3 ms·
(off topic, but this report is a good example of how to handle user data) > anonymized Could we, perhaps, stop using this word? Instead of using the vague, of
by pdkl95 5y ago
(off topic, but this report is a good example of how to handle user data)
> anonymized
Could we, perhaps, stop using this word? Instead of using the vague, often misleading term "anonymized", state directly what actually happened, e.g. "names and addresses were removed", "user data was aggregated by ${group}", or "the UID was replaced with a new, equivalent key". Most of the time claims about data being "anonymized" are simply not true; replacing names or UIDs with a hashed value that is merely replacing an existing candidate key with a new synthetic key. As DJB said[1]:
>> Hashing is magic crypto pixie-dust, which takes personally identifiable information and makes it incomprehensible to the marketing department. When a marketing person looks at random letters and numbers they have no idea what it means. They can't imagine that anybody could possibly understand the information, reverse the hash, correlate the hashes, track them, save them, record them.
The rare examples where "anonymized" actually involves meaningfully making user data anonymous are when the actual user-correlated relations[2] have been destroyed. This report specifically discusses how this was done:
> If a sentence fragment appeared in less than 10 unique adventures, it was discarded from the result set to preserve anonymity.
Sometimes this required accepting a small amount of error:
> this data needed to be processed in batches of around 10000 adventures per batch. In each batch, fragments appearing only once were purged. Therefore, counts under around 25 are actually underestimates.
[1] https://projectbullrun.org/surveillance/2015/video-2015.html#bernstein https://projectbullrun.org/surveillance/2015/video-2015.html...
[2] https://en.wikipedia.org/wiki/Relation_%28database%29 https://en.wikipedia.org/wiki/Relation_%28database%29
- seqwbnukmupxouf 5y agoYou are correct, this word is hugely misleading. I once ran an audit of a major VPN provider who claimed they did not store IPs or in fact any personal data on their users in their marketing material. In fact, their technical justification for this was merely swapping one unique key out for another. When asked to trace a persons connection and identity, a randomly selected engineer on their data science team did it within a few minutes. The fact that they had a data science team when they purported not to collect user data was baffling to me.
- pdkl95 5y ago> claimed they did not store IPs ... on their users "We don't store IPs in the 'users' table." > merely swapping one unique key out for another. "We store them in another table* with a synthetic primary key." Maybe "we don't storing personal data" is how you say "third normal form" in the marketing dialect?