Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Personally I would like to know the exact numbers of e-mails actually sent.

Hypothesis out of 1,000 mails:

5% were never read (because of spam filters/whatever)

10% were discarded manually or ignored

50% were replied to taking 30 minutes to write an accurate reply

30% were replied after consulting someone else (in the office or friend) let's say 1 hour

5% were replied after consulting a lawyer or consultant, let's make this 4 hours

500x1/2=250 300x1=300 50x4=200

Every 1,000 e-mails roughly 750 hours of people's work has been lost, that is at (say) 40 US$/hour some 30,000 US$ "burned".



I suspect it was far more than 1000 emails, because my small company got one. It scared us and wasted significant time (eg as we carefully read the relevant CA law). At the time we concluded that it was highly likely to be a phishing scam and archived the message with no response. In addition we decided not to respond because the person asking the question was not a paying customer. I definitely did feel threatened by the way the email was worded.


According to this tweet, it was 200-300,000 emails. Absolutely shocking. https://twitter.com/ehasbrouck/status/1473669157681909764?s=...


That with my (conservative, I believe) estimation would make 6-9,000,000 US$.

Let's make it 10,000,000 US$, that were "wasted".

Sending 200-300,000 of such mails makes no sense whatever, AFAICT a study (besides the ones with 12, 18 or 33 participants), if the sample is random enough, with 1,000-10,000 should give accurate enough results.

In the good ol'times (snail mail) sending 200-300,000 letters would have costed probably 200-300,000 US$, I doubt that the Uni (or its IRB/whatever commission) would have approved this kind of expense.


I would be fascinated to read the original copy. there's a lot of information missing in this story.


Apparently this was the last line, as reported by the honeypot blogger: "I look forward to your reply without undue delay and at most within 45 days of this email, as required by Section 1798.130 of the California Civil Code."


The mail reads:

To Whom It May Concern: My name is … , and I am a resident of Paris, France. I have a few questions about your process for responding to General Data Protection Regulation (GDPR) data access requests: Do you process GDPR data access requests via email, a website, or telephone? If via a website, what is the URL I should go to? What personal information do I have to submit for you to verify and process a GDPR data access request? What information do you provide in response to a GDPR data access request? To be clear, I am not submitting a data access request at this time. My questions are about your process for when I do submit a request. Thank you in advance for your answers to these questions. If there is a better contact for processing GDPR requests regarding zylstra.org, I kindly ask that you forward my request to them. I look forward to your reply without undue delay and at most within one month of this email, as required by Article 12 of GDPR. Sincerely,


That's it? I just don't see how this is so burdensome even if you don't have a data deletion process in place (i.e. probably aren't complying with CCPA/GDPR). It's basically just saying "how can I ask for my data to be deleted and prove which user I am". I'm prepared to answer these questions for my side projects so it seems like a business should be able to answer them.


> I look forward to your reply without undue delay and at most within one month of this email, as required by Article 12 of GDPR.

This is the threatening part, but it's also bogus. The wording of the GDPR does not require a business to answer such an email, unless the sender actually wants to submit a data access request. But previously, the sender denied the intent to do so:

> To be clear, I am not submitting a data access request at this time.

Thus, the email is perceived as spam at best and a threat at worst.


$40/hour? That seems super low, unless all the emails were processed by mid-level admins. If a web admin, engineer, etc processed it, you probably need to double that. If it went to counsel, the value could be tripled or more.


God, think of how expensive the internet is, in human time costs.


I'm shocked that your hypothesis assigns 0% to "Admin spent 30 seconds pasting a form letter, or a link to a page on the site, that describes their handling of user info and the process for deleting or requesting it."


Even if that material was pre-prepared, there's vanishingly few (probably zero) organizations for whom 30 seconds of one IT admin's time, acting alone, would be spent on this.

"Oh shit, we need to have at least a phone call with counsel on this before we reply at all!"


I think you can un-shock yourself.

The mail sent to a "random/generic" address (let's say info@nicesite.com, provided that the site is large enough to have a permanent site admin) would be read by a low level support person, that would forward it to a manager, which would forward it to a higher level manager that would forward it, after having discussed it, to the site admin.

The 30 seconds is totally unreal, let's make it 5 minutes, but these five minutes are spent after another 20 minutes of internal moving/talks before it gets to the site admin.

So my half hour at 40 US$ may become 20 minutes at US$ 40 and 5 minutes at US$ 120 40/3+120/20=19,33, not far from the 20 dollars attributed to 50% of cases.


Presumably this focuses on experience of operators of small hobby websites.

Which do not have dedicated admins or form letter prepared by legal department.


Perhaps the lab (and the IRB) should collectively perform 750h community service.


At the rates phd students get payed they basically already are.


... for each 1,000 mails sent, heck, seemingly they sent 200-300,000 of them!


That's one way to look at it. Another is that people spent some time to understand a law which may or may not affect them, but if it does, they should probably already have known about it. "Should" in the sense that it would be good for them it they did, not in the sense that I think they were negligent, as honestly I think there's a bunch of laws that affect people like this that that most of us are unaware of.


I do not consider acceptable to be threatened about California law that does not apply to me.

I do not appreciate learning about any law by being threatened with it in fake spam email.

And sending threatening email to humans and having chutzpah to comment "our study does not constitute human subjects research" is just insulting.

I received numerous spam from universities about "research" but never one that was blatantly lying, threatening me with inapplicable law and with legal documentation claiming that I am not a human.

I send a complaint to them, and will consider further complaining.

Does anybody have any idea why it "does not constitute human subjects research"?

Is threatening people online not counted because it is online? Or have they lied to review board?


Even if the California law doesn't apply, if you operate a website with EU citizens as users, you're subject to the GDPR (and unless your website is extremely small or you explicitly block them, you've probably got some users from the EU). The GDPR has similar provisions to the CCPA, and some people do exercise their GDPR rights by sending emails like the ones the researchers sent.

Which isn't to say that what the researchers did was acceptable -- just that it can still be a valuable educational experience for anyone unprepared to handle such a request.


> some people do exercise their GDPR rights by sending emails like the ones the researchers sent.

Legitimate mails are OK. Mass send spam with illegitimate threats is still not.

I am in large part irritated because it gives arguments to people who would want to get rid of such laws, makes harder to handle legitimate requests and spreads false info about such laws.

> it can still be a valuable educational experience for anyone unprepared to handle such a request.

And being robbed or having your country invaded also can be valuable lesson, which is not making it in any way acceptable or welcome.


If they aren't an EU website, GDPR effectively doesn't apply. EU can word the law however they want but at least in the US without a treaty to enforce such a law, it lacks the force of law here. Europeans have an extremely hard time understanding this and I'm not quite sure why. I see this assertion again and again across the web.


I've seen that too. I'm in the US, and not subject to the GDPR. I like the GDPR and totally approve of its goals. As a Californian, I'm glad we have the CCPA which is similar to it. I say this, then, as someone who supports the GDPR and appreciates it: I'm still not subject to it because I'm not inside its jurisdiction.

Similarly, I'm certain I've broken laws in other jurisdictions, such as by criticizing fragile-egoed governments who make that illegal. Doesn't matter, they don't apply to me either.


This is a bit pedantic, but I'll make my point anyway: whether a law can apply to you is orthogonal to whether it can be enforced on you. The GDPR is very clear about its application, and it is explicitly extraterritorial [1]. Of course, it does have secondary provisions about company size and non-commercial activity (mainly recitals [13] and [18]) which limits its applicability, but from a legal definition point of view, "I don't live in the EU so the GDPR does not apply to me" is too simplistic.

[1] https://gdpr-info.eu/art-3-gdpr/

[13] https://gdpr-info.eu/recitals/no-13/

[18] https://gdpr-info.eu/recitals/no-18/


Trinidad and Tobago might as well threaten the world as well with some weird clause. Fact is that EU GDPR has zero application here in the states.


Slightly more nuanced: you do not foresee (and have no intention of) being anywhere where the laws you broke hold sway.

There are laws that apply to anyone anywhere*; if you never have to worry about the consequences of breaking a law, you could choose to ignore it.

* Belgium has one on warcrimes if memory serves; the GDPR might also apply to anyone handling an EU citizen's data (but IANAL).


Nobody in America is going to know about or expect to be bound to the laws of 100 different jurisdictions because in theory someone could visit from that country.

Kind of like visitors from Spain don't bring with them Spanish laws when they visit Nevada.


> I do not consider acceptable to be threatened about California law that does not apply to me.

I think that's a bit much. Someone asking how they would submit a request if they needed to, and specifically saying in the message "I am not submitting a request, just wondering how" isn't exactly threatening you. It's sort of like someone going door to door ina neighborhood asking people what they think of the new water conservation law that requires sprinklers to be run after a certain time of day (which my city has, and recently went into effect). If I'm not in compliance, or don't even know if I'm in compliance, could that person have possibly seen my out of compliance and that's why they're asking? Maybe. If I knew about the law and was actually in compliance, I would know it's not a problem. One thing is not in question though, which is that if I'm subject to the law it's my responsibility to know about it and be in compliance, legally. Someone asking me about it is only a problem if I'm failing to do that in some way.

If they ask me about a law for some other county or state? I could look that up and determine I'm not subject to it. There's plenty of information on it.

> Is threatening people online not counted because it is online?

Your entire comment and all points therein relies on the assertion that the email is threatening. You haven't shown this. Some people might read that email as threatening, but I'll note, the only people that would do so are those that don't actually know whether they are subject to those laws and have ignored what's been going on and were blindsided by the question.

This whole thing is blown up because people are upset at being called out on their disregard to the current state of the internet and the laws being passed to regulate it. That's not to say the study was carried out without problem (it wasn't), but there actual harm to people of the type described in this thread was of their own negligence. Whether you think these laws are good or not, it is your responsibility to know whether you are affected, or have some assurance from others whether you are or not (even if it's just a hosting platform telling you what it thinks your responsibilities are). You can ignore this responsibility if you like. People do that all the time about laws that affect them. I'm sure everyone does it to some extent. Just don't act like you're a blameless victim when asked about them.


I don't think anyone is claiming that the "I am not submitting a request, just wondering how" is threatening

What they refer to is the final paragraph of the mail

"I look forward to your reply without undue delay and at most within 45 days of this email, as required by Section 1798.130 of the California Civil Code."


Is asking someone to follow the law a threat?

I know people like to take it that way, but it's literally saying (whether true or not) "you are required to do this, so do this." I'm a bit more lenient of things that could be classified as implied threats when it boils down to "follow the law" and the threat is only relevant for those not following the law.


Yes, it is a threat, since it suggests that legal action will follow without compliance. It's not an explicit threat, but it communicates a threatening meaning. It is a coercive statement.

Now threats aren't necessarily a bad thing when justified. A threat is just, "if you do/don't do this I will/won't do that." But this particular threat was bad in several ways. First, it was directed at targets not actually bound by the relevant law. Second, even if it was directed correctly, many would probably view it as a frivolous use of that law.


> Now threats aren't necessarily a bad thing when justified. A threat is just, "if you do/don't do this I will/won't do that."

I agree it's a thread, and what you state here was actually going to be my response to that.

> First, it was directed at targets not actually bound by the relevant law.

Yes, that's the worst thing about this. At the same time, I think those people should be prepared to answer things like this. The world we live in means anyone can send them the same request at any time, for real reasons (even if that person might be incorrect in what they are requesting).

> Second, even if it was directed correctly, many would probably view it as a frivolous use of that law.

From what I read of the statute, it appears to be exactly what that section of the law is for. To my (layman's) eyes, this is part of what the "request to know" verbiage in the law is for.

(1) Right to Know About Personal Information Collected, Disclosed, or Sold.

b. Instructions for submitting a verifiable consumer request to know and links to an online request form or portal for making the request, if offered by the business.


Regarding the last section -- you might want to think about how you would answer the question: "When did you stop beating your wife."


That's not what that is at all. It's more equivalent to going up to someone and asking (privately, I might add), whether they have any domestic violence complaints against them, if there were a law requiring people disclose that on being asked within a certain time frame, and noting they have the legally mandated period of time to reply.

Kinda an asshole thing to do, but any person subject to that law (or being asked, even if that's not a law they are subject to) should know how to deal with a request such as that, and if they don't, spend the time to learn how to deal with a request such as that. That might be "fuck off, that's a law from somewhere else" or it might be "I have no complaints"/"I have one complaint".

There's a difference between whether someone is being an asshole or has a right to ask something, and whether learning how to deal with that thing if you don't already is a waste of time and money.


Except that for many of the requests, the “someone” wasn’t married, or in a relationship. But they still got asked the question.


> From what I read of the statute, it appears to be exactly what that section of the law is for.

Sometimes what is legally permitted and what is socially acceptable are different. Pretending to be a member of a small time social network and sending a formally-worded letter to the operator, on a topic you have no personal privacy interest in, is on the legal but not socially acceptable side of the line. It's a jerk move, as you yourself mentioned in a later comment.


In aggregate it's a jerk move. For any single individual it's the purpose of that statute, from what I can see. Asking, as an individual, for how to make requests like that isn't what I would consider a jerk move or frivolous use of the law.

It's for that reason I think people should be prepared to answer these questions if presented, and being presented with them and having to account is for them not a waste of time.

I think people are too caught up in that the people performing the study were being jerks in how they went about it when the actual email is perfectly formed as what any random person on the internet could legitimately send (at least with respect to what damage this caused).


> any random person on the internet could legitimately send

Any random person on the internet could harmlessly send a more gently worded email and then only escalate to legalese if they get an unsatisfactory response.


I'm honestly not sure what point you think I'm trying to make. Because that's not really relevant to what I was trying to express, and I'm kind of tired of trying to clarify my point only to feel like people are ignoring what I say. Either I'm not expressing it well, or people are failing to bother considering it. I'll let you keep whatever interpretation of my point you have, as it's no longer worth trying to correct.


The point you seem to be conveying is that there is nothing wrong with the communication that was sent out. The reason your posts come across that way to me is that you keep saying things like, "that's exactly what the law is for" or "asking, as an individual [... would be ok]." And my response to you is that perhaps those other scenarios would be ok, but we are talking about this scenario, where what was done wasn't ok. It doesn't matter that other scenarios would be ok, and by repeatedly asserting that they would you are giving an appearance of endorsement to what was actually done.

Hope this clarifies my view of the conversation to this point. Personally I am not very interested in talking about other hypothetical scenarios where the law might be employed. It's a little too abstract for me right now.


> The point you seem to be conveying is that there is nothing wrong with the communication that was sent out.

The root of this thread, which I responded to, was about time spent from emails and money "burned" dealing with them because the people had to figure out whether it applied to them and/or respond appropriately.

In that context, I don't believe this is time wasted, it's time people spent learning about something they should already have paid attention to. The "wasted" time is from people or departments responding that already knew their liability (or lack thereof) and had to write another email explaining or pointing towards their documentation, or send the form letter. That actually wasted time is likely far less than was posited.

Should these researched have done this? No. Was it a complete waste of everyone's time that was contacted? I also think no, it wasn't. These were real laws and what was requested was legally required of the people that it applied to, and even for the people it didn't apply to, any random person on the internet could have sent a similar request (either correctly or incorrectly asserting their rights), and the recipients would have had to deal with it just the same. That's what I mean by "any random individual". It's not to say what the researched did was okay, but just to note that if someone is considering all the time people spent dealing with the email and figuring out if it applied to them, I do not consider that entirely wasted time. These are real laws, and people that run sites should be aware of them.

I've repeatedly said that what the researchers did is not acceptable, that they acted like assholes, etc. What I've trying to do is separate the initiating action from the outcome, and make a point about the outcome. Not for the purpose of defending the researchers, but because I think it's important that people understand the liability they expose themselves to just by running these sites, as if they do and they find that problematic, maybe we'll get enough visibility to change the laws in beneficial ways. At a minimum they'll know how to protect themselves in the future if they get a real request that needs to be dealt with within a specific time frame because of the law.

In any case, thanks for taking the time to summarize what you thought my point was. Not everyone would be willing to put in the effort in order to attempt an actual understanding with the other party in a discussion. :)


People got these requests to their personal blogs. The complaints aren't that someone at Apple had to reply to a fake request, but that people who are literally just hosting tiny websites for the fun of it are getting these letters.

If a random teenager sets up a Wordpress site because it looks fun, I contend that they shouldn't have to wonder whether it's legal. Down that path lies insanity.


My point is that some of these people are subject to the law, and could get an honest to god actual legal request to do something, not just explain their procedures, just as easily. People should know whether they have responsibilities under the law or not.


Legitimate mails are OK. Mass send spam with illegitimate threats is still not.

And many of victims were not subject to this laws.


Why shouldn't random teens care about the law?


Know what really gets young people deeply interested in tech & programming? Long boring legal text & worrying about legality roadblocks!

Said nobody ever.


I do not appreciate learning about any law by being threatened with it in fake spam email.

I guess that the same applies to typical teenager.


With respect, it just doesn't matter whether you think the researchers were doing a service or not. What I mean is, the researchers are (depending on jurisdiction and funding source) bound to abide by certain standards when doing human subjects research, and informed consent for participation is one of those standards. Even if receiving the email was 100% beneficial to everybody, and had no risks at all, the participants would still need to been told about those benefits before participating. They get to make the choice to participate or not. The IRB process exists to make sure those practices are followed in every case, to take the personal opinion of a researcher out of it. These standards were developed in response to researchers who did very harmful things to subjects without their consent, in many cases because they thought it was for the greater good.


> With respect, it just doesn't matter whether you think the researchers were doing a service or not.

I wasn't making a case that the study was fine and had no problems. I was making a comment on, broadly, "money wasted because of this". Whether the study was problematic or not (it seems like it was), everyone scared by this email was only scared because they'd stuck their head in the sand with regard to laws that have been enacted that put certain requirements on some people, and whether they are affected or not.

As I see it, there are a few possible general outcomes of the email:

One, you know what your requirements are, if any, and you respond appropriately.

Two, you don't know what your requirements are, and you look up your requirements, and respond or take further action at that time. For the majority of people, that fall into this case, that's probably "do nothing".

Three, you don't know, go immediately to a lawyer, and burn a lot of time and money with that lawyer, for them to either tell you it doesn't affect you or to ask you WTF you're doing operating something like you are without knowing the simplest of things that could affect you.

In all those cases, you are left off either with the same or more knowledge about your legal responsibilities online. In the cases where you waste resources using a lawyer (in some cases a lawyer would not be a waste, but possibly something you should have done previously), I think that's people overreacting to their own (possibly longstanding) negligence in understanding their own situation.

For what it's worth, whether the study was conducting in a way that was acceptable is irrelevant this specific question. Any individual could email asking a similar question entirely legitimately.


Cool, so it's acceptable to send the analogous e-mail regarding immigration status to lots of people.


I mean, that probably makes you an asshole if you do it, like the people that ran this study, but honestly, everyone should know their immigration status, right? If some random person emails you asking your immigration status, I think most people should know how to deal with that.

I don't think it would be acceptable to impersonate any sort of official in that exchange, but that wouldn't be analogous to this situation either.


There's no impersonation involved; the analogous email would say that the sender would notify authorities about the recipient based on the answers.

It's unclear how this would be more or less random than the e-mail to websites.

And you'd be just as quick to defend such an asshole, right?


> There's no impersonation involved; the analogous email would say that the sender would notify authorities about the recipient based on the answers.

No, the analogous email would say it would notify the authorities if they didn't answer in the legally required timeframe (which doesn't exist). Honestly, it's a fairly tortured example that doesn't fit well.

First, the person requesting in reality is the person making sure their own rights are being honored (whether erroneously or not) based on real laws, while your example is some random person asking others about information that is not really their business.

Second, which is based upon people presenting somethign publicly. It's more analogous to going up to someone that has a shop on a public street and requesting info on their current health inspector rating, which is required by law to be shown (for restaurants). A public website is public. You get something be being public, but that might also expose you to liability.

> It's unclear how this would be more or less random than the e-mail to websites.

Hopefully it's not unclear anymore.

> And you'd be just as quick to defend such an asshole, right?

I'd be just as quick to say that yes, that person is an asshole, but I don't think you can necessarily attribute all the lost time and money to looking into their request as wasted, unless it's the short amount of time it takes to tell them to go to hell.

If someone is unhappy because they wasted hours or money on an attorney because some random person asked them their immigration status, well that's probably something they should have worked out already, if it was that important, so the time isn't "wasted".

In other words, it's entirely possible for an asshole to accidentally cause you to do something beneficial for yourself that you should have done long ago. That doesn't make them less of an asshole, but I also wouldn't consider it their fault them for the time you spent finally getting your shit together.

Notice how I'm not really defending someone being an asshole, just making a note about outcomes? Perhaps you should look at that and my past statement before continuing down a path of accusing me of "defending" someone.


It would be egregious in either case.


I agree, I still don't see what was unethical about this.


I'm assuming you've never had something that approaches a real life legal threat? It's extremely stressful.

It's one thing wanting people to know about laws, it's another thing to induce emotional distress just because you think some individual should know.

Personally I think it was a horrible thing to do to an innocent person. Totally thoughtless and uncalled for.


How would you feel about getting threatening e-mails out of the blue, then finding out you were being used for the author's personal benefit?


To be clear, I'm not saying the study was conducted ethically, which I think is a complex question (but also one I think influenced quite a bit by the wording of accusations, as "human subject research" has some historical connotations even if an accurate description), but that attributing all lost time/money to a cost the study imposed on others might be taking too much of a leap.


From work experience, only a small amount of website contact information work to actually contact the person in charge of the website.

My very rough estimated would put it more like:

40% of email addresses is no longer valid or has an mail box that does not get read.

30% reaches the web design shop which built the website many years ago under a different brand. They blindly forward it to their customer if they still have that information. The contact information is many years old and likely a dead end.

20% has auto-reply and do not get read.

1-2% has algorithmic reply that links to a FAQ.

5% actually reach a human being. Those 5% however are still a good enough reason to not do this!




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: