Slashdot Mirror


UK Backs Off From Banning Reidentification Research (theguardian.com)

An anonymous reader writes: The United Kingdom has recently debated banning reidentification in its new data privacy law. This proposal has quickly been identified as dangerous and criticized, as it was argued this is not only ineffective but would also put at risk legitimate security and privacy researchers. Following public outcry, the UK government amended the bill to include safe-guards allowing researchers to study anonymization weaknesses. Researchers will also gain a new channel of disclosure via the Information Commissioner Office (ICO). According to The Guardian, "Researchers will have to notify the ICO within three days of successfully deanonymizing data, and demonstrate that they had acted in the public interest and without intention to cause damage or distress in re-identifying data."

1 of 10 comments (clear)

  1. RE? Identification by Anonymous Coward · · Score: 2, Interesting

    Lets consider Google.

    Google obtains the location (from its location services), name (as specified by you), email (gmail needed for android), ip address (lots of ways), browser profile (lots of ways), real name (credit card used on Google Play), real address (credit card), car driven (from Android Car sync), websites visited (google analytics, Google adverts, Google tag manager,Google content delivery network etc), telephone number (Android), friends and contacts telephone numbers (Android), Wifi passwords of every network around you (Android cloud backup), who you are with at the moment (sniffs surrounding Wifi under guise of location services), your future plans (Google Calendar), your words (Google Assistent), your conversations (chat/email), probably an insane shitload of other stuff you and I don't know about.

    It also gives itself permission to cross link that data.

    It tells you a tiny fraction of the data it links based on the account id.

    OK, so now imagine a dictator or his puppet with that data and you have control. e.g. Puppet put into UK leadership with help of foreign attacking government, signs access to that data to UK security service (already done), who then are instructed to share that data with foreign attacking government to tackle some exaggerated threat... muslims..... mexicans...china..... or something.