Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
c1ll1an
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
27 ms
·
1.
▲
Privacy-as-code: how Fides open-source could have prevented TikTok's $92M fine
(medium.ethyca.com)
2 points
by
c1ll1an
4y ago
|
0 comments
2.
▲
Show HN: Fides, light-weight description language and tools for privacy in CI
(github.com)
26 points
by
c1ll1an
5y ago
|
1 comments
3.
▲
Devtools for Data Privacy – The Benefits
(medium.ethyca.com)
5 points
by
c1ll1an
5y ago
|
1 comments
4.
▲
Privacy Taxonomy – An Open Source draft for describing privacy in any techstack
(medium.ethyca.com)
6 points
by
c1ll1an
5y ago
|
0 comments
5.
▲
by
c1ll1an
5y ago
That is heartening to hear - your strong attitude to privacy I mean @mikece. Agree with you that if you've worked in software for long enough a breach of some kind is an inevitability and that's really important for every dev to u
6.
▲
by
c1ll1an
5y ago
Agreed @swiley. I'm usually heartened when I remember that security wasn't dissimilar a few years ago and while it arguably still has a lot of challenges, security is part of a healthy dev mindset today. We've a way to go fo
7.
▲
by
c1ll1an
5y ago
Really good point fitblipper - I see this all the time. Organizations have poor/no data retention policies so they accumulate information they no longer need for many years and on the other side they continue to build new data processi
8.
▲
by
c1ll1an
5y ago
That's an interesting one - I'm not sure I follow TeeMassive, do you mean to say that privacy is unimportant culturally? If that's the case, we probably differ on POV a little so I'd love to know more about why you think
9.
▲
by
c1ll1an
5y ago
Right b3morales - they can and should be proportionate to both size of company, revenue and the type of regulatory infraction - all of these must be evaluated but it doesn't mean we shouldn't enforce. To take the restaurant exampl
10.
▲
by
c1ll1an
5y ago
Definitely true that enforcement has to be proportional to both the infraction and the size of the organization. However, I would argue that there are plenty of very small companies that also take advantage of that. i.e. very high growth, e
11.
▲
by
c1ll1an
5y ago
We're both agreed on this point @pjmlp - regulations must have teeth and that often takes time. I can't speak to it, as it's not my area of expertise but we also have allowed a type of golem to form, in that big tech is now
12.
▲
by
c1ll1an
5y ago
Commendable work @Stubish on writing that script. You've nailed the exact problem that I'm referring to here. Strong privacy is a kind of anachronistic issue in that the regulations came long after many systems were designed/
13.
▲
by
c1ll1an
5y ago
@atoav - this is awesome to hear! I'd love to know more about where you work and how you guys have done such a good job of helping devs understand and drive privacy. It doesn't really matter if the software's end-user is inte
14.
▲
by
c1ll1an
5y ago
Fair - but I'm not sure we've made it technically easy on ourselves as developers to be "respectful". Right now it's expected that a dev might understand enough about the myriad of privacy laws that might affect the
15.
▲
by
c1ll1an
5y ago
This is valid but potentially a slightly different issue, insofar as I don't believe that the work we're doing at Ethyca affects the moral compass of a company. There are certainly many businesses we actively choose not to work w
16.
▲
by
c1ll1an
5y ago
Fair @isbvhodnvemrwvn - I'd say it's a combination of laziness, lack of knowledge perhaps or both? I'm conscious that it's easy to say "do _____ better" and insert a soap box like privacy or security; but if yo
17.
▲
by
c1ll1an
5y ago
Really good point csande17 but I'd be nervous to tar all ML folk with the same brush :) I know some incredible data science and ML folks who care deeply about privacy - check out http://openmined.org to see hope in the ML c
18.
▲
by
c1ll1an
5y ago
Fair point TheChaplain - I'd actually argue it's across industry. It's a combination of a lack of knowledge about what privacy really is (a lot of confusion over that vs. security for example) and then how to ensure privacy f
19.
▲
by
c1ll1an
5y ago
Exactly Nextgrid - this is on developers to solve. Data flowing through a system isn't policed by the legal agreement, it's developers who understand where/how data is being used - we're the ones who can fix this.
20.
▲
by
c1ll1an
5y ago
Right - you've nailed it, a legal document like a data processing agreement may be enforceable in court but system implementation can vary widely, often without malice but it still fails. So the question to answer is how can we ensure
21.
▲
by
c1ll1an
5y ago
Completely agree pintxo, doing these basic things goes along way to ensuring there's a privacy first mindset when building anything. The question I’m looking to answer as we work on this problem at Ethyca is how do we make it easy for
22.
▲
Privacy is an afterthought. Here's how devs can easily make it better.
(stackoverflow.blog)
85 points
by
c1ll1an
5y ago
|
45 comments