Live data from Hacker News

CCPA Scam – Human subject research study conducted by Princeton University

blog.freeradical.zone

301–310 of 353 posts

Re: CCPA Scam – Human subject research study conducted by Princeton University

#301

Earlier quoted context omitted.

There are three things that you can demand of a company (that meets certain revenue thresholds) if you’re a California resident: - that they delete information about you that they have (with potential exceptions) - that they provide you with what information they have about you, and for what purposes they have that information (with exceptions) - that they opt you out of sharing data with other entities (with excepti…

> You cannot, as implied by the email, demand a response to an arbitrary query. I wouldn't say that the questions were arbitrary; they were exactly the things you would need to know in order to submit a request for information, but without the actual request. The only alternative that I can think of to get the same information is to register at all of these websites, use them for five minutes, then make an actual leg…

"They could also have made better guesses about whether the sites they were emailing would be bound by the law, and targeted the emails better."

They made no guesses - they randomly selected sites from rankings of top websites (specifically, from an common academic time-smoothed aggregation of Alexa and some of its competitors).

From the study website (https://privacystudy.cs.princeton.edu/): "The set of websites for this study is sampled from the Tranco list of popular websites and publicly available datasets of third-party tracking websites."

Re: CCPA Scam – Human subject research study conducted by Princeton University

#302
post #239

Earlier quoted context omitted.

I wholly support the CCPA and GDPR. They have their issues, but they’re big steps in the right direction. In the case of the CCPA, nothing I do is subject to it as it applies only to business, and only to those 1) making at least $25M in revenue, 2) handling the information of at least 50,000 Californians, or 3) making at least half their annual revenue from selling Californian’s personal information. I’m running a f…

Right. My point is that due to the way some of these laws are written even a small hobby website might do things that the law regulates. It would not at all be hard for a small hobby website with low traffic to entirely innocently run afoul of GDPR while collecting data to try to understand how to make the site more useful to their visitors. Thus to avoid unpleasant surprised like the one you had, people with website…

"My point is that due to the way some of these laws are written even a small hobby website might do things that the law regulates."

And kstrauser's point is that, due to the way this law is written, by definition nothing their small, non-profit site does can ever be regulated by this law.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#303

Hm, they use https://tranco-list.eu/ for top website list and not alexa. Whatever happened to Alexa ratings?

From Tranco's "Methodology" page:

"We designed the standard configuration of the Tranco list to improve agreement on the popularity of domains and stability over time, using the rankings from the four studied providers as our source data."

(Alexa is one of their data sources.)

Re: CCPA Scam – Human subject research study conducted by Princeton University

#304

Earlier quoted context omitted.

Mayer has a JD and is licensed in CA (I don't know about NJ), has worked for at least one US Senate office, and has been so involved in actual practical privacy work that ad companies pressured the president of Stanford to expel him for his legitimate work on DNT.

The person who designed and ran this study is not Mayer. Mayer runs the lab, but this is a subordinate's baby. From the study's website: "Please contact the lead researcher for this study, Ross Teixeira (rapt@princeton.edu), if you have any questions, believe you received an email in error, or would like to opt out of any future communication related to the study. The additional members of the study team are Professo…

Sounds like we should all e-mail him to opt out of his future studies. Maybe he’ll get why a massive e-mail campaign is a bad way to do this “study”.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#305
post #203

I am surprised by the reactions here. I did not receive that e-mail but I receive all sort of weird inquiries for my websites, (at least 2 or 3 per day). I don't understand why people are so mad about it or even panicking.

Mentioning a specific section of a law is threatening to hold them to the letter of that law. What happens if they don't follow the letter of that law? The insinuation is legal action will follow.

They did not threat anything, they were just asking information regarding their personal data. And therefor they were in their right.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#306

Earlier quoted context omitted.

In my understanding (from a french cultural context), asking people questions as part of a field study is not human subjects research. Ethical questions arise when you ask people to take specific actions in order to measure their reactions, not when you're asking about the status quo.

> Ethical questions arise when you ask people to take specific actions in order to measure their reactions "Answer my questions within 45 days or I will sue you." That seems to read like a demand for a specific action.

Nonono you don't understand, it was actually "Answer my questions per my extremely benign request including the exact statute requiring your response".

Totally different. Obviously. /s

Re: CCPA Scam – Human subject research study conducted by Princeton University

#307
post #239

Earlier quoted context omitted.

Right. My point is that due to the way some of these laws are written even a small hobby website might do things that the law regulates. It would not at all be hard for a small hobby website with low traffic to entirely innocently run afoul of GDPR while collecting data to try to understand how to make the site more useful to their visitors. Thus to avoid unpleasant surprised like the one you had, people with website…

"My point is that due to the way some of these laws are written even a small hobby website might do things that the law regulates." And kstrauser's point is that, due to the way this law is written, by definition nothing their small, non-profit site does can ever be regulated by this law.

My point is that because some privacy laws are written so that they affect such sites (GDPR for example), it is a good idea for sites to try to be aware of new privacy laws so they can check if those laws are that kind of law.

If they are not, then when someone makes a request under that new law it is just a matter then of responding with a pre-canned response explaining that the law does not apply instead of being a panic and/or stress inducing incident.

And someone will eventually make such a request. Users don't check details. They just know that their jurisdiction has a privacy law and under it they can request things. They don't check to first to verify the site meets the law's thresholds for applicability or is under the law's jurisdiction.

If the new law does apply to your site, same idea. You want to find that out and figure out how to deal with it before you get a request instead of your first request being a scramble to comply.

Note that I'm not saying that kstrauser mishandled anything. I think that most of us overlooked that small non-profit hobbyist sites needed to keep an eye on the privacy law landscape. Kstrauser happened to be the unlucky person who fate chose to use as an example of how annoying it can be too have to figure out on short notice where your site stands as far as a given law goes, even if the answer turns out to be "that law doesn't apply to my site".

Re: CCPA Scam – Human subject research study conducted by Princeton University

#308
post #257

Earlier quoted context omitted.

Here are questions sent to individuals in the study: Would you process a CCPA data access request from me even though I am not a resident of California? Do you process CCPA data access requests via email, a website, or telephone? If via a website, what is the URL I should go to? What personal information do I have to submit for you to verify and process a CCPA data access request? What information do you provide in r…

> I can accept that some people don't see the information requested as being "about whom" and therefore is not human subjects research. But the fact that people who have received this email have panicked indicates that the recipients, at least, felt that the questions were more than merely recording impersonal data about their websites. I guess the distinction is whether you see a website as an organization, even whe…

But at the end of the day a "website" -- whether it's a large organization, a small business or a sole proprietor-- is still maintained by people. There might be a process in place if it's a large enough company, it might even get directly sent to the lawyers to deal with.

But at the end of the day someone has to look at the email and respond, and in many cases that can cost money.

To wave off the whole thing as "we're contacting a website not a person" just shirks all the responsibility of ethically experimenting on people, which is what the study actually does.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#309
post #187

Earlier quoted context omitted.

You misunderstand the research in question. To quote from the researchers website > When the system has even higher confidence, it sends up to several emails that simulate real user inquiries about GDPR or CCPA processes. This research method is analogous to the audit and “secret shopper” methods that are common in academic research, enabling realistic evaluation of business practices. Simulating user inquiries also…

He understands perfectly well. What's relevant is whether the response is a property of the individual or the organization, and it's arguable, and controversial, but you'll find a lot of studies performed using this technique that were not considered human subjects research. As to whether it's deceptive and threatening (the latter of which I find pretty hyperbolic, this is a pretty boilerplate request), that has no r…

Someone looking up the exact statute and quoting it, while not a direct legal threat, certainly carries a lot of implied threats. People don't just look up legal statutes for shits and giggles.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#310

Earlier quoted context omitted.

Mayer has a JD and is licensed in CA (I don't know about NJ), has worked for at least one US Senate office, and has been so involved in actual practical privacy work that ad companies pressured the president of Stanford to expel him for his legitimate work on DNT.

The person who designed and ran this study is not Mayer. Mayer runs the lab, but this is a subordinate's baby. From the study's website: "Please contact the lead researcher for this study, Ross Teixeira (rapt@princeton.edu), if you have any questions, believe you received an email in error, or would like to opt out of any future communication related to the study. The additional members of the study team are Professo…

Ross appears to be a PhD student. Hardly a "career academic."

The point is that the "these are all ivory tower idiots who don't know how real people work" is a silly argument to make given their backgrounds.

Post reply on HN