Live data from Hacker News

Bruce Schneier: Privacy in the Age of Persistence

schneier.com

1–10 of 19 posts

Re: Bruce Schneier: Privacy in the Age of Persistence

#2
"Data is the pollution of the information age. It's a natural byproduct of every computer-mediated interaction. It stays around forever, unless it's disposed of. It is valuable when reused, but it must be done carefully. Otherwise, its after effects are toxic."

I agree with this idea; that's why I prefer the regulation of data collection and storage, rather than use. Allowing companies and governments to collect massive amounts of data about people that they aren't allowed to use in certain ways today is a ticking time bomb. This data is attractive to criminals who aren't bound by laws anyway, and corporate mergers or changing laws can retroactively harm privacy based on data that was previously collected.

Re: Bruce Schneier: Privacy in the Age of Persistence

#3
Every time I read something by Schneier, I'm impressed with just how well he's able to put things. He's somehow able to impart the gravity of things without coming across like he's fear-mongering. I wonder how he's able to write so eloquently and accessibly on security, which is usually hard to do - I'd like to be able to write that well.

Re: Bruce Schneier: Privacy in the Age of Persistence

#4
post #2

"Data is the pollution of the information age. It's a natural byproduct of every computer-mediated interaction. It stays around forever, unless it's disposed of. It is valuable when reused, but it must be done carefully. Otherwise, its after effects are toxic." I agree with this idea; that's why I prefer the regulation of data collection and storage, rather than use. Allowing companies and governments to collect mass…

I've been toying with a Creative Commons like service, one where as an organization, you can choose the criteria which meet your privacy policy. This would have a "visual vocabulary" akin to the CC badges or nutrition facts on food for different privacy models. It seems like a missing component is clarity and transparency when it comes to understanding the implications of several facets: collection, storage, and use being the big three.

This paper by Irene Pollach [http://portal.acm.org/citation.cfm?id=1284627] delves into some of the details and weaknesses in privacy policies and how legalese can weasel out of a real policy.

Schneier's article makes me even more concerned about storage -- which I think most people dismiss if the use argument is addressed.

I think a privacy vocabulary would be wonderful.

Re: Bruce Schneier: Privacy in the Age of Persistence

#5
Arguments for the importance of privacy seem to invoke either corruption (eg. 1984, or the Cardinal Richelieu quote) or the risk of error (eg. misidentifying a suspect because they share attributes). These remind me of the arguments used against artificial intelligence research. I see them as problems that can be worked around, not as a basis for more privacy measures.

Instinctively I feel that privacy is important, but I can't find any solid justification for the instinct. It bothers me slightly to know that I can be tracked by cell phone signals or a public-transit swipe-card, but I couldn't win an argument for the importance of privacy.

Re: Bruce Schneier: Privacy in the Age of Persistence

#6
post #4
post #2

"Data is the pollution of the information age. It's a natural byproduct of every computer-mediated interaction. It stays around forever, unless it's disposed of. It is valuable when reused, but it must be done carefully. Otherwise, its after effects are toxic." I agree with this idea; that's why I prefer the regulation of data collection and storage, rather than use. Allowing companies and governments to collect mass…

I've been toying with a Creative Commons like service, one where as an organization, you can choose the criteria which meet your privacy policy. This would have a "visual vocabulary" akin to the CC badges or nutrition facts on food for different privacy models. It seems like a missing component is clarity and transparency when it comes to understanding the implications of several facets: collection, storage, and use…

That sounds suspiciously like P3P. http://www.w3.org/P3P/Overview.html

Why did P3P fail and how can those problems be avoided in the future?

Re: Bruce Schneier: Privacy in the Age of Persistence

#7
This is a serious issue to consider, but one way we're not going to solve it is by trying to restrict data collection, or simply trying to hide our own digital footprints. The latest facebook ToS episode tells us as much. To continue Schneier's automobile analogy, we're not solving pollution by un-inventing cars, but by coming up with even better clean technology. Similarly, reducing data collection doesn't seem to be a viable option; instead, we're going to have to come up with better technologies for access control & data anonymization.

Re: Bruce Schneier: Privacy in the Age of Persistence

#8
post #6
post #4

Earlier quoted context omitted.

I've been toying with a Creative Commons like service, one where as an organization, you can choose the criteria which meet your privacy policy. This would have a "visual vocabulary" akin to the CC badges or nutrition facts on food for different privacy models. It seems like a missing component is clarity and transparency when it comes to understanding the implications of several facets: collection, storage, and use…

That sounds suspiciously like P3P. http://www.w3.org/P3P/Overview.html Why did P3P fail and how can those problems be avoided in the future?

I think P3P never gained traction in part because it was too early. I don't remember in 2000-2002 people getting in huffs over privacy policies. They weren't common then. Terms of use were -- deep linking policies. Heh.

One of the major P3P criticisms is the lack of enforceability. While say a Creative Commons license is applied to a work, if a P3P "contract" was applied to a site, how does one enforce it?

I think with the oversight a community provides (Facebook ToS is a recent example), a community or communities could keep companies' policy _more_ honest. I'm currently formulating my thoughts on this; I'm not completely versed in privacy nor previous attempts to clarify, add trust, understanding and accountability, like P3P.

Re: Bruce Schneier: Privacy in the Age of Persistence

#9
post #5

Arguments for the importance of privacy seem to invoke either corruption (eg. 1984, or the Cardinal Richelieu quote) or the risk of error (eg. misidentifying a suspect because they share attributes). These remind me of the arguments used against artificial intelligence research. I see them as problems that can be worked around, not as a basis for more privacy measures. Instinctively I feel that privacy is important,…

I find privacy important because I do things which a sizable portion of society might find distasteful, but which I do not find distasteful. I value my ability to do those things without incurring the ire of other people.

Re: Bruce Schneier: Privacy in the Age of Persistence

#10
post #8
post #6

Earlier quoted context omitted.

That sounds suspiciously like P3P. http://www.w3.org/P3P/Overview.html Why did P3P fail and how can those problems be avoided in the future?

I think P3P never gained traction in part because it was too early. I don't remember in 2000-2002 people getting in huffs over privacy policies. They weren't common then. Terms of use were -- deep linking policies. Heh. One of the major P3P criticisms is the lack of enforceability. While say a Creative Commons license is applied to a work, if a P3P "contract" was applied to a site, how does one enforce it? I think wi…

I'm think it is wholly because it is unenforceable and unverifiable when it comes down to it. P3P allows websites owners to assert their privacy policies, and some aspects of the TOS, in "machine readable" formats. This was supposed to allow standardization to allow better filtering automatically when you visit a site. You tell your browser you are only interested in sites that "collect cookies for the purposes of aggregate data collection" and "don't sell personal information to third parties", and the browser was supposed to warn you, or change its functionality, based on your targets with the site's claimed assertions. It doesn't work like that though, for the same reason the Firefox bad certificate screen ended up being more annoying than useful: no one actually cared about security more than using the site. It's easier to override the settings and use the site. And you could never be sure, until after the fact when it's too late because the information is already out there, that the policy was ever followed or not.

And because of that and the way IE's default "internet zone" cookie policy worked, you pretty much had to, as a website, assert policies that were amenable to the IE defaults.

This would only work when there is significant competition between interchangeable and interoperable sites anyway. Facebook asserts policies A, B, and C, while Myspace asserts policies X, Y, and Z. Well, those policy differences don't mean anything if I actually want to use Facebook because that's that's where my friends are. Privacy policies are only a differentiation point if the policies are different and the services are exactly the same, which is actually impossible (and not really in the indivdual sites' best interest anyway).

P3P has some use as a way to monitor the privacy policy and TOS on a site, and have your browser notify you of changes. I don't think this is necessarily better than what happened with Facebook TOS where someone was following it closely, actually read it, and raised hell about it. There's an emotional aspect tied to that, one that doesn't exist when your browser pops up a box with a warning you just want to dismiss and get out of your way.

Post reply on HN