View profile

Do we not care about online privacy any more? [Collision Course #9]

Do we not care about online privacy any more? [Collision Course #9]
By Tommy Collison • Issue #9 • View online
Hello and welcome to the 9th edition of Collision Course, a newsletter about tech policy, consumer privacy, and the future. As always, click here to read previous issues.
If you enjoy the newsletter, I hope you’ll consider encouraging friends, family members, and colleagues to sign up. The link:
Today: are Americans sick and tired of hearing about data breaches?

The Commerce Department released a report this week on the online privacy and security concerns among American households. The new report compliments an earlier study done — first in June 2015 and again in November 2017. Both times, here’s what respondents were asked about:
  • Conducting Financial Transactions
  • Buying Goods or Services
  • Posting on Social Networks
  • Expressing a Controversial Opinion
Before reading on, I invite you to stop and think — what results do you expect? Are we more or less afraid of posting controversial opinions online? Do we feel less safe online? How much of an issue is identity theft today than in 2015?
From the report:
“Privacy and security online continue to be major issues for Americans, […] However, the 2017 survey showed a decline in households reporting concerns and avoiding certain online activities compared with the 2015 survey, which first asked these questions. The proportion of online households reporting privacy or security concerns fell from 84 percent to 73 percent during this period. Similarly, the proportion of online households that said privacy concerns stopped them from doing certain online activities dropped from 45 percent to 33 percent.
The timing of both surveys is interesting: the June 2015 survey happened two weeks after the breach of the US Office of Personnel Management, which exposed the personal information and social security numbers of millions of US government workers. To me, that explains (as the report suggests) why those households with federal employees were twice as likely as other households to report identity theft concerns in 2015.
It does raise the question whether the OPM leak artificially inflates the 2015 numbers. I think not. For one thing, November 2017 would’ve been two months after the massive Equifax leak, when the personal information (and social security numbers!) of millions of Americans (both federal employees and not) were exposed. There are always leaks capturing headlines.
For another, I think the drastic across-the-board reduction in avoided activities (Figure 1) can’t be explained just by OPM leak-induced jitters.
Here we are now, almost a year since the Equifax leak. Can any readers of this newsletter point to some specific damage they’ve sustained because of it? Some action they’ve taken as a direct result?
I suspect the answer is “no” to both questions, and that’s driving the sentiment in Figure 1, that despite everything that happened between 2015 and 2017, we’re just not more concerned about social networks vacuuming up our data and having our identity stolen. Anecdotally, I get the sense that my friends just.. care less about online security. Social media is a Russian meddling-induced dumpster fire and all their information has either been posted online or wound up on a government server or four.
I suspect there might be a sort of “breach fatigue” happening here. Think of the sheer number of information leaks that happen. Off the top of my head, in the last five or so years: the Snowden leaks, the CIA Vault leaks, the Reality Winner leak. The 2014 iCloud photo leak that everyone called “The Fappening.” Sony, OPM, Equifax, Ashley Madison, Reddit, Cambridge Analytica. This, combined with the the lack of direct, demonstrable harm, is creating an interesting dynamic: at the same time as a seemingly never-ending drip-drip of “another day, another data breach”, there seems to be a growing sense of — well, so what?
Bonus round: a counterpoint
One notable exception to the “leaks don’t matter much because there’s no direct personal harm” argument: the summer 2015 breach of Ashley Madison, a social network marketed toward people seeking extramarital affairs. At least two individuals, a pastor in Louisiana and a police officer in Texas, committed suicide soon after their names appeared on the leaked user list. 
As always, I welcome your feedback, and I’d love to hear your suggestions for what you’d like to see covered in this newsletter. I’m @tommycollison on Twitter, or you can email Please get in touch! 📩📬
Did you enjoy this issue?
Tommy Collison

A newsletter about tech policy, consumer privacy, and the future.

In order to unsubscribe, click here.
If you were forwarded this newsletter and you like it, you can subscribe here.
Powered by Revue
Seattle, WA