Live data from Hacker News

Maine passes bill to prevent ISPs from selling browsing data without consent

techcrunch.com

131–140 of 233 posts

Re: Maine passes bill to prevent ISPs from selling browsing data without consent

#131
post #8

Earlier quoted context omitted.

There was a campaign by the Maine Chamber of Commerce running against it on the grounds that the privacy protections didn't go far enough. They only applied to ISPs (carriers) not to companies higher in the stack (Facebook, etc.). [1] I couldn't quite work out of this campaign was done out of legitimate concern or was a cynical attempt to derail it? I mean, I agree with them that privacy legislation should apply broa…

I feel like industry groups often use the "perfect as the enemy of the good" tactic to try and sabotage any starting point on progress.

Industry groups in favorable contexts would say this is fine, then for the "didn't go far enough" part they just lobby some changes in definitions next year, another change in scope the year after that, etc. Pretty soon it's exactly what they wanted and nobody's the wiser.

Re: Maine passes bill to prevent ISPs from selling browsing data without consent

#132
post #53

Earlier quoted context omitted.

Boy have I got a surprise for you. I was an engineer at a web analytics firm a decade ago and yes, ISPs have your web browsing data and are selling it left and right. Also apps, Cell phone companies, etc. Our company bought all that data. and when that wasn't enough, we created apps that collected even more. Every click and ajax request, etc.... timestamped. Yes, there are analysts sifting through your browsing data…

> ISPs have your web browsing data Since you worked in this area: What specific things do they track, and by what technical mechanism? DNS requests? (Do they capture those that don't go to their servers?) IP addresses? HTTP snooping? Full HTTP (non-TLS) MITM?

I wasn't responsible for the data intake, but I know that the data was extensive, and always included time on page, full URL, other request information (often post stuff).

I know that HTTPS provided a technical hurdle that our company and data providers worked around after about 6 months.

My guess is that some MITM-type collection? Some data providers gave us IPs and some just gave us some Tokenized ID. I don't know if ISPs provided IPs, but probably not.

Note that we did lots of data linking. Let's say an ISP provided us your age, URL, and Timestamp. We would link that into another data provider that provided past purchases, URL, and Timestamp (shopping toolbar/plugins do this) to get a bigger picture of who you are.

Re: Maine passes bill to prevent ISPs from selling browsing data without consent

#134
post #116

Note that this is only necessary because the 2018 Republican Congress voted to allow ISPs to sell user data. https://www.consumerreports.org/consumerist/house-votes-to-a...

Gotta make it easier for the Russians to target you.

Re: Maine passes bill to prevent ISPs from selling browsing data without consent

#135
post #61

I can predict the "Dark Patterns" right now. Giant Accept button and 6pt font opt-out link.

There needs to be some law against dark patterns because nothing is enforceable anymore. I'm not sure what can be done but I know that the death of our society is due to people/companies that are using loop holes and all sorts of tricks to game the system and undermine basic trust. It used to be that these "tricks" were used only sparingly but as more and more bad actors engage in this type of behavior it only makes…

What you are describing is a form of race to the bottom, if all you competitors (in business or life generally) get ahead and away with behaving unscrupulously the only rational course is to behave unscrupulously.

What is particularly tragic is that all it takes to get this rolling is the perception that others are doing something and people will move to follow.

Campaign attack adds, lying about diesel emissions, doctoring footage, falsifying compliance to environmental regulations and on and on.

The perception is becoming that if you obey the rules you are a fool and that is horrifically dangerous position.

Society by and large runs on a trust (but verify) model, I trust that when I walk down the street a random person isn't going to murder me but when that trust is eroded things go bad fast.

Scares the crap out of me and I'm not sure what we could do at this point, more genuine openness from government/authorities, properly funded government watchdogs with independent oversight that kind of thing but they are expensive and easy for either side to rally against "big government"/"the man".

Re: Maine passes bill to prevent ISPs from selling browsing data without consent

#138
post #116

Note that this is only necessary because the 2018 Republican Congress voted to allow ISPs to sell user data. https://www.consumerreports.org/consumerist/house-votes-to-a...

Which isn't even technically possible in the first place. So voting to allow it doesn't do anything

Re: Maine passes bill to prevent ISPs from selling browsing data without consent

#139

Earlier quoted context omitted.

Each and every time? As a user who understands and consents to that request, that would be incredibly annoying.

Causing incredible annoyance is obviously the idea. It would drive away users, making business models that relied on it less efficient. It's a great idea.

Has this worked out in practice, say with cookie warnings? Or do most of us click Accept and move on?
Post reply on HN