Live data from Hacker News

Rally, a novel privacy-first data sharing platform

blog.mozilla.org

191–200 of 201 posts

Re: Rally, a novel privacy-first data sharing platform

#191

Earlier quoted context omitted.

That’s rather nihilistic. How exactly are academic researchers supposed to guarantee that their research will be applied for the good of humanity? Government is you and me and everyone else. If you want government to care about it, write to them and tell them to care about it. They probably aren’t going to care about random comments on HN. Research on ethical machines has been taking place since the dawn of the drone…

Not the OP, but no, the government doesn't and can't represent me. We are systematically locked into a two party system due to winner-takes-all voting in the USA and you seem to think that two (very similar) parties are enough for me to have representation. They aren't. It also isn't nihilistic to have a very high bar for sharing any data these days. I personally am beyond considering sharing my data and go to great…

I would refer you to the political theory of John Locke, et al., in particular the consent of the governed.

Additionally, see the UN Human Rights declaration for the most modern (as far as I am aware) descendant of that political theory.

UN Human Rights declaration has as its immediate political theory ancestor the US Declaration of Independence.

Re: Rally, a novel privacy-first data sharing platform

#192

Earlier quoted context omitted.

I don’t think it’s in any way “combative” to point out that I am indeed competent and capable of interacting with the online world safely without the assistance patronizing of strangers on the internet. And, whether your intention or not, that’s exactly what your comment was: patronizing. With undertones of “well what did you think would happen when you present yourself in such a way”. Whether you’re willing to admit…

Now that's just nuts.

I can understand that some people may disagree with and/or not understand what she said, it is both unkind and not helpful to say "Now that's just nuts." The comment does not move the conversation forward in terms of clarification or understanding. The comment does not demonstrate patience nor does it show curiosity of other perspectives.

Re: Rally, a novel privacy-first data sharing platform

#193
post #78

Earlier quoted context omitted.

> Now you can opt-in to a a Rally study where independent researchers can examine the data. It would have been great if they’d invested the resources to use Solid, here.

Thanks for mentioning this. Two questions: 1. In your experience, what is the maturity level of Solid? 2. Would you mind sketching out how you would do the integration with Solid? I'm reading over https://solidproject.org/users/get-a-pod but haven't spend a lot of brain cycles on it yet.

You’re welcome!

I’m in the same boat as you - haven’t spent many brain cycles on it yet.

Mozilla Rally would have been the perfect proof-of-concept for putting that idea to use and giving it a shakedown.

Generally, Solid seems to be pretty grounded in its attempt to resolve data sharing privacy concerns.

My understanding is that the implementations would be about the same as using browser storage.

I believe developers would need to approach data access from the perspective of “an infinitely sharded document database - shards are globally-uniquely identifiable - shards are remotely distributed - shards have their own IAM - for each shard, you must register as an authorized user and authenticate to access remote data”

Re: Rally, a novel privacy-first data sharing platform

#194
post #29

I understand there is a perfectly legitimate need and reason to do what they do. However “privacy-first data sharing” sounds like doublespeak to me. In the same vein as the famous “war is peace, freedom is slavery.”

> sounds like double speak That’s rather cynical. What’s wrong with someone wanting to share their data with certain people while also demanding that those people respect the data’s privacy?

There is nothing wrong with it.

Like I mentioned, there are perfect legitimate reasons and need to do it.

However, the best privacy practice is to never share it. If you share, then it is no longer privacy first. The goals which one wants to achieve come first. I'm not saying it will not have adequate privacy protection. But it's not "privacy first" because it introduces the risk to someone's privacy for the benefit of something. That something comes first.

Re: Rally, a novel privacy-first data sharing platform

#195

Earlier quoted context omitted.

That wasn't chastising you. I don't know you so there was no way I could have known how long you've been on the internet nor your depth in experience in identity within it. I was attempting to point out some of the bigger factors feeding into your complaint, regarding the potential of people harassing you, with the intent of no more than to bring attention to something you may have overlooked, as humans tend to do so…

I don’t think it’s in any way “combative” to point out that I am indeed competent and capable of interacting with the online world safely without the assistance patronizing of strangers on the internet. And, whether your intention or not, that’s exactly what your comment was: patronizing. With undertones of “well what did you think would happen when you present yourself in such a way”. Whether you’re willing to admit…

> And, whether your intention or not, that’s exactly what your comment was: patronizing.

E: Not quite. You perceived the comment as patronizing. This is not a universal assessment. From my point of view, I didn't find it patronizing. I'm not saying I'm right and you are wrong; I'm simply saying it is far from clear cut.

Here is one definition of patronizing that I find useful:

> apparently kind or helpful but betraying a feeling of superiority; condescending

You may think that someone else feels superior to you. That is your assessment, I respect that, and I'll listen. At the same time, it is subjective and is uncertain, because your knowledge is incomplete.

The principle of charity is useful here. I hope you can see alternative interpretations that show N does not perceive himself as superior. In particular, their commentary, in my view, is by and large very thoughtful, with the exception of a few sharp edges (which everyone has). From what I can tell, N's edgier comments came out because they felt attacked.

That's the pattern I see here. A person feels attacked and their communication becomes less charitable and even abrasive. At least two people fell into this trap in this thread. As a community, we don't benefit when this happens, but this is human nature.

The solutions are not easy. In my view, we should try to observe, be thoughtful, and attempt to deescalate tensions. I believe a vast majority of people are here for positive reasons and have plenty to learn from each other.

Re: Rally, a novel privacy-first data sharing platform

#196
post #114

Earlier quoted context omitted.

> In that sense any opt-in choice given to another is yet another privacy breach on their 'contacts' for example. That is a non-sequitor, when we are discussing opting-in to social science research. Rally is not a social network platform. It is a social science platform. There is no reason for it to be directly, as a platform, concerned with your contacts. Per their FAQ: > We abide by a series of principles known as…

>> In that sense any opt-in choice given to another is yet another privacy breach on their 'contacts' for example. That is a non-sequitor, when we are discussing opting-in to social science research. > That is a non-sequitor, when we are discussing opting-in to social science research. As I understand it, the commenter's point does not rest on 'contact' linking being present. Their point is that any kind of data link…

> As I understand it, the commenter's point does not rest on 'contact' linking being present. Their point is that any kind of data linking provides a reindentification risk.

It appears that the parent commenter revised its content to indicate that the concern was indeed “your data getting mixed with my data, when browsing Facebook”, to paraphrase.

My response there was essentially: ethical review would have to determine if all data must be provided through informed consent of all the originating humans.

Held to the gold standard of ethics, an IRB would likely have to contraindicate a research design if it did not provide a way for every individual human involved to provide informed consent. If any single individual in a data set indicated that they did not consent, then that data set would need to be reshaped to not include that individual. In lieu of that, the entire data set would have to be excluded from study.

Of course, that has some complex implications, when it comes to broad categories of data sources for browser usage: social networking sites would be a minefield. Did the website author provide consent for their content to be machine analyzed for sentiment, etc., if one really wanted to get down to it. You’d have to consider each and every resource location. Can’t assume that all browser traffic is open web traffic - someone could have left their Rally extension running while navigating to a corporate confidential network, complex copyrights, etc.

My understanding is that the US Supreme Court is about to decide on whether “if you can read it, you can keep it” as a consequence of Microsoft/LinkedIn vs. hiQ Labs, so don’t forget the “arms race” of justice, either.

> Many smart, well-meaning efforts have fallen prey to linkage attacks. They are insidious.

Indeed, even just basic double-blind medical studies are hard to defend when you consider operational security, let alone information security.

Re: Rally, a novel privacy-first data sharing platform

#197
post #127

Earlier quoted context omitted.

Sure, I understand your point. Have you dug into the problems of data linkage attacks? (see questions above)

Not yet! I’m vacuously familiar with the basics, but I’m curious about the details and their relation to research design. Will comment more fully as I find the energy.

In case it is of interest, here is a fairly short article with a short historical look at data de-identification. If nothing else, it is one jumping off point.

"Data De-identification: Possibilities, Progress, and Perils". 2019. https://forge.duke.edu/blog/data-de-identification-possibili...

Re: Rally, a novel privacy-first data sharing platform

#198
post #7

Whoever wrote this piece is way too close to... whatever it is Mozilla is doing here. There seems to be an assumption that users will be gleeful to throw their data at legitimate researchers from legitimate institutions doing legitimate work. What "data"? Browsing history? Identity? Something else? Why? What's in it for them? Since when was giving our data to third parties a good idea? There is literally no motivatio…

I was really excited for most of the time reading thinking “A privacy-first general data store that lets us donate insights for the common good, and may even end up being a marketplace where we can choose to sell data. This is so cool! I hope they have a mobile app so I can record things like what I ate for supper or how long I looked at a screen today”

But, it seems like they’re just tracking browser behaviour, and there’s absolutely zero place for people to add their own data?

Why bother giving it a branded name then? Why not “crowd-sourced browser behaviour study in partnership with ____”?

Re: Rally, a novel privacy-first data sharing platform

#199
post #194

Earlier quoted context omitted.

> sounds like double speak That’s rather cynical. What’s wrong with someone wanting to share their data with certain people while also demanding that those people respect the data’s privacy?

There is nothing wrong with it. Like I mentioned, there are perfect legitimate reasons and need to do it. However, the best privacy practice is to never share it. If you share, then it is no longer privacy first. The goals which one wants to achieve come first. I'm not saying it will not have adequate privacy protection. But it's not "privacy first" because it introduces the risk to someone's privacy for the benefit…

> But it's not "privacy first" because it introduces the risk to someone's privacy for the benefit of something. That something comes first.

It certainly isn’t “privacy last” or “privacy later”, either, shall we call it “privacy enforced” or “privacy now”?

Re: Rally, a novel privacy-first data sharing platform

#200
post #169

Earlier quoted context omitted.

My reply predates this edit from the parent: > Sorry, I definitely did not put as much thought into my comment as I should have and I left out the critical piece of information that really ticked me off.

Such are the perils of edit logs not being available and/or not quoting what you are responding to.

TBF, if the stuff that would have needed to be quoted was added after he replied...
Post reply on HN