Live data from Hacker News

How my sexual health searches ended up in the hands of big tech companies

abc.net.au

11–20 of 95 posts

Re: How my sexual health searches ended up in the hands of big tech companies

#11
post #7

Further proof, as if any was needed, why other countries require something like the GDPR, backed up be significant penalties, and well-resourced enforcement. It won't happen in Australia though, as we are governed by fools who barely understand technology, and if they need to, rely on the representations of business to make any decisions.

From the perspective of a casual, non-European observer, the only effect of the GDPR that I've witnessed is the explosion of websites being extremely aggressive about forcing me to consent to their tracking cookies. Where is the real benefit to Europeans' privacy?

Are you potentially confusing GODR with the EU cookie law?

Re: How my sexual health searches ended up in the hands of big tech companies

#12
post #8

I had a related thing happen a couple of months ago: I started getting some lower back pain that I thought might be kidney stones based on a couple of Google searches. Went to my doctor, who prescribed a muscle relaxant, which I got at the pharmacy across the street. It went away. Over the next few weeks I got several robocalls on my cell phone from a pain clinic offering me relief for my "chronic pain", so it was ei…

Does anyone know how effective incognito mode is at preventing data and privacy abuses like this? I've been using it more and more, but I imagine there may some clever ways of tracking even across incognito sessions (or between incognito and regular).

If google is the issue maybe - but I seriously doubt they are the issue: they sell their ability to target you, and selling your data to third parties would essentially be against their interest. This kind of FUD has been repeated ad nauseam here and everywhere in tech sites (against Facebook too usually), but that's not the way their business model works.

If it's your doctor or your pharmacist, or the shop you bought online (or offline) something once, incognito will not help at all. They have your personal information already, the only thing that can stop them is law. The cause of the robocalls may also have been his medical insurance, if you want to go full paranoia. :)

Note those shops, the sites you created an account on, the companies those shops sold your personal data to, all of them can target you with ads on both facebook and google by using your PI (essentially donating your data to facebook and google in the process).

Re: How my sexual health searches ended up in the hands of big tech companies

#13
post #8

I had a related thing happen a couple of months ago: I started getting some lower back pain that I thought might be kidney stones based on a couple of Google searches. Went to my doctor, who prescribed a muscle relaxant, which I got at the pharmacy across the street. It went away. Over the next few weeks I got several robocalls on my cell phone from a pain clinic offering me relief for my "chronic pain", so it was ei…

Does anyone know how effective incognito mode is at preventing data and privacy abuses like this? I've been using it more and more, but I imagine there may some clever ways of tracking even across incognito sessions (or between incognito and regular).

Your IP makes incognito relatively pointless, and that's before you get into various clever forms of browser finger printing. If you want privacy you need to use TOR. Incognito should be treated as a convenient way to run without cookies / to log out of sites temporarily. It's also nice for sites such as YouTube as they'll pretend to not know who you are so you can get recommendations related to what you're currently watching instead of just constantly recommending everything you've recently (or not so recently...) watched instead.

Re: How my sexual health searches ended up in the hands of big tech companies

#14
post #7

Further proof, as if any was needed, why other countries require something like the GDPR, backed up be significant penalties, and well-resourced enforcement. It won't happen in Australia though, as we are governed by fools who barely understand technology, and if they need to, rely on the representations of business to make any decisions.

From the perspective of a casual, non-European observer, the only effect of the GDPR that I've witnessed is the explosion of websites being extremely aggressive about forcing me to consent to their tracking cookies. Where is the real benefit to Europeans' privacy?

GDPR is just the newest privacy law, a lot of EU countries had privacy laws before GDPR. So it isn't that radical, but the fines are bigger.

We've already seen quicker reporting of breaches. Web trackers are down [0]. Telemetry without an off-switch has been ruled in violation (Microsoft Office [1]). In smaller cases, apps that don't secure passwords properly have been fined [4]. I'm sorry for linking to el Reg so much, but there just aren't that many English language news outlets covering these things.

As for "forcing me to consent", it violates the GDPR (e.g. [2], ICO "consent cannot be freely given and is invalid"). This is largely websites trying to see how far they can push it, because the data protection agencies aren't handing out fines straight away. This is actually very frustrating in obvious cases.

If you'd like to help getting rid of them, but aren't a European or can't be bothered reporting them to the relevant data protection agency, Max Schrems has founded https://noyb.eu/. Privacy international has also done some work in this area [3], but Schrems seems to be focussed on the "smaller" violation such as popups, and has a great track record.

[0] https://www.theregister.co.uk/2018/10/12/gdpr_helps_google/

[1] https://www.theregister.co.uk/2018/11/16/microsoft_gdpr/

[2] https://www.theregister.co.uk/2018/11/19/ico_washington_post...

[3] https://privacyinternational.org/topics/general-data-protect...

[4] https://www.theregister.co.uk/2018/11/23/knuddels_fined_for_...

Re: How my sexual health searches ended up in the hands of big tech companies

#15
post #8

I had a related thing happen a couple of months ago: I started getting some lower back pain that I thought might be kidney stones based on a couple of Google searches. Went to my doctor, who prescribed a muscle relaxant, which I got at the pharmacy across the street. It went away. Over the next few weeks I got several robocalls on my cell phone from a pain clinic offering me relief for my "chronic pain", so it was ei…

Does anyone know how effective incognito mode is at preventing data and privacy abuses like this? I've been using it more and more, but I imagine there may some clever ways of tracking even across incognito sessions (or between incognito and regular).

Not effective. Use Tor Browser instead.

https://panopticlick.eff.org/

Re: How my sexual health searches ended up in the hands of big tech companies

#16
post #12

Earlier quoted context omitted.

Does anyone know how effective incognito mode is at preventing data and privacy abuses like this? I've been using it more and more, but I imagine there may some clever ways of tracking even across incognito sessions (or between incognito and regular).

If google is the issue maybe - but I seriously doubt they are the issue: they sell their ability to target you, and selling your data to third parties would essentially be against their interest. This kind of FUD has been repeated ad nauseam here and everywhere in tech sites (against Facebook too usually), but that's not the way their business model works. If it's your doctor or your pharmacist, or the shop you bough…

I'm assuming it's not the doctor or pharmacist, as that would be a severe breach of HIPAA, I believe. But maybe that is happening...

Re: How my sexual health searches ended up in the hands of big tech companies

#17
post #7

Earlier quoted context omitted.

From the perspective of a casual, non-European observer, the only effect of the GDPR that I've witnessed is the explosion of websites being extremely aggressive about forcing me to consent to their tracking cookies. Where is the real benefit to Europeans' privacy?

Are you potentially confusing GODR with the EU cookie law?

No, these notices explicitly mention the GDPR.

Re: How my sexual health searches ended up in the hands of big tech companies

#18
post #12

Earlier quoted context omitted.

Does anyone know how effective incognito mode is at preventing data and privacy abuses like this? I've been using it more and more, but I imagine there may some clever ways of tracking even across incognito sessions (or between incognito and regular).

If google is the issue maybe - but I seriously doubt they are the issue: they sell their ability to target you, and selling your data to third parties would essentially be against their interest. This kind of FUD has been repeated ad nauseam here and everywhere in tech sites (against Facebook too usually), but that's not the way their business model works. If it's your doctor or your pharmacist, or the shop you bough…

When I said triggered by my google searches, I mean the sites I clicked on were able to correlate to my personal details that got collected somewhere else, not that google sold my details. The thing that makes me suspect the doctor or pharmacy, though, is that I've done that sort of search in the past, but I didn't start getting the pill mill calls until I got that prescription.

Re: How my sexual health searches ended up in the hands of big tech companies

#19
post #6

Further proof, as if any was needed, why other countries require something like the GDPR, backed up be significant penalties, and well-resourced enforcement. It won't happen in Australia though, as we are governed by fools who barely understand technology, and if they need to, rely on the representations of business to make any decisions.

Has GDPR meaningfully changed enforcement of rights? I’m familiar with the law itself and the details of it. (IAAL who practices in this area.) I’ve seen these regulatory pushes toward consumer-oriented privacy in the past, and they seem to serve the consulting industry above all. The consequences of breaking the rules are laughably impotent so far, despite more or less well-meaning words passed as binding legislatio…

> People don’t even seem to punish the offenders by shifting their spending habits

Well, if that was viable, we probably wouldn't have needed such high fines in the GDPR. Two scenarios:

A) It's hard to move away because of dominance, e.g. Google. You either have to buy an offensively expensive iPhone, or root an Android phone. Even then living without the Play store is hard. Moving e.g. email providers takes years nowadays regardless of the provider. Google Search and Maps can be replaced in theory, but it's quite a chore - Google didn't get big on bad products.

B) What spending? How do you stop spending on something you aren't paying for with money? Yes, ad and tracking blockers, but for Joe Bloggs that isn't obvious. And Consumers weren't paying Equifax directly, otherwise they probably would have been bankrupted.

> Has GDPR meaningfully changed enforcement of rights?

We don't know yet. (I'm assuming this isn't a rhetorical question.)

On the one hand, the fines now have business impact. For example, before the GDPR, the UK's ICO could only hand out a laughable max fine of £500,000. On the other hand, ICO has been toothless, only handing out the max fine once. ICO was severely underfunded, so this is almost by design.

Germany is pretty privacy conscious, but unfortunately data protection is also handled on a state level. So there are 16 data protection agencies and one federal one (Datenschutzaufsichtsbehörden, the federal one being the BfDI). From experience, that kind of bureaucracy doesn't help with speed.

While this isn't enforcement, it has had some meaningful effect. Having worked for a big multinational, there was a lot of money and hours spent on GDPR compliance. This reduces e.g. data retention, which could help limit damage in future. Before that, data retention was basically endless.

We've seen some minor cases, but being a lawyer, I'm sure you know we're at least a few years off the really big cases, especially if the European data protection authorities need to work together.

Re: How my sexual health searches ended up in the hands of big tech companies

#20
post #7

Further proof, as if any was needed, why other countries require something like the GDPR, backed up be significant penalties, and well-resourced enforcement. It won't happen in Australia though, as we are governed by fools who barely understand technology, and if they need to, rely on the representations of business to make any decisions.

From the perspective of a casual, non-European observer, the only effect of the GDPR that I've witnessed is the explosion of websites being extremely aggressive about forcing me to consent to their tracking cookies. Where is the real benefit to Europeans' privacy?

[deleted]
Post reply on HN