Live data from Hacker News

Grindr Shares Personal Information With Third-Parties

github.com

291–300 of 317 posts

Re: Grindr Shares Personal Information With Third-Parties

#291

Earlier quoted context omitted.

OkCupid may be even more dangerous in that regard. As far as I know they allow you to set ethnicity preferences.

Most dating services do. Why shouldn't they?

I think the reasoning is innocent, the problem is that if it gets leaked you have people (probably incorrectly) interpreting things using the data which is half the problem.

"Your ethnicity preference is white? You goddamn racist".

This gets worse when those interpreters are in a position of power.

Re: Grindr Shares Personal Information With Third-Parties

#292
post #151

So vending HIV status is a straight up HIPAA violation, I'm fairly sure that's been found to be the case over and over again -- it doesn't matter what your business is, health information is covered by HIPAA. That's 250k per violation fine, and leaking status positive or negative is a violation. And every person, and every time they pass that information to every "partner" is a distinct violation.

And that's just US law. Any data stored or transmitted through the EU is subject to even stricter laws.

Re: Grindr Shares Personal Information With Third-Parties

#293

It might be worth making another post to highlight an additional concern: this repository itself appears to leak profile images of many Grindr users. The raw-data folder includes nearly 14,000 files, including many ads and scripts, but also thumbnails of many user profiles. This file[1] for example, once you strip out the HTTP headers, is a JPEG that shows the legs and gym socks of one user. This one [2] shows a user…

Since SINTEF is based in Norway, it's certainly possible that my profile picture is somewhere in there, and that really pisses me off. I'm out and have no problem with people knowing that I'm gay, but I shouldn't have to deal with "researchers" pulling this type of crap.

Re: Grindr Shares Personal Information With Third-Parties

#294

It might be worth making another post to highlight an additional concern: this repository itself appears to leak profile images of many Grindr users. The raw-data folder includes nearly 14,000 files, including many ads and scripts, but also thumbnails of many user profiles. This file[1] for example, once you strip out the HTTP headers, is a JPEG that shows the legs and gym socks of one user. This one [2] shows a user…

Since SINTEF is based in Norway, it's certainly possible that my profile picture is somewhere in there, and that really pisses me off. I'm out and have no problem with people knowing that I'm gay, but I shouldn't have to deal with "researchers" pulling this type of crap.

Are you happier with teens in Slovakia pulling this type of crap? If it isn't locked down someone has already scraped it and saved it forever. That you don't see most of the data being stored about you means nothing.

Just another data-point explaining why in 10 years you got pulled off that Emirates plane in a layover in Dubai and were never seen from again.

Re: Grindr Shares Personal Information With Third-Parties

#295

I'd be interested to see how Scruff/Jack'd/etc stacks up. My guess is Scruff does better (it has always been a better designed/developed app) but I understand why they focused only on Grindr as it does have the largest market share (admittedly a guess). Grindr has never been exactly a bastion of good programming... Their app has always been subpar at best with infrequent updates, months/year long bugs, terrible UI/Na…

Grindr has the largest share of users by far. I suspect SCRUFF is #2, both because it is almost as old, but also because they clearly skew towards a different segment of the community. I assume that Jack'd and Hornet are more popular in certain geographical areas.

But I agree with pretty much everything you say, except for wanting to emphasis that getting people to enter their status is crucial in helping to normalize regular testing, safe sex practices, and allowing HIV+ individuals to be open members of the community.

Re: Grindr Shares Personal Information With Third-Parties

#296

Earlier quoted context omitted.

Since SINTEF is based in Norway, it's certainly possible that my profile picture is somewhere in there, and that really pisses me off. I'm out and have no problem with people knowing that I'm gay, but I shouldn't have to deal with "researchers" pulling this type of crap.

Are you happier with teens in Slovakia pulling this type of crap? If it isn't locked down someone has already scraped it and saved it forever. That you don't see most of the data being stored about you means nothing. Just another data-point explaining why in 10 years you got pulled off that Emirates plane in a layover in Dubai and were never seen from again.

To me that's the slippery slope argument.

Sure, someone else could have done it already, or could be doing it right now. But SINTEF is supposed to be reputable research organization, and I think it's more than acceptable to expect them to properly handle any data they gather.

Grindr faces significant hurdles in improving security and complying with GDPR, and we do need to hold them to account, but that does not absolve SINTEF of their responsibilities either.

Re: Grindr Shares Personal Information With Third-Parties

#297

It's scary that it doesn't surprise me anymore. Especially social networks are considered most lucrative in terms of targeted marketing and data mining, and it's obvious why. Social networking remains a big deal, it's almost mandatory to have some social networking footprint online, or else you miss out on social life. Why is it still OK to trade data distilled from social media accounts? It's not! One of the many re…

I think that adoption of privacy preserving data aggregation/analysis will become the norm. The most immediate applications are 1) telemetry data that is used for monitoring (for example, Google Chrome uses differential privacy for collecting this data), and, 2) services like Google Maps and Tinder-like dating apps. In these applications, essential user information can be represented as integer/boolean values (is use…

This requires trusting at least one of the servers to store your raw data, correct? Local differential privacy doesn't.

You might imagine having servers in different countries so that the whole system can't be subpoenaed by any one country, but I believe this is a legal gray area that becomes illegal if you say you're doing this to be intentionally subpoena-proof (in the US).

Re: Grindr Shares Personal Information With Third-Parties

#298

Earlier quoted context omitted.

Reminds me of the relationship between the Mafia and the homosexual community of the early-mid 20th century. The Mafia didn’t particularly like gays, but they ran all of the gay bars because it gave them the opportunity to blackmail their patrons.

> The Mafia didn’t particularly like gays, but they ran all of the gay bars because it gave them the opportunity to blackmail their patrons Source? Curious to read more about this.

"At the time of the 1969 Stonewall Uprising, the Greenwich Village bar Stonewall Inn was owned and operated by the New York Mafia."

http://www.pbs.org/wgbh/americanexperience/features/stonewal...

Re: Grindr Shares Personal Information With Third-Parties

#299
post #145

Even within its confines, Grindr's data are rich for blackmail. (Consider: images and messages sent and received within 100 feet of Capitol Hill.) It was recently acquired by an offshore billionaire [1]. [1] https://www.bloomberg.com/news/articles/2016-01-12/china-tec...

Yikes. Combine this with the Chinese OPM hack, where extremely personal data for most government employees with security clearance has been stolen, and they have a blackmail goldmine on their hands. https://en.wikipedia.org/wiki/Office_of_Personnel_Management... They can verify what has been reported on sf-86 vs what might be found from this service. Any affairs or issues not reported are ripe for blackmail. Possibil…

Uh, none of this would be on an SF86. You don't report affairs or dating on an SF86. They could still correlate membership and expose anyone who is private about their sexuality or hobby, but they won't be able to say "omg you didn't tell the government you banged Paul!"

Re: Grindr Shares Personal Information With Third-Parties

#300
post #215

Earlier quoted context omitted.

Another data point on why you should not take money or sell your business to Chinese investors. Their price points for pricing companies is strange (e.g. a lot higher than western pricing) and it would make sense that they're doing it for other, perhaps more nefarious, reasons.

If I’m selling my company and a Chinese buyer offers me more, I’m not going to turn him down just because he’s Chinese.

Your patriotism and integrity are noted. The things some people will do for a buck tells you all you need to know about unregulated trade.
Post reply on HN