May 2021
315 tweets
I would add that carpenting is a form of technology. The scale of carpenting, however, mostly makes it less impactful. See the Winner reference in my thread for a bunch of great examples.
It's very difficult to avoid. Using ads? Building content for a platform? Applying ML? Not prioritising accessibility? Using so much JS your site only works for the richest?
Tech is what's most changing the world. How we choose to change it is politics.
♥ 1
That was the event that triggered it, yes, but he also wrote a long thread about it that had other considerations.
♥ 1
De rien! Curieux de tes retours si tu en lis!
♥ 1
I agree it's unfair. Prior to Apple's changes there was almost no such thing as first-party data that you don't also have to share with Facebook and Google. Now there is some. Is it enough? Nowhere near. But it's concrete progress.
♥ 2
It doesn't hurt to let those parts of the brain lie fallow! I still code for fun from time to time, it's nice 😁
♥ 1
It's just that the cover designer is in their 40s.
♥ 4
Well, we knew it was coming...
The Consent Dialogs Are At It Again
♥ 3
@ntnsndr nails it: when we provide access to a capability but do not offer governance and accountability for it then we're not democratising anything, we're paternalising it.
♥ 29↺ 8
Thanks! That looks very much like the issue I need to solve, I'll definitely read these closely too!
♥ 1
I'm only ~50pp in but so far I'm nodding a lot. Coop models are largely absent in the existing organisations that support internet governance, I think there's opportunity for change!
♥ 4
"Admins, Mods, and Benevolent Dictators for Life: The Implicit Feudalism of Online Communities", by @ntnsndr.
mediarxiv.org/sf432/
A nuanced look at the way in which we build anti-democratic patterns into our digital systems, leading to a proliferation of benevolent dictators.
♥ 17↺ 3
"Nuanced" because it doesn't say "feudalism bad". It may work well at highly embedded levels (where there's accountability because you can tell it to their face) or in early stages (where you can just exit because there's little investment or entrenchment).
♥ 1
The work that the @W3CAB is doing to establish a Director-free model to prepare for the post-Tim era, 25 years into the org (and probably a good 15 years later than ideal) shows how hard building democratic models is.
♥ 3
Fostering institutional diversity should help us build these muscles, but I would hesitate to ask the big platforms to enable it. They thrive on scale and diversity (of anything) is precisely what they are the worst at. It's scientific forestry all the way down.
♥ 2
One difficulty in getting institutional diversity is the widespread belief in tech that there is a single optimum in the landscape and that it can rationally be attained. They see not feudalism but meritocracy, more like Veblen's Soviet of Technicians.
♥ 3↺ 1
Is it not rather that they are governments (in at least some sense, but not an entirely fictitious one) and therefore autocracies?
The only thing that I've found to be clear on today's WebAdv call is that the "Partnership for Responsible Addressable Media" officially does not have any definition of "addressable" or "responsible" that they will agree to stand behind.
♥ 10↺ 1
"Automating the audience commodity: The unacknowledged ancestry of programmatic advertising", by @LJamesMcGuigan
This draws the ancestry of programmatic all the way back to the automation of TV buying six decades ago. It's super interesting.
journals.sagepub.com/doi/10.1177/14…
♥ 12↺ 2
One fascinating aspect that this reveals is that programmatic isn't a *consequence* of the Internet; rather it has been shaping the Internet to feed a much older beast that seeks to commodify people and publishers.
♥ 2
It's important to understand this history to keep a clear head in discussions about the future of advertising.
Advertising is a key business model of the internet, perhaps *the* key business model here. But it can be done in many different ways that are different optima.
♥ 1
Today's programmatic isn't "the business model of the internet", it's using the internet to deploy an older business model designed to empower agencies.
We should keep this in mind to design a system that empowers the actors we feel should be empowered.
♥ 5
I'd love to hear more about that! (The marketing ethics bit — I know about the transparency part ;)
♥ 1
I'm in Princeton now! But sometimes we hang out on the video things 😁
In his @ObfuscationWS video, @mikarv makes a great case about the risk of on-device ad targeting using the excuse of confidentiality to open the door to a data free-for-all.
It's comparable to DRM in that you cede sovereignty over your own device.
3rd.obfuscationworkshop.org/exhibition/mic…
♥ 8↺ 1
also mentions the need to include browsers, user agents, etc. in our regulatory thinking. Here is a first draft of my humble contribution to that: papers.ssrn.com/sol3/papers.cf…
♥ 19↺ 4
Tu peux aussi y aller franco avec une <table> direct dans le source!
I'm not claiming that I have an answer right now for this specific case, but the idea that the only sources of governance here would be either governmental or self-regulation is part of the problem. There are other governance models.
There are plenty of difficult questions: who would be the legitimate stakeholders, how do we ensure they commit the resources, what participatory power do they have, etc. but there are examples of other approaches and it's worth thinking about better alternatives.
Ah, ça me rappelle quand j'essayais de faire marcher des tableaux d'articles scientifiques convertis automatiquement depuis Word sur un écran mobile. Fun times — ça me manquerait presque. (Presque.)
I really couldn't commit to anything specific since I haven't thought about the Facebook case enough to make a very specific proposal anyway :) But my core point is that alternatives exist, so I can at least share some examples!
There are quite a few non-gov non-corporate governance examples in "Governing the Commons": bookshop.org/books/governin…
Most are for different things but the principles are interesting. There are ways to consider an "attention commons" and govern that, for instance.
♥ 1
There's also a whole set of examples in Our To Hack And To Own: orbooks.com/catalog/ours-t…. I'm still reading through this book, but again that's a whole bunch of approaches to governance that fall outside the state-or-corp model.
♥ 2
More broadly, there are relatively large-scale governance bodies that operate on different models. IANA is a typical example, but also IETF or the W3C. Things like the FIFA too.
The point being: it's not a trivial problem, but if Facebook wanted to make actual progress on this, there are plenty of options that are more credible than the OB and plenty of smart people who could work on it.
And that's the second shot. Fuck yeah.
♥ 18
Exactly my dance!
This is actually a general law of governance 😁 Institution provision is a second-order dilemma, if you don't architect a way to make it happen, it won't.
No, I think they've given up on the FL part (and may even have said as much?). At the very least, the implementation is definitely not built that way.
♥ 1
Ah, thanks! Glad you liked it 😁
♥ 2
♥ 4
Go read the amazing @k_johnsn:
"That leaves companies with two options: to reactively respond any time a change is required, or to invest in privacy as part of their business strategy and dedicate resources to the task.
The Times has chosen the latter."
open.nytimes.com/how-we-manage-…
♥ 18↺ 8
Ha! I just texted my wife two consecutive pictures of our cats sleeping in my lap 🐱😂
♥ 2
Hey, happy to discuss details offline (not discussing legal questions in public without myself being a lawyer, irrespective of whether I think them defensible, which I do)!
♥ 1
Have you noticed that Big Tech is pretty bad at any form of governance, but you're not entirely sure that regulation can be made to work? There are other ways.
Quoting a tweet by @ArthurSmid ↗
♥ 7↺ 3
I'd totally watch/read that.
♥ 2
Wow, thanks a lot Michael! If you have feedback, I'll very gladly take it. This is the first draft, I am completely faking any competence in legal scholarship, and I'm not even sure what to do with it :)
Thank you!
♥ 1
I recommend reading the piece at the top of this thread in general, but not for the fiduciary UA part. I have a draft of my ideas over in there: papers.ssrn.com/sol3/papers.cf….
It's a very early draft and I don't know what I'm doing, I'd love feedback :)
"Just 4% of iPhone users in the U.S. have actively chosen to opt into app tracking (…) based on a sampling of 2.5 million daily mobile active users."
This is what "transparency & choice" looks like when it's designed to actually work. macrumors.com/2021/05/07/mos…
♥ 130↺ 49
I'd like to read a study of who those 4% are and what made them make that decision.
♥ 14↺ 1
Tout un monde qui s'effondre!
♥ 2
Presumably errors can work both ways and might cancel out, though.
♥ 1
Most of those apps don't have an identifier to use for that, though, so it's unlikely that there's that much tracking?
♥ 1
In all studies there is usually a group that says "sure, take my data if I get something". It could be that, but I don't think users see the trade here (because there isn't one). I suspect this is "I don't care" users clicking whatever to get through.
♥ 1
One thing that's particularly interesting here is that it provides a statistical baseline: if you are getting opt-ins significantly higher than this, you're probably using a dark pattern.
"Just 4% of iPhone users in the U.S. have actively chosen to opt into app tracking (…) based on a sampling of 2.5 million daily mobile active users." This is what "transparency & choice" looks like when it's designed to actually work. macrumors.com/2021/05/07/mos…♥ 130↺ 49
♥ 23↺ 7
Very good point.
♥ 1
Right, but the IDFV is (mostly) first party.
I think that one is complicated, but I would say probably yes.
♥ 2
Programmatic ads are usually pretty crap anyway, so I'm not convinced that we'll see that big a switch. Studies of the impact of removing trackers on perception of ad quality usually don't break direct/PG/open apart so I don't think we know that there'll be an impact here.
♥ 2
My (anecdotal) personal evidence from preventing tracking but keeping ads on is that my ad experience actually improved. Ads that are contextually relevant are much more pleasant.
♥ 2
I usually understand "tracking" as short for violation of privacy. That can happen with 1P of course, but unlike 3P it's not the default.
♥ 3
He RTed me once! But a lot less cool than yours.
"Goliath: The 100-year War Between Monopoly Power and Democracy", by @matthewstoller. A struggle for power of epic proportion with a big cast of larger-than-life characters. It's like Game of Thrones except that more people die and it really happened.♥ 31↺ 9
♥ 1
But most apps don't have it is my point (also on iOS, Apple makes it easy to give a fake one).
I'm sorry Maria but for once I'm going to have to disagree with you. A wink+glass raised IRL is way, waaaaaaaay cooler than an RT.
♥ 1
You can only have an exchange if both parties understand the terms and implications of the trade. I don't think that that's even approximately possible in this case, so the "exchange of value" idea isn't really doable.
♥ 1
Put differently, if data is being used as money, then it's a better idea to give people money for the data and then ask them to pay. Otherwise this is using data as scrip, which makes it an even worse idea than paying people for data :)
I think it's somewhat more flexible than that, but the clean room case is a bit more borderline. If done correctly (which needs proving) it's closer to 1P.
♥ 3
Agreed. I think the exercise of converting data to money mostly has the value of showing that this isn't a great model overall.
IANAL, etc. but hashed uploads I think is a definite no. But methods where there's an audience match without revealing audience membership to a third party I think are fine.
I think it's fuzzy, but if others link to you the situation is different from if you link to others — I think.
I don't know how it works, I don't have an iOS device :)
Not just Americans, I mean... this is what GDPR consent should look like, but it really doesn't.
I think it's more complicated than that. The FIPS, that ground procedural opt in regimes like the GDPR, were heavily developed in the US. But then you started getting shrinkwrap terms where opening the box opted you in.
This quickly became "by using this site, you are agreeing to the terms" which is actually a form of opt in. It's an insane variant, but fundamentally it's just as rotten as the European version, only more streamlined…
I know, I've seen it, it's progress, though the problem then becomes that what you can do under the refusal state is way too limited — much more limited than what Apple supports. This is DPA territory though, it can be fixed without changing the GDPR.
Many thanks to the team behind the @ObfuscationWS, it was an amazing event and one of the best I've seen under Covid constraints. So many great ideas!
This is probably the last thing the organisers want to hear right now but I really look forward to the next one!
♥ 6
Deep thanks as well to @hackylawyER for moderating and @megyoung0 for chairing this morning's session! I really enjoyed the conversation and I hope others did too.
♥ 4
This is what longing for user agency looks like. t.co/f66uyVwhl9
♥ 8↺ 1
Hell of a hangover from that over here.
It wasn't a thing with my daughters, easier to tell the cat's cries apart!
♥ 1
Ha, I like the idea.
♥ 1
The first draft of "The Fiduciary Duties of User Agents" made it into the top ten articles in its category this week on SSRN. Go read it to find out why!
(Granted, there are higher bars to clear, but it's still a nice email to kick the weekend off with!)
papers.ssrn.com/sol3/papers.cf…
♥ 6↺ 3
Thank you my friend! Soon a draft improved with your feedback!
♥ 3
I always paste it from a previous script. I'm not sure what will happen if I ever find myself without a previous script to copy from. I'm not sure how I came by the first script either. I assume a future me travels back in time to drop it on my drive circa 1996.
♥ 2
I can't tell if you see that as a bad thing or not 😂
♥ 1
After the Privacy Sandbox, Google is working on Privacy Balloons. Our reporters caught the chilling moment as it readies to pounce on an unsuspecting employee who left some cookies lying around. (ht nytimes.com/2021/04/30/tec…)
♥ 31↺ 2
It's for privacy Hannah, of course they look like big threatening jellyfishes.
♥ 1
This is a very important point: free speech isn't something that you decree a right and then you're done. You need to dedicate significant social structures to make it work in practice. Postal subsidies is a great example. 👇
Quoting a tweet by @glakier ↗
♥ 2↺ 1
Delivery subsidies are one tool that solved a specific issue to do with the cost of delivering physical items at smaller scales. They worked in concert with any number of other interventions (including, eventually, trustbusting the AP.)
♥ 1
Today's problems are different. Many have to do with the destruction of value, governance, & knowledge at scales smaller than global ("disembedding"). We need solutions to match, and ones that work at a time when states are institutionally weak & corps strong. Interesting times!
♥ 2
I want to put a canonical definition in a Web standard document so it can serve as technical reference for all. Help welcome 🙂
♥ 6
I'll take you up on that! I hope to be cleared to release a draft soon, it's still very patchy but I hope iterations can make it decent.
♥ 2
Wait, what's this bot, I want to know more.
♥ 2
Hmmm, it looks like you want AdNauseam, no? That seems old and unmaintained. See adnauseam.io. They were banned from the Google extension store (for no reason) but you can still sideload it into Chrome if you insist on using that browser.
♥ 4
It's a shame you tell me now, there was a whole conference around it last week!
♥ 2
Ooooh!
♥ 1
It's Chaff that I was saying is unmaintained!
Glad you like it! 😁
♥ 1
You don't see that every day.
♥ 2
I don't think it's the only country, it looks less cheap that way.
I might be cheating 😁
♥ 1
I know, I have a few friends and sometimes they disagree about grammar 😁
♥ 2
For scientific research, would you not stick to common practice and ground it in Belmont?
Not everything needs to be sectoral, there are structural relations that people find themselves in that can be addressed across sectors. (Which I argue in papers.ssrn.com/sol3/papers.cf…)
♥ 1
One way to answer that is to ground the question in comparable physical situations. The owner of a bookshop you frequent often would not be disloyal making a recommendation based on knowledge of your preferences acquired through previous interactions. That's fine targeted ads.
♥ 1
But if they let a third-party camera capture a facial print plus the books you buy, and that was then used to make the same book recommendation when you visit a random airport bookshop, that's disloyal.
♥ 1
No worries!
That scoping seems like, as a general rule, it would be sensible for research purposes in a way that it wouldn't for, say, credit rating?
♥ 1
Glad I could be of service 😁
I know, I accept donations.
She can, it's actually stable 😎
♥ 2
C'est marrant, mais je ne vous sens pas à fond sur les élections consulaires, en France là?
Je parie un peu sur une dérouillée de la majorité présidentielle, vu d'ici ça n'a pas l'air top en France. Mais c'est pas comme si j'avais un tas de sondages à analyser...
♥ 1↺ 1
I mean, have you been on the Internet lately?
♥ 4
I think it's worth toying a bit with the proportions. Or maybe finding the right bitter. I like it a lot but it's very smooth, it could use something to add just a little edge.
♥ 2
Cheers!
Why do people still pay attention?
♥ 3
A tool is something you can become good at. It reveals new affordances in the world.
What we call "AI" is not about building tools. Mostly, it's what the world looks like when Clippy's in charge.
Quoting a tweet by @erikphoel ↗
♥ 10↺ 1
But that's not the heart of the issue. The problem isn't ML, the problem is how it's used. The assumption is that it should replace user action rather than enhance it.
The Gmail promotion tab is actually a great example of how to get this completely wrong.
If you have Clippy sort your mail, what's going to happen is that there'll be false positives but you're never looking in that folder because it's mostly crap.
So either you have to slog through a folder of crap, or put up with losing some things you want. It's dumb.
A better way to do it would be to have Gmail's UI actually designed so it's possible to be fast when using it, and to make your own calls sorting email quickly. Clippy could add a little flag next to an email indicating likely promo — so you can kill is faster.
This, of course, would require there to be an actual UI designer involved in creating Gmail instead of a pile of engineering gimmicks in a product-like trenchcoat.
I'm not sure what you're trying to say? You can always find things used incorrectly therefore don't point out they're used incorrectly? If this were just one instance, maybe, but this is systemic: we are using automation wrong across almost all that we build. It's worth noting!
Note that the context here is promotions rather than spam. You can pick thresholds. Some egregious spam should of course just be junked. It should also be easy (rather than twenty clicks) to killfile someone. These can work together.
You're imagining a point I didn't make. Treating ML as a servant rather than a tool is a pervasive issue. I never said "get rid of it".
By default they are, which is why they create a problem.
Wait — they're sending cleartext passwords over SMS?
♥ 1
I mean, frankly, the risk remains quite limited. Worst case scenario is that someone who actually cares about this election gets to vote 😂
♥ 2
That's an excellent point. No one's going to hack this one, so it risks being considered fine.
♥ 1
I'd love to do this PhD, if only I could. I look forward to seeing what comes from it!
Quoting a tweet by @mikarv ↗
♥ 7↺ 1
Sure — but what the final customer (advertisers here) pays for and how the value gets distributed upstream are two different things.
Maybe people will pay CoffeeSpace $5 for a beet frappuccino. But how much did CoffeeSpace pay for frappuccino-grade beets?
If Robin's Chill Beets are the only beets in town (or distinctly better), I'll extract more of that $5. If Ben's Bestest Beets is also in market, whoever wins the tender will extract less and CoffeeHouse will pocket the diff. (In a perfect market it would be different, but…)
The question for advertising is: what goes into a good conversion predictor? If I have a strong conversion predictor (you're currently comparing frappuccino machines on Wirecutter), sharing that away isn't going to increase how much I can sell it for.
That's before considering that it's data, and therefore that I can sell it multiple times in parallel, which will decrease the value I get but increase someone else's ability to arbitrage the value. (What constitutes data monopsony conditions is a fun question too!)
♥ 1
Of course, that's a loss when you have conversion predictors, but if your content is interchangeable and your audience is one-and-dones, then you might benefit from the system. But all that does is incentivise whoopie cushion and content farm "publishers".
Should we care?
Well yes — contextual is just behavioural with depth=1 :)
♥ 8
Cart information isn't structured. It's easier to get shops to hand over that information by making it a competitive disadvantage if they don't. I haven't looked, but do you wanna take bets as to whether that data stays just between the user and the site?
♥ 3
I don't expect they'll document it, they know this is unfair, that users would hate it if it were made clear and that it's anticompetitive as hell.
And to be fair, neither Apple nor Facebook get anywhere near this level...
♥ 2
This is not resisting disintermediation, though, this is using market power to gain an information advantage in competing against publishers.
♥ 1
Ads in tabs can be perfectly fine, but this looks like they're acquiring intent and conversion information across the whole web. Not a fan.
There are 100% ways of doing this right. They require that all stakeholders take part in decision-making around the collection and use of this data. That's a far cry from what we have here.
Essentially, (assuming this matches previous behaviour) Google creates prisoner's dilemmas where they didn't exist before, and uses that to extract value.
The only out from PD is collective governance. If they wanted to do this right that's how they'd approach it.
♥ 1
Credit where due: it's more than an analogy, it's based on the work of Elinor Ostrom and on how the PD is precisely the failure mode of commons management.
I agree, this needs regulation, otherwise the Web won't live through this.
♥ 1
Discussions of privacy, particularly in technical contexts, are often fraught with misunderstandings and poor terminology.
With PUP, I hope to give the Web community a more robust conceptual toolbox to think about privacy and build a better Web.
darobin.github.io/pup/
♥ 91↺ 25
It's a first draft, it's got rough edges. If you're reading this more as a privacy expert than a Web technologist, keep in mind that this is written as part of a body of documents and with the goal of informing better technology and tech policy.
Comments very much welcome!
♥ 7
My NEXT one has a bird-related acronym — but I think you're going to like it. #teaser
I had been thinking we should call the ad creative format SLIC for "Safe Locally-Inlined Content" but maybe we could do BIRB for "Beautifully Interactive Resource Bundles"!
♥ 2
You're not wrong, but it was taken (by me) and I promised the dog people on my team to do a dog thing :) nytimes.github.io/std-cat/
♥ 2
Thank you! ❤️ Please send feedback!
♥ 1
I'm glad you like it; I strongly recommend reading @neilmrichards and @hartzog on this, they do the topic much, much better justice than my one-paragraph compressed rendition :-D papers.ssrn.com/sol3/papers.cf…
♥ 2
Thanks Wayne. The goal is to provide a shared vocabulary and conceptual toolbox; this is not a legal document. What people do with the law is something they should take up with their lawyers!
♥ 1
You're welcome! It's not perfect, the first party can do bad things, but it sure works well as a line 😁
I generally find that ethno-nationalist arguments in privacy fail to carry much weight. There isn't an existing legal regime that this isn't in part critical of.
♥ 1
I'm not sure what global expectations you're referring to. This isn't a compliance document.
I am *very* curious about how you come to this conclusion, because that's definitely not the case.
♥ 1
We have seen from three years of GDPR (and other procedural approaches) that consent is a great way to trick people out of their privacy. Consent is a procedure, it has no inherent moral valence. The moral goal is agency, autonomy. This procedure works poorly for that.
♥ 2
So... you would have the most invasive tier as the default?
♥ 1
But asking over and over again is in and of itself a dark pattern.
Consent is the "Linux on the desktop" of privacy. Yes, it's very empowering to be able to recompile your kernel; it's very disempowering to *have* to do it.
♥ 2
OMG I was thinking exactly the same.
It's funny — I have never thought of that part, even though I've often thought of exactly the same but for new foods.
"Oooh, love the look on those orange berries!" — Grüük, remembered fondly in the gatherer community.
was complaining about that, I told him it was entirely your fault.
♥ 2
Yeah, I mean, Nancy Kim did write a whole book about it :)
One thing that I haven't seen (but you might have, Nataliia?) is a study showing actual improvements in self-determination and understanding from consent, even under supposedly ideal conditions (let alone real world).
♥ 2
You make a good point. But they're SO FLUFFY.
It's not about *me* asking over and over again — it's about the fact that, in the course of a day, users interact with dozens of services. They will get asked over and over again, even under some purportedly ideal implementation of GDPR consent.
♥ 1
And that's the heart of the problem: we can all imagine a perfect consent flow, and it'll look like informed consent in its natural setting of for instance experimentation on human subjects. But that is a cartoonish view of user interactions in practice, IMHO.
♥ 1
I think that duties and principles can work together — other parts of the draft are more like principles, I would say. Do you think that NYPA still has legs?
I am very interested in considering duties for other controllers, but I have a less crisp idea of how to apply them.
♥ 2
Put differently: in making the duties very generic, I am unsure that we get something precise enough to use in tech design (without more "precedent", as it were). For UAs it's super clear.
But I'd love to find a way, the concepts are there to be used!
♥ 2
Ah, that's a very interesting analysis — thanks! I'm having trouble getting a read on the various data bills in NYS, it's a bit of a mess in there.
♥ 2
That's where I think duties and principles can work together. This is meant to drive intelligent consideration, and eventually precedent-setting. So not a checklist but a set of principles — that may be in tension with one another — can ground that without it being too vague.
You seem to be arguing that 1) consent should be rare, and 2) there should be browser controls. As someone who just published a draft stating that consent should be rare, and as one of the editors of GPC, I'm not sure we disagree that much?
100% agree that this has a long history — but in a different context. Informed consent works great when you're participating in one experiment at a time and an IRB-trained grad student will sit down with you to make sure you get what you're consenting to.
♥ 1
If the approach does not work in the face of how bad players will use it, it's not a great approach. If the choice is "strictly essential processing (as DPAs currently understand it) or consent" then all we can expect from that is a lot of consent, it's designed in from the start
♥ 1
We can then keep pushing for stricter and stricter UI requirements; but then you just end up with the companies that can deploy the best A/B testing getting data. Look at the Chrome Sync consent funnel — it's super close to guidance, even though any human can tell it's deceptive.
♥ 2
I just want to put greater emphasis on collective decision-making in terms of what is appropriate and make individual carve-outs inherently suspicious.
Hyper-individualistic approaches to data protection, like GDPR-style consent, put people at a disadvantage.
♥ 3
Right — GPC isn't intended to solve the entire problem, it's meant to chip away at a decent chunk. It specifically targets processing that shouldn't be consentable in the first place, at least not without having someone sit down and walk you through it :)
Honestly I'm not sure they know either.
♥ 1
I just wanted to say that I'm very thankful for your threads on this, it's heroic.
Right, which is part of the problem. You almost always have to resort to consent. The forced overuse of consent makes it impossible for people to distinguish between a huge range of processing behaviour. It all looks like open programmatic.
♥ 3
That's exactly the angle that PUP is taking. I believe that as a framework it is compatible with the GDPR, but it assumes different guidance that offloads less responsibility to people. Consent should be a red flag, not a catch-all.
♥ 1
In fact, the initial 3 tiers came from GDPR, with default being LI, essential being Art21, and the high tier being consented. But with a view that the high tier should almost never happen and that LI should be built from ethics instead of cop outs like "direct marketing".
♥ 1
Yup, though almost all the relevant processing happens off device. But you're right that the ePD constraints on local storage make it very difficult to design effective data protection that helps users more than lawyers!
♥ 1
S'il fallait une preuve supplémentaire que le vote par internet est une mauvaise idée, les élections consulaires sont là pour l'apporter. 15 onglets, 12 allez-retours de confirmation, tout ça pour dépendre au final de la sécurité de mon mail au SMS. Inutilisable et fragile.
My second shot is now over two weeks ago. The two things I want back are:
• Dive bars with bad beer where drunk people spittle at each other.
• Karaoke with bad beer where drunk people spittle at mics.
Quoting a tweet by @LAM_Barrett ↗
♥ 7
What else is life good for?
♥ 1
Awww man — it'll be back soon I'm sure!
So, because I moved the local dive is not a habitual place and I've only really been on the outside. Discovering a dive from only its patio is a weird experience.
♥ 1
A dive is a dive, I don't make the rules.
I completely understand that that was how it was designed to work. But a system that's easy to game by bad actors because they cannot be distinguished from good actors isn't a successful system — no matter the intentions that went into it.
♥ 2
My team and many others with us have spent the past four years working to make The Times use as little data and as safe processing as is possible without being a nonprofit bankrolled by a billionaire. I'll make zero claims that it's perfect or done, but it's far ahead of most.
♥ 2
We've entirely removed open programmatic, only marketing-related pages have 3P controllers and even then few, etc. Yet users perceive the UX as the same as if we have 300 programmatic partners because we have to get consent anyway.
♥ 2
Making good actors and bad actors look almost exactly the same doesn't help anyone's autonomy much. And it's not how it works in the physical world. My idea is the default tier should roughly match an equivalent interaction in a physical context, so people can decide easily.
♥ 1
What you describe is *exactly* why it's gamed by design. Imagine going to a bookshop and you need to sign a waiver so the owner can remember what books you told him you liked before he can recommend one. Then the coffee shop needs a waiver to know which coffee you take every day.
♥ 2
Then the grocer needs a waiver to pull up the order you'd asked for. Eventually the supermarket asks for a waiver to share your biometrics with a bunch of chains, it looks a little different but you're going to sign it anyway — everyone needs a waiver, the law said so.
♥ 2
The idea that making people choose more is better for their autonomy is the single biggest boon and subsidy to the data-industrial complex.
♥ 4↺ 1
Not in a dive bar.
Because what is considered "strictly necessary" is less processing than an equivalent physical interaction and less than is necessary to operate. If I wanted to give adtech trackers as much cover as possible, I would design "strictly necessary" exactly that way.
♥ 2
It's not binary — you can have default rules for retention!
Tempting!
A relatively small number of first-party, single-controller purposes, with limited retention, no sensitive processing, controls, etc. A relative equivalent to what an independent bookstore does.
If it's less than what is strictly necessary to run a business, then it's useless.
♥ 1
There's a reason the adtech folks love consent to the point that they're presenting PETs as "anti-choice": it's the best thing that ever happened to them. Do whatever they want, blame the user for agreeing.
♥ 1
It's also politically perfect because it forces non-data businesses to align with the adtech complex. Nothing but win, all thanks to an approach grounded in perfect rationality and individualism.
♥ 1
The owner sees you, recognises you, depending on interactions will recall what you got before, what you liked. You're describing a world in which people walk into a bookstore with a motorcycle mask until they sign a waiver.
♥ 2
And that's pretty much the same online, given appropriate retention, etc.
Likewise, I have nothing against you but I've mostly been arguing against the people who make actual spy devices and I honestly can't tell your arguments apart from theirs.
♥ 2
Surely enough in Art4(7), "‘controller’ means the natural or legal person, public authority, agency or other body." There's certainly a lot of stuff that could be an "other body" determining means and purposes, including treating Poodle Naps and Poodle Fetch as separate.
It looks like they're hinting at what could be an effective way to enforce purpose limitations against processing that is both unfair to users and anticompetitive.
I'd love to hear if this has worked before!
♥ 2
I don't think so? Their whole argument is that there shouldn't be an advantage to horizontal integration in making it less burdensome of data protection and less fair to users. If you can just tweak ownership/reporting structures, it's a pretty weak argument?
♥ 1
On dirait que chaque petit morceau a été créé par quelqu'un de différent.
It's possible, but if so that makes for a pretty weak argument since they claim that horizontal integration shouldn't make things easier. I mean, basically the whole thing becomes pretty moot, or you have to be able to transfer very easily between unrelated companies!
♥ 1
Yes, the definition of "controller" is even specific about that. It's certainly true that they could be thinking about national laws. Also, it might already be the case in the UK Data Protection Act.
♥ 2
That's why I'm curious. I've pushed to rely on the former much more, but consent makes it tricky as users can waive the limitation unknowingly. If the latter is enforceable, it's an interesting alternative.
People often love to claim that Americans don't care about privacy, have a different approach to it compared for instance to Europeans, that legal approaches have to differ.
Or claim that people want relevant ads for data.
@GregBensinger calls bullshit.
nyti.ms/3ysdeLu
♥ 39↺ 17
It turns out that, weirdly, Americans are people. Crazy stuff!
♥ 2↺ 1
But even between products of a unified company?
♥ 1
I sure love the idea, but I haven't seen it documented much!
♥ 1
I'd love that to be the case.
♥ 1
If you have some, sure!
I think Teams works in Edge too.
Not that I've seen so far!
♥ 1
I mean, I could literally open the bbq grill and wait for them to step on.
I try to file it under "enjoy the marvels of wilderness and biodiversity in a generational event." Only partial success 😁
♥ 1
I've had cicadas before, and they were good. But also smaller than these, and I hadn't been watching them for days shed the empty shells of their nymph stage everywhere.
OK, they do that in Finland??
Je ne me souviens plus des chiffres, mais vous êtes à peu près aussi petits que nous, non? Et puis je crois que tu connais le métier un peu mieux que moi! 😁
♥ 1
I wish that were more common!
What the Tulsa Race Massacre Destroyed
nytimes.com/interactive/20…
♥ 3↺ 2
First they ignore you,
Then they laugh at you,
Then they co-opt your terminology into their marketing word salad,
And then everyone is, like, totally confused.
♥ 88↺ 17
I mean, can you find a single adtech vendor that's not talking about how wonderful its privacy is? The whole pitch for UID2 is that is privacy-preserving privacy solution for privacy identifiers on the privacy privacy.
If they keep repeating it, it must be true, right?
♥ 15↺ 2
Or the SWAN thing, which is entirely defined by word salad, is entirely about how tracking you more is better for privacy and how sludge choice architectures improve agency.
♥ 3
Oh it doesn't stop there. It has a whole section on Ostrom common-pool resources that doesn't seem to understand that data doesn't fit that framework, and they also consider PETs to be "anti-choice" because you can't trick people out of their data.
♥ 4
It's... It's too late for me, but my friends, save yourselves while you still can!
♥ 3
Well yeah, if your data is protected obviously you can no longer choose to be tracked!
♥ 2
Just ignore it I guess? As far as I can tell, it's of dubious legality anyway.
♥ 2
Well, it works for FB 😁
This happens every few years. Some industry segment doesn't like the evolution of the web, and after years of not participating all of a sudden they find themselves to be stalwarts of web governance. It's like cicadas, it eventually passes.
♥ 3
It's always the same script. They don't do their homework but they know everything about how it all should run, any difference with their world is a problem, and they always talk about how they do this for the users and because they understand business and others don't.
♥ 2
It's very tedious, but you can't argue with motivated reasoning, you have to let them make all the same mistakes and get in the way of fixing the actual governance problems that are there.
♥ 2
Please. Do not go down this rabbit hole unless you have to.
♥ 4
It's a joke, except that because input into the W3C is meant to be egalitarian, it's a joke that gets press coverage as an "alternative".
♥ 3
No, no it's not, but it has been submitted to WebAdv for consideration. I don't think that it's getting much, but that's enough for some trades to pick it up, and some of the less savoury agencies to start talking about it.
♥ 2
Yeah, "the law is a ceiling, not a floor."
♥ 7
The FPPA had the same exemption. I think it's just part of the regulatory template in Florida.
They are singing. #BroodX
♥ 2
Whoa that's amazing! Congrats!
♥ 4
This makes me want not to ever be a genius.
♥ 1
It's hard work, but the peace of brain is twice-appreciable.
♥ 1
Wondering what all the fuss over privacy is about? This thread scratches the surface.
Quoting a tweet by @RobertGReeve ↗
♥ 29↺ 16
Just when you thought that that train wreck couldn't keep piling up…
♥ 1
Wait — you can actually get us out of these holes?
♥ 2
Perfect gif :)
My first reaction was to laugh, because it's true.
Then it hit me that we let the people with arguably the worst urbanism in the world create institutions for a humankind-wide network. It should have been obvious from just the locale that it couldn't work!
Quoting a tweet by @JoshSchoen ↗
♥ 15↺ 2
♥ 2
Same, I have some notes on NYC urbanism, but it beats SV any day of the week without even getting out of bed.
♥ 2
Can you cite an example of a group of people with comparable resources and anywhere near that level of urbanism fail? Because I really can't think of any.
♥ 1
The question isn't so much the attributes as it is whether this information is used to build a profile or put into a cohort as it accumulates. Following contextual over time is behavioural.
♥ 3
Ooooh, thanks!
♥ 1
1. That's not discrimination, you're using a strawman.
2. A wealthy area not fixing 50yo problems isn't a counterexample.
3. At no point did I generalise to "everyone", another strawman.
Are there a few people in SV who are good at urbanism? Almost certainly. Are there a few people in SV who are actually good at technology instead of just scale and engineering? Same answer.
But I'm not talking about what exceptions might exist here and there. I'm talking about overall structure. The problems of tech and urbanism are similar. A collective that sucks at one is very likely to suck at the other. It's not a weird or radical argument.
I can't read the details in Italian, but this seems like an excellent and logical decision: you cannot consent to what you can't understand. This should significantly reduce the scope of consent under the GDPR and point towards more responsible approaches.
Quoting a tweet by @IvanaBartoletti ↗
♥ 44↺ 17
Heard through @montezumachavez, who knows everything that's going on.
♥ 2
I'm not sure what's going on, there was a storm and now there are... even more cicadas? I think they're elaborating a constitution. #BroodX
♥ 3
Oh my god! Living the dream!
♥ 1
In context it's understood to imply: through a minimalistic computer interaction. If you do any of these that way, well...
I love Portland, Maine! There should be a thing where people can follow the wave of dive bar reopenings, like foliage but with more drunk people spittling in your face.
♥ 1
Voting is also an action in itself rather than consent to the actions of others. And it is subject to significant collective scrutiny.
♥ 1
I'm tempted to mute anyone who ever finishes any kind of pile — I just have The Pile and I'm concerned that it may become sentient any day now.
♥ 1
Using the vanilla GDPR, no, but I wonder if this couldn't be an area for Art40 to help with. If businesses came together to establish credible use and guardrails for this specific area (not one business but a large enough group), and DPAs kicked the hell out of it…
♥ 1
…to make sure it's safe, respectful, solid, and accountable, would this not be better? Nothing is perfect, but I will take strenuous expert oversight, especially with a democratic component from DPAs, over offloading this to people and hoping they can act.
♥ 1
Well played!
TWO CATS even.
I think that voice assistants are being approached with the wrong assumptions, deliberate from their makers but too-often unchallenged by critics.
The logical architecture (if only from the name!) is that they would be user agents to access voice services.
♥ 3
Instead, they are being developed as a presence from a single company that is enriched with skills that other companies develop.
Recognising them as agents representing the user in an interaction opens the door to fiduciary agency. Shamelessly, I'd plug: papers.ssrn.com/sol3/papers.cf…
♥ 4
You were well ahead :) One thing that is unfortunate is that the expectation that browsers are trustworthy agents for the user was a foundational assumption in the development of Web technology, but it was considered so obvious that it was decades before anyone wrote it down.
♥ 2
I'm really starting to wonder if this whole "moving to Egypt" plan was such a good idea.
Quoting a tweet by @evanperez ↗
♥ 6↺ 1
But is that *really* enough butter?
♥ 1
That's indeed a key question for the future of advertising and also highly significant for the web: is Chrome a user agent, or is it the in-app browser for Google? If Chrome Sync remains cleartext, we'll know it's the latter.
Quoting a tweet by @kyotonio ↗
♥ 20↺ 7
What... what is... this? I... You... But...
Is this, like, the entire set of what you're working on?
♥ 2
Aside from the cool psycho style, is there anything about this that doesn't work for you? Like would you want links, searching, things in databases? If not, I don't see the problem 😁 I use Notion, but I have a lot of structure and a lot of links.
♥ 1
I get the minimalism thing, but it feels like your finding-stuff experience could be improved :) I'd suggest either going barebones but in a single thing with Notes, or trying something more structured (but not overbearing) like Notion.
♥ 2
We see it a lot less today because everything is overconstrained to death so as to corral users, but when tools were more open and flexible pretty much everyone had their own psycho world like Davey.
I have to say I miss it!
♥ 1
Location data is some of the most dangerous and sensitive data to have.
If you're not sure whether Google can be trusted with data or not, I highly recommend that you read this thread. My favourite part is when Google engineers can't figure out how not to be tracked 😂
Quoting a tweet by @jason_kint ↗
♥ 65↺ 35
This is instructive when compared with how Chrome Sync operates. It's another highly sensitive data set, and judging from how location is treated I fear for Chrome users.
Also, you can see exactly how the deceptive tricks to get users to share and then be stuck there are made.
♥ 8
Yeah, I'm still on Android because I prefer the UI, but frankly I'm increasingly sure that my next phone will be an iPhone just because there has to be a limit to muppets with data.
♥ 2
It's the problem with trying to do things for the user instead of making tools to empower the user: you end up always needing more data. It's a bottomless rabbit hole.
♥ 1
Hahaha, that's exactly how I get people to do what I would like them to!
Thank you @celiabelin for writing about the situation of those in the US on non-immigrant visas. Right now we have to choose between not seeing family for a second year or risking not being able to keep working here. This covid travel ban on vaccinated people makes little sense.
Quoting a tweet by @celiabelin ↗
♥ 11
It makes me feel smart when I make things easy for others 😁
♥ 2


















