Live data from Hacker News

A Case That Has Microsoft, Apple and Amazon Agreeing

bloomberg.com

171–180 of 190 posts

Re: A Case That Has Microsoft, Apple and Amazon Agreeing

#171
post #69

Earlier quoted context omitted.

The "3rd party doctrine" is a bullshit interpretation and it needs to die. When I go through the trouble of coming up with a long complicated password and setup two factor authentication it's pretty obvious that I have "an expectation of privacy". Maybe what the tech companies need to do is have a checkmark on sign up that says "I expect my data to be private".

My take: The third party doctrine is a natural consequence of the use of "their" in the 4th amendment. People have a fourth amendment right to "their" persons, houses, papers, and effects. Bits on Google's hard drives aren't "theirs" they're Google's. You have no property right in those bits. If Google loses them, you can't sue them for negligence. If they change their TOS and monetize those bits, you have no recours…

Google's TOS negates your point. Google requires such a license to because those works belong to you. The license (which does not transfer ownership) gives Google the right to do all the things listed.

Of course, a lot information is actually generated by Google and even though it's about you (search history, etc) and doesn't belong to you.

Re: A Case That Has Microsoft, Apple and Amazon Agreeing

#172

"There’s irony in any tech company confronting the government on privacy matters, considering how much heat many take for mining their own customer information and using it for advertising and other profitable purposes." See, I don't find this very ironic. In fact, my only real issue with data mining and analysis by these sorts of companies is the way governments can demand this info without my approval. If Microsoft…

> But just because I agree to let Google read my location to send me traffic warnings before heading out to work doesn't mean I want the FBI to grab that data without my knowledge so they can determine if I might be a troublemaker Constitutionally, privacy is a pretty cut-and-dry concept. Information is either private or not. Private information isn't "information I don't want the government to have" it's "informatio…

Wow, I had no idea this was the case. Thanks for sharing. I seem to remember that you're a lawyer so I'll have to assume you know what you're talking about. :)

> some third-party entity (and its employees) actively sifts through

Just to be clear, is this condition important to your statement? That is, can you store information with a third-party entity with the assumption that it's constitutionally "private" there if you don't let them sift through it? Say, a bank safe deposit box, or some sort of encrypted enterprise crowd storage, or cperciva's tarsnap?

Re: A Case That Has Microsoft, Apple and Amazon Agreeing

#173
post #128

Earlier quoted context omitted.

Yeah that opt out theory was nice some years ago. Now it's not that simple anymore. Most of the times you just have no choice. What right has Amazon to do this? They get their share from the fact that I buy stuff though them. So I pay and still get analyzed. There are many more services that work like that. You can get around some of them by spending much money or acquiring special skills that would allow you to run…

Not useful enough to be able to acquire a bank account, which requires a drivers license or social security number, which then requires a birth certificate. And as it turns out, it seem acquiring any of these things for purposes of a false identity is illegal. So much for remaining anonymous online just because I'd like to be, not because I need to be.

Yeah...well. I was talking about normal people like my friends and family ;)

Re: A Case That Has Microsoft, Apple and Amazon Agreeing

#174
post #133

Earlier quoted context omitted.

Do you mean like Ashley Madison hack? Nothing in the ad-backed company model prevent someone sending a fake advertisement to the demographic who are likely involved in adultery. After that you publish a "people who subscribe to this service are ..." list based on who clicked on it. The only question if someone could do this with Facebook/Google is if they provides targeted advertisement to that demographic or if you…

There is no way whatsoever that you're getting my name or email address by some third party serving your ad to me, unless I happen to end up voluntarily filling those details in on your web property. Which I probably won't do, unless you have something I actually want, and I trust you. That's the difference. That and the fact that if you publish your "the small fraction of people on $EMBARRASSINGTHIRDPARTYSERVICE's m…

You assume the false advertisement would be done lawfully. People who hack places to publish list of embarrassing information don't do so legally, so why should we assume that people who abuse data mining services would only be lawful entities?

The false advertisement might say something like "save 50% of your next amazon purchase" or "try out our new car service by getting the first trip free" or any other ways of getting people to voluntarily filling in information which looks completely innocent. All you need is the additional information of name and address, which for the user feels completely separate from the sensitive information which was surreptitiously inferred through the targeted advertisement.

This assuming they can't simply push some malware and get the name that way. We constantly hear about tor hidden service attacks done by de-annonymize people with flash/java/browser exploits.

Re: A Case That Has Microsoft, Apple and Amazon Agreeing

#175

Earlier quoted context omitted.

Constitutionally, privacy is a pretty cut-and-dry concept. Private information isn't "information I don't want the government to have" it's "information I don't want anyone else to have." You are incorrect. Your line of thinking runs in direct opposition to Roe V. Wade. You can share information with your doctor that you specifically do not want the government to have. There's nothing special about doctors, in a cons…

I'm talking about "privacy" in the 4th amendment sense. The Griswold "privacy" line of cases is pretty much totally inapplicable outside the reproduction/sexual activity/family planning context, largely because they conjure up a "right to privacy" that doesn't really exist in the Constitution.

I'm still not sure about your claim that private information consists _only_ of "information I don't want anyone else to have."

You can share information with another trusted party and still have an expectation of privacy (such that the government needs a warrant to compel access to that information). Conversely, you can have information that you don't share with another living soul, and the government can also compel access to that information - e.g. a warrant to search your private belongings. The standard for how the government can access your information doesn't automatically change depending on whether you've shared it with 0 or > 0 people.

Re: A Case That Has Microsoft, Apple and Amazon Agreeing

#176
post #152
post #131

Earlier quoted context omitted.

> Constitutionally, privacy is a pretty cut-and-dry concept You clearly don't understand the US Constitution or existing US law. Saying it's cut-and-dry doesn't make it so. > Information is either private or not I'm sorry, I made a mistake. You don't understand privacy as a concept at all. Privacy is about access controls. What's more all this frothing about privacy is not the issue under consideration. The issue is…

Please be civil. BTW, the person you're replying to is a lawyer. Are you?

>BTW, the person you're replying to is a lawyer. Are you?

I'm a unix systems administrator. That doesn't mean everything I say about unix systems is right.

I'm not saying that said lawyer is incorrect about anything, because I honestly have no idea - but if we're asking people to be civil, we should also probably refrain from logical fallacies and defend him on the merit of his statement, and not his job title.

Re: A Case That Has Microsoft, Apple and Amazon Agreeing

#177
post #164

Microsoft has shown that they are quite willing to access induviduals private data if they have a financial stake in it [0]. Yes, they eventually backtracked under public pressure (after trying very hard to justify how it's totally okay because they were going to pay a lawyer to rubber-stamp things in the future), but it's rather hard to listen to their general council talking about how they value privacy on principl…

Their statement says In this case, there was a thorough review by a legal team separate from the investigating team and strong evidence of a criminal act that met a standard comparable to that required to obtain a legal order to search other sites. I don't think that supports your claim that they would only ask a lawyer in the future.

> Their statement says

> In this case, there was a thorough review by a legal team separate from the investigating team and strong evidence of a criminal act that met a standard comparable to that required to obtain a legal order to search other sites.

>I don't think that supports your claim that they would only ask a lawyer in the future.

From the link I included in my comment, Microsoft deputy general counsel John Frank is quoted: "As a new and additional step, we will then submit this evidence to an outside attorney who is a former federal judge. We will conduct such a search only if this former judge similarly concludes that there is evidence sufficient for a court order."

This lawyer (his past employment as a judge has no bearing here) would have been paid by Microsoft.

Could you explain how that does not fit with my earlier comment?

And to preempt the inevitable, yes, as I said in the original comment they eventually backtracked on this and said they'd report such future crimes to the police. You know, what they should have done in the beginning, and would have done if they had the respect for privacy-on-principle that they are now trying to shower themselves in.

Re: A Case That Has Microsoft, Apple and Amazon Agreeing

#178
post #170
post #161

Earlier quoted context omitted.

This may actually be a very good idea for some cases. If the stuff being protected by the key is, for example, the type of data that someone would otherwise keep in a personal fire-safe, then simply printing out the keys and keeping them in that fire-safe wouldn't change the type of security being provided. It might be nice if we had some type of highly-reliable (like the redundancy in QR codes[1]), so the process of…

You could just use a QR code. There's no real reason they need to be URLs.

I've tried this. Turns out that very few QR-code readers are able to cope with QR-codes large enough to hold a decently sized RSA key.

Re: A Case That Has Microsoft, Apple and Amazon Agreeing

#179
post #115

Earlier quoted context omitted.

I am not very familiar with penalties in EU, but I thought that on all the basics, like fraud, robbery, burglary, assault, murder, etc the penalties were comparable to US. Where US does go insane is when it comes to drug and gun crimes. The NRA lobbied for very stiff penalties for anyone who uses a gun in a crime, at least in CA. The drugs on the other hand are just a national obsession for people here in US, so I ge…

According to the prison documentaries I've seen EU penalties in general are much lower (like half to one third) than US ones for the named crimes. And we don't have death sentences over here so that changes perception a lot.

For instance this is robbery sentence guidelines in UK [1] and CA [2]. As you can see, penalties are very comparable. Robbery in CA is 2, 3, or 5 years or 3-9 years, depending on the degree, while in UK it's 2-7 years or 7 - 12 years, also depending on the degree. The first level of robbery in UK is more attune to Petty or Grand Theft in CA. In CA there is also a GBH enhancement, that will bump you up to the 12 years, just like in the UK.

Obviously, I have not done the comparison for all the crimes, but I think if done, we would find that EU and US both have very similar penalties for all the person crimes, like theft, robbery, rape, murder, etc. Where there is a big difference is probably in the crimes that have to do with national obsessions. For US it's drugs, guns, terrorism. For EU it's WW2 and holocaust, and also terrorism nowadays. But checking drug penalties in UK I also found them to be very similar to Federal statutes in US. [3] Though, if I had to guess, I would think the UK is far less likely to apply it's possession only laws. So, that's a valid criticism.

US does have an insane incarceration rate, but it's again due to our obsession with drugs. Take that out of the equation, and we are about even. Not that that makes it all ok, but I think we are on a path to changing that.

[1]http://www.cps.gov.uk/legal/s_to_u/sentencing_manual/robbery... [2]http://www.shouselaw.com/robbery.html [3]https://www.gov.uk/penalties-drug-possession-dealing

Post reply on HN