← Back to context

Comment by elric

1 day ago

I fully share your concerns. And I don't understand how apparently tons of Teams and email conversations can be archived and sold without any kind of scrutiny. How can such data be sold without the consent of all involved parties? What gives Google the right to use it to train LLMs? Is that just a way of washing away the legal protections?

It is being scrutinized. The sale is overseen by the courts. Also, the media is scrutinizing. Also, PII has already been addressed by the court, from the article: "If you’ve flown Spirit and worry that Google will soon know about a testy conversation you had with the airline’s call center, you’re being told not to worry. The court filing says the data was deidentified before being put on sale and Google has promised to scrub any PII it finds in the trove."

  • "De-identified" data is trivially easy to re-identify, especially by google.

    https://www.nytimes.com/2006/08/09/technology/a-face-is-expo...

    • Specially when you have a list of flights, people on board, issues, etc... The fact that they are specifically tellling people to not worry about that is also a red flag for me. They know what they'd worry about if they were the affected ones.

    • Sure, you can argue that its a bad deal, shouldn't be allowed period, etc. But that is a different argument than saying that there is no scrutiny.

      6 replies →

  • I'm sure we can trust google to keep to their word and that we can trust a bankrupt airline to do their best at removing pii.

    • Yes, the same google that has repeatedly, entirely "by accident", captured boatloads of wifi data with their wardriving vehicles (or google streetview or whatever it's called). They sure seem like a trustworthy bunch.

      4 replies →

    • The article claims it has already been removed, that Google is committing to remove anything leftover that they find.

      You can argue that its a bad deal, shouldn't be allowed period, etc. But that is a different argument than saying that there is no scrutiny.

  • I prior worked at Google, I can say they DO de-anonymize data. You’d be foolish to think some PM within the company wouldn’t use this for malice. L

  • I'm sorry but such assurances are worthless without being explicit what was scrubbed and what is retained. An "anonymous" customer ID with a list of flights is very identifiable when you have other information about the trips someone has taken. PII is not a binary yes or no and even benign data can become a problem in aggregate.

  • This is when a track record of Google's "Don't be evil" motto, culture and corporate habits being literally front and center on its official code of conduct, instead of moved to the very last line in 2018, would have persuaded people to give it the benefit of the doubt. Functionally effective privacy seems to be retreating ever more exclusively into the domain of very wealthy families and behind the corporate veil (by purchasing information scrubbing services on a regular basis), and the loss by normal people of the commons of mass privacy has unfortunately not been appreciated by the common citizen. It is a more valuable commons than recognized by most citizens, and is being rapidly co-opted and monetized by commercial entities that are not aligned with individual interests.

    Even as an investor who stands to benefit from that monetization in the short term, I stand against this trend because like any Tragedy of The Commons economic scenario, in the long term (which isn't that long due to the automation that harvests this resource) it sows the seeds of its own dilution into functionally near non-commercial value.

Makes one appreciate living in place with sufficient constitutional protections against this sort of stuff. Even for work stuff selling this info wouldn't fly in some parts of the world.

  • If you're referring to GDPR, companies routinely evade such protections using "informed consent" / "legitimate interests" loopholes. The big ones get caught once in a while, get a slap on the wrist and continue to do whatever they were doing before, albeit with more safeguards.

Not for nothing, but you have probably already consented. Typically user agreements allow for this kind of sale if you’ve authorized use and processing but YMMV.

Usually when you work a job you sign a little thing that says "yeah you own everything I produce for you, no matter how small".

Which is, of course, ridiculous, and follows the trend of absurdist contract law wrangling in corporations. Similar to non-competes and NDAs.

It makes sense to some degree, but the fact that semi-private conversations are included in that makes no sense. These have little to no business purpose.

The party owning this data (Spirit Airlines) is consenting to the sale. Employees and customers of Spirit consented when they started employment and did business with Spirit, respectively.

  • If this were a European company: That’s not how the GDPR works. You can only consent to specific purposes of using the data.

  • This is why the GDPR (and to a lesser extent the CCPA) is a good thing. The data was supplied for a specific purpose. The handler of the data should have to obtain further consent if they wish to use it for another purpose.

  • Did they consent? Just because one receives a letter it doesn't mean they “own” it, much less that they are entitled to publish it at their leisure. If Spirit were active in any country with GDPR-style laws, the seller of these data would be most likely investigated.

Since it’s work communications, consent was already given.

When you join a company, you typically sign an agreement that talks about how the company owns all your output. Thumbs upping a Teams message is work output and they own it.

Every email sent and received. Every keystroke. Etc etc etc.

If you don’t want your employer to log and sell it, start your own company. Or use a personal device. I do the latter.

  • I don't know the US law, but surely in Europe specifically every private conversation is private, period. No matter if it's work email, your company cannot read the emails directed at your company mailbox by its initiative (of course in case it's needed a judge can ask it to be taken as evidence), nor it can read the files on your computer, or anything similar, no matter if the device it's company provided, because it would be considered the same as using a camera to spy on the employee, that is of course illegal.

    Of course if it's shared communication media (e.g. a mailing list) it can, but not at your private address, no matte if it's @company.com, it's considered the same as your private email.

    • It heavily depends on country if employer can access the email or not. For example in Italy:

      > Italian Supreme Court case law according to which defensive controls may be carried out where there is a well-founded suspicion of unlawful conduct, provided that an appropriate balance is struck between the employer’s interests and the employee’s dignity and privacy, and that the control concerns data acquired after the suspicion arose.

  • That's not consent. It's a one-sided condition of employment. Consent would imply a meeting of the minds and a way for each employee to negotiate, or opt-out without losing employment.

    It's like saying I consent to my phone company's 200 page long terms and conditions.

    Corporate America has a very fucked up definition of consent, and they seem to have spread that definition broadly.

> How can such data be sold without the consent of all involved parties?

In the US, whoever owns the computer owns the data on it. Courts have routinely ruled that you have no say in what other people collect about you. The goal of bankruptcy courts is to minimize the losses of the creditors. And bankruptcy courts routinely rewrite contracts except where statute prevents it (like mortgages).

In the EU, you own the data about yourself. A lot of people utterly hate GDPR, but that's reason that you own the data about yourself.

[flagged]

  • Mass automated data collection and automated analysis are probably the biggest threat to freedom in the present day.

    • And here I was thinking that flooding the zone with fascist bullshit, an office that's entirely above scrutiny, and their violent, unaccountable private army was the biggest threat to it.

      1 reply →

    • Funny, when I watch the news I see freedom being taken away by authoritarians, not people tracking who complains about window seats, or what pizza place you like best.

      2 replies →

  • Why should corporations have the same rights and freedoms as human beings?

    I think this is a far more important question than do you believe in right or left economic policy. idc, I want you to know, do you think a human’s rights, especially many humans together, outweigh that of non living entities like large tech companies.

  • What a load of crap. Your liberty to swing your fist ends where my nose begins. What's "triggering" is when it hits my nose.