Live data from Hacker News

Yahoo is now part of Oath

policies.yahoo.com

41–50 of 68 posts

Re: Yahoo is now part of Oath

#43

Earlier quoted context omitted.

Take care though, they allow email address reuse.

How do they avoid HIPAA violations in that case? Or is that not at issue somehow?

HIPAA only applies to medical information. I didn't see any mention of that, so I'm assuming it doesn't apply here. Wish it did.

Re: Yahoo is now part of Oath

#44

Earlier quoted context omitted.

Take care though, they allow email address reuse.

How do they avoid HIPAA violations in that case? Or is that not at issue somehow?

I have no idea. I know that my providers avoid sending covered information to my email, they send me a notification to log into their messaging system.

Re: Yahoo is now part of Oath

#45
post #15
post #5

We will share ... your account registration information (such as your user ID, gender, name, email address, postcode & age), your content and advertising interests, content associated with your account, the types of services you use and how you engage with them, cookie and device IDs, IP addresses, geolocation information and activity information from across our websites, apps, software and other services. All of the…

A fun test would be to post the data sharing policy of various services/apps and see how often someone posts a comment like this. Someone always posts a comment like this and it always feels, to me, like a knee-jerk reaction. They've had your data for years (and were previously not only irresponsible but likely shared it with countless other partners), what has changed now? Just because Yahoo is forthecoming about th…

> They've had your data for years (and were previously not only irresponsible but likely shared it with countless other partners), what has changed now?

This seems like it cuts both ways.

To be sure, Yahoo's data handling was reprehensible before the acquisition also. But if this reminds some people to pay attention to that, it's all to the good - I don't actually expect things to get better. Deleting or restricting your Yahoo presence was probably the right decision 1 or 3 or 5 years ago, but that doesn't mean it's wrong now.

More broadly, there's normally an argument for distrusting ISPs and mobile carriers even more than internet companies; they can correlate with physical presence, have a history of shockingly immoral behavior, and have repeatedly colluded with state surveillance far beyond what they were compelled to do.

I'm not sure how relevant any of that is in Yahoo's case, though, since they've basically alternated between handing user data to the government and handing it to literally everyone in the world. You're certainly right that anyone who only lost faith in their data security now has been in trouble for a long, long time.

Re: Yahoo is now part of Oath

#46
post #5

We will share ... your account registration information (such as your user ID, gender, name, email address, postcode & age), your content and advertising interests, content associated with your account, the types of services you use and how you engage with them, cookie and device IDs, IP addresses, geolocation information and activity information from across our websites, apps, software and other services. All of the…

Apparently doesn't work if you don't have a yahoo mail account.

Re: Yahoo is now part of Oath

#47
post #46
post #5

We will share ... your account registration information (such as your user ID, gender, name, email address, postcode & age), your content and advertising interests, content associated with your account, the types of services you use and how you engage with them, cookie and device IDs, IP addresses, geolocation information and activity information from across our websites, apps, software and other services. All of the…

Apparently doesn't work if you don't have a yahoo mail account.

Reboot and try again.

Re: Yahoo is now part of Oath

#48
post #4

Let's say I run company A, and Company B wants to buy all of my user's information but I've already created policies that say I won't share user information with 3rd parties. Could I: 1. Create a subsidiary (Company C) 2. Share info 'internally' with company C 3. Sell Company C to Company B

Sometimes programmers' minds get infected with the idea that the whole world, especially courts and regulatory agencies, are just little virtual machines that will dutifully execute based on whatever steps you lay out at the beginning. They're not. Machines can't call bullshit on you, but people will.

I think that comment makes the mistake twice over, even. First, because T&C are (usually) not an immutable contract - companies can just change them without any legal shenanigans at all. Then second because, as you say, actions taken just to circumvent laws are usually themselves illegal.

It is pretty baffling to see how often programmers talk about law like it's an algorithm. Even the DAO didn't work out that way, and that was explicitly intended to turn contracts and law into algorithms. If that didn't resist social pressure to redress harms, why would we expect actual humans to do so?

(And frankly, thank god the law doesn't work like that. I don't want to live in a world where legal loopholes open up as often as software vulnerabilities.)

Post reply on HN