4 ms·
Hey, I'm the author of this blog. Much of my previous deanonymization research has been discussed on HN; see http://www.google.com/search?q=33bits.orgsite:news.
by randomwalker 15y ago
Hey, I'm the author of this blog. Much of my previous deanonymization research has been discussed on HN; see http://www.google.com/search?q=33bits.orgsite:news.ycombinator.com http://www.google.com/search?q=33bits.orgsite:news.ycombinat... Also, if you find the premise of the blog interesting check out the sitemap linked from the page.
But since this post is about the About page, let me share a couple of lessons I've learned from the blog, which has been more successful in communicating my research than I'd dared to hope for when I started it 3.5 years ago.
1. Those of us working on technical areas often struggle to explain our ideas to others not as technical, in a way that avoids oversimplification and losing essential meaning. Sometimes you'll discover an analogy or metaphor or phrase that does both. Seize those chances, they're powerful.
2. Coming up with a name is more important than you might think. If a good name will make your idea or product even 5% stickier, it follows that it may be worthwhile to spend 5% of your time just coming up with the name. One way to do it is to be constantly on the lookout for a good name while you're working on the product.
3. If you're writing about something that has policy implications, and want it to be read in Washington, it's hard but not impossible. Two important requirements are to network and build up an audience — they aren't going to read your blog just because it ranks high in Google searches — and to use language that non-technical people can understand.
Happy to answer any questions!
- chrisacky 15y agoI've been trying to think of a way of using typing cadence to capture "bits" of information. Think you would have a good solution for that? Take this scenario (and also check out the exclaimer at the bottom!). All users on the earth type the same paragraph, or perhaps some password (clearly the longer the most distinct fingerprint, but bear with me on this). Based on this sequence of keypresses, I capture the timestamp that each keypress is activated, and then the duration that each key is held down for. Based on this information, how would you recommend, or suggest that a person goes about detecting some unique fingerprint from these values. I was thinking the best way would be to have each keypress some space point and the duration held down a vector. And then if each use is entering the same paragraph, the distance accross all of the vectors could be used to calculate some identifying fingerprint. Exclaimer: I'm absolutely not interested in the slightest in tracking users. Every weekend I try and research something that interests me. Last weekend was user fingerprinting based on the typing speed and cadence of users.
- randomwalker 15y agoThis is a well-known technology :-) See http://en.wikipedia.org/wiki/Keystroke_dynamics http://en.wikipedia.org/wiki/Keystroke_dynamics In the research community it's a proven and accepted concept. There are products in the market that do two-factor authentication based on password + keystroke dynamics, but I don't know how well they work.
- chrisacky 15y agoThanks! I was sure it must have been called something!
- deleted 15y ago[deleted]
- Hoff 15y agoI know a user that has treated his computer keyboard as a keyboard on a musical instrument, and "played a tune" with the keys as his password.
- unimpressive 15y agoIt's too bad that this is halfway to the bottom of the page. That's easily one of the most interesting steganographic techniques I have ever heard of. It certainly allows for unique password reminders. A tape recording next to your monitor with strange music on it would probably be passed over by...I honestly can't think of anyone who'd make the leap between music and passwords. So lets just say anyone except (potentially) people who've read this post, the user you mentioned, and anyone else who happens to be doing this.
- microarchitect 15y agoHey! I ran into your blog after I saw an announcement for (one of?) your talk(s) next week. I submitted the about page because the two key claims that you make: (1) you only need a few bits of information to identify a person uniquely in the whole world and (2) this information is becoming easier and easier to obtain - both make a lot of sense to me. Your about page does an excellent job of communication these two points and I thought it might interesting food for thought for HN. I'm wondering whether much as we'd all like to have privacy and anonymity, these could be goals that might be impossible to achieve in the future. I'd like to hear what your thoughts are on where, we as a society are heading in this context and whether it's unrealistic to expect that conventional expectations of privacy will continue to be fulfilled in the future. Perhaps, we should accept that the privacy battle is lost and try to other solutions to the problems that privacy was solving?
- randomwalker 15y agoThat's a great question with no simple answer. I've written two essays about this that look at it from two different sides: http://33bits.org/2011/10/18/printer-dotspervasive-tracking-and-the-transparent-society/ http://33bits.org/2011/10/18/printer-dotspervasive-tracking-... http://33bits.org/2011/06/08/the-many-ways-in-which-the-internet-has-given-us-more-privacy/ http://33bits.org/2011/06/08/the-many-ways-in-which-the-inte... The synopses of the two posts are: My opinion is that it impossible to put the genie back into the bottle — the cost of tracking every person, object and activity will continue to drop exponentially. ... If we accept that we cannot stop the invention and use of tracking technologies, what are our choices? Our best hope, I believe, is a world in which the ability to conduct tracking and surveillance is symmetrically distributed, a society in which ordinary citizens can and do turn the spotlight on those in power, keeping that power in check. On the other hand, a world in which only the government, large corporations and the rich are able to utilize these technologies, but themselves hide under a veil of secrecy, would be a true dystopia. and from the other side: There are many, many things that digital technology allows us to do more privately today than we ever could. [examples snipped, but I recommend taking a look at the post] Of course, I’ve only presented one half of the story. The other half, that technology is also allowing us to expose ourselves in ways never before, has been told so many times by so many people, and so loudly, that it is drowning out meaningful conversation about privacy. Although these two opinions might at first sight seem contradictory, they are not. Some day I will get around to putting the two sides of the argument together into a coherent narrative that explains the nuanced scenario that I think we're heading towards, but for now I will offer you the above articles.
- zeratul 15y agoYou say in your blog that you sat on the "Heritage Health Prize" advisory board. Have you looked at these data sets? https://www.i2b2.org/NLP/DataSets/Main.php https://www.i2b2.org/NLP/DataSets/Main.php De-identification of medical charts is a bottleneck in clinical research. It's impractical to ask for thousands consent forms, however, smaller sample sizes are inconclusive, so much, that most of medicine is driven by inconclusive research findings. Moreover, full anonymization does not allow to follow patient records over time. This will kill any big patient outcome study, at least financially. What are your thoughts?
- gwern 15y agoWhile I'm here, thanks for writing your blog. I would never have been able to write my little essay http://www.gwern.net/Death%20Note%20Anonymity http://www.gwern.net/Death%20Note%20Anonymity without it, and oddly enough, it's turned out to be (on Hacker News) the most popular thing I've ever written: http://news.ycombinator.com/item?id=3634320 http://news.ycombinator.com/item?id=3634320
- geoffschmidt 15y ago> If a good name will make your idea or product even 5% stickier, it follows that it may be worthwhile to spend 5% of your time just coming up with the name. I'm a sucker for a great name, but this is misleading. If something will give you an x% better outcome, it doesn't follow that you should spend about x% of your resources on it. It depends entirely on the opportunity costs, yeah? You should spend time on your name only when you believe that thinking about names for another hour will do more good than coding or talking to customers for another hour.
- aangjie 15y ago>1.. Those of us working on technical areas often struggle to explain our ideas to others not as technical, in a way that avoids oversimplification and losing essential meaning. Sometimes you'll discover an analogy or metaphor or phrase that does both. Seize those chances, they're powerful. Am sorry does both of what?.. Don't mean to nitpick, but this is a problem i run into regularly and don't seem to be able to find a reliable approach. So just trying to divide it into the factors involved...
- bgilroy26 15y agoDoes {explain ideas} with both of {understandable by non-technical people}, {avoids losing essential meaning}