Live data from Hacker News

Red flags in the Threads privacy policy

qz.com

181–190 of 263 posts

Re: Red flags in the Threads privacy policy

#181

Tbh if you are concerned about the privacy and ethics concerns here the biggest red flag is in the subtitle: Meta's Twitter rival launched in over 100 countries today—but not in the EU Anything more is simply detail - if a major launch of this sort of service omits the EU we immediately know exactly why.

I for one keep thinking: "Ah good, that that shit is not here yet." The longer it takes, the better. If they do not enter the EU at all, that would be perfect. But I probably am kidding myself, if I think, that they will never enter the EU. They will wriggle their way around the law somehow and if not, they will calculate and break the law, like they did many times before, in the name of profit.

Re: Red flags in the Threads privacy policy

#182

Earlier quoted context omitted.

For me the biggest red flag is that they have apps in the EU but what they're doing with this one is so dodgy that they're not even risking entering the EU. Also, interesting to see a big international company actually back up their "we just won't do europe then"

> interesting to see a big international company actually back up their "we just won't do europe then" that's the most interesting things to me. Whether: 1- Threads is dead in the water 2- They figure it out and makes the EU happy 3- EU is irrelevant enough to be ignored 2- still looks like the most likely 1- would be very embarrassing and 3- would be, indeed, an "interesting" development.

What is the EU missing out on if Threads never enters it though?

I don't believe Facebook, Instagram, Tik Tok or Twitter were net gains for people. I don't see how Threads might be.

I do honestly believe that if all these services disappeared overnight we would live in a better world. I legit just don't want Threads to enter the EU, ever.

Re: Red flags in the Threads privacy policy

#183
post #149
post #140

Earlier quoted context omitted.

I want to be able to read (former UN weapons nspector) Scott Ritter on twitter. A man with a huge amount of experience and someone who is able to give very informed commentary. On pre-Musk twitter I couldn't read him, now I can. And I could give quite a number of similar examples.

Hey thanks for your comment and other perspective! How couldn’t you read him before the overtake? What’s the difference? Could this inspector join Threads and would you follow him there?

They probably couldn't read him on pre-musk twitter because he was briefly banned. From the Wikipedia page, this is why:

"Ritter rejected the Western media's coverage of the 2022 Russian invasion of Ukraine and has voiced his perspective on multiple podcasts, including Andrew Napolitano's.[42][43] In April 2022, he posted a tweet claiming that the National Police of Ukraine is responsible for the Bucha massacre and calling U.S. President Joe Biden a "war criminal" for "seeking to shift blame for the Bucha murders" to Russia.[44][45] Ritter was suspended from Twitter for violating its rule on "harassment and abuse" after this, but his account was reinstated the next day.[45][46][47]

The U.S. Department of State and Polygraph.info described Ritter as a frequent contributor to Sputnik and RT during the war.[48][49] Polygraph reported that he compared Ukraine to “a rabid dog” that needed to be shot.[49] He has also compared Ukraine's treatment of Russians to Nazi Germany's treatment of Jews.[50]

In July 2022, the Ukrainian Center for Countering Disinformation included Ritter on a list of what it called Russian propagandists.[51][44]"

He's a Russian shill, imperialism apologist.

Re: Red flags in the Threads privacy policy

#184

Earlier quoted context omitted.

> interesting to see a big international company actually back up their "we just won't do europe then" that's the most interesting things to me. Whether: 1- Threads is dead in the water 2- They figure it out and makes the EU happy 3- EU is irrelevant enough to be ignored 2- still looks like the most likely 1- would be very embarrassing and 3- would be, indeed, an "interesting" development.

Let me give my 2 cents as an EU citizen. The way I see it is a mix of all of that, but number 3 is the biggest. Twitter is not big here. There’s people who use it, sure, but there’s a reason you don’t see that many EU issue trending on Twitter. Here’s an example out of the top of my head: France is rioting and it barely registered on Twitter. The biggest European market for Twitter is the UK and it has 19M users, the…

By contrast, when I was on Twitter (up until rumours of the Musk purchase), 75% of what I saw was European-centric.

Re: Red flags in the Threads privacy policy

#185

Tbh if you are concerned about the privacy and ethics concerns here the biggest red flag is in the subtitle: Meta's Twitter rival launched in over 100 countries today—but not in the EU Anything more is simply detail - if a major launch of this sort of service omits the EU we immediately know exactly why.

I would bet over 95% of companies don't comply with GDPR. I know some startups don't serve EU because of this. Facebook is under the microscope of the EU, they probably aren't risking getting fined until they can scale the product and implement the thing they need to lower the fine they would get and make being fined worth it. They are going to get fined most likely, but again 95% of the companies in the world could…

It’s exceptionally easy: one just has to not do shitty things with personal information. Complying if you are doing shitty things with personal information is, by design, impossible - and that is good.

Re: Red flags in the Threads privacy policy

#186
post #86

Earlier quoted context omitted.

No my problem with Twitter is that the quality of the discourse is poor and getting worse every day. Which is a direct result of Musk deciding to prioritise blue check comments over others. If you're having to pay to have people listen to you then that means you typically don't have something worth saying. And we see this manifest in many ways e.g. pages of laughing emojis in response to a tweet.

> If you're having to pay to have people listen to you then that means you typically don't have something worth saying. This basically invalidates all of advertising in one stroke.

People literally pay in order to escape advertising.

Of course advertising is not worth it for the target. It's harmful more often than not.

Re: Red flags in the Threads privacy policy

#187

Earlier quoted context omitted.

People keep saying this and yet it’s never happened despite the GDPR being in place for 5 years now. As a tech manager for an EU company, I can honestly say that it isn’t that hard to be GDPR compliant. Even when I worked for a company that did need to collect customer information, we pretty well understood what we could and couldn’t do under GDPR. This whole “GDPR is dangerous” meme needs to die because businesses a…

> As a tech manager for an EU company, I can honestly say that it isn’t that hard to be GDPR compliant It's pretty easy for a business to be GDPR compliant unless their business model or processes in some way involve collecting and processing or selling personal data of their users. Before GDPR a lot of businesses used this as a nice little second income stream, or just grew used to being able to freely analyze every…

> Suddenly you have to basically gut it, or even throw it out entirely.

Good.

Re: Red flags in the Threads privacy policy

#188

Earlier quoted context omitted.

So many websites don’t actually need to collect any user data. Any commercial organisation is going to have customers and therefore customer details and payments data. Any commercial site needs to record enough logs to investigate events like outages or security threats. Any site that isn't purely informational and read-only probably works with user-provided data in some way. People keep writing about GDPR and simila…

> Any commercial organisation is going to have customers and therefore customer details and payments data. Necessary for the performance of a contract or to comply with legal obligations. > Any commercial site needs to record enough logs to investigate events like outages or security threats. Legitimate interest, and possibly legal compliance if the nature of your site means you have a legal duty to collect those log…

There should be no debate that the items I mentioned are allowed under the GDPR because one or more of the lawful bases for processing applies. My point is that on many sites you're still going to be collecting and processing personal data for many legitimate reasons and therefore you still need to have all the policies and provisions in place for that data to be compliant with the data protection regulations. "Just don't collect the data in the first place" is mostly not a very useful argument for how easy it is to comply with the GDPR.

On numerous occasions in GDPR-related discussions I have seen people seriously questioning whether you can keep a basic server log with IP addresses in it of the kind that every web server has generated by default for decades. Often there are suggestions that such logs must be automatically deleted after a short period or the IP addresses masked in order to be compliant. And yet having records of which addresses were doing what on your site can be useful information for security and fraud prevention purposes months or even years after the records were originally created. So who is right? GDPR doesn't actually say and as far as I'm aware neither have any of the relevant data protection authorities yet so if you're running a site with these security concerns but also making an honest attempt to be compliant then you literally have no way to know how far you're allowed to go without crossing a line and upsetting a regulator.

That's just one everyday example that would probably apply to millions of different websites and that has been discussed many times but still with no clear answer. There are many more areas of ambiguity that even a well-intentioned organisation can easily run into. Backups and archives. Soft deletes when a user asks to delete something but you know for a fact that many users subsequently contact your support staff saying they've made a mistake and asking to restore the data. It's a long list with few clear answers.

Re: Red flags in the Threads privacy policy

#189
Threads will also automatically, silently, and without your consent doxx and/or deadname you[1] by digging up your legal name from its massive social network and access to personal information and changing your display name to your legal name. This is horrible for everyone, but it also makes it incredibly dangerous for marginalized people who are often targeted for harassment, doxxing, as well as IRL harassment and stalking by people like GaysAgainstGroomers and LibsOfTikTok, which are, incidentally, being allowed free reign on the platform.

[1]: https://xantronix.social/@megaspel/110666980545804656

Re: Red flags in the Threads privacy policy

#190
post #167

Earlier quoted context omitted.

How are you going to "fix" that "design flaw" when the personal data in question is the result of legally required customer age checks? Evidence needed to support your tax filings? Used to identify and block people who are repeatedly trying to defraud you or breach your security? Subject to a legal hold because it might provide relevant evidence in some legal action between other parties or it's been requested as evi…

I don't know where your actual problem is. The GDPR allows holding data for most of these purposes. You intermingled legal obligations with data legal departments would like to hold in the end there. Only one of those is required. Also, some of these are pure theoretical in the EU. You're not even allowed to photocopy an ID in Germany; age verification is a checkmark someone sets upon verifying the ID is valid and th…

I don't know where your actual problem is.

My point is that knowing which personal data you need to redact and under which circumstances is not always easy. Before you can build a system that does something you first need to identify exactly what something is required.

Post reply on HN