Hacker News new | ask | show | jobs
by dredmorbius 3370 days ago
The (presently) top-rated comment on this thread by nikcub is not only wrong, but fractally wrong in every particular. I'm offering this as a possible counterpoint.

https://news.ycombinator.com/item?id=13982966

* False dichotomy: that the solution lies in only one sphere. (Lessig, Code). This is lightly moderated, but resurfaces at several later points in the argument.

* Personal responsibility. Check. Never mind that the source article states concisely and specifically why this doesn't work or scale.

* Hybrid system. Or as I prefer, the worst of both worlds. In the healthcare example, a guarantee of emergency room services is posited as a sufficient mitigation for mandating individual responsibility in all other areas. Disregarding the fact beneficial health outcomes comes from public or preventive measures, not acute (read: late, expensive, heroic measures) interventions:

"In all, 86 per cent of the increased life expectancy was due to decreases in infectious diseases. And the bulk of the decline in infectious disease deaths occurred prior to the age of antibiotics. Less than 4 per cent of the total improvement in life expectancy since 1700s can be credited to twentieth-century advances in medical care."

― Laurie Garrett, Betrayal of Trust: The Collapse of Global Public Health

* As with all good Techno-Libertarians, nikcub "personally believe[s] in user responsibility". Despite some 50+ years of experience that user responsibility for security simply does not work or scale.

Nikcub continues with specifics:

* Universality of policy. Which seems to boil down to "since every jurisdiction cannot offer the same high levels of protection, no jurisdiction should". What ever happened to the concept of a competitive marketplace for ideas, including legal and moral frameworks? Isn't the very idea of liberal democracy that its principles, premises, and protections are so manifestly self evident that all people everywhere would want them? (And hence: why it's such a major pain in the ass of tinpot despots everywhere.)

* Some governments are bad ... so no governments can be trusted. Again: a slope so slippery nikcub loses his footing instantly. We can apply the same argument to ... anything. Including his proposed technological solutions: Software is a major party in privacy violations and is conflicted (and buggy), so it cannot be expected to behave in the interest of users. In government as with software, the proper response to buggy implementations is to fix the bugs, not burn the house down and abandon the domain completely.

* Government trust. Where do I even start (the concept and questions of trust are ... a whole 'nother essay). If liberal democratic government, the agent and agency* of The People, cannot be trusted, then what can?* Private, self-interested business? Which, I'll hasten to add, has landed us in the present kettle of fish? If you're finding that your government (or parts of it) aren't trustworthy, then you have two problems. But the one doesn't invalidate proper approaches to the other, and fixing the problem of government trust gives you an exceptionally powerful tool to apply in remedying privacy and other policy failures. Say, such as single-payer, universal, socialised medicine.

* Tech solutions that are universal ... are called policy. And, to add to that, a primary reason for approaching such policies through government is that governments have the clout and scale to make policies stick. Keep in mind that this need not be at national or international scales. Policies at the sub-national scale -- say, Northern Ireland or Scotland within the UK, or California or New York within the United States, could have major impacts. Given the option of adopting multiple and conflicting regulatory standards, or a unified and coordinated standard, companies will often prefer the latter. The case of US EPA and California EPA emissions standards would be an excellent study in same.

* Good policy is hard work. Yes, well, hard problems are hard. This doesn't make them not worth pursuing. And remedying the specific problems highlighted would be a key goal of any privacy regulatory overhaul.

* Penalties are small. Well, duh: embiggen them. I thought yuuuuge!!! was in now, anyways....

* On information disclosure: yes, it's very hard to un-leak data. On the other hand, comprehensive and pervasive regulations against the storing or transmission of personal data, stiff penalties for doing so, and sufficient rewards for reporting on such violations, will tremendously decrease the incentives for doing so. Given that the value of vast troves of personal information to firms such as Facebook is ... roughly $12/year per person, those penalties need not be tremendous, though they do need to be sufficient given scales of detection. This isn't dissimilar to present approaches against counterfeiting of money or goods: the fundamental capability to violate norms exists, but with appropriate penalties, and incentives, against transacting in such money or goods, it can generally be tamped down to an acceptable level. The more so if technology and other means are applied in concert with policy.

The argument continues spewing the additional canards of perfect worlds (no policy world is perfect, at best it is sufficient), sole reliance, and of mis-casting the argument as warning people away from VPNs (it doesn't, it merely points out that VPNs alone are grossly insufficient).

And for the capper, we have free-market it harder. As if it wasn't free-market interests, and failures, which haven't landed us precisely in the present situation.