GDPR: Don't forget to bring a towel!
May 25 is Towel Day, when fans of The Hitchhiker's Guide to the Galaxy jokingly adorn a towel and praise the household item as if it prepares the owner for any sticky situation. Author Douglas Adams was a master of these tongue-in-cheek references to our modern existence, helping the reader (and listener) feel as if they might one day walk across their livingroom and into a silly, star-spanning adventure.
As The Guide says, "A towel is just about the most massively useful thing any interstellar Hitchhiker can carry. Partly it has great practical value." But the true power of a towel is its role as a symbol: "More importantly, a towel has immense psychological value... any man who can hitch the length and breadth of the Galaxy, rough it, slum it, struggle against terrible odds, win through and still knows where his towel is, is clearly a man to be reckoned with."
Possession of a towel is a calming force, a reification of the mantra printed across the cover of The Guide in big letters: "DON'T PANIC".
As Towel Day 2018 approached, our e-mail inboxes filled to the brim with similar platitudes. May 25 was also the day that European General Data Protection Regulation (GDPR) went into effect. And boy, did we hear about it.
"NOTHING TO SEE HERE" is the message of the marketing barrage around GDPR. It's much more bland than The Guide's cover phrase, to be sure, but there can be no desire to panic if there's no problem.
Data collectors and data brokers are keen to remind us that there simply is no surveillance concern, that small tweaks are required to shoehorn GDPR into a well-functioning, privacy-respecting system. Website popups around the world seem to say, "Maybe the reckless corporations over there have created a nightmare, but over here we would never dream of hurting you. If we screwed up in the past, we've fixed everything now so you should forgive us."
That conversation dodges fundamental threats to our computer networks that aim to segment, classify, and surveil traffic. As we emphasize at Yale Privacy Lab, there are are also serious problems with the underlying structure of our software ecosystems.
It may be difficult to communicate these concepts via e-mail and website popups, but companies that avoid mentioning the surveillance underbelly of their business model are flat-out deceiving people. GDPR contains very stringent requirements, including explicit consent from users that would limit the data harvesting that currently powers Silicon Valley and the app economy. If GDPR were followed according to security industry recommendations, it would not only threaten Facebook and Google, but also Pornhub, Imgur, AccuWeather, Yelp, and much more obscure companies.
So, what's a data hoarder to do? An Internet meme summarizes the strategy: "Hi there. You purchased a potato from us 7 years ago and we somehow got [ahold] of your email address... we have more information for you not to read on our [Terms and Conditions] and it doesn't really matter... you don't have any choice anyway if you'd like to continue using our potatoes or celeries."
Electronic contracts are notoriously ignored by users, prompting the creation of Web browser plugins that rate terms of service and try to categorize policies via Artifical Intelligence.
Shortly after our work with Exodus Privacy exposed an entire industry of hidden trackers in Google Play, Google changed its policies to ask Android app developers to "prominently highlight how the user data will be used and have the user provide affirmative consent for such use". Warning screens and verbose agreements often become software malpractice: they not only mask the poison coursing through the system, they sedate the user into a click-through coma.
Now that GDPR has landed, we're seeing challenges to the faux-consent model. Do users have a free choice when they are a captive audience just trying to use a service?
Communication about updated privacy policies may be a mechanism to hide the fact that consent was never asked for or granted by users in the past. Silence and pre-checked boxes may be interpreted as consent, even though GDPR specifically forbids this. When the dust settles, will users even know what they may have consented to, and from which service providers?
The corporate version of GDPR is a bizarre cauldron of doublespeak, intended to elicit B.F. Skinner-style conditioned responses on the part of users. As current trends to undermine, circumvent, and twist GDPR continue, the regulation begins to resemble the Towelie character from South Park, who reminds everyone "Don't forget to bring a towel!" at every possible opportunity. In stark contrast to Douglas Adams's helpful tool for survival and comfort, the towel becomes a ridiculous suggestion that serves no utility. Mere mention of GDPR may elicit the same disdain as Towelie's character, a vehicle for jokes about uselessness and lazy inaction.
Taylor Swift used facial recognition technology at her live performances so that technicians running the system could then check those face scans against a private database of her stalkers.
Surveillance libraries in common smartphone apps have amassed dossiers on the minute-to-minute movements of 200 million+ Americans
An investigation by the New York Times into the shadowy world of location-data brokerages found a whole menagerie of companies from IBM, Foursquare and the Weather Channel to obscure players like Groundtruth, Fysical and Safegraph, who pay app vendors to include their tracking code in common apps.
San Franciscans! Come celebrate the launch of the EFF/McSweeney's special privacy issue with me on Dec 11!
I'm heading to San Francisco next week for a launch party on December 11th celebrating the release of The End of Trust, a collaboration between EFF and McSweeney's on internet surveillance and the future of the net; the event is at 7:30PM at Manny’s at 3092 16th Street (RSVP here), and I'll be on a […]
Adobe’s design software catalog is essential to any graphics program, as much for their simplicity as their versatility. Anyone can be an effective graphic designer with tools like Illustrator and InDesign – and the right training in their potential. That’s where the Adobe CC A-Z Lifetime Bundle comes in. Whether you’re getting your feet wet […]
Businesses of any size continue to use PDFs despite – and perhaps because of – their stubborn resistance to simple editing. But for those who need a little flexibility on their documentation, the search is over for alternative software. PDF Expert for Mac is the catch-all solution for wrangling those PDFs, and it’s available at […]
When it comes to tech, smaller is better, and these items fit the bill both in terms of size and price. We’ve rounded up our favorite stocking-ready gadgets, most of which are already on sale – and you can take an additional 15% off any of them with the special code MERRY15. iPM 3-in-1 Fast […]