Earlier quoted context omitted.
If you're going to start using logic and reason with this issue then that government will simply outlaw those as well. This government has already set a precedent of having overridden the basic limits of mathematics before. See also: anything to do with encryption.
Relevant article, for the curious: https://www.independent.co.uk/news/malcolm-turnbull-prime-mi...
Melbourne professor quits after government pressure about reporting data breach
11–20 of 40 posts
Re: Melbourne professor quits after government pressure about reporting data breach
#12> The breach so shocked the government, the then attorney general, George Brandis, quickly announced plans to criminalise the act of re-identifying previously de-identified data, although ultimately the legislation never passed before the 2019 election. If Australia makes it illegal to re-identify information, what about information that has been re-identified outside Australia then distributed into Australia?
The letter sent to the university [0], claims that re-identifying information is actually illegal, according to the department's understanding. (Nevermind that they also admit that particular law is completely irrelevant to the work of the researcher).
[0] https://www.righttoknow.org.au/request/correspondence_on_re_...
Re: Melbourne professor quits after government pressure about reporting data breach
#13This is horrible but not surprising, the government was told beforehand it was a bad idea and within a few months ended up with egg on their faces. Instead of remedying the situation they shoot the messenger. Dr Teague was also part of the team that found flaws in the Swiss e-voting system used in Australia state elections, nothing was done about and she was written off, the attack was deemed impractical as it requir…
Is there any other kind?
Thanks for the smile! :)
Re: Melbourne professor quits after government pressure about reporting data breach
#14I.e., do they mean that nobody they talked to could think of a way to recover the identity of even one individual in the set with 100% certainty? Or is there some information-theoretical or legal standard of anonymization they're claiming to have met?
Re: Melbourne professor quits after government pressure about reporting data breach
#15The title is just horrible.
Edit: I've taken a crack at fixing it now.
Re: Melbourne professor quits after government pressure about reporting data breach
#16When organizations claim to have "anonymized" a data set, what exactly does that mean? I.e., do they mean that nobody they talked to could think of a way to recover the identity of even one individual in the set with 100% certainty? Or is there some information-theoretical or legal standard of anonymization they're claiming to have met?
I'm not aware of any legal definitions, but given the thorniness of reidentification I would assume they're insufficient.
[1] https://en.wikipedia.org/wiki/K-anonymity
[2] https://www.wired.com/2007/12/why-anonymous-data-sometimes-i...
Re: Melbourne professor quits after government pressure about reporting data breach
#17When organizations claim to have "anonymized" a data set, what exactly does that mean? I.e., do they mean that nobody they talked to could think of a way to recover the identity of even one individual in the set with 100% certainty? Or is there some information-theoretical or legal standard of anonymization they're claiming to have met?
> Indeed, encryption was not necessary – a randomly chosen unique number for each person would have worked.
Scroll down from here: https://www.oaic.gov.au/privacy/privacy-decisions/investigat...
[0] The data had ids for providers (e.g. doctors) as well as patients.
Re: Melbourne professor quits after government pressure about reporting data breach
#18When organizations claim to have "anonymized" a data set, what exactly does that mean? I.e., do they mean that nobody they talked to could think of a way to recover the identity of even one individual in the set with 100% certainty? Or is there some information-theoretical or legal standard of anonymization they're claiming to have met?
For "organizations" in general? It means approximately nothing, or if you're feeling particularly generous, it means "we probably remembered to drop the column containing your social security number before publishing this data... this time". You're asking exact specifics of a vague and broad category.
There are some legal standards, information theory, and non-legal organization standards that might being met in some cases - involving adding noise or removing data / making it sparse. https://en.wikipedia.org/wiki/Data_re-identification goes into all the ways that it can go wrong despite the best of intentions. My basic take on this all is: data "always" gets more identifying, not less. Two datasets that were successfully anonymized individually can still be correlated to de-anonymize some or all of the data when combined. Even organizations applying information theory with the best of intentions and proper diligence will eventually make a mistake.
Re: Melbourne professor quits after government pressure about reporting data breach
#19The title is just horrible.
Re: Melbourne professor quits after government pressure about reporting data breach
#20> The breach so shocked the government, the then attorney general, George Brandis, quickly announced plans to criminalise the act of re-identifying previously de-identified data, although ultimately the legislation never passed before the 2019 election. If Australia makes it illegal to re-identify information, what about information that has been re-identified outside Australia then distributed into Australia?