Posts

Comments

Comment by pharadae on Can Ads be GDPR Compliant? · 2023-01-09T07:36:52.402Z · LW · GW

The problem of inflated ads is currently very real for bigger players, who rely on paid traffic - I've worked with a company which did buy large quantities. They were employing several employees to just check and negotiate with the ad-publishers each month about the fraud rates, because the performance (meaning the chosen method - i.e. CPM, CPC, CPL, CPA) were vastly different between the ad-publishers, and it didn't make sense.

So there definetly was fraud involved, but it was extremely hard (and expensive) to weed fraudulent advertisers out.

Your scenario of an email newsletter is a special case, because it's virtually impossible to introduce any form of client run code to check for fraud, and can only start your fraud detection after the traffic hit your website.

Comment by pharadae on Can Ads be GDPR Compliant? · 2023-01-09T07:18:03.417Z · LW · GW

Good points, I'll look into the other studies at another time. I remember a german newspaper actually switching completely to non-targeted ads after their own experiment, but can't find the source anymore. I'll comment it here, if I find it again.

Thanks especially for your transparency on your Motivation and Disclaimer.

Comment by pharadae on Can Ads be GDPR Compliant? · 2023-01-08T11:56:10.176Z · LW · GW

There's a lot to unpack here. 

First, european union law like the GDPR works in the form, that they cannot directly make laws for every european member, but each european nation has to transform the european law into national law. So the implementation of the irish GDPR is different than from the german GDPR and while the general idea behind a european law must be abided by the nations, each one has their own pecularities. The german GDPR law is called the DSGVO and since I'm from germany, I'm most knowledgable there. So some of my comments might be wrong under GDPR, but completely valid for the DSGVO.

Under GDPR, every time a service (in this context the homepage) is requesting or using data sent from the client (the browser), the service owner has to have written down and abides to a set of privacy rules, which govern

  • what data falls under this set of rules,
  • how long the data is being processed and stored,
  • (if used without consent) if it has a legitimate purpose to use the data for this purpose, and
  • that they thought about and excluded a less privacy-invasive way of processing the data

All of these have been more or less required before as well, but with the GDPR, the service is also responsible for each and every 3rd party data processor they use (e.g. doubleclick as an ad provider). So if they send data over to a 3rd party, and they mishandle the data or use it for a different purpose than originally stated, the original service is now responsible - with hefty fines attached.

Having said that - let's get back to your points.

Are services allowed to use data for personalization of content (specifically ads) without consent?

Yes and no - Direct Marketing is a legitimate interest according to the GDPR, so you would not need to have consent. But: Is there a less privacy-invasive way of processing the data? Yes there is, not serving personalized ads, but only according to the (unpersonalized) content of the page. And, there's the right to object to direct marketing, so this has to be taken care of somehow as well.

This is what Der Spiegel and other news websites have been basing their modus operandi on: Give the user the choice to either consent to personalized ads, or to pay for not seeing ads.

Are services allowed to use data for security purposes (specifically fraud detection)?

Yes, they are. They can collect and use pretty much every bit of data they can generate and get from the browser. There is no less privacy-invasive way, because it's a everylasting race between fraudsters and counter-measures.

But: The data must be used for this purpose only. They must not be used to ads, personalization, login, marketing, whatsoever - or they risk a hefty fine. When Facebook used the 2 factor authorization phone number to send out ads, they were violating the GDPR and will hopefully get a hefty fine for it.

Can websites finance themselves without personalized ads?

Most likely. Non-targeted ads only reduce their effectiveness by around 4% in contrast to targeted / personalized ads - which makes sense, since if e.g. a user is reading an article on topic X, they are already interested in the topic. So an ad for people interested in topic X is already very likely to be effective.

(as said before: websites are still allowed to use any data for security purposes like fraud detection.)

Why are big companies like Microsoft being sued for data usage for fraud detection anyway?

Because they are trying to push the boundaries and how far they can go again, and the courts (and politicians) are using the GDPR to punish them for it. 

Most big companies still have no clue what data is being requested, stored for what purpose, distributed to whom, etc. - which was one of the reasons the GDPR initiative was started in the first place.

Example Microsoft: after a brief period of being privacy-concerned, Windows 10 is much more "androidized" in terms of spying on the user, pushing bloatware and ads, installing invasive features without consent, and trying to trick the user into giving consent for more data. It's e.g. not possible to simply say "I don't want to create a microsoft account" (which would enable Microsoft to track the user better) - only "I don't want to create a microsoft account at the moment (we'll ask you again in two weeks)".

I predict, that the previous rulings will be thrown out at the upper courts and that no smaller websites (even if they are Der Spiegel) would be sued for using data for fraud detection - assuming that they are not using the data for other purposes.

Are other means of financing websites possible?

Sometimes, yes - main question is the availability of competition (scarcity) and the relation a company has to their users. Spotify, Amazon Music Unlimited, Apple Music, etc. all have no problem of raising money from users through a subscription model, because a lot of music is simpy not available for free without a payment option. Even free "user-content" on sites like Youtube, where a lot of music is uploaded illegally from users, the content-id system is effective (if an artist or their publisher don't want their music to be available there).

Other services like Patreon, SubscribeStar, Substack, Locals, etc. show, that people are willing to pay creators just for the content they create. This only seems to work sufficiently well for parasocial relationships - most bigger Youtube creators are effectively businesses with dozens of freelancers or employees, but focusing everything on one person for the parasocial relationship.

Conclusion

Ads can be GDPR-compliant, don't have to be personalized and their fraud detection is a separate legitimate interest. 

Comment by pharadae on Baby Monitor with Delay · 2022-10-03T08:19:14.996Z · LW · GW

We used an old phone and the (paid) Babyphone 3g App. You can set a delay, although not as Long as you suggested.

I do not recommend such a long time. Waking at night hast a reason and Kids need time to build the confidence, that they are not alone. Not reacting for too long can lead to panic and result in a much more parent-dependent behavior and inability to sleep again without the parents help/attendance.

I've had much better results with learning to sleep without parents while going to sleep (Iteratively prolonged times of absence when going to sleep).

Comment by pharadae on Solar Blackout Resistance · 2022-09-08T17:41:59.736Z · LW · GW

Out of curiosity: How is the situation with several parties sharing one solar farm? Since you're sharing the house with several other inhabitants, how do you share the electricity bill? Do you have any form of metering on the different rooms?

Comment by pharadae on Infant Talk boxes? · 2022-01-31T07:39:06.342Z · LW · GW

From my discussions with two speech therapists a few years ago, the most significant difference between early- and late-talkers according to current research is engagement (citation needed). Baby learn by copying behavior, including speech - the more they are spoken (and listened) to, the easier it is. This is different to e.g. the way babies discover a sense of "self" vs. "outside" world, which can be influenced by binding in other senses to their movement (there are some hilarious videos of babys that have some helium balloons on their hands and feet and discover, that they can move them - the more common alternative is hanging toys that make a sound when hit over the babies head).

Babies learn very quickly about their ability to produce sound, even before they get a feeling of "physical self boundary", so I'd guess the talk box wouldn't help much there. Talking and listening to the baby is the best bet to get them interested in speaking in general, and then giving extra positive feedback for identifiers like mom or dad or some other word for a physical thing.

My guess is, that one of those high-pitched speak-back toys would give better results on speech development than a talk box - while obviously not trying to underestimate the fun they (and their family) can have with the talk box ;)

Comment by pharadae on Grandpa Has Different Rules · 2022-01-24T07:35:12.925Z · LW · GW

We do it exactly the same in all accounts - context is important and kids are perfectly capable of distinguishing those from a very early age on (and I had many discussions with relatives, who doubted that). 

One thing to add to the "who supersedes who" when multiple adults are present: We had the additional problem, that my wife and I do have different styles of parenting as well and while we tried our best to harmonize them, there are some edge cases, where we handle things differently. This lead (and still leads) to some stress, because if both parents are present, every situation with the kids is more ... noisy? The kids express more energy? IMHO, this is due to the problem of context: which parents' context to follow now? So from the kids' view the situations' context is ambiguous.

We introduced the rule, that if one parent starts to ... parent and starts solving a situation, the other parent must shut up and not intervene at all. The parent who started handling a situation also finishes. If the other parent disagrees on how this situation is handled, they still shut up and we sit down later without the kids, talk about it and try to harmonize our approaches.

That greatly reduced the stress with (and in) the kids - they (and we) have a predictable context to follow and are less stressed from the context being ambiguous.

Comment by pharadae on Kids Roaming · 2021-09-06T19:01:02.567Z · LW · GW

You should check your local laws (your point #4). Some counties seem to have very strict laws on unsupervised children and construct a child protection case very fast, which might be a reason against that.

I generally never taught my children (same age as yours) to distrust people. They know not to get into cars of people they don't know, but that's about it. The rationale is that it's a lot more realistic of a child getting lost or hurting themselves and needing help - and people wanting to help them - than all potentially bad things that could happen to them. At least here in germany, the statistics are way in favor of being optimistic than being pessimistic - most kidnappings are from divorced parents here. Last time a child got lost in my part of town - not kidnapped, just lost for an evening - was over 25 years ago, according to our local police.

My kids are free to roam the streets around the house and locations that they know for sure - after telling me where they'll go and when they'll be back -, but I made sure that they know my phone number by heart first. The radius is around 3km for the farthest friend, which they take their scooter for. They are not allowed to take the bike any further than just around the house for safety reasons, because they are not yet behaving safe enough in terms of traffic safety.

My oldest has started using the bus to one of his hobbies now as well. I printed a bus map for him, drove with him both ways once and taught him how to read the map in case he gets lost - which happened right on his first solo tour due to a technical problem and the bus had to take a detour. He also got a cheap mobile phone for those tours, which made him feel a lot safer and came in handy then.

And that's also about as far as I go for technical supervision. In case of a real emergency, I could track the phone from my cell phone provider, but in the end, I trust him to make the right choice for problems and talk to people he feels ok to ask for help.

TLDR: make sure your child is okay with the level of independence and that you feel safe enough that they can handle it. If not, work on how to build that trust in you and your children.

Comment by pharadae on Power Outage Chances · 2021-05-17T13:48:14.338Z · LW · GW

According to this table (which only includes providers big enough that they are obligated to file a form when an outage occurs), there were 5 outages in Boston from 2000-2014, from which only one was longer than 3 days (by a few hours).

Could be a good starting point to deduce a probability, if you can find the ratio of total providers vs the number of big providers in the table. But it looks like one event in 15 years, in which case I would not bother to secure it, if there are no other reasons (e.g. a medical device needing power or better insurance rates or something).

But: the generator can be used for other things like camping or other out-of-home activity as well, so if you're into that, might be worth buying one after all. Especially since you're splitting the cost with the rest of your housemates.

Comment by pharadae on Thinking About Generators · 2021-05-17T13:34:08.255Z · LW · GW

...aaand you already wrote an article about that.

Comment by pharadae on Thinking About Generators · 2021-05-17T13:33:14.349Z · LW · GW

Question is: Do you really need one? How often does a blackout occur annually that you can not cover with the existing backup systems?

Comment by pharadae on Vaccination and House Rules · 2021-05-05T08:55:04.483Z · LW · GW

Germany here. On my premise, I have a shared garden with three households, 3 kids in school (homeschooled every other week), 2 kids in kindergarden. Since we are very very lucky with this configuration (in terms of the kids being able to play with each other in the shared garden and not being stuck indoors all the time), we have had hard rules most of the time and everyone isolated on the premise, while most of the research on covid spreading was going on - this meant no kindergarden, no school, only one other household to meet adults with outdoors, FFP2-masked, with 2m distance.

While most risk factors on spreading are coming to a scientifically viable conclusion, the risks and length of long-term effects of a covid infection are not. Combined with the very low detection rate of covid in children before - which is bound to increase now through the mandated testing twice a week in most of germany - we are still being cautious (we also have people on the premise with preconditions, which are in the mid- to high-risk category for complications from an infection).

So our rules for now:

  • Kids are allowed to meet other kids outside, that are in the same group they meet with anyway (same kindergarden group or school class)
  • Meetings outside for adults are okay (due to the low risk of infection in the lower 0.x% range without mask, but with distance)
  • Work-related meetings indoors that can't be virtual only under precautions (open windows, masked, distance)

The idea is to (still) restrict contacts to the same in-group and to minimise any contacts out-group. This works for small groups (our premise) as well as larger groups (premise and our contacts) as long as we hold the contacts accountable to the standard as well. This makes the risk more calculated than having no rules, but obviously more risky than our previous strict rules.

Since it's still unclear, if a two-shot vaccination (where the second shot is extremely important, since it boosts the antibody response by a factor of 20-40x) actually prevents a vaccinated person from being a spreader (with cautiously optimistic scientific finding towards "yes"), we will keep these rules for a little longer and treat vaccinated contacts similar to unvaccinated, until the findings are clearer. Which will hopefully be in the next weeks.

Comment by pharadae on The Cost of a Sixth Seat · 2021-03-12T07:20:50.013Z · LW · GW

Note that most cars only have 2.6 seats in a classic three seat second row - at least in european models - where the middle seat is not a full seat, but only two thirds as wide.

If you're seating three children, don't forget that you're not only seating them but (usually) also their car seats¹ - which have gotten so wide through their side shock absorbation zones, that you can't fit three beside each other in a standard three seat second row of a car.

Even when you remove some of the extra-padding some seats offer as removables, it's a snug fit even with a full width three seat second row. So it might make sense to think about a bigger car all along, since most bigger cars with a full second row also have a collapsible third row anyway (at least as a premium option). A cheap model in europe is the SEAT Alhambra, which is essentially a Volkswagen Sharan but with a different chassis.

When factoring in the resale value, take a look at the second hand market specifically for your model, because these family vehicles tend to keep their value a lot better than other cards (since most families drive them until their kids are grown-up).

--

¹ in this case I mean not only a booster seat, but the full seats for ages 3-12. At least in most parts of europe, they are widely accepted if not mandatory.