5 ms·
A lot of geolocation data on the market is anonymized, following medium-lived unique IDs that aren't able to be mapped to other identifiers. The problem with th
by Johnbot 6mo ago
A lot of geolocation data on the market is anonymized, following medium-lived unique IDs that aren't able to be mapped to other identifiers. The problem with that is that if you have precise locations, or enough samples that you can apply statistics to find precise locations, in many cases you can de-anonymize the IDs. You can purchase address and resident listings from a number of different data vendors, and by checking where the device returns to at night you can figure its home address. Then if you find information on the residents (work locations, schools, etc.), you see if said device goes where each resident of the home address is likely to go, and you now have a pretty good idea of exactly who the device belongs to.
- 1121redblackgo 6mo agoYep. With side channel/one order of thinking above the laws, its trivial to get around said laws. Need better laws.
- sroussey 6mo agoCompanies exist that de-anonymize other data brokers data. Lets the other data brokers claim they have anonymized data while end end users get everything.
- ImPostingOnHN 6mo agoyou could probably run a anonymization company at the same time you run a de-anonymization company
- gessha 6mo agoBest of both worlds - legal and profitable \s
- rockskon 6mo agoThere is no such thing as anonymized location data when you have the location of something where and when they sleep and work. It's a rhetorical fiction the ad industry tells itself.
- deleted 6mo ago[deleted]
- deleted 6mo ago[deleted]
- Forgeties79 6mo agoAnd with LLM’s now it’s easier than ever to piece the parts together. Companies were doing it before we even knew what LLM’s were capable of. Edit: It's a rhetorical fiction the ad industry tells us.
- deleted 6mo ago[deleted]
- Terr_ 6mo agoRight, there's probably no other phone in the world that typically stops for hours within 1000 feet of my bed and typically stops on Monday-Friday within 1000 feet of my work-desk.
- mapt 6mo agoNow think what Lavrenti Beria and an LLM could have done with that.
- wafflemaker 6mo agoSomebody once said that if Stalin had access to television, he would never have to kill 20+ million ppl. What would he do with all that data? No idea.
- vovanidze 6mo agoexactly. calling it 'anonymized' is pure security theater once you have enough data points to map out someones daily routine. waiting for legislation or eulas to fix this is a lost cause since adtech always finds a loophole. the fix has to be architectural. moving toward stateless proxies that strip device identifiers at the edge before they even hit upstream servers. if the payload never touches a persistent db there is literally nothing to de-anonymize. stateless infra is the only sane way forward
- microtonal 6mo agoTo be honest, I feel like this is where iOS and Android are failing us. Why is every app allowed to embed a bunch of trackers? Only blocking cross-app tracking on user request as iOS does is not enough (and data of different apps/websites can be correlated externally).
- CPLX 6mo agoBecause we don’t enforce antitrust law in this country and the people that make those decisions profit from the ads.
- rolph 6mo agoim not sure about allowed. perhaps required may be closer. why would someone include tech that makes people think twice about using the app, unless it is required if you want to "sell" in a particular venue. if your developing geolocation based apps, location tracking is a core function. a calender, absolutely does not require location tracking beyond what side of the prime meridian are you on.
- malfist 6mo ago> A lot of geolocation data on the market is anonymized A lot isn't good enough.
- jandrewrogers 6mo agoLocation and identity are inextricably linked. You can't destroy identity without also destroying location and location is critical for myriad purposes. The analytic reconstruction of identity from location is far more sophisticated than the scenarios people imagine. You don't need to know where they live to figure out who they are. Every human leaves a fingerprint in space-time.
- deleted 6mo ago[deleted]
- nickburns 6mo ago> and location is critical for myriad purposes. It's not though. Critical for myriad elective purposes? Sure.
- jandrewrogers 6mo agoOnly if you consider the entire concept of logistics in civilization as "elective".
- nickburns 6mo agoI don't follow what you mean by 'logistics in civilization' as that's pretty vague and amorphous. Could you be more specific with maybe a single example of where my physical geographic location is electronically critical for a purpose that isn't elective/optional/avoidable? (And I'm not just trying to be obtuse. I think you're touching on at least part of the 'heart' of both this conversation and that of digital ID verification.)
- quickthrowman 6mo agoHow does tracking the movements of individual humans aid shipping and logistics, other than providing traffic data to freight companies? How did we manage to have global supply chains prior to GPS being invented? Edit: I assume I am missing a crucial part of logistics that you’re familiar with, genuinely curious.
- 6mo ago
- ninalanyon 6mo agoIn what sense can the latitude and longitude of my house be called anonymous data?
- kube-system 6mo agoUltimately, a map is anonymous data containing lat/lon of everyone's house Alone, these points are not deanonymizing, it's when there's other data associated.
- ninalanyon 5mo agoWhen such data is sold I'm pretty sure it would be more than just list of coordinates.
- teraflop 6mo agoWe should have learned this lesson 20 years ago when researchers were able to deanonymize a lot of the Netflix Prize dataset, which contained nothing except movie ratings and their associated dates. https://arxiv.org/abs/cs/0610105 https://arxiv.org/abs/cs/0610105 If movie ratings are vulnerable to pattern-matching from noisy external sources, then it should be obvious that location data is enormously more vulnerable.
- totetsu 6mo ago> In contrast to previous attacks on micro-data privacy [22], our de-anonymization algorithm does not assume that the attributes are divided a priori into quasi-identifiers and sensitive attributes. Examples include anonymized transaction records (if the adversary knows a few of the individual's purchases, can he learn all of her purchases?), recommendation and rating services (if the adversary knows a few movies that the individual watched, can he learn all movies she watched?), Web browsing and search histories (12], and so on. In such datasets, it is impossible to tell in advance which attributes might be available to the adversary; Is Location data highly dimensional though?
- ramoz 6mo agoFrom what I've seen none of this is that complex, one could simply 'draw a circle around your house' and get all the "anonymized" device pings and just trace those.
- nzach 6mo ago> enough samples that you can apply statistics to find precise locations, in many cases you can de-anonymize the IDs I think a lot of people don't realize the power of a big enough sample size. With enough samples even something pretty innocent looking like your daily step counter could make you identifiable. As far as I know we don't have large enough databases to make this happen in practice, but I don't think this is impossible in the future.
- jandrewrogers 6mo agoHow large are you estimating is "large enough"?