4 ms·
It's very difficult, arguably impossible, to revoke access to data that's already been accessed. You could try a DRM-type scheme but there's always ways to get
by jameslevy 9y ago
It's very difficult, arguably impossible, to revoke access to data that's already been accessed. You could try a DRM-type scheme but there's always ways to get around it.
What you could do, pretty easily, is revoke access to the latest data that hasn't already been shared, and to have an audit trail of exactly what data has been accessed and when it was accessed. That would still be a massive improvement on the status quo.
I wouldn't rule out the eventual possibility of something like Facebook migrating their Open Graph API to some type of encrypted blockchain. Although I would be completely shocked if it were more than essentially a publicity tactic that wasn't actually using any true decentralization.
- noddy1 9y agoFor medical records - consider a secure reader tablet-like device. It has encrypted hardware which can be temporarily permissioned to have access to encrypted data based on blockchain timestamps. It is tamperproof - if you open it it has some self-destruct mechanism. Data is accessed in chunks, therefore the owner of the data can see whether data is being accessed in the way a human might use it, or if it is being downloaded en masse. The organisation with data access devices gets audited on an annual basis to see where all their access devices are and to ensure none of them are being tampered with. Suddenly, we get to a situation where the security of the medical file begins to resemble that of the paper-based medical records department. If you want to copy records, you need to physically go to where they are, get access to each individual file, and go page-by-page photographing each.
- lawpoop 9y agoThis is actually a genius application. I hope more HN readers read it and this meme spreads.
- reitanqild 9y agoThe improvement here is this: a secure reader tablet-like device. It has encrypted hardware which can be temporarily permissioned to have access to encrypted data This part is how it works today and it has been like this for years: Data is accessed in chunks, therefore the owner of the data can see whether data is being accessed in the way a human might use it, or if it is being downloaded en masse. The organisation with data access devices gets audited on an annual basis to see where all their access devices are and to ensure none of them are being tampered with. No blockchain is needed to achieve this.
- noddy1 9y agoit is if you are working across multiple jurisdictions/regimes and you don't want a centralized point of failure.
- dogma1138 9y agoThere isn’t a single DRM scheme that cannot be technically broken even it its with pen and paper. DRM is only as strong as the legal mechanism behind it. Since the DMCA and other legislation protects DRM the actual strength of the DRM are irrelevant. DVDs are still protected by the same broken key, BR are also broken every DRM system gets broken or is easily circumvented through side channels.