Wil's point about companies using information about you that you did not provide, and in fact have no relationship with, business or otherwise, is a more interesting one. For some people, contact information is a very sensitive matter, and celebrities are the uninteresting case, compared to those being stalked, witness protection, etc. How are we going to deal with this?
Especially in light of the fact that the data is essentially unprotectable. It is not often observed that "DRM in general is impossible" doesn't just apply to media conglomerates, but to people as well; there's no way to DRM your phone number or address, either. So that's pretty much out. What's next?
EU law deals with it. It's illegal (and has been for decades) to store personal information about someone unless you have a legitimate, proportionate reasons etc. etc.
Maybe not DRM as DRM, but sure you can protect such things. Just not necessarily with systems in place currently. Conceptually simple solution: unique tokens for your phone / address that a routing system directs to you. Your info is never even in the hands of e.g. someone you buy from, and you can simply revoke the token to prevent any and all spam from now until forever, regardless of what they do with it.
The problem here is not that "DRM in general is impossible" and I fail to see how DRM could solve the issue with Instagram, even if DRM wasn't totally broken. Facebook can access your phone contacts and Instagram can access your photos only with your consent. You're willingly giving them that data.
The far bigger issue here is that services like Instagram can take and use your data without your consent indirectly. If I give your photo or your phone number or your location to some service and that action brings you harm, who's to blame and whom can you sue?
I'm not a lawyer, but I bet it's not going to be Instagram or Facebook or the other offenders out there ;-) And DRM here is meaningless.
You don't own somebody's phone number because you have it in your contact DB. You are willingly giving them the phone numbers of everyone in your phone book... your contacts are not giving their consent to having their data sent wherever.
DRM would, hypothetically, solve the problem of giving your phone number to somebody but not allowing them to share it further without your consent. Except, of course, it doesn't.
By the way, because after years on the net I can see this coming from miles away, let me draw a distinction in advance between "I personally don't care about my number being shared without my knowledge out of other people's contact book to arbitrary third parties", and "I don't think anybody else should ever care about having their number shared out of somebody else's contact list with arbitrary other third parties." They aren't the same thing, and if you want to argue the latter point, that can be done without trying to argue that there isn't any consent issue at all, which is simply false. Whether you consider it right or wrong, some things are happening that some people don't want to occur.
I wasn't trying to defend these services. Instead I believe that such EULAs should be against the law, as the fine print is too subtle to be understood by a majority.
> Axiom 3: Company has no other visible means of income
This is not true.
There are plenty of other ways for social sites to make money. If Twitter is doing billions off promoted Tweets, then surely a company like Facebook which has even more data on you can make a similar amount selling standard targeted advertising.
What we are seeing here is crossing the line. The worst thing is, this data was acquired under completely different terms and conditions. I never agreed to this when I signed up, and there is the faint scent of bullshit now that the company is trying to turn around years after that fact and retrospectively acquire my data. 'Opt out by deleting' doesn't cut it - we had a contract!
That "contract" you had with all those sites specifically stated that the business could change the terms of the contract at any time in the future. If you don't like that stipulation, then don't agree to those terms and don't use those services.
You can't just unilaterally change a contract and expect it to be valid. My understanding of things like this is so that if things do change, the company can offer up a new TOS/contract which would supersede the previous.
The problem is that it's a service and they never promised they would keep providing it under the same terms forever. So when they change the terms, you can stop using it, but you can't (if the new terms are enforceable) demand to keep using it under the old terms, any more than you could demand they keep offering the service if they decided to shut it down.
On the other hand, we've all now all got always-on always-connected computers in our pockets that already have more computing power than typical web servers a decade ago, so maybe somebody will write some software and that whole personal server thing will finally take off soon.
"The problem is that it's a service and they never promised they would keep providing it under the same terms forever. So when they change the terms, you can stop using it, but you can't (if the new terms are enforceable) demand to keep using it under the old terms, any more than you could demand they keep offering the service if they decided to shut it down."
Right, but terms need to be agreed upon by both parties. They can change the terms all they want but that doesn't mean that I have to abide by them if they don't ask for another agreement. The simple solution is to provide another agreement and make me agree again. If I don't agree, then the service is cancelled and we both go on our merry way.
Is that issue settled? Right now most entities we're talking about have a "TOS can be changed at any time" clause and seem to operate under the assumption that if they changed them and you keep using the site you have agreed.
Do you have to click an "I agree" for the new terms? Do they have to notify you or can they just change them and everyone has silently agreed to the changes?
I've seen all of the above and have never been clear on the current legal precedents on this.
I'm not sure. I do know that games like World of Warcraft would make you agree to the terms each time you had a patch or they changed. It seems like Instagram is doing what you are describing. I would definitely be interested in hearing a lawyer's opinion of it, since just changing it at any time without any specific action required on the part of the user seems to not be a valid contract in my eyes.
I can't remember specifics, but I do remember reading either some corporate lawyer opinions or maybe a low court decision that this was valid (or maybe they had to notify, in some way, that the TOS had changed by email or with a flash message on login).
I have certainly read plenty of lawyer opinions that it's blatantly invalid to have "this contract can change at any time with no notice" clauses in a contract but I'm not sure what precedent is out there.
Axiom 1: Company is collecting and storing personal data that you voluntarily provide.
Wil's entire point stemmed from the involuntary nature inherent in much of public photography today. There's a reason that TV shows blur out the faces of people who don't sign commercial usage waivers.
That sounds like the kind of gray area lawyers love. In the years it takes for the court dust to settle, though, you may want to avoid having your picture taken.
You don't really have any rights to your image taken in a public place.
Gets a little dicey when your image is used in a way that could be viewed as you endorsing something, like an ad or a service. For that I use a pretty blanket model release form, but it's a grey area. Unless you are rich and famous. They have their own set of rules.
Depends on the jurisdiction I suppose. In Austria, and I believe also Germany and maybe Switzerland, I do have a "right to my own image". That means I'm allowed to control the publication and use of an image if me, with some exceptions (i.e., if I'm not the main motive of the image but just a member of a crowd).
Germany and Austria have some of the most strict privacy laws in the world so they are a good example of the extreme case. In Germany, you do not control the use of the image, only its publication. That is I can take your photo in public and hang it on my own wall. Publication of public figures is pretty much universally allowed. Use of your image taken in public for data purposes (not published) remains controversial.
If I take your photograph and you cannot be identified in it, I can publish it without your permission, (say in a crowd or in front of a building as you note, etc)
Another possible solution is to do without said service, and realize that there are other alternatives that won't sell your personal information. I've dumped Facebook, Twitter, Instagram and Google (with the exception of Reader, and occasional searches when DDG doesn't work right).
I can share pictures (Group MMS & Shared Photostreams) and find out what people are doing (texting, phone calls & email) without giving up that information.
These companies do all of the above deliberately until there is no viable competition left. This is a situation they competely created over several years.
It's not surprising people are upset when the mass trial period ends and there are no competitors left to move to.
Axiom 5: Company X's only chance of monetization is
by IPO or acquisition by Company Y.
If Company X is acquired by Company Y,
goto Axiom 1 through 5 for Company Y.
Independence is also important, when it comes to privacy.
I don't know how Tumblr is doing - it seems like it's under some pressure to do a better job of monetization - but there's been this idea of a bubble in social media for years, and it we are beginning realize that in some way we were right. It's just that we didn't consider that companies would pursue the sinister solutions to their fiscal quandaries.
Makes you wonder how this makes the investors look.
Yep, we all recognize that companies actually have to cover operating expenses (and I suspect that most people here are capitalistic enough to say a company should ideally make a profit).
But if you're going to change the rules once you have millions of users, a prominent notification as opposed to inserting language into the middle of a terms of use policy would seem to make sense. I think Instagram users would be much more willing to listen if the reason and justification for this policy shift were clearly explained and users clearly notified.
There's a big difference between being surprised by behavior and simply not liking it. Being surprised by Instagram's intent to monetize is unreasonable, but it's fine to dislike it.
Why don't online businesses start offering privacy-conscious customers the option to pay for their services? This seems like a pretty obvious alternative to paying with privacy. I doubt they would even have to charge much for it to be profitable.
The problem is that the people willing to pay are exactly the people the advertisers most want to reach. The whole point of all this privacy invasion is to target the people with money who are willing to spend it. You take those people out of the pool and offering a free service no longer makes any sense, because nobody wants to pay to reach the people too cheap to buy stuff.
Which leaves you with a pay-only service, competing with a free-only service that consequently has ten times as many users (and therefore much stronger network effects), and the pay service goes out of business.
The true problem with all of this is that we're using services for things we should be using products for. You want to share photos with friends? We could do that in 1999 with AOL Instant Messenger. But now Facebook and Instagram have a better UX -- and it has nothing to do with whether they're services.
What we need is an open source P2P Instagram. No ads, no paying anybody anything, just photo sharing.
> The problem is that the people willing to pay are exactly the people the advertisers most want to reach.
So charge more. Instagram et al are trying to make money, not serve advertisers. If privacy-conscious people are willing to pay more than advertisers that's great.
The trouble is that the users (including the privacy conscious users) have to go where their friends are to interact with their friends. And the majority of users are not willing to pay money for more privacy, so the advertising-funded service gets the majority of the users, and the privacy conscious users can then either give up their privacy or lose the ability to interact with their not so privacy conscious friends. And they choose the first option in droves (or there just aren't enough privacy conscious people left), so there is no real market for the alternative.
I mean think about it: It's not like offering a paid service is rocket science. If there was money to be made there, why isn't anyone making a billion dollars offering it? Why aren't you?
Maybe it's an untapped market and no one else has had the vision to serve it. But this is kind of one of those money where your mouth is situations. If you think that market is lucrative enough to be worth chasing, do it. If not, well, apparently no one else does either, so here we are.
Axiom 5: It is possible to monetize free services in numerous ways without violating the privacy of your users, reneging on a TOS they signed earlier, and generally destroying their trust or expectations of fairness.
In the long run, this is not a viable business model. Servers might get cheaper every day, but you're still going to have to pay for them every month your service is up and running.
Facebook makes $36/user per year, on average. They are mostly about photos. Instagram knows this. $0.99 will be cutting it way too short.
I don't understand why companies like this don't just offer an ad-free pay option with a stronger privacy policy as an alternative to their free option and make everyone happy, except the total freeloaders who want free and their privacy protected. Seems to work fine for Flickr.
Axiom 2: Company does not charge you for this service
Axiom 3: Company has no other visible means of income
Axiom 4: Company has non-trivial operating expenses
Given that this covers a huge amount of "our digital life", there are a few possible solutions:
- Keep getting services without paying money but paying with privacy
- Identify another way to get the services we rely on to be paid for
- Hope that a large benefactor company will buy the services we use and write the operational cost off out of the goodness of their hearts