| ▲ | aiiotnoodle 11 hours ago |
| I'm seriously at a point where I'm opposed to talking to my doctor because the information may be digitally recorded and leaked, going on a flight because my passport may be used to aqquire a loan by cybercriminals, comparing car insurance because my phone will be called by robocallers selling me things or verifying my ID with websites because it might be used to associate my information with whatever else I do online. I don't think, for a vast majority of cases, these companies I'm forced to interact with can be trusted with my data and it's having a real world negative impact. Even with the best intentions the information is somehow valuable to steal and I'm baffled how it's not secure. There should be some consequences for companies asking for things like SSN/National Insurance numbers on job adverts or retaining drivers licence photos after test driving a car, they just don't need the data anymore. |
|
| ▲ | suslik 10 hours ago | parent | next [-] |
| I am at a point where I simply stopped worrying and began to love the bomb. I did my best, I really did - degoogled before it was trendy, dropped all social media, built a homelab for complete data ownership, set up matrix messaging with family, and so on - but it feels like a wasted effort at this point. All my data is out there, one way or another, and a dedicated cybercriminal - or worse, a government entity - can obtain or exfiltrate it without issues. I know it, they know it, everyone knows it. The only thing I can change now is my reaction to this fact, and although the idea of off grid autarky is tempting, I am not there yet. I just don't want to stop living - flying abroad, going to doctors - I just accept that privacy in the current state of human condition is impossible, and move on with my life. |
| |
| ▲ | shit_game 10 hours ago | parent | next [-] | | >I simply stopped worrying and began to love the bomb This may apply to the consequences of ones data being subject to so many breaches and leaks and thefts, but it should not be the attitude one adopts towards the idea of ones data being taken and used by so many parties. At some level, my data is my personhood - it is my evidence of myself, and my record of myself, and my proof of myself. It encodes who I talk to, what I'm interested in, where I go, and what I do. My health, my finances, my habits, vices, schedule, family, friends, coworkers, beliefs. People more clever than myself use this data to advertise to me; people more powerful use this data to surveil me. When will people more malevolent use this data to persecute me? I should not have to love the bomb because the bomb will kill me. | | |
| ▲ | lencastre 5 minutes ago | parent | next [-] | | well isn’t the point of the movie that if you have a doomsday-(dead man switch)-device you should let everyone know? I don’t get that comparison with data being available everywhere | |
| ▲ | kspacewalk2 4 hours ago | parent | prev | next [-] | | Loss of privacy has no upsides. The bomb, on the other hand, saved many millions of lives over the last 80 years, so it works as a metaphor everyone shares, but the metaphor itself was always much more arguable with nukes. It's possible to actually rationally love the bomb, but what are the upsides for everything about me being exfiltrated at will? | | |
| ▲ | bonoboTP 29 minutes ago | parent | next [-] | | Oh, but of course there is. He you ever seen arguments from the other side? It is to catch criminals of various sorts (money laundering, trafficking, smuggling goods and people, terrorism etc), to keep children safe etc etc. Also,it can help you uncover and put behind bars your dangerous political enemies. That the tables may turn and the shoe may be on the other foot soon, that's too abstract of a thought to occur to most of them. | |
| ▲ | fpoling 2 hours ago | parent | prev | next [-] | | The upside is that you can know everything of almost any person as well. Whether that upside is beneficial for you is a different matter. | |
| ▲ | trimethylpurine 2 hours ago | parent | prev [-] | | It tracks terrorists' efforts to acquire the bomb. |
| |
| ▲ | BobaFloutist 5 hours ago | parent | prev | next [-] | | Yes, that's the direct subtext of that phrase. | |
| ▲ | EA-3167 an hour ago | parent | prev [-] | | Some of us are more practical than ideological, but we tend not to put as much energy into communicating our views as the ideological types. The result online is an often distorted sense of the universality and importance of ideology. You feel
That your data is part of your personhood? I feel that it’s more like tracks in the woods and scat. |
| |
| ▲ | clickety_clack 4 hours ago | parent | prev | next [-] | | It’s not the current use of the data that’s concerning, it’s its future use. Who’s to say that some facet of your life that is ordinary now will not one day paint you as the target of some future regime? It happened in Europe a few decades ago, and in many other countries around the world. | | |
| ▲ | vladms 2 hours ago | parent [-] | | Yeah, like the way US citizens now are not targeted at all by ICE because their data is out there? Future evil government will not care about your data, they can just invent shit. The idea is to instill fear and uncertainty not "finding the correct people". On the other hand, said data can be today use because various entities use extremely shitty authentication methods, like just insert your birthday and first name and voila you have a credit with our bank (not an actual example, just for illustration purposes). |
| |
| ▲ | thomassmith65 8 hours ago | parent | prev | next [-] | | To be zen about one's privacy is easier for some people than others. There are situations in many a person's life that if revealed to the public would have life-altering consequences. Rather than the world give up, we should have better tools and laws to flood the internet with spurious personal data. | |
| ▲ | ruszki 10 hours ago | parent | prev | next [-] | | Similarly. My browser was carefully containerized, with a ton of anti fingerprinting measures, VPN, Linux, Librewolf, everything. Even on my phone, I restricted whatever possible. Then one day I went to the YouTube main page, and I saw that Google somehow got to know that I played Minecraft again after a decade. I gave up right there. I suffered to avoid this, and it was pointless. I knew at that point already that probably all my PI is public information anyway, but I wanted to restrict whatever possible, and no, everybody sells my data anyway, and it seems that avoiding fingerprinting is impossible without turning off the internet completely, and ditching smart phones. | | |
| ▲ | neobrain 10 hours ago | parent | next [-] | | > Google somehow got to know that I played Minecraft again after a decade. [...] I knew at that point already that probably all my PI is public information anyway How are you jumping from Minecraft (probably one of the most watchtime-generating content types out there) being displayed on your main page to… your personal information being known to everyone? | | |
| ▲ | close04 9 hours ago | parent | next [-] | | Your data is still out there, just compartmentalized so each outside party only has a bit. It turns out that's a losing strategy when each outside party decides to cooperate with every other and pool/share/sell that data uniquely attached to you. | | | |
| ▲ | yieldcrv 9 hours ago | parent | prev [-] | | because it’s the same process of intermediaries accumulating, inferring and sharing data to each other intermediaries that will be compromised | | |
| ▲ | neobrain 9 hours ago | parent [-] | | > because it’s the same process of intermediaries accumulating, inferring and sharing data to each other Except that YouTube doesn't need any of that to recommend Minecraft videos to you. One mundane explanation that seems more likely is that it's the type of content that on average works best on people they don't yet have information on. Reminds me a little of these "phones listen to everything we say, otherwise I wouldn't have been shown this ad" anecdotes that don't hold up against empiric evidence. | | |
| ▲ | pbhjpbhj 6 hours ago | parent | next [-] | | You saw the LG TV exposé? They do speech transcription on the TV and so have available for upload the logs for audio even when the TV is off. Microsoft would definitely sell data on which IPs have Minecraft users, as would your DNS provider, cloudflare, or your ISP. It could also be coincidence, though my experience is YouTube's suggestion algo is very tightly tracked to use data. (What I was fed on a guest account recently was a mix of fascist propaganda and AI nonsense masquerading as reportage. | |
| ▲ | autoexec 3 hours ago | parent | prev [-] | | > Reminds me a little of these "phones listen to everything we say, otherwise I wouldn't have been shown this ad" anecdotes that don't hold up against empiric evidence. If phones weren't listening technology like audio beacons couldn't have been invented or useful (https://medium.com/@williamwais01/ultrasonic-beacons-the-sil...). Surveillance capitalism has been so successful because it's so opaque. It would take a whistleblower for you to know when and how the data companies have is used against you, or how they got that data in the first place. Their tactics can be used in ways that are highly targeted and transient, especially for data collection companies like Google. Even for something as basic as search results what I see when I search may not be what you see, and what I today might not be what I see when I take the same actions tomorrow. This can make identifying what our phones are doing almost impossible. A possible explanation for the "phones listen to everything we say, otherwise I wouldn't have been shown this ad" phenomenon might be that a phone picked up an audio beacon being broadcast while something played on a TV, which sparked a related conversation in the person carrying the phone. The conversation wasn't recorded, but topic being discussed was successfully logged anyway. There are countless other data points available that could be used in the same way. In cases like that it would clearly not be coincidence that Google showed an ad when it did, but the spying involved was even more involved and invasive than just listening to what was being said. There's nothing to stop Google from having small clusters of phones listening to everything for certain periods of time under certain circumstances. They wouldn't have to send all that audio data back to their servers to be effective, just monitor for a sample of specific words/phrases (processed on device) and send back a flag when something is overheard. That kind of behavior would be extremely hard for researchers to catch. The truth is that we're not allowed to know how and when we're being surveilled, but we are being watched all the time, and that data is collected to be sold or used against us at every opportunity. It doesn't do any good to tell the person imprisoned in the panopticon that he's being paranoid and that it's all coincidental. Even when it happens to be, feeling watched is the natural response. | | |
| ▲ | vladms 2 hours ago | parent [-] | | I guess I was selected for the cohort "never show a useful ad to hide we're listening" even if I don't try to protect a lot (except an add blocker in a navigator). Honestly I wish I would get more targeted ads for the stuff I look for, when I look. Instead, for some, it happens that after I buy them, I get repeated ads after couple of weeks or even months (like, invoice is on gmail, photos of the object on my phone, but nooo they want to trick me, so they still send me more ads of the same shit that I will not buy again in years). Seriously, I think the tracking is as crappy as most software is. Sure, it might identify one/two keywords and throw ads at you, but it does it a dumb volume way that corporations work, not in a smart "we know everything about you way", that a true geek might implement. |
|
|
|
| |
| ▲ | astura 8 hours ago | parent | prev | next [-] | | >My browser was carefully containerized, with a ton of anti fingerprinting measures, VPN, Linux, Librewolf, everything Doesn't that just make your browser very unique? | | |
| ▲ | slumberlust 3 hours ago | parent | next [-] | | Yes. Its a fingerprinting paradox that the more you do to obfuscate the better they can pick you out of the crowd. | |
| ▲ | emj 6 hours ago | parent | prev [-] | | It is unique in a new way every page view. | | |
| ▲ | autoexec 2 hours ago | parent [-] | | It's way better to do that than hope that you've managed to cover every possible means of fingerprinting. When trying to make your fingerprint as common as possible it only takes a single consistent data point to identify you, and new techniques pop up all the time. TOR browser is a good example of what not to do. |
|
| |
| ▲ | sillyfluke 9 hours ago | parent | prev [-] | | >Then one day I went to the YouTube main page, and I saw that Google somehow got to know that I played Minecraft again after a decade Did you play minecraft on the same network? If so, I'm not sure why the results are surprising or why it would negate all your efforts. If someone else played minecraft on your network you would also see a minecraft video on your main page I would imagine. | | |
| ▲ | dmurray 8 hours ago | parent [-] | | That's worse. My family or housemates can infer what activity I've been up to online by watching their YouTube recommendations? | | |
| ▲ | astura 8 hours ago | parent [-] | | If your family or housemates wanted to know what you did online they could just flash DD-WRT onto the router and turn on logging. |
|
|
| |
| ▲ | hypfer 9 hours ago | parent | prev | next [-] | | These swings can be avoided by not doing stuff so hard but instead more effectively. For example, matrix sucks ass. It's terrible. Everything about it is a bad experience.
Of course you'd want to eventually stop using it and go back to the previous life. But that is not the correct take-away. The correct take away is to include UX (and honesty to yourself about it) in the calculation and to not go all in on an unsustainable compromise, just to then snap back to doing the opposite ca 3 months later. Same as with loosing weight, really. If you replace 100% of the pleasure of eating with the "right" but unpleasant solutions, you will not be able to keep that diet going indefinitely. | | |
| ▲ | kuon 8 hours ago | parent [-] | | We use xmpp in the family and the experience is good enough. I wish WhatsApp would support official federation and it would be perfect. |
| |
| ▲ | PatronBernard 7 hours ago | parent | prev | next [-] | | This makes me think: how would someone like Mark Zuckerberg handle this for his own internet presence? Or does he sidestep this issue completely by having assistants for nearly everything? I can imagine he doesn't do much more than look at .ppts and fire off emails. Do data brokers have any information at all on this guy? | | |
| ▲ | goosejuice 6 hours ago | parent | next [-] | | There's concierge services for this kind of data removal. At a certain level of wealth I assume there are teams working on this with lawyers 24/7. | | | |
| ▲ | bix6 6 hours ago | parent | prev [-] | | I bet you could find his SSN if you looked. | | |
| ▲ | zelphirkalt 3 hours ago | parent [-] | | It would be funny, if there was a website anywhere, which accumulates data about all the tech giant C levels and shares it with the public, just like they share data about all of use behind closed doors to manipulate us and sell us shit, or sell our data to the next tier of data hungry businesses. Probably wouldn't last long though, as they would be furious, that us lowly human beings are able to glean anything about them. The double standard of this is not obvious to them. |
|
| |
| ▲ | gentlerain 10 hours ago | parent | prev | next [-] | | The next frontier is to maintain 'limited privacy'. That's denying most culprits the opportunity to use the collected data against you. Like always on VPN, turning off personalization, ad guards and using open source products where possible. | | |
| ▲ | arethuza 10 hours ago | parent | next [-] | | It's a bit like physical security of your house - could someone break into my house, not easily but it's a house not a bank vault. Keeping our gate closed and having a large dog (who is actually very friendly) about the place probably keeps the vast majority of possible thieves away. | |
| ▲ | TeMPOraL 10 hours ago | parent | prev [-] | | That's still a bit on the obsessive side. The reasonable position is the same as it always has been in the real world too: - Don't volunteer your intimate details left and right; - Feel entitled to deny requests for unnecessary data (and advocate for such rights if you're in position to) - Otherwise don't sweat it, because you can't actually control what others know about you, you never could | | |
| ▲ | deltoidmaximus 3 hours ago | parent | next [-] | | The trouble with this is the baseline is getting to high. You've got age verification coming, google rolling out phone verification for websites, etc. Once that is rolled out, accepted and "easy" it will be used for everything important "for security" and then everything not important because hey, you were doing anyway? The reasonable position will be slow marched into hell same as the rest of them, just a few steps behind. | |
| ▲ | az09mugen 8 hours ago | parent | prev [-] | | I feel like this is the best compromise. Thanks for wording it. |
|
| |
| ▲ | _the_inflator 9 hours ago | parent | prev | next [-] | | I agree. And most people on the behavioral side do too, but not at the cognitive level. EU is the best example with EU AI Act, strict data regulation as well as privacy rights, on the other hand demanding that Apple does serve the EU with AI. I have mainly one distinction: the state is the worst protector of your data and the most ruthless gatherer of all your details. Opposite to the open sourcing of your data in the end by the state are private companies who live by your data but do this for 20+ years - battle tested protection and hardening against malicious hackers. Security is their business while security for the state is a cost factor. Being at the mercy of some ignorant politician is not the best way to talk about data security. Berlin, Denmark - those are the known one. And there are many more to come. And regarding cognitive dissonance: politicians demanding high standards and punishing data loss ruthlessly on the one hand, giving oneself a pass on a hack is nothing to increase trust into the system. X got fined for a missing blue mark. Berlin? Denmark? Others? A second aspect is that the average guy doesn’t get that part of the whole spectrum must be the degooglers, the home server guys. So it is relatively easy to get data on them as well just by filtering out the other data. In other words: 95% not doing degoogling makes for a great small sample of 5%. Negating and interpolating other demographic and psychographic factors and you get a great way of gaining insights. And remember: being the one who is not using google when being around other guys who do - magic. So my idea is simple: what’s in it for me, and the state offers way lower value than Google and co. Pick your fate. | | |
| ▲ | KPGv2 7 hours ago | parent [-] | | > I have mainly one distinction: the state is the worst protector of your data and the most ruthless gatherer of all your details. How many state data breaches vs corporate data breaches? There are hundreds of state entities with my data (probably thousands), and yet private companies with my data have been hacked more times. | | |
| ▲ | Grimeton 3 hours ago | parent [-] | | > and yet private companies with my data have been hacked more times. ...and yet private companies with my data have been hacked more times, so far. Also they might have not been targeted.... |
|
| |
| ▲ | thewizzardofnl 10 hours ago | parent | prev | next [-] | | I think both are possible. To have a goal and to accept reality. I would not draw the conclusion that all privacy measures are meaningless. It is hard, but I think it is still worth working towards a goal of better privacy for citizens. | |
| ▲ | mdp2021 8 hours ago | parent | prev | next [-] | | > wasted effort That depends. One thing is following precautions, another the Principles. Precautions may have a limit ("due diligence done, I'll stop there"), Principles do not. Remember also that many phenomena occur because the individuals in the masses have not said "no". Acceptance enabled them. So the acceptance of some ill conceived systems is criminal - it is what lets them exist. | |
| ▲ | adverbly 7 hours ago | parent | prev | next [-] | | Two problems with that: 1. I don't want to love it. I hate it. You can learn to live with things you hate though, and not have it impact your day to day life or mental health though. 2. Its still a bomb. Until we find out how we can de-value the data, it will have an incentive to be stolen. One thought here that I don't personally agree with, but might be important regardless: Imagine a society without secrets or privacy at all for example. I don't personally like the sounds of it, but it is sort of where we're headed at the moment, and if the fundamental reality is that obtaining data is much more easy than defending it, then perhaps we need to come to terms with a world without privacy, and how to create the best version of that unconstrained world. Again, I don't like the sounds of this, but I'm curious to read more about it. Can someone give a philosophical pitch of why GDPR style regs on personal and company data are so important? | |
| ▲ | robwwilliams 4 hours ago | parent | prev | next [-] | | LoL. We are all dancing naked on the table and hoping our clothes and wallet or purse and some of our pride will be where we left them. | |
| ▲ | swozey 7 hours ago | parent | prev | next [-] | | All of the popular surveillance apps correlate your email address and phone numbers mostly, but if you used 1@gmail.com to sign up for 2@gmail.com google knows and marks it as your altnerate account, it could give them all your 30 rando gmails, you're then linked by phone activations through those emails to everything else, whatsapp, telegram, credit card purchase, etc. the biggest link in the chain is always the phone number though. They also have a big "Alternate Emails" button. Everything fans out from those. I don't know how deep palantir can build profiles on someone, like digging into comment histories and extrapolating you are x y or z sort of stuff. I'm sure they've learned a lot about people via public irc logs and discord servers. But the only screenshots I've seen have been way more simple than that, basically a facebook UI that gives them buttons for all the apps with the phone # that has been identified as you the user, so it would be your list of social media apps accounts and they just click in and read messages. These screenshots have popped up in court cases recently. We need to stop using the same phone numbers and rotate them constantly. Ideally back to something like fi that masks your "real" isp account phone number. They need to stop being a 2fa and especially stop being able to identify a person. Carry a dumb 2fa. I've always been on the "dont ask for my phone number to use your service" bandwagon but absolutely now. And now some banks are doing instant voice recognition. I don't pick up my phone for any number I don't know anymore. | |
| ▲ | TeMPOraL 10 hours ago | parent | prev | next [-] | | Evidence is pretty clear after decades of this: big data breaches are inconsequential for an average person. They happen all the time, nobody cares, criminals who want to target you will target you anyway, criminals who don't target don't care about you specifically, legitimate entities cannot use this data anyway, and legitimate scammers (marketing) will find different ways to get you to give them the data you need. At this point I thing privacy obsession is modern copium, a way for people to deal with the fact that we're all individually a speck of dust on the face of human civilization. It's about asserting, "I am not an NPC, I have this richness of experience", and then trying to hide it all in case the world wants to check. | | |
| ▲ | anilakar 10 hours ago | parent | next [-] | | > big data breaches are inconsequential for an average person A relative killed herself after her therapist was hacked[1] and the data was leaked. If that is inconsequential, I do not know what isn't. [1] https://en.wikipedia.org/wiki/Vastaamo_data_breach | | |
| ▲ | sgjohnson 4 hours ago | parent [-] | | A single suicide due to a massive data breach is, unfortunately, completely inconsequential. Especially if we consider what social media does to teenagers without needing any data breaches. |
| |
| ▲ | diydsp 9 hours ago | parent | prev [-] | | [dead] |
| |
| ▲ | sillyfluke 9 hours ago | parent | prev | next [-] | | >I just don't want to stop living - flying abroad, going to doctor Good, you're not throwing out the baby with the bathwater. I don't get why you think throwing out the bathwater itself was wasted effort though. The point is to get rid of things you can live without. If you're going to get rid of something but then spend every day thinking of its absence, then yes, that may be bridge too far. Otherwise, getting rid of it has some value. I don't see the harm of asking, "Do I need this entity's services enough to justify forking over this data" for every entity that you interact with. Everyone draws their line in the sand at a different place. Data hygiene is a good phrase for that reason, everybody's acceptable level of hygiene (or lack thereof) is different. | |
| ▲ | ionwake 10 hours ago | parent | prev [-] | | I gave up when i realised Firefox had google analytics and noone even knew or cared. That was about 10 years ago now. | | |
| ▲ | Kbelicius 10 hours ago | parent [-] | | Because it did not. Extensions page used them but nothing else. | | |
| ▲ | ionwake 10 hours ago | parent [-] | | I love the bit where a programmer always proudly chimes in with this statement as if it means anything. You dont get it bro, its not a good vibe. And if I had bean in management I would have fired anyone involved with that decision. Why is it so often HN that I point something obvious out , like Rockstar having clearly failed management and a complete loss of control, but instead of agreement or silence I always get flak from some random user who just doesnt get it, and then a year later the company starts falling apart. Im just a guy who recognises patterns and im not even smart. | | |
| ▲ | Kbelicius 10 hours ago | parent | next [-] | | > I love the bit where a programmer always proudly chimes in with this statement as if it means anything. So you knew that fierfox never came with google analytics but you decided to claim it anyway... | | |
| ▲ | sillyfluke 5 hours ago | parent [-] | | Not the parent, but I'm not sure I understand your reasoning. You download firefox. In firefox, you go to settings->Extensions to download extensions and get exposed to google analytics, is that correct? If that's true, how is it not insidious that in order to download the thing that blocks google analytics, you have to get exposed to google analytics? |
| |
| ▲ | TeMPOraL 10 hours ago | parent | prev | next [-] | | > Why is it so often HN that I point something obvious out Because many "obvious" things are just plausibly sounding bullshit. For example: > Rockstar having clearly failed management and a complete loss of control That's both very broad and generic, and completely unfalsifiable, and comes with nothing backing it up. It's just an unsubstantiated opinion. These things are fine when drinking in friends, or otherwise socializing by bonding over ramblings. If you want to convince someone of something, the standards of evidence (not to mention, clarity of thinking) are a bit higher. | |
| ▲ | bluebarbet 10 hours ago | parent | prev | next [-] | | >the company starts falling apart. This site will start falling apart if we don't keep things civil. | |
| ▲ | astura 8 hours ago | parent | prev | next [-] | | >if I had bean in management I would have fired anyone involved with that decision. Oh, I love the bit where a programmer always proudly chimes in with this statement as if it means anything. | |
| ▲ | wyre 9 hours ago | parent | prev [-] | | What? So 10 years ago you though 1+1=Firefox is using Google Analytics, something you can't prove, but is "obvious" and "recognizing patterns" I get wanting to be conspiratorial, but its not cool to go after others that challenge your conspiracy, even if its "obvious" |
|
|
|
|
|
| ▲ | archon 7 hours ago | parent | prev | next [-] |
| > I'm seriously at a point where I'm opposed to talking to my doctor because the information may be digitally recorded and leaked And then add on that fact that my doctor recently started using some kind of AI voice transcription app that listened to our entire conversation. Except that it hallucinated details I absolutely did not say, which are now in that doctor's records and I'm sure will be taken at face value in the future. It's maddening. |
| |
| ▲ | 98codes 4 hours ago | parent [-] | | It is definitely worth asking for a copy of those notes, verbatim, as-is from the automatic transcription, to check for errors while the session is fresh in your mind. If your doctor is worth seeing at all, they will be glad for the corrections. |
|
|
| ▲ | coryrc 4 hours ago | parent | prev | next [-] |
| I have another solution. I look normal online when filling out information. I use Facebook, whatever. But whenever possible, I lie. Different name, birthdate, every question about "favorite pet"? A lie. "They" have tons of data on me, but more and more is wrong. Let it leak. |
| |
| ▲ | sib 2 hours ago | parent [-] | | I use my password manager to maintain unique answers to all of the useless verification questions about pets, movies, teachers, etc. Only way to scale it. | | |
| ▲ | docjay an hour ago | parent [-] | | I just use the noun in the question. The name of my pet is pet, my favorite movie is movie, and I attended High School. Add your own standard prefix if you want it impossible to guess. Nobody will know you attended “BLARG High School.” |
|
|
|
| ▲ | strideashort 11 hours ago | parent | prev | next [-] |
| I recently needed a lawyer on something that involved lots of highly sensitive PI. Sending my file over to lawyers in a semi-safe way has proved impossible. And in any case, i received an answer with lots of PI over a plain email… Absolutely maddening |
| |
| ▲ | master-lincoln 10 hours ago | parent [-] | | Why? I would assume encrypting and sending the key via a different channel would be sufficient. Or are lawyers still not technically apt to do so? | | |
| ▲ | CrimsonRain 10 hours ago | parent | next [-] | | Then lawyer replies in plain email discussing those very things... | | |
| ▲ | data-ottawa 9 hours ago | parent [-] | | The lawyers I’ve used have always asked and used encrypted email. I don’t know if that’s regional, but it was taken very seriously here. | | |
| ▲ | SoftTalker 6 hours ago | parent [-] | | Probably greatly depends how old the lawyer is and how big the law firm is. If it's one older guy, good luck. You're probably better off doing everything by FAX honestly. |
|
| |
| ▲ | strideashort 4 hours ago | parent | prev | next [-] | | “We can’t open this” It was .7z with strong pwd. The normal zip is supposedly too weak according to llms | |
| ▲ | Telaneo 9 hours ago | parent | prev [-] | | If normal people aren't, I wouldn't expect lawyers to be either. If there's no happy path to encrypted communication, then it will not happen. | | |
| ▲ | chronogram 8 hours ago | parent [-] | | It's part of their job. If they can't do that right they certainly can't do the rest of their job right. Just like it's OK to get queazy if your doctor is functionally illiterate or your lifeguard can't swim. Also things that match average people in some areas. |
|
|
|
|
| ▲ | NooneAtAll3 14 minutes ago | parent | prev | next [-] |
| > or retaining drivers licence photos after test driving a car, mind that there was a breach recently where all the data was being leaked *the moment it was collected* so simply controlling retention is not enough. The very fact of data being taken is already a vulnerable part |
|
| ▲ | faidit 5 hours ago | parent | prev | next [-] |
| We need HIPAA for businesses. We tried letting them regulate themselves and it didn't work. Businesses need to be forced to compete on the quality of their products/services and not rewarded for reselling customer data to spammers and criminals |
|
| ▲ | msdz 10 hours ago | parent | prev | next [-] |
| > There should be some consequences for companies […] retaining drivers licence photos after test driving a car, they just don't need the data anymore. I know it’s modern American tech tradition to make fun of the GDPR, but this is genuinely one of the things it stipulates: You’ll get at least a slap on the wrist, or potentially much
worse, if you needlessly keep data around longer than necessary to do the task you had collected it for in the first place. |
| |
| ▲ | nswizzle31 7 hours ago | parent | next [-] | | What punishment does the country of Denmark get here, if you had to guess? | |
| ▲ | senordevnyc 7 hours ago | parent | prev [-] | | Pretty ironic to be extolling the virtues of the EU's privacy approach on this story in particular... |
|
|
| ▲ | amelius 11 hours ago | parent | prev | next [-] |
| I mean why does every hotel need to make a copy of my passport? |
| |
| ▲ | ElDji 11 hours ago | parent | next [-] | | It is a basic police requirements on most countries. Hotels must collect visitor id's and keep it for several weeks. | | |
| ▲ | toyg 11 hours ago | parent | next [-] | | Yeah, it's old-school people control. This said, these days it could be done electronically, without the hotel storing physical information: at check-in, you put your passport in goverment-issued, (hopefully) tamper-proof machines, the hotel confirms length of stay, police server gets the info and that's it; early checkouts, the hotel must notify via some web portal. It would be relatively easy to implement. But nobody really cares enough to spend money modernising this sort of system. | | |
| ▲ | rithdmc 10 hours ago | parent | next [-] | | I'm sure they're done electronically in some places: Your passport details are appended to the shared Google Spreadsheet... I'm only half joking: I used to work in payments, hotels didn't care about PCI. Full card numbers stored everywhere. | | |
| ▲ | toyg 10 hours ago | parent [-] | | I know, and that's really the thing: nobody cares, not the government and certainly not the hotels. | | |
| |
| ▲ | 10 hours ago | parent | prev | next [-] | | [deleted] | |
| ▲ | sib 2 hours ago | parent | prev | next [-] | | Yeah, honestly I'd prefer the remote, simple hotel makes a physical photocopy which at least has a chance of being thrown out after a couple of weeks vs the government of "random country" gets a digital copy which will never, ever, ever be deleted. | |
| ▲ | GJim 10 hours ago | parent | prev | next [-] | | > This said, these days it could be done electronically Are you 'avin a laugh mate? A photocopy of my passport is going nowhere and is shreadded afterwards. An electronic copy..... God lord. The GDPR also requires data deletion once you no longer need it; physical as well as electronic. This is common sense, and why some organisations don't do this is simply mind boglling. | | |
| ▲ | toyg 10 hours ago | parent [-] | | The whole point is that the hotel would not even get a copy, the machine would just send hashes around and the hotel would only get an anonymous transaction ID to store. It would probably be even more secure than what you have today at the airport. If you think photocopies kept in some folder accessible to anyone working in the hotel, with a promise to delete it at some point, is "secure" in any way, I don't know what to tell you. | | |
| ▲ | preg_match 3 hours ago | parent | next [-] | | I’m sure this can be done, but somehow I doubt it. When I toured apartments they would often take a photocopy of my ID. Okay, overkill. But realistically I have no idea where that photocopy is stored. Probably in a OneDrive somewhere to this day. | |
| ▲ | GJim 9 hours ago | parent | prev [-] | | Good lord! Rather a paper data breach exposed to a few hotel employees than eletronic data exposed to the entire planet! | | |
| ▲ | tlb 9 hours ago | parent [-] | | When paper data is breached, the crooks don't steal the paper and put in their own locked file cabinet. They take pictures of the documents and sell the data on the dark web. So the end result is the same. | | |
| ▲ | mainecoder 9 hours ago | parent [-] | | the will need to take a picture everytime they are lazy but stealing all the people who ever stayed at that hotel is a simple copy past taking less than 10 minutes |
|
|
|
| |
| ▲ | astura 8 hours ago | parent | prev | next [-] | | Ironically, that would enable tracking much more than the normal case, which is a hotel stores the scans on a hard drive on the closet that nobody every looks at unless they get a subpoena. | | |
| ▲ | toyg 8 hours ago | parent [-] | | That's not what happens in Italy, at least - the documents are scanned and uploaded to a police portal in less than 24h. I expect that's roughly the same elsewhere. (I honestly did not know until today, I just knew the police would come every night to collect copies - good to see some modernization...) |
| |
| ▲ | carlosjobim 10 hours ago | parent | prev [-] | | All these giant data leaks are coming from the government's "tamper proof" systems! | | |
| ▲ | toyg 10 hours ago | parent [-] | | I know, and it's really the trade-off whenever this sort of system is centralized: you can better secure the leafs, but the central repository becomes an even juicier target. This said, the police already has a database with these info, and it likely is somehow already on the network, so adding an api (if done properly) would not dramatically alter the exposure profile. |
|
| |
| ▲ | severino 7 hours ago | parent | prev | next [-] | | The requirement is that they provide some of the information contained in the visitor's id to a police web application. At least, that's how it works here in Spain. But it doesn't mean the hotel needs to take a picture of your id, nor scan it. They just need to transcribe the required information. Yet some would not let you check-in if you refuse to let them scan your id or take pictures of it, that you never know how and for how long will be kept. Of course, you usually don't want to argue after you arrive at some place to make the check-in when the alternative is to sleep on the street. | |
| ▲ | ninalanyon 8 hours ago | parent | prev | next [-] | | Not in my, admittedly limited, experience. I've stayed in hotels in at least a dozen countries and under half of them wanted my passport. In the UK it's usually enough to just say my name to the receptionist, they confirm how long I'm staying, ask me to sign a form and tell them my car registration number and then they hand me the key. Quite often there isn't even a form to sign, just a terminal to enter my car registration number to avoid parking fees. I was asked for my passport in a Premier Inn this summer because they thought I was a foreigner but when I pointed out that I was a UK citizen they dropped the requirement. In Europe it was mostly Italy and Poland that wanted to see my passport. | |
| ▲ | edelbitter 8 hours ago | parent | prev [-] | | I politely refused the data collection a couple times just to confirm my understanding, expecting to trigger some discussion in case I was wrong. But hotel staff was perfectly aware of the applicable local rules and just skipped ahead to explaining the most convenient route to my room. Apparently the general assumption among visitors is that they would not ask if they were not required to collect it. |
| |
| ▲ | Scaled 10 hours ago | parent | prev | next [-] | | I just tell them they can look at it but not copy it and that's satisfied them, for now. Sometimes had to get a manager in, but never had them deny me fully. I'm sure sooner or later I'll run into a stubborn one and have to scramble for a day-of replacement hotel, and that just adds to my list of reasons to avoid travel. | | |
| ▲ | mk_stjames an hour ago | parent [-] | | Travel to Spain and they will not give you a room key until they can take your passport and make a scan of it, often times on an old flatbed print/scanner combo, that they print out a copy on paper to staple to their copy of the invoice and put god knows where. It's been like that for about 6-8 years. No more showing up and paying cash for a hotel room. You can try to say no, but I don't think you can anymore. I go through this a dozen times a year on my travels there. This is Spain. |
| |
| ▲ | Razengan 11 hours ago | parent | prev [-] | | And why are politicians immune to all of this shit?? Why can’t WE spy on them 24/7? | | |
| ▲ | lynx97 11 hours ago | parent | next [-] | | If democracy really worked, and your desire to spy on politicians is shared by enough people, supposedly, you should be able to create your own party which has that explicit goal. Maybe find a few other goals, or you will end up like the pirates :-) I am writing this because I don't think democracy works as advertised. | |
| ▲ | sparkling 11 hours ago | parent | prev [-] | | Because you are a slave, Neo. |
|
|
|
| ▲ | crabbone 2 hours ago | parent | prev | next [-] |
| Last month I had to lodge a complaint with Lycamobile because they arbitrary cancelled my plan, essentially, pocketing some 50 Euro. Trying to follow their very elaborate support extensions maze, I ended up in some Indian customer support center that proved to be completely useless when it comes to solving issues caused by the service provider itself. However, next week, I started getting calls from other Lycamobile numbers, where it sounded like the same Indian guy, but now he presented himself as a police officer who wanted to arrest my bank account :) The moral of the story: if you have a phone number, it's been already sold to some shady call center in South-East Asia and it's just a matter of time before they will try to scam you or use your phone for some nefarious purpose. I don't think Lycamobile is unique in how bad their system is and how much they want to extract every last penny from you buy outsourcing every service to foreign companies with zero responsibility and questionable work ethics. |
|
| ▲ | tokioyoyo 11 hours ago | parent | prev | next [-] |
| I said it before as well, but it’s because nothing “publicly really bad” happened despite the leaks and stolen information over the past decades. After Equifax breach, everyone got tired, because company survived, and whatever identity theft happens from time to time gets swept under the rug. It didn’t impact most people’s lives, despite leaking half of the US’s SSNs and etc. Then fatigue kicked in, and with subsequent leaks everything just mellowed down, so nobody cares. I’ve switched to operate with the idea that my information has already been leaked at some point. I should be generally ready to fix the problems if/when identity theft happens, rather than inconveniencing myself and figuring out the third party trust situation. |
|
| ▲ | TacticalCoder 9 hours ago | parent | prev | next [-] |
| In France the french IRS leaked infos about the wealth of its citizens and evil thieves cross-checked it with leaks of people who ordered hardware wallet for cryptocurrencies and families are getting kidnapped and tortured. In a recent case three family members have been beaten over two days so that... 40 000 EUR could be stolen. That's the world we live in. "Police and thieves", collaborating one way or another (leaking data collected by big brother and then having big brother being very soft on crime is one way to collaborate with evil people), "to scare the nation with their guns and ammunition" (as in the reggae song). As much as I don't like the cryptocurrency ecosystem, I don't think facilitating and encouraging kidnapping and torture is the way to go. Shame on the french government. Two sides of the same coin. |
| |
| ▲ | Frieren 9 hours ago | parent [-] | | > As much as I don't like the cryptocurrency ecosystem, I don't think facilitating and encouraging kidnapping and torture is the way to go. The cryptocurrency ecosystem is used to not only avoid taxation but to enable criminal activity. How many people are being held hostage and the ransom will be payed thanks to cryptocurrencies? I do not like the cryptocurrency ecosystem either. And I totally agree that it should be abolished. It is just a way to finance crime and terrorism. |
|
|
| ▲ | mdp2021 10 hours ago | parent | prev | next [-] |
| > where I'm opposed to talking to my doctor because the information may be digitally recorded and leaked Let me say "Hi mate, +1". State doctors? There are territories in which a pharmacological prescription is shared DB only now (where previously they could be on paper - a secret between you, the pen, the paper, the pharmacist and the gods). Private entities? Good luck finding one that does not require a privacy waiver as a condition for the visit. Searching for a medical dock (a dock for a doc), calling them to ask? "This is a recorded message. If you proceed with the call then you agree..." (Hang-up click). |
| |
| ▲ | astura 8 hours ago | parent [-] | | >previously they could be on paper - a secret between you, the pen, the paper, the pharmacist and the gods Excuse me? If you weren't paying with cash whoever paid for the prescription (govt, insurance) has a record of it. The pharmacy that filled the prescription has a record of it as well as the doctor who wrote it. | | |
| ▲ | mdp2021 8 hours ago | parent [-] | | > cash How can you presume we do not pay with cash?! How can you remotely suppose one sane mind would not use cash for all sensitive private transactions - books, medicines, preferential (profiling) products etc.? We use cash in general because nobody in Dignity would accept their own daily matters to be recorded and given to multiple untrusted parties¹, not to mention potentially retrievable by even more untrusted parties - of course the matter is much more evident for all transactions over confidential items! (¹EU here: 12 public-hybrid-private DBs as per the PSD2 legislation.) | | |
| ▲ | bookofjoe 7 hours ago | parent [-] | | I haven't used physical cash in over two years. (I'm in the U.S.) I'm don't think I'm an outlier. | | |
| ▲ | mdp2021 7 hours ago | parent [-] | | We know you are not an outlier, it is a grave issue that you are not an outlier. Are the elements in your set aware of what they are doing? | | |
| ▲ | bookofjoe 7 hours ago | parent [-] | | I/we know and we don't care. | | |
| ▲ | NooneAtAll3 11 minutes ago | parent | next [-] | | then why are you commenting here if you don't care? | |
| ▲ | mdp2021 6 hours ago | parent | prev [-] | | > we don't care And why did you post that replying to mine, what is the message? We knew that you in the cashless are many. Is it a cry for help - as you know what you are doing but cannot care? Ok: reread the "Book of Joe", which obviously you have heard of, and take your side. Both of them, really: one for morals, one at least for the mentions of the beast requiring its mark for transactions. |
|
|
|
|
|
|
|
| ▲ | chrisjj 9 hours ago | parent | prev | next [-] |
| > I'm baffled how it's not secure. Our civilisation needs to face up to the fact the reason is simply: its stored on a connected computer. |
| |
| ▲ | Tangurena2 8 hours ago | parent [-] | | Too much is stored in computers. In the EU, you own the data about yourself. In the US, whoever owns the computer owns all the data on that computer - you own nothing and you will love it. We need to make PII radioactive and fine everyone who had that data stored on their computer when it leaked. |
|
|
| ▲ | c-fe 8 hours ago | parent | prev | next [-] |
| > they just don't need the data anymore. Thats the wording of GDPR.. that you should delete data after you dont need it anymore for the original purpose.. Unfortunately, it seems noone is enforcing it enough. |
|
| ▲ | KPGv2 7 hours ago | parent | prev | next [-] |
| > my passport may be used to aqquire a loan by cybercriminals In the US, you can freeze your credit, making this impossible (even for yourself). |
|
| ▲ | Hamuko 11 hours ago | parent | prev | next [-] |
| I’m never going to a therapist after one company leaked all of the patient data / therapy notes for 33k patients. |
| |
| ▲ | lux44 10 hours ago | parent [-] | | It looks like you punish yourself unnecessarily, for things that are out of your control. | | |
| ▲ | Hamuko 8 hours ago | parent | next [-] | | Whether or not that data exists to be leaked is entirely within my control though. | |
| ▲ | wyre 9 hours ago | parent | prev | next [-] | | Thanks, I got a good laugh out of this comment, but therapy is just a tool to mostly learn how to deal with things that are outside of your control. | |
| ▲ | childintime 9 hours ago | parent | prev [-] | | A therapist reads like the-rapist, in his case, and in many others. It's bandaid on a failing system, a failing society, and instead of fixing the system the victim has to pay the-rapist. Misaligned incentives all over again. To correct this therapy should be free, because the need for it shouldn't exist. Let the tech billionaires pay for it: if they cause the damage, they have to pay the bill. That'll teach them how to prioritize user satisfaction. > things that are out of your control That's because of corruption. A system that doesn't want to change because some tits can't be let go of. A well working system would render control back to you. | | |
|
|
|
| ▲ | ratg13 11 hours ago | parent | prev | next [-] |
| This is just a general American complaint that has merit on its own, but has nothing to do with the article and is just derailing any discussion about the article itself and driving the conversation to your own personal concerns about something completely separate. In this case, the EU does have consequences for data breaches where proper protocols are not followed. Additionally, this is not private information .. most anyone can look this information up. ID numbers are not confidential information like SSNs are treated in the US.. they are just a number to tell person A from person B. You give this number to everyone without thinking about it because it's how every company you interact with identifies you. In this case a rogue company, or compromised company, used their access to contact the central database to download everyone's information. In my country we essentially use the same system, except for we still allow companies to download the whole database if they want to instead of making individual queries. In this case the access to their system was unauthorized, and under GDPR data breaches have to be reported within 72 hours. Companies can't make the decision on their own that it's not a big deal. |
|
| ▲ | Zealotux 9 hours ago | parent | prev | next [-] |
| [dead] |
|
| ▲ | heresie-dabord 10 hours ago | parent | prev [-] |
| > I don't think [...] these companies [...] can be trusted with my data Abusing privacy is the lucrative norm. The laws won't help you and the government is busy with its corporate agenda. |
| |
| ▲ | hk__2 9 hours ago | parent [-] | | There’s nothing lucrative in abusing privacy, and yes the government is busy but it has nothing to do with a "corporate agenda", any government or any country with more than a few millions of people is busy, agenda or not. |
|