Live data from Hacker News

A radical proposal to keep your personal data safe

theguardian.com

11–20 of 128 posts

Re: A radical proposal to keep your personal data safe

#11

Obviously this proposal will be rejected because both companies and governments are addicted to the power to control and manipulate that data gives them. We need a strong leader who will go against the grain of these massive entrenched interests and be willing to stand up to the media onslaught such a stance will bring. The mainstream media will attack anyone who threatens their advertising based business model. When…

Simply put, never.

Future strong leaders will employ all of those means of deep state surveillance and invest in new ones in order to remain strong.

That cats out of the bag and it ain’t going back.

Re: A radical proposal to keep your personal data safe

#12
post #10
post #3

The article raises good points. One important aspect is missing though; the reliance on web services, SaaS, and the like. Free software is not enough. We need free software that runs locally and offline.

RMS is also against SaaS (or Software as a Service Substitute, SaaSS), but AGPLv3 SaaS would be a step in the right direction. At least then you could examine the source code and see what data is collected. Edit: s/GPL/AGPL/

The source you directly interact with perhaps. Can you say for sure that the code running at the server end is the one in the repo or tarball?

Re: A radical proposal to keep your personal data safe

#13

Obviously this proposal will be rejected because both companies and governments are addicted to the power to control and manipulate that data gives them. We need a strong leader who will go against the grain of these massive entrenched interests and be willing to stand up to the media onslaught such a stance will bring. The mainstream media will attack anyone who threatens their advertising based business model. When…

1. We don't need a strong leader. Fascism and authoritarianism have zero interest in the privacy of citizens. Never had, never will.

2. Power corrupts, so the overall answer is: never.

Re: A radical proposal to keep your personal data safe

#14
post #6
post #3

The article raises good points. One important aspect is missing though; the reliance on web services, SaaS, and the like. Free software is not enough. We need free software that runs locally and offline.

When it's RMS, free means Free (under Libre terms) & Open Source. And yes, I agree; back to local and offline first applications is a must.

Best i understand, open source it charitably seen as a subset of the freedoms fronted by the FSF.

If you claim that RMS does open source in his presence, he will sternly correct you.

Re: A radical proposal to keep your personal data safe

#15
post #10
post #3

The article raises good points. One important aspect is missing though; the reliance on web services, SaaS, and the like. Free software is not enough. We need free software that runs locally and offline.

RMS is also against SaaS (or Software as a Service Substitute, SaaSS), but AGPLv3 SaaS would be a step in the right direction. At least then you could examine the source code and see what data is collected. Edit: s/GPL/AGPL/

That sounds like exactly the Affero GPL.

Re: A radical proposal to keep your personal data safe

#16
post #10

Earlier quoted context omitted.

RMS is also against SaaS (or Software as a Service Substitute, SaaSS), but AGPLv3 SaaS would be a step in the right direction. At least then you could examine the source code and see what data is collected. Edit: s/GPL/AGPL/

The source you directly interact with perhaps. Can you say for sure that the code running at the server end is the one in the repo or tarball?

Of course not, but the same can be said for local software. You usually don't build from source. But at least you can inspect your own network traffic more or less reliably.

Having everything be AGPLv3 is not perfect, but I think it would be an improvement over the current state of affairs.

Re: A radical proposal to keep your personal data safe

#17

We need new business models which depend on user-owned data, rather than treating privacy like a charitable contribution for saving the trees. Instead of citizens sending data to the cloud, corporations can send code to citizen-owned devices where local computation can take place, with data only leaving via an open-source content inspection engine that enforces citizen-consent policy.

You mean something like this?:

https://ruben.verborgh.org/blog/2017/12/20/paradigm-shifts-f...

Re: A radical proposal to keep your personal data safe

#18
post #10

Earlier quoted context omitted.

RMS is also against SaaS (or Software as a Service Substitute, SaaSS), but AGPLv3 SaaS would be a step in the right direction. At least then you could examine the source code and see what data is collected. Edit: s/GPL/AGPL/

That sounds like exactly the Affero GPL.

Whew, I confused those. Thanks for pointing that out

Re: A radical proposal to keep your personal data safe

#19
> Video cameras should make a local recording that can be checked for the next few weeks if a crime occurs, but should not allow remote viewing without physical collection of the recording.

it would suck if the terrorist bomb also took out the cameras themselves.

I have cameras at my house wired to a local unit. It's mostly for convenience and looking for animals and not very serious for security; any well-respecting house prowler would want to take the recording unit from my server area so that I wouldn't have any video of who broke into my house.

Re: A radical proposal to keep your personal data safe

#20

I wish we could find a way to apply the model of the vending machine to mass commerce. A vending machine doesn't make notes of who buys its products. A vending machine doesn't keep logs of its transactions or of the payment methods used. A vending machine does not make "recommendations" of what the consumer might like based on their past purchases. You give the vending machine a dollar, it gives you a soda. The trans…

It sounds like you are describing the problem of trust. In a vending machine, you trust the brands to deliver a standardized product. You know what you are buying ahead of time with no doubt at all. the cost is also low enough that you trust the delivery mechanism within a given level of risk tolerance. Finally, you don't expect the product to last, it is a consumable by nature, so no relationship needs to exist - your relationship is with the brand, not the individual can of soda. If you choose to give the soda away, the person you gave it do also knows what they are getting, and the brand doesn't care who drinks the soda.

To take your laptop example, though, you may trust the brand, but, you expect it to last. therefore, your relationship is with the brand AND the product. You will need to service that laptop, and they, as the vendor will need to set parameters around what services they will and will not provide in which circumstances. They have a kind of "contract" with you that doesn't necessarily extend beyond you. In fact, there are some situations with a laptop where giving it away to the wrong person could be a crime.

My only question is: if we could "solve" this problem, would we actually want to? Do we really want to make every interaction we have into some kind of transaction, with no obligations beyond payment for goods? I don't think so. I think most of our consumer protection laws have been developed to protect consumers from the considerable costs that such a system will create - warranties, lemon laws, etc. Critically, all aimed at improving the amount of trust between brands and consumers.

Instead, I think we probably need to more carefully define what kind of trust is required, and what the covenants of brand/consumer trust actually include regarding data. GDPR is an admirable model, and probably a step in the right direction, but certainly not a perfect effort.

Post reply on HN