Live data from Hacker News

When I asked Tinder for my data, it sent me 800 pages of my deepest secrets

theguardian.com

31–40 of 151 posts

Re: When I asked Tinder for my data, it sent me 800 pages of my deepest secrets

#31
post #21

I wonder what Snapchat would return. All the messages ever? Regardless of their pretend volality? Someone please try it, I don't have an account.

Their position is: "Snaps are deleted from our servers after they have been viewed by the recipient".

Re: When I asked Tinder for my data, it sent me 800 pages of my deepest secrets

#32
> A few months earlier, 70,000 profiles from OkCupid (owned by Tinder’s parent company Match Group) were made public by a Danish researcher some commentators have labelled a “white supremacist”, who used the data to try to establish a link between intelligence and religious beliefs.

The guy's name is Emil Kirkegaard and the paper and data is still available. I skimmed the paper and have no idea why he was labled a "white supremacist", or by whom. ("some commentators", really? Is this journalism?)

[EDIT]

paper: https://openpsych.net/files/papers/Kirkegaard_2016g.pdf

dataset: https://www.reddit.com/r/datasets/comments/4jj53i/here_is_a_...

Re: When I asked Tinder for my data, it sent me 800 pages of my deepest secrets

#33

"Some 800 pages came back containing information such as my Facebook “likes”, my photos from Instagram (even after I deleted the associated account)" It's going to be interesting to see how Tinder tackles the 2018 EU General Data Protection Regulation in 2018 and how things will play out in courts and practice. For example, are you allowed to store information that I have chosen to unlink? Will Tinder have an easy wa…

Considering that they've managed to gather all of the author's data in a short time they would fare pretty darn well, for most companies that is the hard part. The GDPR isn't nearly as scary as people set it out to be, and it gives companies a huge amount of wiggle room.

Could you give some examples of this wiggle room?

Re: When I asked Tinder for my data, it sent me 800 pages of my deepest secrets

#34

> A few months earlier, 70,000 profiles from OkCupid (owned by Tinder’s parent company Match Group) were made public by a Danish researcher some commentators have labelled a “white supremacist”, who used the data to try to establish a link between intelligence and religious beliefs. The guy's name is Emil Kirkegaard and the paper and data is still available. I skimmed the paper and have no idea why he was labled a "w…

Is there any tool (chrome extension or whatever) that'll take an article and give thumbs up or down depending on crap like "some commentators", "anonymous sources", "allegedly" etc? So people can simply skip over such articles?

Re: When I asked Tinder for my data, it sent me 800 pages of my deepest secrets

#36
post #27

I always felt a bit silly logging in to Facebook in a private browser window in every other week, many times through a VPN. Also not sharing much more than jokes and cartoons or memes. Not to mention my absense from the hip social web, including Tinder, but many more as well. I don't feel silly anymore. :) (btw: my name is not zoltaan ;) )

Outliers such as yourself won't do much to curtail the practice of companies amassing identifiable, weaponizable, and often undersecured data about their users. And because the data is valuable and there have been few regulations put in place to balance that value with the burden of responsible handling, those companies will continue to collect more and in more creative ways, whittling away at your creative maneuvers to avoid it.

In my estimation, this is a good first step, but privacy has to be a feature of the system, not just a heavy shield you carry through it.

Re: When I asked Tinder for my data, it sent me 800 pages of my deepest secrets

#37
post #33

Earlier quoted context omitted.

Considering that they've managed to gather all of the author's data in a short time they would fare pretty darn well, for most companies that is the hard part. The GDPR isn't nearly as scary as people set it out to be, and it gives companies a huge amount of wiggle room.

Could you give some examples of this wiggle room?

The GDPR replaces the right to be forgotten with the right to erasure. But article 17 also gives the following grounds for refusal:

Paragraphs 1 and 2 shall not apply to the extent that processing is necessary:

1) for exercising the right of freedom of expression and information;

2) for compliance with a legal obligation which requires processing by Union or Member State law to which the controller is subject or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;

3) for reasons of public interest in the area of public health in accordance with points (h) and (i) of Article 9(2) as well as Article 9(3);

4) for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) in so far as the right referred to in paragraph 1 is likely to render impossible or seriously impair the achievement of the objectives of that processing; or

5) for the establishment, exercise or defence of legal claims.

The first example is effectively a carte blanche to argue nearly any request for refusal in court.

The second one allows member states to pretty much tell companies not to delete information, whilst this was set up with compliance in mind, the wording has likely been formatted to also fit other needs such as security and state monitoring.

The third one pretty much allows you to keep medical records and insurance information.

The forth one is similar to the first with celebrities, public figures and major events in mind (the Gawker clause).

The fifth one has been singled out by dating sites and other services such as ride sharing apps as the reason for them to keep data.

I am not a lawyer this isn't a legal advice, speak to a legal firm or an auditor for proper advice.

I have been working on a few GDPR compliance projects internally for the past year and I've had to speak with quite a few lawyers and they all pretty much said it's actually far better for most companies than the existing framework as long as they can automate data discovery and know where they data comes from and where does it go.

You can fight the right to erase the data of a user pretty easily, what you cannot cockup (Art. 15, 20 and 21 of the GDPR primarily) is the ability to disclose what data you have on them and what is it used for which is like I've previously stated the tricky part for most cases. And as far as I can see Tinder pretty aced the tricky part.

Re: When I asked Tinder for my data, it sent me 800 pages of my deepest secrets

#38
Dating websites are, quite possibly, worse for our privacy than any social network ever invented. Consider this: A website like OkCupid can go much deeper than Facebook in understanding who you are, and what makes you tick. This is invaluable to marketers, and the government for that matter. I avoid dating websites because whose to say this data can't be used by others, such as insurance, employment, or the police? The following exchange from the television program "Person of Interest" I think is quite telling, albeit tongue in cheek, as to this threat: https://www.youtube.com/watch?v=DPirWp2oAJ4

Re: When I asked Tinder for my data, it sent me 800 pages of my deepest secrets

#39
post #15

Earlier quoted context omitted.

The country the data resides in is irrelevant. If the data is about an EU citizen, that's all that matters. I believe the company in question would also need a legal entity in the EU in order for the EU to prosecute them, as I don't think you can take (e.g.) an American company to an EU court. IANAL though.

You can take an American company to an EU court assuming the EU court has jurisdiction, and laws can specify that its jurisdiction should extend to actions taken outside the geographical area (I don't know if that is the case here). Without a US court case they'd be dependent on assets or an income stream in the EU to be able to force payment of any fines, though.

> assuming the EU court has jurisdiction

If the company wants to do business with a EU customers, they have _some_ surface area in the EU, which is enough.

> an income stream in the EU

If the company cares for EU customers, there's probably also _some_ way to make money on them. Unless EU customers will exclusively get Netflix USA ads in the future (which are 100% useless to them) on an otherwise 100% free service, there is a money stream to hook into.

Re: When I asked Tinder for my data, it sent me 800 pages of my deepest secrets

#40
post #27

I always felt a bit silly logging in to Facebook in a private browser window in every other week, many times through a VPN. Also not sharing much more than jokes and cartoons or memes. Not to mention my absense from the hip social web, including Tinder, but many more as well. I don't feel silly anymore. :) (btw: my name is not zoltaan ;) )

They still build profiles on you though. When you phones wifi is near someone with an android phone or a Facebook app they'll handshake and tell the interwebs where you are and with whom.
Post reply on HN