Live data from Hacker News

CCPA Scam – Human subject research study conducted by Princeton University

blog.freeradical.zone

231–240 of 353 posts

Re: CCPA Scam – Human subject research study conducted by Princeton University

#231
post #151

Earlier quoted context omitted.

That's a very generous assumption. Especially in the context of an email sent under false pretenses and a false name and an anonymous domain. It's either a veiled threat or a serious error. Either way, this study needed more oversight.

Calls for more oversight are calls for more bureaucratic procedures and this whole situation is already bureaucracy gone mad.

In this specific situation it doesn’t seem like there was any bureaucracy at all

Re: CCPA Scam – Human subject research study conducted by Princeton University

#232
post #224

Earlier quoted context omitted.

Sounds like a good place for a class action! Those legal fees ought to come out of Princeton.

Why? If that's indeed the law, then it's up to the website owner to comply. Whether it's Princeton or a private individual writing the email doesn't matter.

The websites have to comply with the law, but a university should not be sending them emails lying about their obligations under any law.

The emails were from fake people. So any work preparing any response regarding those fake peoples personal data is obviously not required by law. They don't exist.

And, as pointed out elsewhere in the thread, the researchers are probably not protected by either of CCPA or GDPR.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#233
post #100

It is interesting in the study web page ( https://privacystudy.cs.princeton.edu/ ) that they consistently mention contacting "websites" instead of "people." As if a website is some autonomous thing that can communicate with a researcher. I wouldn't be sleeping well if I were involved in this study. There is no way an IRB could determine that this is not human subjects research if you're emailing people and asking the…

> I wouldn't be sleeping well if I were involved in this study. There is no way an IRB could determine that this is not human subjects research if you're emailing people and asking them anything.

Do you have a citation for this? What I'm seeing from random Googling is that you have to be obtaining information about the person for it to count.

If I were researching, say, price trends in some commodity and I called up several companies' sales lines and asked for their current price that looks like it would not be human subject research despite the fact that I'm talking to a human to get each company's price.

If I were researching pay trends at those companies and called up their sales lines and asked the people who answered how much they were paid it would be human subject research.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#234
Me, 5 days ago:

https://news.ycombinator.com/item?id=29539266

I was concerned enough about this that I updated our project privacy policy with pre-emptive wording about CCPA (now reverted):

https://web.archive.org/web/20211218125309/https://textpatte...

I'm mildly annoyed about the time I wasted on this, but I guess that in itself is anecdata for this study.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#235
The problem here seems to be that governments created laws that allow everyone to scare the shit out of people who dare to build something and put it into the public - without having to leave the comfort of their chair (pun intended). Data privacy is important. Not feeling the urge to hire a lawyer just to publish a small blog is even more important.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#237
So it'd be perfectly reasonable to conduct an experiment to see how certain Princeton researches react to emails telling them bad things are going to happen to them and their families and pets, right? "If thrown from a tall building how high do you think you'd bounce?"

Re: CCPA Scam – Human subject research study conducted by Princeton University

#238

Earlier quoted context omitted.

If I had to guess, the wording is in the study's FAQ is carefully chosen: "an application detailing our research methods" doesn't necessarily mean "an application with the verbatim text of the emails we planned to send, including our thinly veiled legal threat at the end." Not trying to turn this thread into a generic flameware against "academic" research methods, but this whole things seems oddly reminiscent of the…

The wording of the message is one hell of a detail to leave out when detailing your research methods.

It’s seems like it but it’s not.

The IRB review determination is going to be based on the typology of what you are doing not the internal contents for the most part. Once they decide the level of appropriate review then they will typically look at the ‘details’.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#239
post #103

Some jurisdictions consider IP addresses to be personal identifying information, and so if you run a web site that logs the IP addresses of visitors you should generally try to be aware of the privacy laws in any jurisdiction that might think its laws apply to you. These fall into three groups. First, there are those jurisdictions in which you and/or your site are actually located. You almost always have to care abou…

I wholly support the CCPA and GDPR. They have their issues, but they’re big steps in the right direction. In the case of the CCPA, nothing I do is subject to it as it applies only to business, and only to those 1) making at least $25M in revenue, 2) handling the information of at least 50,000 Californians, or 3) making at least half their annual revenue from selling Californian’s personal information. I’m running a f…

Right. My point is that due to the way some of these laws are written even a small hobby website might do things that the law regulates. It would not at all be hard for a small hobby website with low traffic to entirely innocently run afoul of GDPR while collecting data to try to understand how to make the site more useful to their visitors.

Thus to avoid unpleasant surprised like the one you had, people with websites should add "check to see if my site has any obligations under privacy laws" to the list of routine things they do to maintain the site, and then plan accordingly.

If that check reveals that they aren't doing anything that places any obligation upon them, they can write a canned response to send back to anyone who asks.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#240

Earlier quoted context omitted.

Not sure I follow your question. An example of something that's not human subjects research would be emailing people who have websites and asking about their privacy policy. An example of something that is human subjects research would be emailing people who have websites and asking what inspired them to start a website. I realize that may seem like a subtle difference, but it's an important distinction from an IRB p…

I think one problem is that with small websites run by a single person or small group, a person can feel the website is an extension of herself. So a question about the website in some way becomes a question about the person.

More critically, it may actually be an extension of themselves in terms of legal liability.
Post reply on HN