Live data from Hacker News

I wrote to Flock's privacy contact to opt out of their domestic spying program

honeypot.net

1–10 of 276 posts

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#2
I wrote this. I had/have absolutely no expectation that Flock would comply with my request, but figured I should try anyway For Science. Their reply rubbed me wrong, though. They seem to claim that there are no restrictions on their collection and processing of PII because other people pay them for it. They say:

> Flock Safety’s customers own the data and make all decisions around how such data is used and shared.

which seems to directly oppose the CCPA. It's my data, not their customers'.

Again, I didn't really expect this to work. And yet, I'm still disappointed with the path by which it didn't work.

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#4
To me this sounds like the equivalent of visiting a website that sells your data, and then asking AWS to delete your personal data when it actually belongs to a customer of theirs and only resides within their private storage.

Would you ask your local ISP to delete data they provided to Tinder like your IP address? That doesn't make sense to me.

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#5

To me this sounds like the equivalent of visiting a website that sells your data, and then asking AWS to delete your personal data when it actually belongs to a customer of theirs and only resides within their private storage. Would you ask your local ISP to delete data they provided to Tinder like your IP address? That doesn't make sense to me.

Yeah I was getting the same feeling. I wonder if an equivalent request to California police agencies that contract Flock technologies would work though.

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#6
I think you're going to have a hard time with this...

Flock seems to leave the data in ownership of the government. They are just providing the service of being custodians for storing and accessing that data.

You probably would get a similar response by submitting your request to Amazon web services or Google cloud or whoever has Flocks data: "sorry, we're just holding the data on behalf of Flock"

In either my example case or your stated case, you would have a very hard time convincing the host business to destroy their customers data without a court order or court case that shows their policy is invalid and they must comply.

Not a lawyer, just noting the parallel.

I do appreciate that Flock's response says that they cannot use the data they've collected for other purposes.. which further reinforces my cloud storage analogy -- the cloud vendor can't look at your data you upload to storage to e.g. build profiles on you/your business.

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#7

If that's a valid excuse than the CCPA isn't worth the paper its written on.

The rule of any documentation is that it is out of date as soon as the ink is dry. By the time a regulation is enacted, workarounds/loopholes have already been found (if not intentionally worked into it).

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#8

I wrote this. I had/have absolutely no expectation that Flock would comply with my request, but figured I should try anyway For Science. Their reply rubbed me wrong, though. They seem to claim that there are no restrictions on their collection and processing of PII because other people pay them for it. They say: > Flock Safety’s customers own the data and make all decisions around how such data is used and shared. wh…

They were saying "don't write to us, talk to the people who own the cameras and ask them to delete the data". A company that manufactures video cameras is not the one to talk to when someone records you, talk to the person who recorded you.

But a reasonable person would say -- the data is stored on Flock servers, not with the camera owners. And Flock would say, just because we sell data storage functionality to camera owners doesn't mean we own the data, anymore than a storage service you rent a space from owns what you put in that space.

But then an even more reasonable person would say: the infrastructure is designed in such a way as to create inadvertent sharing, and the system has vulnerabilities that compromise the data, so Flock has responsibility for setting up the system in such a way that it's basically designed to violate privacy.

And that is the main criticism of Flock. You need to have a more nuanced criticism. It would be really interesting to see this litigated.

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#9

I wrote this. I had/have absolutely no expectation that Flock would comply with my request, but figured I should try anyway For Science. Their reply rubbed me wrong, though. They seem to claim that there are no restrictions on their collection and processing of PII because other people pay them for it. They say: > Flock Safety’s customers own the data and make all decisions around how such data is used and shared. wh…

These laws get complicated quickly. There's a specific ALPR law in the CA civil code which seems to carve out several exceptions for a business like Flock:

https://leginfo.legislature.ca.gov/faces/codes_displayText.x...

The enforcement provisions are rather bleak as well and afford no opportunity to directly bring a case against the agency that operates the system but instead just the individual who misuses it.

I think one of the more direct attacks would be going after jurisdictions that chronically have officers misusing the system. I think you're going to have to create precedent in this way to foment actual change.

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#10

To me this sounds like the equivalent of visiting a website that sells your data, and then asking AWS to delete your personal data when it actually belongs to a customer of theirs and only resides within their private storage. Would you ask your local ISP to delete data they provided to Tinder like your IP address? That doesn't make sense to me.

Yeah I was getting the same feeling. I wonder if an equivalent request to California police agencies that contract Flock technologies would work though.

Probably not, as the law enforcement agencies get a bunch of exceptions to the CCPA.
Post reply on HN