4 ms·
This sounds absolutely, positively impossible. There can never be such a thing as read access without “store access”. Taken to the extreme, a person could read
by usui 4y ago
This sounds absolutely, positively impossible. There can never be such a thing as read access without “store access”.
Taken to the extreme, a person could read the data and then literally handwrite it down on a piece of paper. That’s storage. It is nearly impossible to prevent that.
Also, if it’s illegal to duplicate the data, then it would have no purpose to be read from. For example, the system needs to access your birthdate field. Is using that piece of info somewhere considered storage, if it persists in any way? Probably.
So what this means is that the next best thing we can do is enforce read access to trustworthy parties only, with confidence for now and the future.
- black_puppydog 4y ago> This sounds absolutely, positively impossible. There can never be such a thing as read access without “store access”. but there could be very clear rules just how many $$$ in fines you have to pay per data point if you ever get caught with your pants down. The issue with these leaks is that the perps never have to pay for them. edit: that being said, I don't think a single such pool is a good idea since it would become the prime target for every hacker on the planet, right next to 1pass.
- usui 4y agoStill, I don’t understand. If it’s illegal for a data point to be stored, how could it be used anywhere with confidence? If your microservice returns an illegal datum, and a consuming service needs to use it somewhere, how is that secondary usage not a form of storage? This is before taking into consideration things such as cached responses, temporary files, RAM, and other downstream services. You would also have to prove that datum wasn’t derived from anywhere else. What a legislative nightmare this sounds like!
- black_puppydog 4y agoYeah what I'm writing about there not being a pain signal applies either way; even if you have a good reason to store data, leaking them should hurt. But even so, many times a website seems to ask for data they absolutely strictly don't need. Electronics shop -> doesn't need my gender, nor birth date really. If someone does need my birth date, they typically a) don't need to store it but just verify, and b) what they'd really need would be a trusted third party (like my govt ID) certifying that date. And even then, often just properties about it like "is over 21" or such. Which is incidentally what my german ID allows to do, albeit in a way too complicated way.
- deleted 4y ago[deleted]