Firstly, I’m not against privacy or anything, just ignorant. I do try to stay pretty private despite that.
I wanted to know what type of info (Corporations? Governments? Websites??) Typically get from you and how they use it and how that affects me.
(I am not an expert, just a hobby self-hoster)
Think of how police obtain information about people. They usually do an investigation involving questioning and warrants to receive records and put together a case. They must obtain consent from someone or get a warrant from a judge to search records.
Or, they could just buy info from a data broker and obtain a massive amount of information about someone.
Imagine if every company has this info and can tie it in to your daily life. Google probably has your data location history and can see exactly what routes you’ve taken lately. They can use that information, with timestamps, to estimate your speed. What if they sold it to your car insurance company, who then uses it to raise your rates because you are labeled as a speeder?
What if your purchase history is sold to your health insurance provider and they raise your deductible because most of your food purchases are at unhealthy fast food joints?
Now, with AI being shoved into every nook and cranny in the tech we use, AI can quickly get a profile on you if it is fed your chat history. Even your own voice is not safe if it can be accessed by AI. This can be used to emulate you - Interests, chats, knowledge, sound. People could use this to steal your identity or access accounts.
Actually police (and governments) don’t need to purchase your data. They can gather anything and everything from what people share publicly and constantly on social media. Countless numbers of people have been arrested because of what they shared publicly and the metadata included with that share.
If they need criminal info they have immediate access to it.
The concern isn’t that you do something wrong, it’s that the data that you put out there can be used against you in countless ways. Marketing, sales, and so on are the least of your worries. If anyone wants to threaten you, your loved one’s, or even trick you into thinking they are in a threat situation, most people don’t realize how easy that could be with the data they give away daily.
That’s why I said this:
Or, they could just buy info from a data broker and obtain a massive amount of information about someone.
They don’t need warrants for location data if it’s bought from a company that sells that data.
Whether or not it’s admissible in court is another question, though.
Let me tell you a story. Many years ago I worked for big banks and insurance companies. One day I was tasked with a project. It was an amazing, from the tech point of view, project. It was something like this: a user navigates to a bank website looking for information about some product. The website presents the user a simple contact form - first name, last name, phone number and/or email. Based on provided data bank would use it to update user data (if there was no official account it would update the “ghost” account, aka “I know about you, but you don’t know about me”). Next the bank would scrape all publicly available social media accounts and build the “hidden” profile (I’ll get to this later). Based on all that data, user would be assigned a score based on which all future interaction with a bank would be determined. For a regular person this would mean that “I’m sorry but according to our system we cannot give you a loan”.
Now, about the “hidden” profile. It’s a thing that all big companies (including banks and insurance companies) hold. It’s all the data collected from all publicly available profiles (and sometimes from the shady sites), used to create a profile that’s not visible to a frontline workers and it’s referenced as a “system decided based on your data”.
Now, to make this more scary. This happened 10-15 years ago. Way before the so called AI. Imagine how much more data those companies have about you in today’s world and how good they are in processing it.
Now i have another question. What’s the issue if they’re ONLY using this info to improve my experience or make sensible business decisions?
They are using the info to engineer more efficient ways to separate you from your money. It’s not a benefit to you in any way.
I would have to assume that if I’m buying the product, i want it
Hey guys, this right here is a super valuable point to address and really strikes straight to the heart of the ability of a system like this to give the illusion of choice. People absolutely will still think, despite this, they are still in control and we need to address it not dismiss it.
I’m undoing the downvote on this comment, it absolutely is a big part of the conversation, even if you think it’s naive.
It’s naive to think you can’t be influenced into buying things you wouldn’t otherwise.
Also there’s the matter of pricing: they’ll get you to pay as much as possible, either by pushing more expensive versions or by actually changing the price you see on websites like Amazon.
“Improve user experience” tends to mean if you’re poor, the lowest level of hell isn’t gonna compare to how shitty of an experience they’ll give you
What’s the issue if they’re ONLY using this info to improve my experience
Suppose they start out entirely benevolent. That commitment must be perpetually renegotiated in upheld over time. As the landscape changes, as the profit motive applies pressure, as new data and technologies become available, as new people on the next step of their careers get handed the reigns, the consistency of intention will drift over time.
The nature of data and privacy is such that it’s perpetually subjected to these dynamic processes. The fabric of any pact being made, is always being rewoven, first with little compromises and then with big ones.
They don’t use it only for improving user experience. Based on a user profile they can bump your premiums just because you posted a photo on a snowboard (risky activity) or they can deny you a loan because someone posted on your timeline that you own someone some money.
Also based on your profile you are manipulated to buy products/services you don’t really need.
I am/was in the same boat as you: For a long time, I just didn’t care that I was giving away a bunch of information in return for convenience, and didn’t get why people cared so much.
I don’t really know what triggered it, but at some point I became painfully aware that the only goal these companies have is to squeeze every possible penny out of selling me. I started noticing that the stuff they ask you to confirm is 95% stuff they want because they can sell it, or use it to get you hooked to their service, and 5% (at best) stuff they need to make the service good for you.
This triggered a change in my perspective: Now it pretty much makes me sick to my stomach to think about all the companies that are drooling over me, trying to make a buck by getting me to click something I’m not actually interested in, or don’t actually need.
These people have a vested interest in manipulating me, and by giving them my data, I’m giving them the tools to do it. I don’t want to be manipulated or sold as a product: That’s what made me start caring about protecting my data.
You have asked the most important question in this topic. Privacy and security only have meaning when you develop a threat model or encounter a threat. With digital security it is usually pretty straightforward in that you don’t want anyone else controlling your computer or phone and using it for their own ends. And a lapse in digital security can ruin attempts to secure privacy.
Privacy is where threat models should be developed so that you (1) don’t waste time worrying about and working around nonexistent threats and (2) can think holistically about a given threat and not believe in a false means of privacy.
For example, if you are of a marginalized community, closeted, and in a very unsafe living situation, your main threat model might be getting doxxed and outed. To prevent this you should ensure that there is zero to no information that would link your real identity to an online identity and you should roll accounts to ensure small slipups can’t be correlated. VPNs probably don’t help in this threat model but they don’t hurt either. A private browser does nothing in this situation. Securing your phone and not leaving it unlocked anywhere is good for this situation (sometimes privacy isn’t really about tech but behavior). Using strong passwords that can’t be guessed helps with this situation. Making a plan to move to a safe living situation so you can be out will resolve the threat entirely, though it may mean needing to think about new ones.
Notice that the government was not in this threat model and that it was more about violence towards the marginalized. Cis white guy techbros generally have nothing to worry about re: infosec and are just being enthusiasts or LARPers. Nobody is showing up at their house with a gun and the feds are not going to arrest you for having the most “centrist” political takes and actions available. The people that need to project themselves are those facing overt targeted marginslization or who take political action that the government wants to, or would eventually want to, suppress. For example, the US government labelled anti-apartheid groups as terrorist organizations and intimidated or jailed those they could identify. It has a habit of doing this to any advocacy groups that gain steam and actually pose a political threat to their opponents.
Even if you don’t have a threat model, though, having good digital hygiene is useful in case one develops in the future. You may currently do political work that seems safe, and it is because it is not perceived as a threat. Let’s say you help organize unions. But there have been times where organizing unions would mean you’re targeted by the government and hired thugs and those times can easily return. If they have compiled a database of likely union sympathizers, will your name be in there? Maybe that’s a risk that you just take. But maybe you should use good privacy practices so that you can go underground when needed.
The latter applies to the threatless cis white techbro “centrists”. Such an individually may someday change politically or in their gender identity and having good practices would then pay off.
In addition to everythong everyone has said, one major thing that people often don’t think about privacy is how it relates to enshittification.
Modern software services try to optimize everything to make as much money as possible. Everything is a/b tested, and whatever increases some arbitrary metric is what gets released.
They do this by tracking a ton of metrics about how you interact with everything. I know where I work we collect data about every time you click on anything, how long you hover over buttons, etc.
I’m probably gonna mess this quote up, but I thought it was brilliant:
“Privacy is essential to security, and shitty people feel entitled to take that away from you.”
You can’t be secure in your dealings or operate on equal footing (economically speaking, as others here have pointed out) without a measure of privacy.
SSRN is a kind of vast warehouse of academic papers, and one of the most
excitedcited and well-read ones is called “I’ve got nothing to hide and other misunderstandings of privacy.”The essence of the idea is that privacy is about more than just hiding bad things. It’s about how imbalances in access to information can be used to manipulate you. Seemingly innocuous bits of information can be combined to reveal important things. And there are often subtle and invisible harms that are systematic in nature, enabling surveillance state institutions to use them to exercise greater amounts of control in anti-democratic ways, and it can create chilling effects on behavior and free speech.
Privacy is important because it gives you control over your life; details, info, thoughts, emotions…
I recently met a guy out of town at a trade show. We were both in the same show, grabbing some snacks, and I complimented his hat. We started talking, a little this, a little that. Eventually we parted ways. On the outro we introduced ourselves by first name only, more as a BTW side note because we might run into each other again. Why am I telling this story?
Because I forgot his name almost instantly and really only remember his hat. I know nothing about the guy. He knows nothing about me. But wouldn’t it be weird if I didn’t just remember his first name, but I knew his last name too? Where he lived, worked, shopped for groceries, sexual orientation, he last time he ordered pizza and what toppings were on it, how he voted last election, etc… If I knew all that about him, I could have a much more in depth conversation with him. And even if I had no mal intent and simply wanted to give him better experiences in life…that’s not my decision to make. He didn’t ask for that. And it’s freaking weird.
But that’s what has been made normal in our lives. Privacy helps keep your life…well, private.
Then the rabbit hole goes deep on nefarious uses. And it’s not “its possible” to do this, but rather “it’s being done” (with absolutely no doubt or argument).
Why do you need curtains on your windows?
To make sure the whole world isn’t just a window for the HR department. I can have “dissident” views, or just talk trash with my friends, and not get fired since it wasn’t at the office.
To make sure real dissidents (from totalitarian countries) can express their political views.
So a lady can send her husband feet pics without some secret agent spy gawking at them too.
So I can share my family’s secret BBQ sauce recipe with my cousin without Arby’s stealing it (they have eyes everywhere).
But these are all specific things. The truth is that we simply cannot trust institutions with all our data. I don’t need a reason for privacy. They need a reason to have my info. Security is a legit reason to seek citizens’ info, generally, but you should need a specific security-related reason to access a specific person’s data.
They get as much information from you as they possibly can. Age, sex, gender, weight, phone numbers, addresses, work history, purchase history, income, tax records, net worth, family and friends, hobbies, kinks, criminal records, food preferences, medical history, etc.
All of it is worth money, because the more data they have about you, the better they can predict what you will be interested in buying. They want to target ads towards you that have the highest chance of getting you to watch/click them.
Even if you think you aren’t influenced by advertisements and marketing, you are. And remember, it isn’t just you, they will use your data to target your friends and family. So even if you don’t care about all your personal data being mined for targeted ads, you should care about your friends and family.
Also, they more data these government agencies and corporations have on you, then worse it is when (not if) they get hacked. So even if you have no issue with these companies and government agencies storing your data, you wouldn’t want hackers and scammers to get that info and use it to hack your accounts and the accounts potentially of your family and friends too.
It’s about having control over your information and keeping yourself safe and protected. If you truly had nothing to hide, you would walk around naked, leave your door unlocked with your valuables inside, hand random strangers your credit card number, and leave the bathroom stall open while pooping. But most likely, you don’t do any of those things when you’re out and about, and the same should be true for your digital life.
10 years ago by having your full name and face your whole data would be in risk of exposure like all social media apps your online footprint etc, etc and in the wrong hands hackers for example can do god knows what with it like sell your data to your enemies track it against you to steal your bank informations whatever they can put their hands on…
Nowadays they only need your face, almost everyone in the world has had uploaded a picture of them online somewhere and that’s enough to dox you and again your online digital footprint and again for whatever reason they want to possibly hurt you,
However having digital privacy forbids this data from leaking to the wrong hands and makes you a little more secure, just knowing little bit about your private life is sometimes enough to track you and open a weakness to take advantage of. this age isn’t for nuclear wars it’s about digital wars and data is power.
Because, even if what you’re doing now is fine, moral and legal, it might not be perceived as that later, whether by your friends, neighbors or government. This has become especially relevant in recent years. Even if your own opinion shifts to match later trends, your past actions might hurt you.
You might be doing nothing wrong and still jeopardize your future self.
Because peoples mindsets change on an individual level and on a mass scale. One very good example, if someone was a raging racist in the past and turned his life around people can ruin his life if they showed old online posts of his to an employer. Idk if youve seen this but theres been a trend of people getting fired from jobs due to being onlyfans models in the past, it would suck bigtime if everything people do or did online was stuck to them forever because everyone makes mistakes and its bad for them to be brought up once theye older/outdated/irrelevant.
The way we socialise has changed to the point where it’s normal to talk to people over text chat. This leaves a footprint that talking face to face with someone does not.
In addition to other privacy concerns, I don’t want things I say that I would’ve gotten away with had I spoken it to my friends in real life, to come back and haunt me, either by a platform having a massive data breach, or it being used as evidence in a legal case against me.
On that last point, I’m not using chat services to organise crime, but taken out of context, any message I send can paint a picture that I’m an awful person and change some jury’s opinion of me. This isn’t something I want to think about before sharing a dank meme to a friend on discord.
You know how you fill in security questions or have a certain knowledge about yourself that other people trust only you to answer to in order to permit you access to your own information online such as accounts?
Well a hacker can use that shit and then you have a long road to convince anyone who ever lost trust in you because of that that you have been hacked.
Also you want to protect the people on your contact list if you want to keep their trust.
You shouldn’t even give your phone number out. That’s linked to accounts.