of years, but I guess more public rambling is called for!
Thanks Gabriela! Boom 😉
Lol, where is that from?
In case you missed this over the weekend, here is your Monday morning privacy thread!
The heart of privacy is about *appropriate* flows of data. It's not about collection or control, though they impinge on the issue. An example helps: If I've invited you over to hang out, and you observe what I'm doing in my living room, that's fine: no privacy violation.♥ 13↺ 3
♥ 4↺ 1
Oh wow, they still use my stuff! That's crazy! Sure enough, that reads like docs I would've written...
♥ 1
I am not saying that control is useless, and in fact both transparency and choice also have their place. But it's just a possible means towards appropriateness and is not on its own ever an indication of privacy.
♥ 1
If you look at all the anti-privacy privacy proposals (Privacy for America, @InternetAssn's Privacy for all Americans, or Google's thing) they all use transparency, choice, and control. In there, control is seen as after the fact, assuming you know what happened, and have time.
♥ 1↺ 1
None of those will ever deliver privacy.
♥ 1↺ 1
Well, if it's an actual true and respectful choice, then it is privacy!
Or the sale of goods (now that I’ve moved into your house, will you sell it to me?), not to mention sex…
That’s what was asked for in California as well — it’s a classic move at this point.
♥ 1
This is easily the worst decision in ongoing #ePrivacy drafts.
Quoting a tweet by @WolfieChristl ↗
♥ 11↺ 2
If I happen to have a hypothetical friend who would be willing to explain that this is bad for online newspapers and press publications, who would they bring that opinion to in order to effect change?
♥ 4↺ 1
Not received, no. It's unclear to me why people shouldn't have reasonable expectations of privacy when reading the news...
♥ 1
Thanks!
♥ 1
My DMs are open — thanks!
♥ 1
La description parfaite!
We need to know.
♥ 1
I'm the best third wheel, outstanding awkwardness taken fully in stride.
♥ 1
I think what's missing is a positive proposal as to how this could work. Maybe even an Article 40.
Do you know if more information is available on that study?
This morning, @axios has a few interesting details about how The Times is progressively evolving its practices towards greater privacy. axios.com/newsletters/ax…
♥ 16↺ 4
Who's the other Jamie?
♥ 1
What bothers me most is: even in that setting you had privacy. If you confided in someone, I'm sure there was an expectation that it not be shared inappropriately. Your friend's business was not the village's. Information boundaries worked.
♥ 6
Dude, you screwed up, that’s PerfCow Conf.
♥ 8
Some people settle for just triangles on paper. I know it's hard to believe, Olivia, but it's a fact. Just triangles. On paper.
♥ 2
Hi Jakub!
Does that make this a subsubtweet?
For reasons I'm finding myself having to use Gmail and I can't remember the last time I have been this frustrated with software. What am I missing? Are there special tricks to make it usable?
♥ 6↺ 1
After a day with that thing I am seriously considering other callings!
That's precisely the option that isn't there right now 😑
That's actually quality advice, Peter 😁
I normally use Thunderbird on desktop and Aquamail on mobile, neither is especially wonderful but I find they get the job done.
♥ 1
TELL ME YOUR SECRETS, TAKE MY MONEY ALREADY!
Seriously, Gmail feels like it was made by someone who's only ever used Snapchat and had email explained to them over a bad phone line in a language they took as an elective in middle school.
♥ 8↺ 1
I used to think that that was true but now that I've had to actually put in serious time with it all I can think of is whhhyyyyyyyyyyyy.
♥ 1
Yeah, that's where my personal email is, I've been a happy paying customer for years!
♥ 1
Yeah, I don't need convincing, I just have to use it in this case...
You're just jealous, you want to be the one and only CyberTurk.
Everything? Just the most basic stuff is broken or doesn't exist. For instance, the only way I can ever stay on top of email is 1) filters, and 2) regularly I scan quickly through my inbox and delete/archive what I don't need to handle.
But Gmail filters are near useless. I wanted to move Calendar messages out of the inbox which you have to filter on Sender, but it can't do that. So that's a couple dozen messages I now have to manually sift through.
And for deletion, you can't delete a message in a thread without five clicks. There doesn't even seem to be a sane shortcut to delete a message, you need to first select it then delete.
This was made by psychopaths.
♥ 1
I found that hack, but it's such a terrible hack! I mean, this is basic functionality and instead you have to match file names as text in a MIME payload...
That's the conclusion I'm reaching: people who find Gmail fine also read email with a mouse 😁
Hey, sorry, I am not *at all* judging! I do appreciate the help, but I think this is actually the deciding factor: it's optimised for mouse users. If that works for you that's genuinely great. But it REALLY doesn't work for me.
You know the feeling when you're walking in a hurry and everyone in the street is walking slowly, and you're trying to move faster without being rude? That's what clicking through email feels like to me.
Right, so you adapted to the tool. I might have to do the same! My email reading method is to get as fast as possible from, say, fifty emails to five, and then just focus on replying to those. Right now it feels impossible to focus because I have 250 emails and can't trim down 😑
Yeah, unfortunately I get a lot more mail than that, which is why I want to be fast. You give me hope I will adapt, right now it’s mostly been actual physical pain from frustration and I had nightmares about using Gmail that woke me up :-(
Unintellectual property?
♥ 1
Wow, congratulations Erik!
♥ 1
Anyone on here have a good exorcist to recommend in Brooklyn?
♥ 3
Let us know when it’s available for pre-order1
♥ 1
Yeah, maybe bring in a bass and go full jazz.
Indeed! The problem is that the neighbours have been changing their heaters which is making things worse and I don't think there's a point in trying to fix this until that's done!
That would explain a lot.
Oh, you love JavaScript? Name a three-letter acronym that isn't a way of loading a dependency.
♥ 15↺ 2
You can't just say that and not give us some details 😁
♥ 3
That's Functional Sideloading with a BOM. It was used for Unicode-safe dynamic plugins in Prototype.
♥ 2
No, FIBm was FSB but in MooTools. I'm always in favour of Yet Uknown Knowledge for its predesynchronous predictive promising, it's the best option for Truly Interoperable Dependencies.
♥ 2
There have been discussions about getting SVG elements to extend HTMLElement but last I checked they were stalled sine die.
♥ 2
It's one of those things... everyone wants SVG fixed but no one wants to do it (or to pay those who would).
♥ 2
The Internet is a force for good, and increasing awareness of suffering is not why it is in a bad place.
The Internet is in a bad place because decades of astoundingly bad policy have created companies of such stupendous scale that no one no matter how smart can make them safe.
Quoting a tweet by @evan_greer ↗
♥ 12↺ 5
Fix the policies. Break up Google. Break up Facebook and Amazon.
Enjoy a return to innovation, to responsibility, to caring about users, to scale that doesn't corrupt absolutely. I'm old enough to remember when this was fun.
♥ 11↺ 3
Oh man, so good. The mighty indeed have fallen.
♥ 1
The STEM vs. Humanities debate (or even distinction) is for lazy people who only want to understand half the things.
Quoting a tweet by @olivertraldi ↗
♥ 6↺ 1
This circumvents blocking but does not bring cross-site tracking back. Am I missing something or is this a pretty weak move? It feels more like a desperate last ditch attempt than anything else.
♥ 4
Sure, but it still feels pretty last ditch tbh. I’m not saying that it shouldn’t be fixed but some of what I’ve read out there makes it sound like a revolution in tracking. The problem will be solved.
♥ 5
I’m looking for examples of things that everyone talks about but no one understands (or few do).
Feel free to quote-tweet if you want to be sassy!
♥ 6
Merci Abie :)
The weather is the best example I’ve found so far.
I’m curious about urban planning: what is it that people don’t understand?
Or quantum supremacy — for sure!
♥ 2
Hmmmm, interesting. I’m curious about LED?
Good example indeed!
That's a good point, thanks c
♥ 1
The MTA works?
♥ 1
"Accidentally" 🤗
This is the best answer, thank you.
♥ 1
Awww
♥ 1
In fact, money!
♥ 3
Truth!
The problem is that the people who make tech have shown no interest in understanding how the web is monetised. As a result, marketing is operated by marketing vendors.
♥ 6
I can confirm that.
♥ 2
Oh dear god yes.
♥ 1
Resistance to corruption and resistance to W2 bias are not the same thing, though.
But the folks building standards there didn't. Nor did most of the major open source environments, or developer advocates, or tech conferences. We just let martech run free.
♥ 1
This one! en.m.wikipedia.org/wiki/Form_W-2
Haha, true!
♥ 1
Indeed! That said, in talks I now describe ML as "lots of dumb stats very fast" and it does seem to unlock people's ability to be more critical! 😁
♥ 1
I have mine which I think no one will cite, I'm curious what others think!
Oh yeah.
Cutie.
♥ 1
Anything with more than three agents, really 😁
♥ 1
Yes, viruses are weird.
That's actually true!
YES! I was wondering if this one would ever come up!
♥ 1
Haha, the sad part is how true that is.
I agree that no one understands that, but I'm not sure people talk about it much!
♥ 1
One thing I love in these responses is seeing what people see as stuff that "everyone talks about". Entheogens is a fascinating addition to that list 😁
Yes, animal minds are a great example of matching both talked about a lot and not understood!
That’s by design ;)
♥ 1
Completely agreed on cheering up — there is a path forward. To be clear on my original statement: I feel there is too much ignorance and naïveté on the part of the people who would want to do good. It’s not that no one understands, it’s that those who should often don’t.
♥ 2
It’s safe to say that Brexit makes no sense whatsoever to anyone.
GDPR does not have a built-in notion of third party but the WP29 literature does, and rightly so: it is certainly not the only aspect that matters, but it is a key distinction to users and to understanding privacy.
♥ 1
Whichever one of you made this tweet, THANK YOU 🤗
♥ 1
Amis Canadiens, j'ai une question de toute première importance: au Québec, est-ce la petite souris ou bien une forme de tooth fairy qui passe? 🧚♂️ 🐁
♥ 1↺ 1
Thank you 🤗
If you've ever parented while hungover, I highly recommend giving "Mama Hangover Blues" by the excellent "Milfy Way" (yes) a listen! Cc @NYTParenting
open.spotify.com/track/6kr34ZLp…
♥ 3
Hahaha, it might be! Thanks 😊
♥ 2
Fair.
♥ 1
Has anyone looked into @DAAUSA’s implementation of their announced “CCPA Tool”? Notably, is it the same mechanism as is used for AdChoices? Because if so it is already known not to work unless you use the browser that supports tracking.
prnewswire.com/news-releases/…
♥ 1↺ 1
This is pretty much my reaction every time someone says "privacy paradox", except I'm not quite as tame and polite.
Quoting a tweet by @Dymaxion ↗
♥ 5
I still remember the day I first had it.
♥ 1
Honestly, I simply don't understand what these universal ID schemes are about. It was never going to fly. No one was ever going to buy that it helps privacy. Why sink yet more energy into a dead end instead of looking for novel solutions?
Quoting a tweet by @larakiara ↗
♥ 40↺ 16
Same!
♥ 2
I mean.
♥ 1
I don't know, Marion, I don't know. If I were greedy, I'd want to get my fucking money at the end. I'd like to think I would do unethical things that would make me rich instead of unethical things that are just DoA while everyone spectates in bafflement.
♥ 2
Thanks Luke, much appreciated 😁🙏
♥ 1
1. The best you can do (that I know of) with them is a variant of DNT. At that point, it's better to do DNT minus the risk.
2. If adtech had demonstrated an interest in governance and self-regulation, this might be a conversation. But the past twenty years have been the opposite.
♥ 1↺ 1
Generally, the technical features of the proposal lend themselves to easy cheating and to substantial risk for users without a clear demonstrated benefit to anyone other than adtech.
DNT is global and persistent, is there any evidence that users understand adtech purposes?
The IAB has been such a toxic force in the past, I think it's going to be a while before any external observers believe that. The TCF didn't help, either
Users can't really enter into a compact too opaque for them to understand and that makes no guarantees for the safety of their data. And the whole point is to protect against bad actors, if everyone were trustworthy this would be easy!
Why would it not be the browser? It's literally its job too be the user's agent. And it has to default to something a lot safer than identification, otherwise the user has no real choice.
Absolutely. There is a small but substantial population that actually does want to be tracked and advertised to in the way it is currently done, they should be addressed.
♥ 1
Mutexes!
But none of this requires an id.
You're wrong, Ed.
♥ 1
The Veil of Ignorance lottery is quite popular.
♥ 1
Great answers in the thread!
Quoting a tweet by @keithfrankish ↗
There's a gaming arcade called Le Poêle in which tout can battle a Malin Génie.
♥ 1
That's a terrible comparison. Your phone number cannot be used by malicious actors to profile you. And we have DNT which offers privacy without the risks. UIDs are a strict privacy harm.
This is particularly egregious example but the whole thread is great: there is clear evidence of systematic cheating in the @IABTechLab TCF. Without testing, governance, or enforcement it's just too easy to cheat.
Quoting a tweet by @nataliabielova ↗
♥ 7↺ 3
Hey Web tech friends! I think you might benefit from a clearer understanding of just how crazy things have become with cookies. No matter how bad you think it is, it's worse. This is why tracking prevention isn't optional.
Quoting a tweet by @v0max ↗
♥ 34↺ 18
That's not necessarily true. There is precedent for trust busting to create far more profitable companies after they get split. Breaking tech up voluntarily might actually be the best option for shareholders.
Is it available?
I can grasp the analogy. It's just not analogous to the real world.
♥ 1
One important prong of fixing the monopolistic Internet is that, especially if we don't want a break up to only be effective for a few years, we need enforced interoperability. In order for that to work, we will need a renaissance in standards. Hard to bootstrap, but worth it!
Quoting a tweet by @jennifercobbe ↗
♥ 6↺ 2
I'm a standards nerd so I don't find that hard to believe 😁
♥ 1
In taking about profiling by malicious actors, you respond with... database telemarketing? Maybe if you stepped down from your little tower of condescension once in a while you'd find it easier to understand what people are talking about?
♥ 2
Much agreed, though it is insufficient on its own. It's subject to regulatory capture (see claims made against @wicg_) and you can use dominance in one market to cross-subsidise a fast-moving interoperable product (see Chrome, IE 4-6).
♥ 1
That would rock!
Indeed, indeed, I'm just cautious because a lot of us in standards once thought standards were enough (because, for a while, it's worked).
♥ 1
I'm not hostile, you're arrogant bordering on trolling and I'm just treating you as such. And no, this has nothing to do with balancing rights. This is about threat models. Saying UIDs help privacy is like saying drilling a hole in your hull helps with your barnacle problems.
Nothing bold there. What is incomprehensible is not the tech, it's that someone would understand privacy so poorly as to think it helps, or be so far removed from user expectations to think that user products would go along.
♥ 1
JSON has pretty damn good interop.
♥ 1
But how would you enforce that allowlist? If it's yet another IAB pinky promise it can't be trusted, not from actors who've failed to deliver on every promise of privacy for so long.
At the browser level, it's enforceable. I'm with you on the Google issue but keeping adtech unsafe and privacy-hostile just sends people their way.
I didn't say it didn't have shortcomings! But you can have a format that totally sucks and still be highly interoperable!
♥ 1
See, I told you you were a troll. If you ever did your homework on anything you'd know just how laughable your little attack is.
That gets you added to two lists.
There's a few things that can be measured. Number of trackers but differentiated by controller/processor, use of Referrer-Policy and CSP.
♥ 1
Oui, Sidewalk ça craint! J'aurais adoré mais je ne peux vraiment pas voyager là. Embrasse JC de ma part!
I've been trying to get more details on the study, notably methodology. If you know anything...
I've been told to bug Alan Toner but I haven't heard back.
♥ 1
I found out: it's La Fée des Dents!
♥ 1
Philosophy of science, though a number of other academic disciplines beckon. Mental health at the time and utter lack of preparedness made college challenging though, so I went to work instead.
♥ 1
They are so many kinds of wrong.
Sometimes Twitter shuts down batches of accounts. You might have been followed by part of a bot herd.
♥ 1



















