Live data from Hacker News

CCPA Scam – Human subject research study conducted by Princeton University

blog.freeradical.zone

211–220 of 353 posts

Re: CCPA Scam – Human subject research study conducted by Princeton University

#211
The study FAQ claims:

> What happens if a website ignores an email that is part of this study?

> We are not aware of any adverse consequences for a website declining to respond to an email that is part of this study.

But the email sent out states:

> I look forward to your reply without undue delay and at most within 45 days of this email, as required by Section 1798.130 of the California Civil Code.

So the email very clearly states that there is an adverse consequence for a failure to respond, namely a violation of the California Civil Code.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#213
post #88

From the study's FAQ[0]: > Did an Institutional Review Board consider this study? > We submitted an application detailing our research methods to the Princeton University Institutional Review Board, which determined that our study does not constitute human subjects research. From the social experiment[as reported by OP's link]: > I look forward to your reply without undue delay and at most within 45 days of this emai…

I don’t think it’s intended as a veiled threat of a lawsuit so much as a statement of the compliance requirements. Unfortunately it seems they misunderstood the scope which makes the it inaccurate. But if the statement was true and accurate I would just take it as a helpful reminder of the timeframe.

> But if the statement was true and accurate I would just take it as a helpful reminder of the timeframe.

No. Absolutely not. A helpful reminder of the timeframe would be "the deadline for our study is ..., please try to send your response by then if you wish to be included."

Quoting legal code is not at all a helpful reminder of a timeframe, but is a direct implication of legal ramifications for failure to comply.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#214

Let me help: We’re some students from Princeton trying to understand how businesses are responding to CCPA and GRPR requests. Could you help us with our study? How would you answer these questions? … The point is disclosure. It’s unethical to do otherwise, especially given that is about the use of data. I’d love for there to be more data published about the impacts of these policies, but please don’t use the tactics…

It is likely that quite a few people would lie if they knew they were going to be observed/studied or reported on. However, I'm sure they could've made the actual email less threatening and more friendly/ethical without revealing research intent. (or the intent to research this specfic aspect)

> It is likely that quite a few people would lie if they knew they were going to be observed/studied or reported on.

Even assuming your premise is true (it's not), you think the solution to not have people lie is....to lie to them?

Re: CCPA Scam – Human subject research study conducted by Princeton University

#215
> I had a minor panic attack, literally, upon receipt, as I thought I was about to be sued

Oh please! A tad bit dramatic, no? A single email from someone claiming to be in France is made out to be equivalent to an official letter from a US lawyer. They even said it was not a request for data so you can ignore it.

Was this a mistake? Yes.

Was it a big mistake? Hell no.

Let's not lose perspective and keep things real.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#216
post #153

Earlier quoted context omitted.

Who is the subject of the emails sent to personal domains?

Not sure I follow your question. An example of something that's not human subjects research would be emailing people who have websites and asking about their privacy policy. An example of something that is human subjects research would be emailing people who have websites and asking what inspired them to start a website. I realize that may seem like a subtle difference, but it's an important distinction from an IRB p…

Epistemologically, using a fake name and a threat of legal action to elicit a response from whoever's picking up the phone is no different from dressing up as a cop and harassing someone on the street. The question of whether the content of your accusation stems from their own or their employer's action is peanuts compared to the ethical boundary you crossed when you decided to impersonate authority to witness their reaction.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#217
They've been doing this since April 202 [1]. Early reports also found on reddit with people being concerned. We too received quite a few of these emails over the last few days from various fake idenities and wasted time responding to one of them before realising it was not legit!

I can't imagine how much time and potentially money was wasted on these mass emails.

[1] https://joewein.net/blog/2021/04/21/questions-about-gdpr-dat...

Re: CCPA Scam – Human subject research study conducted by Princeton University

#218
post #151

Earlier quoted context omitted.

I don’t think it’s intended as a veiled threat of a lawsuit so much as a statement of the compliance requirements. Unfortunately it seems they misunderstood the scope which makes the it inaccurate. But if the statement was true and accurate I would just take it as a helpful reminder of the timeframe.

That's a very generous assumption. Especially in the context of an email sent under false pretenses and a false name and an anonymous domain. It's either a veiled threat or a serious error. Either way, this study needed more oversight.

Calls for more oversight are calls for more bureaucratic procedures and this whole situation is already bureaucracy gone mad.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#219
As a counterpoint here I don't consider this study or the Linux kernel study human subject research unless we define human subject research so broadly that the definition essentially becomes meaningless.

As a side note I find the "outrage" about these small academic studies quite hipocritical. This is a community where a significant proportion of people work in related to ads/clicks who constantly experiment on human subjects (at least by the definition applied to the cases above). Let's not even talk about the research done by Facebook et al (where a significant proportion of developers here work as well), who literally looked at how changing the time line affects the mental health of users.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#220
I'm not sure what to think of this.

I remember at least one article for which the journalist sent fake job applications tomdigfeeent companies, using European and Arabic names for the same CV, to uncover bias in the application process.

Is this the same or different? It also wasted the time of the people reviewing the applications.

Is the implicit legal threat what makes the difference between ok and not ok?

Post reply on HN