20 ms·
Two types of privacy
- atoav 4y agoTracking evasion is close to the concept we in Germany call "Datensparsamkeit" or data scarcity — the idea that only the data that needs to be collected for a certain purpose should be collected. The idea is: Data that just isn't there cannot be lost, abused or stolen. Or phrased differently: Data is also a liability for you and your users and you should balance this liability with the use it has for you. The idea comes from Germany's Nazi past, when the Nazis invaded the Netherlands where religion was a field in the official documents, which lead to an very efficient genocide.
- _carbyau_ 4y agoThis is one thing I came away from Germany with. Germans today don't hide what happened - the better to learn from it. In this regard to data, the rest of the world seems intent on repeating their mistake. Hopefully to a lesser degree but only time will tell.
- n0n 4y ago"[...]data is a toxic asset and saving it is dangerous." https://www.schneier.com/blog/archives/2016/03/data_is_a_toxic.html https://www.schneier.com/blog/archives/2016/03/data_is_a_tox...
- 4oh9do 4y ago> the idea that only the data that needs to be collected for a certain purpose should be collected. The US has a similar stature, the Paperwork Reduction Act, a "law governing how federal agencies collect information from the American public", with the aim being to "not overwhelm [the public] with unnecessary or duplicative requests for information" and that the data collected be "a good fit for its proposed use" and further still "To respect privacy, we avoid asking for personal information that’s not relevant or necessary." https://pra.digital.gov/about/ https://pra.digital.gov/about/ In practice, of course, this is all bullshit and any data that the government cares to collect is rationalized as fitting all those requirements. So I'm curious if the German Datensprsamkeit is actually effective?
- atoav 4y agoIn my (university IT) circles it is definitely part of the lived culture. IT sees itself as the ally of the users and not a data collector for the management. The management mostly agrees with the principle of data scarcity as well. I recall one instance where the highest person at a university tried to get all the user's contact tracing data because of some incident (theft), IT explained that their request was not only illegal, but also useless, because the way data was stored would not allow to extract data without going to another official place and requesting the other half of the data which could only be accessed by the health department. There is a german saying that goes a bit like: "where there is a feeding trough there are pigs". The idea of data scarcity is to avoid putting up things that can be used as food by pigs. So instead of defending data silos, you build them in a way that they don't become targets in the first place because they are of limited use outside of the intended use case. Judging by the number of politicians complaining about data privacy, it works.
- 9dev 4y agoWell... I suspect German Datensparsamkeit is only a figment of the utterly ridiculous digital infrastructure of the german governments, both federal and state ones. Most processes are still carried out via paper or fax (fax!), you have to show up personally for the most insignificant things, every single village has their own records (practically never digital), and every time the government attempts to make a stab towards more digitalisation, big corps waste billions on giant projects that never get finished - we had the attempt to get health insurance (mandatory here) cards with an NFC chip on them that would securely store medical records and grant online access to your data; finally, no more carrying X-Ray CDs from MD to MD or filling out registration forms at the doc. But of course, 10 years later, everyone has a new card, but you can't do anything with it. Someone has earned a lot with it though. So, all in all, it's not that Germany's government is so privacy conscious, but we're simply stuck in a pre-digital world with no reasonable way to share data.
- nicbou 4y agoGermany asks for your religion during your address registration, to collect church tax. It's one of the first forms you'll fill after moving to Germany. However, this is largely correct. German offices don't even talk to each other without your consent. It can be frustrating at times. Germany also has some of the strongest photography laws I know of. You have a certain expectation of privacy even in public.
- rawbot 4y agoAnd they start charging you without telling you directly (by a letter) or getting your consent! First thing I tell everyone moving here is that they should be careful with that form and be atheists officially. I ended up paying 4 years of tax before they relaxed the process.
- stavros 4y agoBut when the New Crusades begin again, guess who'll be the first to go!
- marcosdumay 4y agoThere are a few centuries of history telling you what are safe options to put there and what aren't. They won't come for atheists first.
- tut-urut-utut 4y agoI don't want to be a devils advocate, but why is it a problem that you paid a church tax? In Germany, members of the church pay for the church service, it is made available to them by the church. It's just how it is, you pay the tax, and then you can marry for free, attend church for free, baptise your children free of charge, ... If you don't want to use or don't need their services, you can always cancel your church membership. It costs one visit to Bürgeramt and a few euros. I am sick of people staying in church and complaining that they should not pay. Before church tax, everyone had to pay through taxes, even people that are not members of catholic or evangelical church, like atheists and members of other confessions. That is immoral. Either pay or leave the church if it is not worth it for you to pay.
- bheadmaster 4y ago> The idea comes from Germany's Nazi past, when the Nazis invaded the Netherlands where religion was a field in the official documents, which lead to an very efficient genocide. I am very afraid that a similar thing could happen in the modern world. The Great Surveillance Machine is just a ticking time-bomb, waiting for the right tyrant to use it to enforce their own idea of Good. Whatever characteristic they want to cleanse out of society, they can easily track down people with that characteristic, and neutralize them. And when that happens, there will be nothing we can do to save ourselves, because we have already surrendered our whole lives to The Machine.
- Agamus 4y agoCould happen? Isn't this what is already happening in totalitarian countries?
- paskozdilar 4y agoPerhaps, but I didn't want to claim anything without proof. If you have any proof, please post here, so I may use it in future arguments.
- deleted 4y ago[deleted]
- atulsnj 4y agoI always thought that since I opted for DO NOT TRACK I am not being tracked, now that it is a fingerprinting vector, it feels like being duped, and BTW if WebKit removed it then why not Firefox, I mean is there any good reason to have it anymore?.
- the_dege 4y agoSome analytics software respect DNT headers, like Matomo by default [0] so it might still be useful. [0] https://matomo.org/faq/general/configure-privacy-settings-in-matomo/#step-4-respect-donottrack-preference https://matomo.org/faq/general/configure-privacy-settings-in...
- imwillofficial 4y agoRelying on the good will of the advertising industry seems to be a poor choice.
- rnkdsvja 4y agoposting from a throwaway account -- I worked at a few audience measurement companies, DNT was never looked at -- completely ignored. The reason was simple: all upside to ignore, no downside. Regarding fingerprinting -- I know firsthand the places I worked at considered it, and rejected it. Problems are: too cumbersome, they do not persist over long enough periods to be useful to the industry, and they cannot be shared with other companies in the data marketplace. An adversary can use them short-term, but if an adversary has the data to do that, they probably have additional more accurate means at their disposal. Also, in my view, academic papers on this subject always seem alarmist and naive, and methodologies have problems (lack scale, have selection bias, lack ground truth, overlook persistence over time, etc.) {edited} - the way DNT worked in practice led to a very misleading, and harmful effect. Standards should be designed with stakeholder incentives in mind.
- hyperdimension 4y agoYeah, the DNT header ultimately being used as another bit for tracking seemed to me the ultimate irony. This, as for many things: Thanks, Microsoft.
- 4oh9do 4y agoOne thing I never really understood is the incongruity between online tracking and real-world tracking, the latter of which we would call stalking. If you followed around the owner or employee of a tracking...err "advertising analytics"...company, and recorded everywhere they went, and everyone they met and interacted with, including writing down all of the purchases they made when they go to a store, and then you sold the notebook you kept of all this, would you be in any legal trouble? What if you followed around their spouses and children too? Would the employees of the advertising company be creeped out by this? And yet they do it virtually to millions of others.
- femto 4y agoThere's no incongruity, as it is happening in the real-world. https://www.theguardian.com/technology/2022/jun/15/bunnings-kmart-and-the-good-guys-using-facial-recognition-technology-to-crack-down-on-theft-choice-says https://www.theguardian.com/technology/2022/jun/15/bunnings-...
- rgbrenner 4y agoNo, you wouldnt be in legal trouble. I have news for you: When you're grocery shopping, there are cameras watching you: how long you spend looking at an item (which tells them if it's a regular purchase, or something you're considering), the path you take through the store, etc. They use this info to increase the amount of your purchase. The layout of a store is not random. And then when you get to the register, they know you. Not just from your loyalty number, but from your credit card (even if you're not a member). They use this to create a history of your purchases and create a demographic profile of you. They use this profile to determine what to stock in the store, what to put on sale, etc. For example, sometimes they'll stock an item with poor sales, because the customers that buy it make larger purchases (keeping these customers loyal to the store). They'll also use this info to advertise to you, send you flyers and coupons in the mail, for example. They'll combine this with your credit card purchase history to create a more detailed profile... because Visa (et al) sell your purchase history to analytics firms that sell this data to companies like your grocery store. Similarly, analytics firms already know who you're related to, and can match up purchases from other members of your household. My point is: You dont think about even the stuff above, because it's hidden from your view and you arent familiar with what they're doing. Just like many people dont think about what Facebook is doing with their data. You phrase your questions like a hypothetical, but it already exists.
- nonrandomstring 4y agoRohan makes a valiant and useful attempt to expand the over-simplified notion of digital privacy. Anything that throws more light on this area is welcome. However I feel that some of the distinctions are incomplete or need highlighting more strongly. The word 'tracking' shouldn't be used to stand-in for "absence of privacy". For example, I may want to be tracked in every detail and might buy a GPS tracker. However it should remain under my exclusive control. If I find it's defective because it's treacherously uploading my data somewhere I didn't ask it to, that's a breach of privacy. The suggestion that techniques for web browsing might be generalisable to wider privacy doesn't hold up well. The main focus is mitigations (evasion and reduction) against cross-site identity leakage. Active obfuscation, avoidance, spoofing, dazzle, camouflage and decoying isn't covered, nor are threat actors or actor position. For example my ISP or device vendor may be a greater threat than a website (doubly so when the device and site are owned by the same entity eg. Google.) It is oft said that privacy means different things to different people, but this is not the same as saying people have different use cases and needs, and is rarely unpacked by socio/psychological analysis (different expectations and ethical judgements may exist within the same use-cases and needs). Also, someone "being okay" with a violation of privacy is not a sufficient indicator. Objective harms exist and they don't go away because the user is ignorant or convinced, or coerced to make "acceptable trade-offs".
- dcow 4y agoI read this as an attempt to explore the tension between people who want total anonymity and people who just don't want their personal information abused. Sure, there are companies that abuse your information and yeah that's a violation of privacy. But the way I am reading the argument, the solution to one company violating your privacy isn't necessarily a surefire: we should take one more step towards total anonymity. Rather, it depends on the threat model. > Also, someone "being okay" with a violation of privacy is not a sufficient indicator. Objective harms exist and they don't go away because the user is ignorant or convinced, or coerced to make "acceptable trade-offs". Curious what you'd consider an objective harm. For example, I've been in discussions where any stable identifier is objectively harmful because it could be used by a service to track you. Therefore we can't do things like mutual authentication since your cert has a globally unique name, allow signatures in the browser because your key is a global identifier, behave normally at layer 2 (thanks Apple, I can't manage devices on my network anymore because they all randomize their MAC), or find my nearest Lowes because now my traffic exits 5 states away because ~~Apple wants to own my data~~ of my big scary ISP who can't be trusted. Sadly the only conclusion I can come to is that these problems are social and, though technology may have introduced new means to abuse people's privacy and it's natural to seek a technology solution, ultimately require legal solutions. For example, "deleting" IP addresses from the internet is not an acceptable solution in the fight against privacy abusers. Nor is telling services they can't collect information that could identify you unless they need it because, well, everyone needs it at some level and it turns out everything can identify you in the right context. Punishing people who abuse others' privacy is the solution. That, or, technology would need to let me select a la carte exactly which identifiers I want to allow and which I don't and we'd have to live with most everyone never touching those toggles and blissfully remaining tracked and targeted. Frankly I'm sick of privacy nut technologists (who no doubt are genuinely concerned for everyone's safety on principle) continually pushing everyone towards "tracking evasion" when all that most people really care about is surface level "tracking resistance". That much, at least, I resonated with in the essay.
- kkfx 4y agoIMVHO there is a deep fallacy in the article: privacy is not about individuals as single human being but about society, witch means that privacy is not about standing out because of tracking avoidance vs appear as "common generic human" as possible, it's about the power of aggregated data. The war here is already lost but the point is that we do mandate by laws privacy because there are no issue if anyone know anything about anyone else or anyone do not know anything about any others. The issue happen when very few knows very much on anyone else and anyone else know next to nothing about them. The two kind of privacy depicted are just a single emergent aspect, like a flame pinnacle, who stand out, but the real issue is at the base of the flames.
- nonrandomstring 4y ago> privacy is not about individuals as single human being but about society Yes indeed, an important point. Privacy makes little sense on a desert island, even though a solitary castaway has lots of it. (I'm not even sure it makes very much sense for two people on an island) > the power of aggregated data. plus the intent, means and opportunity for a group to use that data to the disadvantage of another group or individual. > The war here is already lost No. The war is won again the moment that data supply dries up because it goes stale quickly. People changing their attitudes can and will have a massive and rapid impact on those industries. Don't be cowed and browbeaten by defeatist talk. > mandate by laws privacy because there are no issue if anyone know anything about anyone else It is equally important to attack intent, means and opportunity. For example, recent research <citation needed> has shown that targeted advertising is really ineffective puff and bluster. Breaking the spell of its mythology is a tactic favourable to privacy because it disabuses potential customers of surveillance capitalism. Technical measures like Tor, overlays and other strong anonymity deals with means, while education pro-privacy propaganda addresses opportunity. At the end of the day we're fighting a counter-intelligence war.
- kkfx 4y agoHonestly? How many always have an Android/iOS device in their pocket, they use it all day long, talking and texting with it, taking photos send to some cloud for backups etc, ... yes, the war is definitively lost, also because most choose not to really fight it. People could and should change attitude but so far those who change are a so little minority to being just irrelevant at social scale. It does not even matter that some or many aspects of surveillance capitalism fails partially or substantially, once you create the surveillance infra some parts will be surely failure but the overall architecture pay back anyway those who control it. Take a look at China... Some fight back sure, who does it matter? Let's say I do my best, at a really paranoid level, to try protecting my privacy: I can't even going in urbanized are since they are full of cams like most modern vehicles. I can't probably use a bank here since 99% of them demand a crapplication who run only on Android/iOS (of course, not in an emulator) as a third factor for auth, I might be able to circumvent their check BUT it's a continuous fight for what? The list is soooo long that at maximum you can try fighting for the army honor, not to win...
- a_c 4y agoWould love to hear HN's opinion on tracking. I was of the camp that all tracking is bad and should be banned. But one day I re-realized, website owner, having access to the server (e.g. nginx), can always track their visitor if they wish to. So maybe the problem is third party tracking instead of tracking? What do you feel if a website doesn't use any 3rd party tracking, but analyse visitor usage pattern using nginx/cloudwatch/any sort of logging provided by the tools essential in running the services?
- Rygian 4y agoYou were right initially. First-party or third-party is not a useful distinction from a privacy point of view. If you want analytics, anonymize first and then use whatever tracking you want. But first price that your anonymizing is really effective, even if they results in less precise tracking.
- XCSme 4y ago> First-party or third-party is not a useful distinction from a privacy point of view It is a huge difference. There's one thing to have your data stored on a server that only one person has access to, and they are obliged to respect strict privacy laws and a completely different thing to have your data sent and shared to hundreds of companies that can use that information for various marketing or analysis purposes.
- Rygian 4y agoLate reply. I really disagree. Whether the cookie shows under a dns name or another means next to nothing as to who is doing the tracking. If I'm not mistaken, Google Analytics is now pushing to have all cookies served by a front domain, hiding from the user who the third parties are. I may be wrong on this, have not done my research yet.
- XCSme 4y agoI agree with you, but my comment was not regarding the DNS, but the legal entity having access to your data. There's one thing to send your data to Google and accept for it to be processed by them and all their partners and another thing to send your data only to the company that owns the website that you are currently visiting and only allowing them to internally use this data, without it being sent or processed by any 3rd parties (as strictly specified and regulated by the privacy laws).
- loicd 4y agoReading the title, I assumed that the article would talk about what people mean by privacy. However, it really is about how people try to achieve privacy (by reducing the mount of collected data, or by reducing the amount of collectible data). The thing is how you do it depends on what you are trying to achieve. When discussing privacy, I find it useful to distinguish three types: a) privacy from government, which is fondamentally not a technical problem but a political one, b) privacy from big corporations, and c) privacy from criminals (i.e. "hackers"). In my experience, people are really mostly interested in c) and so-called privacy conscious people are mostly interested in b). As for how to achieve b), I (perhaps naively) assume that corporate data collection obeys a law of diminishing returns, so the best strategy is simply to do more than the masses who do not care.
- JadeNB 4y ago> When discussing privacy, I find it useful to distinguish three types: a) privacy from government, which is fondamentally not a technical problem but a political one I think that this is not quite true. At its best, privacy from the government is granted willingly by the government; this is a political process. However, one might be dealing with a government that explicitly revokes certain privacies, or one might not trust a government's guarantee to respect certain privacies, in which case the political problem is once again technological. (Or of course one could trust one's government implicitly but not the next government, or one could trust one's government to try to do things well but fear government stores of data as a juicy target for hackers.)
- loicd 4y agoI mostly agree. What I mean by "fondamentally not a technical problem but a political one" is that technological solutions to bad or incompetent government policies seem to me to be band-aids that do not actually solve the problem. They are useful if this is all you have, but they are no substitutes for good policies.
- denton-scratch 4y ago> of course one could trust one's government implicitly but not the next government Quite so. Consequently my priority is a); if I can keep my information away from the government, then b) and c) follow along. That is, if government can't get the data, then (unless I'm careless) nor can corporations and crooks. The government is the toughest nut; they have the whip hand. I need to interact with the government to get government services I've paid for, such as my pension and medical treatment.
- MomoXenosaga 4y agoRoe vs Wade educated me on the fact that the US Constitution never mentions a right to privacy. Normally the response would be "so just add it" but that's America for you I guess.
- lrvick 4y agoThis is covered by the Bill of Rights. First amendment - privacy of beliefs Third amendment - privacy of the home Fourth amendment - privacy of person and possessions Fifth amendment - privacy of personal information If only the extraordinarily powerful and well funded defend-from-the-government second amendment advocacy groups understood that the freedoms they think they are protecting with guns are being lost from the data they freely give to governments and corporations. State DMVs make millions every year selling home addresses and emails to marketing firms and no one cares.
- saalweachter 4y agoThat's what the Ninth Amendment is there for, hypothetically. The Bill of Rights was never intended to be an exhaustive enumeration of even fundamental rights, and the Ninth Amendment explicitly says that you cannot ascribe significance to a right having been omitted from the enumeration. That depends on the SCOTUS deciding there is an unenumerated right being infringed upon, and historically the SCOTUS has preferred to tie judgements to enumerated rights even if it'd be simpler to just say outright, "this is an unenumerated right", but still, we're not supposed to need to actually spell them all out. In theory. In practice--
- night-rider 4y agoAuthor mentions Tor, yet Tor can make you stand out just by mere use of it, unless you use pluggable transports/ bridges to hide the fact you’re using Tor. Also you could hide in plain sight by using Safari on iOS with a generic mobile Internet IP. Generic useragent and generic IP. What’s wrong with that? Bonus points for browsing in a private session to stop cookie tracking.
- cowtools 4y ago>Tor can make you stand out just by mere use of it That's always a concern with obfuscation networks. But that concern decreases with the number of other users on the network. The more that people start to use Tor, the more it becomes socially excusable and the more the anonymity set grows. Traffic goes in, traffic goes out. Few can connect the dots. >Also you could hide in plain sight by using Safari on iOS with a generic mobile Internet IP No, you really can't. There's no browser (other than Tor Browser) that I know of that takes sufficient anti-fingerprinting measures. Using safari/ios to "hide in plain sight" is a lot like trying to hide in a crowd in front of a security camera with a unique QR code tattooed to your forehead.
- night-rider 4y agoYou could also disable JS in Safari but with the caveat you would stand out among the masses who have it enabled. However like you said, the more people that disable JS in Safari, the easier it is to blend in, but we’re far away from that happening. As regards unique fingerprints, no JS mitigates things like canvas fingerprinting and other factors like time zone, battery charge level etc
- AndrewUnmuted 4y agoI disagree with this basic premise. Privacy is not a baseline philosophical module that gives way to two separate concepts; privacy is simply a thing that can be achieved upon exercising one's property rights. We want privacy because we desire control over the dissemination of our secrets. We desire this because our secrets are derived from activities to which you do not want the public privy. The reason one does not want their activity public is because it ultimately threatens the foundation upon which our lives are built. We use our right to property to protect ourselves against this outcome. We buy homes to say "this land is mine, please do not come onto it." We buy cars to say "this is my wheel machine, please do not use it." We buy computers to say, "these are my thoughts and productive activities - not yours." We do not mind when our privacy is violated when it is perceived to have no material impact on us for that information to be out there. This article is not really about privacy, but rather different ways by which to go about privacy _protections_. It is an insightful article when tuned to this context, and without doing that, it can be a little misleading.