9 ms·
Agreed, we still have the right to avoid having one's identity stolen, to take action toward making that more difficult, to protect our one real name IRL. Pare
by dbtx 7y ago
Agreed, we still have the right to avoid having one's identity stolen, to take action toward making that more difficult, to protect our one real name IRL.
Parent: if you s/driver's license/credit card & CVV visible/, does your position change? It's "just another picture of a thing."
- danShumway 7y agoGood question. As a practical example, I am skeptical that Todd Davis should be able to force Wired to take down his social security number[0]. I am also skeptical that people should be able to demand that HaveIBeenPwned remove their information from a database. On social security numbers or IDs, I am definitely more open to discussing limits to the Right to Remember if they're very narrow and very rigidly defined, in the same way that I'm OK with exceptions to Freedom of Speech that are narrow and rigidly defined. However, I want to posit that if infrastructure around identity verification is broken, we should focus on fixing the infrastructure, not curtailing rights as a band-aide. Identity theft is rampant because our identity metrics are horrible. Social security numbers are a joke. Credit card numbers are a joke; the only reason that system works is because banks are willing to reverse charges whenever identity theft happens. These are bad systems, but instead of forcing companies to fix them, we restrict user rights to make it easier to have some semblance of pseudo-security. This same principle has come up in a few other places on this page, particularly with the Right to Filter, and whether that should allow a monopoly communication platform to circumvent the Right to Communicate. My take on that is similar: this sounds like an infrastructure problem. We wouldn't have an issue there if we didn't allow a private company to have a monopoly over communication online. To me, it feels like people are attacking the wrong problem. It's also important to remember that the Right to Be Forgotten is separate from GDPR. Where GDPR (arguably) is narrow and allows you to demand that a subset of companies delete specific PII, the Right to Be Forgotten is broad, and allows you to make demands regarding general information and your reputation. I have some issues with GDPR as it's implemented today, and I won't go out of my way to endorse it, but I also won't take a strong stance that GDPR is incompatible with the Right to Remember. Readers can draw their own conclusions, but on GDPR, I'm neutral. But I do take a hard stance on the Right to Be Forgotten. There's a difference between talking about edge-cases with IDs in a private, purely corporate database, and talking about deindexing news articles. [0]: https://www.wired.com/2010/05/lifelock-identity-theft/ https://www.wired.com/2010/05/lifelock-identity-theft/
- michaelmrose 7y agoSSN as proof of identity is stupid. Any time proof of identity requires you to share all information needed for the party to impersonate you to other parties you know that you have fucked up and undermined the purpose of such proof. It a sane universe you simply share proof of your secret and we move on to discussing policies regarding data about you instead of data you have a direct interest in controlling.