Live data from Hacker News

Grindr Shares Personal Information With Third-Parties

github.com

161–170 of 317 posts

Re: Grindr Shares Personal Information With Third-Parties

#161
post #67

Earlier quoted context omitted.

Makes me think that data should be treated differently in the case of a potential new owner, allowing users to opt-out from their data from being transferred; you may trust the leadership and governance, and may not trust whomever takes over or who will newly has access to the data.

Change of control is a huge problem when it comes to privacy sensitive data. That's also a big factor in why I have a problem with governments collecting data. You may trust the present day administration (or not...), but who knows what a future administration (or occupying force) is going to be up to (beside the obvious risk of a leak or a breach). The same goes for situations like bankruptcies and 'bad leavers', th…

> That's also a big factor in why I have a problem with governments collecting data. You may trust the present day administration (or not...), but who knows what a future administration (or occupying force) is going to be up to

The standard example is how the Netherlands were rather religiously tolerant, but used to keep track of Jews for tax collection purposes before WW2. Then when the Nazis arrived, they had all the records they needed to achieve their goals.

Who knows what will happen in the future, and how currently harmless data could be used by new actors then.

Re: Grindr Shares Personal Information With Third-Parties

#162
post #151

So vending HIV status is a straight up HIPAA violation, I'm fairly sure that's been found to be the case over and over again -- it doesn't matter what your business is, health information is covered by HIPAA. That's 250k per violation fine, and leaking status positive or negative is a violation. And every person, and every time they pass that information to every "partner" is a distinct violation.

You aren't bound by HIPAA just because a user hands over health related information. You will however fall under it if you are sharing that data with a covered entity..

Re: Grindr Shares Personal Information With Third-Parties

#163

Earlier quoted context omitted.

> Also, does HIPAA say anything about technology companies outside of the medical field's data that may voluntarily collect HIV status? No, HIPAA binds only covered entities, which are (basically) care providers, insurers, and certain other parties in certain business relationships with care providers and insurers. If you give out your health information to a dating service, it's not protected by HIPAA.

> HIPAA binds only covered entities Covered entities are specifically defined as: "(1) A health plan"; "(2) A health care clearinghouse"; or "(3) A health care provider who transmits any health information in electronic form in connection with a transaction covered by this subchapter" [1]. [1] https://www.gpo.gov/fdsys/pkg/CFR-2017-title45-vol1/xml/CFR-...

Then why are research institutions included?

Re: Grindr Shares Personal Information With Third-Parties

#164

These are 3rd party analytics firms and not any random companies. Both these firms have strong data protection processes and are very secure. From Grindr's perspective, they are probably looking for analytics for different segments of their users and send all data to Localytics who help them with this (vs. trying to build these internally). Here is a thought. Do we think that the data is more secure with Grindr itsel…

The data is already in Grindr’s systems, this means it is ALSO at Localytics (and others). This is not as safe as if it was only in Grindr’s own systems.

And any of these companies could be purchased by some other entity and change their data privacy policy.

Re: Grindr Shares Personal Information With Third-Parties

#165
post #143
post #115

Earlier quoted context omitted.

Rooted phone, no google services, and netflix downloads are just fine.

SafetyNet is a cat and mouse game. A lot of people don't have the patience for it.

I've never had a problem over months of using Magisk.

Re: Grindr Shares Personal Information With Third-Parties

#166
post #156
post #151

So vending HIV status is a straight up HIPAA violation, I'm fairly sure that's been found to be the case over and over again -- it doesn't matter what your business is, health information is covered by HIPAA. That's 250k per violation fine, and leaking status positive or negative is a violation. And every person, and every time they pass that information to every "partner" is a distinct violation.

This is like saying Twitter is liable if you tweet your own status.

That's not even close to the same thing. You're comparing involuntary and unknown sharing of personal data with explicit and self-actioned sharing of that data.

Re: Grindr Shares Personal Information With Third-Parties

#167

Earlier quoted context omitted.

Reminds me of the relationship between the Mafia and the homosexual community of the early-mid 20th century. The Mafia didn’t particularly like gays, but they ran all of the gay bars because it gave them the opportunity to blackmail their patrons.

> The Mafia didn’t particularly like gays, but they ran all of the gay bars because it gave them the opportunity to blackmail their patrons Source? Curious to read more about this.

The Mafia controlled most gay bars due to their illegal status, and extracted a monetary premium from the gay community. This recognized both the legal risk the Mob was taking and the near-monopoly status it enjoyed. After all, where else were gay folks going to meet? There were often high cover charges and minimum drink requirements. Moreover, gay men were at risk of blackmail from their Mob overlords

https://www.vice.com/en_us/article/gqmym3/how-the-mafia-once...

I had never heard this before, but it is easy enough to find it. There are at least a couple of other articles that readily came up.

Re: Grindr Shares Personal Information With Third-Parties

#168
post #101

Earlier quoted context omitted.

Who's growing is the more important question. Regulation benefits the already big.

> Regulation benefits the already big "Regulation" isn't guaranteed to do anything. Some regulations benefit already-big, some harm them. Some have no effect at all. Lack of regulation is guaranteed to benefit already-big, though. Unchecked corporations become oligopolies or monopolies. Free markets (meaning free movement, not free of regulation) and consumer protection are impossible without regulations, though.

>Lack of regulation is guaranteed to benefit already-big, though.

Not neccessarly, it depends on how educated market participants are. Shouldn't a world that becomes more and more informed, connected and educated not become less regulated?

>Unchecked corporations become oligopolies or monopolies.

But not forever, less regulation also means more opportunity for competitors. And educated customers would be aware of the situation and just ignore the monopolies if they can buy somewhere else.

Re: Grindr Shares Personal Information With Third-Parties

#169

Even within its confines, Grindr's data are rich for blackmail. (Consider: images and messages sent and received within 100 feet of Capitol Hill.) It was recently acquired by an offshore billionaire [1]. [1] https://www.bloomberg.com/news/articles/2016-01-12/china-tec...

Makes me wonder, what would it take to legislate the use of personal information?

Maybe we are getting close to this point?

Seems like situations that result in direct pressure on the legislators would be more productive than ones involving us, their “employers”...

Re: Grindr Shares Personal Information With Third-Parties

#170
post #145

Even within its confines, Grindr's data are rich for blackmail. (Consider: images and messages sent and received within 100 feet of Capitol Hill.) It was recently acquired by an offshore billionaire [1]. [1] https://www.bloomberg.com/news/articles/2016-01-12/china-tec...

Yikes. Combine this with the Chinese OPM hack, where extremely personal data for most government employees with security clearance has been stolen, and they have a blackmail goldmine on their hands. https://en.wikipedia.org/wiki/Office_of_Personnel_Management... They can verify what has been reported on sf-86 vs what might be found from this service. Any affairs or issues not reported are ripe for blackmail. Possibil…

I feel like it's only a matter of time before we see some devastating compromise(s) of security using the OPM hack and/or hacks of private data sources.

When you look at some of the common methods intelligence adversaries use to ensnare assets (extortion, money, exploiting sympathies, stroking egos, revenge, etc.) the information in these hacks are a treasure trove the likes of which may never have been seen before. I can't imagine the various powers that be in the US Gov't are ready for the espionage threat posed by this..

Post reply on HN