Live data from Hacker News

Red flags in the Threads privacy policy

qz.com

171–180 of 263 posts

Re: Red flags in the Threads privacy policy

#171
post #142

Earlier quoted context omitted.

This is correct. So many websites don’t actually need to collect any user data. It’s just a distraction, slows down and bloats their site and worsens UX. I recommend to simply get rid of any tracking. If you want user feedback, ask them or do tests. It’s cheaper and more effective.

So many websites don’t actually need to collect any user data. Any commercial organisation is going to have customers and therefore customer details and payments data. Any commercial site needs to record enough logs to investigate events like outages or security threats. Any site that isn't purely informational and read-only probably works with user-provided data in some way. People keep writing about GDPR and simila…

> Any commercial organisation is going to have customers and therefore customer details and payments data.

Necessary for the performance of a contract or to comply with legal obligations.

> Any commercial site needs to record enough logs to investigate events like outages or security threats.

Legitimate interest, and possibly legal compliance if the nature of your site means you have a legal duty to collect those logs or that they could help in the course of an investigation.

> Any site that isn't purely informational and read-only probably works with user-provided data in some way.

If it's a UGC-based website, then collecting some data is necessary as part of the provision of a service or legitimate interest for fraud/spam prevention.

Every single point you mentioned would explicitly be allowed under the GDPR with either compliance with legal obligations, necessity for the performance of a contract or legitimate interest, no consent required even.

Re: Red flags in the Threads privacy policy

#172
This level of scrutiny is really excellent. Now we need to apply it to other companies working in the same space.

There is a serious lesson for startups though, if you actively start collecting data, you will, if you survive long enough, begin to have to declare what data you have when you "grow up". For example, if you do anything with photos, you will have to ask for permissions to process location data. even if you throw it away, it still counts as processing. Taken in the wrong light, or explained badly, this will tarnish your brand.

Rant time

Twitter can infer (if they hadn't have sacked all their data scientist people) your sexual preferences, location, and employer.

Google already knows your employer, especially if your work uses any google service. they also know everything you look at, type and interact with on the web. If you have an android phone, then your every move is logged, not only that but shared with your phone manufacturer as well.

Apple hoovers everything you do. I know they say its all for a "magical" experience. But they will and do monetise it. Anyone who says differently is in denial.

let us not talk to deeply about tiktok.

Is threads actually setting out to hoover that data? I doubt it. Have some people filled in their facebook profile with gender, preference, employer, house location and significant spouse(s)? you betcha.

Re: Red flags in the Threads privacy policy

#173

Earlier quoted context omitted.

For me the biggest red flag is that they have apps in the EU but what they're doing with this one is so dodgy that they're not even risking entering the EU. Also, interesting to see a big international company actually back up their "we just won't do europe then"

> interesting to see a big international company actually back up their "we just won't do europe then" that's the most interesting things to me. Whether: 1- Threads is dead in the water 2- They figure it out and makes the EU happy 3- EU is irrelevant enough to be ignored 2- still looks like the most likely 1- would be very embarrassing and 3- would be, indeed, an "interesting" development.

Let me give my 2 cents as an EU citizen.

The way I see it is a mix of all of that, but number 3 is the biggest.

Twitter is not big here. There’s people who use it, sure, but there’s a reason you don’t see that many EU issue trending on Twitter. Here’s an example out of the top of my head: France is rioting and it barely registered on Twitter.

The biggest European market for Twitter is the UK and it has 19M users, the second biggest is France with 9.5M [1]

The only time I see EU events surging on Twitter is during continental sporting events like Champions League, or Eurovision.

Twitter is just that that big around here.

Instagram on the other hand, I don’t know anyone without an IG account - so that might muddy the waters on this dynamic.

This however is just my personal experience.

[1] https://www.oberlo.com/statistics/number-of-twitter-users-by...

Re: Red flags in the Threads privacy policy

#174

Tbh if you are concerned about the privacy and ethics concerns here the biggest red flag is in the subtitle: Meta's Twitter rival launched in over 100 countries today—but not in the EU Anything more is simply detail - if a major launch of this sort of service omits the EU we immediately know exactly why.

I would bet over 95% of companies don't comply with GDPR. I know some startups don't serve EU because of this. Facebook is under the microscope of the EU, they probably aren't risking getting fined until they can scale the product and implement the thing they need to lower the fine they would get and make being fined worth it. They are going to get fined most likely, but again 95% of the companies in the world could…

I would say that no company or person is immune to arbitrary legal attacks. Complaining 100% with law is difficult if not impossible for companies or people with few resources. Laws could ge contradictory and/or inconsistent if you dig deeper.

That is why it is important to have sandboxes and/or laws that are based on size, number of consumers, etc. one thing is to ask for a full GDPR compliance to a bank and much different is for small companies.

Re: Red flags in the Threads privacy policy

#175

I'm wondering something here, and I humbly ask for feedback: to anyone hyped about Threads, why? Has Meta ever displayed any particular quality regarding content moderation, freedom of speech, privacy, information control, transparency, or mental health? Not implying Twitter is any better, Musk Tweeted, "It is infinitely preferable to be attacked by strangers on Twitter, than to indulge in the false happiness of hide…

Im someone who doesn’t have a Facebook account for years, and because I still have the same phone number I had back when I deleted my account I can’t even create a new one. But I still want to check it out when it comes out in the EU.

Just to see what it is like. I will probably not use it, because the lack of proper chronological feed irks me, but as an iOS developer I want to check out new apps all the time to see if they do anything different.

Re: Red flags in the Threads privacy policy

#176

This level of scrutiny is really excellent. Now we need to apply it to other companies working in the same space. There is a serious lesson for startups though, if you actively start collecting data, you will, if you survive long enough, begin to have to declare what data you have when you "grow up". For example, if you do anything with photos, you will have to ask for permissions to process location data. even if yo…

[deleted]

Re: Red flags in the Threads privacy policy

#178

Earlier quoted context omitted.

Don't jump to conclusions. They're likely not launching in EU because EU requires user data be stored in EU, and their current launch stack is hosted elsewhere, look at this datacenter map of Meta: https://datacenters.atmeta.com/ They're mostly in the US, and most outside the EU. Given the record timeline from concept to launch for this app, it's normal they can't whip up a datacenter from nothing overnight.

GDPR require equivalent protections, not to store data in the EU.

The US is not in the list of countries with equivalent protections, in fact most of the world isn't in that list. Which means in effect it should be in EU. Another nearby location that's permitted is UK, but they have no data center there at all.

https://gdpr-info.eu/issues/third-countries/

Re: Red flags in the Threads privacy policy

#179

Tbh if you are concerned about the privacy and ethics concerns here the biggest red flag is in the subtitle: Meta's Twitter rival launched in over 100 countries today—but not in the EU Anything more is simply detail - if a major launch of this sort of service omits the EU we immediately know exactly why.

"They trust me. Dumb fucks."

[deleted]

Re: Red flags in the Threads privacy policy

#180

Earlier quoted context omitted.

Apple should really communicate more clearly what they mean in these privacy reports, because I don’t think it’s insane to interpret “The following data may be collected and linked to you: … Health & Fitness” in this way. An incorrect interpretation, sure, but not one you have to be dumb to make.

> Apple should really communicate more clearly what they mean in these privacy reports This information is provided by the app developer; in this case Meta are telling Apple they use your health data and Apple is merely showing that information in the App Store.

Yes; my point is that 1% of the people who see this while browsing the App Store understand enough about the HealthKit data access requirements to interpret the language that Apple chooses correctly. And Apple does choose the language here, it’s selected by Meta from a list of Apple-created options.
Post reply on HN