Live data from Hacker News

‘I've got nothing to hide’ and other misunderstandings of privacy (2007)

papers.ssrn.com

251–260 of 293 posts

Re: ‘I've got nothing to hide’ and other misunderstandings of privacy (2007)

#251
post #246

Earlier quoted context omitted.

How many people do you think is an acceptable level of loss for cars to be justified? How many people need to die because their medical information wasn't available quickly enough to deliver life saving treatment in time? Pedophiles are walking free right now because the criminal justice system can't gain access to their computers to prove what it otherwise painfully obvious; they're hurting children. I can make exac…

> but pretending like any loss at all is unacceptable, such as you're doing here, is a farce. There's a weird transformation that this conversation has gone through. As a reminder it started out with you saying "besides, doomsaying that 'anything could be illegal!' isn’t backed by anything real or lasting." Which is just false. And I'm not sure where I or frankly anyone else in this thread has suggested that even jus…

The negative consequences of incomplete privacy are certainly real, they’re just not nearly as numerous as you seem to believe.

I can and I will dismiss the kinds of privacy concerns that rely on me being unable to understand how risk works, that rely on me falsely believing a solution to any problem exists with zero downside, that rejects any decision that has even one casualty.

I tried to show you how futile a game of, “your idea hurts people” is, but you seem incapable of moving past it. What a shame.

Re: ‘I've got nothing to hide’ and other misunderstandings of privacy (2007)

#252
post #2

I’m wondering: is there a good list of data privacy failure consequences? There are good lists of breaches but few describing what happened to the people afterwards. Credit card theft resulting in a loss being the most obvious one. Such concrete (real) examples would help me to argue with people who say: all this non-sense about data privacy. What would anyone want to do with your data anyways?

Amy Boyer ?

Re: ‘I've got nothing to hide’ and other misunderstandings of privacy (2007)

#253

Earlier quoted context omitted.

[dead]

To my fake name (from family and friends), anything official goes to the mailbox at my real address to which I have access to. But that rarely happens thanks to e-government. Because of presumed delivery, there's no benefit in receiving that kind of mail on paper, so I opted-in. For e-mail, I use a domain with a catch-all mailbox. I rot13 the service name or whatever in the local-part to identify where the e-mail got…

[dead]

Re: ‘I've got nothing to hide’ and other misunderstandings of privacy (2007)

#254
post #187
post #112

Earlier quoted context omitted.

My version of this is “Just go ahead and send me your browser history, I’ll wait.”

Tbh most people who use Chrome already send it to Google. The ISP can only see the domain name. Google can see the full url. But it's so convenient to sync browsing history between multiple devices, apparently.

This is probably true, but I’d bet the ‘nothing to hide’ crowd don’t know it.

Re: ‘I've got nothing to hide’ and other misunderstandings of privacy (2007)

#255
post #251

Earlier quoted context omitted.

> but pretending like any loss at all is unacceptable, such as you're doing here, is a farce. There's a weird transformation that this conversation has gone through. As a reminder it started out with you saying "besides, doomsaying that 'anything could be illegal!' isn’t backed by anything real or lasting." Which is just false. And I'm not sure where I or frankly anyone else in this thread has suggested that even jus…

The negative consequences of incomplete privacy are certainly real, they’re just not nearly as numerous as you seem to believe. I can and I will dismiss the kinds of privacy concerns that rely on me being unable to understand how risk works, that rely on me falsely believing a solution to any problem exists with zero downside, that rejects any decision that has even one casualty. I tried to show you how futile a game…

Holy crud, HN has been weird lately :) So I learned today that suggesting Facebook should encrypt its messenger app is actually just me embracing a fantasy about the nature of safety and risk.

I don't know I feel like you're probably 3 messages away from telling me that I should remove my smoke alarms from my house because house fires are uncommon and then calling me deluded because I wear a helmet when I go biking. I didn't realize that me taking 30 seconds to install Signal and then using it to chat with my friends was a futile rebellion against the natural order ;)

Okay apologies, I really don't mean to be snarky. But you've taken this conversation in a very strange direction that I don't think is representative of what anyone who rejects the "I have nothing hide" narrative actually believes. I would just point out once again, I am less pseudonymous than you are right now. I'm using my real name, I have more contact information listed on my profile. Very obviously I am willing to publish information about myself. So the context of this conversation really just does not align with this view you've gotten that the people disagreeing with you are just privacy absolutists who think any privacy risk at all is too large to take.

If you're saying that someone is rejecting all risk and refusing to accept a privacy system with any downside, and at the same time you notice that they're actively and deliberately publishing their real name and email address, then that should give you pause and it should make you step back and think, "maybe I don't understand what their argument is." Maybe when that person points out that risks exist they're saying something more than "any risk is too much risk".

Re: ‘I've got nothing to hide’ and other misunderstandings of privacy (2007)

#256
post #251

Earlier quoted context omitted.

The negative consequences of incomplete privacy are certainly real, they’re just not nearly as numerous as you seem to believe. I can and I will dismiss the kinds of privacy concerns that rely on me being unable to understand how risk works, that rely on me falsely believing a solution to any problem exists with zero downside, that rejects any decision that has even one casualty. I tried to show you how futile a game…

Holy crud, HN has been weird lately :) So I learned today that suggesting Facebook should encrypt its messenger app is actually just me embracing a fantasy about the nature of safety and risk. I don't know I feel like you're probably 3 messages away from telling me that I should remove my smoke alarms from my house because house fires are uncommon and then calling me deluded because I wear a helmet when I go biking.…

You compared using Whatsapp to wearing a seatbelt; the problem with this analogy is that many, MANY more people die in car accidents than from... whatever abstract value me using Whatsapp will provide you, a complete stranger.

You're failing to understand that the conversation does not end just because someone is harmed by something. You, and society generally, do not consider "one single negative outcome" to be enough of a reason to not do anything.

We can't get past this. You must either accept this as an observation about reality, or you will not understand whatever other direction this conversation may go.

Re: ‘I've got nothing to hide’ and other misunderstandings of privacy (2007)

#257
post #256

Earlier quoted context omitted.

Holy crud, HN has been weird lately :) So I learned today that suggesting Facebook should encrypt its messenger app is actually just me embracing a fantasy about the nature of safety and risk. I don't know I feel like you're probably 3 messages away from telling me that I should remove my smoke alarms from my house because house fires are uncommon and then calling me deluded because I wear a helmet when I go biking.…

You compared using Whatsapp to wearing a seatbelt; the problem with this analogy is that many, MANY more people die in car accidents than from... whatever abstract value me using Whatsapp will provide you , a complete stranger. You're failing to understand that the conversation does not end just because someone is harmed by something. You, and society generally, do not consider "one single negative outcome" to be eno…

> You, and society generally, do not consider "one single negative outcome" to be enough of a reason to not do anything.

Like I said, this is a completely incorrect reading of my position, and it should be obvious to you that it's incorrect because I'm taking privacy risks right now. If I believed that "a single negative outcome" was enough privacy risk to justify not doing something, I wouldn't be talking to you right now, I'd be living in the woods and shooting drones out of the sky. But I'm not, so very clearly you are missing something about my views.

> whatever abstract value me using Whatsapp will provide you, a complete stranger.

Collective usage of E2EE makes it easier for other people to blend into the crowd and makes usage of E2EE messaging less suspicious. This is not exactly hard to understand and it's not abstract. It's the same reason why many cisgender people list pronouns when filling out profiles on new services -- it's a very low-cost way to make it so that transgender users aren't singling themselves out.

Collective normalization of E2EE also encourages people who aren't technically inclined and who are just following network effects to switch over to better messengers, which makes them safer without forcing them to become privacy experts.

And of course, when we talk about the "nothing to hide" fallacy, we mean more than "your actions as a stranger benefit me" -- we're pointing out that the risk analysis most people do about privacy risks is flawed and over-optimistic and advising you that you might want to redo that risk analysis. For comparison, you wearing a helmet when you ride your bicycle won't keep me safe, but the safety benefits to you outweigh the downsides and you should still probably wear one anyway. Because people feel invincible about accidents even though they're very much not.

Re: ‘I've got nothing to hide’ and other misunderstandings of privacy (2007)

#258
post #256

Earlier quoted context omitted.

You compared using Whatsapp to wearing a seatbelt; the problem with this analogy is that many, MANY more people die in car accidents than from... whatever abstract value me using Whatsapp will provide you , a complete stranger. You're failing to understand that the conversation does not end just because someone is harmed by something. You, and society generally, do not consider "one single negative outcome" to be eno…

> You, and society generally, do not consider "one single negative outcome" to be enough of a reason to not do anything. Like I said, this is a completely incorrect reading of my position, and it should be obvious to you that it's incorrect because I'm taking privacy risks right now. If I believed that "a single negative outcome" was enough privacy risk to justify not doing something, I wouldn't be talking to you rig…

Your argument relies on "one single negative outcome" to be enough of a reason not to do anything. Obviously I know you live incongruously with your argument; that's my entire point! Glad you're figuring that out, but that doesn't mean your argument suddenly has merit, just because you're aware of how bad it is.

I'm not missing anything, you're just failing to resolve your internal inconsistency.

Re: ‘I've got nothing to hide’ and other misunderstandings of privacy (2007)

#259
post #258

Earlier quoted context omitted.

> You, and society generally, do not consider "one single negative outcome" to be enough of a reason to not do anything. Like I said, this is a completely incorrect reading of my position, and it should be obvious to you that it's incorrect because I'm taking privacy risks right now. If I believed that "a single negative outcome" was enough privacy risk to justify not doing something, I wouldn't be talking to you rig…

Your argument relies on "one single negative outcome" to be enough of a reason not to do anything. Obviously I know you live incongruously with your argument; that's my entire point! Glad you're figuring that out, but that doesn't mean your argument suddenly has merit, just because you're aware of how bad it is. I'm not missing anything, you're just failing to resolve your internal inconsistency.

Look, your risk analysis of privacy harms does not become accurate just because you say it is. Saying that this is "one single negative outcome" a bunch of times doesn't make it true.

Pretty much the entirety of recorded human history backs up the idea that privacy matters, including the present where state governments are currently campaigning hospitals and social platforms to identify transgender people and to prosecute abortions.

Your risk analysis is wrong. That's what people are pointing out to you. We're not privacy absolutists, obviously we are not privacy absolutists. We are not suddenly having a realization about incongruity, it's honestly just really silly to suggest that this entire disagreement boils down to me seeing one trans person die and suddenly thinking "never again, no cost is too great." Take a step back out of the weeds and think about whether it's actually likely that anyone believes that :) That is not and has never been the argument, I haven't seen anyone in this entire thread even in sibling comments make that argument.

What we've all been pointing out is that the eventual arc of justice in the universe is unhelpful to people who are suffering right now, and that your risk analysis about the likelihood of people being put into that position is wrong. But go on, tell me again that this is actually a deep philosophical disagreement and I haven't internalized that safety measures involve tradeoffs.

Re: ‘I've got nothing to hide’ and other misunderstandings of privacy (2007)

#260
One of the biggest problem I see with surveillance is not the breach of privacy, but incompetence.

See, I live in Pakistan, where we have mandatory ID cards that are required for anything, and the data of which has been leaked, and where you literally don't have a right to privacy, or any other rights, for that matter.

So I have no delusion that I have any privacy whatsoever from the government, and frankly I damn care because, after all, it's not like I've done or said anything wrong, I self-censor myself quite strictly.

What I fear are mistakes in data collection.

Sometime ago, I went to get a copy of my "family tree" (a legal document) upon the passing of my late father, and discovered that by mistake some other people's data had been linked to the same family tree as ours (some typo in the family tree ID field, the rest of the data was clearly distinct).

Imagine the consequence had I not asked them to correct this, from inheritance issues, to being picked up by the secret police because some "supposed" family member had done something and they check the database, discover I am "linked" and question me about my none-existent sibling.

The fact that I have nothing to hide would be little solace as the police perform rubber-hose decryption on me.

Worse yet, with the data breaches, my (outdated) data being in the darknet means loan sharks using it can come harass me for any debts my supposed relative took.

There are so many reasons why data security/privacy matters, none of which have to do with hiding anything.

I still fear any new additions or deletions in the database since then, but I can't keep going to the HQ and asking to verify my data every day.

Post reply on HN