What screenreaders are you using to test the models with?
HN user
jdp23
Strategist, activist, software engineer ...
@jdp23 and http://facebook.com/jdp23 are the best ways to get in touch with me, or leave a comment somewhere on http://talesfromthe.net/jon
Really interesting paper, and thanks for the followon points.
The over-optimism is indeed a really important takeaway, and agreed that it's not tool-dependent.
Agreed. Although based on the downvotes HN doesn't see it that way, who could have predicted?
Yes, it's very typical. There are almost never any consequences for actions like this.
While it has some good features (data minimization) it's also got some major weaknesses -- for example state attorneys general say they wouldn't be able to enforce it, it preempts existing stronger privacy laws in states like California and Illinois (and potentially Washington to some extent), EFF's warned about some big loopholes, etc. And that was even before these latest changes.
Why not move the needle in the right direction and then lobby for additional things?
Two reasons. Preemption not only weakens some existing laws, it keeps states from passing future stronger laws -- so it caps protections. And, politicially, no privacy law in the US has ever been strengthened by Congress (or state legislatures) ... so, it's very unlikely that the lobbying for additional things will have an affect.
A new draft was released last week -- the committee markup's on Thursday. https://iapp.org/news/a/new-draft-apra-released-ahead-of-27-... has a summary. https://punchbowl.news/wp-content/uploads/PRIVACY_05_xml-005... is the text.
I htink there were three key sections that got cut out:
1) "A covered entity or service provider may not collect, process, retain, or transfer covered data in a manner that discriminates in or otherwise makes unavailable the equal enjoyment of goods or services on the basis of race, color, religion, national origin, sex, or disability." This was hugely important, it was sa major victory to get a bipartisan committee majority supporting similar language in APRA's predecessor ADPPA.
2) Requirements for algorithmic impact assessments by large companies (I forget the exact threshold).
3) A requirement to let people opt-out of consequencial automated decisions (with some exceptions), somewhat similar to California's CCPA.
Paul Graham, 2020: "Lambda School will teach you programming faster than most colleges. And it not only works well remotely, but was designed to from the start." [1]
Paul Graham, 2022: "Of 1277 students who graduated from Lambda School in 2020 and sought jobs, 950 got them, for a placement rate of 74.8%.
(Lambda's weirdly dedicated haters will be happy to hear that these numbers were audited by an accounting firm.)" [2]
Yep. When I get upgraded to an SUV I exchange it for something along the lines of the car I had originally reserved. I've asked them to put something in my file saying "don't upgrade to SUV" but it appears beyond the capabilities of their system.
Defending RIghts and Dissent has an form to contact Congress on FISA Section 702 renewal
https://secure.rightsanddissent.org/a/protect-liberty-act
It asks legislators to vote
NO on the Intelligence Community's fake reform bill, the FISA “Reform” and Reauthorization Act (which as the OP points out is actually an expansion of warrantless wiretapping)
YES on the Protect Liberty and End Warrantless Surveillance Act, which actually does include some significant reforms
Yeah, that's one of the big ways that it's stronger than California's law (where the private right of action is limited to data breaches). [Another way is that it's opt-in, with an additional authorization for sale of data; California's law is opt-out.]
Of course MHMD doesn't take effect until after the next legislative session, so I'm sure there will be attempts to weaken it. So I'm not counting any chickens quite yet!
It's very good in that it's significant progress over other US-based laws. Then again if you compare it to the much stronger privacy protections in the EU, there's still a looooong way to go.
It's true that California's legislation gets a lot of industry input, and they're not going to pass something puts the big tech companies out of business. On the other hand, there's a very effective coalition of privacy organizers there -- who are quite familiar with tech's tactics, and can be very effective at cutting through tech's spin with legislators. Plus, the California Privacy Protection Agency (which got established by a referendum, not through the legislature) has a lot of clout -- there isn't anything comparable in any other US state.
Washington state has similar dynamics, although with the CPPA equivalent. Microsoft and Amazon are hugely influential here; but, grassroots organizers had repeatedly stopped them from getting the very weak Bad Washington Privacy Act through the legislature. And this year, we passed My Health My Data -- stronger in some ways than California's privacy law.
Texas ... has been a disappointment. The privacy law they passed this year is based on the Bad Washington Privacy Act but significantly weaker.
It's a very good point, I haven't seen a lot of discussion of the role of Experian et al in KOSA.
In the US, it seems like it's mostly being driven by "child-safety" orgs, some of whom are well-intentioned but just don't understand the downsides, some of whom are anti-LGBTQ and appreciate the downsides. But others may well be active behind the scenes.
The new version that just dropped today is even worse. Evan Greer has a good Twitter thread: https://twitter.com/evan_greer/status/1684303837874593794
And, there's a committee vote on KOSA tomorrow, so if you're in the US please contact your Congresspeople -- https://www.stopkosa.com/
Of course Meta hasn't been prevented from adopting an open standard. The section on "The next step in embrace-and-extend, coming soon to a standards working group near you" goes into more detail.
As the article says, "So Meta and their supporters aren't going to give up on their plans to embrace and extend the fediverse just because of the pushback." The section on "The next step in embrace-and-extend, coming soon to a standards working group near you" goes into more detail.
Yeah when there are multiple causes it's hard to know how much each contributed.
AcitivityPub's also meant to be extended, there are FEPs, and it's likely that the working group will come up with a new version as well. That said there certainly are differences between XMPP and ActivityPub, most people say the ActivityPub ecosystem is significantly farther along than XMPP was.
I could imagine Meta doing an open-source AP server (and with a fresh start it would be cleaner base than Mastodon). I also wouldn't be surprised if the release a app building toolkit / framework / whatever ... there isn't a good one now, they do that stuff well, and as they introduce proprietary AP extensions then they toolkit is a good way to get people to adopt them. But it's very hard to know at this point, it's also possible it's just PR spin and they won't really invest in it. We shall see.
Anyhow, good discussion, thanks much!
I wasn't objecting to your point so much as you calling their summary a fair point. They stopped reading the article before they got to the example of non-public information in it, so mischaracteried it, which doesn't seem fair to me.
Agreed that if something's available encrypted on the web with no login required then usually the only protections you can put on it is security-through-obscurity like hard-to-guess links that don't show up on profiles (YouTube's "unlisted videos") or advisory like "noindex". But, although it's not something I talked about in this article, there are design choices. Mastodon (etc) could evolve so that a lot of what's currently "public" isn't available on the web with no login required.
Agreed that these other issues were a problem for XMPP. Christina Warren made this exact point on Mastodon a few hours ago -- in response to a post from Evan Prodromou that talked about the role that spam and harassment played and how he and others in the XMPP community didn't diversify the network. So, there are multiple factors. That said, I still think the post I linked to is very much worth reading.
The article explicitly says that talking only about public posts ignores other privacy risks, and has an example related to a followers-only post. Knowing that, do you really think his point is fair?
Blocking Threads is necessary but not sufficient. I should probably be clearer about that in the article.
Thanks for the explanation, that all makes sense. I don't care about the votes (or karma), it was really about whether it would impact it's ranking and visibility, clearly it's been thought through!
It's certainly a challenge. Mastodon's development tends to prioritize mastodon.social (Eugen Rochko is BFDL of the software platform and also runs mastodon.social) -- for example, the mobile app now signs people up by default on mastodon.social, and functionality that people running smaller instances have implemented in forks hasn't been integrated back into the main line. So there's the weird dynamic that people generally have better experiences on small instances (as long as they're well-admined) but the vast majority of the current fediverse is on large Mastodon instances. So it'll be interesting to see what happens in response to Meta. There's likely to be a partition, and if .social winds up taking a Meta-friendly position, then the anti-Meta region may be much less centralized.
https://heat-shield.space/mastodon_two_camps.html looks at tensions between people who just want a "better twitter" (which tends to lead to centralization) and people who focus more on small communities (a more decentralized solution).
I should have been clearer about how this relates to general issues. I added a sentence
"Of course, Meta's far from the only threat out there, but as I discuss in 'Threat modeling Meta, the fediverse, and privacy', looking at Meta-related threats also points to solutions that increase privacy and safety in the fediverse more generally."
Here's a link to the longer post (still a draft). https://privacy.thenexus.today/fediverse-threat-modeling-pri...
And agreed, it doesn't scale for Meta to infiltrate people into every single fediverse instance -- although threat actors who are targeting specific people or communities might well do this, so it's also something to take into account.
Did you even read the article? This is about data going to Threads from people who aren't on Threads.
There's a lot of discussion about that! Here's a very good article on the EEE threat. https://ploum.net/2023-06-23-how-to-kill-decentralised-netwo...
Personally I think it's more an "embrace, extend, and exploit" approach; a decentralized model could work well for Meta, for example if they do revenue-sharing on ads hosted by other instances (think Disney or LA Lakers).
Update: here's another good article looking at how Meta could embrace and extend -- again, not extinguish. https://darnell.day/heavy-meta-four-business-reasons-why-ins...
That's true -- and my more detailed threat modeling post has a big public service announcement saying "don't share information on the fediverse that you want to keep secret" -- but there's a lot of information that's not "secret" that people do want to share on social networks.
https://privacy.thenexus.today/fediverse-threat-modeling-pri...
Thanks ... but what does that do to the ranking? Tnere were quite a few upvotes on the newer submission that don't seem to have transferred over.
Here's a couple of excerpts highlighting way many LGBTQ+ people see Libs of TikTok as a threat
"After gaining a large Twitter following in the spring as she baselessly accused LGBTQ teachers of being pedophiles and “groomers,” Raichik began criticizing children’s health facilities earlier this summer, targeting a hospital in Omaha in June and another in Pittsburgh in August. The attacks resulted in a flood of online harassment and phoned-in threats at both hospitals."
(From "Twitter account Libs of TikTok blamed for harassment of children’s hospitals" https://www.washingtonpost.com/technology/2022/09/02/lgbtq-t...)
...
"One former English teacher, Tyler Wrynn, told Lorenz for her piece that he had been harassed, sent death threats and eventually fired after one of his TikToks about supporting LGBT+ kids was posted by Raichik"
(From "How Libs of TikTok Became an Anti-LGBTQ+ Hate Machine" https://www.them.us/story/libs-of-tik-tok-twitter-facebook-i... )
"While the account doesn’t always explicitly encourage followers to do anything, its posts have sometimes led people to harass or physically threaten its subjects. In one instance, a group of five Proud Boys members disrupted a Drag Queen Story Hour at a public library, spewing homophobic and transphobic insults at attendees, which investigators believe was spurred by Libs of TikTok."
(from "Teacher targeted by Libs of TikTok sent death threats and lost his job" https://www.thepinknews.com/2022/04/20/libs-of-tiktok-teache... )
Back in the day Reed told me that he added the leak detection to Purify v1 towards the end of the dev cycle and was very surprised that it wound up being one of their biggest selling points
Mastodon lead developer has resisted including some of the glitch-soc improvements since 2017 -- like "local-only posts", which are valuable both from a privacy and anti-harassment (and are also in Hometown).