Live data from Hacker News

I wrote to Flock's privacy contact to opt out of their domestic spying program

honeypot.net

231–240 of 276 posts

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#231
post #154

Earlier quoted context omitted.

I don’t care. I don’t care who owns the data. If I can’t easily get private information like my movements removed from a database like this, the legislation does not sufficiently protect me. It should absolutely be Flock’s responsibility to remove my data and we should absolutely require it by law. Full stop.

The problem with this is where do you draw the line? If I film you with my iPhone (e.g. you walk past in the background of my video), Apple should delete my video from my phone and iCloud account based only on your instructions? Apple hold the data in iCloud, Apple (or a phone network) may be leasing me the phone. That sounds pretty similar to the Flock situation. I guess the difference is that flock might be sharing…

Not pronouncing about what path is the most distopic, just for the fun of the exercise of what if we push in the direction:

Given the rule, I would expect (IANAL), Apple should not deal with data stored on phones they sold.

People are responsible for what they store on their device. When I take a photo in the street, if someone come to me asking to erase a photo with them or their kids as they were in the background, I'll tell I don't publish any photo online, which is generally what people are thinking of as a concern and that stop there, but if they insist I will remove it from my phone. Because I'm too lazy to actually live edit the photo and remove them from the picture, even if that is certainly doable with a simple prompt by now.

Now if Apple store automatically photo in some remote server they own, they are the ones who should be responsible to comply with making sure they won't store something illegally. Microsoft, Google, and Apple use PhotoDNA to detect known CSAM if I'm not mistaken. Though legally they only should remove once they get a notice about it. Same way, they could proactively blur visages of people not detected as the people that were whitelisted for the uploading account. And, by that logic, they should certainly remove the information regarding a person if they get a notice, just as well as they wouldn't keep CSAM data once notified, would they?

Anyway the underlying issue is not who store what, but what societies lose at letting mass surveillance infrastructures being deployed, no matter how the ownership/responsibility dilution game is played on top of it.

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#232
post #34

I wrote this. I had/have absolutely no expectation that Flock would comply with my request, but figured I should try anyway For Science. Their reply rubbed me wrong, though. They seem to claim that there are no restrictions on their collection and processing of PII because other people pay them for it. They say: > Flock Safety’s customers own the data and make all decisions around how such data is used and shared. wh…

Wait, is it your data? If you drive your car in front of a Ring camera on my house (I don't have a Ring camera don't @ me), is it your claim that you own the data on that camera?

Who paid for the camera? If I did with taxpayer dollars then, you're damn right I should have a say.

The "my Ring camera" trope is a fun strawman, though.

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#233
post #34

Earlier quoted context omitted.

Wait, is it your data? If you drive your car in front of a Ring camera on my house (I don't have a Ring camera don't @ me), is it your claim that you own the data on that camera?

Who paid for the camera? If I did with taxpayer dollars then, you're damn right I should have a say. The "my Ring camera" trope is a fun strawman, though.

If it's the municipality holding the data it's even less an issue! Municipalities are exempt from CCPA!

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#234

I wrote this. I had/have absolutely no expectation that Flock would comply with my request, but figured I should try anyway For Science. Their reply rubbed me wrong, though. They seem to claim that there are no restrictions on their collection and processing of PII because other people pay them for it. They say: > Flock Safety’s customers own the data and make all decisions around how such data is used and shared. wh…

Lawsuit challenging Flock's illegal data brokerage:

https://www.courthousenews.com/california-drivers-accuse-flo...

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#235
How did we get to allowing this in the USA? I remember the zeitgeist used to be to make fun of China's mass surveillance / social credit system, and ten years ago proposing to build something like this in the USA would be unthinkable. It's wild that we're just willingly sliding into the same system here too.

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#236
post #123

Earlier quoted context omitted.

Equivocation. My stock broker doesn't own my stocks either, they merely hold my assets in a brokerage account.

I encourage you to present that analogy to an actual court and see how far it gets you. It's very easy to find the statutory definition of a "data broker" under California law. This is what I mean by the fruitlessness of these kinds of legal discussions on HN. What do you want me to argue, that you're wrong to want the law to work that way?

Are you aware that not every lawyer with skin in the game shares your opinion of what a broker is?

https://www.courthousenews.com/california-drivers-accuse-flo...

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#237

Earlier quoted context omitted.

Because Flock isn't a data broker. Flock's customers own their data, not Flock, and they use Flock's platform voluntarily to share data with other customers.

If Flock's customers, using Flock's infrastructure or tooling, can share data with each other, that would be bad. I'm not saying that's what's happening, but that's what I thought was happening before reading this thread, and now I have to go and run through their policies. Either way ALPRs and AI-facial scanners in public are a huge violation of privacy and I loathe them, but I hope it's correct that Flock customers…

That's absolutely what is happening.

https://www.courthousenews.com/california-drivers-accuse-flo...

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#238

Earlier quoted context omitted.

It’s the other way around. Flock is the subprocessor for whoever hired them to collect data. If they are collecting data on behalf a city or municipality, those are the entities you need to address.

I'm not sure about that, I'm pretty sure any company that has your PII is obliged to follow the law, regardless of their contracts with their customers/vendors. Law doesn't make you investigate who's the end customer for your data, only who has it. As for "subprocessor" -- it might as well be the case that both sides are subprocessors for each other, nothing wrong with that.

I don’t know this specific law, I just know how it works in the EU with the GDPR. Of course any company that has your PII has to follow the law, but it matters which entity is the one that has is the end customer for your data. They are the one that has to have a legal basis for even collecting that data and they are the one you as a use deal with. If they use a sub-contractor then that’s an internal matter for them and not something you as the subject has to deal with. Of course they have to have a DPA in place with the sub-contractor and they have the responsibility to make sure the sub-contractor follows the law. Likewise the sub-contractor has to make sure that their client has a sound legal basis for processing the PII.

For example: if a bank outsources part of their KYC process to a third party, that’s not something you have to concern yourself with, you only deal with the bank.

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#239

How did we get to allowing this in the USA? I remember the zeitgeist used to be to make fun of China's mass surveillance / social credit system, and ten years ago proposing to build something like this in the USA would be unthinkable. It's wild that we're just willingly sliding into the same system here too.

It's been bad since the patriot act.

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#240

Earlier quoted context omitted.

Who paid for the camera? If I did with taxpayer dollars then, you're damn right I should have a say. The "my Ring camera" trope is a fun strawman, though.

If it's the municipality holding the data it's even less an issue! Municipalities are exempt from CCPA!

They aren't. Flock is, so are they? Also, the state I live in has a GDPA that would override CCPA, so it's not exactly that cut and dry as you very well know.

The Ring example is garbage. You paid for it and it's on your property. Nothing remotely similar.

I guess then it's OK for Flock to be required installed on your mobile device so they can check your geo history for the last hour and that you don't match the profile of the guy who stole Billy's Huffy bike?

What happens when the municipalities buy time on your device since, well, you don't own it and have no right to the software running on it because of ToS you agreed to. Or that awesome "save the children from CSAM pedos" bill you cheered for that paved the way for the USG and states to be guaranteed citizen introspection app slots on your device?

Because the piece of paper says so, it should then just be accepted as is!

Post reply on HN