3 ms·
This is buying into the idea that security and openness are at odds. Bitcoin is extremely secure, and also open to all. The way forward is people owning all the
by ericflo 9y ago
This is buying into the idea that security and openness are at odds. Bitcoin is extremely secure, and also open to all. The way forward is people owning all their data encrypted, and revealing zero knowledge proofs about that data to services that want access.
- ot 9y ago> Bitcoin is extremely secure, and also open to all. And it has zero privacy: everybody can see everybody's transactions.
- ericflo 9y agoThat's because privacy was not a goal of that particular system. Pseudo-anonymity was the goal. (That's unrelated to my point about security and openness though.)
- nl 9y agoIt seems pretty related in this case, since the kind of security that is being discussed here is around access to private data (and I'd note that it was you that used the word security here, not the OP who made the more correct contrast between openness and powerfulness). One could equally make the point that Facebook is secure because no one has hacked their servers, and that it is open because it is free to join. That's a pointless thing to say though. But in any case: yes, there is an inherent tension between privacy and openness.
- ericflo 9y agoI should have used Monero as an example instead of Bitcoin, but I thought less people would have heard of it. Privacy can also be achieved with these primitives.
- nl 9y agoThat's still not the point though. How do I openly share social information with some people without sharing it with everyone? These principles are in conflict. I did some work way back when FB got popular on the idea of using probabilistic data structures (ie, Bloom filters) to store contact lists, which could then be shared so that (in theory) only people who knew the same people would also know that they knew them. I built a FB app proving this could work technically. But there are clear security issues with it - it gives a veneer of apparent privacy but doesn't stand up to attacks. This is what everyone is talking about and the point you seem to be missing: you can't have this both ways. There is a conflict between privacy and openness. Since you seem fixated on the crypto-payment thing: Monero mostly solves anonymous payments, but then what? Say I want to buy a pair of shoes with it - how do I stop someone knowing where to deliver it? Any attempt at solving this runs into the same problem: you have to tell someone the same thing you are trying to keep secret, and if that person is the attacker then the system falls to pieces.
- ericflo 9y agoWe've accepted trusted computing as a society, many phones have a secure element now, and I think this can migrate down to that level. That's the real trade-off: we reclaim ownership of our data with knowledge of where it goes and who's using it for what, but that means a full embrace of DRM (something our community has typically been against.)
- nl 9y agoI'll take that as implicit acknowledgement that the OP's point was correct (DRM of course being the complete opposite of "open"). I agree that could work though.
- rrdharan 9y ago> I should have used Monero as an example instead of Bitcoin, but I thought less people would have heard of it. Privacy can also be achieved with these primitives. Well actually that’s very much still in dispute: https://www.wired.com/story/monero-privacy/ https://www.wired.com/story/monero-privacy/
- fiddlerwoaroof 9y agoThe Facebook API is, now at least, a capabilities based system where you ask the user for permission to access various bits of information. The major problem these days is that people don’t read through the authorization dialogs because they want to see which Star Wars character they are.
- ericflo 9y agoTo my knowledge, you're not able to reveal just your first name, or just a proof that you're a FB verified user. And once you grant access, it's forever. We may be at a global maximum for user permissions, but I doubt it. The problem is we can't try anything new - since it's all stored in FB's servers, we have to wait for them to build new granular capabilities.
- ethbro 9y agoThe truth is that Facebook engineering & UX has been either incompetent (incredibly unlikely given the caliber of people they have) or willfully / inadvertently avoiding clearly communicating to users what permissions apps need. The thought that they can't "do better" than dialogs / strings identifying each permission is laughable. It's not rocket science.
- munificent 9y ago> The way forward is people owning all their data encrypted, and revealing zero knowledge proofs about that data to services that want access. Who has a financial incentive to build and maintain that system?
- ericflo 9y agoCryptocurrency projects.
- alexbeloi 9y agoYou're using "open" in different contexts, one applying to a platform (e.g. blockchain or facebook app api) and another in regards to access control. As platforms, blockchain is more open than facebook and for access control it's less open. GP was referring to security being at odds with openness in the sense of access control.
- matheusmoreira 9y ago>open to all That's in direct opposition to security. When you grant people you don't even know much less trust access to your system, all bets are off. There's just no way to predict what is going to happen. You've lost the fundamental protection afforded by trust. Today, computers are expected to be able to talk to and serve hundreds of thousands of random users. What if one of them has access to a 0day? They could own the machine. The world would be a lot more secure if servers dropped all incoming packets by default and talked to trusted users only. Bitcoin is open to everyone and that's great, but it doesn't change the fact people managed to sneak a bunch of illegal pictures into its blockchain.