Live data from Hacker News

Privacy Icons

azarask.in

11–17 of 17 posts

Re: Privacy Icons

#12
post #9

Earlier quoted context omitted.

> It's an obvious question to say "Do you store personal information for more than X months? still the question is, what exactly qualifies as "personal information", many seemingly irrelevant things can be used to identify you, login ip addresses, session ids, login frequency, Its a term with holes the size of Montana. > Being "very hard to stop" isn't relevant. I will concede this point, but uncovering cooperation c…

> still the question is, what exactly qualifies as "personal information", many seemingly irrelevant things can be used to identify you, login ip addresses, session ids, login frequency, Its a term with holes the size of Montana. "Personally identifiable information" is not some nebulous term that means whatever the writer wants it to mean, it has a pretty strict legal meaning. "Information which can be used to disti…

>when combined with other personal or identifying information which is linked or linkable to a specific individual

Take a look into data de-anonymization techniques, this can encompass basically any stored information at all. This is not at all a clear issue.

(pdf warnings)

http://www.cs.utexas.edu/~shmat/shmat_oak08netflix.pdf

http://iseclab.org/papers/sonda-tr.pdf

Re: Privacy Icons

#13
I think any "bad" actors will simply display the easier-to-achieve privacy icons and not display poor privacy icons (this is contrary to the authors opinion that bad actors will decide to display none at all). The issue is consumers will start to see "black circle with green ring" and associate it with good privacy, whether or not the site displayed all 5 or only 1 or 2 of them.

To summarize, it is worse for a consumer to be misled about a website's privacy policy than to not display one at all.

Re: Privacy Icons

#14

I think any "bad" actors will simply display the easier-to-achieve privacy icons and not display poor privacy icons (this is contrary to the authors opinion that bad actors will decide to display none at all). The issue is consumers will start to see "black circle with green ring" and associate it with good privacy, whether or not the site displayed all 5 or only 1 or 2 of them. To summarize, it is worse for a consum…

I think you're right about the danger of conditioning users to trust a certain symbol. See also: anything with a yellow padlock icon or a brightly coloured shield icon.

> To summarize, it is worse for a consumer to be misled about a website's privacy policy than to not display one at all.

On a related note, the descriptions for the negative icons aren't in the form "can't promise this good thing", they are in the form "does this bad thing". If Mozilla started displaying those negative icons against any site just because the site didn't follow their non-standard privacy policy protocol/mark-up, then that would be not only misleading to users but potentially damaging to sites that really do take privacy seriously and happen to say so in plain $LANGUAGE rather than using Mozilla's pre-defined, machine-readable categories. That also sounds to me like a lawsuit waiting to happen if anyone's traffic stats suggest that they are taking a hit because of Mozilla's misdescription.

Re: Privacy Icons

#15
post #11

I was disappointed by the lack of an icon to represent "data is never shared with law enforcement."

In America law enforcement can get a court to issue a warrant if they can prove just cause. You could refuse to comply with the warrant, but you'd be jailed.

Besides, I want police using the Internet as an investigative medium. I just want them to get a warrant. The real problem we have these days is when companies roll over for the government and give them whatever data they want without just cause.

Re: Privacy Icons

#16
You know how you sometimes run across a set of icons which immediately spark universal recognition? Ones which are visible at any size, that are language and culture independent? For me, these don't come close.

How I'd make things clearer is mostly by eliminating the "person in document" graphic and focusing on the rest. So the "your data is never sold" icon, it's a dollar sign in a circle that has a diagonal slash trough it... like the creative commons non-commercial icon. For "your data may be sold" there is no slash. Similar for law enforcement. The others I don't have a lot of ideas about, but I would think that "AD" (for example) doesn't translate well into other languages. Would Japanese users recognize what that means?

Re: Privacy Icons

#17

I think any "bad" actors will simply display the easier-to-achieve privacy icons and not display poor privacy icons (this is contrary to the authors opinion that bad actors will decide to display none at all). The issue is consumers will start to see "black circle with green ring" and associate it with good privacy, whether or not the site displayed all 5 or only 1 or 2 of them. To summarize, it is worse for a consum…

A lot of scummy sites use static "secure site" logos which have no backing in order to deceive the user into believing the site has some sort of security in place. These mimic the geotrust and hacker safe logos typically but I've seen all kinds. Bad actors have no problem misleading consumers by duplicating common "indicators" of positive reputation and are already actively doing so. A new set of privacy icons would just as easily and quickly be deployed to deceive consumers further.
Post reply on HN