Live data from Hacker News

Schluss – A secure vault for personal data

schluss.org

11–20 of 43 posts

Re: Schluss – A secure vault for personal data

#11
I like the idea and I think (and hope) someone (hopefully not a FAANG) will manage to build a product. As for schluss.org specifically, I don't see any reason to trust them.

On a side note, I also find their "Responsible Disclosure" page at https://schluss.org/responsible-disclosure/ to say the least, funny:

- "Your reward. We work as a community, in which you contribute to improve Schluss. With this you contribute to a better internet."

- "If you meet all conditions, we will not submit legal proceedings against you."

- "Any abuse of our systems in any way will be punished."

Re: Schluss – A secure vault for personal data

#12
post #2

Idea-wise, this seems similar to Tim Berners-Lee's Solid ( https://solidproject.org/ ). The problem with these approaches is that no significant company is going to do this voluntarily. And this is not going to make a dent until Meta, Apple and friends do it. They are not going to do it because it doesn't give them an advantage, it only makes their lifes harder. It makes it harder even if they don't use the data for…

I agree that this won’t change anything significant until the law makes it mandatory, however a huge step towards getting the lawmakers to do so is tho have the tech already out there and working well with hundreds of smaller players. That will save us years of lobbyists claiming it’s unworkable, to expensive, technically impossible, etc.

> however a huge step towards getting the lawmakers to do so is tho have the tech already out there and working well with hundreds of smaller players.

Not only this, but it will also prevent a scenario where the political will is given, but the tech does not exist yet and then the lowest bidder will implement it, instead of a genuinely interested group of players.

Re: Schluss – A secure vault for personal data

#13
post #2

Idea-wise, this seems similar to Tim Berners-Lee's Solid ( https://solidproject.org/ ). The problem with these approaches is that no significant company is going to do this voluntarily. And this is not going to make a dent until Meta, Apple and friends do it. They are not going to do it because it doesn't give them an advantage, it only makes their lifes harder. It makes it harder even if they don't use the data for…

I agree that this won’t change anything significant until the law makes it mandatory, however a huge step towards getting the lawmakers to do so is tho have the tech already out there and working well with hundreds of smaller players. That will save us years of lobbyists claiming it’s unworkable, to expensive, technically impossible, etc.

> That will save us years of lobbyists claiming it’s unworkable, to expensive, technically impossible, etc.

Lobbyists will do this regardless if the tech exists or not. They currently doing it for messaging app interoperability, even though open protocols and APIs have been around since the internet started.

Don't get me wrong, I'm not saying let's not work on this tech. Just saying that this is not some hard tech problem that needs to be solved. If a law would be passed today that forbid companies from saving customer data, a dozen startups would launch tomorrow with this tech.

Re: Schluss – A secure vault for personal data

#14
If I have it right, this service would allow me to have another company between me and what I am trying to do when I use internet technology.

Why on earth would anyone in their right mind do this? I use things like noScript to specifically avoid this kind of thing.

Do I need a service between me and Schluss, to ensure that they are following my laws?

Re: Schluss – A secure vault for personal data

#16
post #7

"Information wants to be free (freely copied)", even when it's information about you. Freely copied means stored in many places. GDPR is in essence reverse-DRM. Normal DRM prevents you from copying and storing some company's information. GDPR prevents companies from copying and storing information about you. And we all know how good DRM works.

GDPR gives people the same leverage against companies as companies have against people because of DRM.

Re: Schluss – A secure vault for personal data

#17
post #2

Idea-wise, this seems similar to Tim Berners-Lee's Solid ( https://solidproject.org/ ). The problem with these approaches is that no significant company is going to do this voluntarily. And this is not going to make a dent until Meta, Apple and friends do it. They are not going to do it because it doesn't give them an advantage, it only makes their lifes harder. It makes it harder even if they don't use the data for…

Solid is a specification that allows for decentralized data storage in so-called pods. The idea is that consumer applications don't store a copy of your information in their own silo - thereby having many copies of your data floating around with 3rd parties - but instead query your pod. That's the ownership / self-control aspect of the idea.

The crux is that you can self-host your own solid server with your own pods, or choose to rely on a hosting provider. That's the decentralized aspect of the idea.

The big question is how this plugs into an economic model with real world incentives, interests, distribution of power / leverage, trust / credit, and so on.

Re: Schluss – A secure vault for personal data

#18
post #5

I still don't understand how one can retract access once given. If I share my purchase history with some financial web app and later decide to retract access the web app will no longer get new data, but how can I be sure they don't keep a copy of my old data around? Same with GDPR. I often ask companies to remove my data, and legally they should, but I highly doubt many of them do indeed scrap all my data. I still ne…

Agree, you're basically adding another middleman which now also has all your data.

> Same with GDPR. I often ask companies to remove my data, and legally they should, but I highly doubt many of them do indeed scrap all my data

Anecdotal: When GDPR came, the companies I worked with/in took it REALLY serious and spent huge amounts of money and resources to change ALL of their processes to label and clearly isolate data with customer-identified and identifiable content. Not necessarily because they had a change of mind about privacy, but because the risk and the penalty if found non-compliant was so high ("up to €20 million, or 4% of worldwide turnover for the preceding financial year – whichever is HIGHER (!)", PER incident!). Some level of user-data privacy was already in place, but suddenly all understood the risk of not sufficiently isolating identifiable data (data which in itself is not personal information, but could be combined with other data to identify the user)

So at least in my direct experience GDPR caused a huge shift in many company mindsets from "let's store now and review later" to "wait, what is this data?", and all departments which store data from the field had to start answering to a data protection entity within the company about all the data they have or intend to collect.

It literally forced companies which always played with the idea of one day utilizing harvested data to create some undefined value in the future to challenge themselves. And many companies concluded "we don't know what type of data we have, it's too risky/expensive, scrape the servers and delete it".

Those were all large international companies though, maybe smaller companies acted differently. And for sure your typical data-collecting companies (FAANG) are a completely different story.

But the complexity for a small company with smaller processes to become GDPR-compliant is much lower, with the penalty risking to not just hurt you but immediately send you into bancrupcy. So for a small company especially in Europe it would be plain-stupid to not have GDPR-compliant processes...

Re: Schluss – A secure vault for personal data

#19
Good idea in general, the term for this category of products is personal information management system (PIMS). digi.me is the largest player but even they can't seem to get any reasonable traction, as it's an uphill battle to convince third parties to integrate with you. Classical chicken & egg problem: If you have many users the integrations will come naturally, but users will only come when there are enough integrations.

A large company like Apple would be in a better position to do something like this, and in principle Apple Pay does it already as merchants can e.g. request your shipping or billing address through that system.

Re: Schluss – A secure vault for personal data

#20
So, let's take all of our personal info that is being harvested by many organizations and further defragment & centralize it by giving it to one organization?

What could go wrong?

I like the idea of getting it out of control of the current harvesting orgs, but what makes this group more trustworthy? They seem great now, but when you are dealing with a corporation, things can change - their situation andmor leadership changes and the formerly trustworthy organization is now extracting everything they can from you.

A much better model would be to store the data locally with your equipment (maybe offering e2e encrypted cloud backup such that they can't read it), and their service provides a hub controlling the gathering & distribution of info according to your rules/permissions.

EDIT Typo in 1st line

Post reply on HN