5 ms·
There's a way to identify individuals in the raw data: http://userweb.cs.utexas.edu/~shmat/shmat_oak08netflix.pdf http://userweb.cs.utexas.edu/~shmat/shmat_oak
by gaika 17y ago
There's a way to identify individuals in the raw data:
http://userweb.cs.utexas.edu/~shmat/shmat_oak08netflix.pdf http://userweb.cs.utexas.edu/~shmat/shmat_oak08netflix.pdf
http://userweb.cs.utexas.edu/~shmat/netflix-faq.html http://userweb.cs.utexas.edu/~shmat/netflix-faq.html
- deleted 17y ago[deleted]
- nfnaaron 17y agoIt's almost always surprising just how much private data can be exposed after data has been "anonymized." When you're using private data in any public way, or even with "partners or affiliates," you need to be very careful, watchful and responsive.
- nlabs 17y agoInteresting thanks for the link. However, seems like you need to be able to cross-correlate with another database in order to de-anonymize. If netflix made a good faith effort to protect privacy, how are they liable?
- raganwald 17y agoIf I am your bank and I make a "good faith" effort to protect your money from robbery, how am I liable if I am robbed of your money? For certain types of agreements, good faith is not enough. Netflix chooses to go into a business where it is privy to private information about its customers. The onus is on Netflix to protect that information. I would say the same thing had hackers cracked their security and made off with the data. Good faith efforts that fail to secure the data are not enough, they must succeed in protecting the privacy of their customers.
- nlabs 17y ago>>If I am your bank and I make a "good faith" effort to protect your money from robbery, how am I liable if I am robbed of your money? Banks take the precautions ahead of time (deposit insurance) against robbery-thats part of the "good faith" of protecting a users money. Nice try.
- inerte 17y agoCar manufacturers have to make sure the brakes and air-bags work. Elevators makers have to make sure they won't fall. Parachutes can't have holes. Lots of examples. Heck, imagine if companies could do things wrong and get away with: "Hey at least I was, like, trying reeeeally hard. I thought it was ok to do this". Acting in good faith would become the excuse to use when the shit hits the fan. PS: "Acting in good faith" in the real world means following the standard, industry adopted, government mandated: policies, process, regulations, laws, etc... That's what let you get away from problems. Not happy thoughts.
- nlabs 17y agoditto my above comment. If netflix says data will be collected and then anonymized in its TOS, and it does so, then it acted in good faith. If a hacker reveals a weakness and Netflix pulls the plug, should they be sued? If yes, then how can companies innovate, when they will constantly fear liability?
- HeyLaughingBoy 17y agoThe same way they do now. (Successful) companies don't fear liability: they prepare for it but realize that they will never be 100% insulated. You weigh your options: if the benefits of doing something outweigh the costs (including lawsuit outcomes, poor public perception, etc) by enough of a margin, then you forge ahead.
- inerte 17y agoYou think the amount of effort by Netflix to protect the identities of its costumers was enough. It was not. They intentionally released an amount of information, thinking none of its costumers could be traced, but guess what? They were. Yes, it had to be used with other datasets to discover individuals, but Netflix ignored (you say acted in good faith) this possibility and decided to go ahead. They were ignorant of the implications of the data they released. They didn't saw the possibilities that their costumers could be found. They were stupid and reckless. The problem is that you're thinking about this situation as the researcher, the person who wants the data set to play with. Put yourself into the company's shoes. You want to improve the recommendation algorithm. You hold a contest, which needs the costumer data to work. But you know that your costumers won't be happy to have their info released, so you go and anonymize the data. See where I am going? You had an idea, executed, but the consequences were bad. Imagine if car companies acted this way, one morning an engineer comes to work and puts a new brake system in the company's car already in production thinking it'll be awesome and work ten times better than the previous brakes. Without rigorous, government and industry trials, experiments and tests. Good idea, poor execution. Netflix doesn't have "good faith", they wanted to improve their recommendation algorithm. They wanted to profit. Now, I don't have anything against profits. But it's naive to think Netflix did this for the benefit of mankind. They had their own reasons, and to achieve that, they've broken a promise to their costumers. They said: Hey, we'll keep on our database this information, but don't worry, none will ever know it. But then they go and _relase_ costumer data, _thinking_ it's sufficiently anonymized. They were wrong. Double mistake there. The "hacker" wasn't alone in this, "he" had a direct help of the company which was supposed to not let this happen.
- pyre 17y agoSure we released that murderer from jail, but he needs to buy a gun to shoot someone, and we didn't sell him the gun. You can't blame us. If they know that the information can be de-anonymized using publicly available information, have they really made a good-faith effort?
- nlabs 17y agoSometimes you release people (sometimes murders) because of a thing called a constitution...a case where there is liability for NOT releasing the murderer.
- pyre 17y agoYou weren't meant to take that literally. It's just to illustrate a point, not necessarily describe a real-world scenario. Notice how you're arguing my metaphor's accuracy rather than actually defending your original point.
- nlabs 17y ago>>If they know that the information can be de-anonymized using publicly available information, have they really made a good-faith effort? If your premise that Netflix knew the db could be de-anonymized is correct, then its not "good faith". Otherwise, Netflix could argue it did everything it said it would do in its TOS, and didnt foresee the hackers exploit. Whether that makes them liable or not is what Im asking. Im not a lawyer. The reason the bank robbery example is irrelevant is banks say in their TOS that your money is 100% protected up to the FDIC limit. So, Netflix TOS said it would make its db internally anonymized, which it did. Clever cross-correlating made this not enough.
- pyre 17y agoTrue, but then the question becomes: What does Netflix do now? Once they know that their efforts are not enough, what is their reaction? IIRC, they were warned about the fact that the second prize was revealing too much information, but went forward with it anyways.
- toby 17y agoI get "Forbidden" for both those links. Are there any other links to those papers? I hadn't heard of this result and I'm very curious.
- deleted 17y ago[deleted]
- davidu 17y agohttp://cc.bingj.com/cache.aspx?q=%22shmat+oak08netflix+pdf%22&d=4766125284327848&mkt=en-US&setlang=en-US&w=914e38af,76fc4030 http://cc.bingj.com/cache.aspx?q=%22shmat+oak08netflix+pdf%2...
- wingo 17y ago"Let us summarize what our algorithm achieves. Given a user's /public/ IMDb ratings, which the user posted voluntarily to reveal /some/ of his (or her; but we'll use the male pronoun without loss of generality) movie likes and dislikes, we discover /all/ ratings that he entered /privately/ into the Netflix system" (em. orig.) One's "political orientation maybe revealed by his strong opinions about "Power and Terror: Noam Chomsky in Our Times" and "Fahrenheit 9/11," and his religious views by ratings on "Jesus of Nazareth" and "The Gospel of John." Even though one should not make inferences solely from someone's movie preferences, in many workplaces and social settings opinions about movies with predominantly gay themes such as "Bent" and "Queer as folk" (both present and rated in [one individual's] Netflix record) would be considered sensitive"