8 ms·
Federal Right to Privacy Act – Draft legislation
- chzblck 6mo agoBold idea but too much money on the other side to let this gain traction
- JumpCrisscross 6mo ago> too much money on the other side to let this gain traction This view is unfortunately common among regular privacy advocates. That makes them politically useless. To have a hope, this bill needs to target support outside tech, where civic laziness and nihilism are normalized. I’m not seeing any indication of that strategy here.
- Nevermark 6mo agoYou are saying exactly, and I mean exactly, what they would want. Dismissing an avenue of progress outright is to be defeatist or to sow defeat. AI is going to use all this information against us. Because AI alignment can’t be better than people and corporations deploying the AI. Lack of privacy is now a gaping security hole, being continually exploited on all our devices, across most sites on the internet. [EDIT: And the leverage that information enables is being auctioned off to manipulators who we are exposed to continuously. This is just the beginning.] We need to plug this security hole now, before power centralizes further and we can’t.
- chzblck 6mo agoGoogle, TTD, Applovin, Magnite, Roku, Freewheel, + 100 more adtech and martech companies. Lets add Facebook, twitter, openai, claude + all the others. then lets add Flock, Palantir. Do you honestly think the lobbying from them would be more or less if this bill gained any traction?
- Nevermark 6mo agoOf course they are going to resist. That is the terrain. That doesn’t change the critical need to make progress. Surrendering power, even when apparently outgunned, is a far more insidious enemy than opposition.
- rexpop 6mo agoAmen! And, in fact, the harder they fight, the harder our resolve.
- dotancohen 6mo ago[dead]
- JumpCrisscross 6mo ago> Do you honestly think the lobbying from them would be more or less if this bill gained any traction? Small communities are thwarting these companies’ datacenter buildouts. The difference is they show up. Defeating privacy in tech is easy because there is no functional opposition.
- kg 6mo agoDoes anyone know what this part means? > Require Social Security Numbers to authenticate preventing fraud. There's a ton of stuff piled into the agenda on this page but that one in particular stumped me. Is it proposing that people (who?) are required to use their SSN to authenticate (for what?) or that the SSN agency is supposed to authenticate... something before doing something?
- buzer 6mo agoThe bill text is at https://github.com/righttoprivacyact/bill/blob/main/bill/right_to_privacy_act.md https://github.com/righttoprivacyact/bill/blob/main/bill/rig... It contains following: > (i) Finance and high-risk identity proofing.—No person shall extend credit, originate a loan, open a high-risk financial account, or provide another high-risk financial service based solely on a Social Security number, static identity information, or an uploaded image or copy of a government-issued identity document. A person engaging in such activity shall use multi-factor identity verification reasonably designed to verify both record consistency and claimant control, using less intrusive reasonably reliable methods where available. > (j) Social Security number not sufficient identity credential.—A Social Security number, taxpayer identifier, or similar identifier shall not by itself be treated as proof of identity for purposes of this Act. So, to me at least, it sounds like they actually mean "Providers must not use SSN for authentication (including fraud)".
- rdevilla 6mo agoHaha. This will accomplish nothing, because the surveillance dragnet is built and used by the people themselves, who deliberately (ab)use the very technologies that enable this breach of privacy at scale. Can't have your cake and eat it too.
- wakawaka28 6mo agoIt will probably accomplish nothing for other reasons. There are secret laws in this country which violate the constitution. I don't think the average person appreciates privacy as much as they should. But saying they are complicit in the making of this mess is going way too far. There are not so many choices in tech as you think. The most private ones require high technical expertise, and involve risks other than those presented by corporate tech. For example, you may have to trust a small number of unpaid individuals (who may even be anonymous) to deliver software.
- Cider9986 6mo agoWe have to try.
- panny 6mo ago>Update CAN-SPAM for one-click deletion of email addresses from databases. Then how can I know not to send you another email if I don't have your email flagged in my database to do-not-send?
- JoshTriplett 6mo agoYou delete the rest of your spam database and replace it with `fn can_send_spam(_: Email) -> bool { false }`. You delete the "can we spam you" checkbox from your checkout page and replace it with "return false". For legitimate newsletters and similar: you delete any and all forms that allow signing up to receive emails without affirmative consent from that email address that they want to receive mail, and you offer a one-click effective-immediately "unsubscribe" to retract that consent at any time. Then, you can tell if you can send someone mail based on whether they're in your database of people who have explicitly consented to send you mail, and you don't ever send email to anyone else other than one-time consent requests and order-confirmation-style transactional mail. The only legitimate database of emails is "these people have explicitly confirmed to us that we can email them"; any other database is radioactive waste, delete it.
- panny 6mo ago>The only legitimate database of emails is "these people have explicitly confirmed to us that we can email them"; any other database is radioactive waste, delete it. That's not actually how HIPAA compliance works. You're required to keep 7 years of communications, and part of those communications is who you sent it to. Amazon SES sends complaint notifications and you're not allowed more than 1 complaint per 1000 emails or they shut you down too. People who are repulsively anti-spam have ruined email as a medium. I'm merely pointing out the technical aspect of this bill is ridiculous and everyone sending transactional emails will fight you, killing any bill you might have.
- JoshTriplett 6mo ago> People who are repulsively anti-spam have ruined email as a medium. That is a ridiculous attitude. Spam has ruined email; anti-spam is the attempt to keep it usable. Anti-spam wouldn't be needed in the first place if not for spammers. > Amazon SES sends complaint notifications and you're not allowed more than 1 complaint per 1000 emails or they shut you down too. Good, that sounds like a reasonable step. Now if only there were existential-level fines for sending spam, too. Yes, I am aware of people who use the "report spam" button because they can't be bothered to hit "unsubscribe". Which wouldn't be as much of a problem if 1) they felt like they'd subscribed in the first place, rather than being tricked by a default-to-spamming "do you not not not want us to not spam you" checkbox, 2) spammers didn't act like having an "unsubscribe" link was all they need to do to make it okay to send unsolicited commercial email, and 3) unsubscribing reliably worked. > transactional emails Transactional emails have never been the problem. People buying lists of emails and sending email marketing spam and trying to defend that as in any way a legitimate practice have always been the problem, along with phishing, scams, etc.
- anonym29 6mo agoPrivacy advocates, UNITE! Just leave your name and email on this contact form on github, so privacy can be solved once and for all! (/s, but an interesting paradox for pro-privacy initiatives soliciting identifiable public support)
- Spivak 6mo agoDefining a picture of your government id not being a sufficient credential for… well anything would probably be enough to kill all these age verification laws and might get some traction legislatively if you frame it right. It has the benefit of being literally true, whoever thought the was necessary to have a bunch of hard to forge security measures on IDs which require physical inspection probably wouldn't be okay with easily faked scans being accepted.
- maxrmk 6mo agoThe bill bans making access to a service contingent on consent. This would kill Gmail, Google Maps, Facebook, Instagram and basically every other ad supported service. Making subscriptions the only consumer business model would be bad imo.
- normalaccess 6mo agoI'm ok with that. for too long the parasites have hidden behind "advertising" as a way to collect data. Say it loud so the kids in the back can here: - IF IT IS FREE YOU ARE THE PRODUCT -
- ArchieScrivener 6mo agoHow is paying for a product instead of being the product a bad thing?
- m463 6mo agononsense. You could have a mail client with a static banner ad at the top.
- maxrmk 6mo agoThose exist! People choose to use gmail because of the scale, stability, and feature set paid for by targeted advertising.
- edoceo 6mo ago
- samename 6mo agoOf course, I’m absolutely for this. It is way overdue. But, what’s the group behind this? Who’s pushing it? I haven’t read through the bill and text yet, but credibility is important in this fight. Plus, this can change at anytime, so knowing who’s behind it amplifies the trust. We need to be having these conversations yesterday. Our fundamental freedoms are under attack, and a bill like this would go a long way to protecting future generations
- dotancohen 6mo agoJust because a bill has a name - and pretence - that you like, does not mean that it contains regulations, requirements, or restrictions that you would like.
- DougN7 6mo agoI’m too cynical because at this point I can only believe this is to help billionaires and ICE hide their identities/money, or it’s to strip away all privacy (as bills are often named the opposite of their purpose).
- burnt-resistor 6mo agoThe oligarchs would roll on the ground laughing at this cute desire from the plebs for a few crumbs. The system is so corrupt and bought, it doesn't matter if this passes or not because it will be diluted, unenforced, and/or overturned by a largely corrupt legislature, executive, and judiciary. All hopeful this time™ feel-good efforts will turn to shit until the corruption is sufficiently removed and prevented. No amount of idealist wishing, "trying", protesting, or campaigning for a single issue can materially change the reality of extremely corrupt, criminal elites having captured the important levers of power. That's reality. Therefore, the first order of business is fixing the corruption before all other single issue advocacy can be addressed.
- cassonmars 6mo agoHow do you propose fixing the corruption?
- throwaway81523 6mo agohttps://www.youtube.com/watch?v=DlGsQU4ZNhU https://www.youtube.com/watch?v=DlGsQU4ZNhU
- burnt-resistor 6mo agoNonviolent noncompliance, work stoppages, boycotts, sanctions, divestment, and further peaceful and effective measures until there are uniformly people in critical positions of power not beholden to the billionaire robber barons. Make it a criminal offense to be a paid lobbyist, abolish PACs and Citizens United, and every elected official profiteering. Keep going until wealth is firmly subordinate to civil authority. There is no perfect or magical plan that can be conveyed by a few sentences, so if you're out for a gotcha answer, you're not going to find a risk-free, batteries-included, cookie cutter blueprint anywhere from anyone.
- 1shooner 6mo agoI appreciate the sentiment, but this doesn't really seem to put itself in the context of the state of play at the federal level. Namely, pro-privacy states have existing legislation they want to be the 'floor' of privacy protections, and anti-privacy states want to use a federal bill to preempt those laws, making the federal law the ceiling that they can lower in one fell swoop. There are real risks to a federal law that preempts state legislation.
- tolerance 6mo agoWhat percentage of this is lawslop? https://github.com/righttoprivacyact/bill/tree/main/tests https://github.com/righttoprivacyact/bill/tree/main/tests There’s clearly a non-trivial level of LLM involvement. I want to say 100% lawslop. I can’t figure out who’s behind this to ascertain their qualifications and acumen in the space. 100% seems like a safe place to start speculating from but I can be talked down.
- garyfirestorm 6mo agoAs opposed to bills sponsored by real people that completely decimated privacy? Patriot Act? I’ll take slop that has some semblance of reasonable privacy protection any day.
- ramon156 6mo agoThere's some obvious issues that come with LLM generated bills. LLMs tend to stay very generic, to have a lower chance of being "wrong". I could also ask my 5 year old to draw a bill for me, that's as successful as giving a generic bill.
- int_19h 6mo ago> LLMs tend to stay very generic, to have a lower chance of being "wrong". It depends entirely on how you prompt them.
- lich_king 6mo agoYeah, most charitably, it seems to be some sort of an LLM art project. And it's another day when we engage with slop because it happens to say something we like.
- ddtaylor 6mo agoI think this kind of argument is a modified version of an ad-hominem attack. When you disagree with an argument, you are supposed to address the argument itself, not the thing making the argument.
- _slih 6mo ago[dead]
- useftmly 6mo ago[dead]
- tangotaylor 6mo agoUpvoted because I like the effort and I want more visibility on this subject. But I also don’t want to step on the EFF’s toes. They’ve been doing good work on this area for decades and I’d prefer we work with them on policy details. Here’s a whitepaper on their policy positions: https://www.eff.org/wp/privacy-first-better-way-address-online-harms https://www.eff.org/wp/privacy-first-better-way-address-onli...
- peter_d_sherman 6mo agoFull text: https://github.com/righttoprivacyact/bill/blob/main/bill/right_to_privacy_act.md https://github.com/righttoprivacyact/bill/blob/main/bill/rig...
- ddactic 6mo ago[dead]