Live data from Hacker News

I Got Access to My Secret Consumer Score

nytimes.com

321–330 of 341 posts

Re: I Got Access to My Secret Consumer Score

#321

Earlier quoted context omitted.

I suppose it was somewhere between when you said that government shouldn't regulate or try to fix the problem until they have a better understanding of it ( "this is a complex issue and the "LETS REGULATE IT" feels premature given how complex and subtle the issue is...We need to understand the full scope of the problem, rather than try to fix what isn't fully grasped" ) and that you don't think the government is capa…

Are you open to the possibility that you treated me overly harshly, and that I've never actually taken the position you seem to badly want me to have taken? Or is that beyond the pale, and this is exclusively my fault? To try and contribute to this conversation a small amount, it makes the most sense to me to establish a Professional Engineer like system for the software industry. I don't know all of the details abou…

I'm very open to the possibility that you are just sealioning and throwing around accusations of being "toxic" while in fact being very toxic and generally not open to discussion yourself.

Professional engineers are generally not liable unless they have substantially neglected the standard of practice, so no, a company using tracking data would not result in personal liability for that engineer (unless they, say, got hacked due to personal negligence on his part).

No professional engineer would ever agree to personal liability for all actions of a company. Only the things they themselves have signed off on. You will never be able to sue an engineer because a company used your personal data for tracking. Period. The professional engineer doesn't have to sign off that the visitor's lounge is hypoallergenic.

Furthermore, who exactly do you imagine regulates this professional engineer system? Who makes sure that everybody on the internet is appropriately licensed before "a spam bot calls you"? Where exactly does that responsibility lay in this system? Does a phone company have to make sure that a client for each phone number they assign is engaging a professional engineer before placing a call? What if it's Google and everything is just SIP calls from various IPs? Does Google have to make sure that everyone assigned an IP has signoff from a professional engineer? What if I just pick up a phone and dial a person? Who has the liability if I then voice an unsolicited commercial solicitation? What happens if I send a packet that wasn't approved by the professional engineer that Google had sign off on my computer system?

You've outlined a system that is hilariously unsustainable and ill-thought-out, where nobody is allowed to do anything without a Professional Nanny literally watching over their shoulder as they place a phone call or send packets over the internet. But you also think that Professional Nannies will definitely agree to personal liabilities for whatever their clients do.

As if the Professional Nannies wouldn't be just as effective here as Credit Rating agencies were in 2007. Sure, nervously watch the phone all you want - if you don't sign off on it, we'll find someone who will. And yes, you'll be personally liable too, since individuals lack the negotiating power that firms (like Credit Rating agencies) do.

Here's a maxim for you: the broader the need for these professional engineers, the less authority and independence they will have. Professional Engineers actually only work because they only have to sign off on complete negligence - life or death stuff, their buildings falling down. If they have to sign off that the visitor's lounge is hypoallergenic the system falls apart.

But I understand your religion here, the Free Market will undoubtedly provide. Nothing bad can ever happen under a Free Market, because people would just buy from someone else. We just need to make sure that everybody has personal liability and the NAP will guarantee that no problems ever exist.

I certainly don't think I was wrong to pin you as a Libertarian right from the first comment. Regardless of whether you claim to deny the label.

Re: I Got Access to My Secret Consumer Score

#322

There is a scene at the beginning of the movie Brazil [1] where a literal bug falls into a tele-type, causes an error that starts a chain reaction that frames the events of the movie. The bug is a metaphor in the movie, just some nice visual story-telling to indicate how errors in automated processes can have unintended consequences. I honestly fear that entire lives will be ruined by AI systems mis-analyzing some da…

But is this really about AI? Almost all aspects of our lives are already controlled by the enormously complex soulless machines of bureaucracy we call firms and governments. Is there any essential difference between a computer bug and a clerical error? If anything, I would assume the former is easier to fix.

The whole purpose of humans inside bureaucracy is to provide humanity, to subvert/override the systems when that makes sense. If they don't do that, and instead take wage as a motorized application-stanping arm, then they are failing horribly at their job.

Re: I Got Access to My Secret Consumer Score

#324
post #96

Earlier quoted context omitted.

I suspect we as a society need new legislation to deal with these sort of issues. Before, much of this was incredibly difficult to impossible so legislation and regulation was entirely avoidable and relatively rare occurence could be dealt with on a case-by-case basis. At this point, technology has enabled this sort of behavior at mass scale, now revealing far more personal and useful information about individuals. A…

>will our representatives actually give teeth to real data protection legislation No. The majority of them don't even understand what data is being collected, how it can be used, or the technology behind any of it. Until the people in office change, the idea that our representatives can or will protect us is toothless and spineless.

Yes, because that's what they are - representatives. Of a general public.

The only way to make these chameleons (pretend to) care about an issue is to make the general public (aka voters, source of their wellbeing) care about the issue.

Re: I Got Access to My Secret Consumer Score

#325
post #321

Earlier quoted context omitted.

Are you open to the possibility that you treated me overly harshly, and that I've never actually taken the position you seem to badly want me to have taken? Or is that beyond the pale, and this is exclusively my fault? To try and contribute to this conversation a small amount, it makes the most sense to me to establish a Professional Engineer like system for the software industry. I don't know all of the details abou…

I'm very open to the possibility that you are just sealioning and throwing around accusations of being "toxic" while in fact being very toxic and generally not open to discussion yourself. Professional engineers are generally not liable unless they have substantially neglected the standard of practice, so no, a company using tracking data would not result in personal liability for that engineer (unless they, say, got…

I didn't read this either, for the same reason I didn't read your prior comment and won't read any of your other comments; you're clearly upset and aren't contributing to this discussion in a constructive way with your hateful, aggressive tone. You're not here to seek knowledge, you're here to bludgeon others (me, specifically).

I can happily engage with folks who are here and actually want to have a discussion and that doesn't involve you whatsoever.

Re: I Got Access to My Secret Consumer Score

#326
How to get your data

There are many companies in the business of scoring consumers. The challenge is to identify them. Once you do, the instructions on getting your data will probably be buried in their privacy policies. Ctrl-F “request” is a good way to find it. Most of these companies will also require you to send a photo of your driver’s license to verify your identity. Here are five that say they’ll share the data they have on you.

Sift, which determines consumer trustworthiness, asks you to email privacy@sift.com. You’ll then have to fill out a Google form.

Zeta Global, which identifies people with a lot of money to spend, lets you request your data via an online form.

Retail Equation, which helps companies such as Best Buy and Sephora decide whether to accept or reject a product return, will send you a report if you email returnactivityreport@theretailequation.com.

Riskified, which develops fraud scores, will tell you what data it has gathered on your possible crookedness if you contact privacy@riskified.com.

Kustomer, a database company that provides what it calls “unprecedented insight into a customer’s past experiences and current sentiment,” tells people to email privacy@kustomer.com.

Just because the companies say they’ll provide your data doesn’t mean they actually will.

Re: I Got Access to My Secret Consumer Score

#327

There is a scene at the beginning of the movie Brazil [1] where a literal bug falls into a tele-type, causes an error that starts a chain reaction that frames the events of the movie. The bug is a metaphor in the movie, just some nice visual story-telling to indicate how errors in automated processes can have unintended consequences. I honestly fear that entire lives will be ruined by AI systems mis-analyzing some da…

"The chains of tormented mankind are made out of red tape" - If Kafka were to live today, he'd write about AI bureaucracy.

Re: I Got Access to My Secret Consumer Score

#328
post #63
post #26

I’m curious what sort of due diligence these companies must do to authenticate you as a person prior to satisfying an information retrieval request. Given that the exchange is entirely digital, it seems plausible that there are bad actors who would pose as someone else to gain access to their personal information. What sort of liability does one of these data controllers bear when they fail to properly authenticate a…

I've sent a couple of GDPR Subject Access Requests out of sheer curiosity. The answer is - in my experience - 'it varies'. One requested a copy of a photo ID or passport and were happy to accept a partly redacted copy with 'FOR PROOF OF ID ONLY - (company), (date)' over-typed on the scan in red. Another requested I email them from an email address they had in their records, or log in to change it and resubmit the req…

>Another requested I email them from an email address they had in their records

so our email providers can get all this data? They can DKIM sign such a mail and simply never have the relevant emails show up in your emails.

Re: I Got Access to My Secret Consumer Score

#329

Earlier quoted context omitted.

>My goal was to make certain that if it leaked, the overtyped expiry date should make it useless after a certain point, and the company name should make any company other than that one question the source. >As a side effect, it'd also clearly identify the source of any leaks - but that wasn't my primary goal. Wouldn't a malicious actor just add block text over your text saying "only for identity verification for Some…

I don't know how GP did it, but I would have made the text translucent and make sure it covered the entire image so that there's no easy way to obfuscated the watermark without also obfuscating the license itself.

translucent text is nearly trivial to remove

Re: I Got Access to My Secret Consumer Score

#330

There is a scene at the beginning of the movie Brazil [1] where a literal bug falls into a tele-type, causes an error that starts a chain reaction that frames the events of the movie. The bug is a metaphor in the movie, just some nice visual story-telling to indicate how errors in automated processes can have unintended consequences. I honestly fear that entire lives will be ruined by AI systems mis-analyzing some da…

My go-to example of this scenario: https://splinternews.com/how-an-internet-mapping-glitch-turn...
Post reply on HN