‘It's not too late to think differently about privacy’
‘It's not too late to think differently about privacy’

‘It's not too late to think differently about privacy’

Not a day goes by that you do not share large amounts of personal data with large organisations. This happens not only when you are active online, but in the ‘real’ world too: while parking, making reservations at a restaurant, travelling by public transport, or paying for your groceries (with or without a bonus card) in the supermarket. We often share that information without being fully aware of it, but to a large extent, we appear to have simply accepted this, even though privacy-friendly solutions are often within reach, says associate professor Jaap-Henk Hoepman in his latest book.

How much personal data do websites really collect? What do we actually have to hide? And, for the sake of convenience, should we accept that not all our data can always be protected? In Privacy is Hard, and Seven Other Myths. Achieving Privacy through Careful Design, Hoepman discusses some of the many the myths surrounding privacy.

Hoepman: “There is an incredible amount of interest in privacy risks these days. Ever since the Snowden’s revelations in 2013 and the Cambridge Analytica scandal, more attention has been paid to privacy, but because we have started doing much more online during the coronavirus pandemic, this has led to even more attention.”

“However, even though we like to complain about privacy risks, you rarely hear anything about solutions. This creates a dystopian image: it's all terrible and it's too late to change,” Hoepman often hears. “With this book, I want to explain to people how this technology works and what can be done differently. Similar to how you can easily estimate from a distance how fast a bicycle is approaching or whether a bridge is safe, I want to give people tools for recognising privacy risks.” To help people get started, Hoepman has debunked a few myths.

‘I have nothing to hide’

“Of course you have something to hide. Otherwise there is no difference between you and the world around you. There are plenty of things you want to keep under your control. For example, my sexual orientation is nobody's business, and when I am looking for a new job, my current boss or my co-workers don't have to know right away either. In addition, seemingly insignificant personal information from various sources can be bundled together by algorithms, allowing an organisation to sketch a complete profile of you.”

“Privacy is not only an individual interest but also essential for society as a whole: without privacy, there is no democracy. For example, consider the possibility of certain groups being able to meet safely, such as people today in the LGBTIQ+ movement, or previously in the black civil rights movement: they must be able to talk to each other in private without being directly in the line of fire. It still carries risks in some countries, and in such cases, privacy is literally a matter of life or death.”

Aren't privacy-friendly solutions very complex?

“Not at all, we've just become overly accustomed to our current solutions. That's what I call technological determinism: the idea that the Internet just grew this way, so that's how it should work forever. But the Internet is something that we are developing together as a society, and it can also grow in a different direction.”

“Imagine that you go to a busy restaurant with a group of friends. If there are no free tables, your name, telephone number and the time will be noted, so you can be notified when a table is available. An additional advantage for the restaurant owner is that he can use this data afterwards to find out which days, or which times of the year are the busiest, and ensure that more staff is present at such times. This sounds useful, but it also creates an entire database that contains all kinds of personal data about the customers.”

“Luckily, there is another, much simpler solution: a numbered waiting list. The restaurant notes owner the group size and assigns a number to the group. As soon as enough space is available, the group with that number can be seated. The restaurant can still analyse peak times, but the customers don't have to worry about their personal data being collected and stored. You can come up with comparable solutions for many situations, both on-line and off-line. You just have to be open to these ideas.”

Why do I have to do all this work to protect my own privacy?

“It indeed involves too much work and hassle, and that is actually the core of the problem. That is why you should not put all the responsibility on individuals, as is happening today. For example, compare our need for privacy with our responsibility for the environment. Each of us can make a small contribution, which would certainly help, but our efforts as individuals have little impact if no restrictions are placed on big polluters as well. For example, this can be done through legislation and regulations, through technical innovations that protect the environment or by promoting environmentally friendly alternatives. We should also consider using this model for the digital services we use. As an individual, you do not have enough knowledge or resources to take effective action, but organisations shift the responsibility for digital privacy onto us. This should change.”

“Governments can clearly play an important role in this process. For example, look at the General Data Protection Regulation (GDPR). This is European legislation, but it has worldwide consequences because companies usually don't bother to build separate systems for each region. The system converges to the strictest standard, as long as someone has the courage to be the first to put pressure on companies. I am moderately optimistic that this can lead to major progress in the coming years, especially if the protection is not only legal, but also technical in nature.”

What kind of developments are possible?

“The problem with almost every online system is that you have to sign up. You have to create an account that requires your personal data. That's actually really weird. If I want to go to a concert or to the cinema, I can buy a ticket at the box office without sharing any personal information. Or, even simpler: the front door of my house is locked, protected and safe, and can only be opened with my own unique key.”

“That's why I'm very proud of the research we are doing at iHub at Radboud University. A very good example is IRMA, which started here but is now being developed independently. It is an alternative login system that allows you to determine which attributes you share with an organisation and when. With IRMA, you store your attributes securely on your own phone, and you only provide relevant information to an organisation when that information is really needed. For example, if you need to prove that you are older than 16 so you can log in somewhere, then you do not have to share your entire date of birth via IRMA, but only the attribute that you meet that age requirement.”

Privacy is Hard and Seven Other Myths. Achieving Privacy through Careful Design will be available on-line and in book shops from October.

Image: Unsplash

Contact information

Theme
Privacy, Media & Communication, Innovation