Live data from Hacker News

CCPA Scam – Human subject research study conducted by Princeton University

blog.freeradical.zone

201–210 of 353 posts

Re: CCPA Scam – Human subject research study conducted by Princeton University

#201

Earlier quoted context omitted.

Because receiving a letter citing chapter & verse of the legal code is generally never the precursor to a nice friendly chat. The actual-not-fake-researcher (instead of fictional people) could have sent a nice friendly request saying, "I'm a PhD candidate working on public policy in the tech sector. Could you please answer the following questions regarding your process of CCPA compliance, if applicable"

Legal threats are a common occurance nowadays though. I get calls weekly saying a warrant had been issued for my arrest or that my "SSN is about to be revoked". The email also clearly says they are not sending a request at this time and it seems nicely written to me. I guess I don't get why this is on HN and everyone is so livid about it.

I understand what you’re saying, but this seemed a far more credible threat than someone wanting me to send them Bitcoin to delete my webcam video. For instance, here’s a story about a lawyer who filed so many ADA lawsuits that a judge barred them from filing any more. People abuse the legal system all the time, and while people on the receiving end of a lawsuit can fight it, it’s guaranteed to be expensive in many ways. I could absolutely see someone filing thousands of CCPA lawsuits that wouldn’t actually stand up in trial, but which would be an utter fiasco for even the un-liable defendants.

Edit: Oops, here’s a story: https://www.azag.gov/press-release/serial-litigant-permanent...

Re: CCPA Scam – Human subject research study conducted by Princeton University

#202
post #125

Earlier quoted context omitted.

If I had to guess, the wording is in the study's FAQ is carefully chosen: "an application detailing our research methods" doesn't necessarily mean "an application with the verbatim text of the emails we planned to send, including our thinly veiled legal threat at the end." Not trying to turn this thread into a generic flameware against "academic" research methods, but this whole things seems oddly reminiscent of the…

The problem, like in that previous case, is that "human subject research" is a pretty narrowly defined category. It is mostly meant to cover testing out drugs on human subjects, and stuff like that. Notably, there is plenty of unethical research that doesn't qualify. So when an IRB gets a proposal that amounts to "I'm going to send some emails/interact with some folks online" their reply is likely to be along them li…

The IRB boards I've interacted with or seen peers go through included more than just drugs etc. A survey or interviewing people has always been included as human subject research by the boards. Depending on the specifics, surveys & interviews may be exempt from a full review of the human subjects process, but only after the IRB itself has made that designation. Basically a PI shouldn't be talking to a human as as part of their research without the IRB making a determination on it.

Anything related to food & drug testing is usually its own special category of review within the IRB, but it's not just meant-- and has never been meant-- to only deal with biomed research. The Belmont Report in 1979 that gave rise to the modern IRB explicitly addressed research with human subjects, not just biomedical research. Anyone in that field is aware of the extreme examples like Milgram's work and the Stanford Prison experiment that make this review necessary.

It may be the case that some IRB's don't take that side of thing as seriously as they should, but that doesn't mean the ethical burden is primarily on the researchers. The legal liability is on the institution, and the IRB is the regulation-mandated body required to ensure compliance.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#204
post #133

Ross Teixeira, the PhD student that did this, had the brazen nerve to post this lie on Twitter: Responses to the study have been overwhelmingly positive, and I particularly appreciate the notes of encouragement that some websites have sent. We look forward to sharing results in the coming year, with the goals of identifying best practices and informing future policy making. https://mobile.twitter.com/RossTeixeira/sta…

> had the brazen nerve to post this lie That's excessive, crosses into personal attack, and breaks the HN guidelines ( https://news.ycombinator.com/newsguidelines.html ). Please make your substantive points without stooping to that. This is not a site for stirring up internet mobs. We're trying to avoid the online callout/shaming culture here. https://hn.algolia.com/?sort=byDate&type=comment&dateRange=a...

That's fair, you're right. I should have been less inflammatory. This story struck a chord in me for... reasons. That's not meant as an excuse, I should have known better to have taken a step back before I said anything, especially something that could escalate tensions. Thank you for killing the comment. I'll be more mindful of it going forward.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#205

Earlier quoted context omitted.

There are three things that you can demand of a company (that meets certain revenue thresholds) if you’re a California resident: - that they delete information about you that they have (with potential exceptions) - that they provide you with what information they have about you, and for what purposes they have that information (with exceptions) - that they opt you out of sharing data with other entities (with excepti…

> You cannot, as implied by the email, demand a response to an arbitrary query. I wouldn't say that the questions were arbitrary; they were exactly the things you would need to know in order to submit a request for information, but without the actual request. The only alternative that I can think of to get the same information is to register at all of these websites, use them for five minutes, then make an actual leg…

> they were exactly the things you would need to know in order to submit a request for information, but without the actual request.

This doesn’t seem accurate to me. The first and fourth questions especially aren’t relevant to submitting a valid CCPA request.

But my point was that, more generally if your goal is to use CCPA to compel a company to answer your questions, I think you’re going to be disappointed.

The law simply doesn’t compel companies to answer arbitrary questions. Heck, I don’t think CCPA even compels them to answer any of these questions.

Only questions 2 and 3 are relevant to submitting a request, and CCPA requires the company to publish that information, but I don’t think it compels them to answer emailed questions asking for that information. Open to being wrong on this point though.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#206
post #92

Earlier quoted context omitted.

I think the plaintiffs would be people who spent money reacting to the emails, and I suspect Princeton may be quick to take care of those expenses to avoid further action. I personally didn’t incur any monetary costs, just a lot of unnecessary stress.

Intentional infliction if emotion distress is a cause of action for a civil suit. You don't have to have lost money.

I think this is pretty awful, but I'd still give the person the benefit of the doubt that it wasn't intentional.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#208
post #73

I'm the person who wrote that blog post. I got an email from a fake person in France who asked several questions about my small social media site's CCPA compliance, then ended the letter with: > I look forward to your reply without undue delay and at most within 45 days of this email, as required by Section 1798.130 of the California Civil Code. I thought I was about to be sued by someone who was the equivalent of a…

I've met Ross during my time at Princeton and he is a really genuine person, he is not trying to ruin anyone's life. This incident is the result of an uncharacteristic blind spot in empathy: a mistake. I also have experience with the Princeton IRB on similar topics. The reality is that Princeton's IRB, and IRBs in general, are not equipped to deal with this sort of online research. IRBs were created as a reaction to…

I'd like to disagree as someone who knew Ross during my time at Berkeley. He absolutely is intelligent and thoughtful enough to know what he was doing -- including the consequences.

Berkeley's IRB is similarly illed -- resulting, a lot of trust (i.e. empathy) is placed that the lead will not do anything as obviously unethical as this. This is not the mistake that someone as intelligent as Ross makes, this was a conscious decision that backfired.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#209

I'm confused how this is human experimentation. Were they not merely collecting information on how a site handles these requests? Is it because they erroneously sent emails to sites that do not fall under the umbrella of the law they were examining? An email asking an organization for answers to questions is human experimentation? I must be missing something.

Any research that at all involves a human being-- performed by an institution governed by laws that mandate the existence of an IRB-- must be reviewed by their IRB. Keep in mind that IRB's govern research, not just experimentation.

We don't even need to get into the weeds on this just being "answers to questions". All you need to do is look at the human impact: This research study has caused anxiety, time, and potentially money to many people being asked to unknowingly participate in the study. IRB's exist to evaluate-- among other things-- potential adverse impacts on people involved in a study. This has had an adverse impact and should not have been allowed through IRB review in this form.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#210
post #131

Earlier quoted context omitted.

* When you do something to people to see how they act, it's a human experiment. The purpose of this study was officially "to understand how websites would respond to real users" * The participants / subjects of the study are people, not "websites" as the study claims. Websites don't read and respond to emails, people do. * The participants of this study were selected without their consent * The participants were not…

> When you do something to people to see how they act, it's a human experiment. That's not the official definition an IRB would use. The official definition is a lot less broad than a lot of people on this thread seem to think. It requires that are collecting biospecimens, identifiable private information, or certain kinds of information about a specific person. [0] [0]: https://grants.nih.gov/policy/humansubjects/re…

IRB's emerged as mandated bodies governing the intersection of research & humans in the wake of the 1974 NRA and subsequent Belmont Report. That report explicitly states that it is more that just biomedical, but also behavioral research that is covered. "do something to people to see how they act" fits pretty well within the domain of "behavior".

If you are doing research with an institution governed by an IRB then you cannot do anything involving a human being without it getting reviewed by the IRB. There are criteria whereby the IRB may exempt the research from a full review, but only the IRB can make that determination.

Perhaps the #1 absolute goal of the IRB is to assess potential adverse impacts of the research on any humans involved. It should be clear from the comments here, and if you read through any of the links to twitter threads, that people were adversely impacted by this study either through anxiety, time spent unecessarily, and perhaps money. I might understand (though disagree) with a point of view that said these adverse results were not foreseeable, but review of the study itself under an IRB for its involvement of humans was absolutely required.

Post reply on HN