
Not so secret anymore (Image: Bobby Yip/Reuters/Corbis)
ONLINE privacy as you know it died last week. But the reaction to the release of Ashley Madisonâs dossier of more than 30 million people seeking affairs was one of muted resignation. one commentator declared. Another bemoaned ââ. The received wisdom is clear: our data will never be safe.
Advertisement
This collective shrug is the result of security fatigue, says privacy researcher Helen Nissenbaum of New York University. The companies who store our data have all the power, but the responsibility for protecting it has been placed on individuals. And weâre ill-equipped for the job. If you were using the Ashley Madison site, the strongest password in the world wouldnât have kept your details off the growing number of searchable databases now being scoured by suspicious partners and those looking for dirt.
And itâs not just members of illicit websites who need to worry. âAll of us are shedding data with no clue as to how it is being used, abused, protected â or not,â says Nissenbaum. We are simply meant to have faith that the trade-off of our data for what the company offers us is worthwhile, she says.
âAll of us are shedding data with no clue as to how it is being used, abused or protectedâ
It is certainly worthwhile for the companies. Sliced and diced and sold to third parties, data can be a bounteous cash cow. What you get out of the deal is less clear. One thing we do know is that the model of trusting someone else to hold your data has failed.
Some researchers think you should revoke some of that trust. âI canât believe people put their real names, email addresses and credit card details on to a website like that,â says Krzysztof Szczypiorski, a security researcher at the Warsaw University of Technology in Poland. He thinks the Ashley Madison hack will be a watershed moment for peopleâs understanding of just how exposed their data is. He says people will start to avail themselves of smarter ways of disguising illicit behaviour. Email accounts under a different name, and that can be loaded anonymously, for example, âwould have saved a lot of peopleâs marriagesâ, he says.
Question of risk
Instead of people storing and sending unencrypted nude photos, Szczypiorski thinks steganography will become more popular â embedding a nude photo inside an anodyne picture of ducks at a park, say.
But while those options will work for the tech-savvy, Lee Rainie at the Pew Research Center in Washington DC thinks they wonât necessarily trickle down to all people. âEven though they are reminded frequently that their data is at risk,â he says, âitâs pretty clear that many are making only modest changes â if at all.â
Sandy Pentland of the Massachusetts Institute of Technology says that putting the onus on individuals is misguided. âItâs the data collectors that are the problem,â he says. âThey have never had any stake in making your data secure.â
For Nissenbaum, itâs a question of risk. âIf a data collector does not provide adequate security, thereâs a small risk to them and a potentially large benefit.â
The spate of recent hacks may be changing that (see âA history of hacksâ). Breaches such as that affecting Sonyâs files last year demonstrate that hacks can damage not only the lives of people whose details are stolen, but also the companies deemed liable for the theft.
Sony suffered financially but survived. Ashley Madison may not fare so well. âUnder data protection laws, that case will be a slam dunk,â says Patrick Rennie, who specialises in data protection at London-based law firm Wiggin. In the past, it has been difficult to prove damages or distress, he says. âThatâs not going to be a problem here.â have been filed in the US and Canada.
âA couple more hacks like this and it will start to change the attitude of the data collectors to holding your data â from cash cow to liability,â says Pentland.
Over the past year, there has been growing awareness that , according to IT market research company 451 Research. So what will happen when companies lose their appetite for storing data?
Several protocols are in the works that would change the way personal data is stored. Instead of simply throwing up our hands in frustration every time our data is violated, we could revoke access to it even when it already exists on the open web. It would be the online equivalent of squeezing toothpaste back into the tube.
âEnigma would let you reclaim your data â like squeezing toothpaste back into the tubeâ
âIn the current model, the data lives someplace and you have to protect it,â says Pentland. âIf you share it with someone, they can run away with it. You can chase them, but itâs pretty hopeless.â So he and his colleagues Guy Zyskind and Oz Nathan have developed a protocol called Enigma, based on the blockchain â the secure digital ledger that tracks bitcoins across the internet.
Instead of having all the data in one place, Enigma constructs a âholographicâ version that it breaks into many encrypted pieces and stores in far-flung spots. Anyone can use the Enigma protocol, Pentland says, including Netflix, banks and health providers, but you would be the gatekeeper of your data. You would have the power to give permission to third parties to run queries on it, and the power to revoke that at will.
Think of it as a jigsaw puzzle whose pieces are in hundreds of different places. âNo one piece means anything,â says Pentland. âIf a thief got their hands on most of it, it wouldnât make any sense.â
Once you grant access to someone querying your data â say Netflix wanting to check that you are 18 â then and only then do the relevant jigsaw puzzle pieces coagulate to provide the answer before vanishing again.
The system is based on the anti-fraud record securing bitcoins. Anyone who owns bitcoins has an exact copy of the blockchain, making forgeries impossible and removing the need for third parties like PayPal to verify online transactions. Pentland and his colleagues have turned that same public ledger into .
There are other ideas about how to keep data safe from prying eyes, or from people who donât want to assume the risk of protecting it. Projects are under way at and Microsoft, whose proposals resemble e-wallets that hold your data for queries but never for direct access or storage.
A version of Enigma will be available later this year, and if such services take off, you truly will be responsible for your own data. At that point, the warnings to guard it will make more sense. âYou can still do stupid things under Enigma,â says Pentland. âYou could give permissions to the wrong person.â However, without access to the original âhard copyâ of your data, he says, it will become impossible for advertisers to use that data without you knowing, or for people to buy it.
Currently, companies that misuse your data can be sued, says Rennie, but youâll never be able to eradicate data breaches. âYou can make theft illegal, but thatâs not going to stop someone pinching a bicycle.â Tools like Enigma could be the next best thing.
Leader: âItâs not too late to reclaim our privacyâ
A history of hacks
NSA â June 2013
Edward Snowden reveals how the US National Security Agency can monitor peopleâs personal data â including medical records, email, bank accounts and phone calls.
Target â November 2013
Malware in the payment system of US retailer Target siphons credit card information, addresses and names of more than 100 million people.
US Homeland Security â March 2014
Social security numbers, financial histories and childrenâs names are leaked when the files of 4 million government employees are exposed. Officials are warned that the .
iCloud photo leaks â August 2014
Celebritiesâ nude photos are swiped from iCloudâs online storage platform.
Sony â November 2014
Five Sony Entertainment films are leaked and thousands of internal documents published. The data included private email messages.
Ashley Madison â August 2015
The details of more than 30 million people who signed up to the adultery website are released. .
This article appeared in print under the headline âYour data, your rulesâ