3 ms·
This is a particularly appropriate link right now, given that the core idea of "saving data and state is something which should be avoided" is seeing a renaissa
by wanderfowl 8y ago
This is a particularly appropriate link right now, given that the core idea of "saving data and state is something which should be avoided" is seeing a renaissance in both privacy-focused circles and in privacy-focused regulatory policies. I love the idea that saving state is to be avoided, and I hope to see it implemented with increasing granularity, both on other people's computers (e.g. web services) and locally.
Remotely, a trend away from "You must create an account to view this cat meme, now enter your date of birth and present a working email address which we'll send a message to" is particularly appealing. And with hosted services, particularly paid ones, I'd love to see privacy policies focused on how little data is kept, rather than how much. I keep hoping that the regulatory or legal or insurance environment will change such that sooner or later, companies will view stored user data as a liability more than an asset, and 'zero knowledge' will be a desirable thing.
Locally, as per-application permissions and sandboxing grows stronger, I can picture a class of applications which would be hard-restricted from saving data between sessions (e.g. the browser, a calculator, a scratch-pad app). Or perhaps, "the only data you can save must be XML, in this plaintext file, so that preferences are saved, but nothing else. Qubes (OP's baby) does this already, but I think a dash of this in existing OSes would be a small step towards big security.
As an aside, in my estimation, Joanna Rutkowska is one of the most compelling computational thinkers today. Although her work tends to be at the most elaborate-threat-focused edge of computing security, reading it, it often feels like she's already running "where the ball is going", and I wouldn't be shocked to find that in 20 years, some of the 'whoa, crazy' things from Qubes or this stateless approach are actually regularly used in mainstream computing. I have no particular threat, and no particular need, and I suspect that many of the programs I use regularly wouldn't work there, but there's a part of me that would love to spend more time in Qubes.