Why Privacy Remains Unsolved After Decades of Breaches
Why is privacy so hard?
Carnegie Mellon's Jason Hong outlines eleven reasons privacy is so hard: it's a fuzzy concept, risks vary by relationship, technology advances rapidly, and companies profit from data. Developers lack awareness, users bear too much burden, and market failures mean little pushback. The same data can be acceptable in one context but creepy in another. Without clear incentives or easy comparisons, privacy remains unsolved and will likely worsen with the Internet of Things.
I often summarize our research by saying that if you round up, the knowledge that a typical developer has about privacy is zero.
- beloch
We should tax data.
Hear me out. Google, Meta, etc. offer "free" services to a significant portion of the world's population. This isn't charitable work. They do this for data that makes them money. Lots of money. Data has real monetary value, but governments don't treat it as such. Few, if any, jurisdictions view data exports as taxable. It's simply not tracked. If data collection isn't tracked, how can one realistically enforce privacy standards?
If we tax data, then we'll have an incentive to track how data is being used and corporations will suddenly have a direct financial interest in not just casually collecting data if they don't need to. Such taxes should be gauged to be tolerable for Google and Meta, but high enough to make companies who make their money via other avenues (e.g. Smart TV sellers) to take a pass on data collection.
- roenxi
The article is exploring a broad topic but one area that seems to be overlooked is governments making privacy illegal or actively working to undermine it. The major privacy risk right now is things like social media age verification laws which, in principle, probably make pseudonymous sites like HN illegal or on the path to being illegal in many jurisdictions.
It is hard to maintain privacy when a law enforcement body insists that it isn't allowed. There are also indications that companies quickly become too enmeshed with intelligence services to be able to create properly private options even if tactically they might have an interest. Companies like Telegram stand out as looking difficult to run in practice because of the pressure from various snoops.
If it is legal to create private options then they will always exist because the people who care about specific aspects of privacy can self-serve.
- daft_pink
Because there are numerous choke points where people need to use devices to do a thing and those devices can record you and the financial incentives for the companies that own these choke points is so great that they end up selling your data.
Even if Apple truly had perfect privacy you still need to use credit cards, bank accounts, insurance, cell towers, drive a car, etc.
I think that’s the underlying reason why privacy is so hard.
- cadamsdotcom
A lot of value is left on the table because informed people don't give up data.
If simple regulation existed - say, "no one can use data for any purpose the user did not explicitly consent to, including product improvements AND including on-selling", that suddenly turns giving up data into a legally-binding, two-party transaction.
There'd be an explosion of really cool uses of data as a result of the trust that'd engender.
But today's status quo is lucrative - so here we stay.
- nfujd7
One thing interesting about the Church is that Kings, Inquisitors, Revolutionaries, Govts etc have all tried to break the seal of confession for thousands od years now. The Church has some how managed to defend it by saying we believe path to repair/forgiveness involves creating and maintaining space where people can confess their sins. If a priest shares those sins with the state, everyone looses trust in the system and therefore breaking the seal over any sin is equal to dismantling the institution itself. This argument is literally the same structure used to defend attorney client confidentiality, psychiatrist patient confidentiality, corporations(telcos, email providers, platforms) from handing all data to the state.
But for all those cases the state has manahed to add huge amount of expceptions which it has not been aable to do with the Church. So the Churchs defense of the seal almost since 1215 has stood on a Belief. A story literally. That privacy is requires for repair.
Everyone else just hasnt come up with a good enough story.
Secondly what is stored in the head of a priest is usually forgotten cuz human memory is flaky and no one is writing anything down in a central db. So every now and then a state attack on the seal work but the everything then reliea on how reliable the memory of a single priest is. Its like a terrible distributed atorage system that is constantly forgetting things. Notice this is literally what large platforms have now built to defend privacy […]