Live data from Hacker News

‘I've got nothing to hide’ and other misunderstandings of privacy (2007)

papers.ssrn.com

21–30 of 293 posts

Re: ‘I've got nothing to hide’ and other misunderstandings of privacy (2007)

#21
post #2

I’m wondering: is there a good list of data privacy failure consequences? There are good lists of breaches but few describing what happened to the people afterwards. Credit card theft resulting in a loss being the most obvious one. Such concrete (real) examples would help me to argue with people who say: all this non-sense about data privacy. What would anyone want to do with your data anyways?

I think location data is the best example.

First, you have those who stormed the Capitol and were identified by the NYT based on their phones location [1]. You also have the Substack that used location data to publicly out a priest as gay [2].

You then have the companies selling location data of people who visit abortion clinics [3]. They obtain this location from SDKs that they deploy via apps you may already be using. And if you want to get more dystopian remember that Texas allows citizens to sue anyone for "aiding or abetting a post-heartbeat abortion" [4], meaning that driving your friend Rebeca to a clinic can land you in a lawsuit for at least $10k by people who do this as their day job.

Even if you're not sued, remember that companies have been reliably predicting whether you're pregnant for at least 10 years [5] and using it to influence your behavior in their favor. This one may be the one with the "least bad" consequences but, paradoxically, the one that better drives home the point since nothing here is criminal.

[1] https://archive.is/r6c7b

[2] https://www.vice.com/en/article/pkbxp8/grindr-location-data-...

[3] https://www.vice.com/en/article/m7vzjb/location-data-abortio...

[4] https://www.cbsnews.com/news/texas-abortion-law-bounty-hunte...

[5] https://archive.is/Z4x2f

Re: ‘I've got nothing to hide’ and other misunderstandings of privacy (2007)

#24
I got through 16 pages of the article, and he hadn't gotten to the point yet. He was summarizing previous articles he'd written. I understand that he's trying to steelman the "nothing to hide" argument, and has dispensed with the usual retorts (ably summarized in this thread so far). I'd like to know what his real response actually is. Did anybody get through the whole thing?

Re: ‘I've got nothing to hide’ and other misunderstandings of privacy (2007)

#25
Ever since Row v Wade was overturned, the method I've taken in arguments is to point out the now blatantly existing cases of misuse of private data to prosecute people. Many people know about the news now about how people have been arrested and convicted because of phone data that should have been private.

I haven't had this argument very often though, so so far there aren't indications as to its effectiveness. We'll have to see how it turns out.

Re: ‘I've got nothing to hide’ and other misunderstandings of privacy (2007)

#26

The problem with the "I've got nothing to hide" argument is it's not "you" who decides what is "right" or "wrong". The entity doing the "spying" determines what is right or wrong. "You" might think "x" is ok, however the "spying" entity may have the opposite view. And it is the "spying" entity's opinion that matters, not yours, because it always them that have the power and authority in determining what is "right" or…

Example: in the 1930, Dutch municipalities would record ethnicity for their citizens. The argument was that ethnicity wasn't something you'd need to hide, and it could be useful should you need to identify yourself.

When in 1940 the German occupiers took over, those records turned out to be very useful for their genocide.

Re: ‘I've got nothing to hide’ and other misunderstandings of privacy (2007)

#27
post #2

I’m wondering: is there a good list of data privacy failure consequences? There are good lists of breaches but few describing what happened to the people afterwards. Credit card theft resulting in a loss being the most obvious one. Such concrete (real) examples would help me to argue with people who say: all this non-sense about data privacy. What would anyone want to do with your data anyways?

> I’m wondering: is there a good list of data privacy failure consequences?

The ultimate example is how 1940’s Germany used 1930’s Germany’s census data. In 1933 it didn’t seem so bad to tick a box with your religious affiliation …

Re: ‘I've got nothing to hide’ and other misunderstandings of privacy (2007)

#28

The problem with the "I've got nothing to hide" argument is it's not "you" who decides what is "right" or "wrong". The entity doing the "spying" determines what is right or wrong. "You" might think "x" is ok, however the "spying" entity may have the opposite view. And it is the "spying" entity's opinion that matters, not yours, because it always them that have the power and authority in determining what is "right" or…

The real problem is that this argument relies on people actually meaning “anything”. It’s a strawman that’s so good, you get people actually trying to argue it, but the real argument isn’t about absolute publicity of information, it’s about providing access to additional information as a means to investigate wrongdoing. Very few people are practically suggesting every single fact ought to be public about a person.

Besides, doomsaying that “anything could be illegal!” isn’t backed by anything real or lasting.

Re: ‘I've got nothing to hide’ and other misunderstandings of privacy (2007)

#30
post #26

The problem with the "I've got nothing to hide" argument is it's not "you" who decides what is "right" or "wrong". The entity doing the "spying" determines what is right or wrong. "You" might think "x" is ok, however the "spying" entity may have the opposite view. And it is the "spying" entity's opinion that matters, not yours, because it always them that have the power and authority in determining what is "right" or…

Example: in the 1930, Dutch municipalities would record ethnicity for their citizens. The argument was that ethnicity wasn't something you'd need to hide, and it could be useful should you need to identify yourself. When in 1940 the German occupiers took over, those records turned out to be very useful for their genocide.

would record ethnicity

*religious affiliation

It makes sense that ethnicity would have been recorded as well, but FAFAIK the Germans mostly used the data on religious identity (i.e. which persons were a member of which church community).

Post reply on HN