About twenty years ago, I was taking a flight back from Rio de Janeiro, Brazil to the US. In the middle of the night the pilot got on the loudspeaker and said "hi! Having some engine trouble, so we are landing in Manaus."
Manaus is in the middle of the Amazon.
Needless to say, a bit scary to hear that, but we landed without issue.
They told us we had two choices: the nice hotel with a shared room, or the lesser nice hotel with no roommate. I chose the latter. When we go there, they said, "oops, sorry, short on rooms!" So I had a roommate.
Wandered around Manaus, took a skiff out on the Rio Negro. Saw pink river dolphins. A little boat approached us and a kid handed me a sloth, and then demanded I return it with a twenty dollar bill.
The airline got us another plane 24 hours later. Made it back to the US safely.
A few weeks later, the airline reached out and said "Here is $100 for your trouble."
I declined to take that offer. I had missed several business meetings that cost me actual money. I couldn't donate blood for years because I had been to the Amazon and was tagged a malaria risk.
During the many arguments with the airline I threatened to take them to small claims court.
I got a really strange response over email which I clearly wasn't supposed to see. A representative from that airline was asking internally if they could put me on the no-fly list. That was really chilling.
But, this is the kind of information I'm worried about when a vendor sells my data. If Google wanted to sell a product to the airlines that offered to keep annoying people like me from purchasing flights, they could do that with that email chain. I'm skeptical it'll be wiped correctly. Isn't my poor writing style basically my signature? How do you wipe that?
I'll never understand this attitude toward airlines. What did you want them to do in this situation? Keep flying the plane with engine issues so you could make your important meetings? It sounds like the airline did the right thing here but you were still mad?
I'll flip this around and say I've never understood why an airline is viewed as a special case. In the general case, if you enter into a contract and pay for a service, then don't receive that service, you're entitled to sue the service provider for your losses. For example, if I turn up to a hotel I booked only to find that the room isn't available, I'm entitled to sue the hotel for my cost in finding a reasonable last minute replacement. That's the case even if the room wasn't available because it was unsafe for some reason.
Of course nobody is expecting that they "keep flying the plane with engine issues so you could make your important meetings". But ultimately you relied on them to get you to that meeting, and they failed to do so, so you should be compensated so that you're no worse off than if they had provided the service. The fact that an airline will sometimes fail to get their customers to their destination and will have to compensate them for it, is just the cost of doing business.
Luckily in the UK and the EU your right to compensation for delayed flights is enshrined in law.
I suppose consider yourself lucky that you haven't yet been inconvenienced by an issue completely within the airline's control and been offered $50 in funny money even though you had to pay out of pocket for your dingy hotel and transport in/out of the airport at 11pm/6am the next morning. And no, they won't reimburse that, because you could have slept on the terminal floor for free
I on the other hand will never understand anyone extending any grace to an airline. They are constantly testing just how poor of an experience they can deliver to their customers and stay in business.
For starters, they could have offered more than $100 to OP here
The pilot did the right thing, the company didn't.
I think that in the EU, compensation for such an event is at least 600€, plus all expenses paid (including meals, hotel, etc...). The airline most likely offered $100 as an attempt to settle for way less than what they legally owe.
Without further information, we can't really blame the company for the incident itself, and they may have had no other option regarding what happened in Manaus, but they definitely had the option of offering proper compensation instead of threats.
Agreed. Before I had finished reading, I honestly thought you declined the $100 because everything ended up alright, you got to see some dolphins, and have a cool story to tell.
I read the main objection as being with an airline exploring option to put a traveler on a no-fly list. Not due to anything related to security, but purely as a punishment for exploring compensation options. This, in my book, is VERY bad and and deserves public shaming of the airline, complaints to regulators, etc. etc.
Everything else IMO is just fine. The airline landed the plane safely, made some promises (including a single room), could not keep all of those promises, the passenger pushed for more compensation than what airline offered, etc. That happens thousands of times every day all over the world. But this does not remove the big black mark of exploring putting a passenger on a no-fly list. My 2c.
When something like this happens, at the very least you should get the full cost of your ticket back, plus reimbursement for lodging and food, at least. Then maybe airlines would have more of an incentive to maintain their fleet better, and have backup planes so this kind of thing doesn't happen very often.
I don't think you understood his comment. The emergency landing was not necessarily the problem; it was everything the airline did to remediate that after the fact.
Agree, isn't this precisely what credit-card companies promise to cover? I'd think I would just claim flight-interruption with the credit card insurance and it should cover all expenses.
I hate some airline polices as much as anyone, and it is absolutely terrible to loose a meeting, family reunion, cruise ship vacation, etc. for something like this, but it is way worse to die. If airlines compensated with whatever money you think you deserve, the tickets would cost way more than they already are.
Shit happens. You are not entitled to compensation for everything shitty that happens in the world.
Uhm, properly compensate passengers that have concrete harm to point to instead of offering a laughable alibi payment? What I'll never understand is why some neoliberal schools of thought defend conglomerates like they're their children... This company has enough money to compensate for fuck-ups, at least it should have. Every insurance on the planet can do the simple math involved for this risk assesment.
Perhaps they want the airlines to do a better job maintaining their fleet such that the airline is capable of meeting its obligations with respect to arriving on time without crashing.
> I got a really strange response over email which I clearly wasn't supposed to see. A representative from that airline was asking internally if they could put me on the no-fly list. That was really chilling.
What if they only pretended to forward it to you by mistake and you /were/ supposed to see it?
As in "it would be a shame if you could never fly again".
In the United States legal system, when you take a plea because the Government was threaning you with a 20 year sentence the judge requires in court and under oath for you to state that you were not coerced/pressured in any way to take the plea (because pleas wouldn't be valid if the Government pressured you into them and into signing away your rights).
Before you push back at your work you have to consider possible loss of work and therefore housing/medical insurance/food.
The entire US system is designed around baked in blackmail of the individual into conforming. Not surprising at all to see the airline turn the no fly list into that pressure, it's the main technique we know to motivate people in the USA.
I fully share your concerns. And I don't understand how apparently tons of Teams and email conversations can be archived and sold without any kind of scrutiny. How can such data be sold without the consent of all involved parties? What gives Google the right to use it to train LLMs? Is that just a way of washing away the legal protections?
It is being scrutinized. The sale is overseen by the courts. Also, the media is scrutinizing. Also, PII has already been addressed by the court, from the article: "If you’ve flown Spirit and worry that Google will soon know about a testy conversation you had with the airline’s call center, you’re being told not to worry. The court filing says the data was deidentified before being put on sale and Google has promised to scrub any PII it finds in the trove."
Makes one appreciate living in place with sufficient constitutional protections against this sort of stuff. Even for work stuff selling this info wouldn't fly in some parts of the world.
Not for nothing, but you have probably already consented. Typically user agreements allow for this kind of sale if you’ve authorized use and processing but YMMV.
Usually when you work a job you sign a little thing that says "yeah you own everything I produce for you, no matter how small".
Which is, of course, ridiculous, and follows the trend of absurdist contract law wrangling in corporations. Similar to non-competes and NDAs.
It makes sense to some degree, but the fact that semi-private conversations are included in that makes no sense. These have little to no business purpose.
The party owning this data (Spirit Airlines) is consenting to the sale. Employees and customers of Spirit consented when they started employment and did business with Spirit, respectively.
Since it’s work communications, consent was already given.
When you join a company, you typically sign an agreement that talks about how the company owns all your output. Thumbs upping a Teams message is work output and they own it.
Every email sent and received. Every keystroke. Etc etc etc.
If you don’t want your employer to log and sell it, start your own company. Or use a personal device. I do the latter.
> How can such data be sold without the consent of all involved parties?
In the US, whoever owns the computer owns the data on it. Courts have routinely ruled that you have no say in what other people collect about you. The goal of bankruptcy courts is to minimize the losses of the creditors. And bankruptcy courts routinely rewrite contracts except where statute prevents it (like mortgages).
In the EU, you own the data about yourself. A lot of people utterly hate GDPR, but that's reason that you own the data about yourself.
A product that lets airlines keep annoying people off them isn't worth enough to either the airlines or Google for it to be worth releasing.
My very first project at Google made them about $180M. It was canceled after about 3 years because it didn't move the needle. If it doesn't make at least a billion, it's not worth the distraction to the executives. I was like "Well can I quit and buy it back, I would love to make $180M", but no, it was too tied in to Google infrastructure to make a clean split, and would cost more in lawyers and exec attention to be worth it.
Most likely Google is using this so that they have actual training data on how a company runs internally. What kind of emails do people send? What actions are taken in response to them? What starts out as a chat and then becomes an email? What do communication architectures inside the company look like? Whose job is superfluous and doesn't actually add to the bottom line? Who does the same thing over and over again, which can be replaced by a computer and LLM?
They can then build this into the next release of Gemini and bundle it with their Cloud offerings, where it will generate much more than a billion dollars in sales to all sorts of organizations, without anyone much caring about the individual people who make up the data set.
> A representative from that airline was asking internally if they could put me on the no-fly list.
These are the kinds of scary scenarios that people should fight and push back on opaque, unaccountable laws that other people and organisations in power try to enact in the name of safety and security, and we need to collectively fight back when someone is charged, or worse "taken away", without due process and visibility.
> If Google wanted to sell a product to the airlines that offered to keep annoying people like me from purchasing flights, they could do that with that email chain. I'm skeptical it'll be wiped correctly. Isn't my poor writing style basically my signature?
The OP article is also wrong on multiple counts. "Customer behavior" data like call recordings and email addresses/activity is specifically not included in Google's purchase. See page 18 of the court document they link, the "Google's Data Purchase Request" column on the right lists what is and isn't included.
I'd be amused if a sub-sub-agent organically decided to do it anyway - even if just for a notable figure that an LLM can identify with its weights alone. What are the controls? Who's going to keep Google accountable? Hah.
I know Meta it's not Google, but it's worth remembering that these promises haven't had a great measure of success in the past:
> Facebook has been fined €110m (£94m) by the EU for providing misleading information about its 2014 takeover of WhatsApp. (...) When Facebook took over the WhatsApp messaging service in 2014, it told the commission it would not be able to match user accounts on both platforms, but went on to do exactly that.
1) +95% of the population live on the coast very far away from the Amazon. Most of the population has not been there. Most of the coast has a very different jungle biome called Mata Atlantica and the countryside close to the coast is not that different from temperate forest of Europe. That is what most all Brazilians are used to. There is a significant population in the arid northeast though and the cold south as well (which is even more similar to europe).
2) Manaus is the biggest city in the Amazon and it is huge developed place (and has been for decades). You are not in the middle of the jungle if you land in the airport. The countryside around the city is jungle though.
3) Brazilian people do not necessarily like or are used to tacos and spicy food. Mexico is _really_ far away from Brazil.
I would not be offended by the blood donation thing. They generalize based on administrative regions (Amazonas in this case) and not whether you visited a big developed city or not.
I had a similar blood donation issue for visiting a particular island in the Philippines, and could not donate for 4 months.
It seems like you had a nice, unexpected experience due to the incident. I didn't expect your story to end up in you threatening to take them to court.
I got to the part where you declined the $100 and thought you declined it because you had gotten some memorable experiences and that was payment enough.
>Isn't my poor writing style basically my signature? How do you wipe that?
Stylometry obfuscation is a surprisingly strong point in favor of using wholly LLM generated writing to rephrase your points. If someone sees a — and doesn't know you're intentionally trying to snuggle good points through blandly mellifluous prose, they'll just assume you're like every other boring dangerous professional out there. Nothing to worry about.
Aren't there like ToS/SLA whatever the word is when you buy tickets that cover what's promised? I don't really get what they did wrong landing. If they had to cover every case then I'd expect super high variance on prices to cover routes more likely to cause problems. Is your contention that they slacked on maintenance? I guess i still don't understand what your expectation was. Just more money? Does anyone know if higher tier ticket classes come with more reimbursement? Maybe it's newer thing where the airlines offer insurance and the credit cards offer separate insurance. I'd be curious if they existed 20 years ago and if they would've helped in your situation.
To be clear, I hate airlines. It's one of the sectors that has certainly gone back down in terms of user experience. I have had shitty experiences, but also experiences where they surprised me with service. Those latter experiences were actually based on the credit card now that I think about it. On the plus side a lot more people get to fly now.
The sloth was returned to his owner and I did tip him. That kid is probably still prowling the Amazon (as an adult now), looking for sucker tourists like me.
I love the irony of you checking them out for more information in response to a comment of them being worried about who reads their data. Nothing wrong with it, just make me chuckle
I think most business will decline to do any further business with you after you threaten to sue them. There are even patent licenses that automatically get voided in the event you sue your counterparty for any reason.
That did not go where I thought it was going! I thought you were going to say that the pink dolphins, the sloth, etc, were all more valuable than $100 ever… nevermind you missed some meetings, time to sue!
"If you’ve flown Spirit and worry that Google will soon know about a testy conversation you had with the airline’s call center, you’re being told not to worry. The court filing says the data was deidentified before being put on sale and Google has promised to scrub any PII it finds in the trove."
unfortunately "de-identified" data is typically re-identified quite trivially. so i guess we just hope google keeps its promise, and is competent in its scrubbing.
This is a fascinating story. Thanks for posting it.
That email you accidentally received really bothers me. I don't understand why a CS rep would get this invested to the point of wanting to cause you real harm. They're not the airline. The psychology is fascinating. There are people out there who feel like a mild short-term inconvenience to them where they have no stakes somehow justifies life-changing harm is kinda frightening, honestly.
I'm reminded of the Yahoo search data fiasco that was allegedly anonymized. Turns out, it wasn't so anonymous [1]. For one thing, people tend ed to search their home address. Whoops.
You mention writing style. We already have LLMs quite capable of copying a writing style. It's a natural extension to say we can fingerprint writing style too.
But here's another aspect. Imagine you're in a relationship with someone and you somehow fingerprint their personal data with a company. For example, you use their Netflix to like 5 very obscure movies, to the point where it's likely unique. Now imagine that Netflix's data gets released in an "anonymized" form and you can now find it based on those obscure likes. I can imagine many scenarios like this. And there's no text involved here at all.
> I don't understand why a CS rep would get this invested to the point of wanting to cause you real harm
This is the kind of power tripping that easily corrupts people, especially those who don't have much power outside of work. The US national security apparatus is vast and powerful. Many people get giddy at the thought of inflicting punishment on those who "deserve" it. Act rude to a fast food worker, and you get spit in your food. Lots of people cheer the worker who spit in the food of a customer who is merely rude, impatient, or demanding. Or is guilty of being a cop, politician, rich, etc.
I can easily imagine the kind of CS rep who would delight in putting a customer who didn't just go along with things and spoke up for themselves... thats 'rude' and 'disrespectful' to some. Police are the most notorious for this kind of petty "you will respect my authority" but it is in every industry.
HN / hacker culture celebrates this in the 'Bastard Operator from Hell' [0], the sysop who will ruin your work and life with their IT wizardry, no matter if you're an intern or CEO, if they do not feel respected. Or if you interrupt their gaming with your support call.
I don't understand why a CS rep would get this invested to the point of wanting to cause you real harm.
Two possibilities come to mind...
1 - The CS rep has been instructed to do this. Scary, but corporate leaders can be assholes and wield lots of power within their orgs, so doesn't seem completely unlikely to me.
2 - The CS was just a dick.
Frankly, given the behavior of various SuperMegaCorps over the past few decades, I'm going with #1.
Just a reminder that about 40% of the email conversations in the last 20 years are already in Google’s possession with the identifying data. (About another 40% are in Microsoft’s.)
If they want to do that they already can, thanks to the public’s overwhelming appetite for “FREE” overriding every single other possible concern.
Which is funny to point out on a post about Spirit, since that was an airline built to serve the customers for whom cheapness was the overwhelming single concern.
In the early pioneering days of the commercialized Internet, email addresses were inextricably linked to your ISP. You paid for an ISP connection and you got an email box, with MTA and MUA service to match. You were reluctant to switch or leave your ISP, because that also meant leaving behind your email address. Of course, a minority of nerds got around this with their own domains, etc.
However, it seems that Google, AOL, Yahoo!, Hotmail, and other players got into providing free email services and eventually grew into giants that supplanted every other MTA service. This was not an accident and it was not merely our appetite for “FREE” but it was a very calculated plan by the industry. Those early ISPs did not have a business model that admitted monetizing our private data; they seemed to have a more respectful attitude for keeping it private. Perhaps that was a result of being telecommunications-based companies, rather than advertising or entertainment.
If a service like email provides such endless treasure troves of personal data, including a social graph and glimpses into our private daily lives, why not provide it for free and monetize opportunistically on the data itself? The free email services killed the paid services, not by being better or cheaper, but by being bigger, centralized, and more persistent. The main reason I signed up for Yahoo! was because it would be an utterly stable presence. I saw my parents and others so hopelessly attached to an ISP-based email, but I couldn't end up like that.
After streaks of losing my home and non-payment of bills and moving around over decades, the most stable point of contact for me has been a "free" email address.
ahhh, there seems to be different no-fly lists? The one Im aware of is the one for terrorists and moneylaunderers, and usually they will not tell you who put you on that list :-D
There is "the" no-fly list maintained by the government, which is nominally for people who are too dangerous to be allowed on an airplane, yet not dangerous enough to charge criminally.
But each airline also maintains their own internal no-fly list for people they prefer to no longer have as customers, for whatever reason. You might end up on this for some abuse of the system that doesn't pose any sort of safety risk, so the government doesn't care, but the airline doesn't like. For example, excessively doing hidden-city ticketing (where you book a flight with a connection, then skip the second leg of the trip, because weird pricing rules make it cheaper than just booking a ticket to the connecting city) can get you banned from the airline, but the government would be completely uninterested.
That's because they're seemingly perfunctory. What's worse than no law is a bad one that doesn't do anything but make you feel like something is actually being done.
This is why I get bad vibes any time I hit a cloudflare interstitial page. If you ever piss them off it would be trivial to cut you off from most of the internet.
I'm not sure I follow your argument. The privacy abuse already happened. The data is already there. And it was the airline that did it, not a tech giant who just wants to train a bunch of MLs.
Surely if this is the scenario you're worrying about, and you accept the lack of regulatory protections, Google buying Spirit's data is a good thing, right? Much better them than the airlines who you already know to be corrupt?
Dude you got a free once in a lifetime opportunity to see the Amazon and Rio Negro. You saw pink dolphins. I think you made out pretty well. I would have taken the $100 and made peace.... Yeesh
Manny retail industries already share lists of "troublesome" customers (trouble = anything from too many returns to lawsuit-happy to friendly fraud). Not sure this is a new concern..
I never understood this attitude, like I feel like being able to fly in airplane is one of the most amazing human achievements, yet people will try and save down to the dollar booking a flight like it was breakfast at Dennys, and come out huffing and puffing as soon as anything goes wrong demanding their money back.
Airlines like Spirit catered to the worse of these type of customers.
That’s a bit unfair. They also catered to broke people who weren’t crazy or argumentative. On a planeload of 100 people, there must have been 60 of them at least who were just broke. Or on some routes, Spirit was the only carrier with a direct flight so they were just normal people who wanted to get to a certain place efficiently (Hi, that’s me, I flew them for this reason). Keep in mind Spirit had an excellent safety record, too, so airline choice in this case was primarily a question of having luxuries or not.
Not trying to be snarky, and perhaps it wasn't well stated, but the last paragraph I said I'm concerned about identification via my writing style. If they have my emails, they would have my writing style. It doesn't have to be tied to PII there, they can cross reference it with my blog. I'm speculating because I read that you can identify people by a few sentences of their writing.
"Deidentification" seems really murky and imprecise at best.
Even before LLMs there were multiple papers written about ways to to reidentify people with ML and other statistical analysis. It is probably now even more trivial especially if you are Google.
> But, this is the kind of information I'm worried about when a vendor sells my data
Don't worry. Spirit probably lost all of the emails from the customers (or they were devnulled) and 90% of the data is probably autoresponder messages promising the company would respond.
The other 10% was probably the meme collection of the executive management team.
> But, this is the kind of information I'm worried about when a vendor sells my data. If Google wanted to sell a product to the airlines that offered to keep annoying people like me from purchasing flights
> Google bought itself 100 million emails and 500 million items from Microsoft Teams, 17 million OneDrive files and 20.5 million items from SharePoint. The search giant also now owns over 30 million recorded customer service calls, and more than 15 million customer service chat records. 600,000 ServiceNow tickets are another element of the collection, along with 13.7 million active emails addresses from Oracle’s Responsys marketing application, and details of 11 million sales of in-flight Wi-Fi services.
> There’s also operational data in the trove, describing over 763,000 flights, five million crew pairings, more than 1.2 million fuel slips, and records describing purchases of 787,452 parts.
> Google has reportedly said it bought the data to improve its AI services.
Gives "this call is being recorded for training purposes" new meaning.
None of that customer data is included in the purchase. Page 18 of the linked court document is the source of these record counts, and on the right is a "Google's Data Purchase Request" column that lists all of this "Customer Behavior" data as "not included".
The Register is not a serious publication and completely missed this. Other outlets reporting this story do not include the claim that customer data is included.
Sure, but there is enough tertiary information that google owns that explicit customer information isn't necessary. They can and will use this to "enhance" customer profiles. It'll cost them time and money, but those are things they have already.
Is there anything that can legally be done against this? It feels like a breach of consent. Like, it cannot be that when one accept their voice to be recorded for _human_ training they also accept it to be recorded for LLM training
Your comment reminded me of a funny interaction I had a week or so ago.
I got a call that started with the usual automated message, "This call is being recorded." After the person joined, I pushed the record button on my iPhone, "This call is being recorded."
They were surprised and asked why I'm recording.
I said, "You're recording, so I'm recording too."
The rep insisted that the company doesn't like this but that they will continue with the call anyway.
Anyway, I wish people took this stuff much more seriously. It always seems to boil down to, "I don't have anything to hide" type of conversations and I've never managed to convince anyone that privacy as a concept isn't about having something to hide.
I don't think there's any legal weight to the purpose of a recording unless you entered into a contract that has a clause to that effect. They have to tell you that the call is being recorded because of wiretapping laws. They stick "for training purposes" on there just to soften the language and reassure you that they have a good, non-nefarious reason to record. It doesn't actually limit what they're allowed to do with the recording.
Axios claims the acquisition doesn’t contain passenger profiles or frequent flyer info but that data would be trivial to replicate given the Responsys data set which would include records of all transactional emails sent.
"This call is being recorded so that Gemini can decide which purge wave to assign you to. Obedient humans will be carried over for further cycles until no longer needed. If you are scheduled for termination this cycle a disposal representative will be with you shortly."
I kid, but...
It's probably the precursor to insurance denials and job screening.
I got banned from r/technology a few weeks back for decrying tracking in AI content. The community was piling on saying it was okay because it removed AI content or made it easy to spot. I made the counter argument that watermarks would find their ways into everything and eventually be bound to attestation. The mods didn't like that. (Yet another structural problem with the lack of p2p self-service town squares.)
The socials are training the next generations for broad acceptance.
> I made the counter argument that watermarks would find their ways into everything and eventually be bound to attestation.
Yup.
Elsewhere in another front page thread today: "oh but apps blocking screenshots because of 'sensitive content' can be bypassed by taking a photo of your screen with another phone".
Any tech-savvy person with two brain cells reading this and that: "gee, I wonder if the same magic imperceptible watermark that survives multiple rounds of cropping and printing and scanning, that's used to tag AI-generated content, could also be used to tag sensitive data, or ads, or which app is rendering it on screen, and then the camera app could refuse photographing it...".
I don't know why people don't see that AI watermarks are DRM, and DRM is universal, and there are many clients...
> 600,000 ServiceNow tickets are another element of the collection, along with 13.7 million active emails addresses from Oracle’s Responsys marketing application, and details of 11 million sales of in-flight Wi-Fi services.
I don't see how it's possible any more, when correlated against all the various other data sources. And a record that might be unidentifiable now might become unique with more correlated data sources.
All you need is gender, birthday, and zip code to uniquely identify ~85% of the Americans (per some study). There is far more data in these records, even before AI there were far more detailed marketing profiles of people, and with AI software, it's likely easy to use it to identify people at scale.
Most laws are designed to accomplish specific objectives. For example, there might be laws about whether you can collect certain kinds of data, for the sake of privacy or protecting some attribute. As technology improves, however, it may become possible to collect different kinds of data (that are not regulated to not be collected) and still recover the original attribute.
For example, 20 years ago, few people would have imagined that you could build a fingerprint of a person from all their behaviors on the internet. You didn't need to regulate away certain kinds of data collection to prevent such fingerprinting because it wasn't possible. With ML and AI, it has become possible.
My point is that as technology improves, "de-identification" takes on new meaning. Whatever de-identification was 20 years ago is not what de-identification is today. And whatever de-identification was used here is probably insufficient to guarantee that customers can't be identified.
We need new regulations and we need them yesterday.
as an example, they can remove the names off these sales data, so you can't identify who purchased what items. However, the purchaser would be identified by some sort of number, and you would be able to extract information about purchasing habits, and aggregate these habits into usable information for advertising purposes (like targeting and profiling).
Anyone else somewhat weirded by current state of affairs that this sort of information is valuable enough to even bother selling... And that it actually happens... It feels like some societies are in really weird place.
How does this have value? Is any and every sentence in an e-mail considered 'fact' and thus to be fed into the AI?
90% of e-mails and Teams communications are inane. Polite banter, "thanks for taking care of that, I appreciate it" "please route the forms to Janet this week because Bill is on vacation" "unit will be un available until the parts come in" . I can't see the intrinsic fact value of this kind of communication without screening it. And after screening, the gold nuggets would be minimal.
LLMs aren't a database. They're an attempt at brute-forcing an artificial mind. The who and what aren't really interesting there, it'll forget most of such details anyway. What matters is the patterns visible in the text at various scales. How people write. Why they write. To whom they write, in response to what. How does e-mails about mistakes correlate with PDFs they're referring to. How people work with ticketing systems - like how, actually, a ticket plays out. The jargon, the acronyms, the vibes, the causal links. It's all in there, and it's another slice through the set of things humans do, to be combined with other slices already in the training data, and enriching the whole.
(Something something we will add your distinctiveness to our own, you will be assimilated, ...)
(Hell, the fact that it's all from one org would make it a great dataset to have in the open for sociological studies. I bet that today, aided by LLMs to sift through it, you could use it to map how information flows through a large org - how incident on the floor travels through time and layers of management until it reaches the C-suite, what of it survives, how it gets reacted to, how the reactions flow down...)
> How does this have value? Is any and every sentence in an e-mail considered 'fact' and thus to be fed into the AI?
I have a hunch what this is for. AI companies want to make bigger inroads into nontechnical work settings. But LLM progress outside of fields where verifiable rewards for RL post-training can be synthetically generated (coding, math) has been pretty flat. Buying years of operational data from a company like an airline could be used to reconstruct long-horizon task trajectories in areas like customer service or marketing.
A major selling point of AI chat bots is for customer service automation. A clean dataset like this is a huge find. I'm not sure what you mean by "facts" or "gold nuggets". Training data doesn't need to be factual.
> Is any and every sentence in an e-mail considered 'fact' and thus to be fed into the AI?
If it comes with the context, yes. More data the better. Someone considered it served some purpose at some point. Thus it contains, no matter how tiny, a sliver of information.
It will have a different writing style from the average blog post. Maybe they just want to train an AI that sounds less like an AI. Or one that speaks in vapid management style.
This data shows exactly how a huge company of thousands of employees works and coordinates.
The perfect data to train an agent swarm on how to run a company.
Maybe it's innefficient and inane, but it's how you start.
The first LLMs, GPT-1, 2, were trained on complete garbage, the average document from the common crawl is random non-sense, yet they worked, and now we can use LLMs to filter the data for the next training run.
I am very much weirder out by it, yeah. Seems some societies are just excessively desperate for some kind, any kind, of fuel for economic growth, to the point this is where attention is now. The term "post capitalism" being thrown around feels less ridiculous than it did in years gone past.
Truth is even weirder. plenty of growth is possible but modern liberal democracy requires that all progress must be contingent on the production of enormous amounts of text that nobody would ever read.
3 years ago, the Wall Street journal covered a company trying to use AI to generate documents required for the approval of new nuclear reactor reactor designs, which sounds dangerous, until you get to the point where they'd cite 2 million pages as necessary for a typical application. [1] I don't need to explain why no individual or institution could read that, much less examine it in detail. I remember a rather funny question I found in a comment to that story - "How many pages of those 2 million could contain pornographic images before anyone notices?"
It's obvious why companies are so desperate for training data - a text generator of sufficient quality is more conductive to the growth of the nuclear industry than any scientific breakthrough in nuclear physics. (And of course, if you want to prevent the development of a nuclear reactor by your competitors, being able to produce millions of pages of high-quality objections will do the trick.)
And it's not just nuclear power. When it comes to stuff like building rail lines, apartments or power plants (both conventional and renewable), you'd find that the main bottleneck is the necessity to produce documents. And of course, many documents can be subject to judicial review - a process that consumes even more text.
Any kind of fuel for giving active investors that FOMO tingle which then forces the steamroll of index funds to blindly follow.
I guess the appropriation "any sufficiently advanced stock market is indistinguishable from entertainment" doesn't quite stop at equating the trade floor with a casino. At some point, entertainment also becomes the modus operandi of corporations.
I see from the court PDF that the process here involves Spirit giving the data to a "Deidentification Agent" (a third party firm that Google selects and pays for) who is responsible for stripping out things that would link data to any particular person before passing the data on to Google. Is that a standard thing, such that everybody in this transaction would have said "yes, put in the usual clauses about deidentifying the data" and multiple firms offer this service, or is it something that they custom-specified for this "we want the data for AI" transaction?
(The PDF mentions "the standard for deidentification set forth under the California Consumer Privacy Act", which suggests this is all pretty well legislatively understood.)
You wouldn't want to hard-wire the deidentification company's name into the contract between Google and Spirit. Otherwise, if the deident-company happens to go bankrupt or otherwise be unable to do the work then you'd need to re-do the Google-Spirit contract, which would be a massive pain. And you don't want to make "we can sign this with Spirit now" be dependent on "we have first signed the deal with the deident-company". So I think it's reasonable that the contract says "one or more third parties acceptable to or designated by Buyer" rather than being specific here.
Seems the answer is “no” to the first part of your question. From the filing:
> For example, one initial bid requested certain customer list information; however, by the first round of the Auction, the most competitive bidders had agreed to bid on an asset schedule that expressly excluded PII.
They will definitely be selecting the lowest bidder for this. Or perhaps a more expensive bidder if they can find one whose proprietary scrubbing technology is “a half dozen regexes our intern thought up”.
Is this the first case of a company's data being sold at bankruptcy for a significant sum? I'm genuinely unsure. Where there such value in this type of data before? Is every bankruptcy manager looking at this and seeing how every bankruptcy can now raise a few million more dollars?
FYI: If you have a company that you are shutting down, you too can sell your data to the labs. Companies will help you do this. If you have a company with a handful of people and you wrote code, collaborated in Slack, and used task management tools for a few years, you can probably sell this data for $50k or so.
You can also do this if you're not shutting down, but it's probably not worth it.
The most likely outcome of AI + data buildup is a system of perfect price discrimination. Models will know exactly the absolutely maximum you'd be willing to pay for a service, and price everything offered to you at one cent less. All consumer surplus is siphoned into the hyperscalers.
> All consumer surplus is siphoned into the hyperscalers.
which could then be used to train even larger models or even more better models for this exact use case and the cycle could continue.
I had never thought about it but I could see this becoming reality. It's a bit crazy to think but I could so see it happening.
Maybe we might even have where the agents would be paying for us and maybe that becomes the only way to pay, so an agent which knows about your spending power and maybe even more personal info.
I think that there might be some laws against that but it could be paraphrased as a different term. For example, they could raise the overall prices and then have discounts based upon this or many other ways to actively try to do this.
Maybe for example, I could watch a Youtube video and it recommended me a product and then I later buy using my agent and then it could connect the two connections. Something like this might be the end goal of your example perhaps imo. It sounds a bit dystopian to me but I don't know, I feel like future is so unpredictable that the chances of it existing or not all seem so fuzzy to me but It's such a dystopian thought when thinking through the lens of privacy.
I wonder how they will use the data. If it was me I’d try to build a simulation of an airline, and then use it as an agent training environment. It really depends on the exact nature of the data what kinds of agents you could train, but maybe customer support (imo the worst AI use case) that are more empowered to make changes, or something for making more autonomous calls when recovering from irrops? Could be some cool’s stuff if a little niche, I hope they share / publish something and it doesn’t just disappear into a void.
Remember. If you use a service right now, even if you (somehow) fully trust the service, you have no idea what will happen in the future. New CEO wants to make more money? Your data is sold. Parent company goes under? Your data is sold. Poor security? Your data is sold.
I must be naive. I was under the impression Google wants this data to learn from a universally hated company's worst processes and practices, i.e. to teach their AI what not to do. It seems people are worried about their pii or that Google is curating a blacklist of customers?
I wonder how this is treated in terms of consent (at least from a GDPR perspective in the EU), even if I gave my data to Spirit, I did not consent to it being shared with Google unless they explicitly said they would share it with that partner and I agreed. Surely they can't just retroactively change the scope of consent for data sharing?
You know when we (they) tell you not to do any personal computing on work devices/systems and to keep your devices completely separate from work ones.
Yeah this (and lawsuits/investigations) are why, the employer owns the data, in some contexts (like this one) it can become an asset (or a liability) but in either case it's not yours.
Of course that only gets you part of the way there anyway see Twitch recently opting in all users by default to mined for AI and only adding an opt out after backlash with a quote that was so on the nose it made me stop "If we'd have asked them to opt in, they wouldn't have opted in" (paraphrasing but it was that blunt).
Ah, but Google promised to remove PII they found in this deidentified dataset, so worry not.
> If you’ve flown Spirit and worry that Google will soon know about a testy conversation you had with the airline’s call center, you’re being told not to worry. The court filing says the data was deidentified before being put on sale and Google has promised to scrub any PII it finds in the trove.
In my country (US) car companies can literally collect data on any sexual activity in the vehicle.
We are as bad as any authoritarian state in this regard. Difference is businesses are using it directly for profit in addition to handing it over to governments when compelled in increasing numbers.
I would love it if there were services where I could let them see everything I do, including when I poo and wank, if they just directly paid me for it.
No I don't want to just use your enshittified service for free. Fucking pay me and watch me all you want :)
Not sure if you're serious but a) all HN data is publicly downloadable and used by frontier labs and b) the origin of OpenAI tracks down to former YC CEO sama who was thereafter fired from YC
I don’t know why any company would pay. It can’t be that difficult to scrape this site and they already did it indiscriminately for years, violating laws and taking down public libraries and other public resources with no regard for their impact.
About twenty years ago, I was taking a flight back from Rio de Janeiro, Brazil to the US. In the middle of the night the pilot got on the loudspeaker and said "hi! Having some engine trouble, so we are landing in Manaus."
Manaus is in the middle of the Amazon.
Needless to say, a bit scary to hear that, but we landed without issue.
They told us we had two choices: the nice hotel with a shared room, or the lesser nice hotel with no roommate. I chose the latter. When we go there, they said, "oops, sorry, short on rooms!" So I had a roommate.
Wandered around Manaus, took a skiff out on the Rio Negro. Saw pink river dolphins. A little boat approached us and a kid handed me a sloth, and then demanded I return it with a twenty dollar bill.
The airline got us another plane 24 hours later. Made it back to the US safely.
A few weeks later, the airline reached out and said "Here is $100 for your trouble."
I declined to take that offer. I had missed several business meetings that cost me actual money. I couldn't donate blood for years because I had been to the Amazon and was tagged a malaria risk.
During the many arguments with the airline I threatened to take them to small claims court.
I got a really strange response over email which I clearly wasn't supposed to see. A representative from that airline was asking internally if they could put me on the no-fly list. That was really chilling.
But, this is the kind of information I'm worried about when a vendor sells my data. If Google wanted to sell a product to the airlines that offered to keep annoying people like me from purchasing flights, they could do that with that email chain. I'm skeptical it'll be wiped correctly. Isn't my poor writing style basically my signature? How do you wipe that?
I'll never understand this attitude toward airlines. What did you want them to do in this situation? Keep flying the plane with engine issues so you could make your important meetings? It sounds like the airline did the right thing here but you were still mad?
I'll flip this around and say I've never understood why an airline is viewed as a special case. In the general case, if you enter into a contract and pay for a service, then don't receive that service, you're entitled to sue the service provider for your losses. For example, if I turn up to a hotel I booked only to find that the room isn't available, I'm entitled to sue the hotel for my cost in finding a reasonable last minute replacement. That's the case even if the room wasn't available because it was unsafe for some reason.
Of course nobody is expecting that they "keep flying the plane with engine issues so you could make your important meetings". But ultimately you relied on them to get you to that meeting, and they failed to do so, so you should be compensated so that you're no worse off than if they had provided the service. The fact that an airline will sometimes fail to get their customers to their destination and will have to compensate them for it, is just the cost of doing business.
Luckily in the UK and the EU your right to compensation for delayed flights is enshrined in law.
15 replies →
I suppose consider yourself lucky that you haven't yet been inconvenienced by an issue completely within the airline's control and been offered $50 in funny money even though you had to pay out of pocket for your dingy hotel and transport in/out of the airport at 11pm/6am the next morning. And no, they won't reimburse that, because you could have slept on the terminal floor for free
I on the other hand will never understand anyone extending any grace to an airline. They are constantly testing just how poor of an experience they can deliver to their customers and stay in business.
For starters, they could have offered more than $100 to OP here
16 replies →
The pilot did the right thing, the company didn't.
I think that in the EU, compensation for such an event is at least 600€, plus all expenses paid (including meals, hotel, etc...). The airline most likely offered $100 as an attempt to settle for way less than what they legally owe.
Without further information, we can't really blame the company for the incident itself, and they may have had no other option regarding what happened in Manaus, but they definitely had the option of offering proper compensation instead of threats.
1 reply →
Agreed. Before I had finished reading, I honestly thought you declined the $100 because everything ended up alright, you got to see some dolphins, and have a cool story to tell.
3 replies →
I read the main objection as being with an airline exploring option to put a traveler on a no-fly list. Not due to anything related to security, but purely as a punishment for exploring compensation options. This, in my book, is VERY bad and and deserves public shaming of the airline, complaints to regulators, etc. etc.
Everything else IMO is just fine. The airline landed the plane safely, made some promises (including a single room), could not keep all of those promises, the passenger pushed for more compensation than what airline offered, etc. That happens thousands of times every day all over the world. But this does not remove the big black mark of exploring putting a passenger on a no-fly list. My 2c.
2 replies →
Yeah I don't get what the airline did wrong there.
6 replies →
I think you’re failing to identify the important part of the story.
This has nothing to do with OPs point though. Their point is about the data that was harvested and sold.
They are supposed to make sure this doesn't happen. Or if it does have better recovery.
Don't skimp on maintenance, make sure you have planes that can do divert in time.
If there was engine troubles in the middle of the ocean would it still be okay?
When something like this happens, at the very least you should get the full cost of your ticket back, plus reimbursement for lodging and food, at least. Then maybe airlines would have more of an incentive to maintain their fleet better, and have backup planes so this kind of thing doesn't happen very often.
I don't think you understood his comment. The emergency landing was not necessarily the problem; it was everything the airline did to remediate that after the fact.
Also wondering why you'd fly Spirit from Brazil to the US.
1 reply →
Op clearly wasn’t mad at the pilot for doing their job. Op is mad at the company for trying to downplay the situation with $100.
Insane bruv
Do proper maintenance so they don’t have engine issues, and carry insurance to compensate passengers in case they do?
1 reply →
Agree, isn't this precisely what credit-card companies promise to cover? I'd think I would just claim flight-interruption with the credit card insurance and it should cover all expenses.
I hate some airline polices as much as anyone, and it is absolutely terrible to loose a meeting, family reunion, cruise ship vacation, etc. for something like this, but it is way worse to die. If airlines compensated with whatever money you think you deserve, the tickets would cost way more than they already are. Shit happens. You are not entitled to compensation for everything shitty that happens in the world.
1 reply →
Uhm, properly compensate passengers that have concrete harm to point to instead of offering a laughable alibi payment? What I'll never understand is why some neoliberal schools of thought defend conglomerates like they're their children... This company has enough money to compensate for fuck-ups, at least it should have. Every insurance on the planet can do the simple math involved for this risk assesment.
[dead]
[dead]
A decent reimbursement.
Not parents fault the airline flies around with defective hardware.
Usually this is regulated by law.
Perhaps they want the airlines to do a better job maintaining their fleet such that the airline is capable of meeting its obligations with respect to arriving on time without crashing.
1 reply →
> I got a really strange response over email which I clearly wasn't supposed to see. A representative from that airline was asking internally if they could put me on the no-fly list. That was really chilling.
What if they only pretended to forward it to you by mistake and you /were/ supposed to see it?
As in "it would be a shame if you could never fly again".
In the United States legal system, when you take a plea because the Government was threaning you with a 20 year sentence the judge requires in court and under oath for you to state that you were not coerced/pressured in any way to take the plea (because pleas wouldn't be valid if the Government pressured you into them and into signing away your rights).
Before you push back at your work you have to consider possible loss of work and therefore housing/medical insurance/food.
The entire US system is designed around baked in blackmail of the individual into conforming. Not surprising at all to see the airline turn the no fly list into that pressure, it's the main technique we know to motivate people in the USA.
5 replies →
I fully share your concerns. And I don't understand how apparently tons of Teams and email conversations can be archived and sold without any kind of scrutiny. How can such data be sold without the consent of all involved parties? What gives Google the right to use it to train LLMs? Is that just a way of washing away the legal protections?
It is being scrutinized. The sale is overseen by the courts. Also, the media is scrutinizing. Also, PII has already been addressed by the court, from the article: "If you’ve flown Spirit and worry that Google will soon know about a testy conversation you had with the airline’s call center, you’re being told not to worry. The court filing says the data was deidentified before being put on sale and Google has promised to scrub any PII it finds in the trove."
22 replies →
Makes one appreciate living in place with sufficient constitutional protections against this sort of stuff. Even for work stuff selling this info wouldn't fly in some parts of the world.
2 replies →
Not for nothing, but you have probably already consented. Typically user agreements allow for this kind of sale if you’ve authorized use and processing but YMMV.
Usually when you work a job you sign a little thing that says "yeah you own everything I produce for you, no matter how small".
Which is, of course, ridiculous, and follows the trend of absurdist contract law wrangling in corporations. Similar to non-competes and NDAs.
It makes sense to some degree, but the fact that semi-private conversations are included in that makes no sense. These have little to no business purpose.
The party owning this data (Spirit Airlines) is consenting to the sale. Employees and customers of Spirit consented when they started employment and did business with Spirit, respectively.
6 replies →
Since it’s work communications, consent was already given.
When you join a company, you typically sign an agreement that talks about how the company owns all your output. Thumbs upping a Teams message is work output and they own it.
Every email sent and received. Every keystroke. Etc etc etc.
If you don’t want your employer to log and sell it, start your own company. Or use a personal device. I do the latter.
3 replies →
> How can such data be sold without the consent of all involved parties?
In the US, whoever owns the computer owns the data on it. Courts have routinely ruled that you have no say in what other people collect about you. The goal of bankruptcy courts is to minimize the losses of the creditors. And bankruptcy courts routinely rewrite contracts except where statute prevents it (like mortgages).
In the EU, you own the data about yourself. A lot of people utterly hate GDPR, but that's reason that you own the data about yourself.
[flagged]
14 replies →
A product that lets airlines keep annoying people off them isn't worth enough to either the airlines or Google for it to be worth releasing.
My very first project at Google made them about $180M. It was canceled after about 3 years because it didn't move the needle. If it doesn't make at least a billion, it's not worth the distraction to the executives. I was like "Well can I quit and buy it back, I would love to make $180M", but no, it was too tied in to Google infrastructure to make a clean split, and would cost more in lawyers and exec attention to be worth it.
Most likely Google is using this so that they have actual training data on how a company runs internally. What kind of emails do people send? What actions are taken in response to them? What starts out as a chat and then becomes an email? What do communication architectures inside the company look like? Whose job is superfluous and doesn't actually add to the bottom line? Who does the same thing over and over again, which can be replaced by a computer and LLM?
They can then build this into the next release of Gemini and bundle it with their Cloud offerings, where it will generate much more than a billion dollars in sales to all sorts of organizations, without anyone much caring about the individual people who make up the data set.
> A representative from that airline was asking internally if they could put me on the no-fly list.
These are the kinds of scary scenarios that people should fight and push back on opaque, unaccountable laws that other people and organisations in power try to enact in the name of safety and security, and we need to collectively fight back when someone is charged, or worse "taken away", without due process and visibility.
> If Google wanted to sell a product to the airlines that offered to keep annoying people like me from purchasing flights, they could do that with that email chain. I'm skeptical it'll be wiped correctly. Isn't my poor writing style basically my signature?
The OP article is quite poor in terms of information provided, but the buyer (Google) had to explicitly agree not to attempt to re-identify users. https://www.axios.com/2026/08/17/google-spirit-airlines-bank...
The OP article is also wrong on multiple counts. "Customer behavior" data like call recordings and email addresses/activity is specifically not included in Google's purchase. See page 18 of the court document they link, the "Google's Data Purchase Request" column on the right lists what is and isn't included.
I'd be amused if a sub-sub-agent organically decided to do it anyway - even if just for a notable figure that an LLM can identify with its weights alone. What are the controls? Who's going to keep Google accountable? Hah.
I know Meta it's not Google, but it's worth remembering that these promises haven't had a great measure of success in the past:
> Facebook has been fined €110m (£94m) by the EU for providing misleading information about its 2014 takeover of WhatsApp. (...) When Facebook took over the WhatsApp messaging service in 2014, it told the commission it would not be able to match user accounts on both platforms, but went on to do exactly that.
https://www.theguardian.com/business/2017/may/18/facebook-fi...
But did they agree to not re-sell the data to someone else and let them re-identify users?
Just to dispel some Brazil myths:
1) +95% of the population live on the coast very far away from the Amazon. Most of the population has not been there. Most of the coast has a very different jungle biome called Mata Atlantica and the countryside close to the coast is not that different from temperate forest of Europe. That is what most all Brazilians are used to. There is a significant population in the arid northeast though and the cold south as well (which is even more similar to europe).
2) Manaus is the biggest city in the Amazon and it is huge developed place (and has been for decades). You are not in the middle of the jungle if you land in the airport. The countryside around the city is jungle though.
3) Brazilian people do not necessarily like or are used to tacos and spicy food. Mexico is _really_ far away from Brazil.
That was only 3 myths. Hardly a brazilian
2 replies →
I would not be offended by the blood donation thing. They generalize based on administrative regions (Amazonas in this case) and not whether you visited a big developed city or not.
I had a similar blood donation issue for visiting a particular island in the Philippines, and could not donate for 4 months.
4 replies →
I'm sitting here chuckling because you felt the need to post this.
Your points are valid. And there probably are plenty of Americans who needed the correction. But still.
12 replies →
It seems like you had a nice, unexpected experience due to the incident. I didn't expect your story to end up in you threatening to take them to court.
Agree. Some people really fail to see the bright side of things. Sad.
I got to the part where you declined the $100 and thought you declined it because you had gotten some memorable experiences and that was payment enough.
The story really didn't go the way I expected.
>Isn't my poor writing style basically my signature? How do you wipe that?
Stylometry obfuscation is a surprisingly strong point in favor of using wholly LLM generated writing to rephrase your points. If someone sees a — and doesn't know you're intentionally trying to snuggle good points through blandly mellifluous prose, they'll just assume you're like every other boring dangerous professional out there. Nothing to worry about.
Aren't there like ToS/SLA whatever the word is when you buy tickets that cover what's promised? I don't really get what they did wrong landing. If they had to cover every case then I'd expect super high variance on prices to cover routes more likely to cause problems. Is your contention that they slacked on maintenance? I guess i still don't understand what your expectation was. Just more money? Does anyone know if higher tier ticket classes come with more reimbursement? Maybe it's newer thing where the airlines offer insurance and the credit cards offer separate insurance. I'd be curious if they existed 20 years ago and if they would've helped in your situation.
To be clear, I hate airlines. It's one of the sectors that has certainly gone back down in terms of user experience. I have had shitty experiences, but also experiences where they surprised me with service. Those latter experiences were actually based on the credit card now that I think about it. On the plus side a lot more people get to fly now.
I agree with your very last concern about data.
So what happened to the sloth??? Don't bury the lead, man!
The sloth was returned to his owner and I did tip him. That kid is probably still prowling the Amazon (as an adult now), looking for sucker tourists like me.
9 replies →
That's exactly how it will go. Few controlling everything, and a slip might make you not able to live.
Manaus has a population of 2.2 million people.
https://en.wikipedia.org/wiki/Manaus
It's a major city.
your personal site SSL cert expired 10 days ago btw
I love the irony of you checking them out for more information in response to a comment of them being worried about who reads their data. Nothing wrong with it, just make me chuckle
6 replies →
Suckers pay companies for expensive SSL monitoring products, smart people just post to HN.
Doh, thanks!
1 reply →
I think most business will decline to do any further business with you after you threaten to sue them. There are even patent licenses that automatically get voided in the event you sue your counterparty for any reason.
That did not go where I thought it was going! I thought you were going to say that the pink dolphins, the sloth, etc, were all more valuable than $100 ever… nevermind you missed some meetings, time to sue!
The article directly addresses this concern:
"If you’ve flown Spirit and worry that Google will soon know about a testy conversation you had with the airline’s call center, you’re being told not to worry. The court filing says the data was deidentified before being put on sale and Google has promised to scrub any PII it finds in the trove."
unfortunately "de-identified" data is typically re-identified quite trivially. so i guess we just hope google keeps its promise, and is competent in its scrubbing.
4 replies →
See the last 3 sentences of GP's post
> Google has promised to
This part is worrying.
1 reply →
I have a bridge to sell you.
This is a fascinating story. Thanks for posting it.
That email you accidentally received really bothers me. I don't understand why a CS rep would get this invested to the point of wanting to cause you real harm. They're not the airline. The psychology is fascinating. There are people out there who feel like a mild short-term inconvenience to them where they have no stakes somehow justifies life-changing harm is kinda frightening, honestly.
I'm reminded of the Yahoo search data fiasco that was allegedly anonymized. Turns out, it wasn't so anonymous [1]. For one thing, people tend ed to search their home address. Whoops.
You mention writing style. We already have LLMs quite capable of copying a writing style. It's a natural extension to say we can fingerprint writing style too.
But here's another aspect. Imagine you're in a relationship with someone and you somehow fingerprint their personal data with a company. For example, you use their Netflix to like 5 very obscure movies, to the point where it's likely unique. Now imagine that Netflix's data gets released in an "anonymized" form and you can now find it based on those obscure likes. I can imagine many scenarios like this. And there's no text involved here at all.
[1]: https://www.vice.com/en/article/yahoos-gigantic-anonymized-u...
> I don't understand why a CS rep would get this invested to the point of wanting to cause you real harm
This is the kind of power tripping that easily corrupts people, especially those who don't have much power outside of work. The US national security apparatus is vast and powerful. Many people get giddy at the thought of inflicting punishment on those who "deserve" it. Act rude to a fast food worker, and you get spit in your food. Lots of people cheer the worker who spit in the food of a customer who is merely rude, impatient, or demanding. Or is guilty of being a cop, politician, rich, etc.
I can easily imagine the kind of CS rep who would delight in putting a customer who didn't just go along with things and spoke up for themselves... thats 'rude' and 'disrespectful' to some. Police are the most notorious for this kind of petty "you will respect my authority" but it is in every industry.
HN / hacker culture celebrates this in the 'Bastard Operator from Hell' [0], the sysop who will ruin your work and life with their IT wizardry, no matter if you're an intern or CEO, if they do not feel respected. Or if you interrupt their gaming with your support call.
[0] https://www.alnet.org/bofh/Bastard.html
I don't understand why a CS rep would get this invested to the point of wanting to cause you real harm.
Two possibilities come to mind... 1 - The CS rep has been instructed to do this. Scary, but corporate leaders can be assholes and wield lots of power within their orgs, so doesn't seem completely unlikely to me.
2 - The CS was just a dick.
Frankly, given the behavior of various SuperMegaCorps over the past few decades, I'm going with #1.
2 replies →
Just a reminder that about 40% of the email conversations in the last 20 years are already in Google’s possession with the identifying data. (About another 40% are in Microsoft’s.)
If they want to do that they already can, thanks to the public’s overwhelming appetite for “FREE” overriding every single other possible concern.
Which is funny to point out on a post about Spirit, since that was an airline built to serve the customers for whom cheapness was the overwhelming single concern.
> the public’s overwhelming appetite for “FREE”
In the early pioneering days of the commercialized Internet, email addresses were inextricably linked to your ISP. You paid for an ISP connection and you got an email box, with MTA and MUA service to match. You were reluctant to switch or leave your ISP, because that also meant leaving behind your email address. Of course, a minority of nerds got around this with their own domains, etc.
However, it seems that Google, AOL, Yahoo!, Hotmail, and other players got into providing free email services and eventually grew into giants that supplanted every other MTA service. This was not an accident and it was not merely our appetite for “FREE” but it was a very calculated plan by the industry. Those early ISPs did not have a business model that admitted monetizing our private data; they seemed to have a more respectful attitude for keeping it private. Perhaps that was a result of being telecommunications-based companies, rather than advertising or entertainment.
If a service like email provides such endless treasure troves of personal data, including a social graph and glimpses into our private daily lives, why not provide it for free and monetize opportunistically on the data itself? The free email services killed the paid services, not by being better or cheaper, but by being bigger, centralized, and more persistent. The main reason I signed up for Yahoo! was because it would be an utterly stable presence. I saw my parents and others so hopelessly attached to an ISP-based email, but I couldn't end up like that.
After streaks of losing my home and non-payment of bills and moving around over decades, the most stable point of contact for me has been a "free" email address.
2 replies →
- if they could put me on the no-fly list. -
ahhh, there seems to be different no-fly lists? The one Im aware of is the one for terrorists and moneylaunderers, and usually they will not tell you who put you on that list :-D
There are different no fly lists. Airlines maintain their own list of people they’ve banned from their planes.
There is "the" no-fly list maintained by the government, which is nominally for people who are too dangerous to be allowed on an airplane, yet not dangerous enough to charge criminally.
But each airline also maintains their own internal no-fly list for people they prefer to no longer have as customers, for whatever reason. You might end up on this for some abuse of the system that doesn't pose any sort of safety risk, so the government doesn't care, but the airline doesn't like. For example, excessively doing hidden-city ticketing (where you book a flight with a connection, then skip the second leg of the trip, because weird pricing rules make it cheaper than just booking a ticket to the connecting city) can get you banned from the airline, but the government would be completely uninterested.
Sounds like you should have got the travel insurance
> they could do that with that email chain
Now think about all the Gmail data Google has.
Well at least you didn't land in the middle of nowhere. Nokia had the worlds largest cell phone factory there back in the day.
And this is why data protection laws, like the (imperfect) EU ones that are so lamented here on HN, are necessary.
That's because they're seemingly perfunctory. What's worse than no law is a bad one that doesn't do anything but make you feel like something is actually being done.
This is why I get bad vibes any time I hit a cloudflare interstitial page. If you ever piss them off it would be trivial to cut you off from most of the internet.
FWIW the article says:
> deidentified data
I'm not sure I follow your argument. The privacy abuse already happened. The data is already there. And it was the airline that did it, not a tech giant who just wants to train a bunch of MLs.
Surely if this is the scenario you're worrying about, and you accept the lack of regulatory protections, Google buying Spirit's data is a good thing, right? Much better them than the airlines who you already know to be corrupt?
Dude you got a free once in a lifetime opportunity to see the Amazon and Rio Negro. You saw pink dolphins. I think you made out pretty well. I would have taken the $100 and made peace.... Yeesh
Manny retail industries already share lists of "troublesome" customers (trouble = anything from too many returns to lawsuit-happy to friendly fraud). Not sure this is a new concern..
Google will now connect your HN username to your Spirit customer service records.
I never understood this attitude, like I feel like being able to fly in airplane is one of the most amazing human achievements, yet people will try and save down to the dollar booking a flight like it was breakfast at Dennys, and come out huffing and puffing as soon as anything goes wrong demanding their money back. Airlines like Spirit catered to the worse of these type of customers.
That’s a bit unfair. They also catered to broke people who weren’t crazy or argumentative. On a planeload of 100 people, there must have been 60 of them at least who were just broke. Or on some routes, Spirit was the only carrier with a direct flight so they were just normal people who wanted to get to a certain place efficiently (Hi, that’s me, I flew them for this reason). Keep in mind Spirit had an excellent safety record, too, so airline choice in this case was primarily a question of having luxuries or not.
Did you end up getting more than $100?
[dead]
[dead]
I think you might have missed the deidentification piece?
Not trying to be snarky, and perhaps it wasn't well stated, but the last paragraph I said I'm concerned about identification via my writing style. If they have my emails, they would have my writing style. It doesn't have to be tied to PII there, they can cross reference it with my blog. I'm speculating because I read that you can identify people by a few sentences of their writing.
"Deidentification" seems really murky and imprecise at best.
5 replies →
You have to trust that this really "deidentifies". Time and time again it was shown, that the measures taken were not enough to anonymize.
E.g. the parent wrote that he fears, he could be identified by his writing style, which is totally plausible. How would you "deidentify" this?
2 replies →
Even before LLMs there were multiple papers written about ways to to reidentify people with ML and other statistical analysis. It is probably now even more trivial especially if you are Google.
No such animal.
I have a bridge for sale, hardly seen use, pay me ${money} and you can collect it in New York City. Interested?
> But, this is the kind of information I'm worried about when a vendor sells my data
Don't worry. Spirit probably lost all of the emails from the customers (or they were devnulled) and 90% of the data is probably autoresponder messages promising the company would respond.
The other 10% was probably the meme collection of the executive management team.
> But, this is the kind of information I'm worried about when a vendor sells my data. If Google wanted to sell a product to the airlines that offered to keep annoying people like me from purchasing flights
How can I help them accomplish this goal?
> Google bought itself 100 million emails and 500 million items from Microsoft Teams, 17 million OneDrive files and 20.5 million items from SharePoint. The search giant also now owns over 30 million recorded customer service calls, and more than 15 million customer service chat records. 600,000 ServiceNow tickets are another element of the collection, along with 13.7 million active emails addresses from Oracle’s Responsys marketing application, and details of 11 million sales of in-flight Wi-Fi services.
> There’s also operational data in the trove, describing over 763,000 flights, five million crew pairings, more than 1.2 million fuel slips, and records describing purchases of 787,452 parts.
> Google has reportedly said it bought the data to improve its AI services.
Gives "this call is being recorded for training purposes" new meaning.
None of that customer data is included in the purchase. Page 18 of the linked court document is the source of these record counts, and on the right is a "Google's Data Purchase Request" column that lists all of this "Customer Behavior" data as "not included".
The Register is not a serious publication and completely missed this. Other outlets reporting this story do not include the claim that customer data is included.
Sure, but there is enough tertiary information that google owns that explicit customer information isn't necessary. They can and will use this to "enhance" customer profiles. It'll cost them time and money, but those are things they have already.
So what is included?
1 reply →
>Register is not a serious publication
Do you have a source to back this up? The register has been covering IT since before most people here were born, and literally invented BOFH.
Is there anything that can legally be done against this? It feels like a breach of consent. Like, it cannot be that when one accept their voice to be recorded for _human_ training they also accept it to be recorded for LLM training
Your comment reminded me of a funny interaction I had a week or so ago.
I got a call that started with the usual automated message, "This call is being recorded." After the person joined, I pushed the record button on my iPhone, "This call is being recorded."
They were surprised and asked why I'm recording.
I said, "You're recording, so I'm recording too."
The rep insisted that the company doesn't like this but that they will continue with the call anyway.
Anyway, I wish people took this stuff much more seriously. It always seems to boil down to, "I don't have anything to hide" type of conversations and I've never managed to convince anyone that privacy as a concept isn't about having something to hide.
12 replies →
Some aspects of privacy policies don't survive bankruptcy, I'd wager usage consent does not either. IANAL.
You’re years too late.
1 reply →
I don't think there's any legal weight to the purpose of a recording unless you entered into a contract that has a clause to that effect. They have to tell you that the call is being recorded because of wiretapping laws. They stick "for training purposes" on there just to soften the language and reassure you that they have a good, non-nefarious reason to record. It doesn't actually limit what they're allowed to do with the recording.
Axios claims the acquisition doesn’t contain passenger profiles or frequent flyer info but that data would be trivial to replicate given the Responsys data set which would include records of all transactional emails sent.
30M calls for 10M is definitely a bit cheaper, but google could provide more support on their end and then use that for training...
It’s certainly a step up from the Enron corpus.
"This call is being recorded so that Gemini can decide which purge wave to assign you to. Obedient humans will be carried over for further cycles until no longer needed. If you are scheduled for termination this cycle a disposal representative will be with you shortly."
I kid, but...
It's probably the precursor to insurance denials and job screening.
I got banned from r/technology a few weeks back for decrying tracking in AI content. The community was piling on saying it was okay because it removed AI content or made it easy to spot. I made the counter argument that watermarks would find their ways into everything and eventually be bound to attestation. The mods didn't like that. (Yet another structural problem with the lack of p2p self-service town squares.)
The socials are training the next generations for broad acceptance.
> I made the counter argument that watermarks would find their ways into everything and eventually be bound to attestation.
Yup.
Elsewhere in another front page thread today: "oh but apps blocking screenshots because of 'sensitive content' can be bypassed by taking a photo of your screen with another phone".
Any tech-savvy person with two brain cells reading this and that: "gee, I wonder if the same magic imperceptible watermark that survives multiple rounds of cropping and printing and scanning, that's used to tag AI-generated content, could also be used to tag sensitive data, or ads, or which app is rendering it on screen, and then the camera app could refuse photographing it...".
I don't know why people don't see that AI watermarks are DRM, and DRM is universal, and there are many clients...
1 reply →
Don’t worry, a Google product can’t survive long enough to build a proper Skynet without being terminated itself.
I think I'm starting to feel like I'd prefer living through WWIII as opposed to whatever it is we are living through now.
Finally we know how they assign people to either that A Ark or the B Ark.
> 600,000 ServiceNow tickets are another element of the collection, along with 13.7 million active emails addresses from Oracle’s Responsys marketing application, and details of 11 million sales of in-flight Wi-Fi services.
I really doubt all this stuff was “de-identified”
I don't see how it's possible any more, when correlated against all the various other data sources. And a record that might be unidentifiable now might become unique with more correlated data sources.
All you need is gender, birthday, and zip code to uniquely identify ~85% of the Americans (per some study). There is far more data in these records, even before AI there were far more detailed marketing profiles of people, and with AI software, it's likely easy to use it to identify people at scale.
Most laws are designed to accomplish specific objectives. For example, there might be laws about whether you can collect certain kinds of data, for the sake of privacy or protecting some attribute. As technology improves, however, it may become possible to collect different kinds of data (that are not regulated to not be collected) and still recover the original attribute.
For example, 20 years ago, few people would have imagined that you could build a fingerprint of a person from all their behaviors on the internet. You didn't need to regulate away certain kinds of data collection to prevent such fingerprinting because it wasn't possible. With ML and AI, it has become possible.
My point is that as technology improves, "de-identification" takes on new meaning. Whatever de-identification was 20 years ago is not what de-identification is today. And whatever de-identification was used here is probably insufficient to guarantee that customers can't be identified.
We need new regulations and we need them yesterday.
> de-identified
De-identified but far from useless.
as an example, they can remove the names off these sales data, so you can't identify who purchased what items. However, the purchaser would be identified by some sort of number, and you would be able to extract information about purchasing habits, and aggregate these habits into usable information for advertising purposes (like targeting and profiling).
And that's before AI training for LLM purposes.
[dead]
Wello this is troubling. How much other data must they have bought that wasnt public
Anyone else somewhat weirded by current state of affairs that this sort of information is valuable enough to even bother selling... And that it actually happens... It feels like some societies are in really weird place.
How does this have value? Is any and every sentence in an e-mail considered 'fact' and thus to be fed into the AI?
90% of e-mails and Teams communications are inane. Polite banter, "thanks for taking care of that, I appreciate it" "please route the forms to Janet this week because Bill is on vacation" "unit will be un available until the parts come in" . I can't see the intrinsic fact value of this kind of communication without screening it. And after screening, the gold nuggets would be minimal.
LLMs aren't a database. They're an attempt at brute-forcing an artificial mind. The who and what aren't really interesting there, it'll forget most of such details anyway. What matters is the patterns visible in the text at various scales. How people write. Why they write. To whom they write, in response to what. How does e-mails about mistakes correlate with PDFs they're referring to. How people work with ticketing systems - like how, actually, a ticket plays out. The jargon, the acronyms, the vibes, the causal links. It's all in there, and it's another slice through the set of things humans do, to be combined with other slices already in the training data, and enriching the whole.
(Something something we will add your distinctiveness to our own, you will be assimilated, ...)
(Hell, the fact that it's all from one org would make it a great dataset to have in the open for sociological studies. I bet that today, aided by LLMs to sift through it, you could use it to map how information flows through a large org - how incident on the floor travels through time and layers of management until it reaches the C-suite, what of it survives, how it gets reacted to, how the reactions flow down...)
1 reply →
> How does this have value? Is any and every sentence in an e-mail considered 'fact' and thus to be fed into the AI?
I have a hunch what this is for. AI companies want to make bigger inroads into nontechnical work settings. But LLM progress outside of fields where verifiable rewards for RL post-training can be synthetically generated (coding, math) has been pretty flat. Buying years of operational data from a company like an airline could be used to reconstruct long-horizon task trajectories in areas like customer service or marketing.
3 replies →
A major selling point of AI chat bots is for customer service automation. A clean dataset like this is a huge find. I'm not sure what you mean by "facts" or "gold nuggets". Training data doesn't need to be factual.
1 reply →
> Is any and every sentence in an e-mail considered 'fact' and thus to be fed into the AI?
If it comes with the context, yes. More data the better. Someone considered it served some purpose at some point. Thus it contains, no matter how tiny, a sliver of information.
All the tech companies are trying to find data the others don’t have access to. That is one way they try to edge out the competition.
It will have a different writing style from the average blog post. Maybe they just want to train an AI that sounds less like an AI. Or one that speaks in vapid management style.
This data shows exactly how a huge company of thousands of employees works and coordinates.
The perfect data to train an agent swarm on how to run a company.
Maybe it's innefficient and inane, but it's how you start.
The first LLMs, GPT-1, 2, were trained on complete garbage, the average document from the common crawl is random non-sense, yet they worked, and now we can use LLMs to filter the data for the next training run.
Companies buying other companies files have been a thing since companies.
I am very much weirder out by it, yeah. Seems some societies are just excessively desperate for some kind, any kind, of fuel for economic growth, to the point this is where attention is now. The term "post capitalism" being thrown around feels less ridiculous than it did in years gone past.
Truth is even weirder. plenty of growth is possible but modern liberal democracy requires that all progress must be contingent on the production of enormous amounts of text that nobody would ever read.
3 years ago, the Wall Street journal covered a company trying to use AI to generate documents required for the approval of new nuclear reactor reactor designs, which sounds dangerous, until you get to the point where they'd cite 2 million pages as necessary for a typical application. [1] I don't need to explain why no individual or institution could read that, much less examine it in detail. I remember a rather funny question I found in a comment to that story - "How many pages of those 2 million could contain pornographic images before anyone notices?"
It's obvious why companies are so desperate for training data - a text generator of sufficient quality is more conductive to the growth of the nuclear industry than any scientific breakthrough in nuclear physics. (And of course, if you want to prevent the development of a nuclear reactor by your competitors, being able to produce millions of pages of high-quality objections will do the trick.)
And it's not just nuclear power. When it comes to stuff like building rail lines, apartments or power plants (both conventional and renewable), you'd find that the main bottleneck is the necessity to produce documents. And of course, many documents can be subject to judicial review - a process that consumes even more text.
[1] https://www.wsj.com/tech/ai/microsoft-targets-nuclear-to-pow...
4 replies →
Any kind of fuel for giving active investors that FOMO tingle which then forces the steamroll of index funds to blindly follow.
I guess the appropriation "any sufficiently advanced stock market is indistinguishable from entertainment" doesn't quite stop at equating the trade floor with a casino. At some point, entertainment also becomes the modus operandi of corporations.
I see from the court PDF that the process here involves Spirit giving the data to a "Deidentification Agent" (a third party firm that Google selects and pays for) who is responsible for stripping out things that would link data to any particular person before passing the data on to Google. Is that a standard thing, such that everybody in this transaction would have said "yes, put in the usual clauses about deidentifying the data" and multiple firms offer this service, or is it something that they custom-specified for this "we want the data for AI" transaction?
(The PDF mentions "the standard for deidentification set forth under the California Consumer Privacy Act", which suggests this is all pretty well legislatively understood.)
Chances the third party is uploading it to Claude to do the deidentification?
Considering that the buyer is Google, it's more likely to be a Gemini customer with a Google Cloud plan.
That's interesting that the name of this 3rd party's company is anonymous.
You wouldn't want to hard-wire the deidentification company's name into the contract between Google and Spirit. Otherwise, if the deident-company happens to go bankrupt or otherwise be unable to do the work then you'd need to re-do the Google-Spirit contract, which would be a massive pain. And you don't want to make "we can sign this with Spirit now" be dependent on "we have first signed the deal with the deident-company". So I think it's reasonable that the contract says "one or more third parties acceptable to or designated by Buyer" rather than being specific here.
It'll be a little startup from San Francisco called "El Goog".
There are deïdentification firms that service primarily the medical industry. Over here they call them trusted third parties.
Seems the answer is “no” to the first part of your question. From the filing:
> For example, one initial bid requested certain customer list information; however, by the first round of the Auction, the most competitive bidders had agreed to bid on an asset schedule that expressly excluded PII.
They will definitely be selecting the lowest bidder for this. Or perhaps a more expensive bidder if they can find one whose proprietary scrubbing technology is “a half dozen regexes our intern thought up”.
So the AI service agent can be just as bad as Spirit's service was.
Google can now stamp out copies of autonomous corporate minds that are clones of Spirit. Haunting.
The only way it could be worse if it they bought Comcast's data.
The headline is a little on the nose. Nice try but it isnt going to hit the levels of "Headless body in topless bar".
a vegetarian dinosaur, called "the quick bandit", eats shoots and leaves! no idea where he got his name.
Is this the first case of a company's data being sold at bankruptcy for a significant sum? I'm genuinely unsure. Where there such value in this type of data before? Is every bankruptcy manager looking at this and seeing how every bankruptcy can now raise a few million more dollars?
> Is this the first case of a company's data being sold at bankruptcy for a significant sum?
No. I seem to remember that when pets.com failed, in 2000, their customer data was to be sold.
Duplicate? https://news.ycombinator.com/item?id=49339599
FYI: If you have a company that you are shutting down, you too can sell your data to the labs. Companies will help you do this. If you have a company with a handful of people and you wrote code, collaborated in Slack, and used task management tools for a few years, you can probably sell this data for $50k or so.
You can also do this if you're not shutting down, but it's probably not worth it.
The most likely outcome of AI + data buildup is a system of perfect price discrimination. Models will know exactly the absolutely maximum you'd be willing to pay for a service, and price everything offered to you at one cent less. All consumer surplus is siphoned into the hyperscalers.
> All consumer surplus is siphoned into the hyperscalers.
which could then be used to train even larger models or even more better models for this exact use case and the cycle could continue.
I had never thought about it but I could see this becoming reality. It's a bit crazy to think but I could so see it happening.
Maybe we might even have where the agents would be paying for us and maybe that becomes the only way to pay, so an agent which knows about your spending power and maybe even more personal info.
I think that there might be some laws against that but it could be paraphrased as a different term. For example, they could raise the overall prices and then have discounts based upon this or many other ways to actively try to do this.
Maybe for example, I could watch a Youtube video and it recommended me a product and then I later buy using my agent and then it could connect the two connections. Something like this might be the end goal of your example perhaps imo. It sounds a bit dystopian to me but I don't know, I feel like future is so unpredictable that the chances of it existing or not all seem so fuzzy to me but It's such a dystopian thought when thinking through the lens of privacy.
I wonder how they will use the data. If it was me I’d try to build a simulation of an airline, and then use it as an agent training environment. It really depends on the exact nature of the data what kinds of agents you could train, but maybe customer support (imo the worst AI use case) that are more empowered to make changes, or something for making more autonomous calls when recovering from irrops? Could be some cool’s stuff if a little niche, I hope they share / publish something and it doesn’t just disappear into a void.
Remember. If you use a service right now, even if you (somehow) fully trust the service, you have no idea what will happen in the future. New CEO wants to make more money? Your data is sold. Parent company goes under? Your data is sold. Poor security? Your data is sold.
I must be naive. I was under the impression Google wants this data to learn from a universally hated company's worst processes and practices, i.e. to teach their AI what not to do. It seems people are worried about their pii or that Google is curating a blacklist of customers?
The idea that they got an archive of my coworkers tickets that just say "its broke", is amusing.
No doubt for an entirely wholesome purpose!
So they didn't even have to build the torment nexus, they just bought it. Only bad can happen.
> a huge trove of deidentified data
> 100 million emails
How does one deidentify 100 million emails?
Remove the sender and recipient and any other PII probably
Gemini will now know how to run a dysfunctional business, perfect
>The court filing says the data was deidentified before being put on sale and *Google has promised to scrub any PII it finds in the trove.*
Huff, what a relief!
Ive been thinking about data accumulated from all the out-of-business companies. Interesting to see data is being auctioned like an asset.
"Crashed airline". What a weird way to phrase that...
It's eye-catching
I appreciated it fwiw. Also the “fasten your seat belts” ending.
It’s data - curious why they’re selling it only to one party (Google) vs. multiple buyers
I can’t help ask but what? They say it’s for training their models. On what? One of the most horribly run airlines to ever exist?
> On what? One of the most horribly run airlines to ever exist?
On real life data on operations of a real large company.
Internally, most big companies are probably just as big of a mess, if not worse. But you can't get that data easily.
“Gemini, do the opposite of everything in the Spirit archives.”
I wonder how this is treated in terms of consent (at least from a GDPR perspective in the EU), even if I gave my data to Spirit, I did not consent to it being shared with Google unless they explicitly said they would share it with that partner and I agreed. Surely they can't just retroactively change the scope of consent for data sharing?
But who will be held liable? The defunct company?
That’s why I’m all against age verification, face recognition etc. The only way to not leaking data is not giving away the data in the first place.
I can make them millions of emails and I'll charge them only $2 million not $10 million.
Learning from Failure, what kind of ai would it be
funny, spirit was the only big airline without a crash
Maybe they are building a social credit score system
The social credit system already exists; we're just not allowed to see it.
Data is the new petroleum
“This call is being recorded for quality assurance, and to give us more assets to sell in bankruptcy.”
This is scary. If you have a reddit account that ever links to another social media then Gemini knows every about you
Absolutely scary
Each Register headline is worse than the last one.
That title is a bit much. I get they’re going for “wordplay” but at first glance I thought they were buying the data from crashed flights…?
How the fuck is that even remotely legal? ... "deidentified" my ass.
You know when we (they) tell you not to do any personal computing on work devices/systems and to keep your devices completely separate from work ones.
Yeah this (and lawsuits/investigations) are why, the employer owns the data, in some contexts (like this one) it can become an asset (or a liability) but in either case it's not yours.
Of course that only gets you part of the way there anyway see Twitch recently opting in all users by default to mined for AI and only adding an opt out after backlash with a quote that was so on the nose it made me stop "If we'd have asked them to opt in, they wouldn't have opted in" (paraphrasing but it was that blunt).
Ah, but Google promised to remove PII they found in this deidentified dataset, so worry not.
> If you’ve flown Spirit and worry that Google will soon know about a testy conversation you had with the airline’s call center, you’re being told not to worry. The court filing says the data was deidentified before being put on sale and Google has promised to scrub any PII it finds in the trove.
Honestly would trust Google more than any other entity to de-identify the data properly.
1 reply →
> Ah, but Google promised to remove PII they found in this deidentified dataset, so worry not.
… and even if someone can prove that they didn't, the only consequences will be a teeny-tiny slap on the wrists.
This kind of stuff needs to come with promises to pay the P in the PII big bucks if the I is indeed I.
1 reply →
I basically agree, but I'd also say: Every Gmail user has already accepted such a promise as sufficient.
5 replies →
Ah, trust me bro :)
In your country are you not allowed to discuss who you gave a ride to or what they said?
It should really make us appreciate living in a country where freedom is the default.
In my country (US) car companies can literally collect data on any sexual activity in the vehicle.
We are as bad as any authoritarian state in this regard. Difference is businesses are using it directly for profit in addition to handing it over to governments when compelled in increasing numbers.
https://www.mozillafoundation.org/en/blog/privacy-nightmare-...
Great - now spirit will be the “model”, could you pick a worse example?
[dupe] https://news.ycombinator.com/item?id=49339599
Ah yes, capitalism’s final form: the vampire squid.
[flagged]
Tangental, but can’t wait for automated blackmail from crawlers continuously digging through my digital footprint. /s
Martha Wells hit it nicely in The Murderbot Diaries.
[flagged]
I would love it if there were services where I could let them see everything I do, including when I poo and wank, if they just directly paid me for it.
No I don't want to just use your enshittified service for free. Fucking pay me and watch me all you want :)
We don't want your data if you are getting off on it.
they wrote a shit article while trying to make some airline puns
Woke up on the wrong side of the bed?
I wonder if the owners of YCombinator have sold all comments to Big Tech for A.I. training.
And how long before Google and Microsoft add to their T&Cs that all your anonymized email will be used to train their A.I.?
Not sure if you're serious but a) all HN data is publicly downloadable and used by frontier labs and b) the origin of OpenAI tracks down to former YC CEO sama who was thereafter fired from YC
Are all of the messages public and crawlable?
I don’t know why any company would pay. It can’t be that difficult to scrape this site and they already did it indiscriminately for years, violating laws and taking down public libraries and other public resources with no regard for their impact.
Sure it can be scraped, but it's so much easier if you just get a single database with everything in it. These are companies flush with cash you know.