I don't trust in the government, but I think digital "personal data" should be only available for "confirmation" to companies that need it. Say, a government entity could have an API that allow you to send hashed personal data that they can verify is right. This way companies will ask the user for their data and hash it client-side. Then they can send the hashes (hashed with a custom provided salt to the entity (government, maybe private) who will basically reply with a True or False on the verification of the different data.
It may even be an interesting use case for a public blockcahin, where your personal data is stored in a Merkle Tree type of data structure, so that one can verify that certain pesonal data of a person is true, without disclosing the data.
For example Estonia has had famously and online identity stuff linked via a federal ID (in europe there are more republics then federations so it's easier to manage country-wise) [0] [1]
Or more familiar to me with a bigger sample is a movement in Poland which is gaining popularity - mojeID (myID) which is a Single Sign On system with major banks as providers (they really regligiously check the identities when you open a bank account) or the statebacked login.gov. The mojeID system allows other entities to use your actual identity as an authentication factor without having to keep that much data and pose risks - for example an online alcohol shop can verify the age. [2] [3]
[0]: https://en.wikipedia.org/wiki/Estonian_identity_card
[1]: https://e-estonia.com/solutions/e-identity/id-card/
Humans will error and enter data incorrectly so the hash would be different every time potentially despite being "correct" to a human at a glance?
You could standardise everything (lowercase etc) but I imagine there are country and regional edge cases such as capitalisation having meaning in a given language (I can imagine it being a thing but I don't know it for sure)
This sounds like a good use case for short brief documentation.
Equifax has more at stake than most. And they've been hacked. Repeatedly. The government has been hacked. Yahoo was COMPLETELY owned. I mean, if someone would put together a list, it would make for shocking reading. It's become so common, that we go, "Oh no! Anyway."
I think this demonstrates that user data can be managed safely and effectively.
Usually the incidents reports on user data leaks show that the company seemed to barely be trying - We need laws that force them (even small companies) to put serious effort into it.
Am I reading this wrong, or are you saying that activists would be more likely to leak data? Then I would wonder what kind of activists you have in mind.
Agreed that yes indeed it seems possible to build a security serious company, and that Google is (seems to be) a good example. (Now, there are other things I don't like about Google but I guess that's of topic.)
Ideological employees of big tech firms taking a sudden disliking to someone or some group and abusing privileged access is certainly a threat that ever larger numbers of people are talking seriously. In particular, it is a concern for industries that do things activists don't like, such as working with immigration control (though perhaps that's no longer an issue now Trump is gone).
Sounds interesting, you don't happen to have a link? (So I can read more)
Kathryn Spiers, who worked as a security engineer, updated an internal Chrome browser extension so that each time Google employees visited the website of IRI Consultants — the Troy, Michigan, firm that Google hired this year amid a groundswell of labor activism at the company — they would see a pop-up message that read: “Googlers have the right to participate in protected concerted activities.”
Discussion here: https://news.ycombinator.com/item?id=21813619
Note that she wasn't able to do that unilaterally. Some other member of the team approved her CL and others defended her in public.
I have a vague feeling there was another case like this some years ago where some security engineer modified a Chrome extension for political reasons, but I can't remember the exact details and can no longer find it.
- "How much money is currently owed in taxes to the government?"
- "Can't tell you that, we're not allowed to aggregate data".
Edit: what I was thinking originally was that in the world of paper-only archives, these massive leaks were all but impossible, yet business could still be done. It should be possible to combine this slowness with the convenience of computers.
That said this is certainly interesting, I wonder if there has already been an exploration of this topic. Could definitely make an interesting startup idea :)