3 ms·
To be clear, I think you're right that no tracking is better than trying to protect data. However, it's important to understand that 'anonymization' is very di
by AdamSC1 9y ago
To be clear, I think you're right that no tracking is better than trying to protect data.
However, it's important to understand that 'anonymization' is very different than the practice of "Differential Privacy."
I'm no expert but here is how I understand it as a simplified example:
Imagine your information is stored in a spreadsheet. It is storing your weight, height, zipcode, age and name.
The 'anonymization' spreadsheet would still have a unique row dedicated to you (similar to a spreadsheet) and it may replace your name with an ID# or an encrypted string. Now, just like in the AOL dataleak that information being stored as a single line item is still easy to backtrack as there is likely no one else with your weight, height and age combination in your zipcode. So a hacker can identify a single person.
Differential Privacy would store information differently, perhaps in separate spreadsheets, one that is list of heights, one that is a list of weights, etc, etc. No two spreadsheets would store the information in the same order (#3 on the height list would not be #3 on the weight list) and it may even contain some incorrect dummy information.
There would be some sort of algorithmic relation however that allows a system to create outputs in which the data has meaningful information (trends, means, standard deviations etc) but it can not be back-tracked to identify any single unique row.
Differential Privacy allows us to see the trend "Males age 45 are taller on average than Females age 45" but not say "User #155083 is age 45, weighs 195lbs, and lives in zipcode 10001"
That's a big difference in privacy, and while it isn't perfect it is a step in the right direction. While I wish more companies would adopt a no-data policy, it is at least better that they are responsible as can be with the data they have.
- rectang 9y agoSuch obscuring is vulnerable against sidechannel attacks to re-link the record fragments. For example, misspellings, incidental geographic information, topics -- any pattern which is unusual, not anticipated by the modeler and deliberately obliterated. What links the AOL fiasco and this one is that both believe they have thought of everything important. They're wrong -- and there will always be a future attacker to prove it. You can't fight information theory. Differential Privacy is an excuse to get around sensible no-data policies -- by making irresponsible promises, it will result in more privacy violations, not less.
- AdamSC1 9y agoYou're right these systems are currently flawed, and may remained flawed. But, the same is true for all systems. Don't get me wrong I agree in theory that every company should not retain any customer information - I work for one of a few companies that does that, but, I also know that many company's will not make that switch (example a bank, or a medical record) and in such cases that data should be as secure as possible. To counter the irresponsible promises you are talking about it'd be ideal to see compliance and security regulation like we see with HIPPA applied to all customer data, but until we evolve proper trust-less identification models and ways for users to self-secure and trustlessly validate their information then some businesses will always collect data.
- frankmcsherry 9y ago> You can't fight information theory. I totally agree with this statement, but I think you are confused about differential privacy. Its guarantees are information theoretic (specifically, a bound on the relative Bayes factors of any conclusion, with and without any individual record). You are obviously welcome to be skeptical, but much of what you've posted so far is not correct.
- rectang 9y agoOf course I don't dispute the math. I maintain that these guarantees will not be achieved in practice because they rely on impossibly airtight implementation and impossibly omniscient modeling.
- frankmcsherry 9y agoInteresting. Do you have similar concerns about cryptography? Edit: to more strongly bind 'similar': would you also say of cryptography that it is "cynical academic malpractice"?
- dsp1234 9y agoNot the person above, but I do, yes. Heartbleed, side channel attacks, etc. Implementation in the real world matters.