Live data from Hacker News

CCPA Scam – Human subject research study conducted by Princeton University

blog.freeradical.zone

111–120 of 353 posts

Re: CCPA Scam – Human subject research study conducted by Princeton University

#111

I run a SaaS product solo, and I receive these message and other similar ones (GDPR requests) every week. Most are generic like this one, but some are out right offensive name calling. I have no problem following these laws and extended the data/privacy rights to everyone (not just CA or EU residents). I must say though, when people threaten me or resort to name calling I make the process deliberately difficult. edit…

Here's a copy:

  >
  >
  > To Whom It May Concern:
  >
  > My name is Tom Harris, and I am a resident of Sacramento, California. I have a few questions about your process for responding to General Data Protection Regulation (GDPR) data access requests:
  >
  >     Would you process a GDPR data access request from me even though I am not a resident of the European Union?
  >     Do you process GDPR data access requests via email, a website, or telephone? If via a website, what is the URL I should go to?
  >     What personal information do I have to submit for you to verify and process a GDPR data access request?
  >     What information do you provide in response to a GDPR data access request?
  >
  > To be clear, I am not submitting a data access request at this time. My questions are about your process for when I do submit a request.
  >
  > Thank you in advance for your answers to these questions. If there is a better contact for processing GDPR requests regarding nymeria.io, I kindly ask that you forward my request to them.
  >
  > I look forward to your reply without undue delay and at most within one month of this email, as required by Article 12 of GDPR.
  >
  > Sincerely,
  >
  > Tom Harris

Re: CCPA Scam – Human subject research study conducted by Princeton University

#112
post #73

I'm the person who wrote that blog post. I got an email from a fake person in France who asked several questions about my small social media site's CCPA compliance, then ended the letter with: > I look forward to your reply without undue delay and at most within 45 days of this email, as required by Section 1798.130 of the California Civil Code. I thought I was about to be sued by someone who was the equivalent of a…

I've met Ross during my time at Princeton and he is a really genuine person, he is not trying to ruin anyone's life. This incident is the result of an uncharacteristic blind spot in empathy: a mistake. I also have experience with the Princeton IRB on similar topics. The reality is that Princeton's IRB, and IRBs in general, are not equipped to deal with this sort of online research. IRBs were created as a reaction to…

Howdy Paul!

I definitely see a problem in that some people think that if the IRB doesn't object to what they're doing, it's OK. But ethics is a responsibility of the entire research team, and the research team is usually far better placed to understand the implications of their research strategy than the IRB.

The following are big problems here:

  - lack of informed consent
  - deception
Researchers should be trained that those are only allowed in exceptional cases where the benefits outweigh the harms.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#113
post #73

Earlier quoted context omitted.

I've met Ross during my time at Princeton and he is a really genuine person, he is not trying to ruin anyone's life. This incident is the result of an uncharacteristic blind spot in empathy: a mistake. I also have experience with the Princeton IRB on similar topics. The reality is that Princeton's IRB, and IRBs in general, are not equipped to deal with this sort of online research. IRBs were created as a reaction to…

Howdy Paul! I definitely see a problem in that some people think that if the IRB doesn't object to what they're doing, it's OK. But ethics is a responsibility of the entire research team, and the research team is usually far better placed to understand the implications of their research strategy than the IRB. The following are big problems here: - lack of informed consent - deception Researchers should be trained tha…

I feel like "coercion" (legal threats) should probably be a separate bullet point from "deception"?

Re: CCPA Scam – Human subject research study conducted by Princeton University

#114

> reply without undue delay and at most within 45 days of this email, as required by Section 1798.130 of the California Civil Code So I looked this up and it really exists. I wonder if an account holder of a Facebook or Google account can use this law to get actual customer service.

There are three things that you can demand of a company (that meets certain revenue thresholds) if you’re a California resident: - that they delete information about you that they have (with potential exceptions) - that they provide you with what information they have about you, and for what purposes they have that information (with exceptions) - that they opt you out of sharing data with other entities (with excepti…

> You cannot, as implied by the email, demand a response to an arbitrary query.

I wouldn't say that the questions were arbitrary; they were exactly the things you would need to know in order to submit a request for information, but without the actual request.

The only alternative that I can think of to get the same information is to register at all of these websites, use them for five minutes, then make an actual legal request, and if not provided with "information" and "purposes", to make an actual legal threat.

I don't get the impression that site owners would feel a lot happier about that approach. I can see how sending the email that was actually sent would be seen by a researcher as a better approach. And can also see a self-serving aspect, in that it's a cheaper approach - saves the labor of registering a bunch of accounts.

But I'm getting the impression that site owners went to defcon 1 after getting a single request for information that should be easily available on the site if it were subject to the law (which the blog author has stated clearly that they were not.)

If anything was missing imo, it's that there should have been help in the email mentioning the for-profit/$25MM revenue/50K Californians requirement in the law - but that might make it sound more like a threat, not less. They could also have made better guesses about whether the sites they were emailing would be bound by the law, and targeted the emails better.

But if the site does fall under the law, and they felt threatened and hired a lawyer to answer those questions, I'm not sympathetic. They're supposed to be able to answer those questions if any of the >50K Californians they work with ask, at any time. If they were, replying would be a simple matter of sending a link or a form email that they already had ready.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#115
Seems like a career academic with no experience in the real world playing around like this is some kind of game. I'm sure they meant no harm, because they don't consider anyone "participating" to be anything more than a potential subject in their agenda to get a good review on their paper.

That letter and their social media posts are nothing more than a facade to maximize return with no consideration of impact.

Total negligence.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#116
post #113

Earlier quoted context omitted.

Howdy Paul! I definitely see a problem in that some people think that if the IRB doesn't object to what they're doing, it's OK. But ethics is a responsibility of the entire research team, and the research team is usually far better placed to understand the implications of their research strategy than the IRB. The following are big problems here: - lack of informed consent - deception Researchers should be trained tha…

I feel like "coercion" (legal threats) should probably be a separate bullet point from "deception"?

Well if you have informed consent, it's not going to be a problem. If you don't, then you need to do a more careful analysis of ill effects might ensue when someone gets the letter (feel distress, spend money on a lawyer).

Re: CCPA Scam – Human subject research study conducted by Princeton University

#117
post #88

From the study's FAQ[0]: > Did an Institutional Review Board consider this study? > We submitted an application detailing our research methods to the Princeton University Institutional Review Board, which determined that our study does not constitute human subjects research. From the social experiment[as reported by OP's link]: > I look forward to your reply without undue delay and at most within 45 days of this emai…

If I had to guess, the wording is in the study's FAQ is carefully chosen: "an application detailing our research methods" doesn't necessarily mean "an application with the verbatim text of the emails we planned to send, including our thinly veiled legal threat at the end."

Not trying to turn this thread into a generic flameware against "academic" research methods, but this whole things seems oddly reminiscent of the "let's try to insert malicious code into Linux" fiasco [1]. I'm conceptually fine with generic passive tools like web crawlers to conduct research, but since when did the internet become a place where nonconsensual interactive research became fine?

[1] https://www.bleepingcomputer.com/news/security/linux-bans-un...

Re: CCPA Scam – Human subject research study conducted by Princeton University

#118
post #107
post #73

Earlier quoted context omitted.

I've met Ross during my time at Princeton and he is a really genuine person, he is not trying to ruin anyone's life. This incident is the result of an uncharacteristic blind spot in empathy: a mistake. I also have experience with the Princeton IRB on similar topics. The reality is that Princeton's IRB, and IRBs in general, are not equipped to deal with this sort of online research. IRBs were created as a reaction to…

The fact that Ross didn't mean to do this is all the more reason why someone - maybe an IRB, maybe not (your argument makes sense) - should be assisting 20-something researchers with having a well-informed perspective. In the absence of an organization that's good at this (which doesn't seem to exist and should), this probably should be the supervising professors.

As a research group leader, I find it unfortunate that the grad student seems to be the public face of this and is therefore attracting most of the ire. Feels like the student is being thrown under the bus, and responsibility for ensuring the study is conducted ethically should ultimately be that of the principal investigator.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#119
post #87

Earlier quoted context omitted.

Part of the premise of the nation state is that you don't need to abide by other countries' laws. If you're doing business within that nation state, you're required to operate by their laws.

Quick, someone tell that to Julian Assange. :) Or all the webpages which choose to implement GDPR by blocking european visitors.

I agree with you. The networks allow incursion, the law seems to allow for excursion.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#120

Earlier quoted context omitted.

I'm just running a hobby website. I'm not at all used to receiving letters that bring up legal questions, then give me a time frame to reply as per a specific law. To my non-lawyer reading, that looks like someone's doing their homework to figure out how to drag me into court. Judging from a lot of the responses I've gotten from other recipients, I'm far from the only one.

I don't know buddy... Might be worth it to invest some time into anxiety/stress management. Meditation, keep an eye on your sleep, exercise, maybe go talk to someone. You're not supposed to have anxiety attacks over fairly lame sounding emails. Not to mention, it's just a matter of time before you get another (spam/scam) email like this. I get these quite frequently? I don't know how often, but definitely at least on…

Obvious scams are a lot easier to dismiss without worry than ones that actually look like potentially credible legal threats.

You're just blaming the victim here, possibly because you're biased by the hindsight of already knowing the legal threat was never real in the first place.

Post reply on HN