soatok

@soatok@soatok.blog

Security engineer with a fursona. Ask me about dholes or Diffie-Hellman!

This profile is from a federated server and may be incomplete. View on remote instance

soatok , to Random stuff

Thanks to Samantha Cole at 404 Media, we are now aware that Automattic plans to sell user data from Tumblr and WordPress.com (which is the host for my blog) for “AI” products.

In response to journalists probing this shady decision from Automattic leadership, the company said nothing but published a statement.

This statement, which was presumably filtered through more lawyers than their CEO’s recent Twitter rambling against trans users (or Automattic employees’ statement about his conduct for that matter), betrays a critical misunderstanding of what consent is.

We are also working directly with select AI companies as long as their plans align with what our community cares about: attribution, opt-outs, and control.

Emphasis mine

This is not the tech industry’s most egregious lack of understanding of consent in recent years. That dishonor belongs to LegalFling: A blockchain app for sexual consent.

However, this is still pretty stupid, and the result of an insidious trend that doesn’t get questioned enough in software engineering circles. So I’m asking that my readers shout this from the fucking rooftops.

Opt-Out Is NOT Consent

Opt-out is “our lawyers told us to make this an option to cover our ass, but we don’t want you to actually do it”.

Opt-out is “if you missed the memo, we assume we have your consent”.

The default state of any decision regarding user data should be opted out. Users should instead be required to opt in for your decision to take effect, and they must not be coerced into doing so.

If consent is not explicitly given by an informed user, you haven’t received consent at all, and to pretend otherwise is unethical.

Your users don’t fucking care about opt-out. We care about opt-in.

“But Soatok, That’ll Hurt Our Revenue”

If you have to make money doing unethical things, or by following dubious practices that don’t actually respect other users’ autonomy, then you should go out of business.

End of.

What Automattic Should Do

If Automattic wants to make things right, they must do two things and could do a third thing (but I’m not holding my breath):

First, nuke the existing opt-out mechanism and replace it with an opt-in mechanism. If nobody checks it, then don’t include their data in the sale to Midjourney or OpenAI.

Second, they should make the permission for third-parties more granular. Some of us don’t care about third parties, but do NOT want “AI” companies using their data to enable plagiarism.

Third, if you want to go the extra mile, add support for a plugin that uses Nightshade on all hosted media in all WordPress.com plans, including free plans, to increase your users’ protection against LLM scrapists.

This is my open challenge to Automattic leadership to do better.

This Issue is Bigger than Automattic

The tech industry has gotten very bad at respecting users’ consent lately. Your options are no longer “Yes” and “No” anymore. Instead it’s “Yes” or “Maybe Later”, without a “Never” option.

ugh not even @signalapp is safe from the unstoppable deprecation of consent in favour of “not now” pic.twitter.com/sW4Ss2pqMb

@delan + cohost.org/delan (@dazabani) October 6, 2020

This entire goddamn thread.> the unstoppable deprecation of consent in favour of “not now”, episode 3 https://t.co/ooaDcHVhMh

@delan + cohost.org/delan (@dazabani) May 12, 2021

It does keep going. I’m going to skip a few, but check it out.> the unstoppable deprecation of consent in favour of “not now”, episode 18 pic.twitter.com/CRdfujOBZt

@delan + cohost.org/delan (@dazabani) September 3, 2023

Yes, even Linux is affected.Even worse, you can rarely uninstall the crapware that nags you with these consent dialogs.

This needs to stop. It’s a toxic mentality and it cultivates a culture that doesn’t respect humanity. (Which is kind of funny to write as a furry blogger.)

If you work in the tech industry, scream very loudly about properly implementing human-respecting consent controls into your software.

Just because it’s widespread doesn’t mean it’s inevitable. Push back against it. Your less privileged, less technical neighbors deserve better.

https://soatok.blog/2024/02/27/the-tech-industry-doesnt-understand-consent/

  • All
  • Subscribed
  • Moderated
  • Favorites
  • supersentai
  • WatchParties
  • Rutgers
  • steinbach
  • Lexington
  • cragsand
  • mead
  • RetroGamingNetwork
  • mauerstrassenwetten
  • loren
  • xyz
  • PowerRangers
  • AnarchoCapitalism
  • kamenrider
  • Mordhau
  • itdept
  • neondivide
  • space_engine
  • AgeRegression
  • WarhammerFantasy
  • Teensy
  • learnviet
  • bjj
  • khanate
  • electropalaeography
  • MidnightClan
  • jeremy
  • fandic
  • All magazines