4 ms·
Of course you can't prevent people from copying stuff. But you can control who you want to trust. If the interface allows easily grouping people, you can easily
by plesn 16y ago
Of course you can't prevent people from copying stuff. But you can control who you want to trust. If the interface allows easily grouping people, you can easily publish your political thoughts with your friends and your children photos with your family. Everything else is not a technical problem: before you tell someone something confidential, you'll gauge wether she will repeat it to everyone and to whom she might repeat it.
- mdasen 16y agoThe point of my post wasn't to bring up the issue of how to gauge whether friends will repeat/copy things. The issue is that Diaspora is bringing in another layer to the mix: third-party service providers. Right now, with Facebook, I have to judge whether I want to share something with you. With Diaspora, I'd have to judge whether I want to share something with you and whether I trust your service provider to be a trustworthy go-between. With Facebook, I have to read and agree to a single privacy policy. With Diaspora, I might have dozens (or more) policies that I'd have to read and track (if I care about privacy). Diaspora seems to say that I don't have to trust the other service providers. They're saying it's "privacy aware, personally controlled". They say that their "current implementations include GPG encryption". They say that "Diaspora knows how to securely share (using GPG) your pictures, videos, and more," and that, "When you have a Diaspora seed of your own, you own your social graph, you have access to your information however you want, whenever you want, and you have full control of your online identity." But how is that? I don't expect them to fix the issue of one of my friends using cut and paste. However, they are claiming that I'm in control of my data. If other sites are able to decrypt that data, then those other sites will be able to store that data. How are they getting around that? From my perspective, Diaspora is adding more privacy concerns since I now have to decide whether I trust my friends and my friends' service providers rather than just Facebook and my friends. It isn't just whether a company is going to be evil. Sometimes companies accidentally expose data and sometimes companies are breached. Diaspora's grandiose statements seem to promise end-to-end security; that none of the servers between me and my friend will be able to decrypt the data. They claim that I'm in control of my online identity making it seem like if I delete something off of my Diaspora account on one provider, it will be removed from the feeds on other providers. But I can't see a way that this would work. If I have a Diaspora server with you as a user and I go to get your friends' status updates from other Diaspora servers, isn't my server going to be able to decrypt that information in order to pass it along to you as text? You've elected to trust me with your information, but have your friends? Couldn't I store their status messages against their will? Couldn't I make them public against their will? What I'm looking for is someone to tell me how Diaspora is going to keep my information private. Yes, I could decide which service providers to trust and weed my friends based on that, but that isn't the security that Diaspora is claiming. They're claiming that they're privacy aware, that I'm in control of my data, that it's being securely shared, that I'm in charge of my social graph and online identity. I just don't see how they're accomplishing it and their site offers no information on how. Here's the base issue: I post a status update. Your service provider has gotten it from mine and put it in your feed. I delete it. Does your service provider just voluntarily remove it on their end? I don't want it there, but there's nothing I can do about it beyond appealing to their good graces. That isn't putting me in charge. If I'm to be in charge, when I delete that post, you have no more access to it (unless you used copy/paste or something else) and your service provider no longer has it in their database. Diaspora hasn't said how they're going to accomplish this. In fact, deleted posts would be the best thing to data-mine: they're things people don't want shared because they're embarrassing or whatnot. Think about it, you tag a photo of me and that gets cached by service providers. I do a remove-tag request on that photo - that's likely a photo I don't want people seeing. That remove-tag request gets propagated out, but rather than removing the tag, some service providers just put a date_to on the tag, others might just ignore it completely. I'm not in control of my data there. How is Diaspora getting around this problem (since they claim to be)?
- williamjames 16y agoYou speak exactly of the problem: Having outside service providers. When you have an outside service provider you are now, and will always be, dependent upon the service provider. The only solution is to not use service providers and to distribute your own data (as you have described). When you distribute your own data, you can have nightly encryption key updates sent to all of the friends you trust. If you remove a friend from your list, they do not get the nightly key update and no longer have access to your information. What I describe in my article that I published on Saturday is that we are not at the point yet where completely distributing all of your own content created by you is plausible. The use of third party "service" providers is simply a necessary (for some people) thing in this transition period. Here is the article I speak of: http://news.ycombinator.com/submitted?id=williamjames http://news.ycombinator.com/submitted?id=williamjames
- plesn 16y agoNothing will give you definitive answers: email is decentralized but computer-litterate and privacy-aware people use gmail and regularly send important emails to gmail users... I agree with you that there should be some way to "quite easily" encrypt everything so that your recipient decrypts it only on its client software, though I doubt the situation will differ from the current one with emails. But "Freedom" lies in the effective ability to use it. Once all protocols are open your issue is more social than technical: for this see Elben Moglen's ideas on personal servers (tiny pluggable servers…) (even if we already have DSL boxes and even phones for small-bandwith data).