Live data from Hacker News

Red flags in the Threads privacy policy

qz.com

111–120 of 263 posts

Re: Red flags in the Threads privacy policy

#111
post #103
post #60

Earlier quoted context omitted.

If anything, the GDPRs wording of "legitimate interest" makes it too weak, where corporations can justify every use of data that makes them money as legitimate until a court stops them, as happened to Facebook very recently over ad microtargeting.

I think GDPR is pretty clear there. That companies like Facebook push fancy theories of what is and isn't legitimate interest is not the fault of the law. People will always try to push the limits to see what they can get away with, esp. when there is money to be made. That doesn't mean it will fly - like Facebook has just discovered (and others before them). Law cannot enumerate every single possible existing and fu…

There are ways to make this problem less bad though. You have your permissive case and then write a number of examples into the law that show what you do not consider allowed and invite future courts to consider them. Pre-emptive case law (which is a lot cheaper than actual case law), if you will.

Re: Red flags in the Threads privacy policy

#112
post #51

Earlier quoted context omitted.

Can you say specifically what goes too far? I don't find it onerous or unreasonable at all, but my business model doesn't improve by violating it either.

How do you know you aren’t violating it? Even with the best of intentions, these laws can be labyrinthian and ambiguous, and therefore expensive to (try to) observe. And there is still always the risk that you are found guilty of something. For a small or medium business, you are likely to be far enough out of the radar to avoid issues. But as a large company you may easily end up in legal crosshairs, costing million…

These laws being byzantine is the result of almost two decades of legal battles. Meta and Google have batteries of competent lawyers and lobbyists, constantly testing for legal loopholes, interpretations and contesting complaints in European courts.

Privacy laws aren't new, they existed before the GDPR. But they were fractured and not up-to-par with the new digital reality of large scale collection of personal data. These laws are geared exactly against the very business model of Google and Meta: offer free services, be first to market and become a gatekeeper, collect user data as broadly as possible, sell business intelligence and marketing services to actual paying customers.

When Meta states that it can't release Threads due to "unknown legal liabilities" that's a round-about way of admitting that their business model doesn't entirely square with European laws, such as they are.

Finally, as far as size in terms of user base, revenue and expenses go, the likes of Meta, Google and Twitter are very much a league of their own. Given their business model and its profitability, it's inevitable that their goals and motives are at odds with the interests and legal rights of citizens.

Re: Red flags in the Threads privacy policy

#113

If your problem is with the ownership of Twitter, I don’t understand why you would run from the arms of one wannabe cage-fighter into another’s. If your problem is with ethics, FB isn’t a beacon of good behavior. If your problem is getting rate-limited or losing your blue checkmark, I guess go wild, but you probably already loved Twitter too much to leave.

So does Threads solve the problem of viewing things logged out?

FB always had this tendency of rate limiting (showing an annoying sign up modal and then eventually silently failing due to HTTP 429 ajax requests- seemingly IP rate limiting). It also seems to not allow viewing of otherwise public info based on user agent (mobile vs desktop)

Re: Red flags in the Threads privacy policy

#115

Earlier quoted context omitted.

How do you know you aren’t violating it? Even with the best of intentions, these laws can be labyrinthian and ambiguous, and therefore expensive to (try to) observe. And there is still always the risk that you are found guilty of something. For a small or medium business, you are likely to be far enough out of the radar to avoid issues. But as a large company you may easily end up in legal crosshairs, costing million…

People keep saying this and yet it’s never happened despite the GDPR being in place for 5 years now. As a tech manager for an EU company, I can honestly say that it isn’t that hard to be GDPR compliant. Even when I worked for a company that did need to collect customer information, we pretty well understood what we could and couldn’t do under GDPR. This whole “GDPR is dangerous” meme needs to die because businesses a…

> As a tech manager for an EU company, I can honestly say that it isn’t that hard to be GDPR compliant

It's pretty easy for a business to be GDPR compliant unless their business model or processes in some way involve collecting and processing or selling personal data of their users. Before GDPR a lot of businesses used this as a nice little second income stream, or just grew used to being able to freely analyze every aspect of their users private data that they could get a hold of. Suddenly they can't do this anymore, and what's actually difficult is not being compliant with GDPR, it's reconciling their business to a new way of working where they have to be considerate of their user's right to privacy.

For example, you have a deeply entrenched analytics system that you base a lot of your decisions on. Suddenly you have to basically gut it, or even throw it out entirely. No matter that's there's plenty of GDPR compliant systems to replace it, they don't feel as effective and it's easy to see why a business would make these changes begrudgingly and with a lot of complaining about how unfair it all is.

Re: Red flags in the Threads privacy policy

#116

Earlier quoted context omitted.

> Can you say specifically what goes too far? Twenty-eight independent data regulators on a complain-investigate model. I’ve seen folks bury early-stage competitors with regulatory inundation as an effective, if unethical, strategy. Zero chance Musk wouldn’t have armadas of randos complaining raining in on Threads.

For EU-based business: The DPA of your country is responsible for you. For non-EU-based business: Appoint a representative in the EU. The DPA of that representative's country is responsible for you. So where do the other 20+ DPAs come in? They might be responsible for your customers - in which case, they'll contact your DPA and sort it out among themselves. You still won't have to become an expert in the nuances of B…

> they'll contact your DPA and sort it out among themselves

No, they won’t. They’ll help you coördinate. You won’t have to become an expert in other bodies of law, but you will need to responsive to them, which is time consuming, distracting and—if you’re running a real business—expensive.

I’ve seen this deployed to remarkable efficacy, with asymmetry in defence:deployment cost in excess of 10:1.

Re: Red flags in the Threads privacy policy

#117

Earlier quoted context omitted.

Apple should really communicate more clearly what they mean in these privacy reports, because I don’t think it’s insane to interpret “The following data may be collected and linked to you: … Health & Fitness” in this way. An incorrect interpretation, sure, but not one you have to be dumb to make.

Until someone provides explanation for exactly what that does mean, how is anyone to know that it is an "incorrect" interpretation?

Here's exactly what it means: Someone at Facebook, when creating the listing for the Threads app on the appstore, told Apple that the app might possibly collect Health data (etc). These labels are entirely based on self reporting by the person doing the upload. That's it, that's the entirety of what these privacy label things mean: the company making the app has made these claims about what it collects.

In this case Facebook appear to have simply ticked every possible box for data collection regardless of whether the app actually does it or not. Note you can't just get health data on iOS without asking, so people would notice if they tried. My guess is that actually figuring out what they do/don't collect was too hard, so they just said yes to everything.

Re: Red flags in the Threads privacy policy

#118

Tbh if you are concerned about the privacy and ethics concerns here the biggest red flag is in the subtitle: Meta's Twitter rival launched in over 100 countries today—but not in the EU Anything more is simply detail - if a major launch of this sort of service omits the EU we immediately know exactly why.

why are you going so far though? it's right there: "Meta"

Ha, yeah I had that thought after I posted.

Re: Red flags in the Threads privacy policy

#119
post #49

Tbh if you are concerned about the privacy and ethics concerns here the biggest red flag is in the subtitle: Meta's Twitter rival launched in over 100 countries today—but not in the EU Anything more is simply detail - if a major launch of this sort of service omits the EU we immediately know exactly why.

Not sure I buy this. Some of the EU stuff is good, I think a lot of it goes to far and it's a terrible nightmare to navigate now, never mind in a decade when we're all using software that doesn't exist yet.

[deleted]

Re: Red flags in the Threads privacy policy

#120

Earlier quoted context omitted.

How do you know you aren’t violating it? Even with the best of intentions, these laws can be labyrinthian and ambiguous, and therefore expensive to (try to) observe. And there is still always the risk that you are found guilty of something. For a small or medium business, you are likely to be far enough out of the radar to avoid issues. But as a large company you may easily end up in legal crosshairs, costing million…

Don’t collect information and you know you’re not violating it. ¯\_(ツ)_/¯ Seriously though, GDPR compliance isn’t that hard. You just have to get out of the habit of collecting everything.

> Seriously though, GDPR compliance isn’t that hard

Unless compiling data on your users and selling it is your entire business plan.

One of the issue I see it that many companies have been lured into this impression that they need to track everything, in great detail, but it doesn't actually provide that much value. I blame the snake oil sales people in the advertising/remarketing/up-selling/cross-selling business.

Post reply on HN