Live data from Hacker News

I wrote to Flock's privacy contact to opt out of their domestic spying program

honeypot.net

81–90 of 276 posts

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#81

Earlier quoted context omitted.

“Personal information” has a legal definition and photos of you in a public street might not satisfy it, regardless of the photographer’s intent.

I think it'd be challenging to rule that a license plate number is not personally identifiable information, when the same regulations often state that an IP address is.

"Anyone could have been driving my car, you can't positively identify me in the driver's seat with the evidence you have submitted" is routinely used to toss out cases involving traffic violations. It's not necessarily common but it does happen. By this logic a license plate does not personally identify the person driving, only the person the car is registered to.

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#82
post #38

Earlier quoted context omitted.

Your example is apples and oranges. Flock maintains private infrastructure that stores data. If the DSLR uploaded them to Rent-A-Center owned/leased servers it would in fact require Rent-A-Center to take the necessary steps. As Rent-A-Center would be the only group with proper access to data storage they would have inserted themselves into the chain of custody, and thereby have such obligation to ensure others data i…

AWS also maintains private infrastructure that stores data. Go write them asking to purge data pertaining to you from S3 and see how that goes.

Does AWS actively and by design parse and keep track of personally identifiable information of the data that AWS customers store on their S3 buckets? If that were the case they would absolutely be subject to CCPA (and GDPR) requests for deletion.

However, I suspect that is not the case. AWS is agnostic as to the type of data stored on S3, and deletion of PII stored on S3 is the sole responsibility of the AWS customer that chooses to store it.

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#83
https://www.flocksafety.com/legal/lpr-policy

> In accordance with its Terms and Conditions, Flock Safety may access, use, preserve and/or disclose the LPR data to law enforcement authorities, government officials, and/or third parties, if legally required to do so or if Flock has a good faith belief that such access, use, preservation or disclosure is reasonably necessary to comply with a legal process, enforce the agreement between Flock and the customer, or detect, prevent or otherwise address security, privacy, fraud or technical issues. Additionally, Flock uses a fraction of LPR images (less than one percent), which are stripped of all metadata and identifying information, solely for the purpose of improving Flock Services through machine learning.

In this document, to which they linked in their reply, it says clearly "address ... privacy ... issues."

Does your case not constitute a privacy issue? I would say so.

Continuing down below, their claim on "Trust Us" about how they employ machine learning would need some proper transparency into how can that be guaranteed.

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#84
post #81

Earlier quoted context omitted.

I think it'd be challenging to rule that a license plate number is not personally identifiable information, when the same regulations often state that an IP address is.

"Anyone could have been driving my car, you can't positively identify me in the driver's seat with the evidence you have submitted" is routinely used to toss out cases involving traffic violations. It's not necessarily common but it does happen. By this logic a license plate does not personally identify the person driving, only the person the car is registered to.

Right, but in this context the license plate number is still personal information, just of a different person.

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#85
post #38

Earlier quoted context omitted.

AWS also maintains private infrastructure that stores data. Go write them asking to purge data pertaining to you from S3 and see how that goes.

Flock has knowledge/use of the data. Their system processes can relate the photos “owned” by two different entities. They’re interacting with it and selling their access to it as a feature. That’s obviously distinct from S3. But you knew that.

I know quite a bit about Flock, having been intimately involved in the process of evicting it from our municipality, and I don't think the distinction you're trying to draw here is meaningful. Flock will say they provide a service, one avidly sought by the actual owners of the data, to generate analysis based on that data.

They're contractually forbidden from "selling their access to it" to arbitrary parties; they can share data only with the consent of their customers, almost all of whom actively want that data shared --- this is a very rare case of a data collection product where that's actually the case.

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#86
post #81

Earlier quoted context omitted.

"Anyone could have been driving my car, you can't positively identify me in the driver's seat with the evidence you have submitted" is routinely used to toss out cases involving traffic violations. It's not necessarily common but it does happen. By this logic a license plate does not personally identify the person driving, only the person the car is registered to.

Right, but in this context the license plate number is still personal information, just of a different person.

Then the key aspect of our discussion is the "identifiable" part, which you've left out.

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#87

Earlier quoted context omitted.

Did you put up a Ring camera on a stand in front of your house for the specific purpose of selling that I drove past at this specific timestamp? If so, yes. The CCPA[0] gives me explicit legal rights: * The right to know about the personal information a business collects about them and how it is used and shared; * The right to delete personal information collected from them (with some exceptions); * The right to opt-…

“Personal information” has a legal definition and photos of you in a public street might not satisfy it, regardless of the photographer’s intent.

Personal information usually does include photos of someone in public without their consent: exceptions usually hold for taking photos of people where it is in the public interest to be able to show them or impractical to get consent. This covers large gatherings and celebrities, but a portrait photo of a stranger might put you on the wrong side of the law.

Obviously, the idea is to not disallow having someone take a photo of you as a background, passing figure as they take a front-and-center photo of their family, but not allow you to be the main subject unknowingly and especially when you object explicitly.

On the other hand, a photographer still owns the copyright to a photo, so a subject (including in a portrait) cannot claim it or distribute it without permission even if they can potentially stop the photographer from distributing that photo.

IANAL, but you are not by default allowed to use anyone's "likeness" for your individual profit.

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#88
post #47

I noticed that the company is glossed as "Flock" and not "Flock Safety (YC S17)" in posts like this and last week's "US cities are axing Flock Safety surveillance technology", https://news.ycombinator.com/item?id=47689237 . Did YC house style change a while back to drop the "(YC xxx)" annotation since so many popular firms particpate / or because it's well known?

Who know, maybe they're trying to distance themselves from the privacy disaster, but I doubt anyone at YC or HN is smart enough to read the room on Flock.

Which room? The one paying them millions to spy on people? Cash Rules Everything Around Me.

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#89

I wrote this. I had/have absolutely no expectation that Flock would comply with my request, but figured I should try anyway For Science. Their reply rubbed me wrong, though. They seem to claim that there are no restrictions on their collection and processing of PII because other people pay them for it. They say: > Flock Safety’s customers own the data and make all decisions around how such data is used and shared. wh…

They were saying "don't write to us, talk to the people who own the cameras and ask them to delete the data". A company that manufactures video cameras is not the one to talk to when someone records you, talk to the person who recorded you. But a reasonable person would say -- the data is stored on Flock servers, not with the camera owners. And Flock would say, just because we sell data storage functionality to camer…

I don’t think you’re informed on the topic. They do not just manufacture cameras.

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#90
They seem to be implying that because they are a "service provider," they aren't responsible for complying with CCPA rules even though they are the ones with the data.

Does this hold water? I'm reading the CCPA rules now but if anyone knows, it would save me some tedious research.

Post reply on HN