Ask Slashdot: How Do You Protect Your Privacy When It's Out of Your Control?
An anonymous reader writes "A week ago, Slashdot was asked, "How do you protect your privacy?" The question named many different ways privacy is difficult to secure these days, but almost all of the answers focused on encrypting internet traffic. But what can you do about your image being captured by friends and strangers' cameras (not to mention drones, police cameras, security cameras, etc.)? How about when your personal data is stored by banks and healthcare companies and their IT department sucks? Heck; off-the-shelf tech can see you through your walls. Airport security sniffs your skin. There are countless other ways info on you can be collected that has nothing to do with your internet hygiene. Forget the NSA; how do you protect your privacy from all these others? Can you?"
...you can't. That's what "out of your control" means.
I don't believe that technological privacy is achievable, and I'm skeptical that it's valuable. Whether cryptography actually works (an interesting mathematical question in itself), cryptosystems fail fairly often. Even when they do work, to truly be untraceable or private with them you have to effectively opt out of commerce. Don't logon to anything when you're using Tor, kids; also, don't use Google, since they can always watch your referer tags and see 3/4 of your pages that way. The problem with privacy as we normally talk about it is that it is extremely fragile -- what we've historically taken as 'privacy' was really laziness -- going back to my example from the detective firm above, all this information was already there, it was just split into a couple of dozen different archives and databases. Beforehand, it took time and effort, so you had privacy because unless something was really important, it wasn't worth the effort of searching. Now, it's very easy to record and archive, and we've been focused for many years on making recording and archiving easier, and we elect to be recorded and archived in order to participate with other people -- bank won't serve you if you're wearing a ski mask, visit vegas and you'll see that any table game has very specific gestures and rules to make what you're doing camera-friendly, want a loan you need to have a credit rating.
So, privacy has to be implemented, which means its going to be a combination of legal, technical and social elements. Technical in the same sense as breaking and entering -- the definition of B&E is that the breaker has to make -an- effort, regardless of how trivial. Lifting a latch is considered B&E, and similarly you need some indication that you're trying to achieve privacy. Legal in the sense of limiting the consequence when your privacy is breached.
One option I've heard is a property right, such as ownership (similar to copyright) of personal information. Joe "owns" his name &* address, and he'll loan a copy to Time Magazine for the purpose of delivering the periodical he has paid for. Any other use of Joe's information by Time Magazine is a violation, unless Joe & Time have come to some other agreement. This is very similar to copyright, so let's just call it personal copyright.
Copyright might be too blunt an instrument though, because remedies mostly involve (expensive) civil suits. A number of European governments passed legislation called Fair Information Practices. These laws basically say that personal information can only be used for the purpose for which it was given, and cannot be repurposed without consent of the person involved. Probably the governments involved have given themselves a loophole for national security, but I haven't investigated the details. This option reduces the cost to the individual, and makes it the job of the government to enforce the law. I see this as a benefit, though some may not.
Writing Fair Information Practices into law would probably explode the business models of the currently most successful tech companies in the USA, so maybe there's a way to ease into the laws and allow the tech companies time to adjust their business methods...
--- Often in error; never in doubt!
And for the TSA, lead condoms with scrotum wings.
09 F9 11 02 9D 74 E3 5B - D8 41 56 C5 63 56 88 C0 45 5F E1 04 22 CA 29 C4 93 3F 95 05 2B 79 2A B2