3 ms·
I believe our current paradigm for how data is stored is fundamentally broken. The author is right that when you choose to use a service you have no real contro
by joshpadnick 10y ago
I believe our current paradigm for how data is stored is fundamentally broken. The author is right that when you choose to use a service you have no real control over how they use your data. Frankly, companies aren't even accountable to uphold their own privacy policies since no one actively monitors them (except perhaps in the context of HIPAA, PCI, etc.)
What I'd love to see is a marketplace of "personal data banks" that would work like this:
- The bank maintains an isolated database of every major database vendor. The databases are isolated to a single consumer.
- The bank exposes API endpoints of every major database to companies like Facebook or new SaaS startups. Those companies now agree -- when requested -- to write your data not to their private database but to the bank's database that is private to you.
- You, the consumer, pay the bank a modest monthly fee to control who can access that data, and even optionally cut off access to the original "generator" of data.
I guess this still suffers from the need to trust that Facebook is abiding by your request that all data be written to the bank, and network latency becomes a real issue. So maybe it's not the right business model, but it's an important problem to solve.
- hardwaresofton 10y agoTaking that one step further, maybe if someone wrote that kind of tool, basically an API for your personal data that you can run locally, maybe they could scale it up to what you're describing? It would require a massive paradigm shift in how the internet works in practice, but image a world where: 1. You sign up for some new social network/thing that requires your data 2. You point it at your own personal (or hosted) info server 3. The service promises/or the use of the personal info server stipulates states that the data should never be stored longer than the lifetime of a relevant transaction 4. The social network queries your data maybe once a day (or more depending on whatever kind of work it does), announces itself, and can be cut off when you want. Of course, things don't sell these days with just privacy these days, but there's some upside to a service like this ironically due to it's centralization -- you could sell the user on "only enter your address/personal/credit card info once, have it available everywhere with one click, no long login forms"
- nbadg 10y agoYou're just shifting the trust to the "data bank". What if it gets hacked, or ignores its ToS, or some rogue employee with database access copies your PII, or... ? Trust is dead; it doesn't scale. End of story. I don't like the idea of a "data bank" or "data brokerage" any more than I like the idea of facebook; either way, someone else holds the keys to my castle. But third-party servers aren't going anywhere, so we have to find a way forward. I've come to the conclusion that the only possible way for someone (or something) to maintain control over data is to encrypt it at all times when not in use. It's exactly the idea of a "data bank" like you're describing, but you become the bank. One of the key struggles with this approach is that it requires a tremendous amount of client-side code; calling it a paradigm shift is a profound understatement. It doesn't matter how snazzy your encrypted-dist-web product is unless you present a compelling economic reason for companies to switch to it, to justify the extreme expenditure of capital necessitated by the technical switchover. Even here, though, once you share something with eg. Facebook, you can only hope they don't fuck it up. That's just the way the world (unavoidably) works; once you share something with someone, they have every capability to do whatever they please with it. You have only the social expectation that they don't, and if they violate that expectation, your only recourse is to stop communicating with them. But I do think, in a world where we actually have autonomy over our data (partly, again, because it necessitates client-side code), it is possible to make the consequences of data misuse so disastrous for a company that it stops being economically viable for them to do so. The key thing we've lost is that agency to make decisions about data. I've no problem with informed, consensual sharing, but in today's world re: data, "informed consent" is nonexistant.