Insulating people from fake consent

While the big cheeses of online advertising are away at Cannes, France, we might as well be honest about something. Online advertising is a dirty business. Even people who disagree with that in general tend to be of the opinion that the ads are full of fraud and mysterious fees except for whatever piece of the ad stack that their particular company is watching right now. Example:What AI is about to expose about programmatic advertising from Matt Wasserlauf, CEO, Blockboard. (Will “AI” catch the fraud? Or just make more layers of complexity for fraud to hide in?)

One of the rackets that make up this whole mess is “consent.” The “consent” as managed by adtech’s “consent management” is not consent as we know it. In order to count for anything, consent has to be informed. And if I ordered pizzas to feed everyone in the world who understands web ads well enough to give informed consent to them, the driver would be able to bring all the pizzas from the car in one trip.

Unless the user is one of a small group of extreme adtech experts and privacy researchers, sites and adtech firms are just going through the motions of pretending to have consent. A whole sub-industry of the adtech business has built up around managing fake consent. That’s because under EU law you need some kind of “lawful basis for processing” for personal information, and so-called “legitimate interest” (LI) no longer works for personalized advertising. Even Meta, which has the lawyers to draft a ToS longer than the US Constitution, and a hiring revolving door for politicians,can’t get away with LI.

Big Tech is too complicated, one-sided, and icky to get real consent, butbecause the fix is in in Ireland, everybody in the business can get away with the fake kind in Europe for now. (The USA is another story. Here, the standard for consent iswhat a jury will accept, and juries have more common sense than EU bureaucrats.)

So if fake consent is at best a show put on for crooked Irish politicians, and at worst something that will just make a company lookworse to a jury, why spend time on it? Doc Searls suggests replacing the fake consent stack entirely, inDigital Omnibus Article 88b needs to be about contract, not just consent.

For customers, the most obvious one is getting rid of cookie notices, which are annoying and not worth the pixels they are printed on.

Doc suggests replacing fake consent with real contracts as a basis for processing—which is doable. Contract formation between a web site and a visitor is an established thing, andit’s even possible to do it without JavaScript or extra software on the server. And, ignoring the ads, sites need to get people to be parties to the ToS anyway, to have a better chance of enforcing their “AI” training rights. And if sites can come up with a few standard contracts, the way the open source software business has settled on a few standard licences, then it’s feasible for a person to pick and understand a contract. It’s not like fake consent, where people have to pretend to understand tens or hundreds of “partners.” In principle, Doc is right and contract should be able to work better. In order to make the shift work, it’s necessary not only to make the contract, but also to remove the fake consent. Surveillance takes the most convenient lawful basis for processing, like electricity taking the easiest path to ground. If fake consent is available, companies won’t form a contract.

A folk privacy practice that works

The first, uninformed, answer to the fake consent problem, that a lot of people come up with, is: let’s just block the annoying “cookie banner.” And that works surprisingly well. No fake consent, now the site has a motivation to do a contract. And it turns out that the same software that blocks the “cookie banner” and prevents getting fake consent can also indicate that the user is willing to accept a contract. Some folk privacy practices are ineffective or out of date, but coming up with some way to “get this annoying banner out of my face” is a solid basis to build on. (And, hey, ifGoogle wants to keep cookie banners then they must be bad for the rest of us.)

But sites aren’t going to abandon their existing investment in fake consent unless they have to. Whatever people come up with to implement MyTerms is going to have to block fake consent too. ThetinyMyTerms demo implementation of MyTerms uses an standard ad blocker, something thatpeople need anyway and that most people in the USA already have.

Doc’s call to action is at the bottom of that blog post so check it out.

Bonus links

Montana’s SB535 and a Potential Biotech Renaissance in America by Alex Tabarrok. Montana’s regulatory system creates the possibility of a self-funding clinical pipeline: companies using early commercial revenues to finance the path to full FDA approval. You get treatments to patients faster, and you keep companies alive long enough to prove their treatments work.

Quartz countertops are driving a public health crisis in the US – 2 occupational health experts explain the surge of lung transplants and lawsuits by David Michaels and Robert Harrison. An estimated 100,000 workers are employed in countertop fabrication shops in the U.S., and studies suggest that 20% or more of exposed workers develop silicosis.

Mika Model by Paolo Bacigalupi. (Short story posted in 2016—IMHO it should make the rounds again since sycophantic AI is trending)

Who Needs GPS? The Forgotten Story of Etak’s Amazing 1985 Car Navigation System by Benj Edwards. (Another old one, but hey, Tests suggest Russian satellites can jam GPS on a continental scale, maybe time to reimplement?)

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论