Remix.run Logo
xrd an hour ago

About twenty years ago, I was taking a flight back from Rio de Janeiro, Brazil to the US. In the middle of the night the pilot got on the loudspeaker and said "hi! Having some engine trouble, so we are landing in Manaus."

Manaus is in the middle of the Amazon.

Needless to say, a bit scary to hear that, but we landed without issue.

They told us we had two choices: the nice hotel with a shared room, or the lesser nice hotel with no roommate. I chose the latter. When we go there, they said, "oops, sorry, short on rooms!" So I had a roommate.

Wandered around Manaus, took a skiff out on the Rio Negro. Saw pink river dolphins. A little boat approached us and a kid handed me a sloth, and then demanded I return it with a twenty dollar bill.

The airline got us another plane 24 hours later. Made it back to the US safely.

A few weeks later, the airline reached out and said "Here is $100 for your trouble."

I declined to take that offer. I had missed several business meetings that cost me actual money. I couldn't donate blood for years because I had been to the Amazon and was tagged a malaria risk.

During the many arguments with the airline I threatened to take them to small claims court.

I got a really strange response over email which I clearly wasn't supposed to see. A representative from that airline was asking internally if they could put me on the no-fly list. That was really chilling.

But, this is the kind of information I'm worried about when a vendor sells my data. If Google wanted to sell a product to the airlines that offered to keep annoying people like me from purchasing flights, they could do that with that email chain. I'm skeptical it'll be wiped correctly. Isn't my poor writing style basically my signature? How do you wipe that?

elric an hour ago | parent | next [-]

I fully share your concerns. And I don't understand how apparently tons of Teams and email conversations can be archived and sold without any kind scrutiny. How can such data be sold without the consent of all involved parties? What gives Google the right to use it to train LLMs? Is that just a way of washing away the legal protections?

Ekaros an hour ago | parent | next [-]

Makes one appreciate living in place with sufficient constitutional protections against this sort of stuff. Even for work stuff selling this info wouldn't fly in some parts of the world.

woadwarrior01 41 minutes ago | parent [-]

If you're referring to GDPR, companies routinely evade such protections using "informed consent" / "legitimate interests" loopholes. The big ones get caught once in a while, get a slap on the wrist and continue to do whatever they were doing before, albeit with more safeguards.

icantevenhold 15 minutes ago | parent [-]

Not really: https://noyb.eu/en/fines-resulting-noyb-litigation

Sure 50 M or even 1 B might be peanuts for faang but still there is real progress.

Support Noyb at all costs

warkdarrior an hour ago | parent | prev [-]

The party owning this data (Spirit Airlines) is consenting to the sale. Employees and customers of Spirit consented when they started employment and did business with Spirit, respectively.

alberto-m 37 minutes ago | parent | next [-]

Did they consent? Just because one receives a letter it doesn't mean they “own” it, much less that they are entitled to publish it at their leisure. If Spirit were active in any country with GDPR-style laws, the seller of these data would be most likely investigated.

hdgvhicv 32 minutes ago | parent [-]

America believes in freedom for large companies to take personal data and make it their own, rather than individual feeedom

Leynos 23 minutes ago | parent | prev | next [-]

This is why the GDPR (and to a lesser extent the CCPA) is a good thing. The data was supplied for a specific purpose. The handler of the data should have to obtain further consent if they wish to use it for another purpose.

layer8 18 minutes ago | parent | prev | next [-]

If this were a European company: That’s not how the GDPR works. You can only consent for specific purposes of using the data.

MagicMoonlight an hour ago | parent | prev [-]

[dead]

PaywallBuster an hour ago | parent | prev | next [-]

your personal site SSL cert expired 10 days ago btw

dwedge an hour ago | parent | next [-]

I love the irony of you checking them out for more information in response to a comment of them being worried about who reads their data. Nothing wrong with it, just make me chuckle

oarsinsync 3 minutes ago | parent [-]

There's something about circles of control in this, that makes the difference. If I publish information about myself, that's about me, and it's in my control.

If someone else shares information about me, without my consent, and someone uses that to nose in on me, that feels creepy and problematic.

xrd an hour ago | parent | prev [-]

Doh, thanks!

snickerbockers an hour ago | parent | prev | next [-]

So what happened to the sloth??? Don't bury the lead, man!

xrd an hour ago | parent [-]

The sloth was returned to his owner and I did tip him. That kid is probably still prowling the Amazon (as an adult now), looking for sucker tourists like me.

breppp 14 minutes ago | parent [-]

You probably should have taken the kid to small claims, that was extortion

transcriptase 6 minutes ago | parent [-]

Great way to end up on the no-sloth list

gspr 14 minutes ago | parent | prev | next [-]

And this is why data protection laws, like the (imperfect) EU ones that are so lamented here on HN, are necessary.

testing22321 43 minutes ago | parent | prev | next [-]

Did you end up getting more than $100?

warkdarrior an hour ago | parent | prev | next [-]

Manny retail industries already share lists of "troublesome" customers (trouble = anything from too many returns to lawsuit-happy to friendly fraud). Not sure this is a new concern..

jefftk an hour ago | parent | prev [-]

I think you might have missed the deidentification piece?

xrd an hour ago | parent | next [-]

Not trying to be snarky, and perhaps it wasn't well stated, but the last paragraph I said I'm concerned about identification via my writing style. If they have my emails, they would have my writing style. It doesn't have to be tied to PII there, they can cross reference it with my blog. I'm speculating because I read that you can identify people by a few sentences of their writing.

"Deidentification" seems really murky and imprecise at best.

jefftk 6 minutes ago | parent [-]

Reidentification via writing style is definitely possible, and I doubt the vendor will modify things in a way sufficient to handle that.

But I think this is a place where we should apply bounded distrust: there are lots of places where we should distrust Google, but reidentifying people in an explicitly deidentified dataset isn't one of them.

fileeditview an hour ago | parent | prev | next [-]

You have to trust that this really "deidentifies". Time and time again it was shown, that the measures taken were not enough to anonymize.

E.g. the parent wrote that he fears, he could be identified by his writing style, which is totally plausible. How would you "deidentify" this?

piva00 an hour ago | parent [-]

Even if they follow to the letter a deidentification process, Google and Meta have so much data about individuals that re-identification shouldn't be very hard for the majority of airline passengers' data they put their hands on.

Of course, takes a lot more effort than not doing proper deindetification in the first place but if they wanted to appear like caring about data privacy they still have enough data points to correlate the sets later on (and/or over time).

reaperducer an hour ago | parent | prev | next [-]

No such animal.

Leonard_of_Q an hour ago | parent | prev [-]

I have a bridge for sale, hardly seen use, pay me ${money} and you can collect it in New York City. Interested?