Live data from Hacker News

CCPA Scam – Human subject research study conducted by Princeton University

blog.freeradical.zone

341–350 of 353 posts

Re: CCPA Scam – Human subject research study conducted by Princeton University

#341
post #224

Earlier quoted context omitted.

Sounds like a good place for a class action! Those legal fees ought to come out of Princeton.

Why? If that's indeed the law, then it's up to the website owner to comply. Whether it's Princeton or a private individual writing the email doesn't matter.

Because they sent me three emails and I don't even provide a service for the domains they mentioned.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#342

Earlier quoted context omitted.

If I had to guess, the wording is in the study's FAQ is carefully chosen: "an application detailing our research methods" doesn't necessarily mean "an application with the verbatim text of the emails we planned to send, including our thinly veiled legal threat at the end." Not trying to turn this thread into a generic flameware against "academic" research methods, but this whole things seems oddly reminiscent of the…

> Not trying to turn this thread into a generic flameware against "academic" research methods, but this whole things seems oddly reminiscent of the "let's try to insert malicious code into Linux" fiasco [1]. I'm conceptually fine with generic passive tools like web crawlers to conduct research, but since when did the internet become a place where nonconsensual interactive research became fine? In a very real sense, e…

If you consider A/B test nonconsensual research, then you can also consider localized versions of the sites as A/B tests. Or even serving differnet content for mobile and desktop.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#343
On the flip side they sent me an email that wasn't lying, so they could have done this for everyone:

priv...@princetonprivacystudy.org Tue, Dec 14, 12:25 AM (5 days ago) to me

To Whom It May Concern,

We are researchers at Princeton University conducting a study of how websites are implementing the EU and UK General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). We are reaching out to you because this email address is provided as a contact on the website seifried.org.

Your website may be required to implement one or both of GDPR and CCPA, and we would appreciate if you would answer a few brief questions about your privacy practices.

1) Does seifried.org implement GDPR or CCPA? If not, could you please explain why? If you are uncertain about whether seifried.org is required to implement these laws or answer questions like ours, we have included informative resources at the end of this email.

2) If you implement GDPR or CCPA, do you process data access requests from individuals who are not residents of the EU or UK (for GDPR) or who are not residents of California (for CCPA)?

3) If you implement GDPR or CCPA, do you process data access requests via email, a website, or telephone? If via a website, what is the URL?

4) If you implement GDPR or CCPA, what personal information must a user submit for you to verify and process a data access request?

5) If you implement GDPR or CCPA, what personal information do you provide in response to a data access request?

Thank you in advance for your answers to these questions. If there is a better contact for questions about privacy practices on seifried.org, I kindly ask that you forward my request to them.

Sincerely, Ross Teixeira

Re: CCPA Scam – Human subject research study conducted by Princeton University

#344

Earlier quoted context omitted.

I hope this fellow Ross does not become suicidal or otherwise depressed when he sees the weight of the internet coming down on him for this faux pas. Ross, none of this wil matter in a year. Or 5 years.

Quoted post unavailable.

Sorry, but this sort of attack is not ok on HN and I've banned the account. It's entirely possible to post substantive critique without stooping to this—as many HN users have demonstrated in this very thread.

https://news.ycombinator.com/newsguidelines.html

Re: CCPA Scam – Human subject research study conducted by Princeton University

#345

Earlier quoted context omitted.

Please explain why this is unethical. The worst case is that you’re simply subject to the law. Presumably you’re abiding by the law. edit: I'm playing devil's advocate. I think the law sucks, the study is weird, and I empathize directly with the blog author. That said, downvoting to 'disagree' without explaining your reasoning is below the grade of this fine institution.

From the perspective of someone not living in the US, how on earth would one be expected to know what "the law" in California is?

when they invented the legal principle of "ignorance of the law is no defence", most common people were illiterate. That didn't stop them from making people guilty for committing crimes they didn't know were crimes.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#346
post #152

Earlier quoted context omitted.

The key phrase is: > a living individual about whom an investigator (whether professional or student) conducting research: The mere fact that you're interacting with a human doesn't trigger it. If you're associated with a university, I'd encourage you to reach out to your IRB and ask them. The fact that the researchers in this case specifically were told by their IRB that it wasn't human subject research should be a…

This is actually the most technically correct answer on this page. Everyone is going by their own opinions about definitions of what constitutes human subjects research, rather than starting from the primary sources. IRB guidelines are dictated by the federal government "common rule", a common standard adopted by all institutions that receive federal funding. "about whom" is a key criteria from the federal government…

Splitting hairs like this may be a useful endeavor in a court of law (or at least ethics committee), but it sidetracks the "real" question: should a university fund research that essentially sends phishing emails en masse and entraps people into admitting they breached the law, incurring legal costs, and/or causing panic among the recipients?

Re: CCPA Scam – Human subject research study conducted by Princeton University

#347
post #313

Earlier quoted context omitted.

> Not trying to turn this thread into a generic flameware against "academic" research methods, but this whole things seems oddly reminiscent of the "let's try to insert malicious code into Linux" fiasco [1]. I'm conceptually fine with generic passive tools like web crawlers to conduct research, but since when did the internet become a place where nonconsensual interactive research became fine? In a very real sense, e…

> In a very real sense, every landing page A/B test is nonconsensual interactive research. I think that lots of benign testing is only this a bit pedantically, at least for the general "two variants of a page" type of thing, context matters of course. "I want to use this service" -> "OK, here is the page for that service" is a certain interaction where, granted, you might be presented with a different kind of look, b…

To play devils advocate - is that really all that different from much other online communication? A significant chunk of the web runs on advertisements; and those are in essence tons of little influence games, often with little regard for the truth or honesty: the aim is to manipulate by whatever means you can get away with.

A lot of forums have issues with spam and sock puppets, and not all of that is obvious nor all of it honest.

Even many large, curated news sites have now succumbed to the benefits of deceiving their audience; whether through outright misrepresentation, or merely selective ommission, or merely editorial emphasis that prioritizes their agenda over their readers' understanding of the material.

Attempts to course correct here run into vast vested interests (when it comes to e.g. advertising or biases media), and also against the implementation of free speech protections in the US (and many other places), and more subtly, against public opinion on free speech, which refuses to countenance any attempts at reform.

In essence, we prioritize the right to deceive over the right not to be deceived - in all but the most extreme of circumstances.

Chalk one up for team deception - while this surely isn't a good trend, I can't see how this research is even close to some of the more problematic stuff floating around.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#348

Earlier quoted context omitted.

It's obviously implying a threat if you're at all familiar with the legal sphere. Passive-aggressive language, sure, but still not exactly inviting the recipient to a picnic, and passive-aggressive language doesn't get you off the hook. Related, doesn't matter if it is completely without merit and could never succeed. This entire story and thread is just something else. Talk about failing to meet even baseline ethica…

> It's obviously implying a threat if you're at all familiar with the legal sphere. And if you're not a lawyer it's just a very normal message of someone trying to get answers and have their privacy rights respected. I've both sent and received many messages like this one over the years (CNIL requests) and there's nothing frightening about it. > Talk about failing to meet even baseline ethical standards. This study c…

You're wrong. The reaction to the email and apology from Princeton is proof of that, but there are also very few people here agree with you. I'm not a lawyer or a business man and I read the email as a clear legal threat. I had anxiety just reading it, the same as the OP.

It's clear as day. And if for whatever reason you don't see it that way the rest of the email and the way it's written should set off alarm bells as being a potential scam.

Re: CCPA Scam – Human subject research study conducted by Princeton University

#349

Earlier quoted context omitted.

Why? If that's indeed the law, then it's up to the website owner to comply. Whether it's Princeton or a private individual writing the email doesn't matter.

A key point is that it's not indeed the law. Many (probably most) of the recipients - including the author of the original article - are not actually required by Section 1798.130 of the California Civil Code do do anything even if it was a legitimate question from a real person, because their websites are far below the limits were those CCPA requirements start to apply. The survey was making a fraudulent legal threat…

[deleted]

Re: CCPA Scam – Human subject research study conducted by Princeton University

#350
post #307

Earlier quoted context omitted.

"My point is that due to the way some of these laws are written even a small hobby website might do things that the law regulates." And kstrauser's point is that, due to the way this law is written, by definition nothing their small, non-profit site does can ever be regulated by this law.

My point is that because some privacy laws are written so that they affect such sites (GDPR for example), it is a good idea for sites to try to be aware of new privacy laws so they can check if those laws are that kind of law. If they are not, then when someone makes a request under that new law it is just a matter then of responding with a pre-canned response explaining that the law does not apply instead of being a…

You're acting like this is an impersonal, natural event. It isn't.

Fate didn't choose kstrauser. An irresponsible academic sent an email blast to people who were not relevant to his study, without making even token efforts to filter things down.

Post reply on HN