3 ms·
I have also pondered on variations of this idea of users _owning_ their own data and only granting access to their data to apps they trust, as a means to counte
by ss3000 7y ago
I have also pondered on variations of this idea of users _owning_ their own data and only granting access to their data to apps they trust, as a means to counter the status quo of every company holding users' data hostage in their own walled gardens and preventing data mobility between apps.
However, the one thing that I've always struggled with is how to handle apps that need write access to users' data in order to be useful. For instance, a messaging app needs to be able to write new messages onto the user-owned data store, but if we allow arbitrary reads/writes to some namespaced path to the store, an app simply needs to encrypt the data with some secret key that the user doesn't know in order to build a decentralized walled garden that stifles data mobility in the same way that centralized walled gardens do today.
- baroffoos 7y agoSometimes problems are better solved legally rather than technically. You could spend all year thinking of a way to prevent this or you could just have a law that states that users must have access to machine readable copies of all the data you collect about them. To a computer there is very little you can do to distinguish between obfuscated and regular data but to a human/legal system the difference is clear.
- gremlinsinc 7y agothe app would have rights to clone data locally, however certain 'fields' would source content via key from source of truth... for instance username/profile name... so that if you revoke key the content remains but the username/name on account would be redacted...similar to how reddit has content w/ a deleted_user...