Live data from Hacker News

Stop Saying, ‘We Take Your Privacy and Security Seriously’

techcrunch.com

41–50 of 112 posts

Re: Stop Saying, ‘We Take Your Privacy and Security Seriously’

#41
Ohh something related to my area! I work with security/data management and often I get to have access to client organizations for a variety of reasons; most of our clients are banks, pharmaceuticals and pension funds, among others.

"We take your privacy and security seriously" from some rando company doesn't even make me roll my eyes because of how desensitized I am to that whole concept. It's genuinely appalling how often banks have no clue of who has access to what data inside their organization: tons of people having accesses they shouldn't and nobody keeps track of it? Of course. Database copies stored in random hard drives sitting on tables? Why, naturally! Attestation processes? What's that? We're not talking about small entities either. These people would be years away from something not too hard like an iso27001 certification.

In short: all of our data is in an incredibly precarious situation and we're fucked forever. I don't get outraged at leaks nowadays, I just laugh at it.

edit: interestingly enough, in my experience pharmas care far more about data security than banks do (I assume that is because they have more shit to hide).

Re: Stop Saying, ‘We Take Your Privacy and Security Seriously’

#43
post #32
post #4

Earlier quoted context omitted.

Tracking cookies provide incommensurable value to site owners for improving the quality of their web properties, which ultimately benefits users. Example abound: finding out where people are the most frustrated (high exit rates), what content drives the most interest (page views), what content is missing or inaccurate (high bounce rate and low visit duration for visitors coming from Google), how they are using the si…

You can get most of this by analyzing server logs with IP addresses. No cookies required. You might need some JavaScript tracking for more detailed analytics, but there is absolutely no need for external tracking by Google or the likes. Examples for self-hosted analytics include GoAccess (server log analyzer) [0] or Matomo (JavaScript tracking, formerly Piwik) , although I think it uses tracking cookies by default [1…

That's still tracking, though. There's no real difference between using a cookie or an IP address. In fact, a cookie may be preferable, because you can make it expire in a relatively short time, making it much harder to link your logs to the user.

Re: Stop Saying, ‘We Take Your Privacy and Security Seriously’

#44
This is slightly off topic and relatively minor, but man does it represent the piss poor state of Tech writers and their articles.

"I was curious how often this go-to one liner was used. I scraped every reported notification to the California attorney general, a requirement under state law in the event of a breach or security lapse, stitched them together, and converted it into machine-readable text.

About one-third of all 285 data breach notifications had some variation of the line."

Don't bother providing a link to either you data source or your code, the ability for someone to independently verify the validity of this claim and its results isn't important, we'll just "trust" you.

Re: Stop Saying, ‘We Take Your Privacy and Security Seriously’

#45

Also stop saying "Before you go further..." we need to share your data with tens of corporations. /s Note to non-EU users: Techcrunch is completely blocking the page with a popup asking me to share my location and behavioral data (for advertising purposes) with a probably very long list of companies (something called "Oath" family). The logos shown are for Yahoo, Aol, Autoblog, Huffpost and Engadget. Nah. I'll skip a…

The Oath websites and Medium are on my mental blacklists of sites I simply don’t bother with. The content isn’t good enough to care. It does mean I hit comment threads like this and can’t read the article. Oh well, I’m trying to reduce my internet time anyway.

Yes, I could do with a plugin to strip links to Medium articles.

Re: Stop Saying, ‘We Take Your Privacy and Security Seriously’

#46
You enter a coffee shop. Before you can do anything, the owner takes a photo of you, and grabs your hand to take your finger print. He quickly writes down the date, time and what clothes you are wearing.

He gives you a smile as he starts his speech. "Before we continue, we at Coffee City want you to know we deeply value your privacy. We need your permission to store your information, improve your coffee experience, personalize your coffee suggestions and share it with our partners. Do you consent?"

You don't fucking value my privacy. I get some serious doublespeak vibes. If you valued my privacy you'd leave me the fuck alone and stop saving information about me.

IMO GDPR doesn't go far enough. Even these popups are wasting my valuable time and invade my privacy due to the ease it is to accidentally consent to some stupid bullshit while navigating the 20 windows needed to reject all consent.

We should outlaw even asking for consent to store personal information for any user that didn't log into your site. If I do not have an account with you, I'm not your user, we don't have an extended relationship and you have no business storing information about me.

Re: Stop Saying, ‘We Take Your Privacy and Security Seriously’

#47
post #20

Also stop saying "Before you go further..." we need to share your data with tens of corporations. /s Note to non-EU users: Techcrunch is completely blocking the page with a popup asking me to share my location and behavioral data (for advertising purposes) with a probably very long list of companies (something called "Oath" family). The logos shown are for Yahoo, Aol, Autoblog, Huffpost and Engadget. Nah. I'll skip a…

Just disable 1st-party scripts and 3rd-party scripts in the uBlock Origin popup for techcrunch.com and that modal should not appear anymore. https://prnt.sc/mo26b4

Or even better, don't visit techcrunch.com.

Re: Stop Saying, ‘We Take Your Privacy and Security Seriously’

#48
post #4
post #2

Say it, when you do. Say: We take your Privacy and Security seriously that is why we won’t ever store a tracking cookie on your machine. If you still want to support us by different means, click here Anybody who takes your privacy seriously won’t even have to ask for consent, because there is nothing to ask for

Tracking cookies provide incommensurable value to site owners for improving the quality of their web properties, which ultimately benefits users. Example abound: finding out where people are the most frustrated (high exit rates), what content drives the most interest (page views), what content is missing or inaccurate (high bounce rate and low visit duration for visitors coming from Google), how they are using the si…

Even ignoring the privacy issues, I'm not sure that it would lead to lower quality websites. Websites don't feel very high quality these days, especially the kinds of websites I know are probably doing the most tracking.

It might lead to lower-engagement websites, but that's a different thing. It might improve the quality of your website to stop trying to optimise my engagement with it.

Re: Stop Saying, ‘We Take Your Privacy and Security Seriously’

#49
post #35
post #11

Earlier quoted context omitted.

I just clicked through the links of that banner and I landed on https://www.oath.com/de/my-data/#protectingdata anyways, I will not read the article because I am sure these dialogs are built in a way to gain "consent" by trickery.

The dialogs are really confusing. 1st popup page: Some text about Oath with big "OK" button and same size "Manage Options" link. By clicking OK you agree to everything. 2nd popup page when clicking "Manage Options" link: Some more text about Oath with big "OK" button and tiny "Manage Options" link next to a headline. I have no idea what happens when I click OK here. Is the same as the "OK" button on the first page? I…

To give that dark pattern some context, Oath has recently been rebranded Verizon Media.

Re: Stop Saying, ‘We Take Your Privacy and Security Seriously’

#50
post #4
post #2

Say it, when you do. Say: We take your Privacy and Security seriously that is why we won’t ever store a tracking cookie on your machine. If you still want to support us by different means, click here Anybody who takes your privacy seriously won’t even have to ask for consent, because there is nothing to ask for

Tracking cookies provide incommensurable value to site owners for improving the quality of their web properties, which ultimately benefits users. Example abound: finding out where people are the most frustrated (high exit rates), what content drives the most interest (page views), what content is missing or inaccurate (high bounce rate and low visit duration for visitors coming from Google), how they are using the si…

> Tracking cookies provide incommensurable value to site owners for improving the quality of their web properties, which ultimately benefits users.

That can certainly be argued.

It can also be argued that websites optimizing for “engagement”, blindly, in a completely data-driven way, end up implementing tons of dark UX patterns.

And that’s certainly no benefit to the user.

Post reply on HN