Skip to content

Comment on Condoleezza Rice, surveillance and torture fan, joins Dropbox board

Comments

As a country, we are having a great national conversation and debate about exactly how to manage privacy concerns

The phrase "having a conversation" or "having a debate" shits me off more than any other bullshit speak. The reason being, whenever somebody uses it, it is exactly because they don't want to have a debate about that topic because they know they're in the wrong. Nobody ever says "we're having a debate about privacy" and then goes on to actually debate it. It's just used by companies or organisations who are doing something objectionable and want to see whether they can get away with it. If everybody complains, well they "listened to your feedback" and can it.

For example, I went to a panel recently about Google glasses that had some Google employees on it. Every time privacy was brought up they said "well that's a debate that we [society] should be having" even though they were literally in a debate about it right there, they never actually put forward their case. They just leave it at this vague notion of a "conversation" that society is having in general without engaging in it themselves. And it's because they know people are opposed to what they are doing, and so engaging in an actual substantive debate about it won't help them at all (not really trying to pick on google here, this is just the first example that came to mind). They just want to ride out the storm and then continue doing exactly what they are doing.

As you said, the phrase "having a national conversation" is a thought-ending cliche designed specifically to terminate constructive thought on the matter in question.

I think the correct response to that kind of statement is, "so, defend your opinion right now, and we can further this 'conversation' you're referring to." Force a fight, then win using facts.

The debate is really happening, because it is impossible to provide a browser-client cloud data service without also creating a massive collection of people's private information. And this entire ecosystem has been largely unregulated to date.

In daily life the debate looks like this: "that service could make my life better, and it's free. But do I feel comfortable sharing my info with this company?" Remember the big news cycle about Gmail's ad targeting technology? But since then millions of people have signed up to use Gmail anyway. So I would not agree that society as a whole has deemed this sort of thing to be wholly bad.

impossible to provide a browser-client cloud data service without also creating a massive collection of people's private information

Well instead of just hoovering up every photo you take with Glass into G+ [1], they could implement even a fig-leaf's worth of client-side encryption. This is far from impossible. Just saying.

[1] Not just by default, but as I understand it, without even the option of turning that off.

Client-side encryption doesn't help much with privacy concerns because the client and the server are both wholly produced by Google, so you have to assume that Google can pierce that encryption if they want to. That's exactly what happened with DropBox.

It helps protect against unauthorized access, but doesn't really address privacy concerns with Google itself.

I did say "fig leaf". But some level of client-side would at least demonstrate good will, or some level of "giving a fsck".

There is a real difference though, which is the difference between code on your client which perhaps you could at least check if you're stubborn enough[1], and plaintext in a datacenter. This can mean the difference between targeted surveillance and mass surveillance.

Dropbox is a separate case - it was always "trust us" (we have your keys) encryption, and not what I would refer to as "client side" at all.

[1] This is a hard problem if you don't trust the OS

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.