15 ms·
Privacy Is Just the First Step, the Goal Is Data Ownership
- edwardr 8y agoI agree w/ OP. Using cryptography for privacy and data control is a step in the right direction and needs some critical mass behind it for broader adoption. Shameless plug - that is exactly what Tozny provides. An easy way to have end to end crypto with a sharing model that keeps data in control of the original writer.
- dannykwells 8y agoThis is mostly a convoluted metaphor comparing data to apples. Only a single line about a mystical "data locker" type object that would store all of our data in a decentralized way.
- kaxline 8y agoYes, it's imperfect for sure, but I'm trying to get people who don't think about these things to understand how the thefts is analogous to physical items we value. Data has its own unique properties so any physical metaphor or analogy is going to fail pretty quick. Tried to keep it simple to make the point.
- febeling 8y agoThinking out loud here. This ownership analogy isn't working well, because ownership is a concept invented for physical things, whereas data can be copied. We can keep it, and pass it on. We know from copyright how painful it is, to put ownership on digital "things". Did data ownership ever work like that in the physical world? Say we see a person walk by, someplace, at some time: is my sensory impression and memory like data? Is it a privacy intrusion to remember that later? Tell somebody? What would be the equivalent online? (Do we have a private "house" online, and public space?)
- devoply 8y agoYes. It's called copyright and intellectual property. Literally the right to copy.
- palehose 8y agoIf the person who walks by did something memorable and unique then we do own that experience and it very much translates into meaningful data. If I was a witness to a crime happening on the street I can convey that information to the police or media as a witness. Even if it was something silly I witnessed it might make a good story to tell friends about. I own the decision to tell others or not.
- kaxline 8y agoThere are types of situations where I think it gets really blurry and complicated, but I think we need to start with things that we intuitively feel like we own, like DNA, or the 3D map of our face. Then as we move out into grayer territory we can rely on precedent, social norms, or consensus to draw lines where needed.
- max76 8y ago> Did data ownership ever work like that in the physical world? Insider trading is a crime in which someone takes an action based on data they had no right to. (Trading on corporate secrets, or data that belongs to the corporation and not the individual profiting.) If a student finds a copy of the answers to a test, even if the student finds the data in a completely legitimate way, it is considered academically dishonest for the student to take the test after learning this information. In many games learning certain information is considered cheating. For example, in Poker it is cheating to know another players cards expect after a player folds and chooses to show their cards. Until very recently it was illegal to make a copy of "Happy Birthday" in the form of a live performance at restaurants in the United States. Yes, in the real world data has owners and it can be illegal/restricted to provide copies of the data or to perform certain actions with the data.
- febeling 8y agoNice examples, yes. I hope I didn't come across as someone from the if-you-don't-have-anything-to-hide crowd. I do think your conclusion is a bit quick, though. > Yes, in the real world data has owners Things happen in the real world, and people perceive and know it as a consequence. We came to call some of that data (if recorded with machines I guess). We wouldn't think of perceptions in terms of ownership. It just wouldn't work. We don't have a response for intrusion, e.g. If someone catches us in the act, there's just no protocol. We often just pretend it didn't happen, and are embarrassed. You can't unsee it, or punish someone for seeing something private. We can throw them out of our house, if they trespass. But if they see you through the window, what do we do? My point earlier was only: ownership as an analogy for data is not as helpful as some think it is. But if you stick with ownership, you possibly end with making very strict rules around personally identifiable information (PIN), like in Europe. Some of that ends in log files, like IPs. I think that is a bit like walking by and peeking into a shop window. The shop owner might see you too (perception). Why is that the shoppers protected information? I think it's rigid and comes from off analogies. That's not to say some data doesn't need to be private. In the end, when this cultural development is further along the way, we might have very specific rules. Like with books, and movies, which have fair-use rules etc.
- nvahalik 8y ago> What we need is a digital locker that encrypts all our data and stores it for us. Or, alternatively, we we need to simply do what people did for ages before us: buy a couple of hard drives and store this stuff offline. If people want to come see our photos, we can either grab them and email them over or they can come review them at our house. People keep talking the fix for technologies problems is more technology—but sometimes it's actually _less_ technology.
- kaxline 8y agoI agree with you in principle, but then we're giving up the redundancy and safety offered by multiple data centers. The cost also comes down at cloud scale so that you're only paying a few dollars a month instead of large up front purchases. There's also a technical hurtle for the average person. Are they going to manually sync all their data from devices every time?
- nvahalik 8y agoSomewhat. There are (were?) some companies trying to break into a personal cloud (WD MyCloud) and I think companies like Buffalo and Synology are making it a lot easier to spend $500-600 and be able to reasonably protect your data from pretty much everything but fire (though, you can buy hard drives that claim fire protection, too). But at a deeper level, we claim that we want to store and keep all this data but do we need to? Really? I mean, back before digital photos, I took some (but not a lot) physical photos. They were dear to me. Still are. But now I have so many photos that I hardly ever look at them except for maybe a few that I've explicitly put into albums. A lot of them never get used. Perhaps even then we don't really need to protect all of it—if it was important to us then perhaps we really should think about how we'd protect it just like we'd protect those old photo albums that people leave with during hurricanes/flooding.
- kaxline 8y agoMy thinking is that you just don't know what will be important to you in the future. Those photos probably weren't that important to you when they were first taken, but now they are. I would advise that everyone store even the seemingly most trivial piece of data. There could be an algorithm in the future for which that is the missing key. I trust in our inability to predict the future more than our ability to predict it.
- palehose 8y agoEvery comment submitted here is kept by Y Combinator and they own it in the same way facebook or "applebook" would own it, except they don't run ads. But if you were to apply to their accelerator they would use your comments to determine if they want to accept your business idea so there is definitely added value to them of your data being surrendered to them freely.
- the_watcher 8y agoYou don't have to tell them your handle. They ask for it if you'd like, but they'd be bad investors if they declined applications from people who said something like "I'm a lurker and don't have an account"
- icebraining 8y agoThey do run (job) ads for YC companies, there's one in the front page right now.
- danShumway 8y agoIt's been a while since I disagreed this much with a privacy-related article. It's a good reminder to me that the privacy community is reasonably diverse, and that different people can advocate for the same policies for very different reasons. I advocate for privacy a lot, but my end goal definitely isn't data ownership. If anything, I'd like to see IP protections start to go in the opposite direction. I'm not against the idea of copyright as a purely practical invention, but I certainly don't believe anyone has an intrinsic moral right to a monopoly on creative or factual information. So I take some issue with the idea that privacy is just a gateway to something else. To me, privacy and anonymity are the end goal. There's not a secondary, deeper issue behind that. I'm not mad that Facebook is making money off of my information, I'm mad that they were able to get it in the first place. This is important, because when you transition to talking about data ownership as the underlying problem, then you start to lose ground on questions like, "why is it important that the government not be able to track my GPS location anytime they like? What was really wrong with programs like PRISM?" Because Government privacy concerns don't really have anything to do with data ownership.
- williesleg 8y agoWhere do you live?
- stdcli 8y agoIt is true that privacy and data ownership are two separate ideas that are often conflated. I think the user having more control over what happens to their data, empowers them to decide who has access to what, and where they choose to host their data. For gaia hubs, we enable users to host their own data wherever they choose, revoke access to apps writing to their data, to delete data, or keep it and render it to another application whitelisted to interact with their data. A work in progress, but I feel confident Blockstack is on the forefront of pushing this idea of data ownership, while also enabling an authentication protocol that associates an immutable identity with gaia hubs, to enable data privacy as well. The immutable identity being anonymous is debatable depending on how the user chooses to identify themselves, but the authentication protocol enables app developers to choose whether to implement end to end encryption, as some cases might not be needed. The reality is there is a catch22 associated with (someone elses comment) the "simple" solution which is to throw everything on a local hard drive. How do you share data with people care about, or companies you do business with dynamically with high and real time performance this way? We are trying to answer those questions at Blockstack with gaia hubs: https://docs.blockstack.org/storage/overview.html https://docs.blockstack.org/storage/overview.html But I would honestly love to see other ideas similar and learn more about the eco system of people approach data ownership, where data ownership enables users to decide what they want to be private, or not.
- warkdarrior 8y agoThe author mentions at the end that monetization of your own data is the option offered by data ownership. But I am not sure that there is money to be made by an individual. Facebook makes about $25 / user / year. Say there are 100 companies willing to buy your data -- would you sell all of your data (out of your "digital locker") for $2500 / year?
- the_watcher 8y agoIf it's the equivalent of what's already given for free, yes. I'm skeptical that this is remotely plausible, but yes, I would happily accept $2500 for the status quo.
- JustSomeNobody 8y agoAnd once you get that $2500, how much of it would you be willing to give to Facebook in order to user their services because they're now not free.
- criddell 8y ago> Facebook makes about $25 / user / year. This feels outrageous to me. They snoop and spy on every move I make online and off for a measly $25?
- maxwell 8y agoThe goal is to snoop and spy on every move everyone makes online.
- imgabe 8y agoIf I visit a webpage does the fact that I did so belong to me, or the site owner, or both? Clearly, it's a record of my activity, so it should belong to me. But it's also a record of the server's activity, which should belong to the site owner ("Served page X to User at 123.123.123.123 a 4:03 PM EST on April 3, 2019") I don't see an easy way to make a case that they don't have at least partial ownership of it. Location data is a little more clear that it belongs to the user, since you aren't requesting anything from anyone, they are just collecting it, sometimes without telling you. Voice assistants are also complicated. Does the information "Analyzed noise XXX at such such time - determined it was not the word 'Alexa' " belong to the company doing the analysis? After all, you bought it and asked it to listen to you and respond when you said a certain thing.
- JustSomeNobody 8y agoIf my normal route for lunch is down the street to the hotdog stand to get a dog and coke, then into the park to read. Do I own that information? If a friend goes to the hotdog vendor and asks if I'd been by there, when he replies is he giving away my information or his?
- lotsofpulp 8y agoIt’s not one or the other, both parties have the information, and without a prior agreement of confidentiality, there isn’t any reason to expect confidentiality from any party other than common courtesy.
- icebraining 8y ago> without a prior agreement of confidentiality Or a law.
- danShumway 8y agoIn that case, let's talk about a current privacy problem and see if the model OP is advocating helps. One of the ways that Facebook fills out relationship graphs is by reading contacts. Both I and my brother own the information that we're related to each other. Both I and my brother own my phone number (I didn't make him sign a confidentiality agreement when I gave it to him), so outside of the bounds of common courtesy, I can't force him not to tell anyone else. So if my brother decides to let Facebook scan his phone contacts, he's just giving away information that he owns, which is his right to do. But if information ownership under this model doesn't provide any real protection to stop one of Facebook's primary data gathering techniques, then what's the value in it at all? What privacy infringement would this protect me from? If a store that I walk into could still claim ownership of the fact that I walked in and track my movements everywhere with facial recognition, and a website can still log that I visited and track where my mouse moves, and if they have co-ownership of that information, then they can still sell it to whomever they want. A big issue with information ownership is that in order to make it logically scale, it has to be neutered to the point where it's no longer useful.
- jpollock 8y agoWe already tried data ownership, and society rejected it. https://news.ycombinator.com/item?id=19035834 https://news.ycombinator.com/item?id=19035834
- pizzazzaro 8y agoThat was neither "us trying data ownership" or "society rejecting it". That was tech titans smearing each other with feces, trying to dodge responsibility for tracking teenagers as if they (companies) were pedophiles in power. Besides, Apple? Is almost always on the side of themselves as brokers of your data.
- howard941 8y agoAt the other end of the spectrum and perhaps more pragmatic is Grassland https://news.ycombinator.com/item?id=19529921 https://news.ycombinator.com/item?id=19529921
- icebraining 8y agoThe Personal Data Ecosystem has been around for about a decade, based on these concepts: http://pde.cc/ http://pde.cc/
- k__ 8y agoFor some apps remoteStorage could be an interesting solution to this problem. https://remotestorage.io https://remotestorage.io
- icebraining 8y agoNice, I had forgotten about that. Previous discussion: https://news.ycombinator.com/item?id=17297673 https://news.ycombinator.com/item?id=17297673
- dfgert 8y agoProtecting users data is a very hard problem to solve in current tech landscape. There are enormously profitable business build around this and are driving significant portion of economy. Only solution I can see is to build alternative economic model that can thrive while protecting data, otherwise it would be an uphill battle with all tech giants that are going after user data for profit.
- hw 8y agoThis would be great, but for that model to work, the end users themselves would have to pay to have their data protected, when in principle I think most people would argue that their privacy should be protected in the first place. For data protection to work efficiently, there has to be a centralized store of data that's deemed private, with a way to authorize / deauthorize consumers of your data. Of course, with centralization, it paints a big red 'hack me' crosshair. Privacy is already lost. There are already cameras everywhere, be it personal home Nest cams, or surveillance cameras inside grocery stores, or street cameras at traffic lights. The fights now for data protection, IMO, are just feel-good initiatives that aim to provide a false sense of data privacy. Take Facebook for example - they've pledged to protect your privacy, offer data protection tools, a way to export all your data. Before privacy became a huge thing, I'm pretty sure people felt comfortable putting all their photos and data in Facebook due to the trust in them being a large enough company that they should protect your data, right? Same goes with Equifax. Same goes with banks and credit card processors. The burden of data privacy and protection lies more towards the end-user than towards multi-billion dollar companies you entrust your data with. They may provide the tools, but once your information is out there, it's retrievable via various means by bad actors. You can keep guns in your home to protect your family, but if you aren't educated enough to use them properly or if you leave your doors and windows unlocked, it's not going to help. Edit: my case in point - Facebook records found in public Amazon cloud servers [0] [0]: https://www.bloomberg.com/news/articles/2019-04-03/millions-of-facebook-records-found-on-amazon-cloud-servers-ju1hde0w?srnd=premium https://www.bloomberg.com/news/articles/2019-04-03/millions-...
- fixermark 8y agoThe Applebook metaphor in the article breaks down because data is infinitely copyable. It's actually costing less than nothing for this hypothetical "Applebook" to store (copies of) my apples: if there's a disaster back home and my orchard is wrecked, I can partially rebuild from the redundant apples that Applebook has stored. By my calculus, that's a net positive for me.
- PierredeFermat 8y agoMost, if not all, arguments on data ownership are arguments by analogy. This makes them ipso facto invalid. Using that same line of inductive reasoning, we could argue that we own the trash we generate, and that's not a reductio ad absurdum. An encrypted 'digital locker' is a naive and unreal solution, at least until homomorphic encryption is mature. How would I request data I'm interested in from people without knowing if they have it in the first place? Issue a million requests? And if I'm issuing such requests, do people have to pay me now because it's data that I have generated? We are agreeing on the terms and policies of all information services we use and generate data from. It's not like they took us by surprise, except for few Analytica cases of course. If we follow the data ownership argument, which has (re)surfaced mostly due to media attention on FB and the likes, such services will become dysfunctional right away. Privacy isn't the weak argument, it's just not very well enforced yet mostly because most people don't care much. Ideally, if a company wants to sell your data, as part of their ToS/PP, they notify you. If you approve, you get a share of that sale (basically what Nukleosome is doing). If you don't, they just move on.
- criddell 8y ago> We are agreeing on the terms and policies of all information services we use and generate data from. If only that were true.
- PierredeFermat 8y agoHow is it not true?
- chillacy 8y agoTo be charitable, maybe we all click Agree in the same way that we consent to being searched at the airport: there's no other choice, so it's a begrudging accept, not an enthusiastic accept.
- PierredeFermat 8y agoI didn't claim it's an enthusiastic one. My claim is that all the sudden "privacy-is-not-enough" arguments make it seem like some breach happened without our agreement. To use your words, it's almost as if they're complaining about airport security/searches because we were never very explicitly warned about it. If we don't do security checks or don't agree to some ToS, we'll be left out (of flights or online services). How many people would do that in exchange for 'ownership'? Also, if you go to a bakery for couple months buying the same bread. Would you sue the bakery if the seller automatically knew what you're going to get, after two months of transactions, and wrapped your favorite bread for you with a smile (not the Amazon smile)? Is that also data you should own and encrypt? Does your physician need your consent on every visit to unlock your health information in his brain and be able to follow up? Imagine that this comment I'm writing here is locked into my very own encrypted vault and HN needs my consent every time someone wants to read it (although I used HN to write it!). I cannot imagine how would the discourse evolve this way. So justifying 'ownership' as the future solution using invalid argumentation by analogy isn't solid. A more solid approach is to actually build products with well-enforced privacy and transparency rather than just theorize about it. Or even build and experiment with the 'ownership' proposition and see how would that play out.
- just_one_time_ 8y agoBlockchain is the only way to do this.
- jerf 8y agoI'd say the primary problem with this argument on its own terms is that one of the natural questions to ask is "OK, then, how much are these companies stealing from me?" and the answer is roughly "At the upper end, probably on the order of $10/month". That's going to be hard to build a social movement around. I could argue that if we were being paid a fair price, it would be worth more, but that's a chicken & egg problem; until we have such a free market, we can't really know what will happen with enough confidence to make a strong argument that we need a market of some sort. The real problem with all this surveillance isn't the direct impact to me, it's the impact to society. It merely turns it into a sick joke that my social order is being upended and social contracts rewritten for an amount of money I'd happily hand to them to just... not. (I mean, that has it's own issues if it actually came to be, but in its current form, yes, I'd happily pay $10/month in hard cash for them to just leave me entirely alone.) In the long term, I'm much more concerned about the fact that knowledge is power. I don't particularly look forward to the era of "SELECT name, current_location FROM citizens WHERE dissidence_level >= .6 ORDER BY dissidence_level DESC". But until that happens, to a much greater extent than it has, and it visibly manifests in the real world, it's going to be hard to get people to care, until it happens and it's too late. What really scares me is idea that the reason why it hasn't happened yet is precisely that the people who want to do that are deliberately waiting until it would be too late.
- floe 8y agoYes, you hit the nail on the head! The societal impacts have to be considered. If you rely on each person to rationally decide whether or not to sell 'their own' data, you'll have a tragedy of the commons situation. Maybe we will see a health insurance company that costs half as much as the rest, but to apply you have to give them all your social data and they run "CREATE TABLE rejected_applicants AS SELECT name, id FROM insurance_applicants WHERE health_risk_level >= .7". All the healthy people will rationally sell their data and try to join this company, and all the other companies will have sicker pools and have to double their prices. For a person who couldn't get accepted into the cheaper company, the fact that they can sell their own data is cold comfort. Privacy harms will always fall disproportionately on the marginalized: the poor, the sick, dissidents, and minorities. The framework of 'data ownership' can never make these harms right because it fails to recognize that half the people selling their data often hurts the other half.
- kkomaz 8y agoThis is exactly what we're trying to solve with debut. (https://landing.debutapp.social https://landing.debutapp.social) The underlying technology uses blockstack where users own their own data and information is not stored in a central database. Beyond data ownership, the future goal is to add a layer of security around your information through encryption. Only user approved parties could access your secured data through a private key.
- naringas 8y agodigital data is not at all like apples which exists as physical objects. this issue is far more nunanced.
- nocturnial 8y agoSuppose what everyone is saying is true: "We pay for the services companies provides us with our data". Normally, depending in which jurisdiction you're in, you could get your money back for "bad" service. If someone still wants to use our data as a service payment, how do you propose we get our data back for bad service?
- scarejunba 8y agoYou can ask them to delete it. If you tell me a story and I sing you a song in exchange, neither of us can "take back" the thing we did for bad service. But we've bartered (and hence paid for the experience). That's just life. You can't take away an experience. So you can take away the data but you can't take away the fact that they had the data.
- nocturnial 8y ago> So you can take away the data but you can't take away the fact that they had the data. I know and that's my point why it can't be considered as a payment.
- scarejunba 8y agoMost people would consider that payment, actually. The exchange there would be barter of experiences.
- sunshinelackof 8y agoIndividual ownership of data doesn't solve the problem because there's an inherently unequal relationship between the data's owner and the data's consumer. The consumer whether public or private has limited use for an individual data point and is really interested in the collective sum of individuals' data. We see this unequal relationship in plenty of other domains and it always collapses into giving into the demands of the larger entity just for the privilege to participate. What really would make more sense is the collective ownership of data. Allow for data owners the power to form a body to collectively bargain with entities that want access to their data.
- troymc 8y agoYes, and the legal frameworks for people to pool their data and _license the pool_ are now being explored. One such framework is the so-called "data trust" (trust as in legal entity).
- kaxline 8y agoYes, I've been thinking about this. I still think the focus should be on individual ownership, because then that individual could opt-in to a bundled data purchase. Their cut would be small, but maybe it's automated so you get a lot of small payments without doing anything. I think you need to leave the door open for an individual's data having stand alone value though, like a unique mutation in their genes that cures cancer.
- chillacy 8y agoHow much do most people collect from class action suits they get bundled into? Vs how much do the lawyers make?
- deleted 8y ago[deleted]
- deleted 8y ago[deleted]
- sgt101 8y agopoor people will have to sell. rich people won't. poor people will have to sell cheap. Anne Frank didn't think that she had anything to hide. Anne Frank didn't have anything to hide. Anne Frank got killed. Why? Because Anne Frank's parents disclosed their religion to the Dutch census. The Dutch government was benevolent, liberal. Bigotry was rare in Holland. Then Nazi's. This can happen to you. Anne was a child. This can happen to children. Privacy, for privacy's sake, is one of the strongest arguments that I have ever come across.
- obelos 8y agoThe analogy used in this article is too ill-fitting to find compelling. It does prompt me to wonder to what extent a person's digital traces left upon the world could be construed as a creative output that they own as a form of intellectual property, like a form of artistic expression. That analogy too seems tortured, unless possibly you're Nietzsche. But it seems less ill-suited than trying to compare one's data traces to a material good.
- soheil 8y agoOwnership is an odd concept to apply to something like data, I don't have a problem specifically with ownership of data as much as I have a problem with statements of form applying X to Y where that relationship previously did not exist. To take it for granted that there should not be a debate about the possibility and the implications of such relationship and just presume the existence of it seems odd to me.
- p4bl0 8y agoIt's a relief to see that the top-voted comments already disagree with this article. I disagree so much however that I need to voice it, I can't just upvote others. So, here it goes: Nope, nope nope nope. Personal data property is a bad idea. And it probably does not come from people who actually care about privacy. It is an ideological push towards more and more privatization and "free market" economy. Think of it for a minute. If personal data protection is based on private property that you can sell or rent, it means that rich people get a right to privacy, while others will necessarily rent or sell their data so they can pay for rent or feed their kids. It means power over personal data belongs with money. That's not what anyone actually fighting for the right to privacy actually wants. Now, people should have control over their personal data, that's a fact. But control means rights, it does not mean that a notion of property is necessary (or maybe a loosely derived notion, like something resembling moral rights [1], in addition to control). It also means regulation of data controllers and data processors. The fight for actual privacy is not the fight for ownership, it's the fight for control. For those who, rightly, think that "control" is a vague term: it was, but it has been properly defined [2], and more recently formally modeled [3] (disclaimer: I'm one of the author of the latter article). [1] https://en.m.wikipedia.org/wiki/Moral_rights https://en.m.wikipedia.org/wiki/Moral_rights [2] https://script-ed.org/article/control-over-personal-data-true-remedy-or-fairy-tale/ https://script-ed.org/article/control-over-personal-data-tru... [3] https://pablo.rauzy.name/research/publications/lemetayer2018capacity.pdf https://pablo.rauzy.name/research/publications/lemetayer2018...
- mcrad 8y agoNo. The "ownership" goal should be within the company. Does Legal own it? Does so-called Product own it? Does Engineering own it? Data Science? Ad clients? Without better governance, you will have misuse. And at some point you have to ask yourself(Zuck), is poor governance on data ownership a bug or a feature?
- pauloppenheim 8y agoThe article presents an economic model of privacy. While I think that is important (and part of the argument for the indieweb - https://indieweb.org/ https://indieweb.org/ ) there are more arguments to be made about privacy, including not only the individual, but also collective harms that the violation of privacy can impact. That argument is challenging to make, because harm changes depending not only on the individual or group and their reason to need privacy, but also on the type of information gathered, and the possible uses of it, which change over time. That kind of shape-shifting argument is challenging to get across, so I can appreciate something simpler. However, when I hear the framing of this as "the problem" I feel nervous, because I hear that as reducing consideration of other possibilities.
- godelski 8y agoI still find it shocking that many people in society quote what originates from dystopian propaganda. The phrase "You have nothing to fear if you have nothing to hide." is commonly attributed to Goebbels, because he popularized it. Though there's an earlier precedent[0], it is also a dystopian reference. So I think there's something wrong when people are quoting literal Nazi propaganda, and having that belief ingrained. [0] https://english.stackexchange.com/questions/217196/origin-of-you-have-nothing-to-fear-if-you-have-nothing-to-hide https://english.stackexchange.com/questions/217196/origin-of...
- nobrains 8y agoThe solution, as I imagine it, is the following: 1. data for web apps should be stored separate from the servers as the code. 2. this separate data store should be owned by the user (not the provider of the web app). 3. user should be able to point the web app to another datastore if needed. so, for example, if you user basecamp for project management. basecamp should be designed so that all data writes happen to a separate database or datafile. the data that i enter in web app (basecamp) should never be stored on basecamp servers. at setup i should be asked for a data store location (that I pay for and manage). ofcourse, for non-privacy consicous customers, the existing status quo option can also be provided.
- brisky 8y agoCheck out blockstack, they solved this in similar way like you described
- mirimir 8y agoTFA lost me in the lead: > As soon as you connect to the internet, there is a vast surveillance infrastructure tracking your every move. Even the most hackery of hackers have trouble moving in complete anonymity. > For most of us, however, our brains assume our pre-internet intuitions are still accurate. That what we do in our own home stays private until we decide otherwise. We feel violated when we discover how much is known about our online activity. I am not -- in an meaningful sense -- a "hacker". I'm a reasonably technical guy. And I know how to use a bunch of tools. But "hacker"? No way. So, my first point. Assuming that "what we do in our own home stays private until we decide otherwise" is foolish. Unless you include implementing strong OPSEC in "decide otherwise". And second, you need not be a "hacker" to avoid surveillance. You just need to learn some OPSEC, and how to use a few simple tools. The core point is never communicating (saying, writing, imaging, etc) anything without a studied awareness of who might be observing. I have a few Internet-facing machines. One is plain-vanilla. Just a box with basic apps, sitting behind a pfSense firewall. But of course, with no WiFi. The others, each on its own LAN, run VirtualBox, and host various VMs. There are some low-security VMs, which reach the Internet through nested VPN chains. Which are implemented with pfSense VMs as VPN gateways. That's what Mirimir, and some of his sub-personas, use. They basically just talk about stuff. And do some consulting work. But nothing at all iffy. Then there are a bunch of Whonix instances, which reach Tor through those nested VPN chains. That's where I do whatever interests me, with no concerns about consequences. All of these machines are full-disk encrypted. And they're on a UPS, with a kill switches on my desk, and in the kitchen and bathroom. Although I mainly focus on being hard to find, I am prepared for discovery. I'm not prepared, I admit, for sitting in prison, after refusing to reveal decryption passphrases. I'll probably claim ministroke and memory loss, but that damn iffy. And then there's my physical workspace. It's basically a walk-in closet. My desk faces the door, and there's a wall behind me. There are no windows. I painted all of the interior surfaces myself, using black EMF-blocking paint (carbon plus Al dust). For the wall behind me, I applied a series of bright washes, using custom-mixed colors. It's locked when I'm not using it. And I live in a multifamily building, in a very cohesive community. So there's very little chance that adversaries could secretly plant bugs. They'd need to enroll or compromise one of my neighbors. That's not impossible, I know. But hey. Anyway, my point is just that you need to keep in mind, always, that adversaries are trying to snoop. And act accordingly.
- ajit283 8y agoTheoretically, we have all the measures in place the article described. We do sell our data - simply not for money, but for services, e.g. FB. The digital locker is actually called data privacy rights. Companies do need to ask you directly, in form of the privacy policy when you sign up to the services. The flaws of the current privacy situation lie in the execution in practice. In theory, everything is fine.
- kaxline 8y agoYes, but there's something about the lack of knowledge on the part of many software users that makes the consent portion debatable. That, and there's no other way to pay to use a service that you want to use.
- thatoneuser 8y agoWow everyone on here defending tech giants owning their personal data. Is this Facebook trolls working their propaganda? What exactly do we stand to lose if Facebook can't aggregate data on a level akin to a hyper advanced dystopiam government? Are we worried out advertisements will become less funny? Are we worries well be less manipulable on a mass scale? Are we worried well have options on our tech overlords instead of being stuck with 4? Its my data and I should own it. Just like I can't login to Facebooks servers and take their data. The only thing that separates Facebook from having privacy and the user is Facebook has billions of dollars of leverage. But hey if yall like billionaires owning you then let's keep it up - let's not say we own what's ours. Make the billionaires even stronger.
- syrrim 8y ago>Its my data and I should own it. Then don't give it to them. >Is this Facebook trolls I personally don't use facebook, and don't advocate for others to use facebook. If you do use facebook, then you are accepting the deal they have offered you. >What exactly do we stand to lose if Facebook can't aggregate data on a level akin to a hyper advanced dystopiam government? This is how facebook makes money, and stronger how they survive as a platform. If they couldn't do this, then more then likely we would lose facebook. I personally don't see this as such a huge loss, but apparently you do.
- PeterisP 8y agoOne of the major complaints about Facebook is their tracking of non-users, of people who haven't accepted any 'deal' nor given them any data - e.g. Facebook is known to do matching of non-users full name with phone numbers and other contact information based on what other people have in their phone contacts, combined with tracking their visits on third-party websites which embed e.g. facebook like buttons. There are ongoing court cases proving such practices, and Facebook insisting in court that it should be allowed to continue to violate privacy even for people who, like you, have intentionally chosen to avoid Facebook.
- thatoneuser 8y agoAs has been explained so many times including my message, you can't opt out. Data collection is beyond that. They take it without you doing anything. It doesn't go away because you ignore it.
- amaradiaga 8y agoData ownership is the goal behind Solid (Inrupt) https://solid.mit.edu/ https://solid.mit.edu/ - project led by Sir Tim Berners-Lee. From the website: Users should have the freedom to choose where their data resides and who is allowed to access it.
- lanevorockz 8y agoPrivacy is nothing more that be allowed individuality. What google and facebook do is to steal your identity and everything that it means to be you. They can then normalise your personality through algorithms, erasing whatever is left of you.
- SimonWeeks 8y agoHi Keith, have a look at https://mysafe.io https://mysafe.io and business.mysafe.io We are the first privacy and data protection ecosystem - With data and infrastructure owned by data subjects. Keen to get your thoughts.
- stackzero 8y agoOne of the big challenges with data ownership is policing it. If I grant one-time access to my data to some company, the company can store the data and use it many times over, potentially distribute it etc. I can see this working for datasets like website interactions or search history which companies could pay a subscription for and receive periodic updates which would be of continued value.
- SlackwareMan 8y agoWell, I have been in the hacker scene since like 1997 and it's ethos has always been about free information and secondarily about anonymity. Hence, data as privacy is a no go. What is going to happen is what Julian Assange outlined in his book "Freedom and the Future of the Internet" lays out. The article lays out that even the hackery of the hackers are having a hard time. I don't what the hell he is talking about. A hard time like a hard time in not eating a chocolate cookie of convenience lays out but nothing more. Elite hackers will always have privacy and it will not always be glorious. It is the masses who think the hackers will save them who are delusional.
- SlackwareMan 8y agoWell, I have been in the hacker scene since like 1997 and it's ethos has always been about free information and secondarily about anonymity. Hence, data as privacy is a no go. What is going to happen is what Julian Assange outlined in his book "Freedom and the Future of the Internet" lays out. The article lays out that even the hackery of the hackers are having a hard time. I don't know what the hell he is talking about. A hard time like a hard time in not eating a chocolate cookie of convenience lays out but nothing more. Elite hackers will always have privacy and it will not always be glorious. It is the masses who think the hackers will save them who are delusional. Annendum : I think some hackers will pick and choose when to be anonymous and others will be 100% of the time. I am the former. Sorry, for the repost I had to edit it for lucidity.
- SlackwareMan 8y agoWell, I have been in the hacker scene since like 1997 and it's ethos has always been about free information and secondarily about anonymity. Hence, data as ownership privacy is a no go. What is going to happen is what Julian Assange outlined in his book "Freedom and the Future of the Internet" lays out. The article lays out that even the hackery of the hackers are having a hard time. I don't know what the hell he is talking about. A hard time like a hard time in not eating a chocolate cookie of convenience lays out but nothing more. Elite hackers will always have privacy and it will not always be glorious. It is the masses who think the hackers will save them who are delusional. Annendum : I think some hackers will pick and choose when to be anonymous and others will be 100% of the time. I am the former. Sorry, for the repost I had to edit it for lucidity.
- YeGoblynQueenne 8y ago>> Privacy for privacy's sake is a weak argument, and privacy advocates should abandon it. But, why? Why is it that "privacy for privacy's sake is a weak argument"? Why is it so hard to find a way to respect peoples' wishes to avoid doing things that offend their dignity? What is that great need to spy on everyone that is so indispensible to the progress of human civilisation that this strong concern of many people must be brushed aside as "a weak argument", an irrelevant and obsolete affectation that can just be ignored? And who is making an argument in the first place? Is anyone arguing for or against the need for dignity in the last days of one's life? Is anyone arguing for or against the need to respect bereavement? Arguments exist for and against the limits of such things, but not their actual need. We need to be able to live our lives with dignity and worth, else our lives are meaningless, we are in constant conflict with everyone around us and the peaceful coexistence and collaboration that supports human societies goes to hell in a hand cart. This is what tech companies have to understand: you can't just take a big, smelly dump on peoples' sensibilities and not face consequences just because you have "arguments".