Live data from Hacker News

What is Differential Privacy?

blog.cryptographyengineering.com

71–80 of 108 posts

Re: What is Differential Privacy?

#71

Earlier quoted context omitted.

>So Apple can (for example) predict that listing to band A means you are likely to like band C And how is that different from my iTunes example?

I used "you" incorrectly, my bad. They can predict that people who listen to band A are likely to like band C, but their data for whether you listen to band A still has a significant chance of being wrong.

Yes, the data has a significant chance of being wrong. But it is useful only insofar as it supports a prediction with a probability of being right that is greater than 0.5.

That's what makes the data useful and that's what makes it a privacy issue at the same time.

Re: What is Differential Privacy?

#72
post #47
post #40

Earlier quoted context omitted.

How would the cookie from the work get to the phone?

I must have been connected to the same Gmail or Facebook account at some point on both devices. However as I said I purposely never stay logged in to google services. Yeah, I can flush all cookies (thus annoyingly resetting all legit cookies as well). But this is not how privacy should work, cause there is a lot of people out there that don't read HN and only recently found out that there is a lot pastry inside their…

Your browser (Firefox, Chrome, Safari) most likely uses Google SafeSearch. That phones home with a super cookie every 30 minutes.

Re: What is Differential Privacy?

#73
post #64
post #54

Earlier quoted context omitted.

Are you saying Notes, Safari Bookmarks, Photos, etc are encrypted on iCloud? How come they are accessible from iCloud.com? Decrypted by the browser on the fly?

It seems so: https://support.apple.com/en-us/HT202303 However I reckon that technically Apple could access data or give data stored on iCloud to NSA/FBI because they actually still hold the keys for that part too (not only backup as I thought). Only the password/creditcard Keychain is now claimed to be fully user-encrypted and can't be recovered by any mean by apple. For anything else than a warrant, they'll "just" h…

> For anything else than a warrant, they'll "just" have to breach every engagement they made in their contract which would, as far as I know constitute a pretty solid legal case that could only lead a public walk of shame that could compromise the whole company's future.

This is something I doubt. It would be rather easy to change the software and make it sync passwords, even on an individual basis. If this would come out, it would mean a big marketing problem, and could result in sales losses like 10-20%.

I said "could", but to be honest I think 2-3% is more realistic. Most people don't care. They want their data to be safe in case of theft, and have a backup in case of loss. Here on HN it's a big thing, but most users don't know, don't care.

Re: What is Differential Privacy?

#74
post #3

> On the other hand, when the budget was reduced to a level that achieved meaningful privacy, the "noise-ridden" model had a tendency to kill its "patients". Uh, the graph is just showing you get an increased 25% estimated risk of mortality from Warfarin, nothing close to "killing patients". Complete exageration, since the mortality baseline is probably very low in the first place.

And, just to be clear, in their paper it not the presence of noise that kills people, it is their treatment of noisy measurements as high-confidence measurements that kills them. When you get low confidence reads from data you should use them as such; the authors just act on them no matter how strong (or weak) the confidence and report what happens.

It's roughly analogous to a doc saying "should I deviate from the baseline treatment?" and when the data say "dunno" the doc prescribes a totally random medicine rather than the baseline, because that is what "dunno" means.

Re: What is Differential Privacy?

#75
If you collect values of random variable Y from phones, where Y = X + N (N being normally distributed with mean 0 and var Y = var X, say) then many statistics can be calculated with that.

The law of large numbers says that after gathering statistics from many values of Y, they will converge (for continuously differentiable functions of X) to the values for X.

Yes?

Meanwhile each individual user will not send so many samples as to identify the true values of X with any useful accuracy.

Re: What is Differential Privacy?

#76

Earlier quoted context omitted.

I used "you" incorrectly, my bad. They can predict that people who listen to band A are likely to like band C, but their data for whether you listen to band A still has a significant chance of being wrong.

Yes, the data has a significant chance of being wrong. But it is useful only insofar as it supports a prediction with a probability of being right that is greater than 0.5. That's what makes the data useful and that's what makes it a privacy issue at the same time.

It doesn't have to support that prediction in specific instances, just in a general trend, where random noise tends to average itself out in a lot of cases. There are lots of different distributions with the same averages, the same conditional probablities, etc. with wildly different data. If you have some mathematical proofs that say you can not reach one of these other distributions by injecting random noise to mask individual contributions, then please write a paper on it! But to my knowledge, Cynthia Dwork's work and others still stands. There is definitely no simple, common sense reason that it doesn't work.

How does sending the same list of conditional probabilities for liking pairs of bands to everyone's device and then having the device pick out the ones actually pertinent to your library compromise your privacy?

Re: What is Differential Privacy?

#77
Seems to be a huge amount of speculative commentary, which is acknowledged, but to me, not a way that shows the potential variation in implementing DP.

For example, Apple could easily download all the data, do a DP on the impact of adding the data to the existing aggregate data, clean out indentiers, and add it to the database.

Key here is that Apple has all the data, then purges the indentiers from it, which is completely different than removing the indentifiers before sending to Apple. _______

(Apple:) "Hi, I'm Apple, Trust Me! Don't mind the black bag, I just likely being mysterious, it's cool, right?"

(Me:) "Umm, no, no thanks!" _________

Apple needs to let go of the whole security through secrecy ploy, since it looks more and more shady.

Imagine if security modules for devices where public and non-secure section of the devices had to be encapsulated for EmSec and tamper proof. If this was the case, security literally wouldn't be an issue; either everyone is impacted, or no is impacted.

Re: What is Differential Privacy?

#78
post #34
post #27

Apple backed themselves into a corner by marketing themselves as the super-privacy company in contrast to Google. The problem is that all the data collection lets you do some really useful stuff that benefits the user. So now they're spreading FUD while trying to pretend that they're not collecting the same type of data that Google does. Google has been using differential privacy for a while in different projects.

But I can't forget that Google is the company that somehow managed to suggest ads on my personal phone based on browsing on my professional PC. Theses devices are never on the same network, the only shared parameters is an exchange account. As a rule I always log-out of the only Google service I rarely use, so this must be some cookie/tracker dark magic. Sadly I have no proof, but I use gosthery to block trackers sin…

Facebook recently recommended to me a "friend" who was a person that worked at another company which was a client for my previous employer. The only means of online communication I've had with this person was through my old work email. My Facebook account uses a unique email address used only for Facebooking, I've never friended anyone from my previous employer, my demographic information is all made up (except for my name), I've set privacy controls in Facebook to be as strict as possible, I run uBlock Origin/NoScript on all browsers, I clear browser history/cookies/etc on exit...yet, here is this person being recommended to me. The lengths that these companies go to fingerprint you online is incredibly scary and creepy.

Re: What is Differential Privacy?

#79
post #40

Earlier quoted context omitted.

It's fairly straight forward - cookies + Google's ad network + Analytics on your phone allow them to track you across devices.

How would the cookie from the work get to the phone?

You don't need to rely on cookies anymore to identify someone online: https://en.wikipedia.org/wiki/Device_fingerprint

Re: What is Differential Privacy?

#80

Earlier quoted context omitted.

Yes, the data has a significant chance of being wrong. But it is useful only insofar as it supports a prediction with a probability of being right that is greater than 0.5. That's what makes the data useful and that's what makes it a privacy issue at the same time.

It doesn't have to support that prediction in specific instances, just in a general trend, where random noise tends to average itself out in a lot of cases. There are lots of different distributions with the same averages, the same conditional probablities, etc. with wildly different data. If you have some mathematical proofs that say you can not reach one of these other distributions by injecting random noise to mas…

I don't doubt the validity of Dwork's work. I think we're talking past each other.

What I'm saying is that if Apple keeps data on its servers that is sufficient to predict some of my actions or likes with any accuracy greater than 50%, then that is a privacy concern.

But if you're saying that the data in Apple's database does not have any predictive power on its own, then I agree that it is not a privacy concern.

In that case, my device would have to download some of Apple's data and combine it with data that resides only on my device in order to make a prediction locally on my device.

If that's how it works then I have no concerns.

Post reply on HN