Live data from Hacker News

CCPA Scam – Human subject research study conducted by Princeton University

blog.freeradical.zone

271–280 of 353 posts

Re: CCPA Scam – Human subject research study conducted by Princeton University

#271
post #252

As a counterpoint here I don't consider this study or the Linux kernel study human subject research unless we define human subject research so broadly that the definition essentially becomes meaningless. As a side note I find the "outrage" about these small academic studies quite hipocritical. This is a community where a significant proportion of people work in related to ads/clicks who constantly experiment on human…

Wait. Did you really mean to tag anyone simply _employed_ by Facebook as hypocritical? As if being employed by an entity immediately connotes acquiescence to whatever unethical or immoral behavior that entity engages in? Isn't that "guilt by association" taken a bit far? It's as if you were to call Google pro Sanders because a significant amount of money was donated to the Senator's campaign by non-executive Google e…

That is a ridiculous comparison and absolutely not what guilt by association is.

If you work for a political campaign before the candidate announces their support for killing puppies, holding you responsible for that position is "guilt by association", but if you go to work for that same candidate after the announcement, it is no longer guilt by association, you have made a deliberate choice to support someone who wants to kill puppies and now share some responsibility.

Much of Facebook's anti-privacy behavior is widely documented. Going to work for Facebook absolutely makes you a little responsible for that behavior.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#272
post #224

Earlier quoted context omitted.

Sounds like a good place for a class action! Those legal fees ought to come out of Princeton.

Why? If that's indeed the law, then it's up to the website owner to comply. Whether it's Princeton or a private individual writing the email doesn't matter.

> Why?

No costs would have been incurred without Princeton asking a very scary question.

Additionally, by not disclosing that the question was research, they also skewed the results if they were looking to see what prevailing attitudes and practices actually are.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#273
post #245

I don't understand the outrage. Even knowing the context, the email is polite, to the point, tells the website administrator exactly what they need to do (something they are already legally required to do), and gives them ample time to do so.

I’m not legally required to reply in any way, although the email strongly implied that I am. This looked a lot like the kind of emails you’d get from someone gathering information before they decide whether to file a lawsuit against you.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#274

There a point here which seems to have been missed. From the study's FAQ: > The set of websites for this study is sampled from the Tranco list of popular websites and publicly available datasets of third-party tracking websites. If that's true, then I have a lot more sympathy for the researchers: it seems they were only targeting particularly popular sites, and sites which use tracking technology. Those sites really…

I looked up my own site — the one that got this whole mess started — and I hover around number 350,000. I was utterly shocked given that I have a few thousand users, and many fewer active users.

I don’t use GA, or any other third-party trackers, on any of my sites. Given that Tranco doesn’t have access to my web logs or the little Matomo setup that I self-host, I’m not sure how they claim to be analyzing my traffic in the first place.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#275

Earlier quoted context omitted.

Because receiving a letter citing chapter & verse of the legal code is generally never the precursor to a nice friendly chat. The actual-not-fake-researcher (instead of fictional people) could have sent a nice friendly request saying, "I'm a PhD candidate working on public policy in the tech sector. Could you please answer the following questions regarding your process of CCPA compliance, if applicable"

Legal threats are a common occurance nowadays though. I get calls weekly saying a warrant had been issued for my arrest or that my "SSN is about to be revoked". The email also clearly says they are not sending a request at this time and it seems nicely written to me. I guess I don't get why this is on HN and everyone is so livid about it.

> . I get calls weekly saying a warrant had been issued for my arrest or that my "SSN is about to be revoked".

And those are all illegal. If the telecoms weren't incompetent and protected from liability, you could find the people who did those things and either sue them or file charges.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#277
Without getting into the question of whether this study involved human subject research, I find a lot of the anxiety and paranoia unwarranted.

Companies to which these laws apply should already have a process in place to deal with subject access requests. Complying with relevant laws is just part of doing business.

All the other site owners could have figured out with a bit of googling that the laws don't apply to them—there is plenty of guidance available.

I can only speak for the GDPR here, but had the requests been real and valid, the worst outcome would have been a regulator telling you to comply with it. Data protection authorities are more interested in helping companies get into compliance than punishing small businesses for minor infractions. If you look at past decisions, it usually takes serious and/or systematic violations to get fined.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#278

Earlier quoted context omitted.

Because he said the response was overwhelming positive at the same time that he is dealing with anxious & irate recipients of his messages.

It's possible that he's only seeing positive responses, because entities who had a negative reaction are either laying low or hiring lawyers.

That tweet was sent out around and the time the project website was edited to immediately indicate the end of the study (instead of continuing it to the spring), and adding a FAQ that tries to dispel concerns about IRB approval and email address harvesting.

That makes it seem unlikely he was unaware of the negative responses to his study.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#279
post #187

Earlier quoted context omitted.

Not sure I follow your question. An example of something that's not human subjects research would be emailing people who have websites and asking about their privacy policy. An example of something that is human subjects research would be emailing people who have websites and asking what inspired them to start a website. I realize that may seem like a subtle difference, but it's an important distinction from an IRB p…

You misunderstand the research in question. To quote from the researchers website > When the system has even higher confidence, it sends up to several emails that simulate real user inquiries about GDPR or CCPA processes. This research method is analogous to the audit and “secret shopper” methods that are common in academic research, enabling realistic evaluation of business practices. Simulating user inquiries also…

He understands perfectly well. What's relevant is whether the response is a property of the individual or the organization, and it's arguable, and controversial, but you'll find a lot of studies performed using this technique that were not considered human subjects research.

As to whether it's deceptive and threatening (the latter of which I find pretty hyperbolic, this is a pretty boilerplate request), that has no relevance as to whether it's human subjects research.

Maybe they should have limited the scope to larger organizations.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#280

Earlier quoted context omitted.

> I look forward to your reply without undue delay and at most within 45 days of this email, as required by Section 1798.130 of the California Civil Code. >So the email very clearly states that there is an adverse consequence for a failure to respond, namely a violation of the California Civil Code. I've read and re-read (and read many comments) but where is the adverse consequence stated?

> but where is the adverse consequence stated? Here: > as required by Section 1798.130 of the California Civil Code. If you tell someone that they are obliged to do something as per the law, the meaning is obvious that not doing so is a violation of the law, which is an adverse consequence (the consequence being breaking the law and whatever penalties come with that).

[deleted]
Post reply on HN