Live data from Hacker News

CCPA Scam – Human subject research study conducted by Princeton University

blog.freeradical.zone

101–110 of 353 posts

Re: CCPA Scam – Human subject research study conducted by Princeton University

#101

I'm confused how this is human experimentation. Were they not merely collecting information on how a site handles these requests? Is it because they erroneously sent emails to sites that do not fall under the umbrella of the law they were examining? An email asking an organization for answers to questions is human experimentation? I must be missing something.

> An email asking an organization for answers to questions is human experimentation?

Organizations are made up of humans.

Human experimentation is very broadly defined, for IRB purposes. As I understand it, if you're going to be asking humans to interact with researchers, in any way, and gathering data based on those interactions, that's human subjects research, and requires reasonable scrutiny from the IRB.

Source: I have worked fairly extensively with my own university's IRB, as I put together and maintain the website that they use to handle submissions.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#103
Some jurisdictions consider IP addresses to be personal identifying information, and so if you run a web site that logs the IP addresses of visitors you should generally try to be aware of the privacy laws in any jurisdiction that might think its laws apply to you.

These fall into three groups.

First, there are those jurisdictions in which you and/or your site are actually located. You almost always have to care about the laws in these jurisdictions.

Second, there are jurisdictions where the people who visit your site live. For these there are two questions. #1 does the jurisdiction think their law applies to you? #2 Does your jurisdiction, or someone else that you have to obey, agree?

The answer to #1 often depend on what your relationship is with the visitor. If you are selling (or trying to sell) them something it is more likely that the jurisdiction will think their law applies. If your website is not in any way targeted to them or encouraging them it is more likely that the jurisdiction won't think its law applies. (But some, like the EU with GDPR, do think it applies if you are tracking the behavior of EU users regardless of whether or not you are selling anything or trying to get EU visitors).

#2 is murkier. Say I've got a site in X specifically selling to people in Y. Y brings a civil case against me in Y. I ignore it thinking they can't touch me here in X, and Y gets a monetary judgement against me. I may be in for a surprise, because X may consider my sales to people in Y as taking place in Y, and so agree that Y has jurisdiction. If Y then brings the judgement to an X court to enforce, there is a decent change the X courts will enforce it. Oops.

Another thing you need to consider when thinking about #2 is entities that both you and the jurisdiction deal with. If you use a service provider (credit card processor, cloud service, hosting provider, etc) that operates in that jurisdiction, you may face pressure via that provider to obey the jurisdiction's law.

Finally, there are jurisdictions that you are not in, you aren't selling to or doing anything to attract visitors from, you are sure your jurisdiction won't cooperate with them on enforcing their laws, you don't use any services that operate there, and you aren't even going to visit there so even if you thoroughly annoy them no big deal.

You can probably mostly ignore these jurisdictions as far as privacy laws go.

If you are in the US I'd say that this currently means that you should be aware of GDPR and CCPA, and have some idea of how you will response to requests under them. For a lot of sites (like the OP's) a short form letter explaining that you are not covered should be fine.

As more states in the US pass their own CCPA-like laws, or we get Federal action on privacy, I'd expect those will generate large threads here. Keep an eye out for them and update your form letters appropriately.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#104

Earlier quoted context omitted.

I see that you're being downvoted, but for what it's worth I agree with you. I read the message and if I received it I wouldn't have thought much of it. Honestly I would've just thought it was spam. It's a shame though if the OP did have mental duress as a result of it, though.

It's entirely possible that you and OP do not share the same 'what do I stand to lose' frame of reference.

[deleted]

Re: CCPA Scam – Human subject research study conducted by Princeton University

#105
post #99

Earlier quoted context omitted.

I love how they say they are "contacting websites" as if websites are sentient beings that can respond to questions, rather than operations run by human beings who will receive and respond to the communication.

Websites aren’t sentient beings, but they are more similar to commercial entities than people. Even if not intentional, websites gain traffic and can display ads. They have Google ranking. They have an audience and can get paid to share information with their audience. Would there be an issue if they sent out letters to businesses asking how they comply with a California regulation?

>Would there be an issue if they sent out letters to businesses asking how they comply with a California regulation?

I think this is where you may be overlooking the context.

People aren't mad they asked about compliance with a law, they are mad about the way it was asked: from fake personas implying legal threat, while cataloguing the replies for their study no one asked to be involved in.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#106
I run a SaaS product solo, and I receive these message and other similar ones (GDPR requests) every week. Most are generic like this one, but some are out right offensive name calling.

I have no problem following these laws and extended the data/privacy rights to everyone (not just CA or EU residents). I must say though, when people threaten me or resort to name calling I make the process deliberately difficult.

edit

I just scanned my email and I got the same email, with CCPA swapped out for GDPR via a "Tom Harris".

Re: CCPA Scam – Human subject research study conducted by Princeton University

#107
post #73

I'm the person who wrote that blog post. I got an email from a fake person in France who asked several questions about my small social media site's CCPA compliance, then ended the letter with: > I look forward to your reply without undue delay and at most within 45 days of this email, as required by Section 1798.130 of the California Civil Code. I thought I was about to be sued by someone who was the equivalent of a…

I've met Ross during my time at Princeton and he is a really genuine person, he is not trying to ruin anyone's life. This incident is the result of an uncharacteristic blind spot in empathy: a mistake. I also have experience with the Princeton IRB on similar topics. The reality is that Princeton's IRB, and IRBs in general, are not equipped to deal with this sort of online research. IRBs were created as a reaction to…

The fact that Ross didn't mean to do this is all the more reason why someone - maybe an IRB, maybe not (your argument makes sense) - should be assisting 20-something researchers with having a well-informed perspective.

In the absence of an organization that's good at this (which doesn't seem to exist and should), this probably should be the supervising professors.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#108

I received exactly the same email with a different sender ("Anna Roland", a resident of San Francisco, California) and was also left quite paranoid by it. The email had an combative tone and felt like a legal threat.

We received the same email as well, also from “Anna Roland.”

Re: CCPA Scam – Human subject research study conducted by Princeton University

#109
post #23

Earlier quoted context omitted.

Almost certainly. The law seems pretty clear that they'd have to completely delete all information about if you ask them to.

I guarantee you that they don't even know what all the information about you they have is and even if they wanted to they couldn't actually delete all of it because their systems have so many levels of redundancy to prevent data loss that even intentional deletion is impracticable, at least if you want it to be comprehensive.

Curious that they don’t know what data they have, no?

Collectors of data should know what they have and who they have shared it with. Think of holding data as risky, as if the data is toxic. Think of the monetary and reputational risk of a data breach.

Incidentally, the data collected must be done so for a specific business purpose. And can even be kept if there are other requirements such as AML or KYC.

Just slapping a zero over the data is not a viable solution.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#110
post #20

Serious question: why should academic institutions be held to a higher standard than commercial ones? Google and Facebook, to just name two, routinely perform human subject research without informed consent as a matter of course. That's what A/B testing is. Ethically speaking the fine print in the ToS obviously isn't actually informed consent, even if the law says it is. I don't see why being a for-profit company sho…

You're asking this backward: why should commercial institutions be held to a lower bar than academic ones. The response isn't to make it easier for universities to conduct research on you, but to make it harder for companies to.

I routinely launch canaries before deploying new code to production. Given there is no intent to deceive, mislead, or otherwise harm customers, and all internal testing has yielded a 'ship it' signal, is there any ethical need for users to opt-in to these A/B tests?

In my view, the alternative is to ship something we _don't_ have data on and hope for the best. And if we demand informed consent, I have to assume it goes into boilerplate agreements nobody reads at signup, which is a mockery of the term 'informed' IMO.

Post reply on HN