Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is dodging the question. Again: What oversight mechanism can possibly protect users from themselves? They're sending this data, whether they understand it or not.

People keep advocating that drug use should be an educational / health issue, not a legal issue. It's ironic that in this situation, people are calling for the opposite: For the government to step in and protect them, when it's unclear how the government can help without causing all kinds of unintended consequences.

This should be an educational issue, not a legal issue. We should educate users about the ramifications of uploading this data.

Remember, if we enforce regulation, users will still upload sensitive data, and the government will still be free to take advantage of it. Whereas if users are educated about what data they upload, then the data won't exist to begin with.



From: http://idlewords.com/bt14.htm#regulate (copied here because I can't add much more than this).

1. Limit what kind of behavioral data websites can store. When I say behavioral data, I mean the kinds of things computers notice about you in passing—your search history, what you click on, what cell tower you're using.

It's very important that we regulate this at the database, not at the point of collection. People will always find creative ways to collect the data, and we shouldn't limit people's ability to do neat things with our data on the fly. But there should be strict limits on what you can save.

2. Limit how long they can keep it. Maybe three months, six months, three years. I don't really care, as long as it's not fifty years, or forever. Make the time scale for deleting behavioral data similar to the half-life of a typical Internet business.

3. Limit what they can share with third parties. This limit should also apply in the event of bankruptcy, or acquisition. Make people's data non-transferable without their consent.

4. Enforce the right to download. If a website collects information about me, I should be allowed to see it. The EU already mandates this to some extent, but it's not evenly enforced.

This rule is a little sneaky, because it will require backend changes on many sites. Personal data can pile up in all kinds of dark corners in your system if you're not concerned about protecting it. But it's a good rule, and easy to explain. You collect data about me? I get to see it.

5. Enforce the right to delete. I should be able to delete my account and leave no trace in your system, modulo some reasonable allowance for backups.

6. Give privacy policies teeth. Right now, privacy policies and terms of service can change at any time. They have no legal standing. For example, I would like to promise my users that I'll never run ads on my site and give that promise legal weight. That would be good marketing for me. Let's create a mechanism that allow this.

7. Let users opt-in if a site wants to make exceptions to these rules. If today's targeted advertising is so great, you should be able to persuade me to sign up for it. Persuade me! Convince me! Seduce me! You're supposed to be a master advertiser, for Christ's sake!

8. Make the protections apply to everyone, not just people in the same jurisdiction as the regulated site. It shouldn't matter what country someone is visiting your site from. Keep it a world-wide web.


I wanted to reply to your response to me, but...

> What oversight mechanism can possibly protect users from themselves?

The idea isn't, to me at least, to protect users from themselves, but to restrict the ways that companies can use/distribute data collected from the user.

Personally (and I obviously haven't thought this through/deeply in the last 10 minutes or so), I think something like HIPAA for transportation information might be appropriate. It would apply not specifically to Uber, but to any kind of transportation data collected by any company (say, self-driving cars, public transportation, taxi companies, etc.) and would place restrictions on how they can distribute or publicize that data and what kind of permissions they would need from whom.


I like the way that the EU starts from the positions that users have an ownership interest in their data. People can require services to provide them with copies of all personaldata held upon them, and demand the removal of all their personald ata if they terminate their account on the service; in addition there are limits on how much data firms can store on tehir users without explicit opt-ins.

I'm summarizing heavily here, obviously - I haven't lived there for a while so this is neither a nuanced nor a fully current picture. Yes, it limits commercial upside in significant ways, but I think a lot of people here can relate to the idea of a muscular privacy regulator.


Regulation does help protect users in many cases.

For example, around 2009 the US government introduced an act which mandated that whenever a customer pays against credit card debt, the highest interest balance needs to be considered paid first if there are multiple balances at various interest rates. This reduced costs for consumers.

Remember how competition is supposed to solve everything - it did not, all banks were doing the opposite as there was no regulation.


> What oversight mechanism can possibly protect users from themselves?

Never using VC backed services seems to be the first step.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: