Live data from Hacker News

CCPA Scam – Human subject research study conducted by Princeton University

blog.freeradical.zone

311–320 of 353 posts

Re: CCPA Scam – Human subject research study conducted by Princeton University

#311
post #305

Earlier quoted context omitted.

Mentioning a specific section of a law is threatening to hold them to the letter of that law. What happens if they don't follow the letter of that law? The insinuation is legal action will follow.

They did not threat anything, they were just asking information regarding their personal data. And therefor they were in their right.

You don't have to actually directly say the threat for the threat to be known. For example, if you're hitting me up for protection money, and you said "it would be a shame if something were to happen to x", that would reasonably be understood as a threat. Notice how you don't have to directly say that you will be the reason something happens to x.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#312
post #145

Earlier quoted context omitted.

The false legal threat is particularly galling, but this absolutely should have gone through IRB even without it. Someone should have had to at least consider the impact on recipients of the messages before they were sent. IRB review is typically required even for just simple research surveys.

How is a reminder of the law a legal threat? More specifically when you feel like you're not impacted by this law, it's as far from a legal threat as could be.

It's obviously implying a threat if you're at all familiar with the legal sphere.

Passive-aggressive language, sure, but still not exactly inviting the recipient to a picnic, and passive-aggressive language doesn't get you off the hook.

Related, doesn't matter if it is completely without merit and could never succeed.

This entire story and thread is just something else. Talk about failing to meet even baseline ethical standards.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#313

Earlier quoted context omitted.

If I had to guess, the wording is in the study's FAQ is carefully chosen: "an application detailing our research methods" doesn't necessarily mean "an application with the verbatim text of the emails we planned to send, including our thinly veiled legal threat at the end." Not trying to turn this thread into a generic flameware against "academic" research methods, but this whole things seems oddly reminiscent of the…

> Not trying to turn this thread into a generic flameware against "academic" research methods, but this whole things seems oddly reminiscent of the "let's try to insert malicious code into Linux" fiasco [1]. I'm conceptually fine with generic passive tools like web crawlers to conduct research, but since when did the internet become a place where nonconsensual interactive research became fine? In a very real sense, e…

> In a very real sense, every landing page A/B test is nonconsensual interactive research.

I think that lots of benign testing is only this a bit pedantically, at least for the general "two variants of a page" type of thing, context matters of course.

"I want to use this service" -> "OK, here is the page for that service" is a certain interaction where, granted, you might be presented with a different kind of look, but... well, you are getting what you asked for I suppose. Though you could get into the ethics of price differentiation by geo-data, and other general things that lead you to feeling ripped off.

OK, maybe lots of "growth-hacking" A/B test stuff does fall into this category...

I think the primary component of both this CCPA thing and the Linux kernel is, esentially, dishonesty. Researchers are doing things to outright lie to others. Here they are using fake identities! And it probably fails the general smell test of "if the counterparty was informed of the details, would they feel bad about the whole interaction". I said it elsewhere, I don't know if it's really fraud legally but it sure feels like it.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#314
post #305

Earlier quoted context omitted.

Mentioning a specific section of a law is threatening to hold them to the letter of that law. What happens if they don't follow the letter of that law? The insinuation is legal action will follow.

They did not threat anything, they were just asking information regarding their personal data. And therefor they were in their right.

There is no real person behind the inquiry. This is what made it deceitful and unethical.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#315

Earlier quoted context omitted.

I don’t think it’s intended as a veiled threat of a lawsuit so much as a statement of the compliance requirements. Unfortunately it seems they misunderstood the scope which makes the it inaccurate. But if the statement was true and accurate I would just take it as a helpful reminder of the timeframe.

> if the statement was true and accurate I would just take it as a helpful reminder of the timeframe. People don't go through the trouble of digging up the particular section number of the specific statute of the specific jurisdiction in question for the mere sake of a generic "helpful reminder of the timeframe" required by law. And similarly for the "without undue delay" part.

I do. Every day. I provide the citation so you can read the law and if you disagree with my interpretation you can respond saying as much. This is internet outrage mob justice. I understand why people are mad but it’s far more to do with ignorance on the part of the researchers than malice.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#316
post #145

Earlier quoted context omitted.

The false legal threat is particularly galling, but this absolutely should have gone through IRB even without it. Someone should have had to at least consider the impact on recipients of the messages before they were sent. IRB review is typically required even for just simple research surveys.

How is a reminder of the law a legal threat? More specifically when you feel like you're not impacted by this law, it's as far from a legal threat as could be.

> How is a reminder of the law a legal threat?

In the same way that "This is a nice place you've got here, it'd be a real shame if something were to happen to it", when spoken by a Mafia enforcer is most definitely a threat.

It's not, outright, threatening to bring a lawsuit, however the language of that last paragraph is definitely something which you'd expect to see from a lawyer in preparation for such legal action.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#317

Earlier quoted context omitted.

In my understanding (from a french cultural context), asking people questions as part of a field study is not human subjects research. Ethical questions arise when you ask people to take specific actions in order to measure their reactions, not when you're asking about the status quo.

> Ethical questions arise when you ask people to take specific actions in order to measure their reactions "Answer my questions within 45 days or I will sue you." That seems to read like a demand for a specific action.

That's not what the message said. The message asked specific questions about data processing in regards to privacy regulations. Anyone could have sent this message. Hell, i have been on both ends of this message (with CNIL not CCPA) and as an honest person taking part in non-profits i can assure you there's nothing to feel threatened about.

Maybe in your Silicon Valley culture where lawsuits are more easily triggered than private data requests things are different, though. The point is, if the author acknowledged they're running a study in the original email (not the follow-up) they would have skewed their data because corporate assholes don't treat college researchers and common people the same.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#318
post #247

Earlier quoted context omitted.

In my understanding (from a french cultural context), asking people questions as part of a field study is not human subjects research. Ethical questions arise when you ask people to take specific actions in order to measure their reactions, not when you're asking about the status quo.

Lying about who you are and pretending that you are allowed a certain thing… I mean legally it’s not fraud but it sure feels like it! Imagine someone showing up to your office building pretending to have an interview , walking into the office waiting room, then walking out saying “oh, just an experiment!” “It’s just an email” the ease of the mode of communication here is not super relevant to the action, right?

> Lying about who you are and pretending that you are allowed a certain thing… I mean legally it’s not fraud but it sure feels like it!

I'm not aware of the details, but maybe there's an actual Victor Coutant from Nice on the research team. If not, what does it change? The point is precisely to study how a random person trying to defend their rights to privacy will be received/treated by hosts. You can't study that if you sign your emails with "Princeton privacy researcher".

> the mode of communication here is not super relevant to the action, right?

Exactly. Researchers will declare themselves as such before conducting interviews, but they'll rarely hesitate to take notes or ask a simple question as part of a field study.

I mean if you're not happy this researcher is doing their job to investigate how corporate America mistreats people's data privacy rights, i'd be happy to be the person sending tons of pseudonymous automated emails and handing them over to a researcher. Would that change something for you?!

Re: CCPA Scam – Human subject research study conducted by Princeton University

#319

Earlier quoted context omitted.

How is a reminder of the law a legal threat? More specifically when you feel like you're not impacted by this law, it's as far from a legal threat as could be.

It's obviously implying a threat if you're at all familiar with the legal sphere. Passive-aggressive language, sure, but still not exactly inviting the recipient to a picnic, and passive-aggressive language doesn't get you off the hook. Related, doesn't matter if it is completely without merit and could never succeed. This entire story and thread is just something else. Talk about failing to meet even baseline ethica…

> It's obviously implying a threat if you're at all familiar with the legal sphere.

And if you're not a lawyer it's just a very normal message of someone trying to get answers and have their privacy rights respected. I've both sent and received many messages like this one over the years (CNIL requests) and there's nothing frightening about it.

> Talk about failing to meet even baseline ethical standards.

This study certainly meets my ethical standard of trying to hold corporations accountable to what they do with out data. I really don't see what the fuss is about: if freeradical.zone admin had received this email from anyone else (as could well be the case) would we even talk about it?

Re: CCPA Scam – Human subject research study conducted by Princeton University

#320
post #224

Earlier quoted context omitted.

Sounds like a good place for a class action! Those legal fees ought to come out of Princeton.

Why? If that's indeed the law, then it's up to the website owner to comply. Whether it's Princeton or a private individual writing the email doesn't matter.

There's a big difference between:

* one honest email

* thousands or millions, sent under false pretenses

There are two differences:

1) I'm allowed to cold call you. I'm not allowed to set up a robot to place millions of automated phone calls.

2) If I lie, I may have a problem. Someone runs up to your home and yells that your house is on fire, and you believe them. You jump out of a second-story window, breaking your windows and your legs. They do it in a stunt for TikTok. Who do you think is liable?

A third difference is IRBs. The right place to handle this are complaints to OMB; Princeton should lose federal funding here.

Post reply on HN