Vue lecture

Il y a de nouveaux articles disponibles, cliquez pour rafraîchir la page.
🔲 ☆

Why selling personal data is a bad idea

Prompt: “a field of many different kinds of people being harvested by machines and turned into bales of fertilizer.” Via Microsoft CoPilot | Designer.

This post is for the benefit of anyone wondering about, researching, or going into business on the proposition that selling one’s own personal data is a good idea. Here are some of my learnings from having studied this proposition myself for the last twenty years or more.

  1. The business does exist. See eleven companies in Markets for personal data listed among many other VRM-ish businesses on the ProjectVRM wiki.
  2. The business category harvesting the most personal data is adtech (aka ad tech and “programmatic”) advertising, which is the surveillance-based side of the advertising business. It is at the heart of what Shoshana Zuboff calls surveillance capitalism, and is now most of what advertising has become online. It’s roughly a trillion-dollar business. It is also nothing like advertising of the Mad Men kind. (Credit where due: old-fashioned advertising, aimed at whole populations, gave us nearly all the brand names known to the world). As I put it in Separating Advertising’s Wheat and Chaff, Madison Avenue fell asleep, direct response marketing ate its brain, and it woke up as an alien replica of itself.
  3. Adtech pays nothing to people for their data or data about them. Not personally. Google may pay carriers for traffic data harvested from phones, and corporate customers of auctioned personal data may pay publishers for moments in which ads can be placed in front of tracked individuals’ ears or eyeballs. Still, none of that money has ever gone to individuals for any reason, including compensation for the insults and inconveniences the system requires. So there is little if any existing infrastructure on which paying people for personal data can be scaffolded up. Nor are there any policy motivations. In fact,
  4. Regulations have done nothing to slow down the juggernaut of growth in the adtech industry. For Google, Facebook, and other adtech giants, paying huge fines for violations (of the GDPR, the CCPA, the DMA, or whatever) is just the cost of doing business. The GDPR compliance services business is also in the multi-$billion range, and growing fast. In fact,
  5. Regulations have made the experience of using the Web worse for everyone. Thank the GDPR for all the consent notices subtracting value from every website you visit while adding cognitive overhead and other costs to site visitors and operators. In nearly every case, these notices are ways for site operators to obey the letter of the GDPR while violating its spirit. And, although all these agreements are contracts, you have no record of what you’ve agreed to. So they are worse than worthless.
  6. Tracking people without their clear and conscious invitation or a court order is wrong on its face. Period. Full stop. That tracking is The Way Things Are Done online does not make it right, any more than driving drunk or smoking in crowded elevators was just fine in the 1950s. When the Digital Age matures, decades from now, we will look back on our current time as one thick with extreme moral compromises that were finally corrected after the downsides became clear and more ethically sound technologies and economies came along. One of those corrections will be increasing personal agency rather than just corporate capacities. In fact,
  7. Increasing personal independence and agency will be good for markets, because free customers are more valuable than captive ones. Having ways to gather, keep, and make use of personal data is an essential first step toward that goal. We have made very little progress in that direction so far. (Yes, there are lots of good projects listed here, but there we still a long way to go.)
  8. Businesses being “user-centric” will do nothing to increase customers’ value to themselves and the marketplace. First, as long as we remain mere “users” of others’ systems, we will be in a subordinate and dependent role. While there are lots of things we can do in that role, we will be able to do far more if we are free and independent agents. Because of that,
  9. We need technologies that create and increase personal independence and agency. Personal data stores (aka warehouses, vaults, clouds, life management platforms, lockers, and pods) are one step toward doing that. Many have been around for a long time: ProjectVRM currently lists thirty-three under the Personal Data Stores heading. Some have been there a long time. The problem with all of them is that they are still too focused on what people do as social beings in the Web 2.0 world, rather than on what they can do for themselves, both to become more well-adjusted human beings and more valuable customers in the marketplace. For that,
  10. It will help to have independent personal AIs. These are AI systems that work for us, exclusively. None exist yet. When they do, they  will help us manage the personal data that fully matters:
    • Contacts—records and relationships
    • Calendars—where we’ve been, what we’ve done, with whom, where, and when
    • Health records and relationships with providers, going back all the way
    • Financial records and relationships, including past and present obligations
    • Property we have and where it is, including all the small stuff
    • Shopping—what we’ve bought, plan to buy, or might be thinking about,
    • Subscriptions—what we’re paying for, when they end or renew, what kind of deal we’re locked into, and what better ones might be out there.
    • Travel—Where we’ve been, what we’ve done, with whom, and when

Personal AIs are today where personal computers were fifty years ago. Nearly all the AI news today is about modern mainframe businesses: giants with massive data centers churning away on ingested data of all kinds. But some of these models are open sourced and can be made available to any of us for our own purposes, such as dealing with the abundance of data in our own lives that is mostly out of control. Some of it has never been digitized. With AI help it could be.

I’m in a time crunch right now. So, if you’re with me this far, read We can do better than selling our data, which I wrote in 2018 and remains as valid as ever. Or dig The Intention Economy: When Customers Take Charge (Harvard Business Review Press, 2012), which Tim Berners Lee says inspired Solid. I’m thinking about following it up. If you’re interested in seeing that happen, let me know.

🔲 ☆

If Your Privacy Is in the Hands of Others Alone, You Don’t Have Any

Prompt: “A panopticon in which thousands of companies are spying on one woman alone in the center with nothing around her.” Via Microsoft Bing Image Creator

In her latest Ars Technica story, Ashley Belanger reports that Patreon, the widely used and much-trusted monetization platform for creative folk, opposes the minimal personal privacy protections provided by a law you probably haven’t heard of until now: the Video Privacy Protection Act, or VPPA. Patreon, she writes, wants a judge to declare that law (which dates from the videotape rental age) unconstitutional because it inconveniences Patreon’s ability to share the personal data of its users with other parties.† Naturally, the EFF, the Center for Democracy & Technology, the ACLU of Northern California, and the ACLU itself all stand opposed to Patreon on this and have filed an amicus brief explaining why.

But I’m not here to talk about that. I’m here to bring up the inconvenient fact that Ars Technica is also in the surveillance business. A PageXray of Ashley’s story finds this—

  • 360 adserver requests
  • 259 tracking requests
  • 131 other requests

—which it visualizes with this:

And that’s just one small part of it.

But will Ashley, or any reporter, grab the third rail of their employer’s participation in the tracking-based advertising business? Or visit that business’s responsibility for what was already the biggest boycott in human history way back in 2015? The odds are against it. I’ve challenged many reporters to grab that third rail, just like I’m challenging Ashley here. In every case, nothing happened.

I never challenged Farhad Manjoo, but he did come through exposing The New York Times (his employer’s) own participation in the privacy-opposed tracking-based adtech business, back in 2019. Here’s a PageXray of tracking via that piece today:

Better, but not ideal.

Five years ago this month, I wrote a column about privacy in Linux Journal with the same title as this post. Here it is again, with just a few tiny edits. Amazing how little things have changed since then—and how much worse they have become. But I do see hope. Read on.


If you think regulations are going to protect your privacy, you’re wrong. In fact, they can make things worse, especially if they start with the assumption that your privacy is provided only by other parties, most of whom are incentivized to violate it.

Exhibit A for how much worse things can get is the EU’s GDPR (General Data Protection Regulation). As soon as the GDPR went into full effect in May 2018, damn near every corporate entity on the Web put up a “cookie notice” requiring acceptance of terms and privacy policies that allow them to continue violating your privacy by harvesting, sharing, auctioning off and otherwise using your data, and data about you.

For websites and services in that harvesting business (a population that rounds to the whole commercial web), these notices provide a one-click way to adhere to the letter of the GDPR while violating its spirit.

There’s also big business in the friction that it produces. To see how big, look up GDPR+compliance on Google. You’ll get 232 million results (give or take a few dozen million).

None of those results are for you, even though you are who the GDPR is supposed to protect. See, to the GDPR, you are a mere “data subject” and not an independent and fully functional participant in the technical, social, and economic ecosystem the Internet supports by design. All privacy protections around your data are the burden of other parties.

Or at least that’s the interpretation that nearly every lawmaker, regulatory bureaucrat, lawyer, and service provider goes by. (One exception is Elizabeth Renieris @hackylawyer. Her collection of postings is required reading on the GDPR and much else.) The same goes for those selling GDPR compliance services, comprising most of those 190 million GDPR+compliance search results.

The clients of those services include nearly every website and service on Earth that harvests personal data. These entities have no economic incentive to stop harvesting, sharing, and selling personal data the usual ways, beyond fear that the GDPR might actually be enforced, which so far (with few exceptions), it hasn’t been. (See Without enforcement, the GDPR is a fail.)

Worse, the tools for “managing” your exposure to data harvesters are provided entirely by the websites you visit and the services you engage. The “choices” they provide (if they provide any at all) are between 1) acquiescence to them doing what they please and 2) a maze of menus full of checkboxes and toggle switches “controlling” your exposure to unknown threats from parties you’ve never heard of, with no way to record your choices or monitor effects.

So let’s explore just one site’s presentation, and then get down to what it means and why it matters.

Our example is https://www.mirror.co.uk. If you haven’t clicked on that site already, you’ll see a cookie notice that says,

We use cookies to help our site work, to understand how it is used, and to tailor the adverts presented on our site. By clicking “Accept” below, you agree to us doing so. You can read more in our cookie notice. Or, if you do not agree, you can click Manage below to access other choices.

They don’t mention that “tailor the adverts” really means something like this:

We open your browser to infestation by tracking beacons from countless parties in the online advertising business, plus who-knows-what-else that might be working with those parties (there is no way to tell, and if there was we wouldn’t provide it), so those parties and their “partners” can use those beacons to follow you like a marked animal everywhere you go and report your activities back to a vast marketplace where personal data about you is shared, bought and sold, much of it in real time, supposedly so your eyeballs can be hit with “relevant” or “interest-based” advertising as you travel from site to site and service to service. While we are sure there are bad collateral effects (fraud and malware, for example), we don’t care about those because it’s our business to get paid just for clicks or “impressions,” whether you’re impressed or not—and the odds that you won’t be impressed average to certain.

Okay, so now click on the “Manage” button.

Up will pop a rectangle where it says “Here you can control cookies, including those for advertising, using the buttons below. Even if you turn off the advertising-related cookies, you will still see adverts on our site, because they help us to fund it. However, those adverts will simply be less relevant to you. You can learn more about cookies in our Cookie Notice on the site.”

Under that text, in the left column, are six “Purposes of data collection”, all defaulted with little check marks to ON (though only five of them show, giving the impression that there are only those five). The right column is called “Our partners”, and it shows the first five of what turn out to be 259 companies, nearly all of which are not brands known to the world or to anybody outside the business (and probably not known widely within the business as well). All are marked ON by that little check mark. Here’s that list, just through the letter A:

  • 1020, Inc. dba Placecast and Ericsson Emodo
  • 1plusX AG
  • 2KDirect, Inc. (dba iPromote)
  • 33Across
  • 7Hops.com Inc. (ZergNet)
  • A Million Ads Limited
  • A.Mob
  • Accorp Sp. z o.o.
  • Active Agent AG
  • ad6media
  • ADARA MEDIA UNLIMITED
  • AdClear GmbH
  • Adello Group AG
  • Adelphic LLC
  • Adform A/S
  • Adikteev
  • ADITION technologies AG
  • Adkernel LLC
  • Adloox SA
  • ADMAN – Phaistos Networks, S.A.
  • ADman Interactive SL
  • AdMaxim Inc.
  • Admedo Ltd
  • admetrics GmbH
  • Admotion SRL
  • Adobe Advertising Cloud
  • AdRoll Inc
  • adrule mobile GmbH
  • AdSpirit GmbH
  • adsquare GmbH
  • Adssets AB
  • AdTheorent, Inc
  • AdTiming Technology Company Limited
  • ADUX
  • advanced store GmbH
  • ADventori SAS
  • Adverline
  • ADYOULIKE SA
  • Aerserv LLC
  • affilinet
  • Amobee, Inc.
  • AntVoice
  • Apester Ltd
  • AppNexus Inc.
  • ARMIS SAS
  • Audiens S.r.l.
  • Avid Media Ltd
  • Avocet Systems Limited

If you bother to “manage” any of this, what record do you have of it—or of all the other collections of third parties who you’ve agreed to follow you around? Remember, there are a different collection of these at every website with third parties that track you, and different UIs, each provided by other third parties.

It might be easier to discover and manage parasites in your belly than cookies in your browser.

Think I exaggerate? The long list of cookies in just one of my browsers (which I had to dig deep to find) starts with this list:

After several hundred others, my cookie  list ends with:

I know what zoom.us is. The rest are a mystery to me.

To look at just that first one, 1rx.io, I have to dig way down in the basement of the preferences directory (in Chrome it’s chrome://settings/cookies/detail?site=1rx.io), where I find that its locally stored data is this:

_rxuuid

Name
_rxuuid
Content
%7B%22rx_uuid%22%3A%22RX-2b58f1b1-96a4-4e1d-9de8-3cb1ca4175b0%22%2C%22nxtrdr%22%3Afalse%7D
Domain
.1rx.io
Path
/
Send for
Any kind of connection
Accessible to script
No (HttpOnly)
Created
Wednesday, December 12, 2018 at 4:48:53 AM
Expires
Thursday, December 12, 2019 at 4:48:53 AM

I’m a somewhat technical guy, and at least half of that stuff means nothing to me.

As for “managing” those,  my only choice on that page is to “Remove All”. Does that mean Remove everything on that page alone or Remove all cookies everywhere? And how can I remember what I’ve had removed?

Obviously, there is no way for anybody to “manage” this, in any meaningful sense of the word.

We also can’t fix it on the sites and services side, no matter how much those sites and services care (which most don’t) about the “customer journey”, the “customer experience” or any of the other bullshit they’re buying from marketers this week.

Even within the CRM (customer relationship management) world, the B2B customers of CRM companies use one cloud and one set of tools to create as many different “experiences” for users and customers as there are companies deploying those tools to manage customer relationships from their side.  There are no corresponding tools on our side. (Though there is work going on. See here.)

So the digital world remains one where we have no common or standard way to scale our privacy and data usage tools, choices, or experiences across all sites and services. And that’s what we’ll need if we want real privacy online.

The simple place where we need to start is this: privacy is personal, meaning something we create for ourselves (which in the natural world we do with clothing and shelter, both of which lack equivalents in the digital world).

And we need to be clear that privacy is not a grace of privacy policies and terms of service that differ with every company and over which none of us have true control—especially when there is an entire industry devoted to making those companies untrustworthy, even if they are in full compliance with privacy laws.

Devon Loffreto (who coined the term self-sovereign identity and whose good work we’ll be visiting in an upcoming issue of Linux Journal) puts the issue in simple geek terms: we need root authority over our lives. Hashtag: #OwnRoot.

It is only by owning root that we can crank up agency on the individual’s side. We have a perfect base for that in the standards and protocols that gave us the Internet, the Web, email, and too little else. And we need it here too. Soon.

We (a few colleagues and I) created Customer Commons as a place for terms that individuals can proffer as first parties, just by pointing at them, much as licenses at Creative Commons can be pointed at. Sites and services can agree to those terms, and both can keep records and follow audit trails.

And there are some good signs that this will happen. For example, the IEEE approached Customer Commons last year with the suggestion that we stand up a working group for machine-readable personal privacy terms. It’s called P7012. If you’d like to join, please do.

Unless we #OwnRoot for our own lives online, privacy will remain an empty promise by a legion of violators.

One more thing. We can put the GDPR to our use if we like. That’s because Article 4 of the GDPR defines a data controller as “the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data…” This means each of us can be our own data controller. Most lawyers dealing with the GDPR don’t agree with that. They think the individual data subject will always need a fiduciary or an intermediary of some kind: an agent of the individual, but not an individual with agency. Yet the simple fact is that we should have root authority over our lives online, and that means we should have some degree of control over our data exposures, and how our data, and data about us, is used—much as we do over how we control or moderate our privacy in the physical world. More about all that in upcoming posts.

The original version of this post was published on the Private Internet Access blogPrivate Internet Access and Linux Journal at the time were both holdings of London Trust Media.

Also, check out the Privacy Manifesto at the ProjectVRM wiki. I maintain it and welcome bug fixes.

† This is an example of what Cory Doctorow calls “enshittification” and Wikipedia (at that link) more politely calls “platform decay.” It’s a big trade-away of goodwill by Patreon. Says to me they must be making an enshitload of money in the adtech fecosystem.

🔲 ☆

Coming soon to a radio near you: Personalized ads

And privacy be damned.

See, there is an iron law for every new technology: What can be done will be done. And a corollary that says, —until it’s clear what shouldn’t be done.  Let’s call those Stage One and Stage Two.

With respect to safety from surveillance in our cars, we’re at Stage One.

For Exhibit A, read what Ray Schultz says in Can Radio Time Be Bought With Real-Time Bidding? iHeartMedia is Working On It:

HeartMedia hopes to offer real-time bidding for its 860+ radio stations in 160 markets, enabling media buyers to buy audio ads the way they now buy digital.

“We’re going to have the capabilities to do real-time bidding and programmatic on the broadcast side,” said Rich Bressler, president and COO of iHeart Media, during the Goldman Sachs Communacopia + Technology Conference, according to Radio Insider.

Bressler did not offer specifics or a timeline. He added: “If you look at broadcasters in general, whether they’re video or audio, I don’t think anyone else is going to have those capabilities out there.”

“The ability, whenever it comes, would include data-infused buying, programmatic trading and attribution,” the report adds.

The Trade Desk lists iHeart Media as one of its programmatic audio partners.

Audio advertising allows users to integrate their brands into their audiences’ “everyday routines in a distraction-free environment, creating a uniquely personalized ad experience around their interests,” the Trade Desk says.

The Trade Desk “specializes in real-time programmatic marketing automation technologies, products, and services, designed to personalize digital content delivery to users.” Translation: “We’re in the surveillance business.”

Never mind that there is negative demand for surveillance by the surveilled. Push-back has been going on for decades.  Here are 154 pieces I’ve written on the topic since 2008.

One might think radio is ill-suited for surveillance because it’s an offline medium. Peopler listen more to actual radios than to computers or phones. Yes, some listening is online; but  not much, relatively speaking. For example, here is the bottom of the current radio ratings for the San Francisco market:

Those numbers are fractions of one percent of total listening in the country’s most streaming-oriented market.

So how are iHeart and The Trade Desk going to personalize radio ads?  Well, here is a meaningful excerpt from iHeart To Offer Real-Time Bidding For Its Broadcast Ad Inventory, which ran earlier this month at Inside Radio:

The biggest challenge at iHeartMedia isn’t attracting new listeners, it’s doing a better job monetizing the sprawling audience it already has. As part of ongoing efforts to sell advertising the way marketers want to transact, it now plans to bring real-time bidding to its 850 broadcast radio stations, top company management said Thursday.

“We’re going to have the capabilities to do real-time bidding and programmatic on the broadcast side,” President and COO Rich Bressler said during an appearance at the Goldman Sachs Communacopia + Technology Conference. “If you look at broadcasters in general, whether they’re video or audio, I don’t think anyone else is going to have those capabilities out there.”

Real-time bidding is a subcategory of programmatic media buying in which ads are bought and sold in real time on a per-impression basis in an instant auction. Pittman and Bressler didn’t offer specifics on how this would be accomplished other than to say the company is currently building out the technology as part of a multi-year effort to allow advertisers to buy iHeart inventory the way they buy digital media advertising. That involves data-infused buying and programmatic trading, along with ad targeting and campaign attribution.

Radio’s largest group has also moved away from selling based on rating points to transacting on audience impressions, and migrated from traditional demographics to audiences or cohorts. It now offers advertisers 800 different prepopulated audience segments, ranging from auto intenders to moms that had a baby in the last six months…

Advertisers buy iHeart’s ad inventory “in pieces,” Pittman explained, leaving “holes in between” that go unsold. “Digital-like buying for broadcast radio is the key to filling in those holes,” he added…

…there has been no degradation in the reach of broadcast radio. The degradation has been in a lot of other media, but not radio. And the reason is because what we do is fundamentally more important than it’s ever been: we keep people company.”

Buried in that rah-rah is a plan to spy on people in their cars. Because surveillance systems are built into every new car sold. In Privacy Nightmare on Wheels’: Every Car Brand Reviewed By Mozilla — Including Ford, Volkswagen and Toyota — Flunks Privacy Test, Mozilla pulls together a mountain of findings about just how much modern cars spy on their drivers and passengers, and then pass personal information on to many other parties. Here is one relevant screen grab:

spying

As for consent? When you’re using a browser or an app, you’re on the global Internet, where the GDPR, the CCPA, and other privacy laws apply, meaning that websites and apps have to make a show of requiring consent to what you don’t want. But cars have no UI for that. All their computing is behind the dashboard where you can’t see it and can’t control it. So the car makers can go nuts gathering fuck-all, while you’re almost completely in the dark about having your clueless ass sorted into one or more of Bob Pittman’s 800 target categories. Or worse, typified personally as a category of one.

Of course, the car makers won’t cop to any of this. On the contrary, they’ll pretend they are clean as can be. Here is how Mozilla describes the situation:

Many car brands engage in “privacy washing.” Privacy washing is the act of pretending to protect consumers’ privacy while not actually doing so — and many brands are guilty of this. For example, several have signed on to the automotive Consumer Privacy Protection Principles. But these principles are nonbinding and created by the automakers themselves. Further, signatories don’t even follow their own principles, like Data Minimization (i.e. collecting only the data that is needed).

Meaningful consent is nonexistent. Often, “consent” to collect personal data is presumed by simply being a passenger in the car. For example, Subaru states that by being a passenger, you are considered a user — and by being a user, you have consented to their privacy policy. Several car brands also note that it is a driver’s responsibility to tell passengers about the vehicle’s privacy policies.

Autos’ privacy policies and processes are especially bad. Legible privacy policies are uncommon, but they’re exceptionally rare in the automotive industry. Brands like Audi and Tesla feature policies that are confusing, lengthy, and vague. Some brands have more than five different privacy policy documents, an unreasonable number for consumers to engage with; Toyota has 12. Meanwhile, it’s difficult to find a contact with whom to discuss privacy concerns. Indeed, 12 companies representing 20 car brands didn’t even respond to emails from Mozilla researchers.

And, “Nineteen (76%) of the car companies we looked at say they can sell your personal data.”

To iHeart? Why not? They’re in the market.

And, of course, you are not.

Hell, you have access to none of that data. There’s what the dashboard tells you, and that’s it.

As for advice? For now, all I have is this: buy an old car.

 

 

❌