6 ms·
Hot dang, that last line is insightful. Some people will argue that whenever you let someone have data about yourself, you're implicitly giving access to pract
by CosmicHorrorSam 11y ago
Hot dang, that last line is insightful.
Some people will argue that whenever you let someone have data about yourself, you're implicitly giving access to practically everyone by virtue of often imperfect security.
I believe that those people are full of shit.
- dkarapetyan 11y agoAs long as there is a data silo that is not under your explicit control you have indeed implicitly granted all parties willing to invest enough to break into that silo implicit access. Where exactly is that full of shit? The problem isn't the implicit agreements. The problem is lack of control and centralization. P.S.: I'd also tone down the language. We're having a discussion and calling someone else's opinion "full of shit" defeats the purpose of having the discussion in the first place.
- abtinf 11y agoWhy is it that data under your control is immune to third parties "willing to invest enough to break [in]", but data trusted to an otherwise reputable service provider is not?
- task_queue 11y agoIf you're the government, it is easier to milk the relationship you have with telcos and the tech industry to get them to hand over data voluntarily/through the court than it is seek out a warrant to confiscate physical property in a suspect's possession which makes it obvious that they're being investigated.
- infogulch 11y agoWho says that you can protect your own data silo better than the experts at company X against these 'parties willing to invest enough to break into them'? In the general case, people are notoriously awful at security. Perhaps you, dkarapetyan, can keep a secure silo, but what about everyone else? Do they have no data rights just because they haven't studied cryptography for 10 years?
- CosmicHorrorSam 11y agoI apologize for the strong language, my intention was not to quash discussion, but to stir it up, I have many thoughts on the topic but only a short time to articulate any of them- a spirited "I disagree!" was all I could budget time for at that moment. :) I argue that part of the solution to this problem is the need for rules and standard practices. And moreso- the big problem and big deal here isn't even my own data, but rather the data other people gather on me. It's not that I want to keep my trove of My Little Pony erotic fanfiction secret- it's that when I do a Google search for incendiary dildos, I'm perfectly fine with google using my interest to target ads to me (they can inform me on the latest incendiary dildo technology!)- it's that I don't want my employer, the IRS, FBI, CIA, etc. to use that information to employ some hodge-podge machine learning algorithm on a dataset with my interest in incendiary dildos included (and therefore decide that they'll target me, because their algorithm indicate correlation between incendiary dildo interest and terrorism). In other words, no amount of data siloing will protect you from this, dkarapetyan, it's your movements and actions in the digital world - and companies' observations of them - that we're talking about. There's simply no way (that I know of) for me to both communicate to Google my search terms and receive services, have them be able to use that data to target ads to me, but also have them not store that data on me in a way that a government entity could demand it from them. Of course, we're nervous about hackers from, say, drug cartels doing something similar, but we depend on responsible storage practices to stop that- we can presently safely stop the thief at the window, but the guy that shows up at the door demanding ransom or our family dies, we've got nothing. In that metaphor, because Google has to have access to the data in order to make it useful (and make money with it), someone with any kind of legal authority can send google's executives to jail until they comply and hand over the data. The ransom metaphor may represent the crux of the whole debate. There will always be some risk of third parties gaining access to data, but some people use the 'implicit' argument to assert that because a bad actor could gain access to the data, that a government entity should be allowed to access/collect the data legally without a warrant. (That, by the way, is a more exact representation of the opinion that I called 'full of shit'.) The REAL risk, and the one where the ransom metaphor applies, is in an entity that can legally request such information and misuse it. Google, Microsoft, etc. can fragment and prevent most such truly valuable and extensive data collections from being breached fully but they are completely powerless against an aggressive intelligence agency insisting they pass on the data (and keep quiet about it) "or else". Because the companies derive great value from our data, they want to keep it safe and use it for approved purposes- and license it or sell it to others who will do the same. We (and they) have tools to keep it reasonably safe for such purposes (not perfectly, but primarily with the idea that it would take many breaches to access all the data for even a portion of the customer database system). So we give them a meager amount of trust! But all those protections are NULL if the legal system allows government entities to legitimately demand all that data without probable cause. Bah. Forgive the length. Brevity takes time, but especially where you'd asked me not to declare you full of shit, I wanted to respond. I appreciate your response, even though I disagree with you.
- joesb 11y agoDo you implicitly grant all parties willing to invest enough to break into the bank all the money you deposit in the bank?
- orf 11y ago> whenever you let someone have data about yourself, you're implicitly giving access to practically everyone I believe there is truth in that. The way I see it is you don't have much control over information entered into any computer. You can practice good security hygiene and that means you can trust information on your personal network, but that really that means you trust your combination of OS vendor, browser, antivirus, router manufacturer, etc. A hole in any one (or more likely a combination) of these could lead to someone gaining access to your data. This applies even more to info stored in 3rd parties/data sent over the net. Then you're at the mercy of the people who stole your data, they could very well release it to everyone, or sell to the highest bidder (and you wouldn't even know).
- tajen 11y agoIf we acknowledge contagion by imperfect security, then please acknowledge by law the right of entering false identites on facebook and false information by electronic means, as a means to protect our privacy.
- twblalock 11y agoWhy should there be a law about this? If you don't like Facebook's rules, you don't have to use it. Nobody is forcing you to get an account.
- CosmicHorrorSam 11y agoOH MAN. No, no, no. This is like saying, "Nobody is FORCING you to have a mailing address, if you don't like the Postal Service, just don't have an address!" Sure, you CAN do so, but if you do, you forego significant opportunities and can't make use of critical infrastructure if you do- and indeed in that example, there are places it literally is illegal not to have an address. Facebook is approaching that level of ubiquity and 'expectedness' in the U.S., at least. Please, please, please don't try to enforce the 'take it or leave it' mentality for ubiquitous software services. It is every person's right, privilege, and DUTY to complain vociferously when companies are stupid and implement stupid rules- hopefully resulting in the clarifying, changing, or removing of said stupid rules.
- joesb 11y agoThat's like saying that, by letting the bank hold your money, you're implicitly giving bank robbers the access to the money, by virtue of imperfect security. And since your own house's security is also imperfect, you are also giving everyone access to your house and properties.
- lotyrin 11y agoNot that I agree with them, but this analogy doesn't hold. What if the bank in question is in a nation where criminals vastly outnumber and over-power public and private security? The matter really is quite a bit different when dealing with information than with tangibles (or mutable information representing scarce quantities) because of how easily information can be copied and how you can't recover privacy. (e.g. how silly it is to say that "Our legal counsel is working to ensure that all copies of these photos are deleted from the internet.") If you start with the reasonable premises of "Information can be copied" "I cannot trust the information security of a third party to be perfect" you only need to add a dash of absolutism ("imperfect security may as well be no security") to get to "Information I cannot risk certain third parties having is information I cannot risk any third parties having". I don't think you're advocating for swapping that with "imperfect security is all that can possibly exist so is by definition good enough" but in the case you are, that's equally absolute and incorrect. Absolutism with information-theoretical assessment of security risk is pretty common (for good reason) in corners of industry so it should be expected as guaranteed that in discussions people will express that kind of position (on top of the human tendency for absolutism in general). The difference is simply that when making practical choices about behavior, you must employ cost benefit analysis with expected values. Will I avoid using services that track my usage? No. Would I while I'm doing something illegal? Probably, if its not very inconvenient. Will I encrypt a private key before I upload it to my backup host? Yes. Will I revoke that key if I find out my backup hosting is breached? Probably. I'd have to do the math on how likely I think it is attackers have the key, will expend effort to brute force it, will succeed vs the pain it'll be to rotate that key.
- twblalock 11y agoA lot of people trusted Apple with their photos, and Apple did not release any photos, but that doesn't really matter because they were stolen. A lot of people trusted Ashley Madison, and Ashley Madison did not release any data, but that doesn't really matter because it was also stolen. Given that nobody has invented perfect security, it is reasonable to assume that any data anywhere can be stolen, and therefore you have no control over who accesses it.
- revelation 11y agoActually, my problem with giving someone else data is that apparently US law considers data given to a third-party to be essentially a free for all for law enforcement agencies. There is zero protection for anything you have at one point shared with a third-party company, even if a device did the sharing.