14 ms·
In computer security, every time machines become fast enough to breach the limits of an algorithm we invent something new so that “hard” problems remain “hard”
by makecheck 9y ago
In computer security, every time machines become fast enough to breach the limits of an algorithm we invent something new so that “hard” problems remain “hard” and therefore encryption is still secure.
There has been no corresponding increase in the difficulty of invading privacy. 30 years ago, even though you probably “could” observe somebody for a long time and eventually connect some dots about them, it would not really have been worth your while (and you certainly wouldn’t have been able to do it for thousands or millions of people). Now, it is ridiculously easy for computers to dredge up information and instantly transmit it, slog through it and basically connect every imaginable dot. There needs to be a new standard for privacy: just like you want a 2048-bit key, you want the equivalent of a “make life a pain in the ass for Facebook” key on EVERY DETAIL of your life.
- deleted 9y ago[deleted]
- Mosi1 9y agoHow many times has your privacy been invaded?
- adamnemecek 9y agoSend me your credit card info, I promise not to abuse it.
- zepto 9y agoDon't you mean how many times per minute?
- tmsldd 9y agoper second.. it would be a more suitable scale
- PhasmaFelis 9y agoPretty much continuously for the last umpty years, I'd say. It doesn't have to be immediately and personally catastrophic to be a serious problem.
- fictioncircle 9y agoIt terms of a hostile 3rd party and not an automated system? 5 times. Snoopy relatives of women I have dated a couple times, a couple times by PIs paid to track me down, and a stalker once. So...yeah. It's a real problem and none of these people had a legitimate cause to do so. Even beyond FB, etc. I don't post my face online because of shit like that. Other people have stopped posting pics of me as well, a couple people have been called based on my name being tagged to things on social media.
- ocdtrekkie 9y agoI went in and untagged myself from a bunch of stuff my parents posted after my online friend commented on one of the pictures. It wasn't that it was super problematic, it's just I realized I really didn't want family pictures broadcast to my friends.
- fictioncircle 9y agoI don't have a FB account.
- draw_down 9y agoSecurity breaches are bad for capital. Privacy invasions like this are good for capital.
- jngreenlee 9y agoSecurity breaches are bad for one party's capital, good for another party's capital. It's interesting to contemplate WHY is there a difference between the two. Security and Private both nasciently have something to do with "info I'd like to keep to myself", but I'm not sure I can come up with a hard delineation between the two, at least when you try to go above "A/S/L" and below "user/pass".
- nine_k 9y agoA security breach allows to use the victim's resources: from CPU and bandwidth to money directly on your bank account. A privacy breach allows... what? Where's a direct threat? A privacy breach can be a first step to a security breach, though. Social engineering is all about it. Social networks can be, too.
- gaius 9y agoA privacy breach allows... what? Where's a direct threat? Any means of authentication that relies on personal data. SSN, mother's maiden name, postal address, date of birth, etc.
- fauigerzigerk 9y ago>A privacy breach allows... what? Where's a direct threat? A privacy breach could mean that your job application is rejected, that you pay higher interest on a loan or higher insurance premiums. It could mean that your health insurance refuses cover for some treatment because some data points towards a pre-existing condition. You could be rejected as a tenant based on the scoring done by a referencing agency or you could get searched every time you cross a border. In a more unlikely event could even become the victim of a miscarriage of justice or get blackmailed by a corrupt government official.
- 9y ago
- NabenHarb 9y agoYou have essentially described differential privacy (https://en.wikipedia.org/wiki/Differential_privacy https://en.wikipedia.org/wiki/Differential_privacy). The main issue is that there is no reason for companies like Facebook to fully adopt it, since it doesn't benefit them and there is no outside pressure forcing them to do so.
- denzil_correa 9y agoMay be I'm the only one but how is the parent referring to Differential Privacy? Differential Privacy is "one way" to achieve privacy. The parent comment talks about a different standard for privacy the moment computing power increases.
- tunesmith 9y agoIs there any work being done on making tracking our details more worthless? Like... generating fake data, honeypot browsing behavior, etc?
- prostoalex 9y agoAdNauseaum
- ihm 9y agoI would love if someone made a Chrome extension that encrypted all the posts and messages you put on Facebook. That is, any post you made would be made as a ciphertext, the extension would swap keys with all your friends in the background, and would decrypt their posts when displaying them to you. Sure Marky Mark still sees when you post, who you send messages to, etc. but it's a much better situation than what's going on now. Plus it would probably put a dent in their bottom line, and so send them the message that privacy matters to people.
- wmeredith 9y agoEh, your head is in the right place, but honestly if you have all the meta data, the message content almost isn't needed.
- denzil_correa 9y agoExactly. I also think that encrypting data is a smokescreen to gain brownie points. Yes, it is more secure than not encrypting messages but the effect of message encryption on your privacy is very low.
- nsajko 9y agoSee my reply to ihm about how to deny Fb metadata.
- gruez 9y agoso like, PGP?
- fooker 9y agoBut for Facebook! Probably also need to throw in a Tinder and Uber to exchange keys properly.
- ghughes 9y agoYou're so close to what I am currently building that I feel like I have to chime in. I left Apple's security team a few months ago to go solo and build an app that is similar to Facebook/Instagram and Snapchat in terms of functionality and UX but uses the Olm protocol (similar to Signal) to protect all content. So, fear not - something is being done, and I'm sure I'm not the only one working in this problem space. I think it's ripe for innovation, counter to popular belief; the trick is to do it in a way that doesn't require a PhD in computers to operate the damn thing, as was the issue with previous attempts.
- fidz 9y agoExactly. Once we can understand P vs. NP completely, all cypto algorithm today will be obsolete since crypto algorithm today ONLY rely on that "hard" problem.
- d33 9y agoOnly if P = NP, right?
- pokemongoaway 9y agoGreat explanation. Would love to see more companies that understood this - we would buy their products! :)
- crucialfelix 9y agoHow about a Scramble Suit as in a Scanner Darkly ? A browser extension that supplies fake events to all the tracking scripts. Fake website visits, fake clicks, fake session duration. Couple this with a network of VPN so that you are appearing in multiple locations, scrambled with everyone else using the service.