Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Each time I read that I'm reminded of Sherlock Holmes. Sherlock Holmes can look at a person and tell you everything about them by just deducing facts from observable facts and cross-referencing what he knows. He can do that, because he's exceptionally smart and knowledgeable, neither of which is illegal - you can't forbid people from being smart and knowing things. Having a machine to do it for you, to me, is a natural extension of your mind, so I feel very much against outlawing a method of doing something, which would not be illegal if you could do it by being exceptionally smart.

Still, I really don't want corporations to have such power over people. The difference between Sherlock Holmes deducing that I usually ride a bicycle to work and a computer system deducing that, is that the computer system then proceeds absolutely automatically to spam me with offers about bike safety gear and indiscriminately shares that information with third parties.

So perhaps the answer here is not to outright outlaw data collection, but to find a model where there is someone personally responsible for your data that will safeguard it and make sure it's not misused.

Imagine a data bank institution, which collects and stores your data and then only allows a very limited access to it to certain parties. You sign up with a databank and pay a monthly fee for your account. Then, whoever wants to collect data from you uploads it to the databank's servers, never stores it locally, and you have full access to it. Each party that collects data on you can access all the data they have stored on the databank's servers, but not the data of some other party, without your permission, and you can always revoke sharing rights or just disallow someone to store data about you, effectively turning off data collection for them. It might also be a good idea to disallow parties that upload data to a databank to compute locally with that data. That is, if someone wants to perform some inference on the data they've collected, they upload a program to the databank, the databank runs it on their servers, subject to access controls that you can modify, and then they get back the results of that computation.

In this model you're the one paying for the safety of your data and the people keeping it are making money not from giving it away, but from keeping it safe. And you can't keep people's personal data without being a registered and regulated databank.

So next time you sign up for a Target card, you give them your databank account number and have full control over your own data.



"Having a machine to do it for you, to me, is a natural extension of your mind"

To you, just to you, really.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: