The Privacy Revolution that never came
journal.standardnotes.org
journal.standardnotes.org
Some things are changing for the better though: Many people finally become a bit more informed about privacy, also thanks to the effort of journalists uncovering some of the biggest data scandals.
In addition, at least for EU citizens the situation should massively improve on May 25, 2018, as then the new EU data protection directive will come into force, which will significantly increase the rights of people to control how, when and by whom their data can be used. And with a maximum fine corresponding to 4 % of the worldwide revenue, companies will finally have some good incentives to be more careful with the data of their users.
The people doing tech now didn't grow up or live through a massive war and police states. Because those that did had insulated them from that.
It seems like we humans are incapable of learning from past events because we primarily learn by experiencing. End result is that we take the status quo for granted until it changes, boiling frog like.
For example : I feel the same way about American positivity on self driving cars, because I live in a country where people can drive on the wrong side of the road, or footpaths. Where beggars can swamp your car during a light, or where gangs distract you by tapping the back of your car.
These are cultural memory and experience.
In India, people are very pro surveillance, many believe that we have nothing to hide and those who do are likely criminals. We are only building civil liberties groups today.
Side note: apparently the boiling frog thing isn't true. If it gets hot it jumps out.
Just want to mention that the anecdote about a frog slowly being boiled alive has no foundation in reality: https://en.wikipedia.org/wiki/Boiling_frog.
There are plenty people doing tech and living in police states even today.
The (mostly young) online paid ad guys are way more paranoid than the old conspiracy theorist hacker types I grew up around. All we do is talk about how advanced the tech around attribution is, all the data DSPs are collecting about you, etc. All of these guys seem to have an attitude where they're making a deal with the devil and they want to make as much cash as they can before retiring to some island off the grid. It's really bizarre.
- uBlock Origin - just straight up blocking ads solves the problem, some lists also block other kinds of trackers, it also has an excellent advanced mode feature that can be used to whitelist
- EFF's Privacy Badger - blocks or trashes tracking cookies automatically, includes social blocking too
- HTTPS Everywhere - force SSL on with as many sites as possible
- Consider referrer control extensions too, though they may break some sites
Other tools in this field include Ghostery and Disconnect, but Ghostery has some sketchy ownership and Disconnect seemed to break random sites - plus most if not all of the stuff they catch will already be blocked between uBlock Origin with privacy lists and Privacy Badger.
But for desktop and mobile I can't endorse enough running a software firewall with outgoing blocking and active prompting - many of these will also let your block things from injecting into other applications, adding themselves to startup, etc. XPrivacy on mobile works wonders. Outpost used to be my recommendation on Windows, but it's unfortunately dead now, so I've been running ZoneAlarm lately, which does a decent job. If someone knows something better, please let me know.
In the past I've had my browser dump everything on exit, every time I exit, but that can be a major inconvenience. SDC sounds like an interesting middle ground though.
Me too, until I realized I often leave my browser open for days and weeks, especially at work.
① https://www.ghostery.com/blog/ghostery-news/ghostery-acquire...
What's worse is that there are privacy-respecting alternatives available out there, all for free or close to it.
For search engines, you can use startpage.com and duckduckgo.com.
For social networks, you can use Diaspora. You might have to pay for a cheap hosting account though.
For phone operating systems, you can use LineageOS (formerly CyanogenMod).
For PC/laptop OSes, you can use Linux.
But no one wants to bother with any of these things. They'd rather use whatever's mainstream, and they're perfectly happy to post all their private information on Facebook for the whole world to see.
Ignoring that the options people do choose are vastly more capable, usable, convenient, reliable, supported, etc, than any of the options that would protect their privacy.
People are making tradeoff, but it has nothing to do with what is 'mainstream'. The mainstream choices are mainstream because they offer tremendous value in comparison to the privacy preserving alternatives.
Are the results as good? Probably not. But there's always a trade-off we make when choosing our tools. It's not always about choosing the one with the most features or the one that's most popular. Sometimes ideology matters, and I'd say that's the case for many who choose a search engine like DuckDuckGo over Google. I'm more than happy to trade not-quite-as-good search results for privacy – and I know that the more people who do, the better those search results will become.
How many people who had no relationship with a university have you gotten set up on Linux? There is a solid chunk of people that just cannot afford the cost of running Linux once you take into account the risk of having to spend a bunch of time mucking about with your package manager or something else with a high cognitive cost.
Granted, I switched from OSX to Ubuntu back in 2013.
A curated app store, akin to a Linux distro repository, is what's missing from Windows experience of many people.
But if you want AAA games, Windows is usually the easiest, or the only, platform. :(
Social networks? How to persuade people to join the better alternatives when all their relatives and friends use the popular ones?
Devices? Most people do not want or need a desktop or a laptop these days. Smartphones are much more convenient and easier to use.
Alternative phone operating systems work well on very few of these devices and the installation procedure is rather harrowing. Might completely brick your phone if you don't know what you're doing, who wants to take that risk?
Those that do need a proper computer probably prefer compatibility with everyone else, and that means they will not run Linux.
Search engines? People would rather trust and use Google or whatever because DuckDuckGo looks and sounds like it's made for five-year-old kids. Startpage.com is spewing stuff about goverment spying and hacking on the front page.
I wouldn't write off software developers completely though. There likely are some who simply do what they're told without speaking up or questioning the decision, even though they know better / think differently. They stick Google Analytics on a site instead of raising the idea of using Piwik instead. Or they add Facebook and Twitter share buttons without asking whether they can be optionally loaded. Maybe they'll be shot down by a superior, or maybe the superior doesn't even care and allows the software developer to decide. Depending on the size of the software's audience, that small decision could make a substantial difference in privacy.
That's why this has to be controlled by regulation rather than driven by market demands (which you allude to in the closing paragraph).
If people don't care about privacy, then government is wasting their time creating regulation that doesn't matter to people. That's not useful.
If people don't know about the privacy implications of technology, is adding regulation the best way to inform them? There are lots of organizations like EFF that are much more effective with their resources to inform people compared to government. And wouldn't it be speculative to create regulation without first determining how people feel about it?
Don't get me wrong – I think privacy is extremely important – I just don't think government can address it nearly as well as the free market, which is much more in tune with how important it is to people.
Regulation could make their use of data far more visible, or even require explicit consent for different instances of tracking. This isn't holding the market back, it's enabling individuals to make more efficient decisions about which transactions they think are actually beneficial to them.
Case in point: Pokémon Go. It didn't take long at all before they were exposed (http://adamreeve.tumblr.com/post/147120922009/pokemon-go-is-...) for requesting full access to your Google account. The subsequent outrage caused them to take a more privacy-minded stance.
My point being, this information is and can be made available to consumers without requiring government or regulation. A whole new non-profit organization could be established that does just that: researches and publishes privacy-related data on products/companies. It could even have a program that rates and awards gold stars to those that pass their requirements, like EFF's Secure Messaging Scorecard (https://www.eff.org/node/82654).
> This isn't holding the market back...
Regulation always makes it harder for new entrants to the market, while simultaneously keeping incumbents in power (because they're often large enough to handle the time and money required to comply). And with less competition comes less choice, poorer service, and higher prices.
It sounds backwards, but not regulating privacy actually makes it easier for privacy-minded companies to enter the market and find success.
And I think that's still far too much effort to expect from people for every single company they interact with. People should not be able to give up their privacy without actively choosing to do so.
>Regulation always makes it harder for new entrants to the market, while simultaneously keeping incumbents in power ... not regulating privacy actually makes it easier for privacy-minded companies to enter the market and find success.
In order to have a competitive market for privacy, it needs to be a visible choice.
If companies can hide data gathering in the small print, it makes it hard to convince people that your product is meaningfully different. Whereas if the other company has a big notice saying "We sell your data to advertisers" and yours doesn't, it's a lot easier to sell.
Yes, the cost of compliance will marginally reduce competition overall, but competition in terms of privacy will be greatly increased because people will actually factor it into their decisions.
Most people are not aware of the scale of this thing. And it's just getting going. I don't think people's ignorance is a good reason to not protect them. If all the companies are at it (which they are due to lack of regulation and need to compete), then what good is it informing the user. What choice do they have? It's all very well saying they can choose to not use said service/product etc, but that is tant-amount to bribery - and an unrealistic prospect. So what actually happens is people click through the T&C's grudgingly (well, the ones who understand what going on), and downwards we go.
We should not be forced into such a choice and the only way that will happen is regulation.
EDIT: then again, this will never happen, because where do you think the gov gets their information from!
> I don't think people's ignorance is a good reason to not protect them.
Even if there are some who are completely in the dark about privacy, this mindset would lead to regulation protecting people from literally everything, as there will always be people ignorant of something. I don't think it's the right default stance to take.
> We should not be forced into such a choice and the only way that will happen is regulation.
We have a right to privacy in the sense that we can choose not to use a product or service that invades our privacy. But we can't force our right to privacy on others.
The good news is, if there's a market for privacy-minded products, entrepreneurs will provide for that market. And I believe there is a market, because there's an increasing amount of privacy-minded alternatives.
> EDIT: then again, this will never happen, because where do you think the gov gets their information from!
Hah, this we can agree on! And I think it highlights an important point: How can we trust government to protect our privacy when they've been the biggest aggressor against our privacy?
It's not that ordinary people don't care; it's a cost benefit problem --- the time/bullshit-costs of moving data from entrenched cloud providers is large.
The joy of hacking is that everywhere we go, we beat a path. We build good clients for bad APIs, we figure out the weird munge and consistency problems involved in data transfer, and we automate the process of managing servers. These levels of responsibility and abstraction are modern software, and the more we go there (personally and professionally), the easier it becomes for viable consumer-grade alternatives to appear.
We also set-trends more than we realize. Almost every major newspaper has a tech section, and much of that is fascination with our culture, and reflection on privacy issues.
This is on us.
The data protection directive is a good example: With the political engagement of Jan Philipp Albrecht (and many others), he did more to protect peoples privacy than any hacker or software developer I could name.
So if you really wanna do something about this, don't think about how you can solve the problem using technology, but for a change think about how you can help us achieve a political solution first.
+ Ownership about your own data.
+ The right to be forgotten.
+ The right to use your own data in your way.
+ The transparency of being able to monitor who is when looking into your data.
* You have the right to know exactly what a company knows about you, for which purposes it uses that information, and how it processes it.
* You have the right to revoke a company's permission to process/store your personal data, and a right to have your data erased (there are some exceptions though)
* You have the right to obtain a digital copy of all your personal data (including data that was generated through your behavior, e.g. by clicking on "Like" on Facebook) in a common machine-readable format, and also to have that data transferred to another company if you wish so (this should make it easier to change providers)
* You have the right to know (actually you even need to be told beforehand) for which purposes your data will be used and by whom it will be used. If you should be subjected to a fully-automated decision making process (e.g. your credit score gets calculated algorithmically) you have the right to know which kind of algorithms are used in the process and how their internal logic is structured.
I'm with you --- my views are pretty much in agreement this, and with Schneier in Data and Goliath.
However, while legislation and regulation are the only things that will prevent us from full-blown monopolistic dystopia, there are meaningful ways in which technologists can make privacy preserving behaviors easier to adopt on a wide scale.
The most obvious example of this is Signal. It wasn't brought about because the government said it had to be built (though they did end up funding it), and not only has it significantly advanced the privacy of instant messaging for millions of people, and moved the Overton window on expectations of encryption, it provided a new open standard (and FOSS reference implementation) for other messaging services to adopt.
You do realize, companies are already lobbying for and soliciting access to Facebook data.
Tick tock...
P.S. I became friends with and helped out a convicted felon, this past year. Three DUI's. Their life is now back on track.
Per corporate-sought data maximalism, our Facebook friendship could cost me in terms of insurance premiums or even simple insurability, employability, perhaps my ability to get or maintain a mortgage. God knows. And that's a further part of the problem, that this is all feeding into corporate "black box" algorithms and decisions.
Maybe I start getting "enhanced screening" at every pass through an airport, because the government -- or a private/privatized screener -- is using Facebook to acquire this third party data that, so far, it's (supposedly) prevented from acquiring directly. You see, it's not just alcohol, but this person used to be into drugs.
So, do I need to rethink my whole decision to help this person? Will data domination dissuade simple kindness and decency? And that proverbial "second chance"?
Privacy. Ultimately, it strikes at the core of our society and our humanity.
A far greater threat than the ostensible threats ostensibly (um, data, please) being prevented.
Or, in the case of private business, a far greater loss than the profit supposedly being maximized.
No. They're growing up with iPads in their laps that teach them how not to code. Computing used to be creative perforce. Now the larger trend is to consumption - perforce.
There is a heartening smaller trend to creativity with Pi, Arduino etc...but it is tiny compared to the mainstream use of computers.
(I mean fraction of the whole, but I would love to have the data to see if we are not having more people leaving software development due to increasing complexity or retired tech than joining. How many have left software development with the downfall of Delphi, Visual Basic, Clipper?).
Naturally, since we spent bunch of time on PCs, we tried and explored many different things. I started learning HTML when I was 11 or 12, I don't remember precisely, but I discovered it accidentally. I found out about View source and how to save a web page (HTML), then I started playing with the code. This was enough to get me interested and I started learning HTML and later, programming. Today I am 23 and I work as a mobile developer. I heard a lot of similar stories, not just in programming, but for graphic design and other fields that use a computer as a tool.
The smartphone is simply not a creative tool, and it's not an open platform. You can't "peek" inside of a mobile app like I was able to peek into HTML. If I didn't, I would never discover it and it would never lead me to other platforms and programming languages. You can't see and play with raw files. You can't just open a photo in an editor, which leads you later into some creative fields like graphic design. Sure, you can "get creative" in Snapchat with your photos, but Snapchat is not a professional tool. When we wanted to edit our photos, we had to first get Photoshop, and learn the basics of working with it. Since it is a professional tool, it is an invaluable skill. I feel like this doesn't happen anymore. Applications like Snapchat are enough to fill their need for creativity and those kids are less likely to discover useful tools.
I share the concern that a phone is a consumer gadget much like the console was as a gaming platform compared to the Amiga/ST/PC stack. I'd imagine that kids that grew up with Amiga/ST/PC were much more likely to become programmers than those that grew up with consoles (Megadrive/SNES).
Never had enough memory for both sound and mouse.
Today's generation doesn't have that option in any of the popular social media platforms.
It's not true for software. There are plenty of people who can use some applications, but can't write any application, even as simple as a helloworld.
Only free software could change it. I hear a lot of people feeling entitled to bash RMS, but it happens because they don't get the big picture.
Umfortunately many people praised the shareconomy without seing the downside that a shareconomy seldom creates new.
I heard this 10 years ago and it didn't came true. It is not coming true in the next 10 years.
It is not a skill at all to comprehend how to select the wlan, open apps, download apps and enter some email address for some free internet.
This article is hosted by a third-party and has Google Analytics.
The super hard thing is to help people value their privacy/security.
They already share everything on their social accounts showing they don't really care. They only care when an ex uses that information to stalk them or something. Or they make stupid myopic comments like "I have nothing to hide..." until you do because one of your FB friends has a muslim sounding name. Then they want privacy and security but still only from that person/group.
Privacy is one more "race to the bottom" where the government has to intervene, since acting one at a time consumers are helpless.
Just because someone is a hypocrite doesn't mean they're wrong.
The point was that there is no accountability in the article. It even says "they're sleeping" instead of "we're sleeping".
Everybody else is too lazy but not me because I'm writing about it so I'm doing something (you're not).
De-centralization is what will give power back to users. Ofcourse I don't want every user configuring their own synchronization solution instead of using Dropbox, and Drive. But running your own server , with modular services like these (sync, backup, email etc), should be like installing apps on your phone.
People have disagreed in this very thread. And can you honestly say that finding out the author was being hypocritical didn't weaken his argument in your mind? It did in mine: this is a very human impulse and in this case it leads us wrong. Now instead of evaluating whether what the author said it's true, we're evaluating whether the author is trustworthy. This needs not to even be considered because the author's statement stands on its own, independent of who said it.
> The point was that there is no accountability in the article. It even says "they're sleeping" instead of "we're sleeping".
I get the point, but why make this point? It's not an ad hominem attack because the logical leap from "the author was a hypocrite" to "the author is wrong" was never explicitly made, but it's hard to imagine a reason why attacking the author is relevant if you don't make that logical leap. And many readers will make that logical leap, as evidenced by responses to my post. If the intent is only to attack the author, it's off topic; if the intent is to undermine the author's statement, it's an ad hominem; either way it's counterproductive to the kind of discussion I want to see on HN.
Security is the responsibility of people who implement software. That's important and it's worthwhile to stay on that topic.
A better comparison would be to murder someone and write an essay about how the world is a violent place.
So you're saying if a murderer says murder is wrong, and it is up to them to fuel the change, then murder is right?
> A better comparison would be to murder someone and write an essay about how the world is a violent place.
So you're saying that in this case murder would be right?
You may had got into an infinite loop in your own poor comparison, though.
The end result is that we are trapped in our own bubbles, preaching to only those who already agree with us. Ideological purity goes on to alienate people. The new generation of computer scientists, developers are not exposed to these ideas, because they are not as accessible. They are using facebook, slack and medium, and we refrain to use those. These are tradeoffs, and clearly, there is needs to be a balance.
Deploy your server into sandstorm.io
https://sandstorm.io/news/2014-07-21-open-source-web-apps-re...
I wrote (as in, me personally, in Node) and just released http://gibber.it , which is currently in beta, to allow users to send end-to-end encrypted messages through basically any place in a browser that you can enter text.
It currently works quite well on gmail, nytimes.com comment boards and on reddit. It will soon be working on facebook (their content-security-policy is very strict - rightly so - and I am making the extension compatible with these requirements).
* It currently functions as a chrome extension.
* Sign up, invite connections just like any other social network.
* Encryption is end to end, AES 128 with nonce'd salts.
* Use a password you share with your connection (NOT your login password) to send connection invites - this is used to encrypt your keys during the invite process. (Make sure to accept the return invite! This is how your connection sends his or her keys back to you. Also note that you will likely need to reload any tab running the extension after accepting an invite in order to get the keys to load.)
* Use the chrome extension to encrypt and decrypt messages as you browse.
You can see it in action here: https://www.gibberit.com/#!how
Mobile coming soon. HIPAA compliance coming soon.
Terms of Service Here: https://www.gibberit.com/terms
Privacy Policy Here: https://www.gibberit.com/privacy
Please note that the system is in BETA. Still many tweaks to work out. Use is at your own risk.
Please feel free to ask any questions you may have. I welcome any and all feedback. Love the system? Hate the system? Please let me know. More about me here: http://www.lawyernamedliberty.com
Edit: Please note that the gibberit homepage - AND NO OTHER PAGE - uses google analytics. This is clearly detailed in my privacy policy. Aside from that, I do not use any tracking software.
I know it's more fun to play blame the nerds, but this author needs to sit down and have a bit of a think about why they're blaming people for building the things they were paid to build, rather than the people who decided that the things should be built. But there are no easy answers there, all you get is a sense that there are an overwhelming number of force vectors that all make the status quo happen.
If the moral imperative is on engineers to band together, and refuse work for the purpose of breaking us out of the feedback loops we're in, you're going to need a lot more principle and actionable advice in your argument than some shitty hand-waving to throw developers under the bus so you can huck your notetaking app.
Blaming engineers for this problem is shooting the messenger. Engineers, so far as I can tell, are the only group who do care about privacy, and spend their hard-earned free hours making products to address it. They're soundly ignored by consumers, who quite frankly don't give a shit.
But I guess "blame the nerds" is all the rage these days. Just like it was when I was a nerdy kid in the 1980's. And just like it was when my dad was a nerdy kid in the 1950's. It's never enough, nerds. Give more to society. Work harder for free.
I agree that most of these big companies/governments are greedily collecting as much data as they can without even a clear plan of how it all will be used, and that the amount of data being collected is definitely way more than most users know.
But will I someday be prosecuted for the news articles I read or the songs I listen to or my amazon purchases or my google searches? I guess maybe, but that is a HUGE maybe.
If the number one motivator for internet privacy is so that if there is someday an oppressive totalitarian government I will be safe, then I'm not convinced. Besides - I doubt the new government will really be stymied by my use of a private server.
The truth is most of the data collection benefits us all in at least some small way. Spotify provides better recommendations, google provides better search results. Even the ads we are served are more appropriate for us (for better or for worse).
And when people do absolutely need privacy there are suitable options already available. But these are niche products for a reason: most people lead innocuous lives.
Sure its more refined than older ad technology, but picking the tv or radio shows during which one runs ads, or picking the magazines and newspapers in which one runs ads is not that different from targeting facebook ads. The first politicians 100 years ago to target ads on the radio probably gained the same advantages that Trump did in 2016 with facebook.
That was only ~60 years ago. I would absolutely argue that we aren't that far off, ATM.
EDIT: Also, look at places like China. They absolutely do use that type of data to do harm to people.
My main point is that an oppressive government is a huge problem, and it really doesn't matter whether you use aws or roll your own server, because either way you're screwed if you've let it get to that point.
> My main point is that an oppressive government is a huge problem, and it really doesn't matter whether you use aws or roll your own server, because either way you're screwed if you've let it get to that point.
But we aren't at that point yet. So lets not give up trying to build things the right way just because we may be screwed in the future.
It could be used for anything, including the No Fly List. It could lead to your arrest. What couldn't it be used for?
The fear is not of being prosecuted. It is of not being prosecuted. Never having your day in court. Being put on watch lists and "no fly" lists without any recourse. No way to examine the evidence against you. The fear is not a orwellian world, the fear is a world driven by kafkaesque bureaucracy. You are right that privacy may not always protect us from violence, but it will protect us from indifferent and abusive bureaucracy.
See: 'I've Got Nothing to Hide' and Other Misunderstandings of Privacy (https://papers.ssrn.com/sol3/papers.cfm?abstract_id=998565)
If anything we would need less privacy and more transparency!
Why is that? How can information be used against you by someone if it never falls into their hands?
>If anything we would need less privacy and more transparency!
Why not more of both?
And I also think without us rolling our own isps, the government will always have a back door.
And truthfully I think Amazon has a better chance of fighting invasive government behavior than I do as an individual.
I don't know why it wouldn't matter. And it is the situation; you can be put on the No Fly List without your knowledge and with no recourse, and now popular legislation would not only deny travel on that basis but gun rights too.
In case you've missed it, there have been a lot of articles on HN recently about US immigration going through people's phones and social media accounts looking for things they can use against them. e.g. https://news.ycombinator.com/item?id=13702981
Totalitarianism doesn't turn up all at once. It starts against those people, one person and marginalised group at a time.
My favourite example of using digital comms against totalitarianism is "Talking to Vula": http://www.anc.org.za/content/talking-vula
Clearly there is huge variance in the value individuals place in privacy. And I guess that is where the author and I disagree.
Would this site be more convenient without forward secrecy? Would WhatsApp be more convenient without end-to-end encryption?
Why can't we fix it? We can't do it tomorrow, but we can do it. We built the Internet; Facebook didn't exist 15 years ago.
The statement seems like the perfect propaganda, written by those who want surveillance and want to spread hopelessness among their opposition.
I mostly just think cloud computing provides a lot of benefits to society and spurs innovation, and the idea that we should roll our own (costly) servers for the sake of privacy is not convincing.
That's not the argument, kind of like the argument for not having unprotected sex with strangers is not that if you use protection and have sex with someone who has HIV, you will be immortal and live forever.
Furthermore, it's really not just about you. Say, you're gay or have a spine in country X or Y, there are so many possible cases. Those people matter, not those who are content that they themselves are not threatened at this very second, or intend to remain on the "good" side of power.
> But these are niche products for a reason: most people lead innocuous lives.
Most people are complicit. Most of us are not dangerous to any murderers or crooks, while lending support, so we are innocuous to them. And congratulations to all of us, too. Well, at least we have ads that are "more appropriate to us" I guess.
Perhaps you aren't vulnerable, but there are many who are. What if you are Muslim or interested in Islam? LGBTQ in a small town? And do we know who will be in power and what the risks will be 20 years from now? We can't wait until someone starts to abuse power; it will be too late to stop them.
Also, I think the parent greatly underestimates the risks of abuses of power. Read the history of the civil rights movement, for example, when the U.S. government tried to blackmail Martin Luther King, or conducted COINTELPRO. People feel vulnerable to this day; when U.S. government mass surveillance became public recently, evidence showed that people began self-censoring their searches.
Finally, one reason many in the West feel safe is that institutions were built to protect against abuse of power. There is nothing genetically different about Western leaders that makes them less prone to abusing it. For example, a military coup in the U.S. might seem very unlikely; one reason for that is the structure of the defense institutions are designed to prevent it, partly based on what happened with the German military before WWII.
What are we doing to protect and provide freedom to the next generations, as our predecessors did for us?
> most of the data collection benefits us all in at least some small way
You may feel that way, but shouldn't people be able to disagree and have a choice?
I didn't mean to be so inflammatory, but I think the premise of the article -- that we should be rolling our own servers as opposed to using cloud computing systems -- is a ridiculous one. By the author's line of thinking we should probably start encrypting our handwritten thank you notes to our grand parents for no other reason than maintaining our privacy.
I never said that it should be illegal for someone to seek privacy, but I do believe that the article advocates a silly solution.
I'm not talking about legality (though that is important); I mean that typical end users should have an option, a practical way to have privacy and function in the real world.
For example, someone looking for a job often needs Facebook and LinkedIn; they have no option.
> for no other reason than maintaining our privacy
I believe privacy is important, as a thing itself and not as a direct means to an end, to more people than you think.
The reality is you need to make the economics and usage of it better than the current de facto reality. There are reasons why the current status quo is the status quo, and you have to be more compelling than the status quo to beat it.
It's why signal forces everyone to use phone numbers as identifiers & use google play services. It is why PGP has failed. It is why your next consumer privacy product will probably still use those cloud services, but client side encrypt.
Now that solar panels are meeting the price of gas, we will very soon see solar overtaking a lot power plant production in the world. Because it will be the cheapest.
So I think people will be more concerned about privacy when it becomes important enough for them to do so. And I believe that's not likely to happen until the evidences of the abuses against themselves becomes too large to ignore. But the abuses of privacy today are largely unseen and unheard. And so the culture of being social and sharing is more dominant than the culture of privacy.
I don't hold developers and engineers directly responsible for ensuring people's privacy (though they could certainly do more to improve it. Their business model often relies on people giving up their privacy, true. But as Facebook stated long ago, "the information users provide is voluntary." Users do not seem to mind volunteering.
https://www.stoutner.com/privacy-browser/
Regarding the article being published on Medium.com, I think it is ironic that anyone with strong privacy views would use a platform that requires accepting third-party cookies to create an account or post a comment.
I think maybe people have wasted a lot of time trying to peddle crypto to hippies and politicos, when lawyers and insurance companies might have been a more receptive audience. The only way PGP was ever going to get any adoption was if people feared getting fired for sending unencrypted private info.
And of course once there's a critical mass of people who know what a private key is due to their work, it's a smaller step to get individuals to encrypt things voluntarily.
How are you coming to that conclusion? Companies may say they take security seriously and they want to avoid becoming the next Sony or Home Depot, but how many actually allocate resources accordingly? It's much more efficient to just issue a press release and offer to pay for credit monitoring services that virtually nobody will actually use.
I'm the opposite to you, I blame developers. They are the ones who build and understand the tech that powers online tracking.
If a user switches from their Google account to a non-related Google website, how are they to know they are stealthily still being tracked thanks to an invisible bit of Google Analytics code?
Do the consumers who purchase a ChromeBook realise everything they do in the OS is tracked and recorded by Google (even simply printing to their desktop printer)?
Are the parents of school children aware of the privacy implications of their kids using ChromeOS in the classroom? ChromeBooks are becoming ubiquitous in US classrooms, and yet there's barely any discussion of the privacy aspects.
Even if these companies assure us they only aggregate the data they collect (never personally identifying individuals), that's still a frighteningly large volume of personal information they capture. Can you imagine the humongous volume of aggregated data that Google must hold on it's users? They probably have the ability to mine that data in ways that most us probably can't even imagine.
What do developers do about this? Nothing. They built this tech and few ever call out these companies on their behaviour. In fact, a great many rush to the defence of these companies and happily recommend their products ("just bought my mom a Chromebook!").
So no, I don't think it's fair to blame consumers, but yes you can certainly blame developers.
That analogy is crap. Is the difference between reading and launching people into space childhood, too? We don't blame authors for kids who can't read any more than you can solve technical illiteracy by bludgeoning software authors. Can we help? Yes, certainly (and check out https://www.cs-first.com/en/home if you haven't). But throwing shade isn't going to magically make an entire class of folks learn something they don't care about.
That's a bit too optimistic.