March 2021

458 tweets

“It’s not social media that’s the problem, it’s the ideas and behavior of the people who use it.” - @nytdavidbrooks That's why 64% of those who joined extremist groups did so from FB recommendations. Tech is neutral, people are the problem.
Quoting a tweet by @CraigSilverman ↗
↺ 1
Several of the "bird proposals" (eg. SPARROW, PARAKEET) rely on a trusted gatekeeper server but tend to relegate figuring out how that server gets trusted to a vague future. Has anyone built a governance model for these gatekeepers that I've missed?
↺ 2
The idea of a gatekeeper server is quite interesting given we have to contend with a situation in which trusting browsers not to self-deal is not evident. But it's a big ask, too, and we should start on the governance now, not later.

Thread of 2 tweets

Replying to @dmarti and @Chronotope

It's not just delays — some things can't be delayed at all, like, well, bidding :)

Replying to @Chronotope

Right, that's been my impression. I mostly wanted to make sure of that before I start writing up something. The more I think about it, the more I like the trusted server model (because browsers are hard to audit, and some have chequered history), but it needs governance.

Replying to @flamsmark

You mean in the level of detail? If so, yeah, they're really not specs by any margin. If you mean more, I'm curious!

Replying to @flamsmark

Agreed, but in fairness that has been a property of every approach I've read so far, not just the bird ones!

Replying to @flamsmark

That's true of a few, but I don't think it's fair of the whole bunch.

Replying to @heydonworks

You don't need to ask for gender, you can ask for pronouns and more generally addressing preferences.

Replying to @heydonworks

For English, if the site is social there are cases when you want to say things like "Robin updating {his,her,their,<other>} profile."

Replying to @heydonworks

Yeah that works for me.

Replying to @heydonworks

It can be both!

Replying to @deontologistics and @LogicalAnalysis

Could SSRN be used for this?
You can do this because @Roku should have made it the default, or you can do it because they're carrying Steve Bannon's show. Either way, it's worth doing.
Quoting a tweet by @RosemanSeth ↗
↺ 1

Replying to @swodinsky

He's not bad, he's just mrawn this way.

Replying to @deontologistics and @LogicalAnalysis

SSRN isn't wonderful but my sense is that it generally works. (Caveat: I worked in academic publishing previously and have a few papers out there but I don't do academic writing for a living.) It clearly seems to be working for legal scholars.
À force d'utiliser la "laïcité à la française" comme cache-sexe pour le racisme, ça finit par se voir et risque de mener à jeter le bébé avec l'eau du bain. (via @econoclaste)
Quoting a tweet by @ChloeMorin2 ↗
↺ 1
It's good to see Google taking steps towards greater privacy in the ecosystem. What I'm very curious about and the billion-dollar question is: at what point will they move past using a security threat model for privacy and improve internal practices too? blog.google/products/ads-c…
↺ 3
This — and the same with opt-in! Offloading privacy labour to the user is just indenture for access. We need to approach privacy from a much more opinionated angle than "transparency & choice" cop-outs. (And failing that, when opt-outs exist they should always be global.)
Quoting a tweet by @MindingPrivacy ↗
↺ 12

Replying to @JuliaAngwin and @daniellecitron

It's not that simple. What @ssnstudy et al. found was that it doesn't increase *publisher* value by that much, but that doesn't mean that it doesn't increase *intermediary* value. There are also, as you well know, many ways to track people. Google hasn't given up its own!
Additionally, it's very difficult to make an assessment from any of the studies because what is considered a "publisher" is hopelessly broad: any entity that provides inventory.
So it's entirely possible that, without cross-context tracking, high-quality news pubs lose little to nothing, whereas ad-supported whoopee cushion app "publishers" lose 95%. The 4% study was clearly a "real" publisher. Other studies are often useless because they blend it all.

Thread of 3 tweets

Replying to @publictorsten and @JuliaAngwin, @daniellecitron, @ssnstudy

I believe that's decreasingly true, though. You can't just target Chrome users :)

Replying to @publictorsten and @JuliaAngwin, @daniellecitron, @ssnstudy

Oh, sure — there's nothing in programmatic that requires targeting or behavioural.

Replying to @publictorsten and @JuliaAngwin, @daniellecitron, @ssnstudy

It's just an automated way of buying inventory, it can use any kind of signal to make decisions. You can even implement it in privacy-preserving ways.

Replying to @publictorsten and @JuliaAngwin, @daniellecitron, @ssnstudy

Because when given a choice, marketers aren't interested in non-BT uses.

Replying to @publictorsten

Behavioural targeting.

Replying to @jathansadowski

If you're not going to get three, then you're probably better off with zero rather than one. That way you can claim it's deliberate :)

Replying to @LogicalAnalysis

I find it extremely painful and demotivating. The whole point of conferences (in my case) is that you can read the room and adjust in real time.
I preordered "Your Computer Is On Fire" what feels like a lifetime ago, I almost can't believe it's finally about to ship!
Quoting a tweet by @bjpeters ↗
↺ 1

Replying to @RebeccaSpang and @kpanyc

I got rid of all of them except for a tall cactus that was very sick and frail from the move, and which I put a lot of energy into nursing back to life. This probably says something deep about me, but I'm at a loss as to what.

Replying to @anabrandusescu and @anabmap

Caption contest waiting to happen.

Replying to @mjbarash and @robleathern, @aripap, @cpokane, @Google

UID is not (and will never be) in browsers. Since what it's trying to achieve is directly hostile to users, there will be growing pressure to eliminate it but that will probably be through origin-unique emails. Apple already has that working, others will follow.

Thread of 2 tweets

Replying to @LAM_Barrett and @heratylaw, @andy_geronimo

Oh wow, have to try that.

Replying to @s_englehardt

Thank you Steven, it means a lot that you'd recommend this!
Sometimes, Twitter, you crack me up.
↺ 1

Replying to @tobie

Oooh, I like this one.

Replying to @danbri

Oh, it would be, which is why that determination should be computed on the client with my data that Twitter can't see!

Replying to @danbri

Yes, and it gets good eventually!

Replying to @nsamuell and @s_englehardt

It's not perfect yet, but there's been progress 😁

Replying to @s_englehardt and @nsamuell

Credit where credit is due: the one and only reason there is any succinctness in that piece is editor extraodinaire @sarahbures 😃

Replying to @fgeorges

C'est le rapport qui a mené à la création de la CNIL. De façon générale, il y a bon nombre de personnes qui avaient compris le problème dans les années septante. Ivan Illich par exemple. Mais ça n'a pas été maintenu dans la culture informatique.
This is probably futile, but I'd like to ask: Can we stop talking about the "Privacy Sandbox"? I know Google used (uses?) the term but… I'm a Web & Privacy guy through & through and I have no clue what that name is supposed to mean. "Vague grab bag of specs that may help"? 🧵
↺ 2
There are different things: • The phasing out of 3P cookies. • A bunch of proposals from Google, some bad some good. • A bunch of proposals from others, some bad some good. These proposals are further influencing one another and making babies.
So sentences like "X will implement the Privacy Sandbox" or "Y only cares about the Privacy Sandbox" or "we need to audit/stop/support the Privacy Sandbox" make no discernible sense to me. Every browser will end up implementing some of the above. Hopefully the same "some".
It's entirely possible to think that the bird proposals have some interesting properties, whereas FLoC is an ethical train wreck begging to happen and if it ships it will be all data ethics scholars study for the next decade. (Hint: discrimination is against cohorts, too.)
↺ 1
You might disagree with my previous tweet, and that's perfectly fine, but at least it's coherent. Conversely, saying "I don't like the Privacy Sandbox" is like saying "I don't like the colour of socks." 👏 Which 👏 Fucking 👏 Socks? 👏
Anyway — I know most of you aren't going to stop. It's a complicated set of things and being precise is hard. I just thought that, since it's Friday, I should let you know that you're wrong on the Internet. Have a great weekend!

Thread of 6 tweets

Replying to @lukemulks

Hahaha, thanks :)

Replying to @null and @arainert

She's so lucky to have you.
Transparency and choice.
↺ 2
Since Agnes is making an appearance, I should probably mention that, after giving up on WandaVision a few weeks ago, I eventually dragged my feet back to it and it progressively gets a lot better! Cc @slayser8 @JGlogovsky.
↺ 1

Replying to @gizmomathboy and @slayser8, @JGlogovsky

Agreed, the first episode is particularly interminable.

Replying to @gizmomathboy and @slayser8, @JGlogovsky

What annoyed me most is that it's TV talking about TV. When they stopped doing so much of that it became a lot better.

Replying to @gizmomathboy and @slayser8, @JGlogovsky

I dunno, I'm pretty into it now, I liked her storyline and now it looks like there's a whole new dimension to it.

Replying to @slayser8 and @gizmomathboy, @JGlogovsky

Oh wow, Joan of Arc at 4, Wanda at 5, I can only hope to ever have a life as adventurous as yours!
Is there a service that can print a tweet on glossy paper and mail it to every person out there working on Return To Office policies?
Quoting a tweet by @eramshaw ↗
↺ 1

Replying to @twentyninepalms

The thing that bugs me is that I can't even guess what it's *intended* to mean. It's not like it describes an architecture or something like that. And what does it have to do with a sandbox?

Replying to @azeem

"More sensible" is a kind way to put this.

Replying to @anvilwalrusden and @mariafarrell, @guardian

It's true that the ePD cookie consent rules are stricter than is sensible (and do close to nothing for privacy) but I'd be shocked if a regulator came after anyone for storing the consent preference of a logged in user.

Replying to @anvilwalrusden and @mariafarrell, @guardian

As a corporate officer who assesses risk, I would say it kinda is 😁

Replying to @mnot and @anvilwalrusden, @mariafarrell, @guardian

Sadly, I doubt it. ePD makes little distinction between first and third party, and is for any local storage. This is one that W3C might fix (in time for ePR?) by explaining how to approach privacy on the web. I should probably get around to it, but there is so much to fix...
Writers and ML have this in common that they can capture important details of a person's identity through seemingly negligible details.

Replying to @mnot and @anvilwalrusden, @mariafarrell, @guardian

Right. GPC is kicking the tyres on a W3C/policy bridge that works. Then we can ramp up to something more ambitious.

Replying to @Log3overLog2 and @mathbabedotorg

Is the appropriate permission agreeing to Sync or is there a separate one? Is the idea that Sync is the solution forever? Also, how do you detect proxies for race, eg. to prevent redlining, or prevent a cohort from correlating with "gays who don't visit sensitive sites"?

Replying to @trekonomics and @ShannonVallor

And - hear me out - reality has been!

Replying to @mnot and @anvilwalrusden, @mariafarrell, @guardian

Indeed. Good thing we have a plan to get W3C into the shape it needs to have to finally rise to this kind of challenge!

Replying to @PrivacyMatters

A major publisher I won't name tested what they described as "valid consent" at significant scale and the best they got single digits.

Replying to @Log3overLog2 and @mathbabedotorg

Isn't all of that the default, though (except Sync, where it's a bit of a stretch to call it opt-in)? I'm not trying to pick nits, but given the justified ethical concerns, would there be a way for the community to work with your IRB to discuss these things & hear their thoughts.

Replying to @Log3overLog2 and @mathbabedotorg

I've seen some W3C discussion, for instance the redlining issue, but not that much, I hope I'm not missing something big? Yeah, not necessarily access to the people but given the scale and risks involved I assume you have a detailed threat/mitigation doc for these subjects.

Replying to @Log3overLog2 and @mathbabedotorg

Right, I get how it works, my concern is rather that this is something that has to be continuously monitored. At the same time, everyone I speak to at Google says the plan is to start getting serious about privacy, so at some point you'll lose access to this data.
I'd like to solve that problem before it happens. I've been thinking about the value of a gatekeeper server for this. It could use its extra knowledge to treat the browser adversarially and build some protection over the long term.
↺ 1

Thread of 2 tweets

Replying to @PrivacyMatters

I think in this case it was, hence the low numbers 😁
This is going to be worth watching!
Quoting a tweet by @catthekin ↗
↺ 4

Replying to @Log3overLog2 and @mathbabedotorg

Haha, well yeah. We didn't exactly do a great job not fucking up the first three decades, it would be n nice to turn that around, especially for stuff with clear risk! If it's any consolation, imagine how much pain it'd be if I'd taken that Google job working on this 😅

Replying to @Log3overLog2 and @mathbabedotorg

Yes, sorry, a few of us have started talking of a "gatekeeper" as the generic idea of having a server involved. It has potential to solve other problems beyond that require shared governance, eg. brand safety that doesn't suck.

Replying to @Log3overLog2 and @mathbabedotorg

Yeah, we've been looking at cool things to do for instance with Prio, but that's not what I'm trying to solve here. It's proving hard to build a good system given that there is no party that anyone trusts, not even the browser.

Thread of 2 tweets

Replying to @kyotonio

Lol
Philosophy of maths has a new champion.
Quoting a tweet by @littmath ↗
↺ 1

Replying to @dkiesow

Paywalls?
This is an interesting question. So far the disruptions of news in digital have largely been in distribution models, and they all variously degraded the system (thinking of Apple News, Google News, AMP, news in social, Showcase looks like more of the same bad). Why?
Quoting a tweet by @dkiesow ↗
↺ 3

Replying to @vinnysgreen

I know right? It was so painful to type. But there's a question here. If we could articulate why it's bad maybe they'd stop, and maybe we could find an alternative that isn't done by people who can't tell the difference between news and blogging.

Replying to @dkiesow

Absolutely. I think we can all see a future in which the platforms keep destroying ad revenue and we have no option left but to license content for their channels. Goodbye democracy. There's some work on funding, though, some of which could work.
Crossing the streams, an ad intermediary that would enforce good rules.

Replying to @Log3overLog2 and @mathbabedotorg

Yeah, we've been looking at cool things to do for instance with Prio, but that's not what I'm trying to solve here. It's proving hard to build a good system given that there is no party that anyone trusts, not even the browser.

Thread of 4 tweets

Replying to @vinnysgreen

All of this is true, but if we set up payment for it then we get trapped just doing "content" and having relationships mediated. It's lose/lose. The solution might be in policy, eg. CPNI for content or making recommendation=publisher in SAFE TECH.

Replying to @AmeliasBrain

These are all true, but as much as they'd be improvements, would they be disruptive?

Replying to @AmeliasBrain

Is that sort of similar to the continuous live briefing?

Replying to @AmeliasBrain

Patch has a beta hyperlocal product, meant for a newsroom of one, that's pretty interesting.

Replying to @Chronotope and @alextcone

I hate to risk awakening the sea lions, but section 230 protection does provide a perverse incentive to seek rent from others' content rather than invent your own. I would like to see it that if you distribute AND recommend, you're a publisher.

Replying to @susanthesquark

Reboot?

Replying to @susanthesquark

That's very weird!

Replying to @susanthesquark

Yeah, I don't think we're supposed to have a daemon mode.

Replying to @ethicistforhire

That was cool, like, ten years ago, no?

Thread of 2 tweets

Replying to @pdolanjski and @alextcone, @ashk4n, @RonWyden, @iab, @globalprivctrl

I don't think that's Alex's objection. There is a problem with the way in which Google uses opt-out cases as an excuse to not allow other companies to bid. That's just using privacy for anticompetitive reasons, not to help users. But you knew that at "Google"!
I'm throwing a party when she gets confirmed! 🌟🍹 🥂
Quoting a tweet by @tarapalmeri ↗
↺ 3

Replying to @johnnyryan and @jason_kint

That's why I think we need FLEDGE et al to work through an independent server that can check their work.

Replying to @F_Kaltheuner and @superwuster, @linamkhan

This is already more than I hoped for, fingers crossed 🤞

Replying to @alextcone and @pdolanjski, @ashk4n, @RonWyden, @iab, @globalprivctrl

Most browsers are meant to be PbD tools and have a claim to GPC by default (Chrome would be a harder case, but it might). GPC by default is best for publishers, users, and legit ad businesses. But if that's abused downstream to prevent competition, comp authorities should look.

Replying to @Chronotope and @swodinsky, @minimaxir

Ah well. I do in fact believe that A/B testing can be evil and we should spend more time thinking about its ethical ramifications; I don't think that when applied to headlines it's really a problematic case 😁
I know it's hard to believe, but your restaurant's menu doesn't need to be in PDF.
↺ 3

Replying to @gcarothers

That too! I'm thinking it could be, like, some pretty basic HTML. Might even work on mobile, for all those people who aren't scanning your QR code from their laptop.

Replying to @npparikh

Not so much these days.

Replying to @ocdtrekkie and @npparikh

This isn't new, though. They used to do Flash, or jpg. Whoever is in the business of building sites for restaurants is doing really crap work. They could even generate printable PDFs from the info.

Replying to @othermaciej

Oh, but some are!

Replying to @null and @benlikestocode

Or "only on our Facebook page"!

Replying to @benwerd

Man... Now someone's gonna do it.

Replying to @npparikh and @ocdtrekkie

I think the first mistake is to reach for ML, there.

Replying to @npparikh and @ocdtrekkie

I am empathetic, but within limits. 25 years ago I catered to small businesses and a key problem was that they couldn't tell the difference between crap and good work, so they just went to the lowest bid. At the time, I don't think anything else could be expected.
Today, restaurant owners can tell that pointing to a PDF is a botched job, they can use the web like everyone else. But it looks like they're not complaining to their tech providers near enough.

Thread of 2 tweets

Outstanding thread on responsibility dodging in tech. Cyberneticians call this POSIWID: the Purpose Of a System Is What It Does.
Quoting a tweet by @jesslynnrose ↗
↺ 8

Replying to @readingrebus and @msdixon

It's... a ton of swine?

Replying to @fantasai and @brucel

Is there... an AB meeting going on?

Replying to @brucel and @fantasai

Or Dr Stanley Dards?
It gives me chills to see the office this way. nytimes.com/2021/03/13/ins…
↺ 1

Replying to @null and @benlikestocode

Oh man, I'd forgotten about LIC! I wonder what's up with that space!

Replying to @fborgesius

The little detail in the video that got me is when they show the newspapers for weekdays and Sunday is empty. That is actually a physical area where the last seven days of the paper are always available. It's normally updated every day. Seeing it 1) old, and 2) empty is a shock.

Replying to @fborgesius

Yes, several colleagues reported the same: they were excited to go back, but they actually found it unsettling.

Replying to @akbarjenkins

I used to t think that, until I discovered just how bad Gmail is.
I tend to think about modernity and excessive order-regime control in terms of tech politics and social impact so I found it interesting to read this from @LMSacasas about more personal implications of modern control. theconvivialsociety.substack.com/p/the-paradox-…
↺ 3

Replying to @null and @dauwhe, @LMSacasas

Ha! I was thinking about you actually since he brings up Illich!

Replying to @fantasai and @brucel

This sounds like the kind of lively I'd like a shot of!

Replying to @fantasai and @brucel

Oooh, that's the good stuff!

Replying to @profcarroll and @wbm312, @swodinsky

By switching it off she gave affirmative consent not to have her data processed for advertising purposes, and consent needs to be at least as easy to withdraw as it is to give so, uhm, sure, that's totally totally compliant.

Replying to @thezedwards and @RichFelker, @FT

If it's state backed they could possibly be surfacing an identifier provided by mobile networks. It's pretty easy to implement and probably not that expensive either. Hard to plug, too.
↺ 1

Replying to @swodinsky and @thezedwards, @RichFelker, @FT

Of course, and I'd want to see some actual docs before speculating further. But what I describe gives you a reliable ID irrespective of stack and the only part a 14yo couldn't code is a compliant telecoms sector.

Replying to @profcarroll and @wbm312, @swodinsky

With flying colours!

Replying to @swodinsky and @thezedwards, @RichFelker, @FT

I love that they call it the China Anonymisation ID, they have the exact same communication strategy as adtech worldwide! Note that the call is async and that you can get both cached and updated versions. This doesn't prove but is congruent with a network source.

Replying to @thezedwards and @RichFelker, @FT

I have a mind for evil, gotta find ways to use it 😁

Replying to @jason_kint and @thezedwards, @RichFelker, @FT

Yes, basically the same idea except even simpler: no need to change every HTTP response on the fly, just provide an API endpoint to give that ID on demand. Each app can ask independently, but they all get the same ID.

Replying to @jason_kint and @thezedwards, @RichFelker, @FT

I'd be interested to see where that goes. It's not obvious how to fix that, unless there's consumer support behind Apple to prevent it. I don't know what sentiment is in China on this.

Replying to @swodinsky and @thezedwards, @RichFelker, @FT

The Translate version is grokkable. Loved the recurring variants on "Overheating Cloud".

Replying to @lukemulks and @swodinsky, @thezedwards, @RichFelker, @FT

Themselves!

Replying to @MaxGendler and @jason_kint, @thezedwards, @RichFelker, @FT

People rich enough to buy iPhones are a political force under any regime.

Replying to @RichFelker and @thezedwards, @FT

The internet is a hell of a side-channel! Also, well, identifying the customer rather than the device is a feature, not a bug. And it can wait to be on a mobile network then cache.
Consensus-building proceeding apace in the WebAdv BG.
↺ 1

Replying to @alextcone

I had to miss it too, I just caught up on the saltier parts :)

Replying to @TzviyaSiegman

What's the AB doing about this issue?

Replying to @fantasai and @TzviyaSiegman

All specs now required to have a meme. In PAGs, lawyers can only make arrangements entirely in meme form.

Replying to @Chronotope

Hahaha, please do! Given that when the "Privacy Sandbox" was announced I asked Google to retract their cookie study (something I think they should still do given how bad it was), I feel a certain kinship here :)

Replying to @alextcone

I don't think so? Google presented underwhelming research, they're being challenged on it. That's pretty much how I'd expect things to work. (Well, I used to expect better from Google, but I'm learning to live with that disappointment.) Or were you thinking of something else?

Replying to @alextcone

That's primarily because no one else is stepping up.

Replying to @blassey and @Chronotope

What are the odds that that would have any impact? Several of us flagged significant concerns of the value of cookies "study" and it's still up, still referenced, unamended.
With CWV we were told that our feedback was desired, that there would even be a group in which to discuss it. But then all our feedback was ignored and we've had to set up our own group, which is basically getting pre-written vacuous statements.
My conclusion from looking at the study is that nothing much has been proven about FLoC. Meanwhile, there is significant risk of discrimination. After mitigations are made for the latter, we should see about a protocol for independent evaluation of the modified outcome.

Thread of 3 tweets

Thread of 2 tweets

A year later, still remote, still the best team — except bigger! ❤️🍸 tweets.berjon.com/1239692624862339072
↺ 1

Replying to @null and @amyvdh

Thank you 🤗 ❤️💋

Replying to @null and @aliceafung

Scary!

Replying to @null and @benharnett, @aliceafung

Thank you! 🤗

Replying to @k_johnsn

Thank you ♥! It's getting closer!

Replying to @null and @phillipsharring, @KimCrayton1

If you don't feel reassured, wait until you see how they are doing that. Chrome has a dark pattern funnel that drives people into sharing their full browser history in cleartext with Google. They mine that to see if FLoCs match sensitive categories.
One thing this article captures well is that Google is succeeding in driving consensus between privacy advocates, browser vendors, publishers, adtech people, academia, regulators, and then some. It's impressive!
Quoting a tweet by @KimCrayton1 ↗
↺ 5

Replying to @alextcone

Thanks Alex! Haha, all of them in a year? That's going to be a hell of a ride!
I know we're all exhausted watching big tech monopoly halt invention and destroy democracy, while those who work there make shallow excuses. It's tempting to just give up. But cat food, folks. There's monopoly in fucking cat food. We cannot let this stand and must reform! 🙀
Quoting a tweet by @amyklobuchar ↗
↺ 3

Replying to @RickByers and @blassey, @Chronotope

It was provided directly in a meeting I think about a year ago? We don't have (or can't find) the answers we need to make an informed investment decision in CWV vs AMP. On the fact of it looks "fake" in the sense that cached AMP still gets a leg up no matter what.
Since the group we were told would happen to discuss that in didn't happen, we just got someone into the AMP TSC and another into the AMP AC to discuss there. They are currently hashing out the issues. The folks involved tell me "all we've heard so far is condescension."
I think they plan to make a last attempt to have a productive discussion, and if that fails just document the outcome and look for another way to route around the damage that cached AMP continues to wreak. FWIW there's also nytimes.github.io/std-cat/ for broader reqs.

Thread of 3 tweets

Replying to @null and @koalie, @kplawver, @mipsytipsy, @jtannady

I think it's very healthy to know that work won't love you back, but no matter what change happens don't forget that some of the people from that endless summer camp will!

Replying to @RickByers and @blassey, @Chronotope

Right, as a set of metrics independent from how they're being used they seem pretty good (and I recall we said as much). But you can have the best metric in the world, if one option gets preloaded and prerendered it's not true that there's a level playing field 😁

Replying to @RickByers and @blassey, @Chronotope

Sure, we're not asking for anything ahead of anyone else (and I think everything they do in the AMP AC is public?). It's just we were told CWV was the fix so that we could stop suffering from AMP which was the whole point for talking about it in the first place...
...but at closer look it seems like it won't work and we've been stalled for almost a year on this. I guess that's on me for believing those "we'll stop forcing you to use AMP" promises.

Thread of 2 tweets

Replying to @Chronotope

Frankly, I don't know why they don't reset the DCU and start from scratch, the whole thing is painful.

Replying to @Chronotope

I don't think that the problem is the characters, they should mostly fire the writers and producers. I was super excited about WW and even made myself watch WW84 despite the first disappointment but it was cringeworthy painful.
OK, but hear me out: What if Ireland, but with a Data Protection Agency? 🇮🇪
Quoting a tweet by @maxschrems ↗
↺ 2

Replying to @LMSacasas

Ha! He anticipated Matthew Crawford by some 35 years. 😁 I slightly disagree, though. If silence is a freedom from encroachment, then it's more a akin to a nature refuge than to a commons. I think attention, including the parts that lie fallow or are collective, is a commons.

Replying to @ireneista

I love my Irish friends, but I think we should be considering sanctions. Just like the OECD does for tax evasion, there should be a list of uncooperative data havens.

Replying to @LMSacasas

Oooh, thanks for the link! Off to read that now.

Replying to @ireneista

Indeed. And sadly, this is an outcome that was visible from quite a distance and could have been avoided.

Replying to @RickByers and @blassey, @Chronotope

Might I suggest communicating on that? A lot of us have roadmaps that depend *a lot* on whether we invest in working around AMP problems or on the contrary write it off and plan the switch to web-only (which I prefer, but I'm biased).
Also, since it doesn't seem baked: we have some pretty clear feedback on what it needs to be if it's actually going to work. Cc @k_johnsn @tobie. And not to make fun of a typo but I like the idea of Responsible Manor. I wouldn't live there, but I'd visit! 😂

Thread of 2 tweets

Replying to @RickByers and @blassey, @Chronotope

Right, I'm aware of that, but the issue for many publishers isn't preparing for CWV, it's figuring out what to do about AMP. AMP breaks a lot for us and it's getting worse with 3P cookies going away. Ideally we'd get a way off, but if not there's a lot of stuff to fix.
Put differently, we have multiple engineering teams who need to know if they need to sink significant resources into making a tech stack they all hate and we were forced into work, or on the contrary if they can focus on switching and perf.
Assuming the 3P cookies timeline holds, which will affect AMP a lot since we're third parties to our own content there, we kinda need to know that three months ago...

Thread of 3 tweets

Replying to @anabrandusescu and @anabmap

Hahaha 😂
I agree with that decision: providers of identifiers, such as operating systems for ad IDs or browsers for third-party cookies, do so as data controllers and need a legal basis.
As I'd argued at the time, instead of sticking to a strategy of trying to maintain an unsustainable status quo that people hate, the ad industry should switch to a pro-consumer stance and push for real privacy from the platforms (instead of the fake moves we see eg. from Google).
↺ 1
Now we have to see if the CMA will also make the right decision in the MOW complaint. I think that some Interim Measures would make sense, but only if they align with stronger privacy. At the end of the day, it's the only way to get better competition too.

Thread of 4 tweets

Replying to @alextcone

Not just the lawyers but the strategists too! These complaints are so predictable they can be gamed out ten moves ahead. I spoke with folks there, my recommendation was to find a consumer advocacy group to align with on better privacy = better competition. Surprise move.

Thread of 2 tweets

Replying to @alextcone and @wayneblodwell

Right, I think their moves should be challenged, it's the way in which they're challenged that I find predictable, poorly thought through, and easy to deflect.

Replying to @BuggeErik and @Adlc_

Yes, completely agree!
Good things can happen in Big Tech. I'm old enough to remember when Microsoft people were insufferably arrogant and in denial as to how bad at security they were. They managed to completely turn that culture around and became a pleasure to work with. I wish that happened more.
↺ 2

Replying to @LSD_Lysergid and @Chronotope

I'm fuzzy on timelines but I think the change actually predates Nadella? When I worked with the IE people in standards, on HTML5 and such, that change had already happened.

Replying to @rubin

You've given up hope on Google? :)

Replying to @rubin

Yes and no. They're become better at policing what others do, but they're not changing their own practices. The degree to which even the nicest and smartest people there are in denial about just how bad at privacy they are is scary.
For instance the fact that they are far, far worse at privacy than almost any other actor, including Facebook, isn't something they seem to so much as consider conceivable. Their entire thinking about privacy is based on security threat models; it's like the 90s in there.

Thread of 2 tweets

Replying to @rubin

Well yeah — it's much better security if you don't even have the data in the first place! But they're very far from that position right now. Just looking at what Chrome does is scary.

Replying to @perigrin

You too kiddo!

Thread of 4 tweets

Replying to @dret and @Google

Yup, even though for most users not being logged in won't ever happen because it's the default, followed by dark patterns to make sure you sync.

Replying to @AwayCaludio and @caludio

It's already outlawed, but @DPCIreland is the relevant DPA and they've decided to give Facebook and Google a free pass for everything.
↺ 2
À la cantine scolaire, le seul menu républicain est un menu végétarien. Il est temps de se tourner un peu vers l'avenir, même quand il existe des traditions. "A French City Dropped Meat From Kids’ Lunches. The Nation Erupted." nytimes.com/2021/03/18/wor…

Replying to @null and @HelloFillip

Indeed, though in fairness for Firefox the extra stuff only exists if you specifically use it.

Replying to @ItsAllySo and @alywitch, @Jason46140216

And all Androids.

Replying to @null and @HelloFillip

Yes, I like mixing it up too.

Replying to @null and @pixeldetracking

My understanding is that Firefox telemetry is Prio, so it's about as safe as it gets.

Replying to @cwilso

The funnel from logged out to sync (but not to passphrase sync) is, in my professional opinion, deceptive. And the way the passphrase option is setup (secure by default for passwords but not for history) makes it look very deliberate.

Replying to @null and @pixeldetracking

Replying to @thezedwards

My understanding is that the way in which Firefox stores this makes it unavailable to Mozilla. It's also not used for tracking. Chrome not only keeps it in the clear for Google, but uses it for tracking, including special-categories processing (by their own account).

Replying to @jaysonmassey and @AutomatedTester

No other browser comes even close to being this bad. Browsers simply aren't supposed to do this, they're supposed to work for the user.

Replying to @thezedwards

Fair, but I would reckon it doesn't make a difference?

Replying to @thezedwards and @publictorsten

Does Brave (the company) get to know your id though?

Replying to @thezedwards

Because this is clearly labelled on user action, it's not about the default, it's about how obvious they make it. That's very different from Chrome.

Replying to @null and @pixeldetracking

C'est possible. Je sais qu'ils veulent utiliser Prio pour pas mal de choses mais je ne sais pas où ils en sont.

Replying to @RyanRadia and @AutomatedTester, @jaysonmassey

Other browsers do this without granting their parent company access to the data.

Replying to @vkw and @googlechrome

If you think Chrome doesn't track you, you're in for a bad surprise. I know what The Times collects and how, and I know a fraction of what Chrome collects. I stand by my statement, easily.

Replying to @RyanRadia and @AutomatedTester, @jaysonmassey

Chrome shares your data to Google, yes, which in this context is 100% a third party. Not sure what you put under "consent" but it's not valid GDPR consent for sure given the sensitivity of the data, UI, and processing. I suspect it may qualify as deceptive under FTC rules.

Replying to @dwlz and @vkw, @googlechrome, @nytimes

Good thing we're talking privacy and not security, then.

Replying to @RyanRadia and @AutomatedTester, @jaysonmassey

Not if you actually know that that is what is happening and understand what your data is being used for. For instance, if it's used to prevent competitors from entering the market and giving you better products.

Replying to @dwlz and @vkw, @googlechrome, @nytimes

It's not snark, and as I told Victor: I'm intimately familiar with what data NYT collects, how, and for what purpose. It's almost certainly the most privacy-forward media outside non-profits. And it compares very favourably to Chrome.

Replying to @UncleBeebaw and @philarcher1

No, it doesn't.
I'll allow it.
↺ 1

Replying to @RyanRadia and @simevidas, @AutomatedTester, @jaysonmassey

Use pretty much any other browser (and several have the same engine, and you got it!

Replying to @vkw and @googlechrome

I think the labels are a decent first stab at giving a high level view for a lay audience, but they fall short of a privacy threat model (which might be impossible to convey easily).
They don't get context, like tracking by the first party (which is fine, like the shopkeeper knowing you're there) vs tracking by a fiduciary, like a browser. Or volume: analytics on one site vs capturing you're entire online behaviour.

Thread of 2 tweets

Replying to @jesslynnrose

That was my first reaction too 😁

Replying to @AutomatedTester and @RyanRadia, @simevidas, @jaysonmassey

No need to convince me, I'm just saying if that's what you like then it's there!

Replying to @montezumachavez and @tweetinjules, @DailyDashboard, @EU_EDPS

Completely agreed, to be honest I'm not sure why other European authorities didn't just follow the guidance from @EU_EDPS! It solved the problem and addressed privacy & safety together pretty clearly I thought?

Replying to @tim_libert and @PrivacyMatters

Is that not purely local?

Replying to @dwlz and @vkw, @googlechrome, @nytimes

That's fine. There's no question Google is far worse at privacy. Chrome alone is much more privacy invasive than much of The Times’s practices. What's more, the most significant privacy issues NYT has are from what Google forces publishers into.
Having said that, I think you have the wrong framing. Privacy is contextual (see pinned tweet). You have to compare contexts. A violation from a browser is akin to one by a doctor or lawyer since it's a fiduciary agent. It's far more serious than most.

Thread of 2 tweets

Replying to @montezumachavez and @tweetinjules, @DailyDashboard, @EU_EDPS

Oh, I know, but anyone can read and appreciate a good position 😁

Replying to @kielgillard

Between Android and Chrome it's hard to pick the worst!

Replying to @null and @Julijan

Literally any other is better. I use Firefox, but take your pick!

Replying to @dinodaizovi

Not just sign in but also sync. Most users are there since the defaults and prompts are architected that way.

Replying to @justinschuh and @dinodaizovi

That is incorrect. Chrome tracks users directly, I'm not "spinning" anything.

Replying to @phenlix and @bgalbs, @justinschuh, @dinodaizovi

Indeed. Chrome has a clear funnel from logged out to sync that is quite deceptive and built on dark patterns.
↺ 1

Replying to @justinschuh and @phenlix, @bgalbs, @dinodaizovi

I'm sorry if it reads that way, it is not an attack and certainly not innuendo. Just intended as a statement of fact. Are you saying Chrome does not collect browsing history in the clear from a majority of its users?
↺ 1

Replying to @justinschuh and @phenlix, @bgalbs, @dinodaizovi

No, it isn't "obviously" about volume of permissions (these aren't permissions?), it's about pointing out that Chrome is a privacy problem and illustrating that.
If your point is that indeed Chrome is bad at privacy but you feel there are better illustrations than the privacy label, I'm definitely interested in seeing those.

Thread of 2 tweets

Replying to @justinschuh and @phenlix, @bgalbs, @dinodaizovi

I clearly indicated history as grounding my point. You say you want to address that separately. Why is it FUD when you refuse to answer? You seem angry and I'm sorry, but I'm serious in my assessment and still waiting for you to dispel what you say is "confusion".

Replying to @justinschuh and @phenlix, @bgalbs, @dinodaizovi

Justin, here's the exchange from my pov: R: Chrome tracks more than any site. J: Back that with fact. R: Sync of history is one such fact. J: That's a falsehood. If I'm wrong about history then *please* explain how.
This is a key part of how I understand you implement protection against discrimination in FLoC. So if I'm wrong about your collection of history then I need to re-evaluate FLoC, and that's a topic of major importance as you surely understand!

Thread of 2 tweets

Replying to @justinschuh and @phenlix, @bgalbs, @dinodaizovi

I'm sorry but I backpedal nothing. As I've said above, if you feel that this is not the best illustration of the problem, then I welcome suggestions for alternatives. But let's keep focusing on the facts because you don't see how it's tracking and I don't see how it's not.
My understanding, and again correct me if that's wrong — this is based on previous discussions with Chrome engineers but I may have misunderstood — is that Sync captures cleartext history such that Google can access it. That's the meaning of this option. No?

Thread of 2 tweets

Replying to @justinschuh and @phenlix, @bgalbs, @dinodaizovi

I'm sorry but that's a strawman. I never said that collection regardless of method is tracking, in fact I'm saying the opposite: the manner in which Chrome does it differs from other browsers in ways that make it tracking there.

Thread of 2 tweets

Replying to @justinschuh and @phenlix, @bgalbs, @dinodaizovi

I'm happy to answer any questions you have about the NYT, but it reads a lot like whataboutism. I'm asking a very simple and specific question: do you default to E2E for history sync or not? If the answer is "no" then I have just one more question and that's it.
And I'm not trying to trick you. Either I'm wrong, and I want to know, or you are and I think you're in a position to make the world better by fixing the issue. Either it's a win, I'd like to think for both of us.

Thread of 2 tweets

Replying to @ericlaw

Browsers used by a significant number of users should be held to a high standard of trustworthiness.

Replying to @justinschuh and @phenlix, @bgalbs, @dinodaizovi

The impression I got from those tweets was "yes" but I was hoping for a clear answer since, again, I am trying to ensure we work from the same facts. I think you know a few people who would trust you if you spoke up?

Replying to @justinschuh and @phenlix, @bgalbs, @dinodaizovi

Thank you for having the patience to make sure we're on the same page. Now, does a dialog like the one below make it clear to users that they are "opting in" to handing over most of their browsing history?
Because, I'll be 100% clear: to me it looks a lot like it's using a legitimate user need to trick people into consenting to handing over highly sensitive data. Put differently, this is a dark pattern deployed by what is supposed to be the most trusted app: the browser.
↺ 1

Thread of 2 tweets

Replying to @justinschuh and @phenlix, @bgalbs, @dinodaizovi

And you know just as well as I do that this step will get skipped through. That's exactly why it's a dark pattern: get the user to press yes and then blame them if they're unhappy with the outcome.
There is simply no possible justification, irrespective of processing purpose, to collect data this sensitive this lightly. It's plainly and simply a violation of privacy. The fact that it is done by the browser makes it significantly worse.

Thread of 2 tweets

Replying to @justinschuh and @phenlix, @bgalbs, @dinodaizovi

Well, Justin, I guess we'll be left feeling for each other. I approached this discussion with an open mind and you saw it as nothing but a trap. I hope you, too, revisit this at some distance.
There is a simple test to run here: take a sample of users who went through this experience and see how well they understood what they handed over.
I'll tell you what anyone who cares about user privacy will tell you: it's deceptive and careless to gain access to data this sensitive in this way. This further qualifies as special categories data since it's being used to detect sensitive categorisation.
Again, as parting words: you took this as adversarial from the start and read the rest in that frame. I would just like to see Google stop fucking up, because it affects a lot of us. That's not adversarial, even if I'll keep saying it loud. Good night to you.

Thread of 4 tweets

Replying to @AmeliasBrain and @ericlaw

I think that's an important facet, but it's in fact even more complicated :) It turns out that people trust small websites that don't look too professional *more*. I think we still haven't figured out what, but IIRC the effect is solid.
What concerns me here is slightly different: browsers have a special place and I think they need to be held to a much higher standard. The Web works *because* of trust, and betraying users' trust in a browser harms trust in the Web even for people who don't use it.

Thread of 2 tweets

Replying to @privacyguru and @justinschuh, @phenlix, @bgalbs, @dinodaizovi

I think Justin was talking about aggregation in FLoC, which indeed has some degree of aggregation (and whether that is protective is indeed an open question). The sync data isn't aggregated.

Replying to @privacyguru and @justinschuh, @phenlix, @bgalbs, @dinodaizovi, @EFF

That's fair. Aggregation can be a PET, for instance for reporting purposes. It's true that when it involves decision-making that's much more debatable.

Replying to @LourdesTurrecha

Much agreed! Even beyond terminology, we need to be clearer on expectations. The framework Google is using there is that Chrome is "first-party" (Justin says as much in the thread). But it's not: it's the user's agent. Expectations are very different.
Same with the "this is valid consent" reaction. I believe Justin is sincere when he says that, but this 1) commits the user to an action they want then 2) shows some legalese with zero decoration. It's pretty clear that it's a dark pattern, but we lack standards.
The frustrating part (for me) is that the same Chrome engineers will easily identify the same tactic as a dark pattern if it were used for instance to gain access to a device feature like location. I would like to figure out what standard I could write to get past such bias.
↺ 3

Thread of 3 tweets

Replying to @LourdesTurrecha and @hartzog, @ariezrawaldman

On the policy front, I do believe that a fiduciary framework (very much of the kind @hartzog has outlined) specific to user agents would go a long way while being a lot more narrow and easier to assess and enforce than broader information fiduciary proposals.
↺ 1

Thread of 2 tweets

Replying to @LourdesTurrecha and @hartzog, @ariezrawaldman, @PrivacyTechRise

From a market perspective the difficulty is that cheating pays. Google can use the Chrome data for instance to enhance Search. That alone can justify putting more money into it than anyone can compete with.
To be clear, I'm not saying this to say we shouldn't try! At the very least we need good market offerings ready for when the law kicks in 😁

Thread of 2 tweets

Replying to @padolsey and @jason_kint

Every other browser supports this feature with end to end encryption so the owning company cannot see the data. Google's decision to grant itself access is not for a better UX because they don't need it.
↺ 1

Replying to @padolsey and @jason_kint

No, the whole point of E2E is that it's your eyes only.
I'm so ready to have a @linamkhan confirmation party.
Quoting a tweet by @jcartillier ↗
Periodic reminder that just because the Dunning–Kruger correlation has been called into question does not mean that Dunning–Kruger individuals do not exist.
↺ 1
So, am I getting this right that no one at Google thought it might be a good idea to check if FLoC and FLEDGE could legally run in Europe before embarking on this project?
↺ 25
"Google’s planned changes address (…) the Peeping Tom theory of privacy, (…) the right to not have random strangers snooping on you. This is a totally inadequate definition, because it overlooks the collective dimension of digital privacy." wired.com/story/google-f…
↺ 5
I think @GiladEdelman tees up a very crisp summary of the noise coming out of Google about privacy: it is a shift from not caring about privacy to "privacy theatre". But so far we've seen very little in terms of meaningful change.
When Google announced its pivot to privacy, I thought they would at least signal some, likely imperfect, changes to their own practices. How else would the project have any credibility? Instead, all I've seen so far is denial that they're doing anything even slightly wrong.

Read the whole thread: 7 tweets →

Replying to @alextcone

I know but "we don't know" and "we won't be running tests there" is a pretty strong signal.

Replying to @davegehring

It's what Michael just said in WebAdv.

Replying to @Chronotope

"We don't know if this is legal but we think it's the way forward" is a very weird take, TBH.

Replying to @riptari and @Chronotope

Not doing origin tests is already a problem (especially since the market works differently), but not even knowing if it could eventually have a legal basis on which to run seems like a strange position to take?

Replying to @null and @KarlXOblique

I get that, but this is being pitched as a replacement for 3P cookies. At the very least "we are comfortable running it there, but you should of course talk to your own lawyers" would be different from "we just don't know".

Replying to @null and @KarlXOblique

I'm not saying that their intentions are corrupt — but what happens if later it turns out that it's not compatible with the law?
Just speculation but: the current FLoC experimentation involves Art9 special-categories processing (to detect potentially sensitive cohorts) on data collected by Chrome without the consent to match. That might block testing?
So, am I getting this right that no one at Google thought it might be a good idea to check if FLoC and FLEDGE could legally run in Europe before embarking on this project?
↺ 25
↺ 2

Replying to @lukOlejnik

Right — and that could explain why it's planned at a later date.

Replying to @publictorsten

That's why I had suggested that the folks who complained about ATT to @Adlc_ should focus on Apple's privacy practices and not on trying to get IDFA back.
This slide from @hartzog captures well why I would like to see browsers (and other user agents) held to fiduciary duties. Browsers are not just any other app — users are in a particularly vulnerable relationship and rely on their trustworthy mediation.
↺ 10
That's different from apps in general. To quote Tamar Frankel: "It is wrong to injure anyone. But it is more reprehensible to injure someone who cannot protect himself, as an entrustor in a fiduciary relation is." That's the standard to which user agents should be held.

Thread of 2 tweets

Replying to @null and @eyesondesign00

That's certainly one theory. "This is the way we'll do it." "But it's illegal." "Well, if we can't do it then publishers die." "Oh, well, go ahead then!"
↺ 1

Replying to @fatemehx2

I prefer doing it the Facebook way: say you signed that as a contract when you installed Chrome, then use contractual necessity :)

Replying to @marshallvale

I understand that, and thanks for reaching out, but from what I see market behaviour in ads is quite different in the EU and US. So just testing the US doesn't seem like it's helpful for a solution intended to be global?
↺ 1

Replying to @null and @catsoo, @alextcone

I don't think that the W3C has a preference to keep legal and product considerations out, though it's true that engineers do tend that way.

Replying to @marshallvale

That's good to hear. But this would put proving that FLoC works there in (optimistically) Q3? That means it won't be ready if 3PC are out of Chrome in early 22. I'm trying to avoid a repeat of GDPR where Google gave a disruptive (and self-serving) shift with just weeks left.

Replying to @tsmullaney

Thanks for editing this, we need this kind of work. This could be a journal 😁

Replying to @tsmullaney

That would make total sense. The fire is everywhere.

Replying to @tsmullaney

I've been wanting to say that forever but somehow always with clunky longer sentences, so I grabbed it!

Replying to @vneldurg

Since it's a multiparty system, the technical name is a clusterfloc ;-)

Replying to @JulesPolonetsky and @hartzog

I'm aware of the critiques (notably from Lina Khan) and in many cases I agree that they point to issues that need to be addressed. My thinking around a fiduciary UA regime is intended to be a narrow but effective first step in the area.
It's narrow because user agents are relatively few, they operate closer to the user (more enforceable), and present a clear architectural position. Effective because that where most of the data enters the system, and because they can develop rules to react to threats.
You ask about ads: people are generally not worried that ads exist, they are worried that ads 1) invade their privacy, 2) cause security issues, or 3) use too many resources or are annoying. All three of these aspects are being increasingly policed by browsers. As should be.
At heart, this addresses the issue that there is no one is the user's corner. In a world of automation, users are entitled to having an automated system in their corner. This is a much better governance architecture than the current system in which tricking the user is key.
Anyway — this is a *much* longer discussion. I have ~8,000 words of really terrible writing on this that I need to clean up and then have torn apart by smarter people :)

Thread of 6 tweets

Replying to @JustinBrookman and @JulesPolonetsky, @hartzog

I agree (which is why I find a lot to like in your model law), but if you approach this from the technical architecture point of view, UAs have a staggering amount of power, and they can be self-dealing in more ways than one (not just data).
Looking at purpose, extent of delegation, and what protections users have wrt UAs we see that: purpose is all the thing you do online, delegation is full mediation, and protection, well, do you have any idea what your browser does? The risk of abuse is very high.

Thread of 2 tweets

Replying to @JustinBrookman and @JulesPolonetsky, @hartzog

Oh, I absolutely love @linamkhan's takedown of the Balkin take on information fiduciaries. Just the idea that they would be voluntary strikes me as enough to discard it. It's the opposite of "trust us," it's "we'll be trustworthy, or else…"
James C. Scott explains that the information that power collects about the world in turn shapes the world to fit the framing the information creates. Does this interaction have a name and additional literature? It might be "reflexivity" in Giddens, but I'm unsure.
↺ 1

Replying to @JulesPolonetsky and @hartzog

These decisions have often been made outside of courts — but they have been made. There is precedent in SDO discussions, it would be interesting to bring it into the fold.
In this specific case, I'm not sure that fiduciary is a punt. The problem with legislating the browser is that it risks making it a ground of shared ownership. You end up with crazy ideas like if the site gains consent for something then the browser must honour it.

Thread of 2 tweets

Replying to @PhilHoldsworth

Did you read it in English? I've read some Baudrillard before, in French, and I found the experience to be quite painful, sadly. Some authors get clearer with translation, maybe that's his case?

Replying to @jackbalkin and @JustinBrookman, @JulesPolonetsky, @hartzog, @linamkhan

Jack — I think maybe I'm reading some of your position wrong then. For example, in Grand Bargain there's a lot about "companies would promise X" which I read as falling very much into accountability & self-reg. We've had ~20 years of self-reg in adtech and it hasn't been great :)

Replying to @jackbalkin and @JustinBrookman, @JulesPolonetsky, @hartzog, @linamkhan

Thanks, I hadn't seen that one yet (not being a scholar myself, much falls through the cracks) — I'm developing a view on how those criticisms could be addressed for a narrow scope, so I'm interested in seeing how you come at it.

Replying to @seanmmcdonald

I like the metaphor! The Overton Windows tend to collapse into one (or, rather, two). And they have to align to the grid.

Replying to @cynddl

It's in Seeing Like A State, but like much of what he says it's sort of spread out across the book. I'm not sure I could identify *the* section in which he says that.

Replying to @murakamiwood

Wow, just quickly scanned through the ToC of "The New Social Control" and bits of "Periopticon: Control Beyond Freedom and Coercion –and two Possible Advancements in the Social Sciences" and this looks wonderful — thanks! Sigh, there's just so much to read!

Replying to @danlatorre

Thanks a lot, this looks great. What I'm eventually interested in is: if instead of having thousands of media we have just one or two entities mediating our access to all media, at what point does it shape us much more than we can shape back.

Replying to @PhilHoldsworth

Hahaha, good point, I'll give it a shot.

Replying to @mikarv

Thanks, I have somewhat distant knowledge of that area and it's great to have a reference to dig into it! For what I'm looking at, we might say we have the bureaucracies of Big Tech setting targets based on what they *can* measure, and then gaming those.

Replying to @danlatorre

I agree that has played a part of it, but big tech worsens it. Even with monopolies, editorial positions are subject to some degree of public checks and balances. When editorial positions are hidden, that's gone. So YouTube is worse than, say, Fox.

Replying to @mikarv and @npseaver

Wow, I think this is perfect, thanks!

Replying to @murakamiwood

Found it: sciencedirect.com/science/articl…. Thanks, I'll read that too!
You went into tech because you didn't like politics. Now you have two problems.
↺ 40

Replying to @consttype

Is it though? I'm not at all an expert, just scratching the surface, but he seems to hold that these choices then feed back into the knowledge. (I agree this may not be collective enough.) Foucault: this probably falls under governmentality, but my Foucault is very rusty!

Replying to @rigow and @JustinBrookman, @JulesPolonetsky, @hartzog

It's not just enforcement, it's also the standard of proof. If you have well-funded UX folks and massive A/B testing you can build a bad faith UI that funnels users without it looking like one to any easy standard of law. No amount of DPA guidance can beat that gaslighting.

Replying to @alextcone

That's the key to being good at tech!

Replying to @theRealHashbron

Hahaha, sorry!

Replying to @edasfr

Well that too, yeah.

Replying to @keithporcaro

I agree! It's good, and it's definitely in the same neighbourhood. But it doesn't have a name for the concept I'm looking for. (And don't worry about knowing the literature well — people can only know so many fields and this crosses many, and personally I know nothing.)

Replying to @rigow and @JustinBrookman, @JulesPolonetsky, @hartzog

Gaslighting isn't the same thing as an abusive clause. You can build a UX that's 100% compliant with guidance from GDPR DPAs that is nevertheless deceptive. You trick people and if anyone complains you can claim they're crazy, they had clear choice.

Replying to @rigow and @JustinBrookman, @JulesPolonetsky, @hartzog

Sure — but that's exactly where we're at. Since Chrome added precisely that type of consent dialog we've now transitioned into a world in which fake paradigms of "consent" in adtech have spilled into the browser.

Replying to @swodinsky

Haha, and you're, like, covering the Hill now.

Replying to @bgalbs

I think that good & reasonable people can strongly disagree *because* the tweet is right! 🍻 We're defining the structure of tomorrow's society, and not everyone agrees on how to produce good outcomes.

Replying to @null and @MichelHenri_

Un ami, qui te veut du bien ;)

Replying to @TzviyaSiegman

I'd be honoured 😁

Replying to @davesgonechina and @FryRsquared, @NewYorker

Thanks, definitely reading that!

Replying to @LourdesTurrecha and @daniellecitron, @ma_franks, @CCRInitiative

If someone sends you unsolicited porn and you publish it, is it really nonconsensual porn?

Replying to @LourdesTurrecha and @daniellecitron, @ma_franks, @CCRInitiative

I know, I'm giving in to evil temptations to make it defensible when it probably isn't... 😇 Maybe there's an argument that sharing indiscriminately with strangers is akin to publishing?

Thread of 3 tweets

Replying to @julien51

My, Julien, do I *wonder* what other cool NFT project The Times should embrace! (Seriously, though, maybe we should chat about an update?)

Replying to @julien51

Replying to @slightlylate

Aren't you, though?
This is perfect.
Quoting a tweet by @JulesPolonetsky ↗

Replying to @JulesPolonetsky and @TooDistracted

What's wrong with you people, I eat the oatmeal raisin first!

Replying to @omertene and @JulesPolonetsky, @TooDistracted

I didn't even know it was healthy! I just like that they're nicely chewy and the occasional raisin sends a little jolt of fruit. It's like a munchable Skinner Box! ♥ 🍪

Thread of 2 tweets

Replying to @tim_libert

And that's not entirely bad, but we're talking about events that took place mostly in Italy and France here. What else would you expect?

Replying to @macsym and @maxleroy89

And wine helps with both.

Replying to @kathyvsinternet

There are worse ways to start a new regime 😁
I don't think I've ever signed up for as many mailing lists as fast.
↺ 1

Replying to @sofiadmateus and @Ostrom_Workshop

↺ 1

Replying to @RebeccaSpang and @IUBloomington

I think you should brag ;) It's wonderful that people get to have day jobs working on all this, I'm totally jealous!

Replying to @TooDistracted and @JulesPolonetsky, @omertene

On this at least we agree — and muffins are altogether too often the stuff of disappointment. For tasty, enjoyable, and healthy snack I recommend a piece of toast with Marmite.

Replying to @IEthics and @omertene, @TooDistracted, @JulesPolonetsky

The hard part is knowing what to drink with this "No teas & chais" regime.

Replying to @coolharsh55 and @salome_viljoen_

You can look at structural problem as an economy grounded in data extraction, and personal choices are the contention that consent can somehow fix that — just like how recycling your trash will somehow fix the climate crisis. It's beautiful in generality 🥰

Replying to @wbm312 and @coolharsh55, @ramosbugs

I could be wrong but I believe that if you don't need consent, the notice requirement can be fulfilled by squirrelling that info off into your privacy policy or cookie policy (where, frankly, it belongs).

Replying to @logicavity and @wbm312

Cookie consent is not about cookies, anything that can serve a purpose equivalent to that of the cookie is in scope.

Replying to @wbm312

In theory, the ePrivacy Regulation *could* fix this. I would be more than a little surprised if it did, but it could.

Replying to @lilianedwards

Those are my favourite panels.

Replying to @wbm312 and @coolharsh55, @ramosbugs

Sure, but no one reads modal popups either so I don't think that makes much of a difference 😂 But it's true that there's always California, the Land of Never-ending Notice. I still hate that the Regs forced us to show a notice after DNS, instead of just opting out right away!

Replying to @wbm312 and @coolharsh55, @ramosbugs

For notices, I think you get greater mileage from rewriting your PP to be readable (which we tried to do) than by pushing them in front of people. At least that way the people who want to know have something to work with! Tot. agreed on regulation! No 3P controllers for starters!

Replying to @wbm312 and @coolharsh55, @ramosbugs

I would even say good privacy people across the board, not just lawyers - it's not just the law that's full of grey goo 😁

Replying to @wbm312 and @coolharsh55, @ramosbugs

I didn't mean to say that PP was the only option, just that modal dialogs were a bad one. If I had the time, I'd love to work on a design system, just like for UI in general, but specifically for all the various ways to show notice in flow, in context, as hints, etc.

Replying to @wbm312 and @coolharsh55, @ramosbugs

100% that's what I meant by design system. I think it could be a great how-to resource. Apart from the time factor, someone who sucks a lot less at design than I do would be good.
"honestly, what is more exciting than a major shipping disaster with no reported injuries or oil spilled?" Amazing article about the boat.
Quoting a tweet by @robhornick ↗
↺ 1
Je ne dis pas qu'il y a forcément un lien de cause à effet, je remarque juste que à chaque fois qu'on a fait barrage au FN/RN, on s'est retrouvés avec Chirac président.

Replying to @tobie

En même temps, depuis Mitterrand je n'ai pas souvenir d'avoir eu autre Président de la République que Chirac.

Replying to @montezumachavez and @craigaatkinson, @TechnicaZen, @PrivacyPrivee

Happy to, of course, though it's a very small ought 😁

Replying to @innovimax

I think that's related, but here it's more how the power to measure (from eg. the state) affects how people define themselves.

Replying to @joejerome and @jeffjarvis, @HillaryClinton, @OnwardTogether, @accountabletech

I would add: they're not calling for a ban on targeted advertising but on surveillance advertising, which is different. There are excellent ways to target without surveillance. The current model structurally advantages big players, it's highly detrimental to media.
↺ 1

Replying to @joejerome

I worry, though, about the focus on advertising instead of surveillance in general.

Replying to @jeffjarvis and @joejerome, @HillaryClinton, @OnwardTogether, @accountabletech

I'm not covering this topic, I work on fixing it precisely so that the media may have a future.
But to answer your question, no state actor has ever had comparable capabilities. For instance, having full knowledge of your entire online activity goes a bit further than cutesy euphemisms like "cookies" or "pixels".
And, even if it weren't insanely dangerous to have this data collected (which governments too can and in fact do use), it's inherently tilted in favour of Big Tech thanks to network effects in the valuation of data. This means that publishers can never compete in ads. Ever.

Thread of 4 tweets

Replying to @joejerome and @jeffjarvis, @HillaryClinton, @OnwardTogether, @accountabletech, @TechPolicyLab

I wasn't aware of the term "ADINT" but it's entirely correct. It's a good description of the data that ICE buys for instance.

Replying to @jeffjarvis and @joejerome, @HillaryClinton, @OnwardTogether, @accountabletech

If working to make sure there's still such a thing as media independent from big tech ten years from now is "very clear corporate interest" then you better believe that I have very clear corporate interest.

Replying to @jeffjarvis and @joejerome, @HillaryClinton, @OnwardTogether, @accountabletech

NYT Open is the blog of the business side, it's not reporting and the people who write there don't "cover" topics the way reporters do. I thought you would have some understanding of this.

Replying to @jeffjarvis and @joejerome, @HillaryClinton, @OnwardTogether, @accountabletech

That completely sidesteps the point that no government has surveillance capabilities to match these. No state actor has your location 24/7. No state actor has a log of your entire browsing history.

Replying to @jeffjarvis and @joejerome, @HillaryClinton, @OnwardTogether, @accountabletech

Targeting is an efficiency outcome. There are many ways to achieve it. I may know that a given page is read overwhelmingly by women 35-50. Advertisers can target that without knowing anything about the people who get to see the ads.
Surveillance is a method. Applied to advertising, it involves knowing as much as possible about individuals. Typically, this uses shared ids (that also match PII if that's your concern) and knowledge about behaviour eg. across all sites, across all movement, or all purchases.

Thread of 2 tweets

Replying to @jeffjarvis and @joejerome, @HillaryClinton, @OnwardTogether, @accountabletech

I don't understand how email address (and maybe name?) is more information than your precise location at all times?

Replying to @jeffjarvis and @joejerome, @HillaryClinton, @OnwardTogether, @accountabletech

I'm sorry, but you might benefit from actually understanding this topic before wading into it with such certainty. This is just a purely uninformed statement.

Replying to @jeffjarvis and @joejerome, @HillaryClinton, @OnwardTogether, @accountabletech

Sure, hey, I can list authoritative things I've done too. But let's just look at a simple, technical part of your very confident statement: how could a typical programmatic player, say a header bidder, not know what you read since it's right there on page load?
I would further note that the context here is specifically about big tech. Programmatic has issues but there are ways to fix them. But Chrome will, for most users, share full history to Google just so they can use it (other browsers encrypt it so they can't see it).
↺ 1

Thread of 2 tweets

Replying to @jeffjarvis and @joejerome, @HillaryClinton, @OnwardTogether, @accountabletech

The Times doesn't have your credit card, and only what you read on The Times, not everywhere. But anyway, good night to you too.

Replying to @EvanSelinger and @jeffjarvis, @joejerome, @HillaryClinton, @OnwardTogether, @accountabletech

Thanks Evan, that's an excellent point.

Replying to @joejerome and @EvanSelinger, @jeffjarvis, @HillaryClinton, @OnwardTogether, @accountabletech

That actually goes to the heart of my concern: people are confusing targeted and surveillance. We need targeting (if we don't want to be plastered in ads) and the odds are decent we'll get better targeting through other means. But fear and misunderstanding risk throwing out both.
↺ 1
Introduce yourself as your name’s meaning: Hi, I wear dresses by the riverside!
Quoting a tweet by @vladtarko ↗

Replying to @realmaplesyrup

I could translate mine as "Robe-Wearing by the River" which could be a cool band too!

Replying to @aldengolab

That's pretty cool!

Replying to @realmaplesyrup

I think it's possible that there are several roots. I have never dug too deeply, but I've read it was a term describing people who wore robes, like monks and lawyers. Sort of like robe-dude.

Replying to @aldengolab

The dunces need wise old friends perhaps more than most.

Replying to @chriscoyier and @AmeliasBrain

I reckon GitHub could put a big warning sign on PRs that touch .workflows and the such.

Replying to @p_reynolds and @chriscoyier, @AmeliasBrain

Yup. But that would be targeted. I assume these are generic.

Replying to @null and @SimonDeDeo, @joftius

Is this not similar to Rodney Brooks's work on subsumption architectures in which robots develop non-representational maps of their environment that are coded all over the place?

Replying to @chris_bail

I agree that new field + anonymity likely both contributed, it would be interesting to tease the two apart. I've been worrying about contexts with respect to privacy, to think about how having everything in the same space confused expectations of privacy, but they may go beyond.

Replying to @chris_bail

Yes! I like the idea of having a SO for politics, my worry is that the feedback loops are too long. SO works because you can test the answer right away, for policy, well... It's possible that Wikipedia is a better model than GitHub, it has the bureaucracy such a project needs.

Thread of 2 tweets

Replying to @justinph

Heh, I don't know that it's not too technosolutionist to work! But there's some indication that it may be operating for Wikipedia: nature.com/articles/s4156…

Replying to @chris_bail and @DzGuilbeault, @joshua_a_becker

Damn, it's almost like humans are subtle and complex or something. That said it would seem to align: if you bring labels from another context, you'll get effects from that context too. Wikipedia is nice in that user pages aren't very detailed.
It's great to see @FQXi switch to @discourse! I think I've been waiting for that for... five years or so? 🥰

Replying to @FQXi and @discourse

Too late — I know the Discourse platform well enough to see that the email was legit and already set my account up over there :)
This is a great explainer on ventilation to protect against Covid transmission, but I can't help noticing that the CO2 ppm levels they report as typical in cars after just a few minutes are ones that lead to significant mental impairment. Is this not a problem?
Quoting a tweet by @cwarzel ↗
↺ 1

Replying to @mhintze and @daniellecitron, @hoofnagle, @liorjs

It's made in the dark, though I don't know if there's a pattern to it 😁 Having said that, dark patterns need not be intentional. It's not rare to see them used by people who don't see that they are deceptive.
Has anyone gone through this suit in detail to see what legs it has? I would, but 620 pages of legalese require more time than I have this bright morning. vice.com/en/article/93w…
↺ 14

Replying to @MaxGendler and @Chronotope, @swodinsky

Replying to @RobertJBateman and @joejerome

Thank you!

Replying to @RobertJBateman

Do you think the court could recognise that it's a sale but otherwise fail to recognise a right to PRA? Would that open FTC Section 5 issues?

Replying to @wendyndavis and @Google

Ha, I feel we've been having the same debate for years :)

Replying to @swodinsky and @MaxGendler, @Chronotope, @alex

There's a lot of lobbying around the idea of "selling data" being a farce, but I'm not sure it's as much of a farce as it's made out to be?
A few interesting notes on cookie syncing.
Quoting a tweet by @thezedwards ↗
↺ 2

Replying to @null and @UlyssesPascal, @thezedwards, @b____j_____, @Chronotope

With better data, Facebook bids higher and does not need to make a competitive offering to Google's.
Excellent thread from @yegg. In addition to what he says, if you use Chrome with the DuckDuckGo extension you are still not protected from Google's tracking unless you also disable history sync in Chrome, or switch to a browser that doesn't corral you into being tracked.
Quoting a tweet by @yegg ↗
↺ 13

Replying to @null and @UlyssesPascal, @thezedwards, @b____j_____, @Chronotope

On Chrome, they're getting the data anyway! There's a point at which it doesn't make much of a difference anymore.

Replying to @swodinsky and @MaxGendler, @Chronotope, @alex

Sure, but I don't know of a single company that is sharing data for no consideration whatsoever. That would just be... weird?

Replying to @RobertJBateman and @swodinsky, @MaxGendler, @Chronotope, @alex

Exactly — it seems pretty straightforward to me? I would argue that if you are providing data to a party that isn't a service provider *and* you're not getting any benefit from it, that's just negligence :)

Replying to @nataliabielova

Yup :)
Simon makes excellent points here (which won't surprise those who read him), and I would add: beyond the direct funding of research, there is also FAANG funding of law schools (which @cagoldberglaw has looked into), journalism schools, economics, etc. It's everywhere. t.co/zbvi3FpCGU
↺ 3
Why, Slack, but of course I would be delighted to have to configure all my preferences again that you already have five times over for a new workspace. That's just too kind, you shouldn't have.

Replying to @kyotonio

They're going to end up being blocked by the chairs...
Privacy by design — wrong answers only!
↺ 3

Replying to @kkomaitis

I think the problem is also that some people want to design privacy out of the picture :)
So, the @TMobile "Do Not Sell" page (t-mobile.com/dns): • Fails in Firefox (CORS failure) • Fails in Chrome (cryptic error) • Fails in Safari (cryptic error) • Fails in Edge (503 and a bunch of issues) • Fails in Brave (resource load fail, and more) So — compliant?
↺ 5

Replying to @_vinnybod and @TMobile

It's not easy to write code that works nowhere!

Replying to @ashk4n and @TMobile

Ha — hadn't seen that! In their defence, I tried to add a new line to my current account and nothing worked with that either. I ended up having to set my daughter up with a different operator. So this could in fact just be sheer incompetence :)
I'm curious what others understand from the updated CWV FAQ. support.google.com/webmasters/thr… What I get from it (but the usual non-committal style makes it fuzzy) is that AMP remains artificially boosted since it's measured with CWV preloaded/prerendered. So CWV seems to fix nothing?
↺ 2
Great article from @bxchen reviewing some browsers that are pushing the envelope on privacy. (I'd also love to see @wirecutter go deeper on this.) nytimes.com/2021/03/31/tec…
↺ 5
Which of these incomprehensible buttons is the one you prefer to angrily bash a dozen times in a row until the problem stops?
↺ 2

Replying to @tim_libert and @bxchen, @wirecutter

I think that bringing ads closer to the browser and sharing some of the profit directly with users are very good directions of travel.

Replying to @simevidas

OMG this is... I don't even know what to call this. I guess it would be hilarious if it weren't bad in real ways that affect real people. @ashk4n is there precedent for simultaneously breaking ADA and privacy law?

Replying to @matthewstoller

Oh is there an iCloud version of this too? I don't use iCloud so I wouldn't get that. Sounds fun!

Replying to @Leah_Nemeth and @matthewstoller

It gave up.
Alternative data governance is the data future worth wanting.
Quoting a tweet by @katyaabaz ↗
↺ 1
Hey, look what came in the mail!
↺ 1

Replying to @pvineetha and @erikphoel, @70sscifi

I think it's even nerdier than that.

Replying to @erikphoel

I'm super intrigued to read it!