Data as a Property Right
yang2020.com
yang2020.com
It doesn't address the biggest privacy concern: the government's collection and use of personal data. No restrictions there, I guess.
Information wants to be free - even when it's about you. Putting that genie back in the bottle - the right to be forgotten - creates a world that is less free.
We should be really going the other direction and not allowing these corporations to hold this data in private silos to re-enforce their monopolies. They use the force of law to hold these monopolies over the things you've written so that it's their property and not the property of the individual. That's wrong and that's granted by the government.
Is freedom worth the harm it enables? That is a choice everyone has to make. Most people are willing to give up a lot of freedom in exchange for mitigating harm.
Yes.
When someone says "I give up this freedom" it's often because they don't use it or it doesn't affect them. The problem is that what they are really saying is "I give up this freedom for myself and everyone else."
This is bad when you have a large group willing to give up a freedom they already don't use or care about that only affects a minority of people. The problem comes that a different, overlapping large group is willing to give up another freedom and now the minority affected by that loss was part of the first large group. It's easy for this to continue until everyone has lost a freedom they enjoyed because they signed up with some large group, often thinking they were 'right'.
TL;DR: The road to hell is paved with good intentions.
I'm pretty sure Yang is the best thing to come out of this election season so far, even though I have to disagree with him on a large number of items, at least he's forcing some conversations.
I don't agree that this is the biggest privacy concern. In my opinion, this is just as concerning as corporate collection and use of personal data.
> We should be really going the other direction and not allowing these corporations to hold this data in private silos
We should not be allowing anyone to collect this information (without informed consent) in the first place.
As a singular example, right now a private corporation (Equifax) has as much say in my ability to be employed as the government (if not more).
It is accepted (I believe) that it is reasonable that federal judges and police officers don't have publicly published phone numbers, similarly people who have been stalked or threatened or doxed have demonstrated why things shouldn't always be public.
I definitely agree that private corporate data silos are no good (since they're essentially public data silos as soon as they're compromised but serve to monetize your privacy by selling it to third parties in the mean time) but I disagree that all data must be free and I am certainly not offended by people's desire to have a modicum of privacy in the modern world...
All that said if the monetary value of this data is removed by restricting private usage of it then we'll likely see the equation of value vs. cost for companies storing data shift back to preferring to store as little as possible. Disallowing private data silos may effectively restore a measure of privacy to most people by removing anyone's motivation to collect data.
on the other hand, the first few years of having everyone's search history be public could be pretty chaotic...
To prevent cases where the "something" that the smart contract does is "copy all your data bit-for-bit and upload it to my evil masters", you could perhaps apply information entropy, on a platform level, to the source and output data, and only allow the transaction if the output data contains many fewer bits than the input. So say you have all of your location data and review history on the blockchain, encrypted with a private key known only to you, and you want to grant an application the ability to recommend nearby restaurants that you might like. You authorize the transaction, and expect that the contract will release ~1K to you (a restaurant name, description, menu, reviews, and geocode) and will increase the data stored within its own data ownership by 0 bytes. If it does something otherwise, it's broken the contract, and can be automatically penalized financially (because this is a blockchain, it inherently needs a cryptocurrency).
I've had an idea for something like this since hearing about Google's Federated Machine Learning research paper and reading the Ethereum spec, but have other more pressing projects right now and don't have time to implement it. If anyone feels it's interesting, feel free to steal - I'd still love to work on it at some point in the future, but there're still some holes in the idea (notably around the information theory & federated learning aspects) and another speculative research project isn't really what I'm looking for now.
Meanwhile, blockchain computation is about getting useful work out of untrusted participants. It doesn't seem like a fit.
Also, how do you do any calculation at all without decrypting the data? Or if you're thinking homomorphic encyption, what does a blockchain have to do with it?
I think a more realistic (but way less money for speculators) is to store PKI on a blockchain, then encrypt any blob anywhere and sign. Send that signature to the smart contract and have them pull blob from non-blockchain store.
If it’s something that the owner has agency issues with (eg, calculating fico score) then register the hashes of the data with a blockchain.
No need to store the data on the chain unless you’re worried about it disappearing.
Frankly, given the long history of data abuse, security problems, and generally anti-human practices by IT and tech companies, I'd be perfectly fine if cowboy developers not be allowed to touch this product space.
That's not to say that large tech companies are blameless angels in any of this.
For some reason people think comparing loss of privacy when voluntarily visiting a website to deaths caused by car accidents isnt intellectually dishonest.
Sure, I don't value my privacy, the security of my financial information, etc as much as my life.
But it's close.
In other words, I think it's a good idea.
If I draw a picture of you, is it your data or mine?
If you walk through my house and I store the pattern you leave in my WiFi signal, is it your data or mine.
I think we’d have to narrowly define what belongs to an individual and it would be too narrow to address the problem.
Also data as property would get signed away for nothing like how arbitration clauses are in practically every contract with no added benefit to the signer.
Clearly mine. You recorded information about me without my consent.
Or all of the above?
There should be no expectation of privacy in public places. Commercialization is a different story, I think.
Second order effects from this crazy policy are nearly infinite.
Note that I’m not talking about the intent of the regulation, but rather the issues of implementing it.
- The right to be informed as to what data will be collected, and how it will be used
- The right to opt out of data collection or sharing
- The right to be told if a website has data on you, and what that data is
- The right to be forgotten; to have all data related to you deleted upon request
- The right to be informed if ownership of your data changes hands
- The right to be informed of any data breaches including your information in a timely manner
- The right to download all data in a standardized format to port to another platform
>>>
The vast majority of these rights only work when applied to commercial entities. They don't protect you from government invasion, and they don't protect you from individual/social invasion. When applied on the individual level, many of them are flat-out unconsitutional (the right to be forgotten is a particularly obvious example).
Does this matter? Is it a problem if we specifically target corporations first? I think it does matter.
Even though corporations are currently some of the worst privacy offenders, I think there's real harm in orienting the privacy debate around Capitalist terms, and I think it sets a really bad precedent for future conversations. I strongly suspect that a pivot to talking about privacy as a property right being violated will make it easier for the government to dismiss future criticism, and easier for malicious groups to claim that data from public sources should be fair game.
My right to privacy is not based on the idea that I am being economically harmed. It's based on the idea that I have a fundamental right to hide my identity, and a fundamental right to choose what I disclose to the people around me. Money has nothing to do with it.
This proposal also goes against years of collective advocacy from activists for both an Open web and a private web that no one can own a fact. I firmly believe that the expansion of IP laws are counterproductive, even when expanded ostensibly for the sake of privacy.
Andrew Yang may speak for some members of the privacy community, but he doesn't speak for all of them. I really wish the politicians who are just now jumping on the privacy train would spend more time looking at the history behind these debates and the history of the activists that were working before them.
What truth am I forcing someone to be silent about if I simply don't want my personal data used for malicious or unwarranted commercial purposes?
If people are spreading lies about you in the US, you can sue them for defamation. Beyond that, silencing someone because what they're saying 'isn't relevant' goes against the US interpretation of the 1st Amendment.
Arguably, we can create exceptions there for corporations (although we should expect a few court cases about it). But the (US) government can't restrict me as an individual from talking about another person's past in private or public spaces.
If one objects to the right to be forgotten altogether, then one objects to the right to demand that even false and libelous content can be removed from the internet. You can sue for defamation, but you can't prevent the publication and spread of defaming content.
>But the (US) government can't restrict me as an individual from talking about another person's past in private or public spaces.
Yes but the right to be forgotten doesn't apply to private or public spaces, it applies to data on the internet, or am I mistaken?
The government doesn't ban firearms, automobiles, knives, etc. because they have potential to cause harm, so why would the government break freedoms to censor information on the basis that it has potential to cause harm?
Defamation (libel/slander) is not a crime and is not censurable as such, but you can be sued for the damages (harm) that it causes. You are free within your first amendment rights to leave that defaming information up after it is proven to cause harm in civil court, but then you are still liable for the damage it continues to cause.
IANAL, but this is a weird interpretation to me. I'm not sure how to describe a court fining you for publishing information other than, "compelling you to remove that information."
I dunno, this really doesn't line up with my understanding of libel laws.
Of course, bear in mind that the Right to Be Forgotten has very, very little to do with libel. If we were just talking about libel, we'd use existing libel laws. The fact that Right to Be Forgotten exists in addition to libel laws should be enough to show that it is targeting different information.
I dislike that people bring up libel when debating Right to Be Forgotten, because I view libel laws as largely irrelevant to the debate. It's just trope #3 again[0].
[0]: https://www.popehat.com/2015/05/19/how-to-spot-and-critique-...
> If one objects to the right to be forgotten altogether, then one objects to the right to demand that even false and libelous content can be removed from the internet. You can sue for defamation, but you can't prevent the publication and spread of defaming content.
We have exceptions to the 1st Amendment for defamation and copyright. They are very, very narrow exceptions.
The Right to Be Forgotten works in Europe largely because Europe has different standards than the US on what Freedom of Speech means. When a US citizen and a European citizen talk about Freedom of Speech, they're not necessarily talking about the same thing.
That's not to say Europe's take is necessarily wrong. But it is to say that Andrew Yang is running to be the president of the US, so the European interpretation of Free Speech isn't relevant to his platform proposals.
> the right to be forgotten doesn't apply to private or public spaces, it applies to data on the internet
Public/private spaces don't go away on the Internet.
A corporation or private actor can delete content from a forum/website they control for any reason. They have a Freedom of Association. But the US government may not compel them to do so, except where that content falls into extremely narrow exceptions that have been carved out over decades of legal debate.
It feels like you’re talking purely philosophically and ignoring the nuance of our legal system.
SCOTUS, including right wing literalists, have held that Constitutional rights are not iron clad in all contexts.
Main Street seems to believe the first amendment is very broad, but then there’s the whole shouting fire in a crowded room. Instigating acts of violence and threats, etc.
Freedom from and freedom to are distinct concepts in our legal system.
I fail to see the issue you bring up.
It's something that some people want, obviously, but is the government really the best candidate to enforce it?
I don't think it's even possible to apply these as blanket rights to all data. Focusing on certain domains (healthcare, finance, etc...) will help.
Many companies already provide the option to download all data, and I've written GDPR data request mails to multiple US based companies with success. Mostly you get the data in JSON files (without schema).
Right now, many companies are trying as hard as they can to skirt the law, but there's land mark cases happening already that will hopefully put an and to that soon [1].
[1]: https://techcrunch.com/2019/10/01/europes-top-court-says-act... ironically, techcrunch is a prime example of a "tracking cookie consent" popup that is absolutely illegal and will hopefully get them huge fines once the data protection agencies have their hands less full with bigger fish (google, facebook, etc).