Live data from Hacker News

CCPA Scam – Human subject research study conducted by Princeton University

blog.freeradical.zone

261–270 of 353 posts

Re: CCPA Scam – Human subject research study conducted by Princeton University

#261
post #133

Earlier quoted context omitted.

> had the brazen nerve to post this lie That's excessive, crosses into personal attack, and breaks the HN guidelines ( https://news.ycombinator.com/newsguidelines.html ). Please make your substantive points without stooping to that. This is not a site for stirring up internet mobs. We're trying to avoid the online callout/shaming culture here. https://hn.algolia.com/?sort=byDate&type=comment&dateRange=a...

That's fair, you're right. I should have been less inflammatory. This story struck a chord in me for... reasons. That's not meant as an excuse, I should have known better to have taken a step back before I said anything, especially something that could escalate tensions. Thank you for killing the comment. I'll be more mindful of it going forward.

Appreciated!

Re: CCPA Scam – Human subject research study conducted by Princeton University

#262

The study FAQ claims: > What happens if a website ignores an email that is part of this study? > We are not aware of any adverse consequences for a website declining to respond to an email that is part of this study. But the email sent out states: > I look forward to your reply without undue delay and at most within 45 days of this email, as required by Section 1798.130 of the California Civil Code. So the email very…

> I look forward to your reply without undue delay and at most within 45 days of this email, as required by Section 1798.130 of the California Civil Code. >So the email very clearly states that there is an adverse consequence for a failure to respond, namely a violation of the California Civil Code. I've read and re-read (and read many comments) but where is the adverse consequence stated?

> but where is the adverse consequence stated?

Here:

> as required by Section 1798.130 of the California Civil Code.

If you tell someone that they are obliged to do something as per the law, the meaning is obvious that not doing so is a violation of the law, which is an adverse consequence (the consequence being breaking the law and whatever penalties come with that).

Re: CCPA Scam – Human subject research study conducted by Princeton University

#263
post #222

Earlier quoted context omitted.

If a study is observing how human reacts to a certain situation, that's research with human subjects. The Linux study observed how maintainers react to bugs, this CCPA/GDPR request spam observed how data protection staff reacts to requests about their processes. And the backlash is not hypocritical. You're of course right that FB has also done really questionable research, but that doesn't matter here. I've also seen…

By that definition if I change the layout of my website and observe if it changes how humans change their behaviour, i.e. how and where they click it's human research. With that definition pretty much everything is human research. Well even if I track where rubbish is being transported to it is observing human behaviour and thus human research. It remains also hypocritical. If you (not you personally but in general)…

If you’ll recall, Facebook did take a lot of flack for changing newsfeed content for users to see what behavioral changes it would induce.

https://www.theguardian.com/technology/2014/jul/02/facebook-...

Re: CCPA Scam – Human subject research study conducted by Princeton University

#264
post #100

It is interesting in the study web page ( https://privacystudy.cs.princeton.edu/ ) that they consistently mention contacting "websites" instead of "people." As if a website is some autonomous thing that can communicate with a researcher. I wouldn't be sleeping well if I were involved in this study. There is no way an IRB could determine that this is not human subjects research if you're emailing people and asking the…

This is incorrect. It's only human subjects research if the researcher is obtaining data about a human. This is the "about whom" requirement. A classic example is calling a business and asking someone about the products and prices they offer. That's not human subjects research.

If you say "I am a researcher studying X, can you please answer the following questions" then you might be studying a "what", depending on the specific questions.

When you lie about who you are, what your purposes are, and use scary legal language in an attempt to elicit a response, that is absolutely human research. You may be able do those things ethically as scientist but you absolutely need IRB review becausr it is definitely human research.

My guess is that the IRB in this case was not informed of the deceptive nature of some of the emails as lieing is absolutely a red flag that you are doing human research and not just information gathering. Indeed, evaluating such lies for potential harm is an important part of why we have IRBs for psychological and sociological research.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#265

Earlier quoted context omitted.

You realize that the internal regulation is wrong, right? Like the semantic distinction doesnt matter because nobody gives a fuck about Princeton’s organizational policy.

This is not Princeton's organizational policy or internal regulation, this is the regulatory definition of human subjects research as set by the government. Its semantic interpretation and the "about whom" requirement is exactly how you go about making a determination about whether your research is human subjects research.

In that case I care, and would say that’s an inadequate way to prevent trolling by researchers

Re: CCPA Scam – Human subject research study conducted by Princeton University

#266
post #73

I'm the person who wrote that blog post. I got an email from a fake person in France who asked several questions about my small social media site's CCPA compliance, then ended the letter with: > I look forward to your reply without undue delay and at most within 45 days of this email, as required by Section 1798.130 of the California Civil Code. I thought I was about to be sued by someone who was the equivalent of a…

I've met Ross during my time at Princeton and he is a really genuine person, he is not trying to ruin anyone's life. This incident is the result of an uncharacteristic blind spot in empathy: a mistake. I also have experience with the Princeton IRB on similar topics. The reality is that Princeton's IRB, and IRBs in general, are not equipped to deal with this sort of online research. IRBs were created as a reaction to…

I think it’s kinda funny how sending vaguely threading emails (suggesting violation of statutes) sailed right through an IRB, but Scott Alexander got the third degree for giving patients a survey. Description:

>> When we got patients, I would give them the bipolar screening exam and record the results. Then Dr. W. would conduct a full clinical interview and formally assess them. We’d compare notes and see how often the screening test results matched Dr. W’s expert diagnosis. We usually got about twenty new patients a week; if half of them were willing and able to join our study, we should be able to gather about a hundred data points over the next three months.

https://slatestarcodex.com/2017/08/29/my-irb-nightmare/

Re: CCPA Scam – Human subject research study conducted by Princeton University

#267
post #132

Earlier quoted context omitted.

Thank you for making this point. I didn't articulate it, but this is part of why I felt I had to say something.

I hope this fellow Ross does not become suicidal or otherwise depressed when he sees the weight of the internet coming down on him for this faux pas. Ross, none of this wil matter in a year. Or 5 years.

No post body was provided.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#268

Let me help: We’re some students from Princeton trying to understand how businesses are responding to CCPA and GRPR requests. Could you help us with our study? How would you answer these questions? … The point is disclosure. It’s unethical to do otherwise, especially given that is about the use of data. I’d love for there to be more data published about the impacts of these policies, but please don’t use the tactics…

It is likely that quite a few people would lie if they knew they were going to be observed/studied or reported on. However, I'm sure they could've made the actual email less threatening and more friendly/ethical without revealing research intent. (or the intent to research this specfic aspect)

Yes, there are reasons that studies sometimes lie to their participants. These lies are something that has to be justified to an IRB and the study has to be designed to carefully minimize harm. Lieing to unwilling particiants only raises that bar. In this case, the bare minimum ethical way to conduct this study would have been a careful manual review of every unwilling participant that was going to be recieving deceptive communication to ensure they actually fell under the laws in question.

The compound of deception, legal intimidation, and scatter shot automated selection of unwilling participants is a particularly egregious ethical failure.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#269
post #153

Earlier quoted context omitted.

Who is the subject of the emails sent to personal domains?

Not sure I follow your question. An example of something that's not human subjects research would be emailing people who have websites and asking about their privacy policy. An example of something that is human subjects research would be emailing people who have websites and asking what inspired them to start a website. I realize that may seem like a subtle difference, but it's an important distinction from an IRB p…

This feels like it creates a massive ethical loophole.

There are different ways to gather pure factual information, too. In particular where the factual information you are trying to gather is information about the extent to which someone complies with the law, there's some real danger in being able to fall back on a 'we're just gathering facts' defense.

Take this example: "a researcher calls the director of a shelter for battered women and asks her for the average length of stay of the women who use the shelter"

What are the regulatory requirements shelters need to comply with? Do any of them concern length of stay? Are there any liabilities a shelter might expose itself to if it were known that it had women staying there for longer than a certain period? Or individual liabilities if it were discovered that they restrict how long people can stay? Would they potentially expose any of their clients to danger if the length of stay information were revealed to a particular person?

If so, then providing the answer to that question is something the shelter needs to give some thought to. And the manner of their response might be different if that question were posed to them by:

- a woman enquiring about staying at the shelter

- a government inspector

- their landlord

- a random man phoning them

- a journalist

- an academic researcher identifying themselves and the nature of the study they are conducting

So if as an academic you ask a 'just gathering information' question, but conceal your identity, don't share whether the information will be aggregated or identifiable, and don't explain what you're gathering the information for, you are not just collecting a fact - you are forcing the person you are asking to make an evaluation of what information to provide; in other words, you are creating a human behavior, and what you are studying will be the outcome of that.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#270
post #222

Earlier quoted context omitted.

If a study is observing how human reacts to a certain situation, that's research with human subjects. The Linux study observed how maintainers react to bugs, this CCPA/GDPR request spam observed how data protection staff reacts to requests about their processes. And the backlash is not hypocritical. You're of course right that FB has also done really questionable research, but that doesn't matter here. I've also seen…

By that definition if I change the layout of my website and observe if it changes how humans change their behaviour, i.e. how and where they click it's human research. With that definition pretty much everything is human research. Well even if I track where rubbish is being transported to it is observing human behaviour and thus human research. It remains also hypocritical. If you (not you personally but in general)…

> I call complaining in others about something that you do yourself on an often much larger scale hypocrisy.

The assumption that everyone complaining about this works in adtech or even does A/B testing is ridiculous. HN has a very strong contingent of people who are antagonistic to that entire field so making such a generalization is absolutely false.

I would point out that A/B testing minor changes without consent is a little creepy, deceiving your users in the process (by say changing pricing measure on them) makes it far more creepy. If you add bogus legal intimidation (or other language designed to elicit a strong emotional response) to that, it becomes creepy on a whole different scale.

Post reply on HN