Blockchain Could Help Us Reclaim Control of Our Personal Data
hbr.org
hbr.org
This article does not answer either of these fundamental questions.
2. If my use-case requires me to give someone access to my data in order to do their job (eg a hospital needs to see my medical records), then I think it's mathematically impossible to defend against what you said. (barring unlikely advances in homomorphic encryption and the like). Using public-key crypto allows us to eliminate having a intermediary party and the risk that the intermediary party gets hacked. Blockchain then allows us to credibly prove that our data existed at a certain point in time. Also there are use-cases where I maybe need not disclose all my data (eg maybe for some use-case my bank does not need to have access to my payslip, just a proof signed by my employer that it exists)
The "use case" here is people's lives. People's lives are messy. Blockchain doesn't solve that mess, it pretty much just makes it worse.
We should focus on using blockchain to solve "neater" problems like who owns what and who is contractually obligated to do what, etc. Those problems don't have edge cases that involve a parent who loses their memory or a kid who gets thrown out of his house.
The biggest problem I can see from the article is that once someone loses their key their identity is lost forever and they must rebuild the data. The first few times that happens the public will be turned off to the idea.
What you could do, pretty easily, is revoke access to the latest data that hasn't already been shared, and to have an audit trail of exactly what data has been accessed and when it was accessed. That would still be a massive improvement on the status quo.
I wouldn't rule out the eventual possibility of something like Facebook migrating their Open Graph API to some type of encrypted blockchain. Although I would be completely shocked if it were more than essentially a publicity tactic that wasn't actually using any true decentralization.
Suddenly, we get to a situation where the security of the medical file begins to resemble that of the paper-based medical records department. If you want to copy records, you need to physically go to where they are, get access to each individual file, and go page-by-page photographing each.
a secure reader tablet-like device. It has encrypted hardware which can be temporarily permissioned to have access to encrypted data
This part is how it works today and it has been like this for years:
Data is accessed in chunks, therefore the owner of the data can see whether data is being accessed in the way a human might use it, or if it is being downloaded en masse. The organisation with data access devices gets audited on an annual basis to see where all their access devices are and to ensure none of them are being tampered with.
No blockchain is needed to achieve this.
DRM is only as strong as the legal mechanism behind it.
Since the DMCA and other legislation protects DRM the actual strength of the DRM are irrelevant.
DVDs are still protected by the same broken key, BR are also broken every DRM system gets broken or is easily circumvented through side channels.
Like FB implemented as Signal on steroids, when I add a friend I exchange keys to open up a channel with him to enable him to see posts/photos etc from my life, but the org (say FB) itself cannot see any of this data.
Not sure how blockchain will fit in here though or enhance this
All of these things can be done with trusted intermediaries, but when you start considering use cases such as - being in china and needing to allow a chinese hospital to access your records back in the USA, suddenly these things become important.
For example, how are you defining trustless? Personal data systems needs to be based on trust and reputation (otherwise you’ll have a bunch of 4chaners spamming claims about you) so are you simply thinking tamper-evidence and non-repudiation? That’d raise the questions of why this would be better than PKI, Merkel trees, etc.
All of the other claims hit similar problems: e.g. you can’t store the data in a blockchain and make any of those promises, and it’s not clear how useful a shared index or log would be when you can’t trust all of the participants.
Another fatal flaw is the lost of control and inability to correct mistakes. If there’s ever a vulnerability all of that data is irrecoverably public. What organization is going to turn control of something they get sued for over to an entity they don’t control? “They told us the software was perfect” doesn’t seem like a good HIPAA defense tactic to me.
Some one can make a copy, game over.