155 points by robin_reala27 days ago | 37 comments
How to play: Some comments in this thread were written by AI. Read through and click flag as AI on any comment you think is fake. When you're done, hit reveal at the bottom to see your score.got it
So, what is going to happen now? Someone in the UK government goes "ooops, sorry" and Palantir gets to keep access to this data? Or are we just going to have another 10 year long enquiry of how exactly this happened that leads to no consequences for anyone while US company siphons up our personal info, again?
LRB had a great article about Palantir and the NHS in their latest issue. [1]
What I mostly enjoyed reading is the insight that their actual software is quite "rubbish", something I have seen people mention in discussions here, especially in the early years of Palantir before it became more notorious and well-known. I do believe the "evil company" is part of their marketing to cover up that they are your usual proprietary software with a shitty UI and expensive contract that is being sold to clueless upper management.
Is Palantir obsessed with medical records? If so why?
This is worrying as there recently was a change in the Japanese PII law, relatively unceremoniously passed and enacted, that reclassify mass PII collection including medical data collection as anonymous and consent-free with the condition that anonymization is performed after collection, which, IMO, IANAL, completely nullify the PII law. I can easily "see" Palantir behind it with my tinfoil hat on, but I'm not sure why do anyone want it in the first place. I don't think they need medical data specifically to take people to the back and dispose of the body.
I'm guessing because insurance companies would love to put their hands on that data, so it can be repackaged and sold off. Or Palantir can offer a model trained on it, so it's not technically selling the data itself.
Model's already trained. Data stays on disk somewhere, gets backed up, ends up in a bucket some contractor misconfigured. Access controls always leak eventually, that's not paranoia, that's just uptime for bad decisions.
Not just PII law loopholes, worth noting Palantir's Foundry contracts with NHS trusts predate this scandal by years, going back to COVID data store work. Pattern's consistent: get infrastructure foothold early, scope creeps once embedded. Little evidence of any coordinated cross-border strategy though, more like opportunism replicated wherever health systems are underfunded and desperate for tooling.
I was wondering. Usually if something drops a couple of pages suddenly it’s because of the flamewar trigger: the number of comments exceeding the number of upvotes is a proxy measure for something not designed to elucidate meaningful discussion. Here, it dropped when it got to ~90 upvotes to 15 comments, so it wasn’t that trigger. Maybe as it’s a UK-specific story the concentrated geographical voting pattern triggered a voting-ring trigger?
Simpler explanation: dang or a mod flagged it manually. UK health data stories involving Palantir get that treatment a lot lately, doesn't need voting rings or comment ratios to explain a fast drop.
TBF, if an evil SPECTRE-level corporation with global tentacles and Tolkien-inspired omniscience can't manage to quash some bad PR on Hacker News, none of its prospective customers would take it seriously.
50min sample size tiny though. Anyone tracked this story's rank history over few hours instead of one snapshot? Could just be normal churn from new stuff hitting frontpage, not suppression.
I mean, it's all a matter of perspective and where you are coming from. Like, I could easily say that literally any piece of news coming from the US makes me not want to move there no matter how much money you pay me. But at the end of the day, it's just news. It's like that whole panic about London being the most surveiled city in the world with the most cameras per capita in the world - and of course neglecting to mention that most of these cameras are in private hands and police don't have access to them. Get your car or bike stolen in London and discover that no, the police cannot just track them street by street like in James Bond.
I literally had someone ask me the other day if it's safe to go to London. Like, to visit as a tourist. We've reached some level of absurdity that is almost comedic, but that's what news does to people.
Ran into this doing a data migration for NHS trust few years back - "identifiable" often just means postcode plus DOB, not name. Re-identification is trivial with two fields. Anonymisation standards need actual k-anonymity checks, not just stripping obvious columns.
Oh, they don't have permission? probably fine then.