Live data from Hacker News

A Case That Has Microsoft, Apple and Amazon Agreeing

bloomberg.com

71–80 of 190 posts

Re: A Case That Has Microsoft, Apple and Amazon Agreeing

#71
post #4

If companies stored customer data encrypted by keys that are held by the customer, they wouldn't have this problem. Furthermore, they wouldn't have to worry about deleting customer data either. The customer would have the power to simply deny access to the keys.

>> If companies stored customer data encrypted by keys that are held by the customer, they wouldn't have this problem.

There is no value to the company in doing that. They can't mine the communications to determine what ads to serve you, or anything else. At that point they'd just be offering a free service. Why?

Re: A Case That Has Microsoft, Apple and Amazon Agreeing

#72
post #36
post #12

I am not a lawyer, but it seems to me that an American court has the power to demand that an American citizen produce an item or information under his control, even if it happens to be in another country (e.g., a man getting divorced can't drive his car and all his gold and jewelry into Canada to shield them from his ex-wife). I imagine that most other countries would behave similarly: being within their borders and…

> it seems to me that an American court has the power to demand that an American citizen produce an item or information under his control, even if it happens to be in another country Does the American government have the power to compel someone to violate foreign law in order to produce an item held in a foreign country? Can the American government force an American citizen to violate Greek law and take a million Eur…

> Does US law for some reason override Irish law?

It's pretty simple. Whoever has more guns backing up their laws wins.

Re: A Case That Has Microsoft, Apple and Amazon Agreeing

#74

"There’s irony in any tech company confronting the government on privacy matters, considering how much heat many take for mining their own customer information and using it for advertising and other profitable purposes." See, I don't find this very ironic. In fact, my only real issue with data mining and analysis by these sorts of companies is the way governments can demand this info without my approval. If Microsoft…

Except that companies generally reserve the right to modify their privacy policies at any time without your permission, only notification, and that's if they even follow them in the first place.

Re: A Case That Has Microsoft, Apple and Amazon Agreeing

#75

Earlier quoted context omitted.

But then you can't leverage customer data to sell to advertisers. The problem is, you are the product for most internet companies. Think of a Cow in a barn. The food/water/shelter is free, because you are what's to be sold.

If by "you", you mean aggregated data about you in lieu of cash payment. Google/Facebook/etc are not selling your data, they are not selling you , they are selling access to you via advertisers, more specifically, they are selling access to people who like certain things and who live in certain areas who have certain demographic profiles. If you're curious about this, go sign up for an Adwords account and see how the…

Not only would "selling your data" as opposed to access to you or a per click basis be a less profitable business model, it'd also be strictly illegal in many jurisdictions without explicit opt-in permission.

Re: A Case That Has Microsoft, Apple and Amazon Agreeing

#76
post #37

Earlier quoted context omitted.

I generally agree with you, but there's one problem with the physical key analogy. The security of physical keys is weak enough that there's always a fallback if you lose all the copies of your key: you pay a locksmith to come pick the lock and rekey it. You can't do this with digital keys because a digital key that is weak enough for this strategy to be usable is also too weak to protect you from the main class of a…

> there's always a fallback if you lose all the copies of your key: you pay a locksmith to come pick the lock and rekey it. In the digital world you have Shamir's Secret Sharing. Generate a non-encrypting, non-signing, decode-only key and give a N-th of if to N escrow services. If you lose your key you contact M of those entities and recover the data. Plenty of tricks have been created in the last two decades to addr…

Thanks. I did not know that.

Re: A Case That Has Microsoft, Apple and Amazon Agreeing

#77
post #13

Earlier quoted context omitted.

The larger issue is that you now have to push key management to the user, and the support problems that go with that. Key management is hard and painful. Telling a customer that they can't access their data on your service because they broke their laptop is going to make them very unhappy. Otherwise, there'd be plenty of services competing with Drive, DropBox, etc, that did just that.

> push key management to the user There is no other way. Unfortunately, there has been a serious lack of r&d in this area, so we have a lot of catching up to do. I believe it can be made to work, though, because this is not entirely a new idea for most people: they already understand physical keys and the problems associated with losing them. Moving to digital (public-)keys isn't a perfect match, but it is entirely p…

> There is no other way.

Well, we can always legislate. Even with encryption of data, you want legislation. Without legislation, the Government will just create a separate channel for data collection to bypass your encryption. It starts unencrypted at the remote site, so it's not that hard to do.

Even with legislation there will be problems, and overstepping, but at least then there's some semblance of recourse and ways to fight. You can't fix the problem for everyone and always, but you can fix it for most people most the time. This is the sort of thing that should be in trade agreements and treaties.

Re: A Case That Has Microsoft, Apple and Amazon Agreeing

#78

"There’s irony in any tech company confronting the government on privacy matters, considering how much heat many take for mining their own customer information and using it for advertising and other profitable purposes." See, I don't find this very ironic. In fact, my only real issue with data mining and analysis by these sorts of companies is the way governments can demand this info without my approval. If Microsoft…

Hot dang, that last line is insightful. Some people will argue that whenever you let someone have data about yourself, you're implicitly giving access to practically everyone by virtue of often imperfect security. I believe that those people are full of shit.

As long as there is a data silo that is not under your explicit control you have indeed implicitly granted all parties willing to invest enough to break into that silo implicit access. Where exactly is that full of shit? The problem isn't the implicit agreements. The problem is lack of control and centralization.

P.S.: I'd also tone down the language. We're having a discussion and calling someone else's opinion "full of shit" defeats the purpose of having the discussion in the first place.

Re: A Case That Has Microsoft, Apple and Amazon Agreeing

#79
post #35

Earlier quoted context omitted.

If the data is opaque to the provider, then there are many services they won't be able to provide on it (without some major advances in homomorphic encryption). For example, spam detection or search. Sharing is also made much more difficult.

There is no reason that stuff can't be done on the client side. Outlook works just peachy searching my GB's of emails and attachments from its local replica, using the internet only to sync.

I'm not saying you're wrong, but how would you go about implementing client-side search for Amazon?

(inb4 "server-side amazon search doesn't work anyway" ;)

Re: A Case That Has Microsoft, Apple and Amazon Agreeing

#80
post #61
post #50

Earlier quoted context omitted.

As a European citizen, I have a different view on this issue. While I do trust Google/Microsoft with some of my data, and I kind of trust my own government with my data, I don't trust the U.S. government for one bit, especially its judicial system. Luckily, I don't normally need to account for that, and I'd rather keep it like that. But this is like somebody at the other end of the planet changing the small letters o…

I'm in the UK, no idea where you are. I don't trust my government one bit with my data, or any one elses. The US so called justice system literally scares the hell out of me. From a UK perspective, its terrifying. Unfortunately for UK subjects, the UK government willingly hands our data over to the US government, and equally willingly allows us to be extradited on little more than a request. Being a European Citizen…

Out of curiosity, which aspect of the US leal system scares you so much? I was under the impression that UK has a rather similar legal system in many respects, and has a number of problems as well. Personally I am a little scared of the French and German legal systems. And last year I read a very scary article about the Swedish legal system on HN.

US is doing a lot of things wrong these days when it comes to privacy, but when compared to EU, I find it to be about the same.

Post reply on HN