Exocrinous ( @exocrinous@lemm.ee ) English41•1 year agoFun fact: Reddit is claiming it has full rights to distribute and sell any content posted to Reddit. So if you’ve ever posted to r/gonewild, they’re claiming to have a full licence to do whatever they want with pictures of your naked body.
NotJustForMe ( @NotJustForMe@lemmy.ml ) 11•1 year agoI might be naive, but isn’t that the point of posting them on the internet?
Exocrinous ( @exocrinous@lemm.ee ) English15•1 year agoNo, many people do sex work on the internet and depend on distribution rights to their own bodies to make an income. I’m not usually a fan of copyright, but I make a big exception for people’s bodies. This also isn’t just a matter of money, it’s a matter of personal dignity and social integrity. Nobody should be coerced into giving up creative rights to their own body. It’s sexual harassment at best. If my nudes are used to train an AI in some way with a profit motive, then I’m engaged in what is essentially prostitution without my own consent.
Holzkohlen ( @Holzkohlen@feddit.de ) 2•1 year agoI think this opinion is so based that I will adopt it. Effective immediately.
NotJustForMe ( @NotJustForMe@lemmy.ml ) 1•1 year agoI am not sure that you realize how public internet works. Only a few countries participate in copyright.
Even fewer have actual laws about it. Most don’t give a shit about it at all. Your Reddit photos are public, you gave up the rights to them already, in any realistic way imaginable. You only have a case in countries with copyright laws. What about the others? How is that realistically protecting your privacy, if only one billion out of eight billion give a shit?
So yeah, it’s a shitshow. Reddit fucked up their image. I’ll never post anything of consequence there and certainly won’t use it to create a business. Same with Facebook. Or any other public forum. I never have. And nobody should, if they are concerned with privacy or copyright.
There is no war for privacy on the internet. Just an endless battle with companies making money. It can’t be won. Public and Privacy don’t mix. And never will. It’s a game the law-makers play. It has nothing to do with rights.
This is reality versus Living inside your head. Prostitution? Coerced? Sexual Harassment? Dude, you are mangling those words into perversions of themselves.
An ai is using hundreds of thousands of nudes for training. Your body is used for normalizing the process, not as a template for porn. How special do you and your celestial body feel? You probably have 10000+ natural look-a-likes. Meh.
INHALE_VEGETABLES ( @INHALE_VEGETABLES@aussie.zone ) 8•1 year agoI honestly figure they do have the rights. I will be bum fucked if I ever read those terms and conditions.
What will they do with my lewd pics anyhow?
soggy_kitty ( @soggy_kitty@sopuli.xyz ) 10•1 year agoUnder GDPR they have to prove that you read the terms and conditions, not just accepted them.
GDPR is a god send for the EU and UK.
BurningRiver ( @BurningRiver@beehaw.org ) 6•1 year agoMaybe a dumb question here from across the pond. Does GDPR even apply to the UK after Brexit?
Dr Pen ( @DrPen@mastodon.social ) 7•1 year ago@BurningRiver @soggy_kitty Not directly, but the UK Data Protection Act adopts nearly every aspect of GDPR to allow for data portability. Eg this is especially important for fintech data but there’s good support for open science and open data in the UK too. https://www.gov.uk/data-protection
BurningRiver ( @BurningRiver@beehaw.org ) 6•1 year agoThank you very much for that. I work in an industry (in the US), but we have increasingly detailed training on GDPR, HIPAA (US healthcare information regulations), CCPA (California’s version of GDPR) and on and on. I didn’t know the UK had their own version.
The lack of uniformity in the US is making it increasingly difficult to comply with everything over here, with states constantly passing their own laws on digital privacy, but those penalties for non compliance vary so greatly it’s almost impossible to follow.
Exocrinous ( @exocrinous@lemm.ee ) English3•1 year agoFeed them to Google’s AI for data. Your boobs will be source material for the next generation of AI porn.
INHALE_VEGETABLES ( @INHALE_VEGETABLES@aussie.zone ) 3•1 year agoSweet.
kevincox ( @kevincox@lemmy.ml ) 1•1 year agoI mean of course they do. Reddit’s job is literally to redistribute those photos and it is well known that they will be used to generate profit.
Maybe there is a little grey around around “selling” but if they have the right to redistribute them I don’t see why they wouldn’t be able to redistribute them directly for money as opposed to just redistributing them with some ads on the page.
Exocrinous ( @exocrinous@lemm.ee ) English2•1 year agoThe reason Reddit shouldn’t be selling other people’s pornos is that the users didn’t knowingly consent to being a sex worker. The distinction between free sex (in which I include open distribution of nudes) and sex work (in which I include paid distribution of nudes) is emotionally important. And it’s especially important when someone is being pimped without their knowledge.
kevincox ( @kevincox@lemmy.ml ) 1•1 year agoYes. “Knowingly” is the hard part here. Reddit will of course say that you agreed to their terms of service and that the terms are reasonable because otherwise they couldn’t operate their service. However it is definitely true that many users didn’t realize that they were giving Reddit permission to sell their content (even if it is the logical conclusion).
Exocrinous ( @exocrinous@lemm.ee ) English2•1 year agoActually it’s not the logical conclusion. Reddit’s terms of service violate the GDPR and many other laws. A client can’t sign a contract by logging in to a website, that’s not how contract law works. Legally, these terms of service are utter nonsense. The only reason these companies get away with it is nobody’s sued them yet.
banghida ( @banghida@lemm.ee ) 39•1 year agoFormer user, I’ve deleted my 12 years old account when Boost stopped working. I am not sure what can I do, I would gladly sue tbh.
TWeaK ( @TWeaK@lemm.ee ) English27•1 year agoIf they still have your comments on the site then you still have a claim.
If they don’t have the comments on the site, they probably do still retain the content secretly and technically you would have a claim, but it would be impossible to prove.
lemmyingly ( @lemmyingly@lemm.ee ) 3•1 year agoBoost hasn’t stopped working. I’m still using it and I’ve used it everyday.
I have Boost for Lemmy and Reddit. Their icons are identical.
Gordon_Freeman ( @Gordon_Freeman@kbin.social ) 29•1 year agoCould we sabotage the LLM training so the data became worthless?
Like adding to our comments stuff like “2+2=5” “Abraham Lincoln discovered America” and whatever silly statement you can think of
delirious_owl ( @delirious_owl@discuss.online ) 41•1 year agoI think reddit is already sufficently full of misinformation that you dont need to add to it
Gamma ( @GammaGames@beehaw.org ) English20•1 year agoGoogle’s LLMs are going to get real good at gaslighting and hating minorities in the next few years
archchan ( @archchan@lemmy.ml ) 7•1 year agoGoogle is already a pro at gaslighting even without LLMs trained on Reddit’s garbage.
“Web integrity is for your privacy and security” my cute ass.
delirious_owl ( @delirious_owl@discuss.online ) 4•1 year agoYep. Ask them if Palestine committed a genocide and they’ll parrot back the Isrsel-funded disinformation spread all over reddit “no. Israel has a right to defend itself”
If people actually turn to LLMs for information, we’re heading to a dark place.
Icalasari ( @Icalasari@kbin.social ) 3•1 year agoThe far right multimedia group Gab released an LLM for people to get answers which “the government and liberal elite keep secret”, so already happening
Hilariously easy to jailbreak though, so I imagine it’s also piss easy to poison
crispy_kilt ( @crispy_kilt@feddit.de ) 1•1 year agoIsrael committing war crimes
Israel has a right to self-defense
Did you know that both of these statements can be true at the same time?
delirious_owl ( @delirious_owl@discuss.online ) 6•1 year agoThats like saying “all lives matter” to the BLM folks.
Of course Israel has the right to defend itself, but the point is that 99% of their activity is offensive and they are the oppressor. that argument is double-speak.
Israel is committing a genocide and you think that’s a reasonable response?
crispy_kilt ( @crispy_kilt@feddit.de ) 2•1 year agoYour reply made little sense to me, I only just now understood where it comes from.
You probably think I am arguing in bad faith, just like the racists saying “all lives matter” as a dog whistle. I assure you, this is not the case. The crimes of Israel are terrible war crimes and those responsible need to be tried in an international court of human rights. The same goes for those responsible for the concert massacre.
I am saddened that people feel compelled to pick a side in this stupid an unnecessary war and then ignore, or at the very least excuse, the crimes of the side they picked.
The assholes of both the Israeli and the Hamas leaderships are complete and utter cunts. Normal people suffer because of their power politics. I hope you can see that.
Possibly linux ( @possiblylinux127@lemmy.zip ) English5•1 year ago“Wipe out all of Europe”
jarfil ( @jarfil@beehaw.org ) 3•1 year agoIIRC, one of the LLMs (was it OpenAI?) that crawled Reddit, had to manually remove subs like r/counting because they were messing with the training.
delirious_owl ( @delirious_owl@discuss.online ) 17•1 year agoIsn’t it a violation once they do something?
Maybe its illegal to make impossible promises to investors, but the GDPR supervisor authority wouldn’t be the place to make that complaint…
It is not clear if reddit has already engaged in this with Google, or if it is something that’s only starting. However, as outlined in my post, they might have to consult with a DPA before engaging in this anyway, which I doubt they have done. So, no, DPAs are absolutely the right place to make that complaint.
Even if they hadn’t started yet, might as well get their eyes on it, and force them to do it right from the get go (which they cannot do, as it currently stands).
Firipu ( @Firipu@startrek.website ) 4•1 year agoYou really believe a large Corp like reddit decided on something as big as this without consulting with their lawyers? Fuck spez, but there’s no way not a single lawyer working with reddit remembered the massive legislation that has by far had the largest impact on the internet in years.
Ephera ( @Ephera@lemmy.ml ) English6•1 year agoCorporate lawyers tend to be …optimistic. And then management will put a risk calculation on top of that. As a result, most larger companies violate the GDPR. See the popular use of Google Analytics or Microsoft 365, for example, which are illegal in the EU, if you ask a DPA¹. Giving them a reality check is never a bad idea.
¹) https://www.imy.se/en/news/four-companies-must-stop-using-google-analytics/
https://news.itsfoss.com/microsoft-office-365-illegal-germany/Especially US companies usually just do things and are willing to engage in lenghty legal battles after the fact.they are very, very litigous.
Another issue to consider is that the GPDR is held vague on purpose since it applies to your neighborhood yoga studio as well as Google or reddit. Entirely different use cases. So there is a lot of room for interpretation.
Looking at the conduct just within Europe, yes, I think it is possible GDPR considerations were either ignored or downplayed to the point of irrelevance. There was a recent study by noyb.eu which showed that DPOs are still often pressured to make recommendations that do not align with GDPR principles.
Either way, the DPAs will have to decide if the complaint has merit. Given new technologies are specifically mentioned im the GDPR, I am at least very curious to see how it turns out.
Ephera ( @Ephera@lemmy.ml ) English7•1 year agoYeah, a formal complaint isn’t quite intended for this purpose. Just writing to your data protection authority/officer to let them know that this is important to look after, will do the same here. They can then hand out a warning to Reddit.
promitheas ( @promitheas@iusearchlinux.fyi ) 16•1 year agoIve been engaged in discussion with my country’s data protection officer since the summer, and the reply I got was that I should delete comments myself. There are 2 comments that appear on my profile only if viewed while I am signed out, and when I raised the concerns with her I basically got the reply that “there is no personal information contained within and once you delete your account there is no username attached to them so you cant be linked with them”. Is she right, and how do I handle this situation?
Blackmist ( @Blackmist@feddit.uk ) English9•1 year agoAs I understand it:
As long as the link between data and user is severed, they are compliant with GDPR. Anonymising data (proper non-reversable anonymisation, rather than pseudo-anonymisation) is as good as deleting. As long as it’s not personally identifiable, it’s OK.
I suspect anyone else expecting the EU to purge reddit of their comments will be equally disappointed.
sibachian ( @sibachian@lemmy.ml ) English5•1 year agowhat about the whole knowing who is who based on word pattern/habit, and connected content and/or opinion?
Blackmist ( @Blackmist@feddit.uk ) English4•1 year agoNone of that really seems to count for GDPR. And good luck picking any one person out of a sea of a million orphaned comments.
LWD ( @LWD@lemm.ee ) 3•1 year agoAccording to how the UK’s Matrix/Element “privacy” messager app acts, that is correct. If, for example, you request a GDPR compliant data deletion of your messages in a room that contains 100 people, they will continue storing your data and delivering it to those 100 people, as well as propagating your data across any other servers where those people may be.
If you’ve lost access to any of those rooms, screw you, your data doesn’t belong to you but it does belong to anybody who was there at the time.
jarfil ( @jarfil@beehaw.org ) 2•1 year agoAs long as the link between data and user is severed, they are compliant with GDPR. […] As long as it’s not personally identifiable, it’s OK.
Wrong.
In the US, data protection refers to “personally identifiable” data, so severing the link is enough. Under the GDPR, all “personal” data is protected, doesn’t matter if it has a link or not to identify the person.
The test under the GDPR, will be whether a comment has any personal data in it. If it’s a generic “LMAO”, then leaving it anonymous might be enough; if it is a “look at me [photo attached]” or an “AITA [personal story]”, then the person can ask for it to be removed, not just anonymized.
LWD ( @LWD@lemm.ee ) 1•1 year agoThat sounds like it places an undue burden onto the user to determine and explain why data might be personal. Is a particular writing style personal? Something that identifies their IP address, or time zone, or three separate messages that can be used to pinpoint someone’s identity or narrow it down significantly?
To build on the Matrix example I mentioned, they give you the ability to “redact” messages but it’s your job to hunt them down across their entire platform, and obviously you can’t look at any messages in any rooms you’ve been kicked out of (and I’m pretty sure an API call to redact them, even if you correctly guessed the ID, would be rejected).
jarfil ( @jarfil@beehaw.org ) 2•1 year agoplaces an undue burden onto the user to determine and explain why data might be personal
The other way around: all data originating from a person, is by default “personal data”, and the burden of explaining which one is not, lies with whoever is keeping it.
you can’t look at any messages in any rooms you’ve been kicked out of
If they’re keeping them, then you can request a GDPR export of ALL your data. Doesn’t matter whether some interface or application allows you access to the data or not, or even if you’ve been banned from the whole platform; as long as they keep the data, they have an obligation to honor your rights of:
- Access
- Correction/Modification
- Removal
Even during obligatory data retention periods, when they can’t remove the data and only make it inaccessible, you still have the right to get a copy of your own personal data.
LWD ( @LWD@lemm.ee ) 1•1 year agoI really hope I’m wrong and you’re right here! I agree with you entirely in terms of what should be allowed, if it isn’t already allowed. And I definitely hope you’re correct. I haven’t recently requested a data export from my languishing Matrix account, but I might give it another go to see what kind of data is stored on my home server.
jarfil ( @jarfil@beehaw.org ) 1•1 year agoI’ve had to deal with this on the data collection end, and it’s a PITA to build in the mechanisms to fully follow the law. If you’re an EU resident, and especially if the server is in the EU or has to follow EU agreements, then they’d risk some quite high penalties if they didn’t follow it.
The DPAs have discretion on how they interpret the laws and what guidance they give. This is something you could only really pursue through litigation beyond what reply you’re getting from your DPA. Personally, I am not trusting reddit to actually, truly delete anything. But there would need to be proof for that, beyond my suspicions.
If deleted was truly deleted, I’d say they’re right on an individual case.
The issue I’m outlining is however of a different nature, so I am somewhat hopeful at least some DPA will take this issue on.
delirious_owl ( @delirious_owl@discuss.online ) 1•1 year agoWhich country?
promitheas ( @promitheas@iusearchlinux.fyi ) 2•1 year agoCyprus
The Hobbyist ( @TheHobbyist@lemmy.zip ) 14•1 year agoFormer reddit user, deleted my accounts just a few weeks back, should I feel concern that my data may still be involved? I guess there would be no GDPR recourse for me anyway?
macniel ( @DmMacniel@feddit.de ) 5•1 year agoDid you also deleted your comments and posts?
The Hobbyist ( @TheHobbyist@lemmy.zip ) 4•1 year agoYes, all content possible, before deleting my account.
onion ( @onion@feddit.de ) 17•1 year agoYou didn’t delete anything. You told reddit to delete stuff, but whether they actually did that is a different question. It isn’t public on their website anymore, but the data might still be lying around on their servers
MouseWithBeer ( @MouseWithBeer@iusearchlinux.fyi ) 16•1 year agoYea they keep all the data. I deleted everything on my account when the whole shitshow happened and then GDPR requested the data associated with the account and it was all still there. And when I requested that they delete that too they outright refused.
Որբունի ( @vorpuni@jlai.lu ) 3•1 year agoCan you post a short version of what you sent them for inspiration?
delirious_owl ( @delirious_owl@discuss.online ) 7•1 year agoIs there a way to export my data from reddit and archive it on Lemmy instead? I dont want my valuable contributions of difficult-to-find information to be lost forever by just deleting it
Possibly linux ( @possiblylinux127@lemmy.zip ) English4•1 year agoHonestly you can just leave it be. If you stop generating new content the value of Reddit will drop.
Kissaki ( @Kissaki@feddit.de ) English1•1 year agoYou can export your reddit data. There’s no simple, existing way to replicate it on Lemmy though.
The export is machine readable, so scripting a loop that creates posts from it would be viable and reasonably doable.
lemmyingly ( @lemmyingly@lemm.ee ) 6•1 year agoI see no difference between most big tech companies and Reddit in terms of selling user data. Reddit is just being more forthcoming with it instead of allowing users to figure it out eventually.
Kory ( @Kory@lemmy.ml ) 4•1 year agoDone. Screw Reddit.
Any based users in general, really
Zerush ( @Zerush@lemmy.ml ) 2•1 year agoA Reddit account a lot of years ago, no relevant occassional posts, made with other PC from other city, no personal data. I don’t think I’m going to bother connecting again to search and delete the few posts from then, the remedy would be worse than the problem.