Live data from Hacker News

Grindr Shares Personal Information With Third-Parties

github.com

251–260 of 317 posts

Re: Grindr Shares Personal Information With Third-Parties

#251
post #151

So vending HIV status is a straight up HIPAA violation, I'm fairly sure that's been found to be the case over and over again -- it doesn't matter what your business is, health information is covered by HIPAA. That's 250k per violation fine, and leaking status positive or negative is a violation. And every person, and every time they pass that information to every "partner" is a distinct violation.

Only if you are a "covered entity"

HIPAA has nothing to do with Grindr unless it starts an acute care clinic.

Re: Grindr Shares Personal Information With Third-Parties

#252
post #62

Earlier quoted context omitted.

Yet Tinder is just one of the 150 online brands owned by IAC, a company created by legendary TV executive Barry Diller. He probably knows the value of the data they have.

Wow, today I learned: Tinder, PoF, OkCupid, Match.com and more are owned by the same company.

And for awhile they were owned by one of the most evil companies of them all... Ticketmaster!

Re: Grindr Shares Personal Information With Third-Parties

#253
post #110
post #82

Earlier quoted context omitted.

You can delete the data from your profile.

Do you have any idea how hard/illegal it is to hack into those servers and manually delete every file relating to JUST your profile without alerting an admin?

Made me laugh - thank you.

Re: Grindr Shares Personal Information With Third-Parties

#254
post #194
post #67

Earlier quoted context omitted.

Makes me think that data should be treated differently in the case of a potential new owner, allowing users to opt-out from their data from being transferred; you may trust the leadership and governance, and may not trust whomever takes over or who will newly has access to the data.

EU's data protection law covers this.

If so, that's great.

Re: Grindr Shares Personal Information With Third-Parties

#255

We need a new business model for social media, one which actually serves the customer instead of trying to lure them into productizing themselves.

Someone has to pay for your service. This can either be your users or a 3rd party. We know the overall acceptance of paying for online services is fairly low. Even high quality news outlets have problems monetising their content. In this case you're also competing with "free" services like FB. Unless you can offer something that is enough of an incentive for people to pay, this is not a battle you can win. What's mor…

I don't think that's true. If you were constrained in how you use user data, you could make money in other, more difficult ways.

Monetize photo services, music, sell access to the audience for applications or monetize the marketplace.

Pillaging users is easy. But if regulators prevented it, Facebook is still a viable business -- maybe even a better one.

Re: Grindr Shares Personal Information With Third-Parties

#256
post #233

Earlier quoted context omitted.

> You're sending data to a third party service when you host an app on AWS. Amazon neither receives nor requires access to the raw underlying data (in this case: data in your database indicating HIV status, or decrypted bodies of requests sent over TLS indicating same) when you host your web services on AWS. While, yes, it's possible for a dedicated attacker to intercept and snoop on this data, it's (a) not easy, and…

I honestly don't get the distinction you're making here. I understand how people _can_ use AWS without ever letting sensitive data touch their disks, but most apps hand everything over wholesale (and frequently in a nicely structured format on RDS). The legal distinction you're making doesn't sound right to me. Contractors for companies that access your data aren't usually about whether or not an attacker can get at…

Amazon is selling an abstraction, and goes to great expense to not have access to customer data. If you are a HIPPA covered entity, they sign a BAA that puts them on the hook.

It's like the difference between putting your papers in a storage locker versus your friends garage. The storage company ultimately has access to the locker, but is less likely to snoop (either consciously or accidentally) than any of the folks with access to that garage.

Re: Grindr Shares Personal Information With Third-Parties

#257

Earlier quoted context omitted.

That's not even close to the same thing. You're comparing involuntary and unknown sharing of personal data with explicit and self-actioned sharing of that data.

The user volunteers their health information into the public domain when they tell Grindr their HIV status. This is information that is already visible to other users to some degree. Declaring your HIV status on Grindr is voluntarily and knowingly sharing your own health information into the public domain. It is much closer to tweeting it out than telling a medical professional imo.

Valid point; I hadn't considered it that way. There's still a large difference in audience between the two but ultimately you're surrendering the information to unknown parties.

Re: Grindr Shares Personal Information With Third-Parties

#258

Earlier quoted context omitted.

Why did they keep those records? Different tax rates for different religions? Seems like none of their business.

I thought it was for this reason, though the sibling comment's link seems to indicate that we don't really know (and I trust him more than my memory). It used to be common to tax different religions in a different way in some countries of Europe. Even today in Germany you are legally required to pay taxes to your church, and I have read multiple accounts of French expatriates who have discovered this only after a yea…

The way in which the German government has been co-opted by the church to act as their debt collectors is fairly disgusting and no longer of this day and age.

Re: Grindr Shares Personal Information With Third-Parties

#259
post #239
post #230

Earlier quoted context omitted.

Why is this a blackmail goldmine? I am ignorant of Grindr, but what I have heard it is basically Tinder but for gay men. Would Tinder be blackmail data? It's hook ups and relationships, dating, etc, no?

> but what I have heard it is basically Tinder but for gay men. Would Tinder be blackmail data? It's hook ups and relationships, dating, etc, no? Absolutely when cross-referenced with information from OPM database. Employee with TS/SCI clearance working on a hasn't reported reported his gay affairs (that his wife might not know about even). The Chinese find out, approach him and make him an offer "Look buddy, how 'bo…

And that's why lack of blackmailability is one of the biggies on clearance applications.

Or, "Lets not become friends. You can tell my wife. She thought it'd be fun to do that!" aaaaand so much for that blackmail. And just don't forget to tell the security officer that someone tried funny shit.

Re: Grindr Shares Personal Information With Third-Parties

#260

Earlier quoted context omitted.

> That's also a big factor in why I have a problem with governments collecting data. You may trust the present day administration (or not...), but who knows what a future administration (or occupying force) is going to be up to The standard example is how the Netherlands were rather religiously tolerant, but used to keep track of Jews for tax collection purposes before WW2. Then when the Nazis arrived, they had all t…

Why did they keep those records? Different tax rates for different religions? Seems like none of their business.

Well if you don’t think it’s a big deal, you may collect it just to have the data (data was as appealing to bureaucrats 200 years ago as it is to big-data engineers today). For example the DMV asks for your height and weight today, but if a fat-hating government came to power and decided to kill all fat people, they would have a target list that was of very questionable value for the DMV to collect in the first place.
Post reply on HN