Debunking the Myth of "Anonymous" Data
1–10 of 107 posts
Re: Debunking the Myth of "Anonymous" Data
#2Re: Debunking the Myth of "Anonymous" Data
#3A good popular take, but they, either intentionally or out of ignorance, omit newer, proven techniques like differential privacy.
Re: Debunking the Myth of "Anonymous" Data
#4A good popular take, but they, either intentionally or out of ignorance, omit newer, proven techniques like differential privacy.
But do you think your average ad tech company gives a fuck? They are going to keep the original data because that's where the money is. Yea, maybe they'll have privacy datasets they sell/release to other groups, but all the real data will remain in a database, and with most companies in this industry, be given to government agencies on demand.
Re: Debunking the Myth of "Anonymous" Data
#5A good popular take, but they, either intentionally or out of ignorance, omit newer, proven techniques like differential privacy.
If I am dependent on the curator to determine the level of privacy then I've already lost.
Re: Debunking the Myth of "Anonymous" Data
#6"The principles of data protection should apply to any information concerning an identified or identifiable natural person. Personal data which have undergone pseudonymisation, which could be attributed to a natural person by the use of additional information should be considered to be information on an identifiable natural person. To determine whether a natural person is identifiable, account should be taken of all the means reasonably likely to be used, such as singling out, either by the controller or by another person to identify the natural person directly or indirectly."
Under EU law, there is no special class of "personally identifying information". Any data that relates to a person or could be related to a person is protected. It isn't enough to just strip the name and SSN field out of the database and call it anonymous, you need to demonstrate that the data couldn't be attributed to anyone through any reasonably practical process.
Re: Debunking the Myth of "Anonymous" Data
#7A good popular take, but they, either intentionally or out of ignorance, omit newer, proven techniques like differential privacy.
Still sounds potentially problematic. Per wikipedia: "Differential privacy provides a quantified measure of privacy loss and an upper bound and allows curators to choose the explicit trade-off between privacy and accuracy. It is robust to still unknown privacy attacks. However, it encourages greater data sharing, which if done poorly, increases privacy risk. Differential privacy implies that privacy is protected, but…
From my perspective this article leans too heavily into the FUD, and really doesn't succeed at keeping the call to action ticking over. On a good day, the EFF can be really good. Today, not so much so.
Re: Debunking the Myth of "Anonymous" Data
#8A good popular take, but they, either intentionally or out of ignorance, omit newer, proven techniques like differential privacy.
Edit: Not trying to start a DP vs ZKP (or Homomorphic Encryption) flame war. We're all on the same side of privacy, right? Different tools for different situations.
Re: Debunking the Myth of "Anonymous" Data
#9Short of us buying up data in bulk and then doing the de-anonymization in-house I am not seeing an easy way to do this. Or even an advertised partner, seems like all the articles are really careful to not do free marketing for companies in this space.
Re: Debunking the Myth of "Anonymous" Data
#10A good popular take, but they, either intentionally or out of ignorance, omit newer, proven techniques like differential privacy.
Still sounds potentially problematic. Per wikipedia: "Differential privacy provides a quantified measure of privacy loss and an upper bound and allows curators to choose the explicit trade-off between privacy and accuracy. It is robust to still unknown privacy attacks. However, it encourages greater data sharing, which if done poorly, increases privacy risk. Differential privacy implies that privacy is protected, but…
This is a really useful argument, because it’s the equivalent of the FDA’s “generally believed to be safe”. If you look into something and this is the risk you find, then it’s safe.