Live data from Hacker News

What is Differential Privacy?

blog.cryptographyengineering.com

101–108 of 108 posts

Re: What is Differential Privacy?

#101
post #99

This is something Apple really needs to release all the details of. Even if they got the crypto exactly right, they could have picked a privacy budget/ security parameters that just leaks everything. And there is every reason to be skeptical about Apple's ability to design even mildly complex crypto given iMessage's flaws. Although the break in iMessage wasn't practically exploitable, that was luck and the fact that…

Apple have designed/implemented several quite successful crypto and security systems too.

What have they actually designed from scratch? Most of what comes to mind (Facetime, filevault) it is off the shelf stuff/ at least there were well known designs to ape which had been subject to analysis. This, well if they just copied what google did, then maybe.

But at some level, my comment is pretty harsh on Apple when they have a better track record than most for privacy and encryption. But remember, this is Apple making you less secure by grabbing data and then saying they took care of the issue.

With iMessage, Facetime, Filefault, if it failed, you were were no worse off than if you used something else. In this case, you actually are. That means there is a higher burden to getting it right than just name dropping magic crypto pixie dust.

Re: What is Differential Privacy?

#102
post #27

Apple backed themselves into a corner by marketing themselves as the super-privacy company in contrast to Google. The problem is that all the data collection lets you do some really useful stuff that benefits the user. So now they're spreading FUD while trying to pretend that they're not collecting the same type of data that Google does. Google has been using differential privacy for a while in different projects.

Agreed. I find it vastly amusing to hear praise for Apple because they're applying some sort of obfuscation to the telemetry they collect ("Proprietary and totally secret, of course. Oh, what telemetry is Apple collecting? That's secret too but, trust us, Apple cares about your privacy.") and yet people are up in arms about Windows 10 telemetry and little, if anything, is ever said about the telemetry collected by An…

I agree, I just wanted to point out that it is slightly different, as historically microsoft has had a "pay us and we dont care what you do" (my words) agreement with users, whereas google has always been a free and ad supported company. But yeah there is a triple standard here.

Re: What is Differential Privacy?

#103
post #10

Earlier quoted context omitted.

The point of differential privacy is to allow for aggregate analysis, without destroying the privacy of outliers. Researchers deal with noise all the time, so is it so odd that a field of researchers believe that adding enough noise to data released with studies will allow for conclusive analysis without ruining privacy for individuals?

As someone with access to data on 50 million patients and having studied aggregation of medical data for last 5 years I can assure you that its not easy as it sounds. The amount of noise that "theoretically guarantees" privacy protection in terms of epsilon renders any reasonable analysis impossible. E.g. How about CDC telling you that there are 0 - 2000 cases of Ebola in Massachusetts. There are theoretical guarante…

0-2000 in a population of 3.6 million does not seem unreasonable to me.

Re: What is Differential Privacy?

#104

Earlier quoted context omitted.

As someone with access to data on 50 million patients and having studied aggregation of medical data for last 5 years I can assure you that its not easy as it sounds. The amount of noise that "theoretically guarantees" privacy protection in terms of epsilon renders any reasonable analysis impossible. E.g. How about CDC telling you that there are 0 - 2000 cases of Ebola in Massachusetts. There are theoretical guarante…

0-2000 in a population of 3.6 million does not seem unreasonable to me.

Sure, but you are neither a doctor nor an infectious medicine specialist.

Its trained doctors and researchers who get to decide quality of medical evidence. There is a reason why we have detailed set of protocols and levels used for assessment of evidence.

http://www.cebm.net/oxford-centre-evidence-based-medicine-le...

Re: What is Differential Privacy?

#105
post #99

Earlier quoted context omitted.

Apple have designed/implemented several quite successful crypto and security systems too.

What have they actually designed from scratch? Most of what comes to mind (Facetime, filevault) it is off the shelf stuff/ at least there were well known designs to ape which had been subject to analysis. This, well if they just copied what google did, then maybe. But at some level, my comment is pretty harsh on Apple when they have a better track record than most for privacy and encryption. But remember, this is App…

> With iMessage, Facetime, Filefault, if it failed, you were were no worse off than if you used something else. In this case, you actually are.

What would someone be better off using?

Re: What is Differential Privacy?

#106
post #34

Earlier quoted context omitted.

But I can't forget that Google is the company that somehow managed to suggest ads on my personal phone based on browsing on my professional PC. Theses devices are never on the same network, the only shared parameters is an exchange account. As a rule I always log-out of the only Google service I rarely use, so this must be some cookie/tracker dark magic. Sadly I have no proof, but I use gosthery to block trackers sin…

Facebook recently recommended to me a "friend" who was a person that worked at another company which was a client for my previous employer. The only means of online communication I've had with this person was through my old work email. My Facebook account uses a unique email address used only for Facebooking, I've never friended anyone from my previous employer, my demographic information is all made up (except for m…

It's possible that the person being recommended has lax settings.

Connections are a two way street. Facebook can assume that if he has connections to you, then you may have a connection to them.

Nothing nefarious is necessary.

Re: What is Differential Privacy?

#107
post #105

Earlier quoted context omitted.

What have they actually designed from scratch? Most of what comes to mind (Facetime, filevault) it is off the shelf stuff/ at least there were well known designs to ape which had been subject to analysis. This, well if they just copied what google did, then maybe. But at some level, my comment is pretty harsh on Apple when they have a better track record than most for privacy and encryption. But remember, this is App…

> With iMessage, Facetime, Filefault, if it failed, you were were no worse off than if you used something else. In this case, you actually are. What would someone be better off using?

Something that didn't report these statistics. An old version of IOS for one. Does android do this type of reporting?

Re: What is Differential Privacy?

#108

Earlier quoted context omitted.

You say that despite this privacy push being a direct response to consumer sentiments. Apple knows well that as tech becomes wearables and the Internet of things, privacy concerns skyrocket. My grandparents won't buy things online. Soon my generation will be those old and anxious curmudgeons unless our concerns are eased. Do they care about their bottom line? Of course. It's for that very reason they are investing th…

This 'push' is just another unprovable unverifiable marketing bs that is just enough for the type of audience they attract until it's all opened to FS licenses and hardware is made to accept any software that user wants it to (like it should if you bought it).

Agreed. Apple is only doing as much security as they reasonably needed to satisfy customers. Most customers don't understand the various types of suffering (and suffering risk I might add) caused by software, but large companies do. Large companies end up "making decisions" for users en masse. This is fine for button placement but falls apart logically when presented in a discussion based on trusted infrastruture. You will note that liquidse's response is conflicted. Those rationalizations are the indicators of dissonance in the privacy debate.
Post reply on HN