Live data from Hacker News

Red flags in the Threads privacy policy

qz.com

241–250 of 263 posts

Re: Red flags in the Threads privacy policy

#241

Earlier quoted context omitted.

Even if that were true, it isn’t but for the sake of the discussion I’ll humour you, America is far more open and aggressive with its protectionism policies. As is China. So I don’t understand the complaint. You’re either in favour of laws that promote the growth of local economies or you’re not. But to be clear, the GDPR is not about protectionism. If it feels that way then perhaps you need to have a hard look at wh…

I'm neutral on protectionism: I'm in favor of laws that are precise and unambiguous, and not up to the interpretation of whatever courts and enforcement agencies wish to impose. For example, which of the following statements are true according to the ECJ's interpretation? American companies cannot run datacenters in Europe, because the CLOUD act might compel them to give up data to American authorities. Canadian comp…

> I'm in favor of laws that are precise and unambiguous, and not up to the interpretation of whatever courts and enforcement agencies wish to impose.

So am I but unfortunately the topic itself is highly nuanced. If it were that easy to say this type of usage is ok but this type isn’t then we would have been able to put better technological measures in place to keep our data safe.

And let’s be honest, GDPR is hardly an outlier. Most laws end up being nuanced when it comes to cutting edge technology. Whether it is intellectual property laws, computer misuse laws, etc. The only difference here is that innocent people aren’t being harmed by GDPR.

So if you’re going to complain about vague laws harming people, then GDPR is the literal last one you should be concerned about at this point in time.

The only reason people moan about GDPR is because entities like Facebook have brainwashed you into believing it’s bad. They say it’s “anti-business”, “harms innocent companies”, etc. but it’s all BS. And I say this as someone who has had to work inside the GDPR every day since it’s inception.

Now if you want to moan about innocent people being arrested in America for “hacking” because they send bug bounties, or even just click “view source” in Chrome…then I’m all ears. Or complain about how IP laws are being abused to hoard monopolies on obvious ideas. Or about how companies are sucking up other peoples copyrighted content for free to train proprietary GAN. Or about the abuses of DMCA.

The thing is, companies don’t to moan about those things because those abuses empower them. Whereas GDPR levels the playing field. So despite the fact that GDPR has never once been abused and the others frequently are, GDPR is the law that everyone gets pissy about.

Re: Red flags in the Threads privacy policy

#242

Earlier quoted context omitted.

For me the biggest red flag is that they have apps in the EU but what they're doing with this one is so dodgy that they're not even risking entering the EU. Also, interesting to see a big international company actually back up their "we just won't do europe then"

It seems pretty obvious that it's no more dodgy than any other app they have. Despite people crying loudly about how untrue it is and how unfair it is when sites block people in the EU, the EU's regulations require a lot of work to comply with (even in the case where you are already complying with the intent of the regulations). Clearly here Meta's number one priority was getting this app out quickly. There are a ton…

It's reusing Instagram. Instagram is GDPR compliant yet, threads isn't. That tells me they added extra stuff that Instagram doesn't have by default. More dodgy than other apps. And considering how long it takes for anything to happen they could have released and fixed minor unknown issues. The fact they haven't seems they think what they've added is dodgy enough for major fines.

Re: Red flags in the Threads privacy policy

#243
post #153

Earlier quoted context omitted.

Facebook changed their algorithm several years ago (2014?) to prioritize paid content over organic comments. This resulted in many companies being force to change how they communicated, as people who followed them were not guaranteed to receive critical information if posted on Facebook. I guess the biggest difference is that Facebook has had almost 10 years to adjust the algorithm towards paid content, and have user…

> Facebook changed their algorithm several years ago (2014?) to prioritize paid content over organic comments. That's a lie. Instead, "Facebook realized that users were growing wary of misleading teaser headlines, and the company recalibrated its algorithm in 2014 and 2015 to downgrade clickbait and focus on new metrics, such as the amount of time a user spent reading a story or watching a video, and incorporating su…

The average rate of organic content on Facebook is 5%, and has steadily increased the amount of paid content that users get on their feeds compared to organic content.

Feel free to provide a source that show a decrease in advertisements on Facebook.

Re: Red flags in the Threads privacy policy

#244

This level of scrutiny is really excellent. Now we need to apply it to other companies working in the same space. There is a serious lesson for startups though, if you actively start collecting data, you will, if you survive long enough, begin to have to declare what data you have when you "grow up". For example, if you do anything with photos, you will have to ask for permissions to process location data. even if yo…

> Is threads actually setting out to hoover that data? I doubt it

Check out the App Privacy section yourself: https://apps.apple.com/us/app/threads-an-instagram-app/id644...

Re: Red flags in the Threads privacy policy

#245
post #185

Earlier quoted context omitted.

I would bet over 95% of companies don't comply with GDPR. I know some startups don't serve EU because of this. Facebook is under the microscope of the EU, they probably aren't risking getting fined until they can scale the product and implement the thing they need to lower the fine they would get and make being fined worth it. They are going to get fined most likely, but again 95% of the companies in the world could…

It’s exceptionally easy: one just has to not do shitty things with personal information. Complying if you are doing shitty things with personal information is, by design, impossible - and that is good.

Ok, what if you do a database back up daily and someone requests you to delete their information. You're telling me you go through all those back ups and delete that person's information? If you don't you aren't complying with GDPR.

Re: Red flags in the Threads privacy policy

#246
post #233

Earlier quoted context omitted.

I will take your point, but I'd say you also need to account for how the GDPR has been enforced to this point. I regularly submit complaints to supervisory authorities and I've been employed by a few companies that regularly have meetings with their local SAs for guidance regarding potential pitfalls. Most enforcement is directed towards total disregard of the GDPR. Data that hasn't been properly deleted after reques…

I will take your point, but I'd say you also need to account for how the GDPR has been enforced to this point. ... Most enforcement is directed towards total disregard of the GDPR. I agree this is true. And at least here in the UK the regulators appear to be acting in good faith and according to the spirit of the law. However I don't like the principle that not enforcing a bad rule somehow makes it better. If somethi…

The actual text starts on page 32.

Also, legal texts are the always longer than a conceptual tl;dr of them. Covering for all eventualities. It's not a flaw of the legislation itself that some boilerplate is required. Also, a lot of it is contextually relevant (e.g. there's entire sections for regulating specific industries).

Your average contract contains the same boilerplate by percentage.

Re: Red flags in the Threads privacy policy

#247
post #5
post #2

Man I hate these alarmist hit pieces. - "You cant delete Threads without deleting Instagram altogether": but you can deactivate it. What's the difference, and why do I care? Without including that info, you're useless. - "Threads collects sensitive personal information about you": How? Inferred from the things I post? Well I'll just not post those things. - "Threads collects data about your employment": Same. - "Thre…

This reply is a good example of someone whose perspective is utterly locked in to their own perceived personal threat model (which may or may not accurately understand their own actual threats). This technology, they think, is perfectly acceptable according to their own sense of threats, so why isn't it good enough for literally everyone ? Other people's threat models are so unimaginable, so inconceivable that the co…

What makes you think these rhetorical sex workers have learned anything at all from this piece? A belief you know more than them about what's best for them?

Re: Red flags in the Threads privacy policy

#248
post #99
post #68

Earlier quoted context omitted.

[flagged]

But we don’t need Twitter for that do we? We have 4chan, parts of the fediverse and so on for unfiltered. Threads is for mainstream. I don’t see that as bad. As someone who was a moderator, sometimes you want that sandwich and not Joe Schmoe stupid verbal trash he thought less than 3 seconds about.

I responded to the claim that Facebook is "run well" and Twitter is "not run well since Musk". You've extended this simplistic division by implying anything that isn't basic sandwich content must be verbal trash.

Political discussion and controversial topics need to be covered in order for society to progress, to solve problems, to canvas the range of solutions and perspectives. Heated exchanges, passionate disagreements, and ideas we don't like come with the territory. No need to be afraid.

If we fall into the trap of "nothing to see here" via enforcing certain people as truth-tellers and everyone else as "stupid sex-predator anti-vaxxer shills", then we have a problem.

It's much better to trust the average educated person can think for themselves rather than need Corporate sponsored Big Gov to push creepy "anti-misinformation" tactics, censoring, back-dooring and manipulation. That's my point done... what exactly was your point?

Re: Red flags in the Threads privacy policy

#249

Earlier quoted context omitted.

> Apple should really communicate more clearly what they mean in these privacy reports This information is provided by the app developer; in this case Meta are telling Apple they use your health data and Apple is merely showing that information in the App Store.

Yes; my point is that 1% of the people who see this while browsing the App Store understand enough about the HealthKit data access requirements to interpret the language that Apple chooses correctly. And Apple does choose the language here, it’s selected by Meta from a list of Apple-created options.

> my point is that 1% of the people who see this while browsing the App Store understand enough about the HealthKit data access requirements to interpret the language that Apple chooses correctly.

How so? There is no hidden meaning here; Facebook are simply telling Apple that they will access your health information, and Apple is passing that information along. There’s no misinterpretation. The fact that the app doesn’t currently request this information is immaterial – Facebook are saying they will. The straightforward interpretation of the privacy card is the correct one.

Re: Red flags in the Threads privacy policy

#250

This level of scrutiny is really excellent. Now we need to apply it to other companies working in the same space. There is a serious lesson for startups though, if you actively start collecting data, you will, if you survive long enough, begin to have to declare what data you have when you "grow up". For example, if you do anything with photos, you will have to ask for permissions to process location data. even if yo…

> Is threads actually setting out to hoover that data? I doubt it Check out the App Privacy section yourself: https://apps.apple.com/us/app/threads-an-instagram-app/id644...

see my sister comment:

> Sure, facebook the app is all up in your junk. But the apple label about "it stealing your health data" is nonsense[1]. Why isn't there a permissions dialogue asking me to share my health data, like fitness apps? Does apple specifically allow Facebook apps to get at my health data unannounced? what about apple pay, is that leaking to facebook as well?

[1] https://apps.apple.com/us/app/threads-an-instagram-app/id644...

As I said earlier, Tech companies are not reliable narrators.

But, to underscore the point, if apple really are letting facebook harvest this data, surely this undermines their "privacy is our magic sauce" shtick? why are they letting them harvest that data? why, as a platform, are they letting them get away with it?

Ideally the US would adopt GDPR like laws at a federal level, however thats not going to happen because there are too many tech billionaires.

Post reply on HN