Live data from Hacker News

I wrote to Flock's privacy contact to opt out of their domestic spying program

honeypot.net

171–180 of 276 posts

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#171
Back in 2018, CloudFormation data leaked through a public gist (misconfigured gist plugin, I thought the gist was private but it wasn't... I had change the default config) and showed up on an obscure website being served via CloudFlare. When I contacted CF, they claimed they couldn’t remove the cached content because their system “doesn’t work like that". I pushed back and then they said that they're not responsible for the content and that I should send another email to abuse@cf... to get data about the hosting provider and deal with the content provider (e.g. VPS, ISP, whatever). After a few back and forth msgs, I made it clear that if the data wasn’t taken down within a week or so, I would escalate the issue to the local and German GDPR authority (see https://www.ombudsman.europa.eu/en/european-network-of-ombud...).

And what do you know? I got not reply, but the content disappeared in ~48hrs.

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#173

Earlier quoted context omitted.

> If I see a flash on a speed camera operated by a business on behalf of a police department, your argument states I should be able to use CCPA to force the business to delete my picture and the record of me speeding If I can get the request to them before the police can file with the court and request that data as evidence. Sounds reasonable to me. If the police want to put up a camera, then the police should put up…

So police departments should have to develop and host all their administrative software also? I think we can all see why that would be a terrible idea. Police are like any other government agency or business in that they contract with the private sector for a variety of services that are not in their area of expertise.

> So police departments should have to develop and host all their administrative software also?

Yes. We're in an high technology and information age. Police should be well-versed and capable of understanding the technologies and informations that people use.

> I think we can all see why that would be a terrible idea.

I don't.

> Police are like any other government agency or business in that they contract with the private sector for a variety of services that are not in their area of expertise.

Why shouldn't police (or some law enforcement agency) be capable of operating and maintaining law enforcement technologies?

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#174

I wrote this. I had/have absolutely no expectation that Flock would comply with my request, but figured I should try anyway For Science. Their reply rubbed me wrong, though. They seem to claim that there are no restrictions on their collection and processing of PII because other people pay them for it. They say: > Flock Safety’s customers own the data and make all decisions around how such data is used and shared. wh…

They were saying "don't write to us, talk to the people who own the cameras and ask them to delete the data". A company that manufactures video cameras is not the one to talk to when someone records you, talk to the person who recorded you. But a reasonable person would say -- the data is stored on Flock servers, not with the camera owners. And Flock would say, just because we sell data storage functionality to camer…

> They were saying "don't write to us, talk to the people who own the cameras and ask them to delete the data".

The response to this should just be, "Yes, very well, please divulge a complete list of your customers, their contact information, and information about camera locations so I will be able to pursue this per instructions".

When that obviously doesn't work either then we can all agree the law as written is completely useless, and feel great about rewriting it in a way that's calculated for maximum damage to both the vendor and their customers, and collateral damage to the whole panopticon. Or, just spitballing here, we can just skip to the punchline here and do all that anyway

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#175
post #160
post #154

Earlier quoted context omitted.

I don’t care. I don’t care who owns the data. If I can’t easily get private information like my movements removed from a database like this, the legislation does not sufficiently protect me. It should absolutely be Flock’s responsibility to remove my data and we should absolutely require it by law. Full stop.

A reasonably nuanced defense could likely claim that to be able to do what you want, would have much worse side effects on privacy. For example, would you want to be able to tell Public Storage (or some other storage unit place) to remove any naked photos of you stored anywhere in their storage units? For them to actually be able to do that would require they have nigh omniscience on everything stored by/for everyone…

Except that the analogy is that they already have, or can easily create, that list. If they couldn’t, their value proposition would be lame. “We know you’re looking for a specific license plate, here’s a million hours of footage from all over the city, have at looking through it all.”

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#177

Earlier quoted context omitted.

That view of data ownership is _highly_ jurisdiction dependent and is not the overwhelming norm in the US.

While that's definitely true, in this particular case he's invoking his rights under CCPA.

They're invoking a right they do not in fact have under CCPA. Flock is a service provider under CCPA, and isn't required to respond to their request so long as they're operating under the terms of their contract with the municipality (which is, in turn, exempt from CCPA.)

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#178
post #160

Earlier quoted context omitted.

A reasonably nuanced defense could likely claim that to be able to do what you want, would have much worse side effects on privacy. For example, would you want to be able to tell Public Storage (or some other storage unit place) to remove any naked photos of you stored anywhere in their storage units? For them to actually be able to do that would require they have nigh omniscience on everything stored by/for everyone…

Except that the analogy is that they already have, or can easily create, that list. If they couldn’t, their value proposition would be lame. “We know you’re looking for a specific license plate, here’s a million hours of footage from all over the city, have at looking through it all.”

Only for paying customers, which you aren't of course. If those customers paid public storage to inventory their stuff, then that inventory is their property. Surely it would be inappropriate to use their inventory data to find your naked photos. A violation of privacy even. (/s, kinda)

I was enumerating the likely defense, not that it's valid.

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#179
post #85

Earlier quoted context omitted.

Flock has knowledge/use of the data. Their system processes can relate the photos “owned” by two different entities. They’re interacting with it and selling their access to it as a feature. That’s obviously distinct from S3. But you knew that.

I know quite a bit about Flock, having been intimately involved in the process of evicting it from our municipality, and I don't think the distinction you're trying to draw here is meaningful. Flock will say they provide a service, one avidly sought by the actual owners of the data, to generate analysis based on that data. They're contractually forbidden from "selling their access to it" to arbitrary parties; they ca…

Except their customer's data isn't actually theirs: OP requested their private data to be deleted from the system. So OP expressed a clear intent for their data not to be used by Flock's customer. We could say that the data thus becomes abusively retained on these systems. As a result, IF Flock has the technical means of performing the requested data deletion, it should be compelled to perform it.

This is the same situation as a web hosting provider: if it is communicated to them that one of their customers uses their service to host illegal content, then it becomes the web hosting provider's responsibility to remove that content.

Reasonable technical feasibility for the service provider is key here, but it can be argued since the data can apparently be shared in ways that identify OP.

Probably not how the law currently works (don't know, not a lawyer), but I guess it should, as otherwise it allows creating a platform that shares abusively retained data without any reasonable recourse for the subjects of this data to remove the data from the platform.

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#180
post #85

Earlier quoted context omitted.

I know quite a bit about Flock, having been intimately involved in the process of evicting it from our municipality, and I don't think the distinction you're trying to draw here is meaningful. Flock will say they provide a service, one avidly sought by the actual owners of the data, to generate analysis based on that data. They're contractually forbidden from "selling their access to it" to arbitrary parties; they ca…

Except their customer's data isn't actually theirs: OP requested their private data to be deleted from the system. So OP expressed a clear intent for their data not to be used by Flock's customer. We could say that the data thus becomes abusively retained on these systems. As a result, IF Flock has the technical means of performing the requested data deletion, it should be compelled to perform it. This is the same si…

I do not believe this is how the law works. Two totally different regimes.
Post reply on HN