6 ms·
Techniques which allow the sharing of data whilst keeping it secure
- deleted 4y ago[deleted]
- xhkkffbf 4y agoPrivacy enhancing technologies are neat, but they're not exactly new. I've been following them since the 90s. There was a book called _Translucent Databases_ and dozens of good papers back then. Since then, there are entire conferences. It's good that the Guardian is covering this, but it's not exactly new.
- mattdesl 4y agoFast, general purpose, succinct, and non-interactive proofs are pretty new, see SNARK (2013), STARK (2018) and Halo2 (2020). Even more interesting is zkVM like RISC Zero. Practical and open source applications of FHE feels even more nascent than ZK.
- woojoo666 4y agoIt's not new but it is undergoing a bit of a revolution because of growing interest in privacy and decentralization. Monero didn't exist in the 90s
- nl 4y agoTranslucent Databases[1] is not the same thing at all. The approach they are using requires the person doing the querying to have the same encryption key that the data is encrypted with (eg, they recommend hashing data then querying with the hashed data[2]). This is a great technique that improves security. But is isn't the same as zero-knowledge techniques which are comparatively new. The maths for them first developed in the mid-to-late 1980s, but zkSNARK (which made it useful in computer science) wasn't developed until 2012[3] [1] https://www.wayner.org/node/15 https://www.wayner.org/node/15 [2] https://www.researchgate.net/publication/301174908_Translucent_Databases https://www.researchgate.net/publication/301174908_Transluce... [3] https://dl.acm.org/doi/10.1145/2090236.2090263 https://dl.acm.org/doi/10.1145/2090236.2090263
- nl 4y agoThere are other techniques that aren't generally included in the "Zero Knowledge Proofs" set of techniques that are perhaps more practical for general development. For example, I find private set intersection[1] as implemented by OpenMined a really useful primitive a bunch of privacy enhancing applications can be built on top of. My colleagues and I recently published a pre-print[2] showing how to use this for sharing locations you and another person have had in common, without being able to see other locations. The paper talks about a social network built around this but I also think there are useful applications in things like real-world games (scavenger hunts etc) [1] https://github.com/OpenMined/PSI/blob/master/private_set_intersection/javascript/README.md https://github.com/OpenMined/PSI/blob/master/private_set_int... [2] https://arxiv.org/abs/2210.01927 https://arxiv.org/abs/2210.01927
- ericalexander0 4y agoWhat's the limiting factor of homomorphic encryption? Is it that it's provable? Is it the compute overhead? Is it too magical for governance?
- deleted 4y ago[deleted]
- lucgommans 4y agoRight now? For broad applicability it is the computational overhead. There are some applications that are doable now, such as reading data anonymously from a small-ish dataset (or a low-volume service where you can afford to wait a minute for an answer, or using really expensive hosting). An example of that was a Wikipedia server that someone made which would serve you pages without the server knowing which page your client was actually after (https://news.ycombinator.com/item?id=31668814 https://news.ycombinator.com/item?id=31668814 4 months ago, 119 comments). It's still not really efficient; you can't simply swap out the real Wikipedia for this system and expect it to simply work. > the server [needs] to scan through the entire encrypted dataset [for every request] (this is unavoidable, otherwise its I/O patterns would leak information) Imagine Wikipedia servers needs to read every byte written on Wikipedia and operate on it before being able to formulate an answer to a random pageload. Additionally, if I remember correctly, things like autocomplete worked by just downloading the entire list of articles and doing that locally. It's all not impossible, but not a drop-in solution. And then when you have a situation where you can practically apply it, there aren't popular/trusted/already-audited software packages out there for you to just use with confidence.
- nopenopenopeno 4y ago>they can discover if their abuser is a repeat offender without identifying themselves to the authorities Nonsense. An anonymous accusation is all but meaningless, and is in no way similar to a conviction. This is some truly garbage journalism.
- chrisweekly 4y agoAgreed. Also not to pile it on -- it's a complete tangent, really -- but every time I read the word "whilst" I cringe and wonder why the author didn't write "while". IMHO it adds no additional information or nuance, it's an archaic word that's long since departed from spoken use, and its presence in a sentence serves only to signal a failed attempt to sound sophisticated. Maybe it's just me, but for some reason it always triggers this reaction of "oh get off it, stop being pompous". /rant /tangent
- nl 4y ago> Nonsense. An anonymous accusation is all but meaningless, and is in no way similar to a conviction. This is some truly garbage journalism. Neither the article nor Project Callisto claim it is anything like a conviction. The article itself points out that even when multiple people accuse the same person the lawyers who are contacted do not (and cannot) get access to the accused person's name via the system.
- nopenopenopeno 4y agoThe article’s claim is simply nonsense. As I quoted, the article literally says “they can discover if their abuser is a repeat offender” but in-fact they can only discover if any anonymous accusations have been registered.
- cortesoft 4y ago> “Maybe one person doesn’t have a case, but two people do.” Except they don’t have any way to contact each other, or for anyone else (like the police) to contact them… so how exactly are they going to have a case?
- Thorrez 4y agoThe victims can contact their own assigned lawyers. The article doesn't explicitly say this, but I think the 2 lawyers can contact each other.
- nl 4y ago> Callisto employees have no access to the name of the perpetrator within Callisto Vault. When two or more survivors have entered the same unique identifier of the same perpetrator and a "match" occurs, each survivor is contacted by a Legal Options Counselor (LOC). The LOC is an attorney and all information discussed with survivors is protected by attorney client privilege. The LOC will discuss all legal options with survivors to find the right coordinated action to take. The only way a perpetrator will find out they have been entered into Callisto Vault is if a survivor tells them or moves forward with legal action against the perpetrator and Callisto Vault is disclosed during legal proceedings. https://www.projectcallisto.org/ https://www.projectcallisto.org/
- sjducb 4y agoIf you're trying to use brute force to break this system it's important to realise that the search space is not all possible hashes. The search space is all likely names. This makes it trivial to break, especially for the CIA case where there are really only a few hundred likely adversaries. The encryption/hashing doesn't really add anything beyond empty marketing. The trusted party who ppl report to could easily work out all of the names of they wanted to.
- mattdesl 4y agoDepends on how the database and application was set up. In a properly formed ZK application you cannot obtain any reasonable information by brute force hashing names. Edit: I realize you’re probably talking about Callisto which does seems like simple hashing of names, but I wanted to note that this is not always the case in apps using ZK proofs and FHE which the article touches on a bit later.
- franknstein 4y agoThis is common misconception. The truth is that in HE every plaintext can be encrypted to (exponentially iirc) many different ciphertexts. During encryption one of those is chosen randomly. This makes dictionary attacks practically impossible. Edit: HE scheme (lwe) works on individual bits. Meaning there are only two plaintexts (0,1). Each has exponentially many ciphertexts, only one chosen at random. They also share ciphertext space, meaning each ciphertext could be either encrypted zero or one.
- sjducb 4y agoMaybe I'm missing something, but surely a dictionary based attack will work because you have to be able to know that your key has already been submitted by another user. That's the point of the application. 1) Initial report is filed. 2) Second report is filed by a user who only knows the attackers details. 3) Match is found Therefore you can just keep iterating through names till you get a match. Another way of saying it is that the application won't work if a second user can't tell that the first user has entered an attackers name. The vulnerability is in the application specification, not HE.