Live data from Hacker News

You can't leak users' data if you don't hold it

seancoates.com

31–40 of 170 posts

Re: You can't leak users' data if you don't hold it

#33
post #18

Earlier quoted context omitted.

That assumes quite a bit of freedom that may not exist for many people. An Uber driver waiting for their next passenger isn’t able to go hang out with friends, but they can play on their phone, or read a book.

Before devices, people were able to find ways to kill time at work just fine. As a human, we're perfectly capable of surviving without the device. I know that seems antithetical to zillenials, but it will be more than okay to look away from the screen for an extended period of time. Personally, having a driver sit their counting the number of red cars or counting the number of different state license plates is equall…

Users didn’t consider them just fine, as they immediately abandoned them when given the chance.

Re: You can't leak users' data if you don't hold it

#34

What happens when Matter gets acquired? I'm sorry, but all this self back-patting is a bit too little too late for this jaded guy, especially because a thousand other companies have made the same promises in cheery blog posts, before something happens and my social security number winds up on a sticky note on some hacker's monitor in Belarus. Hell, I've worked for companies where I was forced to break users' trust be…

While I agree with your sentiment, after re-reading the post and looking at some of the blog posts, I think you missed a major point, that being: 1. You can't leak what you don't have. That is, even if the company gets bought out or is hacked, if they don't have the data, there is nothing to leak. This point is also at least partially enforced by another point from the post: 2. Advanced app users can audit their netw…

Hi, I also work at Matter. Our current backup/restore implementation exports a zip file of complete JSON data. We will improve backups in the future, but no pull request will be merged to remove the existing implementation for at least as long as I’m leading the app team.

Re: You can't leak users' data if you don't hold it

#35

I agree with the core idea, avoid saving info so you can't ever leak it. I personally think our legal framework should be based on consequences to encourage this mentality more. If you are hacked I don't care even a little that you did everything right, I just care that my information got taken. You should be held liable even if you did what the industry thought was right.

The root cause behind the proliferation of privacy breaches is that the legal framework against spying/hacking turns out to have a massive vulnerability.

Developing & spreading spyware that collects people's personal data without permission is illegal (you don't even need to leak the collected data for it to be illegal), but wrap it in some flashy marketing, dozens of pages of unscrutable ToS and "privacy" policy, and suddenly not only your spyware operation became legal but you can even leak or sell the data in total impunity.

This is valid in Europe as much as the US. Keep in mind that even before the GDPR, most countries had some sort of legislation around personal data processing, use and storage, but none of it was enforced. The GDPR is no better in terms of enforcement, which is why you see tons of (non-compliant) "consent" flows and spying continues as usual for the most part since businesses entirely based on non-consensual data processing are still alive and kicking.

Re: You can't leak users' data if you don't hold it

#36
post #26

Earlier quoted context omitted.

> before something happens and my social security number winds up on a sticky note on some hacker's monitor in Belarus Isn't the point of the article that they can't leak something they don't have? So if I never get your social security number from you, then I have zero risk of leaking it or exposing it to hackers. I can't give them (intentionally or unintentionally) something that I don't possess. The author says: >…

> Well the app might [...] change how it works [...] but your data never left your device, so you don't really have to worry about it being leaked to Belarus. You're one update away from having an app that has access to all its data and can ship it anywhere. Do you keep updates off?

I wish I could keep my updates off.

Every time I turn on my computer dnfdragora is like "there are 35 new updates!"

Oh yeah? But my computer is working. Those updates could fix problems that I don't have but could break stuff I have as well. I'm not updating until they release Fedora 40. (my nvidia driver stopped working when I upgraded to 39, again...)

To begin with who thought these notifications were a good idea? Just appear meekly on the system tray when you have something to say. The only time a popup is acceptable is if it says "yo, your computer is on fire." Anything less is unnecessary distraction.

I want my software as-is, changing only when I want it to change. The other day a Windows update removed my "show desktop" button from the task bar to insert a copilot button. Who asked for this? The taskbar changes when I say it changes! I started using the program because I liked the way it was. If it wasn't the way it was I wouldn't have started using it, so why change?

To make matters worse, I don't think there has ever been a time a software updated that I said "they finally added X!" It just never happens. It's insane. Things really only get worse with time. Ten years ago GIMP didn't have nondestructive editing. It still doesn't. I'm still waiting for it. They said it will come in GIMP 3, for years. I feel like that update is just never coming. We're at GIMP 2.99.18 now. Can you believe it? 2.99.18. Who even reaches minor version .99?!

Re: You can't leak users' data if you don't hold it

#37
post #2

> Our first product is an iOS app designed to help you capture the best moments in your life I have increasingly come to the belief that mediating our life experiences and social interactions through apps isn't good for us. Your website "Matter" [1], to be honest, seems completely dystopian to me and an indication of all that's wrong with the relationship between technology and society. [1] https://matter.xyz/

Their website is an epitome of idiocy of modern web product design. They want my email, because we are all "stardust". There is no clear explanation of what their product is or how it's different from a photo app and a notebook. Instead of a proper description of their business, they send to the Business Insider article about the founder who wants to prevent unhappiness.

Re: You can't leak users' data if you don't hold it

#38
post #2

> Our first product is an iOS app designed to help you capture the best moments in your life I have increasingly come to the belief that mediating our life experiences and social interactions through apps isn't good for us. Your website "Matter" [1], to be honest, seems completely dystopian to me and an indication of all that's wrong with the relationship between technology and society. [1] https://matter.xyz/

Back when my kid was born I bought a video cam. I upgraded the videocam a couple of times, but I realized I didn't use it much because when I did I was videoing not being part of what was going on.

As a result there isn't much video of the kid, but I don't regret it. By the timewe switched to video cams in our pockets, I had pretty much given up, and apart from a few few-second captures, I haven't shot any video in years. And TBH I don't miss it at all.

Apps like this are simply more of the same.

Re: You can't leak users' data if you don't hold it

#40
post #25
post #8

Earlier quoted context omitted.

> What happens when Matter gets acquired That's a major point that's addressed in the blog post, did you read it?

Not sure about GP, but I did read the post. If they get acquired, I don't see anything stopping the acquirer from pushing an update that decrypts stuff and sends the plaintext to the servers.

I'm rather baffled at this level of nitpicking. Yes, if the software was being written by completely different people with completely different goals they might then start to acquire user data but what does that have to do with the point (that data this team and this management don't have cannot be leaked)?
Post reply on HN