Live data from Hacker News

Google’s GDPR Workaround

brave.com

571–580 of 629 posts

Re: Google’s GDPR Workaround

#571
post #468

Earlier quoted context omitted.

Governments are likely walking a much finer line than we might imagine. Imagine they carried out your idea. The EU is a political organization manned by a large number of mostly professional politicians. Google is world's largest data harvesting and advertising company whose products are used, on a daily basis, by a pretty sizable chunk of our entire species' population. Imagine if Google decided to fight back. Who w…

I disagree. People were not aware of the shenanigans Facebook was pulling before the media outrage. Now they are and many are leaving the platform. Exactly how would Google fight back? Kill Android? Close down YouTube??

Consider Brexit for a minute. The most recent polls show support for leaving, but throughout it's been extremely close. However multinational corporations are universally against Brexit - a global world is a more profitable world. And these same multinational corporations tend to have a strangle hold on the places most people get their news from. This can be from the news agencies themselves (Disney owns ABC, Comcast owns NBC, Time Warner owns CNN, etc) but more directly also from the way that people get their news. For most people that is Facebook and Google. And these corporations tend to promote what is their own best interest. As a specific example CNN ends up being chosen for about 20% of Google's news recommendations. It's a deeply partisan site that's not uniquely popular and has a dubious track record when it comes to reliability. But their agenda and Google's agenda fit nicely.

Consider the two topics above, combined. The global media has nearly universally tried to condemn Brexit. And while media clearly doesn't have as large as an effect as some would like to imagine (Facebook was seeing an exodus of young users before any media outrage - it's become the social media site for your mom), it equally clearly does have at least some effect. And so imagine Google simply swapped their bias. And was suddenly now disproportionately promoting messaging come propaganda against the EU, in favor of Brexit, promoting things such as the yellow vests in France, the various leave campaigns gaining momentum in other nations, etc.

When topics, even with the media disproportionately on one side, are so close - if that media that people were presented suddenly started lobbying for the other side, that would have a massive effect. I don't think it's hyperbolic to suggest that companies such as Google and Facebook could effectively cause the EU to collapse if they so desired. It's already on somewhat shaky ground with near universal media support. If they don't play ball with the companies that direct that media, that ground very much stands to give way.

That doesn't mean the governments are completely obsequious to the corporations, yet, but it does mean that the corporations are also in no way obsequious to the governments. And I think this interbalanced relationship is one major reason that we see increasingly see governments reluctant to do anything that could meaningfully negatively affect mega corporations or other very powerful players. It's also why I see us gradually headed towards more overt corporatism. Corporations grow exponentially more powerful by the decade, and this shows no signs of abating.

Re: Google’s GDPR Workaround

#572
post #537

Earlier quoted context omitted.

> There was genuine shock in Europe that Chirac, Sarkozy, Hollande, Merkel were all spied on by NSA The USA (and all major powers) has spied on foreign diplomats and leaders since its inception. This should come as a surprise to nobody. You had earlier claimed that the NSA was spying on everybody , which clearly isn't happening.

I earlier claimed that the Patriot act allows NSA to spy on anybody, which is correct. And semantics aside when a court orders Verizon to secretly handle all the information about calls within the US or where one end is in the US [1], saying that they do spy on everybody is not really far fetched. [1] https://www.theguardian.com/world/interactive/2013/jun/06/ve... I can't believe we are having this conversation on th…

> When a court orders Verizon to secretly handle all the information about calls within the US or where one end is in the US [1], saying that they do spy on everybody is not really far fetched.

If the data can only be queried with identifiers of people with a reasonable suspicion of terrorist links, that hardly seems like "spying on everybody." Subsequent oversight board reports showed that automatic querying of the data with identifiers not associated with people reasonably suspected of terrorist links was deemed illegal and shut down prior to Snowden's leaks. If they could spy on everybody, there would be no reason to shut down that program. https://www.lawfareblog.com/latest-nsa-documents-iii-governm...

> I can't believe we are having this conversation on this board, that is supposed to be populated by people who have read that kind of news a bit in depth...

And I can't believe you didn't know that countries spied on foreign leaders before the Patriot Act, yet here we are. http://www.telegraph.co.uk/news/2017/06/22/germany-accused-h...

Re: Google’s GDPR Workaround

#573

Earlier quoted context omitted.

> No, a data processor is any entity that collected personal data gets passed on to and where it is processed as part of the business arrangement. I'm relatively sure that there's another part: it's data processing for the client (here: Google) and the data cannot be used for other purposes. In this case, they don't process data for Google, they process it in cooperation with Google for the ad-buyers. Google also doe…

You are misreading the GDPR badly. A data controller can only pass on PII to a data processor. That is, any entity receiving PII from a data comtroller automatically is assigned this role by law. There are no alternative roles that could assumed instead. This means that a data processor must obey the rules laid out for it by the GDPR or it is in violation.

Oh, okay, I believe I understand your point and understand the misunderstanding. My point is that you can't just make everybody a data processor by signing a contract, share PII with them and be compliant (i.e. hospital sharing data with insurance companies). You're saying that by sharing PII with them, you're making them a data processor, but that says nothing about whether the DC or the DP are compliant.

Re: Google’s GDPR Workaround

#575

Earlier quoted context omitted.

This is a problem because companies can use this ID to correlate private user data, without anyone's knowledge or consent. There are companies that specialise in sharing user information. Some of them work by only sharing data with companies that first share data with them (an exchange). If you got this Google ID, and you had a few other pieces of information about the user, you could share that data with an exchange…

Considering google_gid is valid for you for 14 days only. It is very unlikely to build a profile around it.

The time of validity and how hard it might be to build a profile are not factors in whether or not this is legal under GDPR. Here's the actual text from GDPR on pseudonyms and synthetic keys of this type[1]

> The principles of data protection should apply to any information concerning an identified or identifiable natural person. Personal data which have undergone pseudonymisation, which could be attributed to a natural person by the use of additional information should be considered to be information on an identifiable natural person

So PII that has been pseudonymized (mapped to a gid in this case) is protected in exactly the same way as if it had not been if the pseudonymized data could be mapped to a natural person by the use of additional data. The pseudonym (gid) is itself also considered PII under gdpr. [1] https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...

Re: Google’s GDPR Workaround

#576

Earlier quoted context omitted.

I have no doubt that if you had a record of my browsing habits for 2-3 days you could readily identify who I am the next time you have my browsing habits for that period of time. I wouldn't be surprised at all if 2-3 hours of active browsing was enough for this.

Your device fingerprint alone is generally enough to tie your new google id to any previous ones.

Which is also a typical example of privacy violations in the name of alleged security.

Some newer linux kernels (>2016) use random tcp timestamps offsets to prevent clock skew profiling.

That is a security feature, not the shit big tech is offering here.

But of course the mechanisms in question are suddenly implemented for fraud protection instead of user security. Yeah, bullshit.

Re: Google’s GDPR Workaround

#577

Earlier quoted context omitted.

I don't think the EU, or consumers in general, are terribly interested in "compromising" with the ad-tech industry.

Not that I support the ad-tech industry, but those consumers probably are interested in having their favorite websites being kept alive. Which implies that they might indeed be interested in "compromising" with ad-tech industry.

> but those consumers probably are interested in having their favorite websites being kept alive.

I'm one of "those consumers" and I'm actively looking for sustainable ways to pay content producers.

Here's what I do currently:

- subscribe to two newspapers in addition to the mandatory payments to the national news broadcaster.

- donate to the Guardian

- buy on Blendle

If there was a way to pay for single pay-walled stories I would probably use it a few times a week in addition to my current subscriptions.

I'm not interested in any more subscriptions (unless they are all inclusive like Spotify so I can cancel my current subscriptions, and even then I'm not sure since I actually want to support those two papers and think I do so better through direct payments than through revenue sharing through a huge international tech company. )

Re: Google’s GDPR Workaround

#578

Earlier quoted context omitted.

You're suggesting that hospitals would be allowed to sell patient info to anybody willing to pay, as long as they have a contract?

I'm suggesting : 1.) it might be stricter than you say. 2.) you (possibly like me? ;-) seems to have stronger views on what GDPR means than you can argue for.

Probably, I'm somewhat of a fundamentalist pragmatist ("this cannot be legal!" - "everybody does it, judges say it's okay" - "oh, I guess it's legal then :("), but in this case I'm not so sure. I still believe that Google does not consider them data processors (possibly because they don't consider a google_push id PII), because if they did, they'd have to name them in their privacy terms as entities they share data with. They don't. Of course, this might be because they don't care, but since it's a delicate issue and the stakes are somewhat high already, that doesn't sound plausible to me.

Pretty much all examples for data processing I've read are similar in this regard: the data controller (DC) passes data to the data processor (DP) so the DP can perform a specific task for them (handle invoicing, do analytics, run a web server, mail packages etc). The DP must not use the data for anything else, must not share the data with anyone (except for sub-processing, which has strict rules, too). "Exchanging/Syncing PII of users so we can create better profiles, more efficiently track them and show ads to them that are more personalized" doesn't fit the bill at all from what I understand. Similarly, landlords cannot get together and share all the data on their tenants to figure out who was a pleasant renter and who sued because the heater broke in winter.

So, in my understanding, even if you and I used the same invoicing provider, they wouldn't be allowed to tell me if they've invoiced a certain person for you previously, because we're different entities using them as a data processor and our data is to be kept separate. If we wanted to do data sharing (or even share aggregate probabilities like credit check agencies), we'd need a different construct, explicit consent and a bunch of additional compliance requirements.

Re: Google’s GDPR Workaround

#579

Earlier quoted context omitted.

You're suggesting that hospitals would be allowed to sell patient info to anybody willing to pay, as long as they have a contract?

In the US, HIPAA would apply to individually identifiable health information. HIPAA Providers share information with other HIPAA-covered entities all the time under contracts where the associate entities (non-providers) agree to comply with HIPAA privacy rules.

Those are generally with patient's previous consent though, right? Things get a lot easier if you have somebody sign some documents before you start working on them.

Re: Google’s GDPR Workaround

#580

Earlier quoted context omitted.

> The minute I see ads on a webpage, I automatically associate that site with trash. You might want to reconsider

Care to elaborate a little?

I've visited plenty of sites made by small developers who simply use them to try to offset hosting costs with a banner ad. Hosting isn't a negligible cost for everyone and content should be judged based of content, but you can of course judge a site as a whole with ads included.
Post reply on HN