T-Mobile's New AI "Profiling" Privacy Toggle Is On By Default

corbin@infosec.pub to Technology@lemmy.world – 322 points –
T-Mobile's New AI "Profiling" Privacy Toggle Is On By Default
tmo.report
23

Thanks. I just went and disabled it. I also found that they had “products and services notifications” turned on. I know I attempted to disable all advertising and monitoring stuff shortly after I signed up, but I can’t say for sure whether I had missed this section at that time or if they kindly turned it on for me between then and now.

Or they added a new setting and left it on by default without telling you. I’ve seen this happen with a few sites before

I still don’t even see the things they’re talking about. Wonder if they’re rolling it out in groups.

Are you logged in? It appears you can go to the privacy settings page and set some (not all) settings without being logged in.

I am logged in. I checked the first time this was pointed out and couldn’t see it then, either.

1 more...

There needs to be more laws and regulations. In this system, companies will use every legal way to make as much money as possible. This is especially true for public companies.

FYI: There is a dark pattern in the mobile app where, if you toggle the opt-out buttons in order from top to bottom, one of them will enable themselves.

Demons.

If they are just blatantly retoggling the field, that’s not a dark pattern. But if they are toggling based on a lower toggles “nevermind I didn’t mean the above toggle” or similar, then yeah.

That said, I don’t even know what to call the former.

Edit: The downvotes are a weird reaction to me pointing out this potentially isn’t as benign as dark pattern bullshit.

As an extra FU, if you want to opt out of data sharing with partner advertising on the Magenta Marketing Platform you have to know your Android or IOS advertising ID number or you have to install an app ... which most likely profiles you and sells your data to yet another 1000 partners.

Yeah, what I wouldn't give to have each person responsible for this madness sent to Dante's Inferno worst ring of hell.

That is a breach of GDPR, default has to be opt out. We don't need new laws we just need the existing one enforced.

Does GDPR even apply here?

Edit: It’s a US company, operating within the US, with US customers. Why would an EU law apply?

If I had a dollar for every time GDPR was whipped out incorrectly...

Does T-Mobile operate in Europe?

They do but not this T-Mobile. It's in violation of California's privacy rules to be opted in by default for something like this.

Maybe it's different in California then?

I'm in California and it was on by default. To comply with California rolls anyone in the US who resides in California can be covered even though it's not their billing address. So enabling anything like that by default or not prompting to have permission for cookies or selling data is in violation for anyone who does business in California. The gdpr rules also apply to anyone who's in EU citizen or resident even if they're outside of the EU so since T-Mobile does business in both they need to comply.

If only they put this much effort into not getting hacked every year or so.

I have T-Mobile and don't have this toggle, so it's not all accounts.

Edit: Well, ain't that some shit. I have it in the app, but not online.

Fuck it, I"m going back to a landline where only the NSA can spy on me. My phone has not been a net benefit in my life.

#bringbackdumbphones

The only thing smartphones offer over computers is more convenience and addiction. I read a few articles over the last years about teens who recognize this and went dumb-phone only. Wonder how they're doing now.

Fuck this and all, but I’m also curious about how this works. What is the output? What is the data product that they’re selling and how to companies use it?

Edit: I’m curious if anyone with ad tech experience has any insight. Not looking for the broad strokes, I’m more curious about the technical details.

What the point of data collection tool that required you to turn it on ?