The Register Home Page

* Posts by doublelayer

11293 publicly visible posts • joined 22 Feb 2018

German Pirate Party member claims EU plans for a GDPR-compliant Whois v2 will lead to 'doxxing and death lists'

doublelayer Silver badge

Re: WHOIS not alone

I don't support anonymous companies, though I can see a case for companies that a member of the general public can't identify, leaving that to law enforcement. But I'm not going to argue that point right now; we can proceed with the idea that the public should have instant access to the identities creating any company. In which case, a unique number is much better than birth month and year. If two John Smiths born in May 1981 open companies, you could confuse them. If John Smith 1285939 and John Smith 1287561 open companies, you can't mistake them for one another. And in order to find all the companies with the former, you just search for that director number.

doublelayer Silver badge

Re: Checking at least some details?

It's not hard to set up a front organization in a country you think you trust. The organizations who sell anonymization services or did so before GDPR made that generally applicable were located all over the place. I remember several based in Canada, the U.S., France, and Denmark. Would you trust any of those countries? If not, I wonder what your list is and whether you really checked sites for presence on it.

doublelayer Silver badge

Re: WHOIS not alone

And why might you need to narrow down the company director without the extra access, and if you do, why is it birth month and year that you should use as a key? That is not a very good key, as people could share that data as well and it is of use to scammers. Eliminate those issues by instead having a company director number, which is randomly assigned to a unique person so you can immediately see any other companies they have registered but you can't use it to pose as them. Risk of collision: zero, so it's a better tool for your use case. Risk of abuse: significantly lower.

doublelayer Silver badge

Re: WHOIS not alone

Birth month and year is bad enough, especially as I see no reason the public needs to know that when investigating a company. As for the address, that's great for a company that has its own premises somewhere, but if it's a small one where all the workers work from home or it exists for a freelance person to organize contracting work, then they won't have one. Should they be obliged to rent some external address to receive post just so their real address where they can already receive post won't be publicized?

Client-side content scanning is an unworkable, insecure disaster for democracy

doublelayer Silver badge

Re: Apple has its own agenda

I agree, and yet think you're wrong about the others. I would rather have Google and Facebook comb through my data on their servers than Apple comb through my data on their devices, because I go to lengths not to put any data on Facebook or Google's servers. For that matter, I also put very little data on Apple's servers. That's where I can exert my control, by not allowing things on other people's servers. If they run it on things I own and use, they have much more access to the place where my data really is, and I have less ability to know what is available to be analyzed and what will happen to it. It's not like they were going to offer a "Do you want all your stuff scanned" switch.

doublelayer Silver badge

Ah, you're back. I thought you left.

Standard problems with your repeated comments apply: not text under consideration, these are images. Also of no relevance as we're not talking about advertising and the problem is privacy.

Judge rejects claims Cloudflare should be held responsible for customers' copyright infringement

doublelayer Silver badge

Re: knowledge and the law

Many crimes do in fact require that the person doing them must know that they are committing a crime. It doesn't always apply, for instance the author who committed the plagiarism doesn't have to know that it's illegal, but someone who binds the book does not know of its contents and would not be charged because they didn't commit a crime. Usually, it's the accessory or aiding charges that require knowledge, and that's the charge that would be leveled against most of the people on the "might" list.

doublelayer Silver badge

Re: A lot of support for Cloudflare here...

"What happened to a bit of sympathy and support for the little guy?"

A few things happened. The most important one is that they decided to sue someone who isn't guilty. That kills sympathy fast.

It's certainly sad to see someone lose out to a criminal, and I would not in any way support the criminal, but it isn't automatically the case that any victim of crime is otherwise sympathetic. I know nothing about the company other than what is in the article, and the only decision I see was one I don't support. For all I know, this is a copyright troll whose fashion designs are general enough that they sue everybody small enough to extort. I won't assume that, but it's as possible as their being otherwise blameless. Therefore, I must make my decision based on the limited facts at my disposal or go researching to find more.

doublelayer Silver badge

Re: Missing the point

"If an author writes a book that plagiarized, violated the copyright, of another book, and is published[, o]k, who violated the copyright? The writer who wrote the book, or the publisher who distributes the work for him?"

Good analogy. Let's use that. They are both liable, and for a very specific reason. Both of them know what is in that book. The publisher knows because the publisher reviewed it. The publisher employs editors for that purpose, because they're restrictive about what they publish. They therefore know a crime is being committed.

Here are some people who are not liable: the paper mill, the printer, the bookbinder, the delivery driver, the book storage warehouse, and the book shop. Here are some people who might or might not be liable: the literary agent, the illustrator, the copy editor (if there is a separate editor who looks for typos and grammatical problems), and the contents of the acknowledgements section.

The thing which determines whether those listed under "might be liable" are or not is whether they know the crime is taking place. For the same reason, the people listed under "not liable" are there because they don't know about the crime. And that is the situation here. CloudFlare is useful to criminals, but it didn't design itself in that way, it is useful to law-abiding people as well, and it doesn't know which is which. In addition, they comply with the laws that currently exist which restrict what services they can provide.

If you want service providers to individually monitor what the customer is doing in order to more quickly enforce the law, you can pass a law to that effect. Such laws have been proposed before, but most countries don't have one. In my opinion, that's a very bad idea, but if enough people disagree, you can do it anyway. Until you do, don't expect companies to voluntarily do so.

Missouri governor demands prosecution of reporter for 'decoding HTML source code' and reporting a data breach

doublelayer Silver badge

Re: Dare I admit to the govenor ...

Sadly, there are some people who would see those as worrying criminal tools. I know if I'm ever investigated for some crime, I'm going to get a lot of blame for having a tool called Wireshark installed on my computer. It's even got that scary name and talks about packet capture, so I must be evil. Wget doesn't have the same cool name credential, but by not being a full word, they'll give it extra points for ubertechnical hacking tool so we're probably even. Unless they have a forensic investigator review my hard drive and find that I've got wget too. Then we will be assumed to be acting in concert, which will be very fun if we're in different countries so we can be called "an international cybercrime organization".

LAN traffic can be wirelessly sniffed from cables with $30 setup, says researcher

doublelayer Silver badge

Re: I thought LAN cables were shielded

If by "one of those plastic tags" you mean a label on the cable, then they've managed some very compact designs. A listener needs not only an antenna of sufficient length to receive the signal, but also a processor to decode the signals, a mechanism to send that data to the attacker, likely wireless if this mechanism is useful, and a power source to run all of those. That's going to make for a very thick tag.

doublelayer Silver badge

A serious adversary with what access? Because if they control your endpoint or if you're sent to HTTPS through plain HTTP, you're right. A lot of adversaries don't have that on either end though, so HTTPS and HSTS policies are pretty good.

doublelayer Silver badge

Re: New? Bwahaha!

Oh no, they knew exactly where their risk was, namely the capture of codebooks. They just didn't find out when the allies succeeded in getting some. They didn't know about the computer research either, but without the codebook theft, it would have taken a lot longer.

doublelayer Silver badge

If that wire goes to something else, it probably logs traffic and would notice UDP packets going to a closed port or address that isn't routable. This counts on the receiving machine just dropping the unusual UDP packets, which is what most consumer-level equipment would probably do, but if you're using two airgapped machines with a wire connecting them, you probably want to inspect traffic for an attack and give warnings about unusual packets coming along.

doublelayer Silver badge

Re: I thought LAN cables were shielded

Putting electronics around a cable would be detectable to someone walking in and going "What's that", though. What could work is to take the original cable, add the compromised cable, but only plug in one end and ensure the other is slightly disconnected. When someone notices that the device isn't connected, they connect it themselves or ask you to do it.

Google's VirusTotal reports that 95% of ransomware spotted targets Windows

doublelayer Silver badge

Re: The hubris of Apple (oops I meant Google)

Windows has lots of problems. I would never deny that. Your demonization of it, however, is hyperbolic and therefore inaccurate. Your comparative idolization of alternatives is likewise flawed. Windows is attacked very often for one very important reason: that's where the users and data are found. Getting a user to execute a binary is a great insertion mechanism. Despite your assertions, you can block them from doing so and you can restrict what that binary can do, but many administrators do not. Since most users are on Windows, the attackers go against Windows. The problem with comparing them is that you can also mail a Linux user a binary. They can also run it unless the administrators have restricted their actions. It can do similar things if you do run it. Bugs allowing privilege escalation have been found in both systems, for example. Exactly how the various things are done will differ between platforms, but both can be attacked in similar ways.

doublelayer Silver badge

Re: The hubris of Apple (oops I meant Google)

It seems to me that the "Linux | FreeBSD | UNIX | Chrome ..." whataboutism" is mostly coming from you. Albeit the reverse of what you're claiming to see, but still. You assume that Windows is being attacked because it's "the easiest of all to attack successfully" without much evidence. And it's basically wrong. Nothing stops ransomware working on Linux. It would work pretty well, since there isn't much difference in disk protection between Windows and Linux. Mac OS does have stronger disk sandboxing inside user accounts, and that could help if it wasn't broken by Apple's mistakes, but neither Linux nor Windows have that.

A properly-run Windows network will be good at blocking or recovering from an infection just like a well-run Linux network. The OSes have differences in security, and I generally prefer Linux's model, but it doesn't make it immune or even distinctly better. An attacker who wants to hit you and knows you have a Linux setup can take on that challenge. To claim otherwise is likely to lead to problems.

doublelayer Silver badge

Re: Why this Obsession with Ransomware?

It's a combination of the damage caused and the frequency with which it happens. Both of those operate in multiple ways.

First, the damage. If your database is cracked and someone makes off with your customer data, that's bad. However, people won't notice, some won't understand the risk, and once you close that barn door, your customers bear the cost while your business goes on. A responsible company will handle that differently, but many don't fear that as much as they should. Ransomware is a much more direct hit on a business, making it hard for them to act, even if they do pay the ransom. Whether they pay the ransom or for people to do a full restore, the money comes out of their wallets in one big transaction, so it's very noticeable.

Second, a frequency event. The effect of ransomware is a lot like the effect of a fire in the office building, which is why you need off-site backups even if you don't have an ethical objection to paying ransoms. However, companies don't often hear about someone having their office burn down, so it seems remote to them. Ransomware is popular enough that it happens to people a lot and new enough that it gets news coverage when it happens, so people feel like it's a more likely event. That's why ransomware gets attention. It is a real threat, and it is both frequent and understandable for the nontechnical.

Apple warns sideloading iOS apps will ruin everything

doublelayer Silver badge

Re: Right Hand/Left Hand

You are correct about signing in general. This is an Apple policy with IOS, where they cycle through certs and block apps that have outdated ones from newer versions of the operating system. That's why they update. It has no effect on the security of the users' data. I can think of a few reasons they might do this, which range from acceptable to sneaky, but in no case does it help other security situations.

doublelayer Silver badge

Re: Right Hand/Left Hand

Most of that is wrong.

"It's a way of forcing security compliance."

No, it's changing a certificate so things don't break. The new certificate isn't more secure than the old certificate, and it doesn't do something to change the action of the code. It's there because the old certificate is going to expire and Apple doesn't want users complaining about the apps no longer working.

"If the app developer can't be bothered to update the app to keep it secure, Apple will update the infrastructure around it - thereby depriving the lazy sod of income until they step up and do what needs to be done."

The app developer isn't doing anything, and Apple isn't taking on their role or depriving them of income--in fact, by this point, the developer has probably stopped supporting the app altogether.

doublelayer Silver badge

Re: that aren't from an official source, such as the Microsoft store

The structure of the phrase only allows for the store to be listed as an official source, although the comma isn't required for it. Even with it split out as a separate clause, it can't mean that it's non-official because the only thing the "such as" can apply to is "official source". It can't refer to "aren't from an official source" because that isn't a noun, and it can't refer to "apps" because the store is a source for apps, not an app of its own (in functional rather than technical terms).n I bet the comma was put there without considering this, so it's very good it didn't read like this:"Sideloading apps is when you install apps that aren't from an official source, such as from the Microsoft store." That could apply to the verb, so it would reverse their meaning. English grammar has so many little traps like that.

doublelayer Silver badge

I could make that argument about a lot of things, but it's always fallacious. The general public makes plenty of mistakes with tech, just as we probably make plenty of mistakes with those things we know less about. However, we don't take away our own rights to make decisions, nor should they be taken away from someone else who knows less than we do. Everyone makes a mistake from time to time, and that's no reason to treat them unfairly.

For that matter, I recently made a mistake with technology (a computer stopped booting to Windows and gave me an automatic restore screen instead, and I foolishly thought starting the restore would run a fsck and restart, but it instead chose to do a wipe and reinstall, destroying all the data). Should my right to make system decisions be revoked, even though I knew enough to boot to Linux and do some command-line investigation to find out that this had happened and cleanly reinstall? If we're to decide what rights others have because we know more than they do about the tech, I don't think we want to know all of the rights someone else would take from us on the same basis.

doublelayer Silver badge

Re: Law of unintended consequences

The difference, if there is one, is the amount of competition. If you can, for example, buy a game on a disk and Sony doesn't get paid, then there's a lot more competition than Apple has. If there are lots of game systems available, then each one has less market dominance and therefore has less ability to cause harm. I don't use consoles myself, but if they're doing the same Apple thing, I wouldn't mind making them open up a bit too.

doublelayer Silver badge

Re: Tesco

Not really, as they've just increased the key space. You can spoof with anything you like, but if you do, you probably can't spend any of the theorized points you would have earned because each spoof has been distributing them across fake addresses. They won't mind.

FTC carpet bombs industry with letters warning that fake reviews will be punished

doublelayer Silver badge

If it's related to inflation, it wouldn't be round. There are a few different calculations for inflation, but 1.76% in 2019 and 1.18% in 2020 sounds kind of right. The CPI rate was 1.371% in 2020 and 1.711% in 2019, which isn't the same but close. If so, this year's increase should be quite a bit larger.

Sharing medical records with researchers: Assumed consent works in theory – just not yet in practice

doublelayer Silver badge

Re: Category mistake

They seem to have redefined collectivist as the level of people protesting or disobeying public health recommendations. That has a lot to do with the person leading the country and the politicians supporting them, as well as the trust in government. The combination of those factors is really what made the difference in how badly the pandemic was, also factoring in local problems which made adherence to the public health recommendations harder. While calling concern for others "collectivism" sounds alright, it's not what it really means, so the author has ended up with an incorrect phrase.

How Windows NTFS finally made it into Linux

doublelayer Silver badge

Re: Am I missing something?

It depends. Maybe you're using something I don't know about, as I try not to write to NTFS very often, but if you're using the traditional methods, you'll either get something which works but slowly or something which balks when presented with unusual drives. Another restriction on both is that they often can't deal with a NTFS disk that wasn't cleanly written and unmounted, which used to be normal when Windows shut down, but now doesn't happen by default unless the user either restarts or changes a relatively hidden setting. Supposedly, this version should run fast and support that, so while I don't need it now, I'll welcome it.

Schools email marketing company told us to go away when we told them of exposed database creds, say infoseccers

doublelayer Silver badge

They wanted it fixed. Because not having it fixed meant potential problems for the people whose data was in there.

Don't get me wrong, if the company decided to reward them for their warning, I'm certain they would have taken that gladly. They still wanted the issue fixed though.

doublelayer Silver badge

Come on. The second and third emails mentioned almost certainly looked like this:

First: "You have a problem with your database credentials being shown here ..."

Second: "Sorry if you didn't get our last email, but you have a problem with your database credentials being shown here ..."

Third: "You've got some seriously confidential data in your database, and it's a crime to leak it or not report a breech, and your credentials are right here. You need to fix it."

Then the response. The article notes that the credentials were fixed after the press got involved, not beforehand. You have decided based on no evidence at all that the researchers wanted money, but as the problem they found wasn't fixed, they could easily have just wanted it fixed. Like many other researchers, if someone won't fix their problem which is actively affecting others, they go public. For a similar reason, if you were periodically firing a projectile from your house onto the street, I'd try to make you stop and if you didn't immediately do it, I'd report you to protect pedestrians. No money involved.

doublelayer Silver badge

No, using the simile in its unrestricted ability, it's perfectly accurate. Just as a murderer protects life as they always have done or Facebook acts ethically as they always have done. Nobody said the sentence applied if you cut before the "as".

Apple beat Epic Games 9-1 in court. Now it's appealed the one point it lost

doublelayer Silver badge

Re: Is it going to matter ?

"Let's say that the transaction is $1 and the cost to process the transaction (bank fees, etc) is $.25. That leaves $.05. Many upgrades and in-app purchases are small."

You made the number up and it's completely wrong; no payment method alone has a transaction fee of 25%. As such, the rest of your comment is defending a worthless argument. If we assume that all the fee Apple charges goes to someone else, it's very excusable. It doesn't. They don't claim it does. It would help convince people if you stuck to that clear fact and tried to argue about the massive profit actually being made.

doublelayer Silver badge

Re: Dear Apple...

"Personally I really don't understand why someone who hates Apple and wouldn't buy one of their devices if it was the last thing on the planet can get so hot under the collar about this stuff."

I can explain that, but for the record I have bought Apple products and still use them. But first, the people you describe: you remember the extreme hatred GNU, Linux, BSD people had for Microsoft in the 1990s? You've seen those people who still have that hatred today, even when they don't always seem to know why? It's like that. Someone who sees an abuse of dominance can find that problematic whether they're paying for that themselves.

As for people like me who use Apple products but aren't tied to them, it does somewhat affect me, although Apple doesn't make much from my App Store habits. In fact, my objections are also quite related to the lack of ethics the policy involves and to the rent seeking that the behavior is. I don't like anyone doing that, and when it worsens what I otherwise think is a pretty good platform, it's something I'd quite like to see corrected.

doublelayer Silver badge

Re: How's this work then?

The rule is that you have to use Apple's payments and let them take their charge for anything digital, but you can use yours for physical things. Probably because someone considered doing it for physical things and it was so obviously illegal they slid the digital-only version through instead.

doublelayer Silver badge

"Why do you think Apple are so great at delivering iOS updates to such old devices?"

Here are some reasons:

1. It's a selling point, and if they stopped doing it they would lose some customers.

2. Compared to some Android manufacturers, they have much larger profit margins, which they use to fund that.

3. They only have a few devices, so it's easier than a company which makes sixty models.

4. They have a lot of services tied to their devices, and they update those services. If they didn't keep old devices working with those changes, they would lose their "It just works" reputation, which is a much larger selling point than point 1.

5. When they patch security holes, they also prevent people jailbreaking. Android does try to prevent rooting, sometimes, but if you find a hole, it's likely to stay open. Apple has an interest in making it hard or impossible to jailbreak.

I agree that IOS has better long-term security than Android does, and I've made purchasing decisions based on that before. Apple was rewarded for that when I paid their high prices for hardware. They don't automatically get to take money from others just because I like their product. That's why they charge me.

doublelayer Silver badge

Re: Judge found Apple is not a monopolist?

No, they have two platforms. IOS and Android have no effective competition. Two companies making Linux phones for two years which don't work very well don't a real competitor make. On that basis, Apple controls 20-40% of the market based on the location, which is in economic terms at least an oligopoly position. Laws restrict competitive behavior based on restricted markets, and they often do include that large a chunk with only one competitor who does most of the same things.

Australian PM and Deputy threaten Facebook and Twitter with defamation liability for users' posts

doublelayer Silver badge

"You post something on your website and idjits uses the comments to make a malicious remark... not your fault. Your ENTIRE BUSINESS is premised on people posting remarks, then I'm sorry but you ARE responsible for what people post. IT'S LITERALLY YOUR BUSINESS."

First, that's incorrect; the laws generally say that it's not even if your business relies on people posting. But more importantly, most suggested changes to the law, and in fact almost all of the possible ways of implementing it, would not get you to that state. It is quite hard to define whether a company's business is related to users posting content, and people could make arguments either way. You could argue, for example, that this site has such a business model; although they look like a newspaper, they also have a community of commentors, topics unconnected to the news articles, and make advertising attracting people with those things. Even more so for a site where you post things for free and allow comments. Usually, the suggested changes to laws end up saying that everybody is responsible for something their server sends, with no distinction attempting to target things like Facebook. You can try to make a third law which draws a line down the middle, but know that you aren't joining many others who favor a much more black and white approach to either side.

doublelayer Silver badge

Re: Printer's Imprint

Ah, the classic "abolish anonymity" response from someone who doesn't mind using it themselves. It's a terrible idea and any government that attempts it is intensely worrying.

doublelayer Silver badge

Then this forum too should be shut down immediately. I have no sympathy for Facebook, and if the law could just kill them, I'd like the results. However, it applies to a lot of places and they too have a moderation problem. We've seen posts here which could offend somebody. The moderators get to some of the egregious ones eventually, but not within seconds which is all it takes. There are others which stay up. If they could be sued for anything I or you said, they probably wouldn't be able to justify the risk they're taking on by having this forum in which we can do so.

User locked out of Microsoft account by MFA bug, complains of customer-hostile support

doublelayer Silver badge

Re: Lowest Common Denominator

I certainly don't envy their support requests. When billions of nontechnical people use something, the support traffic must be nearly endless and mostly useless information. Open source operating systems get around this by not having billions of users and not offering general support, but if Microsoft decided not to support Windows anymore and everybody moved to a Linux of some sort, there would be a related wave of requests from new Linux users that I for one would want to run away from very fast.

That doesn't mean Microsoft's level of support is acceptable, as they have plenty of money to spend on improving it. I just don't want to be anywhere near that attempt. I support only close friends and family, and that's hard enough to do over the phone to a nontechnical user.

doublelayer Silver badge

Please list any services you run so I know to avoid them. I'm guessing you do store sensitive information on that service, or you wouldn't have the account, and you have other security problems involving more important accounts. I'd like to make sure the information that gets leaked isn't mine.

doublelayer Silver badge

"Clicked on" in this case probably means copied the URL, inspected the URL, verified that it did in fact go to a Microsoft-owned domain which it did, verified that it was an expected domain name which it was, and one that a standard user couldn't edit which it wasn't, and then put it in a browser. Like we do all the time because people do send legitimate URLs in emails. They don't need to pad out that part of the description when it wasn't a malicious link, do they? Your assumption and the conclusion you imply, despite that conclusion having nothing to do with the problem reported, is not useful.

The planet survived six hours without Facebook. Let's make it longer next time

doublelayer Silver badge

Re: Without Facebook...

Your argument is suffering from this second post.

"Ok, you try being separated from your family for four years."

I'm sure that was terrible. I don't wish that on my enemies. But it's not a cogent response to there being alternatives to WhatsApp.

"Telegram and Signal weren't a thing when we needed WA."

Possible, as WhatsApp started in 2009, Telegram in 2013, and Signal in 2014. So perhaps you do mean the period between 2009 and 2013. However, there were many things like it at that time. Here's one: email. Email is low on data usage, has clients for everything, works internationally, etc. You could easily have used that instead. It's not the only thing out there. Sending text over the internet wasn't invented by WhatsApp.

"Ideological purity is all very well, but matters not a shit when real life intervenes in all its many nasty ways."

I don't begrudge you your WhatsApp use. In fact, if the time period is as discussed, it wasn't even Facebook's at the time so I would have been using it too. In the very limited discussion of whether it does something otherwise unavailable, the answer was no then and remains no nowadays.

doublelayer Silver badge

Re: It will take a while

That solves the first named problem (data integrity) while making two other named problems worse (storage requirement and operation cost) and doing nothing at all about the rest of them. Try again?

doublelayer Silver badge

Re: Without Facebook...

Phone doesn't just mean the PSTN these days. It means a system by which you talk to a specific person, whether that's a normal phone call (works great inside the country but maybe not across borders), Signal audio/video calls, Skype, Jitsi, your own private satellite link, whatever you need. If you can have a Facebook group, you can do one or more of those, probably for very cheap or free. If the forum aspect is nice, you can also do that. This doesn't mean that Facebook's useless, but nothing it does is unique to it and you could switch to something providing the same benefits if you had the interest and could convince the others.

doublelayer Silver badge

Re: It will take a while

"Final meandering question: Would it be possible to create an antisocial media that wasn't antisocial?"

That really depends what you mean by "antisocial". Some of Facebook's particular ills can be corrected. The advertising/data collection can be resolved by forbidding it and assessing large fines. Someone will have to find a way to pay for it which doesn't break that, but it can be done. The buying up the competition could also be prevented in a regulatory way. If the problem is about the users though, it's a lot harder. Wherever you have billions in one place, you can't always stop them doing stupid or bad things. Misinformation will spread, people will commit crimes, people will hurt someone else, etc. While Facebook doesn't care and gleefully allows it, there aren't many easy ways to get around that, and most would have additional negative side-effects.

Patients must know how their health records are used – and approve any sharing for research

doublelayer Silver badge

Re: This will be an unpopular opinion

I am not happy to give it up. I am quite happy to keep it alive and to feed it with my data. I only ask that my data and those of others be treated with respect, which isn't happening. Respect includes telling the people what is happening to their data and what it is. Given the risks the loss of the data can have, people have several good reasons to want to keep it sufficiently anonymous, and some people may have sufficient reasons to deny its inclusion.

Those last sentences may sound a lot like opt out, and I think most people should be happy including their data in a system which respects those aspects. However, the systems as they exist do not, and I have never seen an opt out mechanism that nonetheless maintains rigorous methods of informing the subjects what's happening and allowing them the control needed to opt out. If they can create one and prove its effectiveness, maybe it can be considered, but until that point, opt in is the only way to ensure sufficient information is provided. Opt out incentivizes people to hide the information and opt out path from the subjects because if they don't find out, they don't stop you. Opt in incentivizes information and control, because the more people who agree to what you're doing, the more valuable data you get.

doublelayer Silver badge

Re: I have a big problem with the way this debate is run

I agree with most of these, but they are improving. This time, they have a clear statement about what we're debating:

This week’s motion is: Assumed consent is the right approach for sharing healthcare patients’ data, beyond their direct care. Or to put it another way: patient records should be shared with medical researchers on an opt-out basis.

Which helps clarify what for/against mean. Last time, the motion was vague and the debaters didn't really help.

There's also something to be said for debating tactics where the debaters respond to one another after their statements. I realize that's harder to do in a written medium, but I think that would help. The summary article posted once our votes have been counted goes through our comments for illustrative statements, and they could have the debaters respond to the more common of those and to points made by the opponents. That means the debaters actually have to acknowledge the deficits in their arguments rather than just taking one aspect that works for them and ignoring the rest.

Opt-out is the right approach for sharing your medical records with researchers

doublelayer Silver badge

Re: Very sensible approach to my mind.

I cannot say what everyone will do, but I know people who make hiring decisions who would, if it were legal and reasonably cheap, have their candidates surveilled for days in order to find things. Since that is neither, they engage in plenty of other fishing expeditions looking for potential reasons not to hire them. Health data could be used, and you wouldn't know. Your successful hiring despite health risks may be due to me being wrong about the general employer, but it might also be due to you having more in-demand skills. Not everyone has that.

If you still don't buy my argument, I'll be more simple about the harms, then. The harm is that nobody has given consent. It is not your decision what happens to data that is not yours, even if you can think of some reasons having it could be useful. I can conceive of several benefits I could obtain by having full access to your personal data, health or otherwise, but that doesn't give me the right to take it. Researchers have no special exception from that and the others who would process it lack even the public good argument.

doublelayer Silver badge

Re: NHS Data Slurp As A Threat

You can, but it doesn't often help. For one thing, a victory against them has no chance of affecting them, whereas a sufficiently large victory against a company could. If you win a large judgement from a company, they may have to declare bankruptcy. If you win that from a government, they put the taxes up. Also, you don't win that much from a government because the judges know it is not changing anything.

This overstates the likelihood that you can successfully sue a company, but at least it's possible.

doublelayer Silver badge

Re: Very sensible approach to my mind.

I would also be happy to contribute anonymized information, but there are clear harms from a breech. Here are a few situations:

Someone who has medical conditions may have that appear in checks of public data, which could be misinterpreted by others. For example, the original poster in this thread's history of cancer might convince employers that they will be more likely to have a health situation requiring time off work, so they don't get a job. That's a single possibility which can harm someone severely. The same can happen in locations where private health care means that people's risk for conditions can increase what they have to pay for their health care. Both situations can also apply to children if your health information suggests a risk for inherited illnesses, and since there isn't sufficient data to ensure that, the risk can be used even if it's incorrect.

There are less severe risks too. While it probably won't directly hurt you to have advertisers hold your medical data, that wouldn't be popular for the simple reason that it's creepy. Medical data is among the most private out there, and therefore the controls over who can see it must be strong. Assuming that anything you like will be fine is not strong.