Live data from Hacker News

CCPA Scam – Human subject research study conducted by Princeton University

blog.freeradical.zone

331–340 of 353 posts

Re: CCPA Scam – Human subject research study conducted by Princeton University

#331
post #224

I've gotten 4 of these mails to 4 of my domains (including my personal domain used just for email, and a one-page documentation site for an open source library)... 2 about CCPA and 2 about GDPR. They also gave me a lot of anxiety for no reason. Looking at the responses on Twitter, a lot of websites spent real money consulting lawyers before responding to these mails due to the thinly veiled threat of legal repercussi…

Sounds like a good place for a class action! Those legal fees ought to come out of Princeton.

On what basis? Why can't we reasonably expect these sites to follow the laws? Just that they have in past survived being unethical and not following them does mean they have some sort of claim when they scramble to fix their failures.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#332

Earlier quoted context omitted.

You did not lawyer up, but some other recipient might have had. Is there a ground for a lawsuit here for... well.. fraud? After all, resources were spent; surely, there was some stress.. Yeah, I agree with you.

I'm not a lawyer, clearly, but I'd say so. Some people are replying to him on Twitter saying that they've spent money here and asking who to send the invoice to.

Not a lawyer, but I would say no. Being aware of your legal obligations is part of cost of doing business. Expecting company to follow law isn't anything special. Just because in past they have been unethical and not spend money to follow them doesn't mean when they hear about it and spend money the person they heard about it from has to pay. That would be insane. They have been bad people by not following the laws or being aware. Now they are aware of them. In no way is him responsible for these idiots legal cost. Specially when they should have already paid them before.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#333

Earlier quoted context omitted.

If I had to guess, the wording is in the study's FAQ is carefully chosen: "an application detailing our research methods" doesn't necessarily mean "an application with the verbatim text of the emails we planned to send, including our thinly veiled legal threat at the end." Not trying to turn this thread into a generic flameware against "academic" research methods, but this whole things seems oddly reminiscent of the…

> Not trying to turn this thread into a generic flameware against "academic" research methods, but this whole things seems oddly reminiscent of the "let's try to insert malicious code into Linux" fiasco [1]. I'm conceptually fine with generic passive tools like web crawlers to conduct research, but since when did the internet become a place where nonconsensual interactive research became fine? In a very real sense, e…

> In a very real sense, every landing page A/B test is nonconsensual interactive research.

I think the difference here is that the user requests a page with a web browser (which could be argued as giving consent to view the contents) while the person that received this email didn't request the experimental email (and therefore didn't consent to the experiment).

Re: CCPA Scam – Human subject research study conducted by Princeton University

#334
post #93

Earlier quoted context omitted.

Sure, of course not, but a near panic attack still seems a bit... out of proportion.

If you have run a business small enough that you don't have a lawyer on standby then you might understand a little better. I have, and received a real legal threat. A bit of panic as you contemplate the financial devastation & wreckage it might leave your life in... well, a little bit of panic is actually a pretty reasonable response there. If you've been in that situation and been totally calm about it then that's a…

These businesses should have been aware of this already. It is their own fault for not being aware of their status and preparing for it. In no way anyone but they are to blame in this case.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#335

Earlier quoted context omitted.

> Ethical questions arise when you ask people to take specific actions in order to measure their reactions "Answer my questions within 45 days or I will sue you." That seems to read like a demand for a specific action.

That's not what the message said. The message asked specific questions about data processing in regards to privacy regulations. Anyone could have sent this message. Hell, i have been on both ends of this message (with CNIL not CCPA) and as an honest person taking part in non-profits i can assure you there's nothing to feel threatened about. Maybe in your Silicon Valley culture where lawsuits are more easily triggered…

> That's not what the message said.

The message said:

> I look forward to your reply without undue delay and at most within 45 days of this email, as required by Section 1798.130 of the California Civil Code.

This is clearly a threat of legal action. Your experiences with CNIL might be misleading. There are few risks of getting bankrupt because of a frivolous lawsuit in Europe, but this is a very real risk in the US. Even if you are in the right and did nothing wrong.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#336
post #100

It is interesting in the study web page ( https://privacystudy.cs.princeton.edu/ ) that they consistently mention contacting "websites" instead of "people." As if a website is some autonomous thing that can communicate with a researcher. I wouldn't be sleeping well if I were involved in this study. There is no way an IRB could determine that this is not human subjects research if you're emailing people and asking the…

In my understanding (from a french cultural context), asking people questions as part of a field study is not human subjects research. Ethical questions arise when you ask people to take specific actions in order to measure their reactions, not when you're asking about the status quo.

Guidelines depend on jurisdiction. Research conducted in the United States may have different requirements than other jurisdictions.

The underlying ethos is that researchers should respect the people who are participating in their studies. People should know that you are conducting a study, the aims of the study, and choose whether or not they want to participate.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#337
post #334

Earlier quoted context omitted.

If you have run a business small enough that you don't have a lawyer on standby then you might understand a little better. I have, and received a real legal threat. A bit of panic as you contemplate the financial devastation & wreckage it might leave your life in... well, a little bit of panic is actually a pretty reasonable response there. If you've been in that situation and been totally calm about it then that's a…

These businesses should have been aware of this already. It is their own fault for not being aware of their status and preparing for it. In no way anyone but they are to blame in this case.

I think you didn’t read my original blog post that’s linked here. I’m not a business. They send the email to me regarding my personal, hobby, zero-revenue website. I have no legal obligations under the CCPA, but I didn’t know that until I spent a few stressed-out hours researching this. Even then I was worried about the idea of being sued over it anyway, and having to explain to a court why I believed I shouldn’t be liable for damages.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#338
post #277

Without getting into the question of whether this study involved human subject research, I find a lot of the anxiety and paranoia unwarranted. Companies to which these laws apply should already have a process in place to deal with subject access requests. Complying with relevant laws is just part of doing business. All the other site owners could have figured out with a bit of googling that the laws don't apply to th…

> I can only speak for the GDPR here, but had the requests been real and valid, the worst outcome would have been a regulator telling you to comply with it. Data protection authorities are more interested in helping companies get into compliance than punishing small businesses for minor infractions. If you look at past decisions, it usually takes serious and/or systematic violations to get fined.

The US legal system is quite different; litigants are responsible for their own legal fees[0] and frivolous lawsuits[1] are common.

[0] https://en.wikipedia.org/wiki/American_rule_(attorney's_fees)

[1] https://www.azag.gov/press-release/serial-litigant-permanent...

Re: CCPA Scam – Human subject research study conducted by Princeton University

#339
post #331
post #224

Earlier quoted context omitted.

Sounds like a good place for a class action! Those legal fees ought to come out of Princeton.

On what basis? Why can't we reasonably expect these sites to follow the laws? Just that they have in past survived being unethical and not following them does mean they have some sort of claim when they scramble to fix their failures.

The sites that are big corporates that abuse the shit out of this insufficient law will just consider it legitimate interest and they are vendors, not affiliates with the data being sold to.

A huge amount of the people that got this were ethical, individual, not corporate, not profit.

Post reply on HN