Live data from Hacker News

CCPA Scam – Human subject research study conducted by Princeton University

blog.freeradical.zone

251–260 of 353 posts

Re: CCPA Scam – Human subject research study conducted by Princeton University

#251
post #145

Earlier quoted context omitted.

The false legal threat is particularly galling, but this absolutely should have gone through IRB even without it. Someone should have had to at least consider the impact on recipients of the messages before they were sent. IRB review is typically required even for just simple research surveys.

How is a reminder of the law a legal threat? More specifically when you feel like you're not impacted by this law, it's as far from a legal threat as could be.

Whether or not I feel I am impacted by a law has little to nothing to do with whether someone else will decide to sue or prosecute me based on it. Even if it's without merit, it's still an extreme hassle if that happens (and also very expensive).

Re: CCPA Scam – Human subject research study conducted by Princeton University

#252

As a counterpoint here I don't consider this study or the Linux kernel study human subject research unless we define human subject research so broadly that the definition essentially becomes meaningless. As a side note I find the "outrage" about these small academic studies quite hipocritical. This is a community where a significant proportion of people work in related to ads/clicks who constantly experiment on human…

Wait. Did you really mean to tag anyone simply _employed_ by Facebook as hypocritical? As if being employed by an entity immediately connotes acquiescence to whatever unethical or immoral behavior that entity engages in? Isn't that "guilt by association" taken a bit far? It's as if you were to call Google pro Sanders because a significant amount of money was donated to the Senator's campaign by non-executive Google employees (as if there were many other avenues to protest the status quo and still put food on the table). Full disclosure: not a big tech employee or a dev, just another over-the-hill greybeard sysadmin with absolutely no influence on corporate behavior.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#253

The study FAQ claims: > What happens if a website ignores an email that is part of this study? > We are not aware of any adverse consequences for a website declining to respond to an email that is part of this study. But the email sent out states: > I look forward to your reply without undue delay and at most within 45 days of this email, as required by Section 1798.130 of the California Civil Code. So the email very…

> I look forward to your reply without undue delay and at most within 45 days of this email, as required by Section 1798.130 of the California Civil Code.

>So the email very clearly states that there is an adverse consequence for a failure to respond, namely a violation of the California Civil Code.

I've read and re-read (and read many comments) but where is the adverse consequence stated?

Re: CCPA Scam – Human subject research study conducted by Princeton University

#254

Earlier quoted context omitted.

* When you do something to people to see how they act, it's a human experiment. The purpose of this study was officially "to understand how websites would respond to real users" * The participants / subjects of the study are people, not "websites" as the study claims. Websites don't read and respond to emails, people do. * The participants of this study were selected without their consent * The participants were not…

> When you do something to people to see how they act, it's a human experiment. All AB testing is a human experiment?

I'd be willing to argue that AB testing is human experimentation.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#255
post #55
post #20

Serious question: why should academic institutions be held to a higher standard than commercial ones? Google and Facebook, to just name two, routinely perform human subject research without informed consent as a matter of course. That's what A/B testing is. Ethically speaking the fine print in the ToS obviously isn't actually informed consent, even if the law says it is. I don't see why being a for-profit company sho…

I thought similar - it's such a routine and basic task to set up and run A/B testing to measure and optimize websites and apps for preferred conscious or subconscious response to visual stimuli. If this is a human subject research and human subject research without consent is a crime against humanity, most if not any proper web developer and the whole Web industry collectively are technically guilty of such a mouthfu…

[deleted]

Re: CCPA Scam – Human subject research study conducted by Princeton University

#256

Earlier quoted context omitted.

This is incorrect. It's only human subjects research if the researcher is obtaining data about a human. This is the "about whom" requirement. A classic example is calling a business and asking someone about the products and prices they offer. That's not human subjects research.

You realize that the internal regulation is wrong, right? Like the semantic distinction doesnt matter because nobody gives a fuck about Princeton’s organizational policy.

This is not Princeton's organizational policy or internal regulation, this is the regulatory definition of human subjects research as set by the government. Its semantic interpretation and the "about whom" requirement is exactly how you go about making a determination about whether your research is human subjects research.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#257
post #233
post #100

It is interesting in the study web page ( https://privacystudy.cs.princeton.edu/ ) that they consistently mention contacting "websites" instead of "people." As if a website is some autonomous thing that can communicate with a researcher. I wouldn't be sleeping well if I were involved in this study. There is no way an IRB could determine that this is not human subjects research if you're emailing people and asking the…

> I wouldn't be sleeping well if I were involved in this study. There is no way an IRB could determine that this is not human subjects research if you're emailing people and asking them anything. Do you have a citation for this? What I'm seeing from random Googling is that you have to be obtaining information about the person for it to count. If I were researching, say, price trends in some commodity and I called up…

Here are questions sent to individuals in the study: Would you process a CCPA data access request from me even though I am not a resident of California? Do you process CCPA data access requests via email, a website, or telephone? If via a website, what is the URL I should go to? What personal information do I have to submit for you to verify and process a CCPA data access request? What information do you provide in response to a CCPA data access request?

The word "you" appears in every question.

To quote my IRB training (citiprogram.org):

"Most research in the social and behavioral sciences involves gathering information about individuals. However, some research that involves interactions with people does not meet the regulatory definition of research with human subjects because the focus of the investigation is not the opinions, characteristics, or behavior of the individual. In other words, the information being elicited is not about the individual ("whom"), but rather is about "what." For example, if a researcher calls the director of a shelter for battered women and asks her for the average length of stay of the women who use the shelter, that inquiry would not meet the definition of research with human subjects because the information requested is not "about" the director. If the researcher interviewed the director about her training, experience, and how she defines the problem of battering, then the inquiry becomes about her - and therefore "about whom."

The current example is similar, in my opinion, to "how she defines the problem of battering" which the IRB training identifies as human subjects research. The people receiving the researchers' email in the current study are being ask to define the way they interpret and comply with a legal statute.

I can accept that some people don't see the information requested as being "about whom" and therefore is not human subjects research. But the fact that people who have received this email have panicked indicates that the recipients, at least, felt that the questions were more than merely recording impersonal data about their websites.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#258
post #233
post #100

It is interesting in the study web page ( https://privacystudy.cs.princeton.edu/ ) that they consistently mention contacting "websites" instead of "people." As if a website is some autonomous thing that can communicate with a researcher. I wouldn't be sleeping well if I were involved in this study. There is no way an IRB could determine that this is not human subjects research if you're emailing people and asking the…

> I wouldn't be sleeping well if I were involved in this study. There is no way an IRB could determine that this is not human subjects research if you're emailing people and asking them anything. Do you have a citation for this? What I'm seeing from random Googling is that you have to be obtaining information about the person for it to count. If I were researching, say, price trends in some commodity and I called up…

They're sending requests to websites to see how they behave, not to request information.

If you called up companies' sales lines to ask for prices, that's just gathering facts.

If you called up companies' sales lines to see what happens when you ask them for prices for things they don't sell, or to see if they're willing to accept a bribe, or to see if they respond with different prices when you lie to them about who you are, you're researching human behavior.

In this case, they are testing what procedures, if any, companies have in place for handling CCPA and GDPR law, by posing as nonexistent customers and making potentially bogus and misleading requests under the terms of those laws.

This is like performing research on retail refund practices by going into a bunch of shops and seeing how they handle being asked for a refund for an item you didn't buy from there in the first place.

There's a more ethical way to do that study, though, which is to actually buy something from the store first, then go back and try to refund it.

Similarly, there's a more ethical way to discover how websites handle CCPA/GDPR requests, which is to use the website first, and determine in the course of that what possible information about you the website should have; then, within the terms of your rights under CCPA/GDPR, to contact them and make reasonable and legitimate requests to see if/how they are able to handle them.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#259
post #203

I am surprised by the reactions here. I did not receive that e-mail but I receive all sort of weird inquiries for my websites, (at least 2 or 3 per day). I don't understand why people are so mad about it or even panicking.

While I personally believe the questions stated were perfectly reasonable (and could have been genuine questions from someone), I can understand that people feel (legally) pressured to provide answers to the questions. Which puts this study in a grey area.

With regard to GDPR, the "respond within x" is simply not applicable. The one month period is strictly for any requests concerning Article 15 through 22 and none of the questions are talking about any of that.

Now, if one of the questions was something along the lines of "do you process any information related to me?" then it would potentially fall under Article 15.1 and would require a timely response. IANAL, however, I think in such cases you could simply point to a privacy policy, which you are already required to have.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#260
post #244

So it'd be perfectly reasonable to conduct an experiment to see how certain Princeton researches react to emails telling them bad things are going to happen to them and their families and pets, right? "If thrown from a tall building how high do you think you'd bounce?"

No, it wouldn't. One is a polite but firm email reminding a website administrator of their obligations under the law, and the other is a thinly-veiled threat of bodily harm.

> One is a polite but firm email reminding a website administrator of their obligations under the law

It is not, because OP does not have the obligations that the email claimed they have.

Post reply on HN