Live data from Hacker News

Ban the sale of precise geolocation

lawfaremedia.org

141–150 of 205 posts

Re: Ban the sale of precise geolocation

#141
post #75

Earlier quoted context omitted.

To be honest, I feel like this is where iOS and Android are failing us. Why is every app allowed to embed a bunch of trackers? Only blocking cross-app tracking on user request as iOS does is not enough (and data of different apps/websites can be correlated externally).

im not sure about allowed. perhaps required may be closer. why would someone include tech that makes people think twice about using the app, unless it is required if you want to "sell" in a particular venue. if your developing geolocation based apps, location tracking is a core function. a calender, absolutely does not require location tracking beyond what side of the prime meridian are you on.

> why would someone include tech that makes people think twice about using the app, unless it is required if you want to "sell" in a particular venue.

Because the overwhelming majority of people don't think twice about this tech.

I do, and that's why I use a lot of web tools or old-fashioned phone calls, but most people think metadata=unimportant and assume that the purpose of the app is what it does for them rather than to gather their personal information for sale.

Re: Ban the sale of precise geolocation

#142
post #32

How about we just ban the collection of precise geolocation? Wouldn't that be a better solution?

So you want to ban all mapping apps and all fitness apps?

Nothing external needs my precise location to navigate with a map. An approximate location is sufficient to deliver to my device a map of an area I'm in, and of the overall route, and all of the details that are useful for navigation.

Fitness apps can be local. We have pocket supercomputers; certainly, we don't need help from the clown to keep track of how far (or how energetically) we biked or walked today, or where that took place.

Re: Ban the sale of precise geolocation

#143
The problem the USA has is that it has no concept of "private data" outside of some part of HIPAA.

Until that changes you're going to be stuck.

Something as simple as the data protections act 1998 (https://en.wikipedia.org/wiki/Data_Protection_Act_1998) would kneecap a lot of the shady shit that goes on in the USA.

Re: Ban the sale of precise geolocation

#144
post #17

Earlier quoted context omitted.

>I think we should make this type of tracking opt-out by default That's opt-in, not opt-out. https://en.wiktionary.org/wiki/opt-out

GP states correctly that they believe the default 'choice' of a user should be 'opting- out ' of location tracking.

This is utterly confusing the use of the terms. Opting is making a choice. The default isn't a choice. Opting by default makes no sense.

Re: Ban the sale of precise geolocation

#145
post #91

Earlier quoted context omitted.

What do you mean by "industrial" in this case?

Telemetry from machines and data from environmental sensors that is collected for operational purposes (safety, efficiency, reliability) in industrial applications. Old school engineering systems that in modern times have expansive network-connected sensors that may even have onboard classifiers to reduce the quantity of data. The trouble started when lawyers correctly noticed that these are incidentally capable surv…

Eh?

The GDPR is there to protect your personal/sensitive data, or data that can personally identify you. If has nothing whatsoever to do with data capture from industrial machinary.

I remain astounded how ignorant some people are of basic GDPR principle: protecting your _personal_ data.

Re: Ban the sale of precise geolocation

#146
post #119

Earlier quoted context omitted.

The "GDPR is complicated" meme has been circulating among software developers since probably before it was even written. It's so wild that HN dunks on it so much: Here we have a societal problem in computing we've been complaining about for decades, someone offers an incremental but imperfect regulation to start taking steps to correct it, and everyone hates it!

The GDPR is vague and unworkable as written. It fundamentally restricts all data processing with a few, vague exceptions. What is data processing essential for the services being provided? Many publishers assumed that getting paid was an essential part of providing a service, and it was not until 3 months before the implementation deadline that the committee clarified that getting paid is not included when you are be…

> The GDPR is vague and unworkable as written. It fundamentally restricts all data processing with a few, vague exceptions.

What utter utter FUD

You are free to collect as much personal data as you want, PROVIDING you have my explicit opt-in informed consent to do so.

What about this is difficult to understand?

> How are you to know whether or not the user is an EU citizen (and thus subject to the GDPR)?

The GDPR provides _basic_ data safety and consumer protection. If you aren't protecting users private data regardless of where they live in line with GDPR principles (such as collecting it fairly, and not selling it to randoms) then you are playing fast and loose with your users private, sensitive data. In which case you need to _seriously_ consider if what you are doing is ethical.

> The GDPR also is fundamentally opposed to how things currently work in the internet, making almost all advertising on the web illegal overnight.

Utter Bullshit!

You are free to advertise as much as you like! But if you want to track me with your advertising (hello scummy adtech industry) then you need my explicit informed consent to do so. And so you should!

Again, what about this is difficult to understand?

Re: Ban the sale of precise geolocation

#147
post #146
post #119

Earlier quoted context omitted.

The GDPR is vague and unworkable as written. It fundamentally restricts all data processing with a few, vague exceptions. What is data processing essential for the services being provided? Many publishers assumed that getting paid was an essential part of providing a service, and it was not until 3 months before the implementation deadline that the committee clarified that getting paid is not included when you are be…

> The GDPR is vague and unworkable as written. It fundamentally restricts all data processing with a few, vague exceptions. What utter utter FUD You are free to collect as much personal data as you want, PROVIDING you have my explicit opt-in informed consent to do so. What about this is difficult to understand? > How are you to know whether or not the user is an EU citizen (and thus subject to the GDPR)? The GDPR pro…

> If you aren't protecting users private data regardless of where they live in line with GDPR principles (such as collecting it fairly, and not selling it to randoms) then you are playing fast and loose with your users private, sensitive data.

It's interesting and revealing when someone responds to a law that says "You're not allowed to abuse users in countries X, Y, and Z" with "How can I figure out who's in the other countries, so I can abuse them?" instead of "I'll just stop abusing everyone, and then I don't even need to worry about where anyone is."

Whenever you find yourself asking "how do I toe as close to the 'illegal' line as I can without technically going over it?" I think it's time to ask yourself some pretty hard questions.

Re: Ban the sale of precise geolocation

#148

When I had the opportunity to peer into public records, I found some extremely intriguing stuff. There was one person with a feminine name who showed up with a “home address” that would correspond to being my “neighbor” at home, at my clinic, at church, when I went to college, etc. All the years corresponded correctly, and the addresses were some residential place about a block or less away from the places where I we…

> GPS coordinates

* coordinates

There are many ways of establishing ones latitude and longitude without recourse to one particular GNSS system.

Re: Ban the sale of precise geolocation

#150

Earlier quoted context omitted.

Telemetry from machines and data from environmental sensors that is collected for operational purposes (safety, efficiency, reliability) in industrial applications. Old school engineering systems that in modern times have expansive network-connected sensors that may even have onboard classifiers to reduce the quantity of data. The trouble started when lawyers correctly noticed that these are incidentally capable surv…

Interesting. What are your obligations under GDPR in that case? It's not like a packing machine can request data deletion.

No one has been able to provide a satisfactory answer to this question. I've seen the lawyers try to figure this out at a few companies.

GDPR frames everything in the context of a person's data. There is no "person_id" or similar field in these data models. That isn't the purpose of the data, it would be expensive to extract it, and then it would create obvious liability under GDPR. This makes the idea of finding a person's data expensive -- brute-force search on huge data volumes.

Compounding this, these data systems are often operational and some of the data may be in situ at the edge because it is too large to move all of it. The power and compute budget may not exist to find a person using brute force.

AFAICT, current best practice is to maintain a polite fiction that people aren't being tracked because that is not the intent. No one thinks that would stand up to serious legal scrutiny though. If the regulators come after you then plead best effort based on the technical infeasibility of doing anything else.

Post reply on HN