5 ms·
All personal information sharing should now be purely digital and encryption-keyed. We have all of the protocols, interconnected networking and ubiquitous comp
by makecheck 9y ago
All personal information sharing should now be purely digital and encryption-keyed. We have all of the protocols, interconnected networking and ubiquitous computing necessary to make it practical.
The only “data” any organization should receive is an encrypted blob that is constructed using the key of the person who owns the data and the key of the entity that was directly given the data. Furthermore, the encoded blob should have a date of encoding and a duration of validity. In other words: “I, John Q. Public, authorize You, DataLosingMegaCorp, Inc., to receive This Blob, which is valid for 6 months or until either party revokes the key”.
Other public systems in society should be upgraded to require additional layers of security. Want to send commercial snail mail to my home address? Great: please provide the postal service with a one-time authorization code that you received from me (after all, you are using an address given to you by me and not bought from somebody else, right?).
Another nice feature would be for data to include bank deposit info for the data owner and bank withdrawl info for the data-receiving entity, where EVERY SINGLE TIME your data is decrypted you receive a cash deposit from the data-receiving entity. And make it sting, a lot: I want it to cost real dollars to use data (and of course, I can still revoke my key at any time if you still manage to do something stupid with my data).
- ThrustVectoring 9y agoA big problem with this is that a lot of data about you isn't owned by you. The fact that you took out credit card X on Y date and have paid the balance on time since then is owned by the credit card company you do business with (well, it belongs to you too, but businesses are more willing to trust Chase than you). This information has real business value from being a leading indicator and costly signal of your future propensity to repay debts.
- CaptSpify 9y agoAt the risk of speaking for OP: The point is that the data should be owned by me. Yeah, I get that it has value to other people, but I'm the one that has to deal with the fallout, not them. Just because something is useful to a business doesn't mean that they have the right to it. If they want information about me, they should be asking me, not some third party.
- yjftsjthsd-h 9y agoI don't disagree, but then how do we trust it? I suppose (thinking out loud) that we could have everyone on your credit report sign it, but then encrypt it to your public key? That way only you can let others see it, but it's still tamper-proof.
- ThrustVectoring 9y agoThere's a legit need for tampering, though - to arbitrate disputes between creditors and debtors. Also to comply with the Fair Credit Reporting Act. So there's four parties that contribute to the document: 1. Credit applicants, who release all-or-none of their credit report information, and can see it at any point in time. Means it needs to be stored encrypted with their public key. 2. Creditors, who can add, edit, and remove information from someone's credit report. Presumably this adds a way to verify that the addition/edit/deletion is from them and not some other party (sign with private key). 3. Other creditors, who can - with approval - view an applicant's credit report and know it is complete and up-to-date. 4. Arbitrator, who resolves disputes and deletes or corrects inaccurate information from reports. And presumably you'd want some sort of additional safety mechanism to prevent dissemination of the unencrypted result? Like, if you gave an organization an unlock code, maybe it's possible to arrange things such that that organization's private key is able to create legit-looking data, so nobody else could trust third-party sharing of credit report data?
- typomatic 9y agoThis is nonsensical--your interactions with other entities belong to them just as much as you. Chase gets to talk about their experience with you just as you may talk about your experience with Chase.
- CaptSpify 9y agoI never said they couldn't. But they don't need my personal, non-public info to do that. And if the interaction does also belong to them, why don't I get access to their data?