Some of the recent statements have caused at least me to look those claims in a bit more nuanced light. In particular what does OpenAI consider to be "your data"? I would assume input (prompt) to be it at least. However it becomes more murky when you consider other aspects. Is output "your data"? Is the chain of thought that you are not even allowed to see? Can they use these and possibly even inputs to generate synthetic data that is then used?
All of these would seem to be "your data", but when they are carefully only including certain aspects (like prompts) in their statements it starts to sound they want to hide something.
Agreed. It would actually be a fairly perverse argument to claim that most AI output is somehow NOT owned by the AI provider…
Why wouldn’t they claim ownership of the AI output? They likely already claim ownership of the “transformation” (AI training) of the (pirated) input data.
Exactly. We as users have zero way to confirm they are honoring even the letter of these agreements, much less the intent. And it's super easy for them to weasel around and find a way to cheat while still having a legal claim to honoring the contract. And if you've forgotten, all of these companies are built on a foundation of ignoring copyright law.
Is that actually for smart tvs? The first paragraph includes "the products you may access or otherwise connect to via the ThinQ mobile application (not including Smart TVs)" and "These Terms of Use do not apply to any other LG products or services, including Smart Media Products."
[EDIT] Smart Media products terms appear to be at https://us.lgappstv.com/main/terms (for comparison here's UK: https://gb.lgappstv.com/main/terms, there are some other EU versions available for e.g. Germany but I imagine UK terms should be quite close and more accessible for most of readers)
> 8. I understand that LGE will retain the collected Voice Information for 6 months to fulfil the purposes for which we collected it, and after this period, it will be deleted or anonymized, depending on the case.
> 9. I understand that this Smart Media Product is a household device. If this Smart Media Product will be used by more than one person, I represent that, in addition to agreeing to this Agreement, that I have obtained consent from all other members of my household whose information may be collected through this Smart Media Product and am providing consent on their behalf.
> Then that officer tracked him thru flock over 100 times for some personal vendetta.
That's not quite accurate according to the article. It was actually worse: There were over 100 searches and some of them were done by officer in question, but some were done by other officers. This was due to lieutenant's order in connection with Jones' citizen complaint. So it wasn't just one officer abusing the system.
Someone in EU should try to make a complaint to the local authority who is enforcing ePrivacy Directive regarding anti cheats in general. Despite what people think ePD isn't limited to cookies and rather also applies all data read or stored in "terminal equipment" via use of electronic communications networks. I would say anti cheat should usually qualify. If they want to do it without consent then they need to show that it's strictly necessary for the service user specifically requested (and that applies for each piece of data written/read, including the OS information).
There's good argument that anti cheat itself would need to be consent based. If you don't accept then you simply don't get placed in games with users who have it enabled.
For anyone pursuing this, consider that the EU age verification apps are the EU’s first foray into digital anti-cheat systems at population scale. If you take the time to research how those are being designed and implemented and incorporate awareness of their work into your complaint about anti-cheats in gaming, your missive will be a lot more likely to strike the target and be taken seriously.
The age verification is it's own can of worms. I'm currently waiting for my native country (but not the one where I reside) to actually publish their wallet implementation. I'm planning to make complaint around it because the whole thing almost certainly breaches ePD. ePD's exceptions are actually for "information society service" rather than just any service. The ISS itself has it's own sets of requirements, but the important one here is that "normally provided for remuneration". Service provided by government as part of their public duty almost never fulfills that requirement.
So in order to store or read data they would need consent. But consent requirements come from GDPR and it's unlikely that this type of consent would be "freely given" given the impact of refusal.
From a technical standpoint, there’s no functional difference: without secure boot and OS attestation, age verification is as ineffective as EAC on Linux, because you can simply `insmod GameGenie.ko code=A456-GH4C` to have your mobile device simulator kernel patch success into any challenge. At the surface level they’re different — one is PvP, the other is PvG, one uses webcams for Twitch, the other uses webcams for facial recognition — but the same set of kernel defenses enable both.
Wouldn't the affected individual be able to sue the provider at least in some cases? From what I understand e.g. Stored Communications Act might allow suing T-Mobile in this case, at least if the individual isn't covered by binding arbitration. And possibly even government under 18 U.S.C. §2712.
Of course then it's up to judge to determine if the request was valid or not.
Both SCA and 18 U.S.C. §2712 can grant punitive damages and attorney fees. So there might be lawyers who would take it on contingency, and in this kind of case some non-profit could also have interest in litigating the issue.
And as this is something that has already happened there isn't much else the person in question can do. Third parties always have option to just disclose information to whoever asks it, at most you can hold them accountable for it later if it was unlawful. And what accountability exactly means depends on what laws exists. If you want some real accountability for the people/companies involved in these kinds of decisions then get Congress to pass such laws (however impossible it might be).
If you go by this logic, you can forget the entire legal system. You might as well immediately close all lawsuits and declare the party the winner that has more capital.
>Ιf you go by this logic, you can forget the entire legal system.
I did. I'll still file a lawsuit if I'm forced to, but I gave up in the idea that it functions in any singificant way as to not declare the winner the party that has more capital.
There are several paragraphs where output looks very AI-like (and Claude flavored one at that), e.g.
> In other words, “generated locally” does not mean that the complete operation is local. Microsoft receives and moderates the prompt, then issues the unique GUID that Paint embeds into the locally generated image. Paint also sends the previous promptGenerationId as lastPromptGenerationId with its next moderation request, allowing successive requests to be linked explicitly.
> That relationship is important. C2PA calls this a soft binding: a value derived from, or embedded into, the content so that the content can still be matched with its provenance record after the file-level manifest has been removed. For a watermark soft binding, the value is the watermark’s content identifier. Microsoft cryptographically signed this assertion.
> After an AI result is applied to the Paint canvas, the available formats are still restricted to PNG, JPEG, GIF, and Paint’s own .paint format. BMP—the classic Paint format—is conspicuously absent.
I don't think adding an identifier which can most likely be mapped back to user is "standard mark".
It doesn't explicitly say it, but there is hardly any other reason why it would add server generated ID (from authenticated session) to the saved file.
My personal website isn't customarily used for software interchange, but http is. I think getting into discussions about which websites are acceptable and which aren't feels like a bad place.
Unfortunately, I know more than a few companies who do that. The same kind of developer who used SourceSafe to just checkout the entire project (thus locking it) while busy with it. And then pop a intranetcrm_200826_0713.zip on SharePoint. Enough of them around still unfortunately.
Qualified immunity concerns civil liability. Prosecution is about criminal liability.
Civil liability is helpful because tax payers do care about $$$ (if judgements/settlements are starting to eat major part of budget the people will start to care on how to lower those costs) and victims are not limited by what prosecutors are ready to do. The QI is especially problematic because it has essentially become "did someone prosecute cops about this before" because that's effectively the only way to establish precedence that allows you to get across the QI-line in future for sufficiently similar conduct. And like you said, prosecutors are often unwilling to prosecute cops.
Civilly you can still overcome QI without prosecution, but it's indeed a lot harder to do.
Regardless, IMO, criminal prosecution is the thing that's truly lacking. It's not as if there aren't criminal codes around government officials violating constitutional rights, there are [1]. It's just that they go mostly unenforced.
This cop should be in jail on 700 counts of violating the 4th amendment.
Yes and the burden of proof standard is typically lower in a civil case than it is in a criminal proceeding. So a prosecutor may very legitimately not bring a criminal case if they feel they can't meet the "beyond a reasonable doubt" standard, but the same evidence brought in civil court could very well win the day. So the civil suit path could still be a deterrent to bad behavior if not so severely throttled.
All of these would seem to be "your data", but when they are carefully only including certain aspects (like prompts) in their statements it starts to sound they want to hide something.
reply