Earlier quoted context omitted.
Dude, Spotify is a song streaming service. Holding on to song history is one of the features they offer. Lyft and Uber are taxi services. Holding on to history is a feature. Go start your own privacy car if you want. I’m not in favour of this world where you privacy first people want all these features removed from applications I use.
They keep quite a bit more than what you see on the surface, or what would be needed for the simplest definition of play history https://twitter.com/steipete/status/1025024813889478656
Unintended Consequences: How the GDPR Can Undermine Privacy
31–40 of 50 posts
Re: Unintended Consequences: How the GDPR Can Undermine Privacy
#32It's ironical that websites implement GDPR compliance using cookies.
Re: Unintended Consequences: How the GDPR Can Undermine Privacy
#33This is absolutely a problem we thought about, but we never found a good solution. Try getting the general public to use two-factor auth. Just try and see how that works out.
Re: Unintended Consequences: How the GDPR Can Undermine Privacy
#34Earlier quoted context omitted.
No. Cookies required to do something the user asked do not require consent. This is solely on the lazy and/or dishonest webdevs. See http://ec.europa.eu/ipg/basics/legal/cookies/index_en.htm#se...
Before the cookie law websites did not have annoying useless cookie popups though, so it's an unintended consequence
Re: Unintended Consequences: How the GDPR Can Undermine Privacy
#35Techdirt misses the point. Companies should only collect what they need, and only keep it for as long as they need it, and they have to store it safely while they have it. All companies get hacked. GDPR compliant companies will have less personal data than other companies who see personal data as something to be gathered in huge amounts and stored for as long as possible, or even sold off.
For a public company that’s just not possible. They’d be trowing money out the window just for kicks. The only way we’ll ever get there is through law.
Re: Unintended Consequences: How the GDPR Can Undermine Privacy
#36Re: Unintended Consequences: How the GDPR Can Undermine Privacy
#37Unintended consequences of flatscreen tv’s. They increase the loss when people break into your home! When will lawmakers take action and ban those pesky flatscreens...
A better analogy would be catalytic converters, which increase the loss when a car is stolen, since there's a significant quantity of precious metal up the tailpipe.
Perhaps an even better analogy (since it provides a direct safety benefit to the purchaser) is that of airbags. For a while, they created an attractive break-in/theft target on their own, due to their very high value to size/weight ratio. I'm pretty sure that was an unintended consequence, too.
Re: Unintended Consequences: How the GDPR Can Undermine Privacy
#38Note that techdirt tracking consent form start with all options pre-toggled to "active". This is in violation of the GDPR, is a pain to turn off, and indicates that no, techdirt does not care about the users privacy.
Re: Unintended Consequences: How the GDPR Can Undermine Privacy
#39The GDPR also requires companies to provide another means to access data that is different from the right to data portability, this different article is known as 'the right of access by the data subject'[1] and has much more stringent requirements. It can apply to things like your work place or previous places that you have worked, it can apply to health providers, it can apply to a security consultancy agency you hired 15 years ago to install alarms to your house, etc. The purpose of this article is to provide the 'checks' part in checks and balances, it allows a user to verify whether a company is holding information on them, what data they're holding, why they're holding it, and the rights of rectification or erasure (that is again separate from the 'right to erasure' article) among other things. This may seem similar to the right of data portability at first glance but it covers different niches and is much more broad with a bigger bite, it can apply to companies that do not have a website and to companies you do not have an account with (but may still be holding data on you).
Techdirt however confuses the purpose of these two articles and instead transposes the rationale behind article 15 onto article 20 and calls it a failing of the GDPR. Quoted here:
>That's because, under the GDPR, platforms are supposed to make all of the data they have on you easily downloadable. The theory is that this will help you understand what a company has on you (and, potentially, to request certain data be deleted). But, it also means that should anyone else get access to your account, they could access an awful lot of important and/or personal data.
Let's be clear here, this is not a failing of the GDPR and is arguably a reason as to why the GDPR needs to exist in the first place especially in regards to requiring clear and informed consent or having clear explanations of what data is kept and why. The last part of the quote rings true, if someone has access to your account they can collect the data that is on that account. It should almost go without saying, but it is an embarrassment that it needs to be explained to a tech blog that is masquerading as tech journalism. Other people in the thread have given the example that if someone has access to your email account they can download all of your emails. If someone has access to your Facebook account, they can access all your messages and posts, private or otherwise - hopefully you haven't sent any private pictures to anybody. If someone has access to your Google account they likely have access to 1) your emails, 2) your full search history for however long you have had that account, 3) your full Youtube search history, 4) any private or unlisted Youtube videos that you may have uploaded, 5) any files you have uploaded to Google Drive, 6) any spreadsheets or documents you may have uploaded (if you have flown before and have opened your e-ticket in Google Docs this will have your passport number on it), 7) your full payment history through Google Play or Google Wallet (now defunct), 8) your full location/gps history if you have location enabled on your mobile device, etc. The list goes on. More importantly than having access to all of this, with nothing more than knowing the password, a black hat will be able to crawl all of this data using public scripts that can be found on Github and they can do all of this without the right to data portability. This is one area where black hats as well as technically inclined people have been more aware of the risks of using services like Google than the average person has, and it should remind anybody of the adage 'convenience is the enemy of security'.
The article goes on,
>As Jean notes in a later tweet, this kind of thing could really come back to bite other services, such as Lyft or Uber. She jokes: "Would be pretty bad to get hacked and kidnapped in the same day."
Yes, that would be unfortunate. What is more unfortunate is that companies have trained users to accept that there is no compromise, that it's all or nothing, that users need to store their full location and travel data or none at all. I understand the convenience that being able to rebook frequent frequently travelled taxi routes, I understand the convenience of having a fitness tracker that logs GPS data, however is it a convenience that needs to come with clear and informed consent, with an explanation of the implications of keeping this data that may be accessed and updated in real time, and it needs to come with the option of selectively being able to choose where or how much you would like to opt out. I am struggling to think of how this could possibly be a failing of the GDPR over a failing of the companies to provide these features and opt-outs without formal legislation, as a thought experiment, what would happen if Uber or Lyft had a data breach that had leaked all of their booking history? What would happen if Google had an authentication failure and allowed anybody to view your location history? Or how about allowing anybody to use 'Find your phone'?
The final insult to injury in the article is this quote,
>There are possible technological solutions that could help (again, as Jean suggests), such as using multi-factor authentication to access your own data (one-time passwords, Yubikey, etc), but it's telling that few companies (or regulators!) have really thought about that, because that vector of attack probably hasn't occurred to many people. But, it probably will now.
This is not a new attack vector by any stretch of the imagination and to suggest that it's due to the GDPR is quite frankly horribly misinformed. There was a technique that was popular around 2004-2006 (if Google Trends is anything to go by) that was known as 'fusking', the gist of it is that incremental or predictable file names can easily be guessed and crawled by computer scripts and utilities, it was more often than not used to extract all urls from an image gallery (usually pornographic) however it presented difficulties in personal image hosting websites, as filenames along the lines of "2004-07-22-0035.jpg" could just as easily lead to images that could accidentally be crawled if an attacker were to put "2004-07-22-[0000-0100].jpg" into their fusker utility. This presented some challenges to hosting companies who needed to add UUIDs to the filenames, and eventually the attack was somewhat mitigated when mobile phones started naming images with much finer granularity or even adding a salt to the image so that it could not be guessed. This is why websites like Facebook have long and unwieldy urls so that they cannot be guessed. While this attack is an old one it still pops up from time to time, in 2006 both Microsoft and Google had a vulnerability where their url shortening services could be guessed, which led to accidental exposure for users who were using short urls to generate links to private folders. You may be thinking that this is only tangentially related to being able to download user profiles, and I'll admit that it is, but I want to reinforce the point that black hats and other attackers, or even more technically inclined people, are far more equipped to think about the possibility of crawling and downloading large amounts of data that a regular user may be oblivious to or not even realise exists.
To give the article a tiny bit of credit, the GDPR does not stipulate that the right to data portability should require additional authentication like multi-factor (which can be as simple as an email link with a one time token), and this is certainly a shortcoming that should be addressed, but it is also a shortcoming that a company that cares about your privacy should be able to address of their own accord.
EDIT: on reflection it is a novel idea that just anybody can download your full profile if they have access to your account but at that point the damage has arguably already been done, a site like Facebook requires you to wait for a while before a download link is generated and ones like Google require a password before you can change any account settings. It's probably less intrusive and noticeable if you crawl the profile than to use the download link as there won't be any emails sent.
[0] https://gdpr-info.eu/art-20-gdpr/
[1] https://gdpr-info.eu/art-15-gdpr/
[2] https://arstechnica.com/information-technology/2016/04/guess...
Re: Unintended Consequences: How the GDPR Can Undermine Privacy
#40There's a better solution: Stop collecting and keeping personal data. I can't even read this article without using firefox reader mode to skip the cookie warning / prompt (this works for a lot of sites!). That's a choice that techdirt make. By framing it as an unavoidable consequence of the cookie legislation or GDPR moves the focus to the wrong place.
Collecting data subsidizes the cost of the service. Would facebook have 1 billion users if it cost $5.99 a month? Data collection is not going anywhere, so long as people are willing (even unknowingly) to give up info for a perceived discount. Now here - fill out my form with your address, email, phone, photo id, and passport number for a chance to win a brand new 2019 Honda!
"Accept data collection or pay for it" is a false dichotomy. Ad-supported websites don't need data collection to be profitable, just as NBC doesn't.
Furthermore, there are many paid services that collect data as well. Last time I flew with KLM the online check-in didn't work because some JS errored out as its data collection script was blocked. Turned out it was sending data to 17 domains on the on-line checkin page:
4232724.fls.doubleclick.net ad.atdmt.com apps.static-afkl.com c.webtrends.com cdn.tagcommander.com connect.facebook.com dynamic.dimml.io googleads.g.doubleclick.net lm.commander1.com platform.twitter.com sjs.bizographics.com statse.webtrendslive.com t.svtrd.com tdn.r42tag.com w.usabilla.com www.google-analytics.com www.googleadservices.com
And KLM isn't even a budget airline like RyanAir. I paid good money for my flight.