Live data from Hacker News

CCPA Scam – Human subject research study conducted by Princeton University

blog.freeradical.zone

221–230 of 353 posts

Re: CCPA Scam – Human subject research study conducted by Princeton University

#221
post #132

Earlier quoted context omitted.

Thank you for making this point. I didn't articulate it, but this is part of why I felt I had to say something.

I hope this fellow Ross does not become suicidal or otherwise depressed when he sees the weight of the internet coming down on him for this faux pas. Ross, none of this wil matter in a year. Or 5 years.

No post body was provided.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#222

As a counterpoint here I don't consider this study or the Linux kernel study human subject research unless we define human subject research so broadly that the definition essentially becomes meaningless. As a side note I find the "outrage" about these small academic studies quite hipocritical. This is a community where a significant proportion of people work in related to ads/clicks who constantly experiment on human…

If a study is observing how human reacts to a certain situation, that's research with human subjects. The Linux study observed how maintainers react to bugs, this CCPA/GDPR request spam observed how data protection staff reacts to requests about their processes.

And the backlash is not hypocritical. You're of course right that FB has also done really questionable research, but that doesn't matter here. I've also seen significant uncertainty about this spam series in the data protection/privacy community, i.e. criticism by those people who get to deal with these emails.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#223

Earlier quoted context omitted.

I don’t think it’s intended as a veiled threat of a lawsuit so much as a statement of the compliance requirements. Unfortunately it seems they misunderstood the scope which makes the it inaccurate. But if the statement was true and accurate I would just take it as a helpful reminder of the timeframe.

> But if the statement was true and accurate I would just take it as a helpful reminder of the timeframe. No. Absolutely not. A helpful reminder of the timeframe would be "the deadline for our study is ..., please try to send your response by then if you wish to be included." Quoting legal code is not at all a helpful reminder of a timeframe, but is a direct implication of legal ramifications for failure to comply.

IMHO that is the most significant part of this. Any question about the intent is clearly tipped toward legal trouble by that.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#224

I've gotten 4 of these mails to 4 of my domains (including my personal domain used just for email, and a one-page documentation site for an open source library)... 2 about CCPA and 2 about GDPR. They also gave me a lot of anxiety for no reason. Looking at the responses on Twitter, a lot of websites spent real money consulting lawyers before responding to these mails due to the thinly veiled threat of legal repercussi…

Sounds like a good place for a class action! Those legal fees ought to come out of Princeton.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#225
post #88

From the study's FAQ[0]: > Did an Institutional Review Board consider this study? > We submitted an application detailing our research methods to the Princeton University Institutional Review Board, which determined that our study does not constitute human subjects research. From the social experiment[as reported by OP's link]: > I look forward to your reply without undue delay and at most within 45 days of this emai…

If I had to guess, the wording is in the study's FAQ is carefully chosen: "an application detailing our research methods" doesn't necessarily mean "an application with the verbatim text of the emails we planned to send, including our thinly veiled legal threat at the end." Not trying to turn this thread into a generic flameware against "academic" research methods, but this whole things seems oddly reminiscent of the…

The wording of the message is one hell of a detail to leave out when detailing your research methods.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#226
There a point here which seems to have been missed. From the study's FAQ:

> The set of websites for this study is sampled from the Tranco list of popular websites and publicly available datasets of third-party tracking websites.

If that's true, then I have a lot more sympathy for the researchers: it seems they were only targeting particularly popular sites, and sites which use tracking technology. Those sites really should have have developed processes for responding to GDPR and CCPA requests, rather than just banging in some Google Analytics code without really thinking about it.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#227

There a point here which seems to have been missed. From the study's FAQ: > The set of websites for this study is sampled from the Tranco list of popular websites and publicly available datasets of third-party tracking websites. If that's true, then I have a lot more sympathy for the researchers: it seems they were only targeting particularly popular sites, and sites which use tracking technology. Those sites really…

That's because people are reporting that's incorrect. A commentator on HN got one sent to their personal domain they use only for email https://news.ycombinator.com/item?id=29600542

Re: CCPA Scam – Human subject research study conducted by Princeton University

#228
post #222

As a counterpoint here I don't consider this study or the Linux kernel study human subject research unless we define human subject research so broadly that the definition essentially becomes meaningless. As a side note I find the "outrage" about these small academic studies quite hipocritical. This is a community where a significant proportion of people work in related to ads/clicks who constantly experiment on human…

If a study is observing how human reacts to a certain situation, that's research with human subjects. The Linux study observed how maintainers react to bugs, this CCPA/GDPR request spam observed how data protection staff reacts to requests about their processes. And the backlash is not hypocritical. You're of course right that FB has also done really questionable research, but that doesn't matter here. I've also seen…

By that definition if I change the layout of my website and observe if it changes how humans change their behaviour, i.e. how and where they click it's human research. With that definition pretty much everything is human research. Well even if I track where rubbish is being transported to it is observing human behaviour and thus human research.

It remains also hypocritical. If you (not you personally but in general) are outraged by this research as unethical and you are working for companies who do any optimisation of their ads/engagement etc., you are contributing to the same (and arguably much worse) behaviour that you condem as unethical. I call complaining in others about something that you do yourself on an often much larger scale hypocrisy.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#229
post #224

I've gotten 4 of these mails to 4 of my domains (including my personal domain used just for email, and a one-page documentation site for an open source library)... 2 about CCPA and 2 about GDPR. They also gave me a lot of anxiety for no reason. Looking at the responses on Twitter, a lot of websites spent real money consulting lawyers before responding to these mails due to the thinly veiled threat of legal repercussi…

Sounds like a good place for a class action! Those legal fees ought to come out of Princeton.

Why? If that's indeed the law, then it's up to the website owner to comply. Whether it's Princeton or a private individual writing the email doesn't matter.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#230
post #222

Earlier quoted context omitted.

If a study is observing how human reacts to a certain situation, that's research with human subjects. The Linux study observed how maintainers react to bugs, this CCPA/GDPR request spam observed how data protection staff reacts to requests about their processes. And the backlash is not hypocritical. You're of course right that FB has also done really questionable research, but that doesn't matter here. I've also seen…

By that definition if I change the layout of my website and observe if it changes how humans change their behaviour, i.e. how and where they click it's human research. With that definition pretty much everything is human research. Well even if I track where rubbish is being transported to it is observing human behaviour and thus human research. It remains also hypocritical. If you (not you personally but in general)…

When you study how humans react to changes to a website, you study the behavior of the visitors to the website.

When you study where rubbish is being transported to, you study a system designed by humans.

There's an obvious difference.

Also, I think most of optimisation of ads/engagement is plain unethical. So there's no hypocrisy on my part.

Post reply on HN