upvote
>I simply stopped worrying and began to love the bomb

This may apply to the consequences of ones data being subject to so many breaches and leaks and thefts, but it should not be the attitude one adopts towards the idea of ones data being taken and used by so many parties. At some level, my data is my personhood - it is my evidence of myself, and my record of myself, and my proof of myself. It encodes who I talk to, what I'm interested in, where I go, and what I do. My health, my finances, my habits, vices, schedule, family, friends, coworkers, beliefs. People more clever than myself use this data to advertise to me; people more powerful use this data to surveil me. When will people more malevolent use this data to persecute me?

I should not have to love the bomb because the bomb will kill me.

reply
Yes, that's the direct subtext of that phrase.
reply
well isn’t the point of the movie that if you have a doomsday-(dead man switch)-device you should let everyone know?

I don’t get that comparison with data being available everywhere

reply
Some of us are more practical than ideological, but we tend not to put as much energy into communicating our views as the ideological types. The result online is an often distorted sense of the universality and importance of ideology. You feel That your data is part of your personhood? I feel that it’s more like tracks in the woods and scat.
reply
Loss of privacy has no upsides. The bomb, on the other hand, saved many millions of lives over the last 80 years, so it works as a metaphor everyone shares, but the metaphor itself was always much more arguable with nukes. It's possible to actually rationally love the bomb, but what are the upsides for everything about me being exfiltrated at will?
reply
The upside is that you can know everything of almost any person as well. Whether that upside is beneficial for you is a different matter.
reply
Oh, but of course there is. He you ever seen arguments from the other side? It is to catch criminals of various sorts (money laundering, trafficking, smuggling goods and people, terrorism etc), to keep children safe etc etc.

Also,it can help you uncover and put behind bars your dangerous political enemies. That the tables may turn and the shoe may be on the other foot soon, that's too abstract of a thought to occur to most of them.

reply
It tracks terrorists' efforts to acquire the bomb.
reply
It’s not the current use of the data that’s concerning, it’s its future use. Who’s to say that some facet of your life that is ordinary now will not one day paint you as the target of some future regime? It happened in Europe a few decades ago, and in many other countries around the world.
reply
Yeah, like the way US citizens now are not targeted at all by ICE because their data is out there? Future evil government will not care about your data, they can just invent shit. The idea is to instill fear and uncertainty not "finding the correct people".

On the other hand, said data can be today use because various entities use extremely shitty authentication methods, like just insert your birthday and first name and voila you have a credit with our bank (not an actual example, just for illustration purposes).

reply
To be zen about one's privacy is easier for some people than others.

There are situations in many a person's life that if revealed to the public would have life-altering consequences.

Rather than the world give up, we should have better tools and laws to flood the internet with spurious personal data.

reply
Similarly. My browser was carefully containerized, with a ton of anti fingerprinting measures, VPN, Linux, Librewolf, everything. Even on my phone, I restricted whatever possible. Then one day I went to the YouTube main page, and I saw that Google somehow got to know that I played Minecraft again after a decade. I gave up right there. I suffered to avoid this, and it was pointless. I knew at that point already that probably all my PI is public information anyway, but I wanted to restrict whatever possible, and no, everybody sells my data anyway, and it seems that avoiding fingerprinting is impossible without turning off the internet completely, and ditching smart phones.
reply
> Google somehow got to know that I played Minecraft again after a decade. [...] I knew at that point already that probably all my PI is public information anyway

How are you jumping from Minecraft (probably one of the most watchtime-generating content types out there) being displayed on your main page to… your personal information being known to everyone?

reply
It wasn't a jump. At that time (about a year ago), I already knew that almost all of my traditional PI is leaked (phone numbers, ID numbers, etc), so I tried to prevent to leak my thoughts further. Basically my last non-public PI. And I tried that for years. And I'm quite sure after my trials, that it's impossible without giving up the internet. My traditional PI would leak even if I don't use the internet at all, since for example one time they leaked from my employer at that time. That's a lost cause even with that sacrifice.
reply
Your data is still out there, just compartmentalized so each outside party only has a bit. It turns out that's a losing strategy when each outside party decides to cooperate with every other and pool/share/sell that data uniquely attached to you.
reply
Even porn ads are linked with your normal browsing
reply
because it’s the same process of intermediaries accumulating, inferring and sharing data to each other

intermediaries that will be compromised

reply
> because it’s the same process of intermediaries accumulating, inferring and sharing data to each other

Except that YouTube doesn't need any of that to recommend Minecraft videos to you. One mundane explanation that seems more likely is that it's the type of content that on average works best on people they don't yet have information on.

Reminds me a little of these "phones listen to everything we say, otherwise I wouldn't have been shown this ad" anecdotes that don't hold up against empiric evidence.

reply
You saw the LG TV exposé? They do speech transcription on the TV and so have available for upload the logs for audio even when the TV is off.

Microsoft would definitely sell data on which IPs have Minecraft users, as would your DNS provider, cloudflare, or your ISP.

It could also be coincidence, though my experience is YouTube's suggestion algo is very tightly tracked to use data. (What I was fed on a guest account recently was a mix of fascist propaganda and AI nonsense masquerading as reportage.

reply
> Reminds me a little of these "phones listen to everything we say, otherwise I wouldn't have been shown this ad" anecdotes that don't hold up against empiric evidence.

If phones weren't listening technology like audio beacons couldn't have been invented or useful (https://medium.com/@williamwais01/ultrasonic-beacons-the-sil...).

Surveillance capitalism has been so successful because it's so opaque. It would take a whistleblower for you to know when and how the data companies have is used against you, or how they got that data in the first place. Their tactics can be used in ways that are highly targeted and transient, especially for data collection companies like Google.

Even for something as basic as search results what I see when I search may not be what you see, and what I today might not be what I see when I take the same actions tomorrow.

This can make identifying what our phones are doing almost impossible. A possible explanation for the "phones listen to everything we say, otherwise I wouldn't have been shown this ad" phenomenon might be that a phone picked up an audio beacon being broadcast while something played on a TV, which sparked a related conversation in the person carrying the phone. The conversation wasn't recorded, but topic being discussed was successfully logged anyway. There are countless other data points available that could be used in the same way. In cases like that it would clearly not be coincidence that Google showed an ad when it did, but the spying involved was even more involved and invasive than just listening to what was being said.

There's nothing to stop Google from having small clusters of phones listening to everything for certain periods of time under certain circumstances. They wouldn't have to send all that audio data back to their servers to be effective, just monitor for a sample of specific words/phrases (processed on device) and send back a flag when something is overheard. That kind of behavior would be extremely hard for researchers to catch.

The truth is that we're not allowed to know how and when we're being surveilled, but we are being watched all the time, and that data is collected to be sold or used against us at every opportunity. It doesn't do any good to tell the person imprisoned in the panopticon that he's being paranoid and that it's all coincidental. Even when it happens to be, feeling watched is the natural response.

reply
I guess I was selected for the cohort "never show a useful ad to hide we're listening" even if I don't try to protect a lot (except an add blocker in a navigator).

Honestly I wish I would get more targeted ads for the stuff I look for, when I look. Instead, for some, it happens that after I buy them, I get repeated ads after couple of weeks or even months (like, invoice is on gmail, photos of the object on my phone, but nooo they want to trick me, so they still send me more ads of the same shit that I will not buy again in years).

Seriously, I think the tracking is as crappy as most software is. Sure, it might identify one/two keywords and throw ads at you, but it does it a dumb volume way that corporations work, not in a smart "we know everything about you way", that a true geek might implement.

reply
It's absolutely true that companies are pretty horrible at actually targeting ads.

Right now the amount of data about you companies have is just massive. Everywhere you are at every moment of the day, who you were with, what you talk about, everything you buy, and every website you visit, what your mood is, what your level of education is, how you react to stress, it's all too much information for companies to extract useful data out of right now. AI is going to help with that. Unfortunately, like everything else AI does, it will do it pretty badly and with lots of errors and hallucinations. The companies using AI won't care though as long it works enough times on enough people that they make money.

To make matters worse, ads are only a small part of what all that data is used for. It's the thing that's most visible to you though, so you can imagine that if your ads show that companies think the wrong things about you that HR departments and other companies you interact with offline probably do too.

reply
>My browser was carefully containerized, with a ton of anti fingerprinting measures, VPN, Linux, Librewolf, everything

Doesn't that just make your browser very unique?

reply
Yes. Its a fingerprinting paradox that the more you do to obfuscate the better they can pick you out of the crowd.
reply
It is unique in a new way every page view.
reply
It's way better to do that than hope that you've managed to cover every possible means of fingerprinting. When trying to make your fingerprint as common as possible it only takes a single consistent data point to identify you, and new techniques pop up all the time. TOR browser is a good example of what not to do.
reply
>Then one day I went to the YouTube main page, and I saw that Google somehow got to know that I played Minecraft again after a decade

Did you play minecraft on the same network? If so, I'm not sure why the results are surprising or why it would negate all your efforts. If someone else played minecraft on your network you would also see a minecraft video on your main page I would imagine.

reply
You are talking about a network which is used by 10-100-1000 thousands of people. Yet, they knew when I started to play Minecraft. With this logic, I should see Minecraft videos all the time, but I didn't, for over a decade.
reply
That's worse. My family or housemates can infer what activity I've been up to online by watching their YouTube recommendations?
reply
If your family or housemates wanted to know what you did online they could just flash DD-WRT onto the router and turn on logging.
reply
These swings can be avoided by not doing stuff so hard but instead more effectively.

For example, matrix sucks ass. It's terrible. Everything about it is a bad experience. Of course you'd want to eventually stop using it and go back to the previous life.

But that is not the correct take-away.

The correct take away is to include UX (and honesty to yourself about it) in the calculation and to not go all in on an unsustainable compromise, just to then snap back to doing the opposite ca 3 months later.

Same as with loosing weight, really. If you replace 100% of the pleasure of eating with the "right" but unpleasant solutions, you will not be able to keep that diet going indefinitely.

reply
We use xmpp in the family and the experience is good enough. I wish WhatsApp would support official federation and it would be perfect.
reply
This makes me think: how would someone like Mark Zuckerberg handle this for his own internet presence? Or does he sidestep this issue completely by having assistants for nearly everything? I can imagine he doesn't do much more than look at .ppts and fire off emails. Do data brokers have any information at all on this guy?
reply
There's concierge services for this kind of data removal. At a certain level of wealth I assume there are teams working on this with lawyers 24/7.
reply
Not just lawyers. You get a personal physical and cybersecurity team in most cases. Most largeish businesses also have a dedicated physical security team as well.

You as a normal individual simply cannot replicate the kinds of services that an Executive Protection services provide [0][1].

[0] - https://www.pinkerton.com/services/high-net-worth-individual...

[1] - https://vespergroup.se/en/

reply
I bet you could find his SSN if you looked.
reply
It would be funny, if there was a website anywhere, which accumulates data about all the tech giant C levels and shares it with the public, just like they share data about all of use behind closed doors to manipulate us and sell us shit, or sell our data to the next tier of data hungry businesses.

Probably wouldn't last long though, as they would be furious, that us lowly human beings are able to glean anything about them. The double standard of this is not obvious to them.

reply
The next frontier is to maintain 'limited privacy'.

That's denying most culprits the opportunity to use the collected data against you.

Like always on VPN, turning off personalization, ad guards and using open source products where possible.

reply
> The next frontier is to maintain 'limited privacy'.

The real next frontier is to maintain one or more carefully curated personas with various companies to optimize how they treat you. Wear shabby clothes and fake beards when grocery shopping so that the cameras think you're poor. Security will be all over you, but the digital price tags will give you lower prices as long as you don't have your cell phone on you and they can't get a good face ID because then they won't be able to pull up your actual income level.

Create and maintain specially crafted social media accounts filled with fake hobbies and AI generated photos but never express an actual opinion on anything at all so that future employers can see you have a "presence" but they won't see anything that might disqualify you a job, like your political views.

Buy multiple high/low end devices and rent a closet or PO box in both rich and poor neighborhoods so that you can selectively hand out a mailing address that will make you appear either poor or well off.

Pay someone to take your cell phone out them on friday night so that you can appear more socially active otherwise you'll be flagged as anti-social which can impact employment, raise your health insurance rates, etc.

reply
It's a bit like physical security of your house - could someone break into my house, not easily but it's a house not a bank vault. Keeping our gate closed and having a large dog (who is actually very friendly) about the place probably keeps the vast majority of possible thieves away.
reply
That's still a bit on the obsessive side. The reasonable position is the same as it always has been in the real world too:

- Don't volunteer your intimate details left and right;

- Feel entitled to deny requests for unnecessary data (and advocate for such rights if you're in position to)

- Otherwise don't sweat it, because you can't actually control what others know about you, you never could

reply
The trouble with this is the baseline is getting to high. You've got age verification coming, google rolling out phone verification for websites, etc. Once that is rolled out, accepted and "easy" it will be used for everything important "for security" and then everything not important because hey, you were doing anyway?

The reasonable position will be slow marched into hell same as the rest of them, just a few steps behind.

reply
I feel like this is the best compromise. Thanks for wording it.
reply
I agree.

And most people on the behavioral side do too, but not at the cognitive level. EU is the best example with EU AI Act, strict data regulation as well as privacy rights, on the other hand demanding that Apple does serve the EU with AI.

I have mainly one distinction: the state is the worst protector of your data and the most ruthless gatherer of all your details.

Opposite to the open sourcing of your data in the end by the state are private companies who live by your data but do this for 20+ years - battle tested protection and hardening against malicious hackers.

Security is their business while security for the state is a cost factor.

Being at the mercy of some ignorant politician is not the best way to talk about data security.

Berlin, Denmark - those are the known one. And there are many more to come.

And regarding cognitive dissonance: politicians demanding high standards and punishing data loss ruthlessly on the one hand, giving oneself a pass on a hack is nothing to increase trust into the system.

X got fined for a missing blue mark. Berlin? Denmark? Others?

A second aspect is that the average guy doesn’t get that part of the whole spectrum must be the degooglers, the home server guys.

So it is relatively easy to get data on them as well just by filtering out the other data.

In other words: 95% not doing degoogling makes for a great small sample of 5%. Negating and interpolating other demographic and psychographic factors and you get a great way of gaining insights.

And remember: being the one who is not using google when being around other guys who do - magic.

So my idea is simple: what’s in it for me, and the state offers way lower value than Google and co.

Pick your fate.

reply
> I have mainly one distinction: the state is the worst protector of your data and the most ruthless gatherer of all your details.

How many state data breaches vs corporate data breaches? There are hundreds of state entities with my data (probably thousands), and yet private companies with my data have been hacked more times.

reply
> and yet private companies with my data have been hacked more times.

...and yet private companies with my data have been hacked more times, so far.

Also they might have not been targeted....

reply
I think both are possible. To have a goal and to accept reality. I would not draw the conclusion that all privacy measures are meaningless. It is hard, but I think it is still worth working towards a goal of better privacy for citizens.
reply
> wasted effort

That depends. One thing is following precautions, another the Principles. Precautions may have a limit ("due diligence done, I'll stop there"), Principles do not.

Remember also that many phenomena occur because the individuals in the masses have not said "no". Acceptance enabled them. So the acceptance of some ill conceived systems is criminal - it is what lets them exist.

reply
Two problems with that:

1. I don't want to love it. I hate it. You can learn to live with things you hate though, and not have it impact your day to day life or mental health though.

2. Its still a bomb. Until we find out how we can de-value the data, it will have an incentive to be stolen.

One thought here that I don't personally agree with, but might be important regardless:

Imagine a society without secrets or privacy at all for example.

I don't personally like the sounds of it, but it is sort of where we're headed at the moment, and if the fundamental reality is that obtaining data is much more easy than defending it, then perhaps we need to come to terms with a world without privacy, and how to create the best version of that unconstrained world.

Again, I don't like the sounds of this, but I'm curious to read more about it. Can someone give a philosophical pitch of why GDPR style regs on personal and company data are so important?

reply
LoL. We are all dancing naked on the table and hoping our clothes and wallet or purse and some of our pride will be where we left them.
reply
Evidence is pretty clear after decades of this: big data breaches are inconsequential for an average person.

They happen all the time, nobody cares, criminals who want to target you will target you anyway, criminals who don't target don't care about you specifically, legitimate entities cannot use this data anyway, and legitimate scammers (marketing) will find different ways to get you to give them the data you need.

At this point I thing privacy obsession is modern copium, a way for people to deal with the fact that we're all individually a speck of dust on the face of human civilization. It's about asserting, "I am not an NPC, I have this richness of experience", and then trying to hide it all in case the world wants to check.

reply
> big data breaches are inconsequential for an average person

A relative killed herself after her therapist was hacked[1] and the data was leaked. If that is inconsequential, I do not know what isn't.

[1] https://en.wikipedia.org/wiki/Vastaamo_data_breach

reply
A single suicide due to a massive data breach is, unfortunately, completely inconsequential. Especially if we consider what social media does to teenagers without needing any data breaches.
reply
[dead]
reply
All of the popular surveillance apps correlate your email address and phone numbers mostly, but if you used 1@gmail.com to sign up for 2@gmail.com google knows and marks it as your altnerate account, it could give them all your 30 rando gmails, you're then linked by phone activations through those emails to everything else, whatsapp, telegram, credit card purchase, etc. the biggest link in the chain is always the phone number though. They also have a big "Alternate Emails" button. Everything fans out from those.

I don't know how deep palantir can build profiles on someone, like digging into comment histories and extrapolating you are x y or z sort of stuff. I'm sure they've learned a lot about people via public irc logs and discord servers. But the only screenshots I've seen have been way more simple than that, basically a facebook UI that gives them buttons for all the apps with the phone # that has been identified as you the user, so it would be your list of social media apps accounts and they just click in and read messages. These screenshots have popped up in court cases recently.

We need to stop using the same phone numbers and rotate them constantly. Ideally back to something like fi that masks your "real" isp account phone number. They need to stop being a 2fa and especially stop being able to identify a person. Carry a dumb 2fa. I've always been on the "dont ask for my phone number to use your service" bandwagon but absolutely now.

And now some banks are doing instant voice recognition. I don't pick up my phone for any number I don't know anymore.

reply
>I just don't want to stop living - flying abroad, going to doctor

Good, you're not throwing out the baby with the bathwater. I don't get why you think throwing out the bathwater itself was wasted effort though.

The point is to get rid of things you can live without. If you're going to get rid of something but then spend every day thinking of its absence, then yes, that may be bridge too far. Otherwise, getting rid of it has some value.

I don't see the harm of asking, "Do I need this entity's services enough to justify forking over this data" for every entity that you interact with. Everyone draws their line in the sand at a different place. Data hygiene is a good phrase for that reason, everybody's acceptable level of hygiene (or lack thereof) is different.

reply
I gave up when i realised Firefox had google analytics and noone even knew or cared. That was about 10 years ago now.
reply
Because it did not. Extensions page used them but nothing else.
reply
I love the bit where a programmer always proudly chimes in with this statement as if it means anything.

You dont get it bro, its not a good vibe.

And if I had bean in management I would have fired anyone involved with that decision.

Why is it so often HN that I point something obvious out , like Rockstar having clearly failed management and a complete loss of control, but instead of agreement or silence I always get flak from some random user who just doesnt get it, and then a year later the company starts falling apart.

Im just a guy who recognises patterns and im not even smart.

reply
> I love the bit where a programmer always proudly chimes in with this statement as if it means anything.

So you knew that fierfox never came with google analytics but you decided to claim it anyway...

reply
Not the parent, but I'm not sure I understand your reasoning.

You download firefox. In firefox, you go to settings->Extensions to download extensions and get exposed to google analytics, is that correct? If that's true, how is it not insidious that in order to download the thing that blocks google analytics, you have to get exposed to google analytics?

reply
> Why is it so often HN that I point something obvious out

Because many "obvious" things are just plausibly sounding bullshit. For example:

> Rockstar having clearly failed management and a complete loss of control

That's both very broad and generic, and completely unfalsifiable, and comes with nothing backing it up. It's just an unsubstantiated opinion. These things are fine when drinking in friends, or otherwise socializing by bonding over ramblings.

If you want to convince someone of something, the standards of evidence (not to mention, clarity of thinking) are a bit higher.

reply
>the company starts falling apart.

This site will start falling apart if we don't keep things civil.

reply
>if I had bean in management I would have fired anyone involved with that decision.

Oh, I love the bit where a programmer always proudly chimes in with this statement as if it means anything.

reply
What? So 10 years ago you though 1+1=Firefox is using Google Analytics, something you can't prove, but is "obvious" and "recognizing patterns"

I get wanting to be conspiratorial, but its not cool to go after others that challenge your conspiracy, even if its "obvious"

reply