[HN Gopher] First U.S. ban on sale of cellphone location data mi...
       ___________________________________________________________________
        
       First U.S. ban on sale of cellphone location data might be coming
        
       Author : pondsider
       Score  : 374 points
       Date   : 2023-07-10 15:28 UTC (7 hours ago)
        
 (HTM) web link (www.wsj.com)
 (TXT) w3m dump (www.wsj.com)
        
       | throwaway72762 wrote:
       | Banning sale just moves the problem. The carriers have already
       | mostly stopped "selling" the data by moving the advertising
       | analytics and other mining in house and selling access to that
       | instead of the raw data. They probably make more money on the
       | analytics than just the raw data, win win for them.
        
       | hnburnsy wrote:
       | Does wifi calling avoid tower triangulation and does VOIP like
       | Google voice hide your calling number from the actual physical
       | phone mumber?
        
         | bennettnate5 wrote:
         | Nope, not for wifi calling. The moment your phone connects to
         | cell towers, they siphon location information to what is known
         | as a Gateway Mobile Location Center (GMLC) which collects and
         | aggregates location data on phones connected to the cellular
         | network.
         | 
         | Theoretically, you could perform wifi calling without any
         | connection to a base station, which could then protect your
         | location data (assuming you use an IP hiding service such as a
         | VPN). But you can't just "turn off" cell tower associativity on
         | your phone. They're on whether you want them to be or not--
         | short of taking your battery out of your phone or physically
         | disabling the baseband on your phone, there's nothing to stop
         | it.
        
           | kj4ips wrote:
           | > But you can't just "turn off" cell tower associativity on
           | your phone.
           | 
           | That's what airplane mode does, because it's not good for the
           | cell network if you can be heard by two base stations that
           | share bands (and are normally too far away to interfere with
           | each other) and easily happens when you have altitude.
           | 
           | You can usually turn on WiFi/BT w/o exiting airplane mode,
           | because lower-powered radio devices are typically permitted
           | in situations that cell itself isn't.
           | 
           | sim-less phones typically don't maintain association, because
           | it costs battery to do so, and they only start talking to
           | towers during an emergency call. However, there is no
           | requirement one way or the other.
           | 
           | The easiest way to tell is if the clock of a sim-less phone
           | drifts over a month or two from something it was sync'd to,
           | note that using GPS at all will often sync the clock, and
           | some devices will "wake" the GPS module to allow it to keep
           | an up-to-date almanac and tracking (the math kind, not the
           | surveillance kind) parameters, so it is best to disable
           | location entirely, instead of just avoiding using it.
           | 
           | If the phone has been used for a long time with a reliable
           | time source available (tower/gps/ntp/etc), it may have a
           | pretty good drift calibration, so it may take quite some time
           | for drift to be visible.
        
       | gdelfino01 wrote:
       | [flagged]
        
         | singleshot_ wrote:
         | How is this legislation a reaction to that movie?
         | 
         | Are you suggesting that Massachusetts legislators watched 2000
         | Mules, realized that their efforts to throw the election in
         | favor of Biden had been detected, and then sought to make it
         | impossible to catch them next time?
        
           | r2_pilot wrote:
           | It's more likely the parent poster was trying to generate any
           | traffic to that site; your comment (and mine) is likely just
           | a bonus.
        
       | boopmaster wrote:
       | Good. Still not far enough to account for unreasonable search.
       | GPS a little inaccurate? Suddenly you're in a data slurping
       | dragnet for "standing" in the middle of a Capital riot, while
       | you're not really there at all.
        
       | joebiden2 wrote:
       | [flagged]
        
       | kornhole wrote:
       | Once the lobbyists descend on Mass to ensure a precedent or
       | momentum is not started, anything passed may have loopholes such
       | as for government or allowing the collection and sale from other
       | states or offshore. I implemented countermeasures years ago and
       | will stick with them. Hope is not a good strategy, but I support
       | the efforts.
        
         | gnicholas wrote:
         | > _Once the lobbyists descend on Mass to ensure..._
         | 
         | When I first read this phrase, I thought you meant "en masse".
         | But then I saw that this is actually about Massachusetts, so
         | your phrasing was probably on purpose. Funny multi-word
         | homophone!
        
       | euniceee3 wrote:
       | So where can I, as an individual looking to do research, purchase
       | a data set like this? What about my company wanting to to
       | targeted outbound sales, are we able to purchase a data set like
       | this?
       | 
       | I see the headlines. I understand there are companies that offer
       | this as a service to LEO. I believe the data would need to be de-
       | anonymized to be useful.
       | 
       | Who or where can I source data like this from?
        
         | [deleted]
        
         | berkle4455 wrote:
         | Nobody sells it to individuals. Sprint sold customer location
         | data through a subsidiary called Pinsight. Advan Research,
         | Placer.ai, and SafeGraph are some current companies selling
         | location data.
        
           | poplet wrote:
           | Corporations are first class people
        
           | sweetbitter wrote:
           | Well, you could try something like this:
           | https://news.ycombinator.com/item?id=36672217
        
         | johndhi wrote:
         | It's a good question. We always hear that it's happening but I
         | never see it happening.
        
         | korse wrote:
         | I would try entities in the California data broker registry as
         | a starting point.
         | 
         | https://www.oag.ca.gov/data-brokers
         | 
         | De-anonymization shouldn't be that tough if you have the cash
         | to pay for a handful of data sets that you think are likely to
         | contain overlap.
        
         | sweetbitter wrote:
         | If you just want to track a few individuals... Enumerate all
         | those who possess the data. Now look for data brokers that they
         | deal with (as commenter korse said) and recurse. Find all the
         | employees of every company in question. Muster a few hundred
         | bucks or so, seems to be the market price, and there you go[0].
         | 
         | For research I dunno. You'd probably have to make a deal
         | directly with one of these companies, one way or another, so I
         | would start by talking to them.
         | 
         | [0] - https://www.vice.com/en/article/nepxbz/i-gave-a-bounty-
         | hunte...
        
         | justrealist wrote:
         | > I believe the data would need to be de-anonymized to be
         | useful
         | 
         | I'm not aware of anyone selling person-level location data.
         | Everyone in the ecosystem is far too scared to do that (and
         | honestly not clear how to monetize).
         | 
         | It's all about foot traffic patterns and getting demographics,
         | seeing what kind of other businesses they visit, etc IME.
         | General location business analytics stuff.
        
           | euniceee3 wrote:
           | https://www.nytimes.com/interactive/2019/12/20/opinion/locat.
           | ..
           | 
           | This is the article I am building my hypothesis on. If I am
           | able to correlate place of business with an out of town event
           | like a conference and then further refine with gender and
           | ethnic filters.
           | 
           | I understand that companies will perform this analysis on
           | your behalf. Can anyone recommend a "reputable" one?
        
             | justrealist wrote:
             | I'm not saying it's impossible to put this together
             | sometimes, I just don't think anyone is attempting to do so
             | at a commercial level. It's really pretty unusual that you
             | can heavily monetize the location of a single, real person.
        
             | count wrote:
             | Heh, only sort of joking, but this is literally Palantirs
             | business model.
        
           | throwaway29281 wrote:
           | There is at least one company that doesn't seem afraid to de-
           | anonymize https://www.vice.com/en/article/qj454d/private-
           | intelligence-...
        
       | uggabuggalives wrote:
       | Means absolutely nothing if license plate tracking, biometric
       | (facial et al) tracking, financial tracking, and other more
       | sophisticated forms tracking, from link tracking (follow your
       | social grouping = easily follow you) to drones and beyond.
       | 
       | We'll get none of it as long as vested interests strenuously and
       | financially (read: lobbying/PAC-political donations) object to
       | the very construct of an implicit right to privacy, and the
       | possibility of an explicit right that, say, adds superpowers to
       | 4th Amendment is so far off that one sees the fall of humanity on
       | the horizon long before any such thing is put to bill.
        
         | NegativeK wrote:
         | Don't let perfect be the enemy of good.
         | 
         | Progress, even incremental, makes it more expensive for the
         | brokers and shows evidence that _something_ can be done.
        
       | ROTMetro wrote:
       | I'm still hoping if the 'the government can't bypass the first
       | amendment' case that's currently going on over the government
       | talking to private companies (social networks) is found to have
       | merit it will then set precedent for 'the government can't bypass
       | the constitutional right to privacy' via the government talking
       | to private companies.
        
         | kj4ips wrote:
         | That was the idea of this: https://www.congress.gov/bill/117th-
         | congress/senate-bill/126...
         | 
         | Sadly died in committee.
        
       | SergeAx wrote:
       | I can't wrap my head around it. Selling location data is so
       | obvious violation of privacy (don't even start with that
       | "anonymized" BS), that selling and also buying it should just be
       | a federal offence right off the bat.
        
         | chiefalchemist wrote:
         | That's because, the general availability of such data is of
         | benefit to the government. Who needs the permission of the
         | courts when the data is legally available "on the streets."
        
         | supertrope wrote:
         | Laws are old. Wiretapping is a crime. Harvesting web browsing
         | history is not. US Mail is legally protected. Email is not.
         | Until a law is passed data brokers will ply their trade. Even
         | after they will work right up to the legal limit.
        
       | closetnerd wrote:
       | Is there anyways to make it anonymous?
        
         | mulmen wrote:
         | Technically, yes. Socio-economically, no.
        
       | [deleted]
        
       | toomuchtodo wrote:
       | https://archive.is/M7quL
        
         | cosban wrote:
         | this link has SSL errors
        
           | jauntywundrkind wrote:
           | Works for me. Where are you & who is your isp?
        
           | wnevets wrote:
           | same
           | 
           | This site can't provide a secure connection
           | 
           | archive.is uses an unsupported protocol.
           | 
           | ERR_SSL_VERSION_OR_CIPHER_MISMATCH
        
       | 111111IIIIIII wrote:
       | Fascinating that this could start in the ostensible haven of
       | libertarianism.
       | 
       | Edit: Sorry everyone, I was confusing Massachusetts with New
       | Hampshire.
        
         | [deleted]
        
         | chimeracoder wrote:
         | > Fascinating that this could start in the ostensible haven of
         | libertarianism.
         | 
         | You're confusing Massachusetts with New Hampshire.
        
           | 111111IIIIIII wrote:
           | Oh my, obviously you're right. Thank you for the correction.
        
       | nneonneo wrote:
       | My entry point into this whole fiasco was finding a bug that let
       | anyone track anybody with just a cellphone number:
       | https://arstechnica.com/information-technology/2018/05/servi...
       | 
       | In this case, the site was selling real-time location data from
       | cell carriers, meaning that there was virtually nothing that an
       | individual could use to protect themselves (short of using a
       | burner or no phone at all).
       | 
       | It's great to see some strong action is being taken here against
       | the sale of location data, and I hope the bans can be extended
       | more broadly (and to Canada, please!)
        
         | 1vuio0pswjnm7 wrote:
         | "Krebs went on to cite an official at the Electronic Frontier
         | Foundation who said cellular carriers by law are required to
         | know the approximate location of customers in the event it's
         | needed by emergency 911 services. Whether the carriers are
         | permitted to sell or otherwise provide the information to other
         | third parties is less clear. Expect there to be much more
         | scrutiny about this in the coming weeks and months."
         | 
         | To see this in practice, check out MVNOs offering prepaid
         | mobile service. Some will disable certain features unless this
         | physical E911 address is submitted by the customer.
         | 
         | What if there were a limitation on how that data can be used.
        
           | Terr_ wrote:
           | > Krebs went on to cite an official at the Electronic
           | Frontier Foundation who said cellular carriers by law are
           | required to know the approximate location of customers in the
           | event it's needed by emergency 911 services.
           | 
           | IANAL but the RAY BAUM'S act (yes, it's all caps because it's
           | a silly initialism) only applies to location data that goes
           | "with" a particular 911 call. Not your location _before_ the
           | call, nor your location _after_ the call.
           | 
           | So if your cell-carrier is recording your location at all
           | moments and persisting it indefinitely, no law was forcing
           | them to do that, they are _choosing_ to disrespect your
           | privacy for their own profits or laziness.
        
         | [deleted]
        
         | uggabuggalives wrote:
         | > (short of using a burner or no phone at all).
         | 
         | Not carrying a phone won't help you.
         | 
         | Pulling the SIM won't help you.
         | 
         | Look around you. See all those cameras? Not just the ones above
         | your head in the supermarket that advertise HERE I AM, I'M A
         | CAMERA, but every camera on every phone in the hands of every
         | person you see can identify you and identify your exact
         | location to the meter instantly based on your face and x other
         | biometrics.
         | 
         | Everytime you speak, your voice pattern identifies you
         | instantly.
         | 
         | Burner phones are a thing of the distant past. The moment you
         | speak, the moment the camera "sees" you, your burner phone's
         | IMEI is/can be mapped to your identity in double time.
         | 
         | The methods in use today are just way more sophisticated than
         | the tech you've read about.
         | 
         | A drone at 20,000 feet can identify you in a crowd of 2,000
         | people based on the sound of your heart, your respiration, the
         | shape of your head, your ears, your nose, your face, your
         | facial profile, the shadow your body casts at x time of day,
         | and/or the uniqueness of your gate. Combine them altogether
         | with a scant amount of stat analysis and you can't hide even
         | with effort.
         | 
         | Think darkness will hide you? Nope.
        
           | LakeBoat wrote:
           | Gonna need a source on this. The US has trouble solving
           | simple murders when people are present, let alone some sci-fi
           | stuff you're talking about.
        
             | doublerabbit wrote:
             | Maybe in the Metro parts of the USA, but China is next
             | level scary: https://www.youtube.com/watch?v=Oo_FM3mjBCY
             | 
             | It's all possible.
        
             | AnthonyMouse wrote:
             | The technology exists but the false positive rate is high,
             | most cameras don't actually implement these things and
             | there is no convincing evidence that all cellphone cameras
             | are secretly always on (though a compromised device could
             | be).
        
               | TeMPOraL wrote:
               | I tend to think of it this way: it's theoretically within
               | our technological capabilities, and has been for at least
               | a decade. However, it's fractally difficult - there are
               | technical challenges, political issues, PR issues,
               | principal-agent problems, all mixing together - and
               | importantly, there is no strong enough economical (or
               | political) incentive to do it. Not when doing a small
               | fraction of work, and a shitty job at this, still showers
               | you with money while avoiding most of the problems.
               | 
               | An not to push my favorite TV show that doesn't involve
               | aliens from outer space too much, but recent advances in
               | AI are changing the equation here, making _Person of
               | Interest_ even more accurate and relevant than it already
               | was.
        
           | bradgessler wrote:
           | This is why I think technical solutions alone to privacy are
           | mostly pointless. There's 7 billion people in the world--at
           | some point (if we haven't already reached it) monitoring all
           | of us in real-time will be trivial. Even people who live "off
           | the grid" in a cabin in the woods will be trackable.
           | 
           | What's needed is an agreement between all of us, in the form
           | of privacy laws, that make certain uses of this data illegal.
           | 
           | In the future if you're caught committing a crime by data
           | captured in a manner illegal under these laws, it would have
           | to be thrown out and can't be used against you. Corps would
           | also be banned from collecting, storing, and using personal
           | data in an unlawful manner.
           | 
           | Feels like a pipe dream since there's so much money in the
           | industrial advertising complex, but I'm pretty sure that's
           | what it will take achieve reasonable levels of privacy.
        
             | uggabuggalives wrote:
             | [flagged]
        
             | bilalq wrote:
             | Agreed that this is not a problem that can be solved via a
             | technical solution. However, I don't think a political
             | solution is possible either. Even in the US, police can
             | literally get away with murder today. Why would they have
             | any difficulty getting away with privacy violations? Big
             | Brother is inevitable. All you can do at this point is
             | teach children and future generations to live with the
             | understanding that they are being monitored at all times.
             | This isn't me trying to be edgy or cynical. The genie's out
             | of the bottle at this point and it's just reality.
        
               | xapata wrote:
               | The way to fight back is ubiquitous public monitoring of
               | the state. We should understand that the state is always
               | watching, but the state should also be aware that all its
               | actions will be public knowledge.
               | 
               | Note the increased awareness brought by widely available
               | cameras with immediate upload capability. The commenter
               | above implied this is dystopian, but the opposite seems
               | to have occurred -- as the public gains the capability to
               | surveil the state, it constrains the state.
        
               | handity wrote:
               | WikiLeaks tried that, Assange is still in Belmarsh and
               | the MSM is still largely allowing him to rot there.
        
             | [deleted]
        
             | [deleted]
        
             | AnthonyMouse wrote:
             | > This is why I think technical solutions alone to privacy
             | are mostly pointless.
             | 
             | Technical solutions to privacy are not required to be
             | _alone_. They 're required to be _ubiquitous_. If your
             | country is an authoritarian hellhole, you encrypt
             | everything to help you not get murdered by the secret
             | police. If your country has strong privacy protections, you
             | encrypt everything to help ensure that it never becomes an
             | authoritarian hellhole, and protect you against
             | bureaucratic failures as defense in depth.
             | 
             | To invade your privacy, an attacker should have to break
             | the law _and_ break the encryption.
        
               | Frondo wrote:
               | Life in an authoritarian hellhole almost by definition
               | means technology won't save you. If they can haul you off
               | when you're walking down the street, who cares whether
               | your stuff is encrypted? They'll make something up.
               | 
               | Even if you're innocent, they'll make something up. I
               | lived for a year in one of those authoritarian hellholes
               | and in that time knew two people who were arrested and
               | hauled from station to station til someone paid a bribe-
               | these weren't the dissidents either, just some guys. The
               | dissident was stabbed to death on his doorstep.
               | 
               | Encryption is good to save us from marketing, from
               | megacorps making our lives hell. Laws and norms constrain
               | the rest.
        
             | xapata wrote:
             | What's the goal of preventing use of these data? Are there
             | alternative methods that could achieve the same goal?
        
       | gen220 wrote:
       | This reminded me of how MA passed a right to repair law in 2020.
       | It led me to google about it, and apparently the NHTSA has
       | overruled it [1]. :/
       | 
       | It's good that states are pushing the envelope on digital rights
       | - hopefully, this one has a brighter future. I can't think of any
       | industry-captured federal agency that has the jurisdiction to
       | overrule this one.
       | 
       | [1]: https://www.thedrive.com/news/feds-tell-automakers-to-
       | ignore...
        
         | hiddencost wrote:
         | They didn't over rule it, they just told people not to follow
         | the law.
         | 
         | This leads to an awkward situation that will likely have to be
         | resolved in court.
        
         | mulmen wrote:
         | This is the laboratory of democracy. States pass a patchwork of
         | laws which get challenged in the courts. Law is revised and the
         | process repeats. Eventually we understand it well enough to
         | pass similar laws everywhere or even nationally.
        
       | gnicholas wrote:
       | I find it creepy when I'm visiting a place and I start getting
       | spam calls from that area code. It's clear that companies (and
       | unsavory ones at that) know I'm not home, and they know where I
       | am.
        
         | mulmen wrote:
         | Huh, that happens to you? I live in Seattle but I still have an
         | Idaho number. Almost all of my spam calls come from Idaho. It's
         | especially funny because my iPhone includes the approximate
         | area of the calling number and Idaho only has one area code. So
         | the calls come from numbers in towns I have never visited.
        
           | gnicholas wrote:
           | Yeah, I live in SV but when I visit other parts of CA I get
           | spam calls from the local area code. This happens when I have
           | not made any phone calls to local numbers.
           | 
           | I do sometimes get calls when I'm at home from these area
           | codes, but when I'm traveling my spam calls are always from
           | these area codes, which makes it very unlikely it's just
           | random chance.
        
           | IG_Semmelweiss wrote:
           | This is the best thing ever actually.
           | 
           | Every entrepreneur should be made prior to opening their
           | business, to get a cell phone from montana.
           | 
           | Then, get a google voice #. That will be the burner for all
           | random apps online.
        
           | oefrha wrote:
           | Those are likely VoIP calls with spoofed numbers. I never
           | answer anything with my area code (from where I was a decade
           | ago), those are 100% spam.
        
             | mulmen wrote:
             | Yeah that's what I assume. I never answer them either. The
             | only calls I get from Idaho are people I already know and
             | are in my contacts.
        
       | Workaccount2 wrote:
       | If anyone is curious, weather apps tend to be some of the most
       | egregious and common offenders of this. Obviously people want
       | their weather widget to update with where ever they are, and on
       | the back end these weather apps (which are just passing you
       | freely available NWS data) are selling everything they can on
       | you.
        
         | gruez wrote:
         | This is a non-issue on both android/ios because they support
         | "approximate" location permission for apps.
        
         | kevin_thibedeau wrote:
         | > which are just passing you freely available NWS data
         | 
         | The Android weather widget gives more localized forecast data
         | than the NWS web site which pretty much always locks you on to
         | the local airport. Proximity to a great lake means that my
         | local weather can be significantly different than the airport
         | even though it's relatively near by. It all obviously comes
         | from the NWS but they don't provide easy access to everything.
        
           | NegativeK wrote:
           | The NWS site may give measurements for the airport, but it'll
           | give predictions for the much smaller area you select. It's
           | the only site I've found I can trust for Yosemite Valley, for
           | example, since I can have visual confirmation that it's
           | actually talking about a narrowly defined area. Today, moving
           | that patch of land around just slightly will show you
           | forecasts that are 10 or 20 degrees cooler than El Cap
           | meadow.
        
         | hnburnsy wrote:
         | https://www.nwsnow.net/
         | 
         | No ads No user tracking GPS not needed Unfiltered NWS data
         | including forecast dicussions
        
         | oefrha wrote:
         | Unless you travel all the time, there's no reason your weather
         | app needs anything more than one (or two if your workplace is
         | very far from home) static city/town/zip code. And most people
         | don't travel all the time.
        
           | theptip wrote:
           | With localized weather apps available, the precise location
           | in town (east vs west say) does make a meaningful difference
           | in many places.
           | 
           | For example DarkSky gave neighborhood-level forecasts.
        
         | theptip wrote:
         | This was a big reason for Apple's purchase of the DarkSky app I
         | believe. Fold in the tech to the native weather app to close
         | the security hole of external apps.
        
       | coding123 wrote:
       | Well they should ban all data collection except for debt payoff
       | data.
       | 
       | And maybe even that should be banned (if someone smart can figure
       | out a way to make risks stable without that data).
       | 
       | This entire thing needs its own HIPAA. FTC needs to be put under
       | new management.
        
       | JumpCrisscross wrote:
       | "Massachusetts lawmakers are weighing a near total ban on buying
       | and selling of location data drawn from consumers' mobile devices
       | in the state, in what would be a first-in-the-nation effort to
       | rein in a billion-dollar industry.
       | 
       | The legislature held a hearing last month on a bill called the
       | Location Shield Act, a sweeping proposal that would sharply
       | curtail the practice of collecting and selling location data
       | drawn from mobile phones in Massachusetts. The proposal would
       | also institute a warrant requirement for law-enforcement access
       | to location data, banning data brokers from providing location
       | information about state residents without court authorization in
       | most circumstances.
       | 
       | ...
       | 
       | No state has gone so far as to completely ban the sale of
       | location data on residents. The most common approach in other
       | states is to require digital services and data brokers to obtain
       | clear consent from consumers to collect data and put some
       | restrictions on transfer and sale."
        
         | fsckboy wrote:
         | the US constitution contains an Interstate Commerce clause,
         | which bars individual states from interfering/obstructing
         | interstate commerce. Does banning the sale of location data _in
         | Massachusetts_ do anything?
        
           | hypothesis wrote:
           | Are they being barred from collection/sale in other states?
           | 
           | Did this argument go anywhere with regards to say animal
           | welfare laws and out of state farmers?
        
             | fsckboy wrote:
             | if vendors from outside states follow the rules for what
             | can be sold in CA, then they can sell in CA also; CA can't
             | favor its own farmers. Also CA can't control what those
             | same producers sell outside of CA, but they can control any
             | production within the state.
             | 
             | The only other aspect I think has to do with whether
             | federal FDA and Agriculture regulations take any precedence
             | over CA, but that's not interstate commerce.
        
           | zdragnar wrote:
           | Short version: no. Since Wickard v Filburn, the interstate
           | commerce clause has been a blank cheque for the federal
           | government to regulate anything at all as it pleases, as the
           | case allows regulation of goods down to the level of things
           | that are made on and will never leave an individual's
           | property.
           | 
           | Long version: probably. Allowing the sale of location data
           | would be deeply unpopular among the general public. Under
           | stare decisis, the federal government would have a good
           | chance at beating the state in a court case, but it would
           | still be a risk- why risk the power for an unpopular case?
           | 
           | See also: marijuana legalization and immigration. Arizona
           | tried codifying the federal statutes on immigration into its
           | own state laws- not superceding, just mirroring. The federal
           | government took them to court and won. OTOH, marijuana is
           | also distinctly within the federal government's purview, and
           | Wickard would apply very easily to pot laws as well... And
           | yet, they have done nothing at all, likely because pot is too
           | popular to risk a court case (or an election, I suppose).
        
             | pakyr wrote:
             | How does this square with broad reaching commerce-
             | regulating state laws like the CCPA or CEQA? Also, for
             | federal supremacy/the Commerce clause to apply to something
             | like this, doesn't the Federal government first have to
             | have legislated in this area?
        
         | ARandomerDude wrote:
         | > obtain clear consent
         | 
         | In other words bury an acceptance in the ToS nobody reads
         | anyway.
        
           | JumpCrisscross wrote:
           | > _bury an acceptance in the ToS nobody reads anyway_
           | 
           | This is the benefit of incrementalism in policy making. We
           | tried clear consent, and it was buried. Now the case is
           | stronger for a ban.
        
             | idiotsecant wrote:
             | Yep, policymaking is largely a process that has something
             | in common with erosion. You want a statue of David, the
             | other guy wants a statue of Michelangelo, and each of you
             | has influence over what the temperature of the rain is.
             | Eventually you both end up with a statue of shredder from
             | ninja turtles and somehow the guy whose land the statue is
             | on is now a billionaire.
        
         | theptip wrote:
         | I think consent has proven to be a flawed mechanism on its own.
         | GDPR's requirements around legitimate/required processing show
         | a way forward.
         | 
         | 1. A site can't require me to consent to unnecessary
         | permissions just to use the site.
         | 
         | 2. I can always revoke/delete my data grants and that must be
         | transitive (the site has to delete all downstream data it
         | shared with subprocessors, and have contractual guarantees that
         | they can honor that before sharing any data with them).
        
         | indymike wrote:
         | This may be difficult to do at the state or local level since
         | most wireless is regulated by the FCC.
        
           | ke88y wrote:
           | Why? Pass a law with sufficient penalties (say, $10K) and
           | include lawyer fees. This'll result in a cottage industry in
           | any state. Enough civil litigation and companies will finally
           | decide it's not worth it and MA billing zip codes will be
           | excluded from sale of location data. This has worked in other
           | industries.
        
         | A4ET8a8uTh0 wrote:
         | Hmm, so if it passes. Travel to Massachusets, get a compliant
         | device and.. profit?
        
           | NegativeK wrote:
           | I suspect it'll be compliant carriers, not compliant devices.
           | 
           | And your carrier will know when you're in a jurisdiction they
           | need to care about.
        
       ___________________________________________________________________
       (page generated 2023-07-10 23:01 UTC)