Increasingly, I'm of the mindset that you shouldn't create data you can't destroy; "smart" thermostats, cameras, and whatever else all seem to create a bunch of data and upload it to the cloud. Once there, it's out of your control, and can be subpoenaed and used against you.
I remember the brief period when teaching internet literacy involved teaching people that any text, photo, or video, uploaded to the internet should be considered public, regardless of how the access was limited at the time of upload. Now, people[0] are buying smart devices and uploading all kinds of stuff without even thinking about it.
To a lesser degree, we see the same situation with Event Data Recorders in cars. They record data that can be used against the user in the event of a crash. Are most people aware of this? I doubt it. Having sat on a couple of juries, I've witnessed how ruthless lawyers can be about picking apart an innocuous action to support the case they're making, whether there's malice/negligence/whatever behind it or not.
Maybe we ought to treat creating data as a special case of "Don't talk to the police"[1]
[0] Lay people, the HN crowd is probably making an informed choice. We aren't the majority though.
The real key is don’t put original data in the cloud, period.
If you save your surveillance data to a disk in your home, it’s subject to the traditional old fashioned warrant process. Once a third party has access, you have given up your rights in many ways.
Cloud for these use cases is dumb for many reasons. You don’t need cloud compute, don’t need cloud storage for the use case. I was able to do what these consumer cloud products do with raspberry pi type hardware a few years ago.
Yes. Once you give your data over to a 3rd party, any privacy or adherence to legal process is benevolence on their part. There is nothing (in the US) that requires them to treat (most) data as private information.
> create a bunch of data and upload it to the cloud. Once there, it's out of your control, and can be subpoenaed and used against you.
honestly don't know why anyone uploads to the cloud. there's tons of reasons not to, starting from the icloud hacks to [your favorite app]'s RCE bug.
it takes 5 seconds & $30 (pi) to spin up your own server. it's fun to do and at least you know the only possible F-up is between you, your linux server & your comprisable ISP
GDPR is a government regulation, and governments are routinely above their own regulations, especially when it comes to intelligence. To quote one former US Vice President: "Of course it's a violation of international law; that's why it's a covert action".
GDPR provides a legal framework through which Europeans are able to get companies to honor their wishes with data .
While it has teeth, it does nothing to physically stop a bad (or unconcerned) actor from don't something you don't want with that data, and once they have it you can't put Pandora back in the box.
Once the data is out there, though, you're vulnerable. You can "destroy" it later, from the perspective of a company, by asking the company nicely to destroy it for you, but that does nothing to protect you from state actors who may have had access to the data before. In fact, a state actor would likely take "asking nicely to destroy data in accordance with the rules and regulations" as a signal of which data was the most interesting to collect and retain.
Exactly, and one of the main points GDPR is to force companies to think twice before collecting data in the first place. Thanks to GDPR significantly less data will be out there.
Computers are machines for copying data. A good computer is one that copies well, quickly and cheaply. The internet is a machine for moving copies of data around. When the internet works well, it copies data quickly and cheaply.
Ideologically, this is difficult for some people to accept. If your fortune has been based on stopping people from copying information, it is an inconvenient truth indeed. If you earn your living by preventing copying, the only options are to change everything, or deny everything.
Whilst GDPR partly aims to help educate the user about data being collected, the extend and details of such data are underestimated. Mostly because no company specifically calls out the exact data they collect; They describe it broadly to avoid having to ask for consent again when they add a new product or feature. You only truly understand what data is collected once you make use of the obligated download feature and look through the data.
Also, GDPR does not apply to Intelligence Services, their legal limitations are dodgy at best (on purpose).
All data going over the internet cannot be destroyed by you since it can be copied by anyone who has physical access to the network (the government and ISP for starters). What you can do is apply strong cryptography on your data by default.
Yeah, I agree with your sentiment. We pay with our privacy.
On my home I use a few cameras for our little one plus the cats. I use a VPN on my router, and the cameras cannot connect beyond the router. I can however connect from e.g. a smartphone (with WLAN or 4G) to the VPN and access the cameras. As long as your cameras utilise standards such as RTSP this shouldn't be difficult to set up.
No PrivaCorp? Make / fund PrivaCorp and migrate after a stable Beta
Normally we don’t care about our online privacy (proof is in the pudding with facebook et. al) so historically there isn’t a big enough market online for megacorp-level privacy-oriented web-product stickiness and growth... But I think a very tangible line is crossed inside the home that consumers can resonate with as networked home devices start to become ubiquitous.
Online is so abstract. But at home? That’s where your wife sleeps. That’s where your baby sleeps. We won’t spend a dime on a password manager but we will spend a good amount on fencing and window curtains and locks and home security systems.
I remember the brief period when teaching internet literacy involved teaching people that any text, photo, or video, uploaded to the internet should be considered public, regardless of how the access was limited at the time of upload. Now, people[0] are buying smart devices and uploading all kinds of stuff without even thinking about it.
To a lesser degree, we see the same situation with Event Data Recorders in cars. They record data that can be used against the user in the event of a crash. Are most people aware of this? I doubt it. Having sat on a couple of juries, I've witnessed how ruthless lawyers can be about picking apart an innocuous action to support the case they're making, whether there's malice/negligence/whatever behind it or not.
Maybe we ought to treat creating data as a special case of "Don't talk to the police"[1]
[0] Lay people, the HN crowd is probably making an informed choice. We aren't the majority though.
[1] https://www.youtube.com/watch?v=d-7o9xYp7eE