October 2020

497 tweets

Replying to @LAM_Barrett and @GeorgetownCCT

This is awesome news!

Replying to @kyotonio

Frankly, Facebook’s 28d window always felt excessive, no?
Noguchat.

Replying to @kyotonio and @johnwilander, @singe

I think it's key to make logging in everywhere safe, though. But for that to work we need to reliably partition identity so it cannot be matched across contexts.

Replying to @kyotonio and @johnwilander, @singe

That’s the way if you grandfather in email, so something like that is going to be required for a while. (And in some countries it’s phone numbers, which is even worse.) But I think there’s an opportunity to move beyond that.

Replying to @kyotonio and @johnwilander, @singe

At some point, yes, but I need to research and write a fair bit more first :)

Replying to @null and @pixeldetracking, @kyotonio

Hmmmm, no, this is coming up as a CNAME for hosting reasons and that’s it.

Replying to @kyotonio and @pixeldetracking

Yeah, I think a lot of people use CNAMEs because they’re convenient, not to do anything bad. But once again the bad actors fucked something up for everyone else. Note that with IPv6 I guess the CNAME threats could be replicated with A records, no?

Replying to @null and @SimonDeDeo, @peligrietzer, @joan0fsnark

It appears that they used one column per case rather than rows. This matches my experience with Excel in the wild: you *can* use it as a fine and non-expert data system, but it’s also a hell of a footgun in the hands of people who don’t have at least minimal data literacy.
Something like FileMaker, Airtable, or essentially anything that asks you what data you want to capture and then sets it up for you is likely to be better suited for this. Not that this glitch is unique… I’ve helped the NYT team collecting that data and… I’ve seen things.

Thread of 2 tweets

Replying to @rkhamsi

In some subjects it can be hard to find control behaviour to contrast with, though.
Some writers really have that knack for succinctly sketching out those little details that capture the essence of one’s life. Shoshana does that for mine.
Quoting a tweet by @swodinsky ↗
↺ 1
We need more of this, and we need this for the other tech megacorps (or is it magacorps?).
Quoting a tweet by @FBoversight ↗
↺ 2

Replying to @AmeliaHorgan and @joan0fsnark, @SimonDeDeo, @peligrietzer

Oh dear. The baffling part is why a conversion to XLS would happen at all, especially as part of an automated process.

Replying to @DoraCrisan

A few have, but last I checked the site is still up!

Replying to @DoraCrisan

Yes, that's also one of the strongest arguments against data dividends IMHO.

Replying to @DoraCrisan

Thanks! I will check it out.

Replying to @TzviyaSiegman and @danbri

I agree there are no great answers yet. I've been playing with Roam Research recently and it may be on to something. Slow, ugly, and a few bad decisions in there but it may be good. I have more in there already than in other systems.
Part of the problem is that most personal knowledge management tools are built with people who have a transhumanist mindset. I want cards with links, good search, templates, maybe OCR, not a tool to build the world brain with the Zeitgeist Hive.
↺ 1

Thread of 2 tweets

Replying to @TzviyaSiegman and @danbri

Oh, I meant to add that I've heard a few people saying good things about @paperpile. Their assertion that they're "Gmail for papers" has stopped me so far since I can't think of a shittier UI than Gmail, but I think I'll give it a shot at some point.

Replying to @danbri and @TzviyaSiegman, @LibraryThing

What we're most missing is a way to get all these tools talking to each other. I've been thinking about building some kind of hub tool that would move notes, annotations, papers, etc. across tools, make it all linkable.
The problem is that you need some kind of universal model in the middle that can handle the power. Otherwise it's like pandoc where it's lossy in every direction. I'm afraid that the answer might be JATS. Or JATS4R. I'm serious.
↺ 1

Thread of 2 tweets

Replying to @danbri and @TzviyaSiegman, @LibraryThing

The trick might be not to sync. Or rarely, only as import. But instead have the hub enable linkability for all these sources, to make it easy to refer or paste across the board. As reference manager, but also for related products.
Eg. I often outline in Roam and when it's close enough I move to GDocs. But pasting from one to the other has a million bugs. I want to do that easily, turning bullets to grafs, and also adding a link Roam-side to the GDoc.

Thread of 3 tweets

Replying to @danbri and @TzviyaSiegman, @LibraryThing

Citations are only really gnarly if you care about formatting. It's possible to make a decent data model for it. Also, it's about fucking time people got over themselves with citation styles. And with including city of publication but no URL.

Replying to @danbri and @TzviyaSiegman, @LibraryThing

Agreed. Well. I think that sounds like a plan 😁

Replying to @danbri and @TzviyaSiegman, @LibraryThing

People should just be cited by their ORCID🔥

Replying to @danbri and @TzviyaSiegman, @LibraryThing

Lol. Well, either someone makes a prototype or we talk about it again five years from now. What's easy enough, local but with online sync, and good for querying these days? Pouch? Is there a graph thing?

Replying to @danbri and @TzviyaSiegman, @LibraryThing, @Pinboard

Oh, I would be happy with something on the fs, it's what I would build for myself. I got a sense you'd want more but I can start from that!
I have to say that matches my personal experience. With the other monopolies, in private, you often hear "sure, we're trying to make more money." With Google it's more often "Not at all! Wrong impression dude! We're here to help, it's conspiracy theory to think otherwise!"
Quoting a tweet by @matthewstoller ↗
We know the effects of the press dying out on the health of democracy already. We could then tie the two together. Anyone noticed some problems with democracy recently?
↺ 3
Anyway, next time I hear that AMP or Web Bundles or Google Ads are there "to support publishers" I expect an explanation for these margins attached to it.
↺ 2

Thread of 3 tweets

I believe that platforms are behaving as proto-states. Not in a metaphorical sense: in the very concrete sense of control through and from legibility, as in 'Seeing Like A State'. This could emerge because cyberspace has actually been something of a new *space*.
If monopoly engineers sometimes feel like bureaucrats, with grand theories that make no sense to developers on the ground and imaginary enemies (which they can see through "the data") it's simply because they are. Bureaucrat/priests of the Empire.
Now, this could possibly work if folks at the monopolies saw it that way and handled it accordingly (ie. not by reading about Roman emperors or Alexander the Great). They could build relationships by acting in a way that makes sense to other states. And win.
These days, states are generally OK with other states. They hang out. They commerce. That is, until you fuck with Australia. You don't get to fuck with Australia. If you do, you make it clear that you could fuck with many of the other states, too.

Thread of 6 tweets

Replying to @jsalsman

And that could be fine, if it were in a fair fight.

Replying to @null and @funnymonkey

It's for the good of the peas- err publishers!
Thiiiiiiis.
Quoting a tweet by @jason_kint ↗
↺ 3
It's good to see that there were some inside Google who knew Chrome was cheating its way to the top. The web has been gravely harmed by their not being listened to.
Quoting a tweet by @jason_kint ↗
↺ 10

Replying to @jsalsman and @jayrosen_nyu

I said "could", not "would". If they were to get there in a fair fight, they would likely have to provide a fair alternative. There may well be a better model for news than what we have, and it could drive us all out of business. It's clearly not those guys, though!

Replying to @kingjen

I assume you're more articulate than me about it?
Socially distanced, but still one hell of a data governance team made up of amazing people. ♥ #PrivatelyYours
↺ 1
I'd save a lot of time if I could have this on a t-shirt.
Quoting a tweet by @JInterlandi ↗

Replying to @swodinsky and @byjacobward, @David_Ingram

I really don't see what is hard about splitting up FB and Insta. The complicated backend story, I really fail to see the engineering reason for it?

Replying to @swodinsky and @byjacobward, @David_Ingram

But, much more importantly, it shouldn't be the government doing the work for companies to figure out how not to break the law. The government sets the rules, the companies work out how to abide.

Thread of 2 tweets

Replying to @swodinsky and @byjacobward, @David_Ingram

Oh, sure, I just... don't see why anyone would care about their whining?

Replying to @swodinsky and @byjacobward, @David_Ingram

There's a French expression for this I wish I knew an equivalent for. "Les cons, ça ose tout, c'est même à ça qu'on les reconnaît."

Replying to @JInterlandi

It's a public service you're rendering here for the rest of us.
A quality tweet inside of just the kind of thread that twitter dot com was invented for.
Quoting a tweet by @SarahJamieLewis ↗
People the world around increasingly have privacy rights. But these rights are often made to be hard work: you have to exercise them on every site, and they are often hidden complex settings, "consent management platforms," or "privacy check-ups." This changes today.
↺ 21
Today we announce the Global Privacy Control, or GPC. GPC is a signal that enables your browser to work for you, telling sites that you do not want your data to be sold. The browser's job is to be the user's agent. This empowers browsers to work better. globalprivacycontrol.org
↺ 37
The signal is designed to be legally enforceable under the CCPA, the GDPR, and other similar regimes. This is not a toothless preference: it's an expression of legal rights. You can think of it as DNT, except there are fines if you don't abide by it.
↺ 4

Read the whole thread: 7 tweets →

Replying to @AdaRoseCannon and @Lady_Ada_King, @thisNatasha

Thank you 🤗

Replying to @liorjs

Thanks Lior!

Replying to @anssik

We’re fine-tuning the level of openness given how aggressive the trolls can be in this space. Filed: github.com/globalprivacyc…

Replying to @yoavweiss and @anssik

Filed this on your behalf! github.com/globalprivacyc… GPC is designed to be legally enforceable; DNT existed in murkier times that made that difficult.

Replying to @mkraetke

No, this is incorrect. GPC is deliberately designed not to intersect with cookie consent. Cookie consent is checklist compliance nonsense that has never helped anyone’s privacy. GPC is meant to prevent data sales (ie. multiple controllers). It removes consent to sale.
Collaborating to make the Web better feels retro. We should bring it back in style.
Quoting a tweet by @GiladEdelman ↗

Replying to @null and @icopilots

Fingers crossed that it works!

Replying to @EivindArvesen

Too much baggage and not necessarily designed in a way that binds to the legal infrastructure very well. We could have kept the name and header, but most of the rest would have had to be rewritten. It would have been confusing, too.

Replying to @ashk4n and @GiladEdelman, @yegg, @jonathanmayer, @random_walker, @harlanyu

I still have my TPAC shirt that had a Unicode error on it, from back when that was a thing that happened. We could put together a fashion line.

Replying to @tomhaley

That’s what the law is for.

Replying to @heycori

In truth, it probably doesn’t, at least not so long as the absurd requirements for cookie consent persist. But the hope with GPC is that you can click Accept and then have your browser reject all sharing of data to other controllers.

Replying to @vincib

Because everything is about valuing your privacy and offering you “transparency & control,” unless it actually works at which point it is “destroying the business model of the internet.” 🤦‍♂️ DNT was asking nicely; GPC isn’t asking, it’s expressing a legal right.
↺ 1

Replying to @JeremiahLee and @GiladEdelman

I’m not sure who is still unclear about the meaning of sale in the CCPA, especially after the regs. I’m also not sure how expressing a right would relate to some “permissions to opt-out”?
Incredibly proud that The Times would get mentioned by the CA AG in such good company!
Quoting a tweet by @AGBecerra ↗
↺ 5

Replying to @vincib

Hahaha, oh, I agree — but DNT is considered dead and I doubt that a DPA would require its enforcement at this stage. And DNT was pretty much dead by the time the GDPR came into effect. There was a timing issue.

Replying to @Nihiel

GPC isn’t about consent (unlike DNT which did have that notion). The CCPA (& regs) specifically calls for this. Also, there is nothing “generic” about GPC. It’s an assertion that’s made with *every* request. For GDPR, as explained in the spec, it’s an invocation of Art 7 & 21.

Replying to @null and @funnymonkey

Like this?

Replying to an earlier tweet of mine

The signal is designed to be legally enforceable under the CCPA, the GDPR, and other similar regimes. This is not a toothless preference: it's an expression of legal rights. You can think of it as DNT, except there are fines if you don't abide by it.
↺ 4

Replying to @nataliabielova and @ashk4n, @lukOlejnik

The spec is clear that the scope is meant to include the GDPR. globalprivacycontrol.github.io/gpc-spec/#lega…
↺ 1

Replying to @Nihiel

As per GPC, “This request is expressed with every interaction that the user agent has with the server.” Whatever consent you get from an earlier interaction, if it involves sharing to another data controller then GPC is expressing Art 7 withdrawal of that consent.
If someone designs garners consent that is specific to an interaction (eg. in submitting a form) then that can override the GPC. Otherwise there is no reason why a withdrawal of consent expressed later and more specifically than the gathering of consent would not take precedence.

Thread of 2 tweets

Replying to @publictorsten

It conveys, specifically with every request, a general request to not share to other data controllers. If you are doing that under consent, it withdraws it (Art 7); if under LI it objects (Art. 21).

Replying to @nataliabielova

Sorry, why would you say it’s not meant to refuse consent and not meant to object to LI? It *specifically* cites articles 7 and 21 right there!

Replying to @Paul__Walsh

Thank you! We’re discussing it with the Privacy CG this Thursday (or at least as soon as it fits in the agenda). I hope the CG takes it, if so that will be the best place to get involved.

Replying to @Nihiel

I think it would be better to have that discussion with DPAs before having it in court :)

Replying to @nataliabielova

See my response there! :)

Replying to @othermaciej

We’re not opposed to browser support ;-)

Replying to @publictorsten

Because it’s the law? But also if it does become a standard, is supported widely enough, etc. Several publishers (us included) and browsers already support it as is.

Replying to @podehaye and @nataliabielova, @ashk4n, @lukOlejnik

Some have, yes, but more can. And keep in mind that it’s a draft — if there are better ways to make it stick, then lets. Failing that, ePR?

Replying to @nataliabielova

Sure — this is specifically designed not to do anything about cookie consent. It focuses on addressing the multiple controller issue which is much more useful.

Replying to @publictorsten

The FT’s in :) Also, we’re a European publisher, too!

Replying to @tim_libert

Tim…

Replying to @podehaye and @nataliabielova, @ashk4n, @lukOlejnik

Of which outcome?

Replying to @coolharsh55 and @podehaye, @nataliabielova, @ashk4n, @lukOlejnik

My understanding is that Art 25 is hard to use for anything much. But I’d love to be wrong! I’ve been wondering what to do with Art 40 for years, and I had publishers in mind. But… are you thinking of a CoC for the Web? That… that would actually be interesting.

Replying to @nataliabielova

CMPs gather consent for multiple things. One of those things is ePD cookie consent; a lot of it is sharing data to other controllers. It solves the latter, because that’s needed to support user privacy. The only way to get rid of cookie consent is to stop requiring it.
↺ 1
So indeed it can’t solve the problem of cookie consent — that said if all you’re doing is cookie consent then you don’t need a CMP. (We don’t have one.) Your original statement was that it doesn’t “refuse consent” and “is not meant to object to LI.” It clearly does both!

Thread of 2 tweets

Replying to @tim_libert

Oh yeah.

Replying to @tim_libert and @lorrietweet, @WIRED

I certainly won’t dispute that.

Replying to @coolharsh55 and @nataliabielova

With my European hat on , I certainly don’t think that CI is USA-centric. More generally, I don’t find the nationalistic lens to ever be helpful in these debates, no matter how often it comes up.
There is certainly a tie-in to the CCPA notion of sale. Single controllership is, IMHO, a decent approximation to that. Controller to controller processing can be objected to using 7 or 21, depending on the legal basis. It’s what the spec suggests.

Thread of 2 tweets

Replying to @coolharsh55 and @nataliabielova

And the reason it does not outright say so is so that constructive discussions could take place to help move this forward. The intent, however, is clearly there. Also, I don’t think it’s about third parties — you need a legal basis for the processing that involves further ctrls.

Replying to @JeremiahLee and @GiladEdelman

I have yet to meet a user who actually wants to decline one third party but not another.

Replying to @coolharsh55 and @nataliabielova

That’s why both 7 and 21 are mentioned — to cover both consent and LI.

Replying to @coolharsh55 and @nataliabielova

Haha, that’s okay, I wanted a better name, but apparently the names I like aren’t serious :) GPC/GCS/whatever expresses a withdrawal of consent to sharing data to other controllers.

Replying to @coolharsh55 and @nataliabielova

Sorry — hit send too fast. And that right is expressed with every request.

Replying to @coolharsh55 and @nataliabielova

Sorry, let me rephrase that because I’m contradicting myself & unclear — I don’t think it hinges on a definition of “third party” that would exclude FashionID-style controller setup. Under DNT definitions, which we should bring in, that’s a third party.
I understand the sensitivities around “user” but in a web standard context the browser is the “user agent”. The “user” is the individual using the browser. I know it’s not perfect but in this context I think it has to clearly bind to the person the browser is the agent of.

Thread of 2 tweets

Replying to @coolharsh55 and @nataliabielova

Sure — there are ways folks’ll to either game this or shoot it down. Binding tech to policy & making it work worldwide is hard. But 1) browsers should help solve this, and 2) we can’t have per-geo standards. If you have better ideas to make this work, they’re *very* welcome!

Replying to @coolharsh55 and @nataliabielova

The problem is whose: legal terms? This is Draft Zero, so it will be iterated upon. I think it should have general terminology binding to the tech side, and then dedicated sections per jurisdiction. But for the first draft, it’s better to be high level than wrong.
I would expect one important next step to be discussions with relevant authorities to see how to make sure it works. In CA it’s pretty straightforward; but it’s a failure if that’s the only place it works.

Thread of 2 tweets

Replying to @podehaye and @coolharsh55, @nataliabielova, @ashk4n, @lukOlejnik

I’d love to hear more.

Replying to @recifs

Non! C’est le fait que ça soit conçu pour s’articuler avec un environnement légal qui compte!

Replying to @recifs

DNT a un ACK!

Replying to @coolharsh55 and @nataliabielova

This has been discussed quite a lot before. I have yet to see a proposal that works but if you have something more detailed I’d be super interested. The whole issue with consent is that it offloads the problem to the UI; and that’s even harder.

Replying to @coolharsh55 and @nataliabielova

Yeah, but I think we need a lot more than just that, no?

Replying to @podehaye and @coolharsh55, @nataliabielova, @ashk4n, @lukOlejnik

Hahahahahaha. Oh, that would be *fun*.

Replying to @podehaye and @coolharsh55, @nataliabielova, @ashk4n, @lukOlejnik

You made it very tempting to tempt you...

Replying to @recifs

Oui c'est assez bien résumé!

Replying to @csarven

Ya, going to discuss it at the next Privacy CG.

Replying to @podehaye and @coolharsh55, @nataliabielova, @ashk4n, @lukOlejnik

Possibly best if not 😂

Replying to @peterlern

Thanks Peter!

Replying to @kyotonio

Yeah, been meaning to fix this but forgot to file it. Will get to it ASAP!
Got to give it to Facebook, just when you think they can't make worse decisions...
Quoting a tweet by @wiczipedia ↗
↺ 1

Replying to @deaneckles

There are quite a few problems with policing political advertising, yes, but if you're going to shut it down because you think it's a problem maybe do that *before* the election?

Replying to @coolharsh55 and @nataliabielova

Well, for one the TPE spec is abandoned and the group disbanded. It's harder to claim that it has a pulse and should be abided by.

Replying to @coolharsh55 and @nataliabielova

I think the explicit/automatic distinction is probably the wrong one, we need to think in terms of agents (which is what browsers are intended to be). The point of tech is to do things for people. I have a write-up of the precedence model, I'll find and share.

Replying to @coolharsh55 and @nataliabielova

So (trying to understand how this works, sorry if slow): when a site obtains consent, it would do so in its own (possibly bad) UI, but it would be required to store that consent with the browser, I assume with 1) a description of what is being consented to, 2) a unique ID, and…
…3) a source domain? And then the user could consult the list of what they’ve consented to, and withdraw consent by hitting a button that would call a .well-know in that domain with the unique ID?

Thread of 2 tweets

Replying to @coolharsh55 and @nataliabielova

I know, but this isn’t unique to TPE or GPC. Standards always have a complicated initial adoption dance. Support from large implementers out of the gate (publishers, browsers, extensions) is one step. Having it enforced in some jurisdictions is another.

Thread of 2 tweets

The coat of arms of Bermuda feature the motto “Quo Fata Ferunt,” which means “Whither The Fates Carry Us.” Bermuda’s Privacy Commissioner’s office has as its motto “Quo Data Ferunt” and this is the best thing. privacy.bm

Replying to @coolharsh55 and @nataliabielova

As a rule, one thing that worries me with that type of “give the user power” proposal is that it ends up being “make the user do the work.” It’s like Chrome’s same-site cookies idea: you can go delete tracking cookies and log-in ones. Cool but: who does that?
Put differently: how do you avoid that becoming AdChoices in the browser? One value I see is that, with machine-readable consent info, you could automate consent removal and have the browser withdraw consent for you on a regular basis by calling all those .well-knowns.

Thread of 3 tweets

Replying to @coolharsh55 and @nataliabielova

Yes — some of the earlier drafts had much stronger legal language, but it seems better to iterate towards that in public with expert involvement than to get it wrong out of the gate.
Can we, as a global civilisation, agree that we just won’t be using Microsoft Teams? I mean, half the time all it does is spin without launching. That’s the better half: the rest of the time it will drive you through insane login flows and change your Skype ID for no reason.
↺ 1

Replying to @blogisch

Yup. Across all the orgs that I interact with, I get to use pretty much every system from Zoom to Whereby. They all have pros and cons, but Teams is consistently a terrible experience, when it even works.

Replying to @blogisch

I think in part it’s getting confused because we have Azure login but the Team I’m in on Teams is not NYT. But more generally, most of the time it doesn’t bother starting. Someone else here just gets weird graphics card noise from it. Maybe it’s better on Windows?

Replying to @coolharsh55 and @nataliabielova

Yes yes, I can see the value in having a paper trail. I’ve been thinking about whether it would be possible to get paper trails for more than just consent. Eg. including unique IDs and which processing took place under what basis. No reason to just have consent!

Replying to @blogisch

I should probably try to use it in the browser instead of the app, that’s a good point. I can even use it in Edge!

Replying to @coolharsh55 and @nataliabielova

I mean, giving consent in the first place, no objection there! The degree to which adtech people are smoking consent, even the nice ones who’d like to make things better, is just insane. I think we should: • Forget local storage consent …
… • Outlaw consent involving controllers other than the first party that cover more than one interaction (so you could consent to sharing data through a form, eg. for medical cases). …

Thread of 3 tweets

Replying to @willseth

Honestly I think I’m confused for life.

Replying to @chaals

It’s not dead, and it’s legally enforceable.

Replying to @AmeliasBrain and @chaals

Noooooooooo. This is unrelated to cookie consent. It says so in the spec. This is to enforce single controllership. I think that DNT could have met those needs, but it wasn’t defined in a way that ties well with legislation that came after it and retrofitting didn’t work well.

Replying to @publictorsten and @lukOlejnik, @nataliabielova, @ashk4n

TPE is what people who were involved in DNT call DNT :)

Replying to @AmeliasBrain and @chaals

Ha, that’s totally right! But there isn’t a technical fix for cookie consent, the fix is convincing regulators and requiring antipatterns is a bad idea. But GPC can fix some of the rest!

Replying to @ashk4n and @publictorsten, @lukOlejnik, @nataliabielova

See? You should’ve let me call it the Preference for Interactive Multimedia Privacy.

Replying to @mkraetke

I can only hope that there’s some kind of afterlife in which you will be compensated for your suffering.

Replying to @kevinriggle and @Chronotope, @vincib

This is deliberately designed not to intersect with cookie consent. Cookie consent is a privacy antipattern, I don’t think there’s a solution for it.
↺ 1

Replying to @coolharsh55 and @ashk4n, @publictorsten, @lukOlejnik, @nataliabielova

When this is all over, Ashkan will shame me by publishing the full list of names I proposed.

Replying to @kevinriggle and @Chronotope, @vincib

Cookie consent guidelines are designed too poorly for us to be able to do much about them. But yes, it does apply to consent to other processing.

Replying to @kevinriggle and @Chronotope, @vincib

Any controller to controller processing is in scope, so the answer is many.

Replying to @kevinriggle and @Chronotope, @vincib

It’s harder to ignore when it’s the law.

Replying to @ashk4n and @coolharsh55, @publictorsten, @lukOlejnik, @nataliabielova, @hober

will be sad when she hears about this one.

Replying to @kevinriggle and @Chronotope, @vincib

It actually doesn't, because it includes consent as a loophole.

Replying to @kevinriggle and @Chronotope, @vincib

That depends where, but in Europe yes.

Replying to @hober and @ashk4n, @coolharsh55, @publictorsten, @lukOlejnik, @nataliabielova

That's the way to deal with CMPs.

Replying to @tobie

It reminds me of those video games where you get stuck because you can't find the right clue. Except there's no cheat code.

Replying to @kevinriggle and @Chronotope, @vincib

In California you’ll also get that experience if you have DNT on.

Replying to @kevinriggle and @Chronotope, @vincib

Actually, in GDPR jurisdictions most data sharing to other controllers is done by consent.

Replying to @kevinriggle and @Chronotope, @vincib

Well, the whole ad and marketing ecosystem works like that, for instance.

Replying to @bendrath and @nataliabielova, @ashk4n, @lukOlejnik

Yes, I initially cited that but I was concerned that it is (weirdly) in Art 21 and so applies to LI and PI legal bases but not to withdrawal of consent.

Replying to @_SarahGailey and @gaileyfrey, @laurie_winkless

Hahaha, oh dear, I don't even have a word for how thoroughly French this is. Thank you 🤗

Replying to @bendrath and @nataliabielova, @ashk4n, @lukOlejnik

I understand the withdraw/object distinction and it makes sense since they work in different ways (notably in how absolute they are). But what I find weird is why Art7 doesn't have an equivalent automated means comment (or better still, an article stating that generally).
Having said that, I don't see what logic would drive refusing to honour a request made by a user agent. The user agent represents the user.

Thread of 2 tweets

Replying to @floorter and @nataliabielova, @bendrath, @ashk4n, @lukOlejnik

I think those two problems have to be kept separate. Cleaning local storage isn't automation. I agree that it shouldn't work, it's like breaking a contract by just burning your own copy — the other party needs to be told!

Replying to @nataliabielova and @bendrath, @mikarv, @ashk4n, @lukOlejnik

Or, put differently, automation doesn't mean that the human is out of the loop. The UA is supposed to work *for* the user, it would be a huge loss if the GDPR didn't permit that. If we had machine-readable consent descriptions, I don't see why they couldn't be "automated".
If I tell my browser "I always trust @mikarv to process my data" or "I consent to anyone processing my data for the purpose of making kittens happy" then I don't see why the browser automatically signalling that would be invalid consent.

Thread of 2 tweets

Replying to @csarven

I don't think so? I think that binding has to be outside?

Replying to @mariafarrell and @kkomaitis, @1Br0wn, @raycorrigan, @suzworldwide, @SullivanISOC, @etaylaw, @natural20, @dml, @Des

Ooooh, it does! Thank you! But... we can't get it 😱

Replying to @mikarv and @nataliabielova, @bendrath, @ashk4n, @lukOlejnik

Of course. I mean, those problems already exist with CMP consent. If invalid consent is possible and there is no enforcement against it, then the door is open to being in 2020 and RTB is still happening…

Replying to @mikarv and @nataliabielova, @bendrath, @ashk4n, @lukOlejnik

More generally when it comes to user agents, I feel there is too little guidance and investigation into their behaviour. How and when they could possible mediate consent and its withdrawal is one question. How & when they act as data controllers and need a legal basis is another.

Replying to @lukOlejnik and @mikarv, @nataliabielova, @bendrath, @ashk4n

I mean, the “gatekeeper” framing is definitely the wrong one. The only people I know with that framing are in adtech, where they see it as what prevents them from accessing the user’s data, to which they have inalienable rights.

Thread of 2 tweets

Replying to @e2dot7182818284 and @EuphoricEuler, @Noahpinion

Alas, no, this does not solve cookie consent. This solves deeper privacy issues. Alas cookie consent does not have a technical fix. Cookie consent is an antipattern that does almost nothing for privacy, but regulators insist on it for unclear reasons.

Replying to @juliareinstein and @lastpositivist

This is genius.
I have to say I’m impressed with Twitter’s work on trying to bring genuine change to social media governance. Elections are almost certainly a major growth driver for them, and their willingness to forgo some of that to do the right thing is commendable.
Quoting a tweet by @kateconger ↗
↺ 3
J'ai pas trouvé la page "Covid-19", je pense que ça mérite une mise à jour d'urgence de la part de l'éditeur.
↺ 2

Thread of 2 tweets

The scary thing is that as I now have my library close to my desk I've started doing this in Zoom meetings.
Quoting a tweet by @ryancordell ↗
↺ 1

Replying to @doriantaylor

Non, mais on devrait!

Replying to @swodinsky

I should've gone with "DNT, revisited" for GPC. Damn.

Replying to @iantuck and @doctorow

Thanks!

Replying to @null and @benlikestocode

Now I need to know who and what book! 😁

Replying to @null and @ManohlaDargis

My first thought was that I want that coat but now I'm really wondering how you put that hair together in the morning.

Replying to @CivArchive

Early days. They haven't spoken either way.

Replying to @CivArchive

I think it's more complicated than that. Chrome has been saying that they care about privacy now. This would be a good way to show it. Google has other ways of getting the data, this plugs one but we need to plug more. So they might be OK with losing one.

Replying to @CivArchive

Yes, I think we can and should increase the requirements placed on browsers. And the terms they use through forced consent in the creation of child accounts are clearly abusive.

Replying to @rigow and @nytimes

It reminds me that I had meant to write something about Samsung Internet but then I forgot! @torgo what would be good there? Mentioning the privacy protection that's easy to turn on?
The Web has become dominated by proprietary aggregation technologies: AMP, Apple News Format, Facebook Instant Articles, MIP, and now Web Bundles. These formats cater to the needs of large platforms; not users, not publishers. It’s unsustainable. We need to change this.
↺ 111
I’m delighted to announce the first draft of Content Aggregation Technology, or CAT: nytimes.github.io/std-cat/. CAT offers: 1. An open door to working through consensus. 2. A framework to assess aggregation tech. 3. Some requirements for better aggregation.
↺ 28
Why consensus? The proprietary formats are being imposed unilaterally by leveraging dominance, eg. through a search engine, a device, a browser. Instead of using power to force people to use a format, we want to build it together, for everyone — the way the Web was built.
↺ 4
Why a framework to assess the tech? Because even if it feels meta, it’s important to capture the perception of the people who actually end up having to deal with this tech. This makes the view from the trenches harder to ignore.
↺ 2
And the requirements? Well, it turns out that the Web already has an amazing foundation for aggregation: it’s called hypertext. Unless you want to dominate the Web there’s no reason to go against it! Some small additions are all we need to make kick-ass Web experiences awesomer.
↺ 5

Thread of 6 tweets

Replying to @nsatragno

I am keenly aware :) Though in fairness, all we have are proprietary hacks and no standard!

Replying to @null and @dauwhe, @wicg_

If you think there’s potential for convergence I would love to look into it!

Replying to @nsatragno

Sure, but that’s not enough to make it non-proprietary ;)

Replying to @null and @nhoizey

Thanks! Let’s see if it’s still possible to have an impact or if the platforms have power over everything!

Replying to @null and @nhoizey

I stole that trick from @LeaVerou! globalprivacycontrol.github.io/gpc-spec/ has one too.

Replying to @rowan_m

Yes, the draft is public, we’ll put the repo with the WICG if folks there want it.

Replying to @JonFerraiolo and @wicg_

It could be interesting but there are some concerns about what it reveals. Say, if google.com embeds nytimes.com without user action, that reveals to the NYT what your searches are. Also, so far the embed approaches have tended to favour the powerful.

Replying to @yoavweiss

Ah, I’m out of practice! Which is the template you prefer? Easy switch.

Replying to @adrjeffries

I didn’t reach out to @themarkup because my understanding is you’re not on AMP (or any of the other things), but it should go without saying that if anyone there is in support it’s great!

Replying to @Saphyel

Except there are no standards right now.

Replying to @SamMorrisDesign

Imagine that! It’s not just cost, it’s control too. When you put content inside a bundle you make it easy to control. These formats are a tool to make our content easier to control by the platforms.

Replying to @imperez

Thanks! Ideas are very welcome, we’ll take all the help we can get.

Replying to @SamMorrisDesign and @adrjeffries, @themarkup

These are hard discussions. We have similar issues, as you can guess — and that’s despite having a very sizeable tech team. That independent news orgs could be bullied into AMP (and can barely mount a defence against Web Bundles) is a clear indicator of where democracy’s at.

Replying to @adambroach and @wicg_

Yes — I think that should be part of the solution!

Replying to @JonFerraiolo and @wicg_

No no — I understand. But it’s hard to make that happen without there being information leakage.

Replying to @yoavweiss

I’m not sure ReSpec should be the arbiter here, those docs are probably whatever went through my mind in 2009 :-D But I’ll get around to changing that later if you think that’s best for WICG.

Replying to @null and @kierandelaney, @imperez

Thanks, I appreciate that, but the issue isn’t the automation. We have an awesome tech team and we can solve those problems. The issues are over control, market power, and privacy. Unfortunately, there’s no amount of automation that can fix that!

Replying to @yoavweiss and @marcosc

He says that, but we all know he just hangs by the pool with margaritas. I’ll change it when I’m next in the repo, which should be soon. It would be good if we had a “proposal” style, like member submissions but updated for the 21st century.

Replying to @b0neskull and @Rich_Harris

Yeah, I think we’ll add it at some point.

Replying to @jeffjarvis

The people who have you add crap and the people who then tell you you have to use things like AMP are often the same people, for some reason.
↺ 1

Replying to @jeffjarvis

I don’t think coyness is what I’m most reputed for!

Replying to @saleemkhan

It might still be crazy 😁

Replying to @hiimmrdave

Same answer as for the ten other people with the same joke: there is no standard.

Replying to @hiimmrdave

Thank you!

Replying to @mnot

Consider yourself lucky! I have a million internal services on autocomplete before the real thing, and the worst part is I often go there by mistake then get confused.

Replying to @CT_Bergstrom

This is democracy in the exact same way that privacy policies are transparency. A token, with no substance. Also, it's funny how not all democracies have this problem. Maybe there's a reason?
The longest I've ever waited to vote in a French election was maybe 30min? The lines were long but they were efficiently organised. Difficult? You put the paper with the name you want in an envelope and turn it in.
Quoting a tweet by @BrandonTozzo ↗

Replying to @frivoal

Yes, working on it but it might take longer than I'd wish. Maybe comment on the thread in the meantime?

Replying to @othermaciej

That's always the hardest part!

Replying to @lilianedwards

It has legal teeth, and the timing is right.

Replying to @null and @why0hy

If an entity gives your data to Facebook (for some value) and Facebook can do as it pleases with it, then they're selling to Facebook. That's ruled out.

Replying to @lilianedwards

You mean beyond the ones listed in the spec?

Replying to @null and @why0hy

There is no tech fix for those, you need legislation.

Replying to @lilianedwards

No worries! We kept it relatively high level while discussion is going on, but I think it gives the idea.

Replying to @null and @why0hy

You mean first party?

Replying to @espadrine

They still have that thing, I think. It could be interesting for Scroll, too. I wonder how to make them work without tracking.

Replying to @null and @why0hy

That's my endgame, eventually, but we don't yet have a good definition of what "unnecessary" is. Working on that.

Replying to @davemolloy and @RobDonohoe

Yeah. There are no standards now.

Replying to @gsnedders

It's going to the Privacy CG!

Replying to @base2john and @justinph

Thanks! Come work with us on it!

Replying to @null and @why0hy

Thank you!

Replying to @tabatkins and @bfgeek, @frivoal

Yeah, not sure what anyone would be confused about but I'll look at switching the template when I get back from vacation.
Crossing into a battleground state is a whole different experience.

Replying to @null and @amyvdh

The blend is weird, too. Black families for Trump, Christian Republican women for Biden...

Replying to @lutherlowe and @daiwaka, @davidcicilline

My understanding is that privilege is not automatic, though. If this is deliberately used to cover up misdeeds more often than to seek counsel, could there not be a case that they are all eligible for discovery?

Replying to @null and @amyvdh

Yeah, it feels like really weird targeting. Maybe to convince white families that voting Trump isn't racist?

Replying to @bfgeek and @tabatkins, @frivoal

The set of people who get spec status know what this is and aren't confused. The set of people who don't know there are spec statuses don't risk being confused. So doesn't seem like a big problem? As I said, if it appeases the gods of bureaucracy I'll get to it.

Replying to @AmeliasBrain and @tabatkins, @bfgeek, @frivoal

There's nothing unofficial about needing to fix this mess, though!
It's very interesting to read Dave's analysis here. What he's seen Amazon do to books, Google has done to news (and the web at large). In both cases we are seeing monopolies (ab)use the structure of technology to outcompete pillars of democracy while offering no replacement. t.co/LgJonoRRGN
↺ 17
Good institutions are strong and maintain checks and balances even when those in power lack a sense of ethics. The question before us is: how do we make the web a good institution that it currently isn't? I hope CAT can contribute to an answer.
↺ 1

Thread of 2 tweets

Replying to @alextcone

That feels stressful! It's also not a great time for that, in several ways!

Replying to @RobinvanBeauDow and @RobinCRLee

Thankfully!
I love the thinking in this piece (and Fort Greene Park is the best park). I don't think that building public spaces on the Internet need be that expensive though. It's mostly a failure of imagination, forgetting that tech can be about building a better world for people.
Quoting a tweet by @elipariser ↗

Replying to @null and @dauwhe

Weaponising the user is key to legitimacy indeed! And legibility is needed for power at scale... It's a cluster of views that feels just like a resurgence of high modernism, especially the cybernetic branch of it in the USSR.
The great thing with high modernism is that since it places no value in learning from history, you can keep reinventing it! I mean we're still fixing the fallout from the previous wave.

Thread of 3 tweets

Boromir, have you been reading philosophy again?

Replying to @knowtheory and @jkohlmann

Yes, that's what we're looking at, basically. Thankfully, we don't have to reinvent HTML. Also, things have become bad enough that we do have a shot at reshaping some pretty bad parts. But it's still a hell of a play.
↺ 1

Replying to @DoraCrisan

I'm not saying that we need to weaponise the user, I'm saying that users have been weaponised.
I find it reassuring that a few others too remember the Internet from before Gibsonian technocracies took over, back when we were naive about institutions and power. t.co/0yqFUCX9ra
↺ 1

Replying to @clancynewyork

Is it just me being somewhat confused and hesitant about Twitter's new game as the responsible social media? I'm torn between "still far short of the mark" and "hell, at least they seem to be damning some torpedoes and heading in the right direction".

Replying to @clancynewyork

I saw that! 😄 I think that part of what's confusing to me is that when they're not trying I don't mind dishing out searing criticism, but if they're indeed trying but get some stuff wrong (as has to happen) it feels like it should be a conversation?

Replying to @clancynewyork

Right. The question is how, though!
(And I also work for a powerful org that regularly gets things wrong, and while it's not my area I do see smart people striving to get this kind of communication right and it's not something that feels figured out yet.)

Thread of 2 tweets

Replying to @clancynewyork

Tech companies are looking for leaders rather than institutions (following the distinction that Popper makes). So yeah, you kind of need access to the Philosopher King to get heard. It's wrong, but it's the entire founder mythology.

Replying to @clancynewyork

Heh, I think that's a very good description of what it feels like to work there too 😁

Replying to @null and @SimonDeDeo

Dan Aykroyd has my "debugging some Perl 4" face.
Nice mention of CAT from @protocol: “A new old proposal for the web” protocol.com/newsletters/so…
One of the most innovative outlets in journalism today — @TheMarkup — is looking for a Director of Product. I don’t think there are many places where you’ll have more fun *and* make greater impact. If you’re good at products, take a look! boards.greenhouse.io/themarkup/jobs…
↺ 6
First, it’s good for people. The TCF was designed to support the existing status quo in real-time bidding (RTB). RTB is a data free-for-all that operates with complete disregard for the safety and privacy of individuals. We can fix this! But this requires putting people first.
↺ 2
Second, it’s good for publishers. Broadcasting personal data also means broadcasting audience data. In turn, this leads to devalued audiences and lower revenue since the adtech companies in the RTB system can target high-value news audiences without paying news outlets.
↺ 2

Read the whole thread: 9 tweets →

I can confirm that this is a really cool project — watch this space!
Quoting a tweet by @JuliaAngwin ↗
↺ 1
Fun fact: participating in standards is 10% inspiration, 90% telling people they don’t need a version indicator in their format.
↺ 3

Replying to @mnot

Haha — I’d wager you need a header more often than you need a version signal though!

Replying to @mnot

AAAAAAUUGH MY EEEEEEEEEEYEEEEEEEEEES
Hey — but what if you change your versioning strategy from numbers to letters. Wouldn’t it be better to version your version indicator to make it forward compatible too? <insert meme>
Quoting a tweet by @mnot ↗

Replying to @null and @SoSillyDaddy1

In fairness, a version indicator is sometimes useful.

Replying to @wayneblodwell

News audiences are valuable, they are generally more affluent, more educated, higher WTP, etc. I think that’s pretty well established?

Replying to @docum3nt

LOL! Not even :-D

Replying to @wayneblodwell

Market alignment is a separate issue to me. Whatever the agreed-upon value, the important thing is that news audiences don’t get targeted as such elsewhere and that publisher get the money from their work in developing an audience.

Replying to @wayneblodwell

Scarcity increases price, if the only way to reach a NYT audience is with the NYT it’ll fetch closer to its actual value than if the same audience can be reached in less premium contexts. Context matters, so it won’t level — but it’ll drive the price down.

Replying to @wayneblodwell

Only if people can be recognised between different contexts, which they shouldn’t be.

Replying to @wayneblodwell

And if you trust Facebook.

Replying to @Cennydd and @ChrisGeison, @baxterkb, @daniellecass, @emilyewitt, @JeneeJernigan, @jdlovejoy, @jessscon, @FilippoCuttica, @gabriellacinque, @ChristineWurth, @ushi_, @mags, @ShannonVallor, @ReidBlackman, @TechEthicist, @SBraziel, @ellecortese, @pnts, @milenapribic, @brookebhawkins, @ninzucchi, @tiffanyxjiang, @ruchowdh

Honoured to be on this list! I completely agree with this thread. I used to care about digital privacy. Now, I have to figure out how to make it work while also supporting a newsroom of 1700 people and in an environment extremely hostile to it.
In many ways, this has made my views *more* radical, even as I lost all patience for the "just remove all trackers" crowd. It may be harder to get there, but it's also more necessary.

Thread of 2 tweets

We keep saying that it's in the nature of social media recommendation algorithms to drive towards inflammatory content, and therefore to support violent fascist posts over honest reality-based ones. It turns out, they just tilted the balance that way on purpose.
Quoting a tweet by @ClaraJeffery ↗
↺ 3

Replying to @tbernard1979

Partage!

Replying to @tbernard1979

Hahaha 😂 Classique de la mauvaise gestion de version, beautiful.

Replying to @tbernard1979

Lol, ça finit toujours comme ça!

Replying to @tiffanyxjiang and @mags, @brookebhawkins, @Cennydd, @ChrisGeison, @baxterkb, @daniellecass, @emilyewitt, @JeneeJernigan, @jdlovejoy, @jessscon, @FilippoCuttica, @gabriellacinque, @ChristineWurth, @ushi_, @ShannonVallor, @ReidBlackman, @TechEthicist, @SBraziel, @ellecortese, @pnts, @milenapribic, @ninzucchi, @ruchowdh

That would be great! I was also thinking that this would be a neat group to read a collection of essays on ethics from the trenches from.

Replying to @temptoetiam

Aaauuugh, putain c'est rude. J'ai corrigé pas de copies de philo de terminale dans des boîtes à bac pour riches neuneus et c'était rarement aussi douloureux.

Replying to @temptoetiam

Tu as du courage d'avoir lu aussi loin! Je n'ai jamais trouvé un nom satisfaisant pour ce genre d'écriture. "Just so" ça couvre en partie, mais là ça va plus loin.

Replying to @null and @JeneeJernigan, @Cennydd, @ellecortese, @brookebhawkins, @tiffanyxjiang, @mags, @ChrisGeison, @baxterkb, @daniellecass, @emilyewitt, @jdlovejoy, @jessscon, @FilippoCuttica, @gabriellacinque, @ChristineWurth, @ushi_, @ShannonVallor, @ReidBlackman, @TechEthicist, @SBraziel, @pnts, @milenapribic, @ninzucchi, @ruchowdh

Is there a good place to set up this kind of small community?
This investigation by @daveyalba and @jacknicas is bonkers. A large network of shadowy local news sites pushing conservative propaganda across the US. "As Local News Dies, a Pay-for-Play Network Rises in Its Place" nyti.ms/349RruY
↺ 10
The @nytimes has a pretty amazing legal team, and they just opened up a spot for an attorney specialised in licensing & tech transactions, as well as privacy & marketing compliance. I get to work with that team a lot, and I highly recommend it. linkedin.com/jobs/view/2209…
↺ 17
Hey, look who’s running an ad campaign on Brave.
↺ 4

Replying to @heydonworks

♥

Replying to @null and @SimonDeDeo

Because everyone sells their labour to the monopolies?

Replying to @dascritch and @ParisWeb, @glazou

Whoa ça commence à faire un bail!
“We don’t have email, but you can fax it over.” Healthcare in the US…
↺ 1

Replying to @null and @funnymonkey

You jest, but they just said we could bring a physical copy.

Replying to @judell

You know, at least that would be honest if bad customer service. But their excuse is that they don’t actually *have* email.

Replying to @null and @virtuous_sloth, @judell

It’s a real thing! You can find it in the PCI standard.

Replying to @docum3nt

Isn’t that for internal things at the NHS, though? In France, I think it’s banks that still have faxes…

Replying to @null and @virtuous_sloth, @judell

I’m no expert but I think it’s probably decently secure, at least by the applicable standards at the time of development. It’s meant to be used for medical and financial data, including payments.
I also don’t know PCI well but from what I recall fax security isn’t just about the transmission. There are requirements on locking the room in which the fax is so you can’t have someone stroll by and grab credit card numbers.

Thread of 2 tweets

Replying to @realmaplesyrup

Oh dear… That would almost be hilarious except it really, really isn’t.

Replying to @knowak

Nice.
I love the unspoken assumption.
Quoting a tweet by @Sally_Hubbard ↗
I love how in economics you can say things like “this principle has many holes, perhaps too many to be a theorem.”
This is now a classic move in Chrome: “privacy” actually means “we want only Google to track you without your knowledge or consent.”
Quoting a tweet by @ashk4n ↗
↺ 16
Smart position from @jason_kint.
Quoting a tweet by @voxdotcom ↗

Replying to @fatemehx2

You mean the proposal to analyse publisher content to profile people so as to monetise it elsewhere? Totally.

Replying to @thezedwards and @fatemehx2

Could it be done right? Possibly, yes. But how many cases can you cite in which Google had a chance to cheat but decided not to.

Replying to @slayser8

It's certainly the present state. As for being the outcome, I think there's a few plays that haven't been made yet!

Replying to @judell

Not that I know of. It would be a great project to dig into.
"5 Ways Your Ballot Might Be Rejected", by the excellent @stuartathompson. nyti.ms/2FFlqBm

Replying to @null and @fran_mady

Wow, je n'ai jamais eu à faire ça!
This looks great! (I'd just RT but Twitter seems to have activated the QT-only mode.)
Quoting a tweet by @nataliabielova ↗

Replying to @kzwa

Ah, thanks! I might be reaching that age at which people need to explain social media to me sooner than I expected, but I'll just roll with it.

Replying to @ShannonVallor

Same. I'm getting slowly better, though. Nowadays I can sometimes produce coherent sentences before 11am.

Replying to @lastpositivist and @LeverhulmeTrust

Is Jiji handmade? Oh, and congratulations!

Replying to @Helena_LB

What is margarine even for?

Replying to @_alastair

It’s so shortform that I learnt Quibi existed through their shutdown announcement…

Replying to @euthyphro

I know, right?!? I did that just a few days ago and my first reaction was to think that the milk was off.
14 Astounding Things People Used To Worry Were The Problem of the Internet. t.co/L8RfyTWYG7

Replying to @euthyphro

Yeah, and coffee without some greasy white stuff in it is just… too hot? Too liquid? I don’t know, it feels wrong.
If like me you’re unfortunate enough to have to use Gmail, I recommend disabling those tabs. No one needs Clippy sorting their mail.
Quoting a tweet by @matthewstoller ↗
I wonder what GDPR legal basis Google will use when Chrome is doing behavioural profiling for advertising purposes? github.com/jkarlin/floc At some point, we need to look at browsers as data controllers a little bit more seriously.
↺ 6

Replying to @joshm and @browsercompany

I’m writing these things up — no promise on timing but I’ll share. Would love feedback from your perspective when I do!

Replying to @alextcone and @catsoo

Would be interested in reading whatever you have on this.

Replying to @fborgesius

Well — it’s hard to be successful when you don’t even try ;-) I’ve had a few conversations about this here and there, and I’ve found it difficult to get traction. If you think there would be a good place to start, happy to give it a shot.

Replying to @reg_nerd and @fborgesius

In many cases, the browser determines means & purposes independently from the user.

Replying to @reg_nerd and @fborgesius

1) Some browsers are heavily tied with specific services. Google Chrome is clearly in scope here. 2) Browsers providing data to services unnecessarily and indiscriminately is also a decision they’re making. The service need not be specific.

Replying to @fborgesius and @reg_nerd

I think that argument is particularly salient when you contrast it with what browsers do with security. They work hard to provide solid security, even speed-bumping user decisions when they’re highly likely to be bad. For privacy, it’s… less stellar.

Replying to @null and @catsoo, @alextcone

Thanks! I’m not sure we’re 100% on the same page but I added to the discussion there to see if we can progress in that direction.

Replying to @thezedwards

Yeah, I’ve been wondering if Chrome should have a Do Not Sell button so it stops selling your data to Google :)

Replying to @jmmarosi and @fborgesius

I believe that the @NOYBeu folks are trying to at least sort that out for identifiers from mobile OSs. That would be a start!

Replying to @null and @catsoo, @alextcone, @EU_EDPB

Yes, I’ve spent a lot of quality time with that document ;) My conclusion is that browsers are data controllers in some of the processing they do, particularly if they do not implement ITP-like measures. They decide disclosure independently.

Replying to @alextcone and @catsoo

The GDPR is more subtle than that, thankfully. Controller/processor determination is per processing. So a browser acting within user expectations is the user’s agent, that’s the design. But other processing, like indeed reusing your data for profiling, is separate.

Replying to @alextcone and @catsoo, @EU_EDPB

I think what ultimately matters is regulators waking up and doing their job! Google’s policy team will follow business imperatives and run interference, I would expect.

Replying to @publictorsten and @reg_nerd, @fborgesius

That changes the risk profile, but it’s still processing!

Replying to @alextcone and @catsoo, @EU_EDPB

I wonder if DPAs may be catching up, though? It took two years longer than I expected for the TCF decision, they might be moving forward on other issues too.

Replying to @alextcone and @catsoo, @EU_EDPB

Oh, I didn’t mean on specifics. I don’t disagree there are better, more fundamental reasons to invalidate it, but I was more thinking of DPAs generally looking at more concrete & broad issues, rather than, say, “data protection in civic tech”.

Replying to @alextcone and @catsoo, @EU_EDPB, @nytimes

I’m not sure that that’s the most illuminating comparison? In general I’m not saying that the whole thing needs to be throw out, though. But reform needs to be in depth. Also, if you think there’s one political side that criticises us more than others… 😂

Replying to @Stef_Elliott and @alextcone, @catsoo

Yup — and I think they show clearly that browsers are in scope for some of the processing they do.

Replying to @alextcone and @catsoo, @EU_EDPB, @nytimes

Hahaha, well, as someone who did go on strike over that kind of problem I do offer beer in exchange for frustration sharing ;)

Replying to @alextcone and @catsoo, @EU_EDPB, @nytimes

Fingers crossed it'll take much less than that whole decade!

Replying to @publictorsten and @reg_nerd, @fborgesius

Yes indeed!
Can someone explain to me the privacy advantages of FLoC if your cohort data gets synced to your Google account anyway? Isn’t that more or less the exact same privacy violation except the computing cost got offloaded to you?
↺ 3

Replying to @publictorsten

Oh yeah, it’s generally ridiculous. But Twitter and YouTube think that I’m a Trump voter. Facebook thinks that I’m a woman. They don’t care, people buy segments anyway.

Replying to @publictorsten

BTW have you read “Attention Subprime Crisis”? It’s nothing you don’t know already, but I thought it was well put together and made a good case.

Replying to @dmarti

Sure — but that also basically means that it solves nothing.

Replying to @publictorsten

Absolutely! That’s also where the parallels with financial markets can explain things.

Replying to @dmarti

That, and also privacy solutions in which Google still gets the data are like thinking you’re saving the planet by reusing your kombucha bottles.
↺ 1

Replying to @publictorsten

It’s true that I wonder if that’s having an impact, or if they’re just doing the same over Zoom :)

Replying to @alextcone

Are you implying that well-meaning Google engineers are producing an over-complicated solution to the wrong problem while the ad folks there are, like, “eh, we’re getting the data anyway ¯\_(ツ)_/¯”? That’s… shocking, Alex, really shocking.

Replying to @publictorsten

Man, I know I’m always in the wrong industry.

Replying to @publictorsten

I know, but I wasn’t in 2008 :) I have in fact bumped into a few stars at NYT, but not at parties! I… I live in Princeton, Torsten.

Replying to @alextcone

Oh I agree there’s no ill-intent, but it’s pitched as a solution for privacy and I suspect the people building it are smarter than I am yet don’t understand that it doesn’t solve the problem. I do call Google “ad tech”!

Replying to @alextcone

Awwwww. Well, at the very least they have an education and they can math things up!

Replying to @swodinsky

I’m still not clear on why the “share” thing makes a difference. I don’t know of any case in which people share data in exchange for nothing. And if it’s in exchange for some form of consideration, then it’s a sale. Maybe stronger against bad faith?

Replying to @swodinsky

That’s not the CCPA definition, though. It explicitly included non-monetary consideration. I don’t see how anyone gives data in exchange for nothing.

Replying to @swodinsky

Ah, thanks, that’s super helpful — I hadn’t seen those. I don’t think users often “intentionally direct a business to disclose” their data, but I’m sure there are plenty in adtech who would swear that’s the case :)

Replying to @swodinsky

Oh, I know — I review vendors for a publisher. The number of times an adtech vendor gave me basically a no-mean-yes answer about user consent, always delivered as if it were totally obvious and I was borderline stupid…
I also gave a (very restrained) speech at an adtech CEO dinner the thesis of which was that it would be good to involve consumers in discussions about data. They stopped me two minutes in

Thread of 3 tweets

Replying to @swodinsky

No one wants to browser those non-relevant ads. You’ll see, they ask for privacy and then they write to complain about the ads! Users — amirite?

Replying to @dmarti

Last I checked when Firefox syncs Mozilla has no access to my data. That's not quite the same design.
Highly interesting thread from @SimonDeDeo about the behaviour of knowledge workers in large technocracies (here comparing Facebook and Wikipedia). It matches many interactions I’ve had. t.co/T3X6ZPFYQM

Replying to @othermaciej and @dmarti

Right, I expected no less.

Replying to @Log3overLog2

Hi! No, I understand the temporary part for the experiment, but doesn't Chrome save browsing data to Google anyway?

Replying to @null and @HNissenbaum

Individually, I largely agree. But it also means that it's a system you can't reason with, and as you know this is used outside of ads targeting too. Economically, it likely means that it's a bubble and when it bursts it won't be those who set it up left holding the bag.

Replying to @Log3overLog2

Well, I only use Chrome when I need to use a Google site that doesn't work elsewhere but I'm logged into Chrome anyway, I'm rather sure I never asked for that. Is that normal? It also prompts me to sync very often. What percentage of sync users set a password?

Replying to @fatemehx2 and @HNissenbaum

A kind RT to wrap up a good week! Mixing myself a rye sour, cheers from Princeton to both of you!

Replying to @Log3overLog2 and @swodinsky

Haha completely agree 😁 Since reading "Attention Subprime" I've in fact been wondering if it's possible to switch methods fast enough before the ad crash. Either way I reckon it'll be close.

Replying to @Log3overLog2

That's fair, I don't know equivalent numbers here either, was just curious. Because if you log in without meaning to, then get nudged to sync, and only get E2E optionally that's a lot of people with pretty bad data protection.
Not saying this as a jab, but it's what I was thinking about in the original post. Fixing that would improve privacy more than FLoC. Not at all a reason not to do FLoC, I love the research, but the priorities seem confusing?

Thread of 2 tweets

Replying to @Log3overLog2

Sorry, I'm thinking out loud on Twitter, that's not a recipe for clarity 😄 My focus is making the Internet a trustworthy environment for news (and privacy is a part of trust) and making sure publishers are in a fair competition in the ad market.
Removing 3P cookies could be a big step forward in this, so it's exciting, but if people are being tracked by their browser anyway it doesn't solve either problem on my plate. Hence the thinking out loud!

Thread of 2 tweets

Replying to @LAM_Barrett

Holy ffff. That's... Terrifying.
I intend to use Facebook again, after years off of it, just to support this.
Quoting a tweet by @katecrawford ↗
↺ 3

Replying to @bayesianboy

Many thanks for this moment of beauty, and I'm not just saying that because you're filthy rich.
The meme is good, the conclusion is perfect.
Quoting a tweet by @PaulOverbite ↗
↺ 2
Got some sweet privacy gear in the mail!
↺ 2
The whole thread is great but calling it the "official state religion" is particularly spot on. ToS are one cog in the bureaucratisation of everything, especially in the US where the private sector is a gargantuan bureaucracy, and bureaucracy has become the opium of the masses.
Quoting a tweet by @doctorow ↗
Another interesting wrinkle is that Apple claims to be about user experience, but Google Search has steadily plummeted on that front: you never know which box will show up, the ads look like results, it's basically a portal, etc. But, for $12bn, one might look the other way.
Quoting a tweet by @geoffreyfowler ↗
↺ 1
To put it slightly differently, both government and tech are corrupt, brutal, incompetent, and technocratic, but at least for one of those we have a rough governance model.
Quoting a tweet by @histoftech ↗
↺ 2
I can't wait for this book. We particularly need more on the "what to do about it" front.
Quoting a tweet by @histoftech ↗
↺ 2

Replying to @null and @icopilots

I don't think that we have a model figured out quite yet. Or if we do someone should really put it in a book because it would make my job a lot simpler!
This isn't to say that we don't have bits and pieces. There's also a lot to reuse from non-tech. But we lack a coherent overall approach.

Thread of 2 tweets

Replying to @ma_franks

Somehow the link seems to hang forever for me. Got a copy at repository.law.miami.edu/fac_articles/7…. Looking forward to reading it, and even more so to the book!

Replying to @AmeliasBrain

I'll cross that bridge when I get there?

Replying to @montezumachavez

I don't know if it could get to you on time for the vote!

Replying to @ashk4n

Nice! Bringing the handsome for privacy.

Replying to @montezumachavez and @DuckDuckGo, @SaraMorrison

Yay!

Replying to @roqchams and @jkohlmann

Have you met New York squirrels?

Replying to @JasonWilliamsNY

Holy crap that's terrifying.
Covid cases per million (since June) indexed by state partisanship: dangoodspeed.com/covid/total-ca…

Replying to @svgeesus and @jpscasteras, @EliSugarman

Game theory is counterintuitive that way! High maths and all that, you know. But it also makes for a classier way to say "when they go low, we grab them by the balls and rip them out."

Replying to @publictorsten

They're not wrong!

Replying to @RDBinns

I presume that by "new" you are thinking of groups that would have been discriminated against but we didn't have the technical means to detect them in arbitrary contexts? (As opposed to social change that would suddenly hate a segment.)
If so, you could hypothesise that gamers may have been found to have statistically worse outcomes for health, financial stability, job performance. And then being discriminated against. But that's more from surveillance than AI?

Thread of 2 tweets

Replying to @coolharsh55 and @RDBinns

Right, so you're thinking of disparate impact on a multivariate group. Presumably stable enough that it would be affected by more than one model. I don't think that we could ever detect that?

Replying to @RDBinns

Ah, but I don't think it's historic oppression that makes those stats morally problematic, no? Imagine racism didn't exist and we went ahead and made a structurally racist system. I don't think that would be OK.
Evidently, I find it hard to believe in the oppression of gamers right now, but if we build something that is structurally discriminatory it still seems like an outcome worth avoiding.

Thread of 2 tweets

Replying to @null and @amyvdh, @svgeesus, @jpscasteras, @EliSugarman

Nice one too! We're so good at this game theory thing.

Replying to @RDBinns

Right. I’m trying to think of a demo cluster that would get detected with some stability across models (like @coolharsh55 was pointing at) and would somehow get discriminated against structurally, and I’m finding it hard to imagine.
I don’t think it’s the case for all algos, but it’s certainly possible for all (or most) ML, I would think. It’s easily solved using the “Don’t Fuck With People’s Lives Using Tools You Can’t Understand” fairness/justice model.

Thread of 2 tweets

Replying to @hober

Awwwwww 💖💞💗🤗 It’s *really* good to see your face, even if it’s annoying that it’s just in a small rectangle on screen. I miss you! Let’s go fix this mess :)

Replying to @etportis

Good typography is super important! I’m not your best contact, though. @justinph or @_alastair do you know if we have published a description of the headless hoops we jump through to size/layout headlines properly?
When publishers gather to discuss pseudonymous identifiers, or even privacy in general. #w3cTPAC
Quoting a tweet by @PDLComics ↗
↺ 2

Replying to @ShiraOvide

You know you just jinxed yourself, right?
There are some follow-up discussions planned; I think we’ll see some public events (or at least open events) coming out of it. The other session was more of a mixed bag. A number of good points, but no indication of how pseudo-IDs could work. No clear follow-up.
One participant insisted on making the point that adtech companies are perfectly legitimate representing publishers. That… didn’t go well. I had just been making the point that people should be open to speaking to some trustworthy adtech players. So it was counterproductive.

Thread of 3 tweets

À noter par ailleurs: le partage arbitraire d’identifiants personnels par la plateforme, comme le faisait Apple et le fait encore Google, ne semble pas avoir de base légale valide sous le RGPD. Il serait plus productif de demander à la @CNIL de regarder du coté d’Android.

Thread of 2 tweets

TFW the @IAB asks if you’re a prepper.

Replying to @sidneyfussell

Not all that inaccurate, especially when you consider Sparta’s role in trying to prevent democracy!
Any recommendations on a running app with good guided runs? I tried the @Nike one but the guy doing it is so annoying I literally shouted STFU as I was running, much to the surprise of my quiet Princeton neighbours.

Replying to @null and @SoSillyDaddy1, @Paul__Walsh, @Nike

Thanks, I haven't looked because it always feels a bit cultish from the outside, but maybe that's wrong? Do they talk a lot though?

Replying to @can and @Nike

Thanks, I'll look! I don't see Weav on Android, though.

Replying to @null and @SoSillyDaddy1, @Paul__Walsh, @Nike

Yeah thanks, I'll give it a shot. I don't really want an instructor, I just want it to tell me when to change pace for intervals and such, and maybe if I'm going too fast or slow.

Replying to @Paul__Walsh and @SoSillyDaddy1, @Nike, @shantisheetal

Thanks!

Replying to @nicolasrieul and @CNIL

La logique orientée consommateur et concurrence serait d'interpeller la CNIL sur la légalité de ce traitement s'il devait être soumis à consentement et demander à l'@Adlc_ de pauser les pubs d'Apple.
Si je comprends bien la requête, elle fait le contraire: demander la continuation du partage des identifiants, ce qui favorise les gros et est hostile au consommateur (et dénué de base légale RGPD).

Thread of 2 tweets

There's a lot of denial in adtech today, but "privacy-first IDs" is one hell of an oxymoron.
Quoting a tweet by @kyotonio ↗
↺ 9
Did Facebook feel the wind turning? "Trump’s price advantage in swing states disappeared in September, when the campaigns paid roughly similar prices. In October, Facebook began charging Biden slightly less than Trump."
Quoting a tweet by @themarkup ↗

Replying to @nicolasrieul and @CNIL, @Adlc_

Le consentement n’est pas toujours nécessaire en first party, donc ça dépendra du détail. La valeur des données a des network effects, donc le jeu A+B a plus de valeur que la somme des deux. Les IDs permettent techniquement de constituer A+B, et donc aident les gros.

Replying to @profcarroll

But you clicked “Accept” at some point, so clearly you must have consented!

Replying to @publictorsten

I mean if you don’t burn it…
I’m hearing rumours that if governments keep trying to enforce antitrust and privacy laws, Google threatens to continue to make its icons worse.
↺ 10

Replying to @mario_gug

Hahaha, well played.

Thread of 3 tweets

Replying to @drogersuk and @monzo

Wait, what?

Replying to @drogersuk and @monzo

Ha! I wasn’t familiar with them, but yeah: everyone has the same colour scheme, it’s confusing.

Replying to @drogersuk and @monzo

This notion of innovation in consumer banking is fascinating, I wonder if the US will try it some day.

Replying to @slayser8

I have a theory that it’s just an understudied phase in big tech market dominance.
Ooh, it looks like AdChoices is getting a Web 2.0 version!
Quoting a tweet by @kyotonio ↗

Replying to @swodinsky and @nytopinion, @nytimes

Bruh. It's not Opinion's best work, LA Times's Ed Board did much better there.

Replying to @MikeIsaac

And that's before even mentioning @themarkup's work on ad pricing!
↺ 2

Thread of 2 tweets

Replying to @kateconger and @zneeley25, @MikeIsaac, @les_arenes

Gon-flay. I can record it and put it in the Slack :)
“Super Gonflé — La Bataille Uber”, de mon estimé collègue @MikeIsaac est traduit en français!
Quoting a tweet by @MikeIsaac ↗
Great write-up about Google Search as an automated election misinformation machine: tomkemp.blog/2020/10/30/wha…
Now *this* is how you do election coverage. nytimes.com/interactive/20…
↺ 1

Replying to @jkohlmann and @michaelroston, @lexim, @mikiebarb

We have Times yoga mats???

Replying to @null and @zneeley25, @kateconger, @MikeIsaac, @les_arenes

More like Mi-kah-ell. Or, tentatively, Mahy-kuh. Then I-zack.

Replying to @null and @alienatedgondor, @martinhoffmann

There are worse ways to go.
A question, particularly (but not only) for trans friends: do you get ads misgendering you in their targeting, & if so do you find that hurtful or more like “meh, ads suck”? (I get it often, eg. bra ads, I guess from my name. I’m ¯\_(ツ)_/¯ but also cis, so I’d like to hear!)
↺ 1

Replying to @v0max and @airavn, @montezumachavez

How long before XR devices include this in their ad measurement frameworks? ;)

Replying to @v0max and @airavn, @montezumachavez

Oh sure, wasn’t contradicting that — just pointing out that it’s likely dual-use tech! It could well be in Oculus!

Replying to @adambroach

Oh yeah, there was a phase during which I got lots of German ads. I love it when that happens :)

Replying to @kingjen

Haha, that’s true in many ways. But I do worry about how it could be one more bad thing for someone who gets misgendered a lot. Accurate data is key to self-sovereignty over one’s identity. Under CI there are cases in which a flow is inappropriate *because* it’s inaccurate!

Replying to @__apf__

Yeah, that is sadly classic. But I assume you don’t find that hurtful? I’m curious what ads you clearly note are men-directed?

Replying to @__apf__

I hear you. And I don’t think you’re a misfit! They’re the misfits. Clothing seems to be the most salient ones, yes.

Replying to @jbqueru

I’m not surprised, composed given names exist in English but they’re rare. If it’s any consolation my daughters have two family names and people here butcher that despite it being relatively common.

Replying to @gsnedders

True, I hadn’t thought of pregnancy-related ads — I would have thought those triggered not on gender but also on something else (that is probably wrong more often than right). Yes, again, clothing seems to be the bigger problem area. I assume also body variety might be an issue.

Replying to @AutomatedTester

It’s not the end of the world, really, it’s mostly bras, dresses, and occasionally period underwear. I’m more worried about people for whom it could trigger some dysphoria.

Replying to @erynofwales and @gsnedders

I’m sorry to hear that. I wonder how those models are built, but I assume not well to boot.

Replying to @gsnedders

Probably, but you’d be shocked at how asinine some of this is. I regularly see the segments a well-known data broker puts people in. It looks bad when you see a snapshot, but when you see how the segments change over time for a single person, it’s just incredibly random.

Replying to @gsnedders

The context here is that I’m trying to figure out how to make our targeting safe, ethical, good, etc. I don’t see us having a “pregnant” category so that’s easy, but advertisers do want gender and I’d like to see how to get it right (or at least not horribly bad).

Replying to @gsnedders

Well, pregnancy strikes me as the kind of thing you'd want contextual advertising for. Not only can mistargeting be painful (to several kinds of people) but pregnant women are sick and tired of hearing about nothing else!
In "Free The Tipple" there is a cocktail called the "Beyoncé" that's basically lemonade and bourbon. I went with rye and threw in a dash of Cointreau, and I think I may have a new go-to!

Replying to @ctavan

Funny, I never think to use it on crêpes, it's a margarita thing for me. But I should!

Replying to @ctavan

Even better, crêpes and margaritas sounds like the best evening.

Replying to @DanaTurjeman

I'm curious about how you study privacy using causal inference (and other fancy stuff), do you have a few papers you recommend?
On December 2, join @idonibrasco and I to talk about the dark present and (perhaps!) bright future of adtech and privacy, as part of the (excellent) Cornell DLI series! dli.tech.cornell.edu/seminars/AdTec…
↺ 2
For those of you who use @RoamResearch and need to print your articles, I made this little bit of CSS which you can paste into roam/css. It's not pretty but it does the job. gist.github.com/darobin/943047… #roamcult

Replying to @AmeliasBrain and @gsnedders

Yeah, that's why I said this should be contextual. It's not a demo we have anyway so there's nothing to push back with at this point 😁

Replying to @AutomatedTester

Excellent name choice, by the way 😁

Replying to @null and @JustineHMathews

Thank you, that's a good reason to get this right!
I believe the cool kids call this a power cord.

Replying to @null and @podopie

If you ask some questions of it you get some query logs.

Replying to @null and @SoSillyDaddy1

It's a lot of wood.

Replying to @fatemehx2 and @RoamResearch

Roam is pretty much all about the nerding out 😁

Replying to @DanaTurjeman

Thanks a lot, I'll start with this one, definitely intrigued!

Replying to @peligrietzer

I don't know, I barely value my own childhood either, but I really enjoy parenting! That said, I think the way some American families are child centric feels very unhealthy.