3 ms·
Excellent UIs for shrink wrap software. I think we can agree that the UI for Netflix or YouTube depends on content recommendation in ways that shrink wrap softw
by TimPC 4y ago
Excellent UIs for shrink wrap software. I think we can agree that the UI for Netflix or YouTube depends on content recommendation in ways that shrink wrap software doesn't. One person's engagement (addiction, triggering, controversy) is another person's usability. If YouTube is going to recommend entirely Fox News videos to an apolitical user it's not going to provide a good interface. Even search is hard to do properly without data. How is YouTube useful if it can't do recommendations and you can't search it?
- api 4y ago> I think we can agree that the UI for Netflix or YouTube depends on content recommendation in ways that shrink wrap software doesn't. I can imagine a lot of interfaces for sites like that which do not require personalized feedback at all. In fact, a rich search feature allowing me to say what I want to find would usually be preferable to an opaque recommendation engine designed to steer me toward content the site wants me to visit.
- TimPC 4y agoSure, but how do you build a rich search feature if you are unable to extract features from the private content?
- api 4y agoThe idea the OP put forward is a database that allows "blind" searches. So I could, for example, search for articles between dates X and Y without revealing X or Y or the content or actual date of any article. The results of the search would be encrypted. There is disagreement in the cryptography community about the extent to which this is actually possible. I've seen a few proofs that the obvious "magic" version of this where you can directly but blindly search is impossible because you could use search criteria to reconstruct the content, but that only rules out the most obvious implementation strategies. There's a lot of research going on with this kind of thing in the cryptographic community that involves leveraging zero knowledge proofs, homomorphic encryption, and so on. Nothing practical enough to make anything like a blind SQL database though. In any case I was arguing against the claim that this would preclude good UI/UX design if it were in fact possible.
- TimPC 4y agoMost search in modern projects isn’t things like date ranges though it’s often things like machine learnt mappings that identify similarity scores with words. Failing that it’s some sort of ML to learn tags and keyword matching on those tags. When I search YouTube I’m seldom looking for all videos made on August 29th. I might instead be looking for videos of a black cat. Or videos containing music with certain lyrics that I search for. This is what I thought you meant by rich search. I contend it’s unlikely you can design a privacy respecting service that can also extract the features necessary to train a search model.
- Comevius 4y agoYoutube or Netflix content that's publicly shared would not have privacy protections aside from encryption in transit. The same goes for Facebook content that's publicly shared. But running a service like Youtube that keeps Google in the dark about what you are watching is not possible. It's not even that content creators would have to upload their content padded and encrypted, and privately share the content with their audiences, but the entire audience would need to privately aquire the content each time. A statistically or computationally secure solution like read-only ORAM is out of question at that scale, well any scale that's larger than a few gigabytes. Anything with a constant overhead would only amount to I downloaded five videos, guess what video did I end up watching? And Google would have a one in five chance to tell, if the requests are random, but over time they could still piece you together since your privacy equals to watching five videos at a time, revisiting videos, visiting popular ones, visiting certain ones at a certain time in a certain order. The client could throw in a few fake requests, but such constant effort would still be defeated.