Live data from Hacker News

Open letter: Ban surveillance-based advertising

vivaldi.com

121–130 of 271 posts

Re: Open letter: Ban surveillance-based advertising

#121
post #118

Earlier quoted context omitted.

I don't think that's gonna cut it, but definitely on the right track. Its going to require some kind of legislation, or an insurance requirement that renders the insurers as de-facto regulators. This is still crazy hard due to the possibility of regulatory arbitrage, just open shop in Anguilla or wherever. Without the auditing, compliance, and domain experts to verify and implement this, its going to be extremely har…

The problem is it is not easy to asses the security risk of small businesses in a cost effective way for insurance companies. It's really hard to come up with a set of regulations here that protects users data and doesn't completely disadvantage startups and small businesses.

We do not regulate how a coffee shop does accounts in the same way we regulate a bank.

Many regulations only apply to companies bigger than 50 employees, more than billion of turnover, data on over 1 million people, etc. Or in a spesific market.

Re: Open letter: Ban surveillance-based advertising

#122

I think there's a simpler way to achieve this. Force companies who leak personal data to pay reasonable damages to all the individuals involved, on the scale of 10-100 dollars, depending on how much personal info has been leaked. That would make businesses very quickly reassess how much data they need to keep, and how careful they need to be with it, without requiring any really radical legislation.

>Force companies who leak personal data to pay reasonable damages to all the individuals involved

Doesn't this just consolidate power among FAAG even more? They can pay these fines and they don't often leak data- if ever. That's another thing- define leaking data. Sharing with 3rd parties? It's vague enough for them to beat that in court.

We do somehow need to get back to advertising the old fashioned way rather than this surveillance capitalism arms-race.

Re: Open letter: Ban surveillance-based advertising

#123

I think there's a simpler way to achieve this. Force companies who leak personal data to pay reasonable damages to all the individuals involved, on the scale of 10-100 dollars, depending on how much personal info has been leaked. That would make businesses very quickly reassess how much data they need to keep, and how careful they need to be with it, without requiring any really radical legislation.

Yeah, rather than targeting advertising I'd prefer to get to the actual point, and target mass surveillance and collection of huge troves of personal data no matter the purpose . Ban monetizing data (no selling, no pay-for-access, no derived products) and make leaks guaranteed to be expensive, so companies only keep what they have to to operate, with some large multiplier attached to the leak fine if it was related t…

I'm curious how you would see "ban monetizing data" play out in the case of an e-commerce company. Can they still run A/B tests? Show you products that they think you will want to buy based on your purchase history?

Re: Open letter: Ban surveillance-based advertising

#124
post #89

I think there's a simpler way to achieve this. Force companies who leak personal data to pay reasonable damages to all the individuals involved, on the scale of 10-100 dollars, depending on how much personal info has been leaked. That would make businesses very quickly reassess how much data they need to keep, and how careful they need to be with it, without requiring any really radical legislation.

If my information gets leaked and my identity compromised, you think $10-100 is reasonable compensation? I like the idea but I don't think we can put any sort of numbers on damages like this before it happens.

We need a minimal sum to enable lawsuita.

Every time there is a leak, you have to prove you've suffered damages.

That's hard to prove: even if someone commited massive fraud with your identify, you dont know if the data came from this leak, or from 10 other leaks.

Setting a minimum would mean thay you can immediately fine conpanies for loosing millions of records in one lawsuit, instead of a million suits proving that each particular claimant was harmed

Re: Open letter: Ban surveillance-based advertising

#125

Do we have a good proposed legal definition of surveillance-based advertising?

I think this is quite tricky to pin down. For example, consider an e-commerce site like Amazon. They know your purchase history, reviews you've given or liked, and products you've viewed or put in your shopping cart but not purchased. Which information about your history would they be allowed to use to show you products you might be interested in buying?

They also have lots of information about users in aggregate ("people who bought this also bought x") which they got by collecting data about their users. Can they use this?

Re: Open letter: Ban surveillance-based advertising

#126

Do we have a good proposed legal definition of surveillance-based advertising?

If it collects any data at all, it's surveillance. Anything else is a loophole.

Let's say a streaming music service collects information on what you have listened to and how long. Is that surveillance? What if they use it to back a page where you can see what you've been listening to recently? If they start recommending new artists based on your listening history?

Re: Open letter: Ban surveillance-based advertising

#127

Earlier quoted context omitted.

Sell ads based on time periods. "Your ad displayed here for 1 week for this much $$$". Then the only thing that matters is the ROI and it doesn't matter how many bots have clicked on it.

This approach sounds much harder for an ad network to pull off and sounds like it would add a lot of risk and complication. For example, what if a web master decides they don't want to have ads on their site anymore. Whoever just paid for that space gets screwed.

> "This approach sounds much harder for an ad network to pull off and sounds like it would add a lot of risk and complication.

Harder to pull off than advertising at people who might actually want to see the ads? More risk and complication than the growing backlash against advertising in general entirely because of shady advertising practices? More risk and complication than having to keep track of various countries' and states' laws re; privacy?

> "For example, what if a web master decides they don't want to have ads on their site anymore. Whoever just paid for that space gets screwed."

Existing contract law already covers this in most places. If you paid for ads to be displayed for a certain time period and they are not, then there's been a contract violation.

Re: Open letter: Ban surveillance-based advertising

#128

Earlier quoted context omitted.

>No, you don't have to spy on users to do it. Assuming you are running an ad network you kind of have to in order to prevent ad fraud. Also by reducing that data you know about someone's interests is the knowledge that they have visited a site at least you will not be able to pick as good of an ad compared to if you had more data.

Sell ads based on time periods. "Your ad displayed here for 1 week for this much $$$". Then the only thing that matters is the ROI and it doesn't matter how many bots have clicked on it.

That's actually the way most advertising used to work before all this surveillance stuff started, and still the way it works with some (ethical) advertisers.

Re: Open letter: Ban surveillance-based advertising

#129
post #106
post #88

Earlier quoted context omitted.

That is nearly impossible to avoid. Go to your local store enough times and they might remember you, even when no data is retained at all.

do you mean the people at the store remember you? kinda different than collecting data and deploying it across the whole internet wouldn't you say?

The person running the store remembering you and treating you differently based on your history is within what they're covering here, yes. In the report that Vivaldi is recommending (https://www.forbrukerradet.no/wp-content/uploads/2021/06/202...) they consider both first-party and third-party tracking to be part of "surveillance-based advertising". For example, a site showing ads for users based on what topics they tend to view weighted by how much they interact with each one. There's nothing about having to "deploy it across the whole internet" before it counts; activity on a single site is still (described as) surveillance.

Re: Open letter: Ban surveillance-based advertising

#130
post #71

The problem is with the match of partial virtual profiles with individual-specific identities. That A uses a profile to visit www sites about code optimization, leisure mathematics, statistic software and StackOverflow, and commercial information about some IDE is shown, that may be welcome. That A uses another profile to visit www sites about baking cakes, nutriment science and ethnic restaurants, and information ab…

This makes me think.

What happens when partial profiles are matched to the wrong person? Like, it's very likely these systems are going to match different people in the same household/network because... how can they even separate different people with different interests and a single person using many profiles?

I suspect all our "valuable user data" is tainted by default and its monetary value is an illusion. We do know that the systems are overzealous, and the algorithms driving those systems are far from perfect (and in case of ML models, high chances of it being non-deterministic, to boot).

A friend recently got some of those ISP copyright strikes because the fiancee of his sister got relocated to his house for a few days and decided to leech from the network to download some AAA videogames. Of course the strikes were to my friend's name, because they have no way to know some stranger did it instead.

I can easily see my data profile saying I'm into horoscopes and that voodoo because my mother browses that stuff all day from the network assigned to my name. I'm sure there are attempts to defeat incognito/private tabs by bundling all "indecisive" data to the main profile in a given IP, so a large household can be a completely schizophrenic data profile with data mixed from a lot of users in that household. Imagine someone in your house has been using some extremist or taboo site. If that data is mixed up with yours, and a person with bad intent wants to take advantage of leaked data they obtained on you...they have a pretty strong weapon to assassinate your image. "You can't deny it, it's in the data. Your cousin did it? Oh what an ignoble attempt to save your butt, how lowly!". Since you have no way to plausibly deny it, it can be a strong blackmail weapon. Maybe stronger than medical data leaks in this weirdly political climate we got now.

Post reply on HN