Live data from Hacker News

Proposed Jail Time for Tech Companies Who Steal Data

trofire.com

141–150 of 203 posts

Re: Proposed Jail Time for Tech Companies Who Steal Data

#141
post #57
post #49

Earlier quoted context omitted.

> Is personal information really a kind of property, that can be stolen? If it is, aren’t we doing this all the time, any time we perceive anything about anyone? We are flexible and smarter than Vulcans. Something doesn't have to be necessarily expressible into a single, unambiguous universal formula to be made illegal. We can e.g. allow people to perceive things about other people in their brains (or even notebooks)…

Rule of law demands it be clear what is and is not illegal. Make it illegal to film people in public and the guy who made the Rodney King tape is going to jail.

Your first sentence isn’t true. I was just looking at the laws regarding applying for a sellers permit and filing the tax status for my startup (deductions, compensation, etc).

A single example of the laws not being clear-cut and concrete, but hopefully covering enough ground that people can be reasonably expected to understand, is illustrated in IRS Publication 535 under 2. Employees’ Pay.

Reasonableness is defined as:

Test 1—Reasonableness

You must be able to prove that the pay is reasonable. Whether the pay is reasonable depends on the circumstances that existed when you contracted for the services, not those that exist when reasonableness is questioned. If the pay is excessive, the excess pay is disallowed as a deduction.

Factors to consider. Determine the reasonableness of pay by the facts and circumstances. Generally, reasonable pay is the amount that a similar business would pay for the same or similar services. To determine if pay is reasonable, also consider the following items and any other pertinent facts.

- The duties performed by the employee. - The volume of business handled. - The character and amount of responsibility. - The complexities of your business. - The amount of time required. - The cost of living in the locality. - The ability and achievements of the individual employee performing the service. - The pay compared with the gross and net income of the business, as well as with distributions to shareholders if the business is a corporation. - Your policy regarding pay for all your employees. - The history of pay for each employee.

https://www.irs.gov/publications/p535#idm139767235089984

It is LITERALLY IMPOSSIBLE to cover all of the cases with laws. Arguing “common sense” also isn’t valid, “common sense” isn’t really “commonly shared”.

So, we do our best to create laws that cover bases but also give room for interpretation SO THAT WE CAN catch those people who are deliberately trying to break them.

If we said “you may not go over the speed limit” what happens if a bunch of people decide to go under, making it unsafe for other people?

They would have a basis to argue that they were not breaking the law.

So we create laws that are also guidelines.

Re: Proposed Jail Time for Tech Companies Who Steal Data

#142

> There is no reason why any person on Capitol Hill should vote against this. If I were an elected official, one reason why I would be very cautious about voting for this is that, if we make allowing a data breach a felony punishable by imprisonment, it is likely to have a somewhat chilling effect on the likelihood of engineers to start new companies where they as founders would be potentially prosecutable for such f…

> it is likely to have a somewhat chilling effect on the likelihood of engineers to start new companies where they as founders would be potentially prosecutable for such failures You seem to think that's a bad thing, for some reason.

Well, less competition is generally considered to be a bad thing.

Re: Proposed Jail Time for Tech Companies Who Steal Data

#143

Earlier quoted context omitted.

Read that quote again. It only says opt-in was needed to use this „feature“, not for data access. And that does not even include the other parties in those messages.

“Did partners get access to messages? Yes. But people had to explicitly sign in to Facebook first to use a partner’s messaging feature,” Konstantinos Papamiltiadis, director of developer platforms and programs at Facebook, wrote in the blog post. “Take Spotify for example. After signing in to your Facebook account in Spotify’s desktop app, you could then send and receive messages without ever leaving the app. Our API…

So all they had to do was sign in, and those programs got access to private messages.

What are you trying to refute, exactly?

Re: Proposed Jail Time for Tech Companies Who Steal Data

#144

The great irony here is that people have no issue stealing data -- copyright theft is considered "normal" by many people. However, if it's your data, then maybe jail time should be on the table?

It's not irony. It's you being willfully blind to the difference between "this has copyright" and "this is personal data". Those two aren't even similar!

Re: Proposed Jail Time for Tech Companies Who Steal Data

#145
post #57
post #49

Earlier quoted context omitted.

> Is personal information really a kind of property, that can be stolen? If it is, aren’t we doing this all the time, any time we perceive anything about anyone? We are flexible and smarter than Vulcans. Something doesn't have to be necessarily expressible into a single, unambiguous universal formula to be made illegal. We can e.g. allow people to perceive things about other people in their brains (or even notebooks)…

Rule of law demands it be clear what is and is not illegal. Make it illegal to film people in public and the guy who made the Rodney King tape is going to jail.

You can’t retroactively apply laws, thankfully.

Re: Proposed Jail Time for Tech Companies Who Steal Data

#146

Earlier quoted context omitted.

Read that quote again. It only says opt-in was needed to use this „feature“, not for data access. And that does not even include the other parties in those messages.

“Did partners get access to messages? Yes. But people had to explicitly sign in to Facebook first to use a partner’s messaging feature,” Konstantinos Papamiltiadis, director of developer platforms and programs at Facebook, wrote in the blog post. “Take Spotify for example. After signing in to your Facebook account in Spotify’s desktop app, you could then send and receive messages without ever leaving the app. Our API…

That still says they had access anyway, but you had to opt in to use the feature. Work on your reading comprehension!

Re: Proposed Jail Time for Tech Companies Who Steal Data

#147

Earlier quoted context omitted.

I really love the simplicity of this argument. If you generate the metadata, you own it, no questions asked.

What does "you generate the metadata" mean? If an app on my phone "generates metadata" I own it under this principle. Likewise for code running on my computer.

Your phone/os generate raw inputs (eg touch events in the format of: posx, posy, pressure). Each app then make use of these raw inputs in its own way. SwiftKey will give you some words. Piano app will pay a sound. And So on.

Interpreting and converting these raw inputs into what a user wants, is literally what an app gets paid for.

Re: Proposed Jail Time for Tech Companies Who Steal Data

#148
post #135

Earlier quoted context omitted.

Except that in practice regulation nearly typically protects big incumbents from startup competitors. That is exactly the effect GDPR had in Europe: https://techcrunch.com/2018/10/09/gdpr-has-cut-ad-trackers-i... Incumbents, especially in the tech industry, face a greater threat of being unseated by a startup than being unable to handle regulations. The "heavy hitters" have plenty of cash available to pay for the law…

No, that's not what happened with the GDPR. Most small companies rightfully came to the conclusion that they can't afford to not comply, so at least they tried to. Google though they can afford not to, so they didn't. Now Google is starting to get hit with fines (e.g. France), so they'll probably change their minds.

Google can afford to take as long as they want to comply, and cop the fines along the way.

The startups that never get off the ground because the cost of compliance is prohibitive will mean less competition for Google etc in the long term.

Re: Proposed Jail Time for Tech Companies Who Steal Data

#149
post #41

Is personal information really a kind of property, that can be stolen? If it is, aren’t we doing this all the time, any time we perceive anything about anyone? How is this different than taking a picture of someone? The image is owned by the photographer, not the subject(s) according to current laws. if I meet someone on the street, and record their name, the conversation we had, and the location where I met them, an…

If we consider laws around privacy in meatspace, then here's the common dividing line (according to my memory of an information law class I took something like eight years ago):

If someone is in a public space (such as a park) and you take a photograph for instance that happens to include them in it, then you're not violating their privacy. If they're in their home and you photograph them through their window, that is a violation of privacy because there's a legal expectation of privacy in a private residence.

People are going into the digital equivalent of a park and getting upset when data collection happens there which happens to include them. What happens with that data (selling to advertisers, etc) is not really relevant to the legal privacy discussion. They gave away their data by participating in a public space.

It's sort of like if some organization running public CCTV systems decided to sell recordings of public spaces they covered to advertisers (or heck, even data extracted from those recordings using facial recognition). Creepy? Sure. But not a violation of privacy as such since there is no legal expectation of privacy in a public space. (Incidentally, I'm not sure about the legal details of this specific example, but the point is privacy is dependent on location)

The conclusion, then, is that people who care about legal protection of their privacy online should own the platform where they communicate, such as by hosting a Diaspora pod.

Re: Proposed Jail Time for Tech Companies Who Steal Data

#150
post #41

Is personal information really a kind of property, that can be stolen? If it is, aren’t we doing this all the time, any time we perceive anything about anyone? How is this different than taking a picture of someone? The image is owned by the photographer, not the subject(s) according to current laws. if I meet someone on the street, and record their name, the conversation we had, and the location where I met them, an…

If we consider laws around privacy in meatspace, then here's the common dividing line (according to my memory of an information law class I took something like eight years ago): If someone is in a public space (such as a park) and you take a photograph for instance that happens to include them in it, then you're not violating their privacy. If they're in their home and you photograph them through their window, that i…

If you go into a park and take a picture of the park that has a person standing in the distance and then sell that picture then you have committed no crime.

If you follow someone around the park constantly taking their picture and then decide to sell the ones that look the best without either the permission of nor compensation for the subject of your photo then they have a legitimate claim against you.

People are not getting upset that they are being photographed in the park by someone who is an enthusiast about outdoor architecture and park planning, they are getting upset that the digital paparazzi are recording every footfall and selling it without permission. The idea that this data collection is not something that can or should be regulated is perverse and thankfully the general public is coming around to this viewpoint.

Post reply on HN