HN user

jdp23

7,710 karma

Strategist, activist, software engineer ...

@jdp23 and http://facebook.com/jdp23 are the best ways to get in touch with me, or leave a comment somewhere on http://talesfromthe.net/jon

Posts301
Comments1,679
View on HN
privacy.thenexus.today 1y ago

9 things the Social Web Foundation could do to prioritize safety in the fedvirse

jdp23
5pts0
privacy.thenexus.today 2y ago

Federal Privacy Legislation Update: The American Privacy Rights Act (APRA)

jdp23
2pts0
privacy.thenexus.today 2y ago

Embrace, Extend, and Exploit: Meta's Plan for ActivityPub and the Fediverse

jdp23
4pts0
privacy.thenexus.today 3y ago

Meta now says Threads' ActivityPub integration is “a long way out”

jdp23
5pts7
privacy.thenexus.today 3y ago

Blocking Threads won't be enough to protect privacy once they join the Fediverse

jdp23
197pts415
www.nytimes.com 4y ago

Substack is laying off 14% of its staff

jdp23
131pts191
www.forbes.com 4y ago

Sequoia, Y Combinator, AZ16 Under Scrutiny in Congress over ‘Tech Bro’ Culture

jdp23
37pts30
jedii.tech 4y ago

Microsoft Shareholder Resolutions – Facial Recognition, Pay Equity, and More

jdp23
1pts0
people.idsia.ch 6y ago

Critique of 2018 Turing Award for Drs. Bengio and Hinton and LeCun

jdp23
4pts1
medium.com 6y ago

Lessons from WT:Social

jdp23
2pts0
medium.com 6y ago

WT: Social will have to pick a side

jdp23
1pts0
medium.com 6y ago

Why is an intellectual dark web site at the top of my feed? Thoughts on WTSocial

jdp23
2pts0
www.thecut.com 7y ago

Google Walkout Organizers Explain Their Demands

jdp23
10pts2
www.reddit.com 8y ago

Reddit AMA with Shahid Buttar, on Leave from EFF and Running for Congress in SF

jdp23
6pts1
qz.com 8y ago

Trump may deport thousands of Indian H-1B visa holders waiting for green cards

jdp23
5pts0
www.aclunc.org 8y ago

ACLU of California Statement: White Supremacist Violence Is Not Free Speech

jdp23
59pts145
www.eff.org 8y ago

EFF Urges Supreme Court to Take on Unconstitutional NSA Surveillance

jdp23
5pts0
gizmodo.com 8y ago

Men Have Always Used 'Science' to Explain Why They're Better Than Women

jdp23
15pts29
motherboard.vice.com 8y ago

200 Terabyte Proof Demonstrates Potential of Brute-Force Automated Verification

jdp23
2pts0
techcrunch.com 9y ago

Dear tech dudes, stop being so dumb about women

jdp23
2pts0
medium.com 9y ago

Mastodon: 14 perspectives on a breakthrough month

jdp23
2pts0
www.mercurynews.com 9y ago

Oroville Dam: Feds and state officials ignored warnings 12 years ago

jdp23
121pts59
www.reddit.com 9y ago

We're here (on Reddit) from the ACLU. Thank you for your support

jdp23
5pts0
www.fastcodesign.com 9y ago

The Founder: A Game About the Dark Side of Silicon Valley

jdp23
4pts0
www.propublica.org 9y ago

Bias in Criminal Risk Scores Is Mathematically Inevitable, Researchers Say

jdp23
4pts5
www.recode.net 9y ago

Kara Swisher: Shame on Silicon Valley for Climbing the (Trump) Tower in Silence

jdp23
17pts7
medium.com 9y ago

Learning from Hacker News’ “Detox” Experiment

jdp23
3pts1
www.recode.net 9y ago

Who's going to Trump’s tech summit next week?

jdp23
13pts1
news.ycombinator.com 9y ago

Ask HN: What did you learn from the “no politics” experiment?

jdp23
7pts7
www.wsj.com 9y ago

Donald Trump Invites Tech Leaders to a Meeting

jdp23
12pts7

While it has some good features (data minimization) it's also got some major weaknesses -- for example state attorneys general say they wouldn't be able to enforce it, it preempts existing stronger privacy laws in states like California and Illinois (and potentially Washington to some extent), EFF's warned about some big loopholes, etc. And that was even before these latest changes.

Why not move the needle in the right direction and then lobby for additional things?

Two reasons. Preemption not only weakens some existing laws, it keeps states from passing future stronger laws -- so it caps protections. And, politicially, no privacy law in the US has ever been strengthened by Congress (or state legislatures) ... so, it's very unlikely that the lobbying for additional things will have an affect.

A new draft was released last week -- the committee markup's on Thursday. https://iapp.org/news/a/new-draft-apra-released-ahead-of-27-... has a summary. https://punchbowl.news/wp-content/uploads/PRIVACY_05_xml-005... is the text.

I htink there were three key sections that got cut out:

1) "A covered entity or service provider may not collect, process, retain, or transfer covered data in a manner that discriminates in or otherwise makes unavailable the equal enjoyment of goods or services on the basis of race, color, religion, national origin, sex, or disability." This was hugely important, it was sa major victory to get a bipartisan committee majority supporting similar language in APRA's predecessor ADPPA.

2) Requirements for algorithmic impact assessments by large companies (I forget the exact threshold).

3) A requirement to let people opt-out of consequencial automated decisions (with some exceptions), somewhat similar to California's CCPA.

Paul Graham, 2020: "Lambda School will teach you programming faster than most colleges. And it not only works well remotely, but was designed to from the start." [1]

Paul Graham, 2022: "Of 1277 students who graduated from Lambda School in 2020 and sought jobs, 950 got them, for a placement rate of 74.8%.

(Lambda's weirdly dedicated haters will be happy to hear that these numbers were audited by an accounting firm.)" [2]

[1] https://twitter.com/paulg/status/1254809755681525762

[2] https://twitter.com/paulg/status/1254809755681525762

Yep. When I get upgraded to an SUV I exchange it for something along the lines of the car I had originally reserved. I've asked them to put something in my file saying "don't upgrade to SUV" but it appears beyond the capabilities of their system.

Defending RIghts and Dissent has an form to contact Congress on FISA Section 702 renewal

https://secure.rightsanddissent.org/a/protect-liberty-act

It asks legislators to vote

NO on the Intelligence Community's fake reform bill, the FISA “Reform” and Reauthorization Act (which as the OP points out is actually an expansion of warrantless wiretapping)

YES on the Protect Liberty and End Warrantless Surveillance Act, which actually does include some significant reforms

Yeah, that's one of the big ways that it's stronger than California's law (where the private right of action is limited to data breaches). [Another way is that it's opt-in, with an additional authorization for sale of data; California's law is opt-out.]

Of course MHMD doesn't take effect until after the next legislative session, so I'm sure there will be attempts to weaken it. So I'm not counting any chickens quite yet!

It's very good in that it's significant progress over other US-based laws. Then again if you compare it to the much stronger privacy protections in the EU, there's still a looooong way to go.

It's true that California's legislation gets a lot of industry input, and they're not going to pass something puts the big tech companies out of business. On the other hand, there's a very effective coalition of privacy organizers there -- who are quite familiar with tech's tactics, and can be very effective at cutting through tech's spin with legislators. Plus, the California Privacy Protection Agency (which got established by a referendum, not through the legislature) has a lot of clout -- there isn't anything comparable in any other US state.

Washington state has similar dynamics, although with the CPPA equivalent. Microsoft and Amazon are hugely influential here; but, grassroots organizers had repeatedly stopped them from getting the very weak Bad Washington Privacy Act through the legislature. And this year, we passed My Health My Data -- stronger in some ways than California's privacy law.

Texas ... has been a disappointment. The privacy law they passed this year is based on the Bad Washington Privacy Act but significantly weaker.

It's a very good point, I haven't seen a lot of discussion of the role of Experian et al in KOSA.

In the US, it seems like it's mostly being driven by "child-safety" orgs, some of whom are well-intentioned but just don't understand the downsides, some of whom are anti-LGBTQ and appreciate the downsides. But others may well be active behind the scenes.

Yeah when there are multiple causes it's hard to know how much each contributed.

AcitivityPub's also meant to be extended, there are FEPs, and it's likely that the working group will come up with a new version as well. That said there certainly are differences between XMPP and ActivityPub, most people say the ActivityPub ecosystem is significantly farther along than XMPP was.

I could imagine Meta doing an open-source AP server (and with a fresh start it would be cleaner base than Mastodon). I also wouldn't be surprised if the release a app building toolkit / framework / whatever ... there isn't a good one now, they do that stuff well, and as they introduce proprietary AP extensions then they toolkit is a good way to get people to adopt them. But it's very hard to know at this point, it's also possible it's just PR spin and they won't really invest in it. We shall see.

Anyhow, good discussion, thanks much!

I wasn't objecting to your point so much as you calling their summary a fair point. They stopped reading the article before they got to the example of non-public information in it, so mischaracteried it, which doesn't seem fair to me.

Agreed that if something's available encrypted on the web with no login required then usually the only protections you can put on it is security-through-obscurity like hard-to-guess links that don't show up on profiles (YouTube's "unlisted videos") or advisory like "noindex". But, although it's not something I talked about in this article, there are design choices. Mastodon (etc) could evolve so that a lot of what's currently "public" isn't available on the web with no login required.

Agreed that these other issues were a problem for XMPP. Christina Warren made this exact point on Mastodon a few hours ago -- in response to a post from Evan Prodromou that talked about the role that spam and harassment played and how he and others in the XMPP community didn't diversify the network. So, there are multiple factors. That said, I still think the post I linked to is very much worth reading.

It's certainly a challenge. Mastodon's development tends to prioritize mastodon.social (Eugen Rochko is BFDL of the software platform and also runs mastodon.social) -- for example, the mobile app now signs people up by default on mastodon.social, and functionality that people running smaller instances have implemented in forks hasn't been integrated back into the main line. So there's the weird dynamic that people generally have better experiences on small instances (as long as they're well-admined) but the vast majority of the current fediverse is on large Mastodon instances. So it'll be interesting to see what happens in response to Meta. There's likely to be a partition, and if .social winds up taking a Meta-friendly position, then the anti-Meta region may be much less centralized.

https://heat-shield.space/mastodon_two_camps.html looks at tensions between people who just want a "better twitter" (which tends to lead to centralization) and people who focus more on small communities (a more decentralized solution).

I should have been clearer about how this relates to general issues. I added a sentence

"Of course, Meta's far from the only threat out there, but as I discuss in 'Threat modeling Meta, the fediverse, and privacy', looking at Meta-related threats also points to solutions that increase privacy and safety in the fediverse more generally."

Here's a link to the longer post (still a draft). https://privacy.thenexus.today/fediverse-threat-modeling-pri...

And agreed, it doesn't scale for Meta to infiltrate people into every single fediverse instance -- although threat actors who are targeting specific people or communities might well do this, so it's also something to take into account.

There's a lot of discussion about that! Here's a very good article on the EEE threat. https://ploum.net/2023-06-23-how-to-kill-decentralised-netwo...

Personally I think it's more an "embrace, extend, and exploit" approach; a decentralized model could work well for Meta, for example if they do revenue-sharing on ads hosted by other instances (think Disney or LA Lakers).

Update: here's another good article looking at how Meta could embrace and extend -- again, not extinguish. https://darnell.day/heavy-meta-four-business-reasons-why-ins...

Here's a couple of excerpts highlighting way many LGBTQ+ people see Libs of TikTok as a threat

"After gaining a large Twitter following in the spring as she baselessly accused LGBTQ teachers of being pedophiles and “groomers,” Raichik began criticizing children’s health facilities earlier this summer, targeting a hospital in Omaha in June and another in Pittsburgh in August. The attacks resulted in a flood of online harassment and phoned-in threats at both hospitals."

(From "Twitter account Libs of TikTok blamed for harassment of children’s hospitals" https://www.washingtonpost.com/technology/2022/09/02/lgbtq-t...)

...

"One former English teacher, Tyler Wrynn, told Lorenz for her piece that he had been harassed, sent death threats and eventually fired after one of his TikToks about supporting LGBT+ kids was posted by Raichik"

(From "How Libs of TikTok Became an Anti-LGBTQ+ Hate Machine" https://www.them.us/story/libs-of-tik-tok-twitter-facebook-i... )

"While the account doesn’t always explicitly encourage followers to do anything, its posts have sometimes led people to harass or physically threaten its subjects. In one instance, a group of five Proud Boys members disrupted a Drag Queen Story Hour at a public library, spewing homophobic and transphobic insults at attendees, which investigators believe was spurred by Libs of TikTok."

(from "Teacher targeted by Libs of TikTok sent death threats and lost his job" https://www.thepinknews.com/2022/04/20/libs-of-tiktok-teache... )

Mastodon lead developer has resisted including some of the glitch-soc improvements since 2017 -- like "local-only posts", which are valuable both from a privacy and anti-harassment (and are also in Hometown).