Live data from Hacker News

Privacy concerns are breaking the Census

slowboring.com

21–30 of 80 posts

Re: Privacy concerns are breaking the Census

#21
If the census simply enumerated the population, then I don't think there are the same level of concerns.

The data they are collecting related to demographics is beyond what is necessary for congressional apportionment. If they collected only the required data; then there would not be a need to fuzz it.

Re: Privacy concerns are breaking the Census

#22
Our family of 5 lives in a certain state where politics are very one-sided.

The Census tried to move heaven and earth to contact us. We avoided them like the plague.

Imagine my surprise when i heard that our state had lost a house seat, due to being 80 people short of the required population count to keep its prior state house seat apportionment.

By avoiding the Census, we were able to change the machine of bureacuracy far better than by regular voting.

Sometimes the winning move, is really not to play.

Re: Privacy concerns are breaking the Census

#23
post #17

> unless you are a weirdo living off the grid, basic Census-style information about where you live, your age, marital status, and race and gender identities is widely available to commercial actors. Being able to doxx with PII was shown to be able to be done in the suburbs, so this is more accurately phrased as "anyone in low-density suburbs and below are at-risk." If the author doesn't care about that, then just say…

The author doesn't care about that and says it pretty clearly. He doesn't (and I don't) think that it makes sense to think in terms of "deanonymization attacks" here, since your legal name, address, and basic demographic information are already semi-publicly linked together in a large variety of ways. Is it deanonymization if I go to the county registrar and pull the deed for someone's house?

Re: Privacy concerns are breaking the Census

#24
It seems as thought this author has never read any materials on inference control...

Ross Anderson's Security Engineering Chapter 9 is all about this https://www.cl.cam.ac.uk/~rja14/Papers/SEv2-c09.pdf (Anderson releases the textbook free online)

This is a fairly well developed field (i.e., in medicine there highly screened "Medical Statisticians" who give data to research groups only after it's properly anonymized. They know beforehand what the researchers are interested in, and introduce noise that effects all the measures _except_ the ones the researchers said they were interested in looking at beforehand.

> The idea behind the differential privacy strategy, as I understand it, is that you can basically introduce statistical noise into the block-level results in a way that will make it impossible to reverse-engineer the demographic profile of people who live at specific addresses.

>This has, I think, roughly zero real-world privacy value

This was painful to read...

Re: Privacy concerns are breaking the Census

#25
post #15

I have similar hesitations about registering to vote in my state (North Carolina) because it makes voter record data available to “Any person upon request and for a fee. Free lists are provided upon request to political parties.” [1]. My name, address, etc. ended up on dozens of sketchy websites after registering to vote previously. Privacy conscious legislation can’t come soon enough. [1]: https://www.ncsl.org/resea…

If the government knows it, the same data should be available to all citizens. Traffic camera feeds, voter data, medicare claims, everything. With minor, very narrow restrictions for the very latest military secrets.

You don't see any practical issues with that approach..? Do you know how much personal information is in a medicare claim?

Re: Privacy concerns are breaking the Census

#26
post #17

> unless you are a weirdo living off the grid, basic Census-style information about where you live, your age, marital status, and race and gender identities is widely available to commercial actors. Being able to doxx with PII was shown to be able to be done in the suburbs, so this is more accurately phrased as "anyone in low-density suburbs and below are at-risk." If the author doesn't care about that, then just say…

The author doesn't care about that and says it pretty clearly. He doesn't (and I don't) think that it makes sense to think in terms of "deanonymization attacks" here, since your legal name, address, and basic demographic information are already semi-publicly linked together in a large variety of ways. Is it deanonymization if I go to the county registrar and pull the deed for someone's house?

I fixed the link, sorry about that.

You can deanonymize block level data and the study shows as much. You just need to have some amount of information that is either unique or low enough in distribution.

There's a tutorial on Twitter if you'd like to follow: https://mobile.twitter.com/john_abowd/status/111494218027827...

Re: Privacy concerns are breaking the Census

#27
The Census has really lost the thread. The original mission was simply to do a headcount to determine how many representatives and electoral votes each state was entitled to.

One thing that annoyed me in particular was their creepy obsession around race. Even once you answer, "White", there are several more questions aimed at determining precisely what subcategory of white person you are.

If anyone at the census is listening, here's some advice. If you only get to ask Americans a handful of question once every ten years, don't waste half of them trying to figure out someone's 50 shades of whiteness.

Re: Privacy concerns are breaking the Census

#28
post #27

The Census has really lost the thread. The original mission was simply to do a headcount to determine how many representatives and electoral votes each state was entitled to. One thing that annoyed me in particular was their creepy obsession around race. Even once you answer, "White", there are several more questions aimed at determining precisely what subcategory of white person you are. If anyone at the census is l…

This is important for understanding how gerrymandered a district is.

Re: Privacy concerns are breaking the Census

#29

It seems as thought this author has never read any materials on inference control... Ross Anderson's Security Engineering Chapter 9 is all about this https://www.cl.cam.ac.uk/~rja14/Papers/SEv2-c09.pdf (Anderson releases the textbook free online) This is a fairly well developed field (i.e., in medicine there highly screened "Medical Statisticians" who give data to research groups only after it's properly anonymized.…

There is an enormous practical difference between allowing inference of medical conditions (PHI deidentification) and allowing in edge cases the inference of information that is already available in public voter registration rolls.

Re: Privacy concerns are breaking the Census

#30
post #17

> unless you are a weirdo living off the grid, basic Census-style information about where you live, your age, marital status, and race and gender identities is widely available to commercial actors. Being able to doxx with PII was shown to be able to be done in the suburbs, so this is more accurately phrased as "anyone in low-density suburbs and below are at-risk." If the author doesn't care about that, then just say…

The author doesn't care about that and says it pretty clearly. He doesn't (and I don't) think that it makes sense to think in terms of "deanonymization attacks" here, since your legal name, address, and basic demographic information are already semi-publicly linked together in a large variety of ways. Is it deanonymization if I go to the county registrar and pull the deed for someone's house?

The census contains some data that commercial databases are legally prohibited from holding (e.g., info about children within a household).

The deanonymization/reidentification attacks rely on joining census data against commercial datasets to produce something beyond what either contains. It's not accurate to say this information is already semi-public, because a good deal of it is not.

Post reply on HN