Live data from Hacker News

CCPA Scam – Human subject research study conducted by Princeton University

blog.freeradical.zone

291–300 of 353 posts

Re: CCPA Scam – Human subject research study conducted by Princeton University

#291

There a point here which seems to have been missed. From the study's FAQ: > The set of websites for this study is sampled from the Tranco list of popular websites and publicly available datasets of third-party tracking websites. If that's true, then I have a lot more sympathy for the researchers: it seems they were only targeting particularly popular sites, and sites which use tracking technology. Those sites really…

I looked up my own site — the one that got this whole mess started — and I hover around number 350,000. I was utterly shocked given that I have a few thousand users, and many fewer active users. I don’t use GA, or any other third-party trackers, on any of my sites. Given that Tranco doesn’t have access to my web logs or the little Matomo setup that I self-host, I’m not sure how they claim to be analyzing my traffic i…

Thanks for that -- seems like you're a pretty good counterexample to my hypothesis. Totally agree that sending these emails to site #350,000 on the Tranco list isn't justifiable.

> I’m not sure how they claim to be analyzing my traffic in the first place

They wouldn't need to analyze your traffic to find out if you were using tracking technologies, they would just need to visit your site and examine what they were served. Companies like BuiltWith and Wappalyzer offer this kind of technology survey as a service.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#292

Earlier quoted context omitted.

I looked up my own site — the one that got this whole mess started — and I hover around number 350,000. I was utterly shocked given that I have a few thousand users, and many fewer active users. I don’t use GA, or any other third-party trackers, on any of my sites. Given that Tranco doesn’t have access to my web logs or the little Matomo setup that I self-host, I’m not sure how they claim to be analyzing my traffic i…

Thanks for that -- seems like you're a pretty good counterexample to my hypothesis. Totally agree that sending these emails to site #350,000 on the Tranco list isn't justifiable. > I’m not sure how they claim to be analyzing my traffic in the first place They wouldn't need to analyze your traffic to find out if you were using tracking technologies, they would just need to visit your site and examine what they were se…

I mean, I'm not sure how Tranco would get those traffic numbers, since I'm not sharing traffic data with anyone. All of my analytics are within my own system.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#293

Earlier quoted context omitted.

Thanks for that -- seems like you're a pretty good counterexample to my hypothesis. Totally agree that sending these emails to site #350,000 on the Tranco list isn't justifiable. > I’m not sure how they claim to be analyzing my traffic in the first place They wouldn't need to analyze your traffic to find out if you were using tracking technologies, they would just need to visit your site and examine what they were se…

I mean, I'm not sure how Tranco would get those traffic numbers, since I'm not sharing traffic data with anyone. All of my analytics are within my own system.

Tranco is a merge of the Alexa, Cisco Umbrella and Majestic lists. Alexa data is gathered from a browser extension [1], Cisco Umbrella is passive DNS [2]. Not totally sure about Majestic but it looks like it might be crawling of some kind, then counting links.

[1] https://kinsta.com/blog/alexa-rank/#how-is-alexa-rank-calcul...

[2] https://umbrella-static.s3-us-west-1.amazonaws.com/index.htm...

Re: CCPA Scam – Human subject research study conducted by Princeton University

#294
post #88

From the study's FAQ[0]: > Did an Institutional Review Board consider this study? > We submitted an application detailing our research methods to the Princeton University Institutional Review Board, which determined that our study does not constitute human subjects research. From the social experiment[as reported by OP's link]: > I look forward to your reply without undue delay and at most within 45 days of this emai…

If I had to guess, the wording is in the study's FAQ is carefully chosen: "an application detailing our research methods" doesn't necessarily mean "an application with the verbatim text of the emails we planned to send, including our thinly veiled legal threat at the end." Not trying to turn this thread into a generic flameware against "academic" research methods, but this whole things seems oddly reminiscent of the…

> Not trying to turn this thread into a generic flameware against "academic" research methods, but this whole things seems oddly reminiscent of the "let's try to insert malicious code into Linux" fiasco [1]. I'm conceptually fine with generic passive tools like web crawlers to conduct research, but since when did the internet become a place where nonconsensual interactive research became fine?

In a very real sense, every landing page A/B test is nonconsensual interactive research.

Or at least, if there is line between them, however blurry, I can't find it.

I am skeptical of the idea that such a line should be drawn according to who is doing the experimentation, I don't think that a manipulative act becomes okay just because it is being done by an academic for research purposes, nor do I think that it becomes okay just because it is being done by a layman with a profit motive (or a political one, for that matter).

Re: CCPA Scam – Human subject research study conducted by Princeton University

#295
post #235

The problem here seems to be that governments created laws that allow everyone to scare the shit out of people who dare to build something and put it into the public - without having to leave the comfort of their chair (pun intended). Data privacy is important. Not feeling the urge to hire a lawyer just to publish a small blog is even more important.

Even more fundamental is the fact that defending your innocence is expensive. A system that lightens your pockets when a bad actor invokes your name and will never compensate you for your loss afterwards is a bad system.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#296
post #203

I am surprised by the reactions here. I did not receive that e-mail but I receive all sort of weird inquiries for my websites, (at least 2 or 3 per day). I don't understand why people are so mad about it or even panicking.

Mentioning a specific section of a law is threatening to hold them to the letter of that law. What happens if they don't follow the letter of that law? The insinuation is legal action will follow.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#297
post #257
post #233

Earlier quoted context omitted.

> I wouldn't be sleeping well if I were involved in this study. There is no way an IRB could determine that this is not human subjects research if you're emailing people and asking them anything. Do you have a citation for this? What I'm seeing from random Googling is that you have to be obtaining information about the person for it to count. If I were researching, say, price trends in some commodity and I called up…

Here are questions sent to individuals in the study: Would you process a CCPA data access request from me even though I am not a resident of California? Do you process CCPA data access requests via email, a website, or telephone? If via a website, what is the URL I should go to? What personal information do I have to submit for you to verify and process a CCPA data access request? What information do you provide in r…

> I can accept that some people don't see the information requested as being "about whom" and therefore is not human subjects research. But the fact that people who have received this email have panicked indicates that the recipients, at least, felt that the questions were more than merely recording impersonal data about their websites.

I guess the distinction is whether you see a website as an organization, even when that 'organization' is as small as a sole proprietorship or DBA, or even a personal site or blog.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#298
post #222

Earlier quoted context omitted.

If a study is observing how human reacts to a certain situation, that's research with human subjects. The Linux study observed how maintainers react to bugs, this CCPA/GDPR request spam observed how data protection staff reacts to requests about their processes. And the backlash is not hypocritical. You're of course right that FB has also done really questionable research, but that doesn't matter here. I've also seen…

By that definition if I change the layout of my website and observe if it changes how humans change their behaviour, i.e. how and where they click it's human research. With that definition pretty much everything is human research. Well even if I track where rubbish is being transported to it is observing human behaviour and thus human research. It remains also hypocritical. If you (not you personally but in general)…

The nub there is not the definition of "involving human subjects", but the definition of "research".

By the relevant federal regulations (https://irb.ufl.edu/index/humanrsch.html)

================================================================

(l) Research means a systematic investigation, including research development, testing, and evaluation, designed to develop or contribute to generalizable knowledge. Activities that meet this definition constitute research for purposes of this policy, whether or not they are conducted or supported under a program that is considered research for other purposes. For example, some demonstration and service programs may include research activities.

================================================================

This is a good overview: https://irb.ufl.edu/index/humanrsch.html

Re: CCPA Scam – Human subject research study conducted by Princeton University

#299

Seems like a career academic with no experience in the real world playing around like this is some kind of game. I'm sure they meant no harm, because they don't consider anyone "participating" to be anything more than a potential subject in their agenda to get a good review on their paper. That letter and their social media posts are nothing more than a facade to maximize return with no consideration of impact. Total…

Mayer has a JD and is licensed in CA (I don't know about NJ), has worked for at least one US Senate office, and has been so involved in actual practical privacy work that ad companies pressured the president of Stanford to expel him for his legitimate work on DNT.

The person who designed and ran this study is not Mayer. Mayer runs the lab, but this is a subordinate's baby.

From the study's website: "Please contact the lead researcher for this study, Ross Teixeira (rapt@princeton.edu), if you have any questions, believe you received an email in error, or would like to opt out of any future communication related to the study. The additional members of the study team are Professor Jonathan Mayer at the Princeton University Center for Information Technology Policy, who is the Principal Investigator, and Professor Gunes Acar at the Radboud University Digital Security Group."

Re: CCPA Scam – Human subject research study conducted by Princeton University

#300

Earlier quoted context omitted.

* When you do something to people to see how they act, it's a human experiment. The purpose of this study was officially "to understand how websites would respond to real users" * The participants / subjects of the study are people, not "websites" as the study claims. Websites don't read and respond to emails, people do. * The participants of this study were selected without their consent * The participants were not…

> When you do something to people to see how they act, it's a human experiment. All AB testing is a human experiment?

It involves human subjects, it is probably not "research" in the meaning of IRB rules.
Post reply on HN