Live data from Hacker News

Grindr Shares Personal Information With Third-Parties

github.com

31–40 of 317 posts

Re: Grindr Shares Personal Information With Third-Parties

#31
post #22

Earlier quoted context omitted.

They have the option of not sending HIV status to any third party.

What is the privacy distinction between a third party with a contractual agreement and an employee with a contractual agreement? Remember that Russian intelligence got a spy hired by Microsoft: https://www.theguardian.com/technology/2010/jul/14/russian-s... Will your interview questions find a foreign spy, or someone who isn't even a spy but is interested in looking at private data for personal amusement?

If Microsoft implemented proper security policies, I imagine that guy didn't have access to all of Microsoft's user data.

So that would be the main difference. Virtually all of a company's employees shouldn't have access to user data at all, and those that do would only have access to parts of it.

Re: Grindr Shares Personal Information With Third-Parties

#32
post #8

For what it's worth, the most private data here is shared to analytics companies for Grindr's only analytical use. My guess is that Grindr's agreement with Apptimize and Localytics asks for the strictest possible protection of that data. If anyone at Apptimize or Localytics has access to that data, I'd be incredibly surprised. This sort of deal isn't the same as sharing the HIV status to Google or Facebook so that ad…

> Not everyone can afford to perform their own product analysis.

Just because ethical behavior is expensive doesn't mean you have a license to do whatever you want.

Re: Grindr Shares Personal Information With Third-Parties

#33
post #17
post #2

Does anyone have any information on how Scruff handles that information? Also, does HIPAA say anything about technology companies outside of the medical field's data that may voluntarily collect HIV status?

I believe HIV status is a special protected piece of information and consent needs to be given before you can share it. http://www.aidslawpa.org/get-help/legal-information/confiden...

Those laws apply to healthcare providers, not to social networks.

Re: Grindr Shares Personal Information With Third-Parties

#36

This is deeply troubling. Anyone who uses Tinder or any other dating site should try requesting their data and realize that these services could likely label you a sexual deviant, racist or otherwise based on your swipes alone.

I guess we'll soon find out:

https://www.wired.com/story/tinder-lack-of-encryption-lets-s...

https://www.theguardian.com/technology/2017/sep/26/tinder-pe...

Re: Grindr Shares Personal Information With Third-Parties

#37

We need a new business model for social media, one which actually serves the customer instead of trying to lure them into productizing themselves.

I personally believe that social media may be one of the best use cases for blockchain technology. I think that each node "paying" for their account with some sort of resource usage could be sustainable, but I am not a blockchain expert. It would be interesting to see if something like that could work without turning into a ICO money-grab.

Re: Grindr Shares Personal Information With Third-Parties

#38
post #8

For what it's worth, the most private data here is shared to analytics companies for Grindr's only analytical use. My guess is that Grindr's agreement with Apptimize and Localytics asks for the strictest possible protection of that data. If anyone at Apptimize or Localytics has access to that data, I'd be incredibly surprised. This sort of deal isn't the same as sharing the HIV status to Google or Facebook so that ad…

>>For people who think this is still wrong, I'm curious what their pragmatic alternative is. Use the services you mentioned but DO NOT SEND HIV DATA TO THE ANALYTICS COMPANIES. Holy hell, how hard is that? Just omit that part.

Or just don't fill out that part of your profile.

Re: Grindr Shares Personal Information With Third-Parties

#39
post #8

For what it's worth, the most private data here is shared to analytics companies for Grindr's only analytical use. My guess is that Grindr's agreement with Apptimize and Localytics asks for the strictest possible protection of that data. If anyone at Apptimize or Localytics has access to that data, I'd be incredibly surprised. This sort of deal isn't the same as sharing the HIV status to Google or Facebook so that ad…

As someone who has been working in security for a long time, and has seen how the sausage is made at even the biggest, most reputable companies who “take security very seriously”, the “strictest possible protection of that data” means approximately nothing. The only serious way to protect sensitive data is not to take it in the first place. Hell, not even the NSA can keep a lid on their sensitive data.

”For people who think this is still wrong, I'm curious what their pragmatic alternative is. How else are app developers supposed to analyze their app performance?”

Remember, customers first, your “needs” come second. That goes double when they are placing their trust in you by allowing you to be a custodian of their data.

Not long ago, desktop software phoning home would have been a scandal. Not long before that, it was offline and couldn’t phone home. Yet, we still had software. Unfortunately, developers have taken the slipperly slope all the way to outright abuse of their privileges in order to collect information that customers don’t know about or understand. This has led us to things like GDPR. It doesn’t matter if your intentions are good or your usage is benign. It isn’t yours to begin with, those aren’t your decisions to make, and developers need to learn to seriously respect that.

Re: Grindr Shares Personal Information With Third-Parties

#40

It's become clear over the last year there is a strong need for a data privacy regulatory agency in US government. I understand that regulation hampers growth, but the tech industry is mature and developed to the point that it's time to reel in "moving fast and breaking things" a bit.

> It's become clear over the last year there is a strong need for a data privacy regulatory agency in US government.

I wouldn't trust a governmental regulatory agency to aggressively fulfill it's mission. My impression is that in general they're too much at the mercy of politicians.

I suspect a more effective strategy is to enact legislation that makes companies liable under civil law, with private citizens empowered to sue.

Post reply on HN