4 ms·
So, as the first tech hire/partner, what can we do to protect our users? - Expire non-critical data after 30 - 90 days, e.g. activity data, not account data.
by devrandomguy 9y ago
So, as the first tech hire/partner, what can we do to protect our users?
- Expire non-critical data after 30 - 90 days, e.g. activity data, not account data.
- When feasible, have the client encrypt the really private user data, only store encrypted blobs on the server (Protonmail does this).
- Send out a positively worded, subtle email notice to warn the more savvy users of a pending acquisition, as soon as that news is no longer private. Let them disseminate the real sitrep on social media and in the news. We did build a community, after all.
- Propose a data architecture update for great efficiency, in which redundant and superfluous data is cleaned and aggregated, before the big handover.
Are there any other suggestions? I am particularly curious if the laws of any one user's country could be used to complicate or thwart a bulk handover of private user data to a new owner. Europeans, I'm looking at you for advice.
- pdkl95 9y agoBy far the most important protection you can provide is to bind your future abilities with a "Ulysses pact"[1]. Cory Doctorow ave a great talk[2] last year about how important it is to create these limitations when you don't need them, because there is a good chance you won't be strong enough to resist temptation when problems start accumulating. In some situations, it may not even be your choice. [1] https://en.wikipedia.org/wiki/Ulysses_pact https://en.wikipedia.org/wiki/Ulysses_pact [2] https://www.youtube.com/watch?v=D8ukyKQuNmY https://www.youtube.com/watch?v=D8ukyKQuNmY
- rock_hard 9y agoSSL with pinned certificates would get you 95% there and is super easy to implement. And then only keep the data you actually need. And even of what you need you can probably anonymize a large chunk