> There is nothing in the privacy policy that addresses [that data is being sent to Facebook] > The Zoom app notifies Facebook when the user opens the app, details on the user's device such as the model, the time zone and city they are connecting from, which phone carrier they are using, and a unique advertiser identifier created by the user's device which companies can use to target a user with advertisements So Zoo…
One thing i'll note here as to a potential reason why they do this
I just recently attempted to set up Facebook adverts for an app I developed. When it came time for me to set the metric up I obviously chose "App Installs" as my metric to track.
To do this, Facebook told me I needed to install the Facebook SDK in my app to attribute an adverts conversion.
I didn't end up running the ad, but I can see why companies potentially have the SDK embedded in their apps to track ad-spend, hence the phoning-home to Facebook.
It's past time for us to get serious and apply HIPAA-style protection to the storage and transmission of PII, without exemptions. Companies like Facebook will complain loudly that they won't be able to survive, but that is not our problem. If we pass legislation with teeth, they will need to change their business model. That would be the point.
I disagree with this — more regulation will make it harder to innovate. For example, I’ve met several founders who wanted to enable tele-medicine years ago but decided against it because “the lawyers cost more than the engineers”, and walking-on-eggshells destroys morale & iteration speed. I’m not arguing to de-regulate heath data — my point is that we should selectively apply regulation. It’s likely a great thing to…
When it comes to surveillance capitalism, making it harder to innovate is the point. Innovation is not intrinsically good.
People aren't allowed to go through my mailbox and sell that information. I don't see how this is any different.
They are allowed to look at you and take notes and sell them.
Depending on the specifics they may not be. I live in a Condo tower and my mailbox isn't visible from the street, so if you decided to take notes on me as I read my mail you'd be trespassing.
The specific scenario isn't the point - but the fact that a semi-obvious scenario could be incorrect sorta is. Regulations are complex and tech has a terrible history of playing fast and loose with regulations so it's not like an imposition of regulations would be inappropriate or unwarranted - there are good and bad apples, and the bad apples spoil the bunch.
It's past time for us to get serious and apply HIPAA-style protection to the storage and transmission of PII, without exemptions. Companies like Facebook will complain loudly that they won't be able to survive, but that is not our problem. If we pass legislation with teeth, they will need to change their business model. That would be the point.
I disagree with this — more regulation will make it harder to innovate. For example, I’ve met several founders who wanted to enable tele-medicine years ago but decided against it because “the lawyers cost more than the engineers”, and walking-on-eggshells destroys morale & iteration speed. I’m not arguing to de-regulate heath data — my point is that we should selectively apply regulation. It’s likely a great thing to…
You can develop all of these services, just don't hoard data. With no centralized serverside database you have no liabilities. P2P is a solved problem.
Better implementations of that is exactly the kind of innovation we need now.
I like the effort started by Objective Development (creators of little snitch) called IPA: Internet Access Policy [0]. An IAP is a document that defines to what endpoints does an application connect too. Apple should get on this bandwagon and enforce it and the OS level, so that any application must ship this IAP document and only be allowed to connect the endpoints listed in that document. Furthermore a user should have the option to see which endpoints/domains those are, and disable some of them.
It's past time for us to get serious and apply HIPAA-style protection to the storage and transmission of PII, without exemptions. Companies like Facebook will complain loudly that they won't be able to survive, but that is not our problem. If we pass legislation with teeth, they will need to change their business model. That would be the point.
I disagree with this — more regulation will make it harder to innovate. For example, I’ve met several founders who wanted to enable tele-medicine years ago but decided against it because “the lawyers cost more than the engineers”, and walking-on-eggshells destroys morale & iteration speed. I’m not arguing to de-regulate heath data — my point is that we should selectively apply regulation. It’s likely a great thing to…
Why disagree with this, it actually will cause innovation. How, if someone is able to figure out the way to navigate the laws easily, they will then sale their solution as a service.
So when a FB, Goog or MS can figure it out, they will add it to their stuff. Also a group like EFF would make a tool to verify since it would mean that their existing tools would just be checking the server instead of each thing like Privacy Badger and their other apps do.
It was really easy to innovate the car (look, I made this out of hard pointy steel, who cares if anyone else dies). Until you had to actually made them safe, do you think society would be better off going to the old methods? Innovation is for a purpose, a lot of the stuff we see now seems to be to innovate for the purpose of innovations sake and then sell it to someone who cares.
Also do you really think people won't invest if their current methods don't work, so startup culture wouldn't die. Just system of having people who don't care about privacy not actually think things through ethically first.
If a company can't 'innovate' without sharing users' data with third parties or treating it recklessly through lax security (or uploading database dumps to publicly-accessible S3 buckets) then that company doesn't deserve to be in business. It doesn't take a suite of lawyers to enforce that, either. Health care is gigantic mess of bullshit in the US especially, because of the multiple different 'stakeholders' - custo…
I think you've missed your parents point. The problem they point out is that well intentioned businesspeople who want to provide you a useful service and store your data correctly are priced out. If you want to deal with medical data of any kind, you need a lawyer. Full stop. It doesn't matter how good your intentions are, or how many "best practice" blog posts you follow. You need to hire a lawyer, and lawyers are i…
If you don't store any data you won't need any lawyers. You don't need to store a single byte of data on your users or customers to provide a service or software using that data.
The good thing is that this is illegal in the EU, so they can just be sued for problematic amounts of money.
They can’t be sued. They can be reported to a proper privacy authority who can chose to do something about it or not.
GDPR Article 79 [1]:
> 1. Without prejudice to any available administrative or non-judicial remedy, including the right to lodge a complaint with a supervisory authority pursuant to Article 77, each data subject shall have the right to an effective judicial remedy where he or she considers that his or her rights under this Regulation have been infringed as a result of the processing of his or her personal data in non-compliance with this Regulation.
> 2. Proceedings against a controller or a processor shall be brought before the courts of the Member State where the controller or processor has an establishment. 2Alternatively, such proceedings may be brought before the courts of the Member State where the data subject has his or her habitual residence, unless the controller or processor is a public authority of a Member State acting in the exercise of its public powers.
So what options do we have for private video conferencing?
jitsi-meet, see: https://meet.jit.si/ https://github.com/jitsi/jitsi-meet You can self-host it, or use the first link. No need to give your email, name, or phone number.
Indeed. We don't need regulation. Nobody is forcing anybody to pay Zoom for the privilege of sending their data to Facebook.
I've been using Jitsi a lot recently and it's great! It's high-quality free (libre) open source software.
Similar to how we have organizations which can certify whether produce is organic or not, we need organizations which can certify whether apps and websites are certified ad tracking free.
Ironically, those orgs have themselves been accused of being pay-to-play -- if you give them enough money they will certify you organic. Since it's industry run, there is no one checking that the organic certifiers are legit. It's turtles all the way down. The only legit solution is the government, because they are the only ones without a profit motive in the whole system (although they can be bribed, but that's a wh…
They may be without a profit motive but individual bureaucrats and legislators certainly have a power motive which is often just as, if not more, insidious.