Live data from Hacker News

Blacklight – A Real-Time Website Privacy Inspector

themarkup.org

101–106 of 106 posts

Re: Blacklight – A Real-Time Website Privacy Inspector

#101

Earlier quoted context omitted.

To simplify the bookkeeping. When all data about me is mine, everything else falls into place.

This doesn't simply it, it complicates it. With privacy, you are generally looking to prevent the redistribution of facts , but only in specific circumstances. Copyright does a very different thing, where it only prevents the redistribution of more creative expressions, but does so in broad circumstances. If you take the typical data elements that you want to keep private and apply copyright law to them, I think you'…

Great reply, thanks.

How is collecting, aggregating, redistributing PII prevented today?

I like that you distinguish voluntary sharing, eg with friends and family.

I'll ponder your point about names (identifiers). There are currently semi-legitimate uses, like political campaigns in the USA have voter files for GOTV (ballot chasing). Which is a ridiculous practice. (I've worked on many campaigns.) So instead of accommodating pathological use cases, I'd rather resolve the paradox by eliminating the practice. In the case of GOTV, compulsory voting would greatly improve voter privacy.

I've been waiting for anyone to criticize my thesis by pointing out the government already knows all. My provisional response remains: If someone's making a buck off my data, I want my cut.

In cases like the CA State's DMV reselling PII, my thesis is that treating my data as an asset, and therefore a liability, would deter that behavior. So relying on disincentives vs prohibition.

Re: Blacklight – A Real-Time Website Privacy Inspector

#102

Earlier quoted context omitted.

This doesn't simply it, it complicates it. With privacy, you are generally looking to prevent the redistribution of facts , but only in specific circumstances. Copyright does a very different thing, where it only prevents the redistribution of more creative expressions, but does so in broad circumstances. If you take the typical data elements that you want to keep private and apply copyright law to them, I think you'…

Great reply, thanks. How is collecting, aggregating, redistributing PII prevented today? I like that you distinguish voluntary sharing, eg with friends and family. I'll ponder your point about names (identifiers). There are currently semi-legitimate uses, like political campaigns in the USA have voter files for GOTV (ballot chasing). Which is a ridiculous practice. (I've worked on many campaigns.) So instead of accom…

> How is collecting, aggregating, redistributing PII prevented today?

The handful of privacy laws today (HIPAA, CCPA, GDPR) take a pretty direct approach; they define:

* the types of organizations that are restricted from sharing PII

* the types of collection, retention, and sharing that is allowed and/or prohibited

* the definition of PII -- which specific attributes about a person are protected

> In cases like the CA State's DMV reselling PII, my thesis is that treating my data as an asset, and therefore a liability, would deter that behavior. So relying on disincentives vs prohibition.

It seems to me the CCPA could have prevented that -- if it applied to governments as well as "businesses".

Re: Blacklight – A Real-Time Website Privacy Inspector

#103

Earlier quoted context omitted.

Great reply, thanks. How is collecting, aggregating, redistributing PII prevented today? I like that you distinguish voluntary sharing, eg with friends and family. I'll ponder your point about names (identifiers). There are currently semi-legitimate uses, like political campaigns in the USA have voter files for GOTV (ballot chasing). Which is a ridiculous practice. (I've worked on many campaigns.) So instead of accom…

> How is collecting, aggregating, redistributing PII prevented today? The handful of privacy laws today (HIPAA, CCPA, GDPR) take a pretty direct approach; they define: * the types of organizations that are restricted from sharing PII * the types of collection, retention, and sharing that is allowed and/or prohibited * the definition of PII -- which specific attributes about a person are protected > In cases like the…

I've been keen to see how the GDPR and CCPA play out. Hopefully better than HIPAA, FERPA, etc.

Providence Hospital in Portland OR (details?) had a big (for the time) data leak about the time I started doing medical records. They settled out of court. I contacted both sides and tried to reach the admins, to ask what fix they settled on.

"Try harder next time."

Terrific.

We geeks creating the infrastructure for electronic medical record interchanges resigned ourselves to the inevitable massive data leak. I spent a lot of effort trying to figure out how to protect patient privacy.

I eventually determined there's only one technical solution, based on strategies from Translucent Databases book. (TLDR: field level encryption for all data at rest, just like proper password storage.)

But there's no social, legal, or cultural protection. And the small legal change (globally unique person identifiers) we'd have to do for the sole workable technical solution is strenuously opposed across the political spectrum.

So. My plan now is to rethink the entire stack. Extend property rights to PII. Let accounting fix what algorithms couldn't.

If someone divines a better plan, I'm totally on board. As in "shut up and take my money". But I'm not holding my breath.

FWIW, one of my besties wrote a book on privacy. My proposal makes his head explode. Apoplectic. So I get the push back. But 15 years later, no one, including him, have a better idea. Better as in feasible, actionable.

If you've got something, please share.

Re: Blacklight – A Real-Time Website Privacy Inspector

#104

Earlier quoted context omitted.

> How is collecting, aggregating, redistributing PII prevented today? The handful of privacy laws today (HIPAA, CCPA, GDPR) take a pretty direct approach; they define: * the types of organizations that are restricted from sharing PII * the types of collection, retention, and sharing that is allowed and/or prohibited * the definition of PII -- which specific attributes about a person are protected > In cases like the…

I've been keen to see how the GDPR and CCPA play out. Hopefully better than HIPAA, FERPA, etc. Providence Hospital in Portland OR (details?) had a big (for the time) data leak about the time I started doing medical records. They settled out of court. I contacted both sides and tried to reach the admins, to ask what fix they settled on. "Try harder next time." Terrific. We geeks creating the infrastructure for electro…

That's an interesting idea -- property rights for PII.

Of the four main IP types we have today, PII is probably most similar to trade secrets. Maybe since companies have rights to their secret information -- we could recognize a 5th type of IP for PII, similar to trade secrets, but for individuals?

Re: Blacklight – A Real-Time Website Privacy Inspector

#105

Earlier quoted context omitted.

I've been keen to see how the GDPR and CCPA play out. Hopefully better than HIPAA, FERPA, etc. Providence Hospital in Portland OR (details?) had a big (for the time) data leak about the time I started doing medical records. They settled out of court. I contacted both sides and tried to reach the admins, to ask what fix they settled on. "Try harder next time." Terrific. We geeks creating the infrastructure for electro…

That's an interesting idea -- property rights for PII. Of the four main IP types we have today, PII is probably most similar to trade secrets. Maybe since companies have rights to their secret information -- we could recognize a 5th type of IP for PII, similar to trade secrets, but for individuals?

I support anything remotely similar to what you're proposing.

I just can't get over the case of Henrietta Lacks.

https://en.wikipedia.org/wiki/Henrietta_Lacks

TLDR: The immortal cells central to cancer research are hers. Unacknowledged. The debt we owe this woman is immeasurable. Yet she and her family have no claim.

How many more Lacks are there?

There's a wide band between a record of my shopping habits and this woman's genetic code. But the principle is the same. If someone's making a buck off my data, I want my cut.

Post reply on HN