Hacker News new | ask | show | jobs
by Barraketh 1835 days ago
I'm trying to differentiate between data that is anonymized (cookies), and data that is not. I'm unaware of any data leak of anonymized data that resulted in any harm, but if I'm wrong I'd love to hear about it.
2 comments

How about intentional publishing of "anonymized" data? It's intentional, so it should be even less potentially harmful than an unintentional leak, right?

Well, Yahoo's publishing of supposedly "anonymized" data still poses a privacy risk to any of their users: https://www.vice.com/en/article/yp3d8v/yahoos-gigantic-anony...

That's just one of many apparently "anonymized" datasets that has been trivially deanonymized by researchers/hackers/internet-stalkers; so there's plenty of harm to be done.

Fun fact: one of the top 5 digital advertising platforms "anonymizes" user identifiers with a simple hash algorithm and "salts" all of the hashes with the same "salt". Can you guess the "salt"? Hint: it is commonly found on a dinner table and is used to season food.
I can't say I'm at all surprised. I've had similar conversations in a non-advertising field with non-technical managers where their attitude basically boiled down to "What do we care?" when it came to problems that would cost someone else money.

I also can't see attitudes like that changing until companies that collect data are seriously held to account for any leaks/abuses of the data that they collect.

Potential penalties would probably have to include criminal charges, in much the same way that individuals and companies can be held criminally liable for mishandling toxic waste.

Perhaps? But focusing on that specific case means you're not aiming for the same goalpost as the article was.
I think you are right - this was a brain dump of some things I've been thinking about, specifically on how the fight against cookie tracking is making centralization worse and companies like Facebook more powerful. This article generically criticizes both, but I think there's actually a tradeoff here, and not making the distinction may lead to bad policies