While it has some good features (data minimization) it's also got some major weaknesses -- for example state attorneys general say they wouldn't be able to enforce it, it preempts existing stronger privacy laws in states like California and Illinois (and potentially Washington to some extent), EFF's warned about some big loopholes, etc. And that was even before these latest changes.
> Why not move the needle in the right direction and then lobby for additional things?
Two reasons. Preemption not only weakens some existing laws, it keeps states from passing future stronger laws -- so it caps protections. And, politicially, no privacy law in the US has ever been strengthened by Congress (or state legislatures) ... so, it's very unlikely that the lobbying for additional things will have an affect.
I htink there were three key sections that got cut out:
1) "A covered entity or service provider may not collect, process, retain, or transfer covered data in a manner that discriminates in or otherwise makes unavailable the equal enjoyment of goods or services on the basis of race, color, religion, national origin, sex, or disability." This was hugely important, it was sa major victory to get a bipartisan committee majority supporting similar language in APRA's predecessor ADPPA.
2) Requirements for algorithmic impact assessments by large companies (I forget the exact threshold).
3) A requirement to let people opt-out of consequencial automated decisions (with some exceptions), somewhat similar to California's CCPA.
Paul Graham, 2020: "Lambda School will teach you programming faster than most colleges. And it not only works well remotely, but was designed to from the start." [1]
Paul Graham, 2022: "Of 1277 students who graduated from Lambda School in 2020 and sought jobs, 950 got them, for a placement rate of 74.8%.
(Lambda's weirdly dedicated haters will be happy to hear that these numbers were audited by an accounting firm.)" [2]
Yep. When I get upgraded to an SUV I exchange it for something along the lines of the car I had originally reserved. I've asked them to put something in my file saying "don't upgrade to SUV" but it appears beyond the capabilities of their system.
NO on the Intelligence Community's fake reform bill, the FISA “Reform” and Reauthorization Act (which as the OP points out is actually an expansion of warrantless wiretapping)
YES on the Protect Liberty and End Warrantless Surveillance Act, which actually does include some significant reforms
Yeah, that's one of the big ways that it's stronger than California's law (where the private right of action is limited to data breaches). [Another way is that it's opt-in, with an additional authorization for sale of data; California's law is opt-out.]
Of course MHMD doesn't take effect until after the next legislative session, so I'm sure there will be attempts to weaken it. So I'm not counting any chickens quite yet!
It's very good in that it's significant progress over other US-based laws. Then again if you compare it to the much stronger privacy protections in the EU, there's still a looooong way to go.
It's true that California's legislation gets a lot of industry input, and they're not going to pass something puts the big tech companies out of business. On the other hand, there's a very effective coalition of privacy organizers there -- who are quite familiar with tech's tactics, and can be very effective at cutting through tech's spin with legislators. Plus, the California Privacy Protection Agency (which got established by a referendum, not through the legislature) has a lot of clout -- there isn't anything comparable in any other US state.
Washington state has similar dynamics, although with the CPPA equivalent. Microsoft and Amazon are hugely influential here; but, grassroots organizers had repeatedly stopped them from getting the very weak Bad Washington Privacy Act through the legislature. And this year, we passed My Health My Data -- stronger in some ways than California's privacy law.
Texas ... has been a disappointment. The privacy law they passed this year is based on the Bad Washington Privacy Act but significantly weaker.
It's a very good point, I haven't seen a lot of discussion of the role of Experian et al in KOSA.
In the US, it seems like it's mostly being driven by "child-safety" orgs, some of whom are well-intentioned but just don't understand the downsides, some of whom are anti-LGBTQ and appreciate the downsides. But others may well be active behind the scenes.
Of course Meta hasn't been prevented from adopting an open standard. The section on "The next step in embrace-and-extend, coming soon to a standards working group near you" goes into more detail.
As the article says, "So Meta and their supporters aren't going to give up on their plans to embrace and extend the fediverse just because of the pushback."
The section on "The next step in embrace-and-extend, coming soon to a standards working group near you" goes into more detail.
Yeah when there are multiple causes it's hard to know how much each contributed.
AcitivityPub's also meant to be extended, there are FEPs, and it's likely that the working group will come up with a new version as well. That said there certainly are differences between XMPP and ActivityPub, most people say the ActivityPub ecosystem is significantly farther along than XMPP was.
I could imagine Meta doing an open-source AP server (and with a fresh start it would be cleaner base than Mastodon). I also wouldn't be surprised if the release a app building toolkit / framework / whatever ... there isn't a good one now, they do that stuff well, and as they introduce proprietary AP extensions then they toolkit is a good way to get people to adopt them. But it's very hard to know at this point, it's also possible it's just PR spin and they won't really invest in it. We shall see.
I wasn't objecting to your point so much as you calling their summary a fair point. They stopped reading the article before they got to the example of non-public information in it, so mischaracteried it, which doesn't seem fair to me.
Agreed that if something's available encrypted on the web with no login required then usually the only protections you can put on it is security-through-obscurity like hard-to-guess links that don't show up on profiles (YouTube's "unlisted videos") or advisory like "noindex". But, although it's not something I talked about in this article, there are design choices. Mastodon (etc) could evolve so that a lot of what's currently "public" isn't available on the web with no login required.
Agreed that these other issues were a problem for XMPP. Christina Warren made this exact point on Mastodon a few hours ago -- in response to a post from Evan Prodromou that talked about the role that spam and harassment played and how he and others in the XMPP community didn't diversify the network. So, there are multiple factors. That said, I still think the post I linked to is very much worth reading.
The article explicitly says that talking only about public posts ignores other privacy risks, and has an example related to a followers-only post. Knowing that, do you really think his point is fair?