privacy by default - ia summit 2017

98
Lutz Schmitt - Twitter: @luxux - IA Summit 2017 - Vancouver PRIVACY BY DEFAULT illustration by Lutz Schmitt – licensed under cc-by-nd 4.0

Upload: lutz-schmitt

Post on 05-Apr-2017

638 views

Category:

Internet


2 download

TRANSCRIPT

Page 1: Privacy by Default - IA Summit 2017

Lutz Schmitt - Twitter: @luxux - IA Summit 2017 - VancouverPRIVACY BY DEFAULT

illustration by Lutz Schmitt – licensed under cc-by-nd 4.0

Page 2: Privacy by Default - IA Summit 2017

A CONCEPT FOR PRIVACY IN A WORLD WITH THE INTERNET OF THINGSPRIVACY BY DEFAULT

illustration by Lutz Schmitt – licensed under cc-by-nd 4.0

Page 3: Privacy by Default - IA Summit 2017

Missing parts for a world with ambient

intelligence, that I would

want to live in.

Page 4: Privacy by Default - IA Summit 2017

PREAMBLE

Page 5: Privacy by Default - IA Summit 2017

SECURITY IS FUNDAMENTALit isn‘t really worth talking about privacy

in an insecure environment

Page 6: Privacy by Default - IA Summit 2017

IT‘S ALL ABOUT SOCIETYand how technology is used to help shaping it.

Page 7: Privacy by Default - IA Summit 2017

AND IT‘S ABOUT BUSINESS

Page 8: Privacy by Default - IA Summit 2017

https://twitter.com/MetroUK/status/776150782194376704

Page 9: Privacy by Default - IA Summit 2017

ABOUT PRIVACY

Page 10: Privacy by Default - IA Summit 2017

you VERSUS the others

Page 11: Privacy by Default - IA Summit 2017

THE RIGHT TO BE LET ALONEThe Right to Privacy (Brandeis & Warren)

Harvard Law Review, 15 Dec 1890

Page 12: Privacy by Default - IA Summit 2017

1. The right to privacy does not prohibit any

publication … which is of public … interest

4. The right to privacy ceases upon the

publication of the facts by the individual,

or with his consent.

LIMITATIONS TO THE RIGHT TO PRIVACY

Page 13: Privacy by Default - IA Summit 2017

Would you hand over your Facebook-Login to a stranger?

Page 14: Privacy by Default - IA Summit 2017

Photo by Beatrice Murch on flickr. Licensed under cc-by-sa 2-0

At JFK Airport Immigration you will.

Would you hand over your Facebook-Login to a stranger?

Page 15: Privacy by Default - IA Summit 2017

you AND the others

Page 16: Privacy by Default - IA Summit 2017

Alan Westin in Privacy and Freedom, 1968

Page 17: Privacy by Default - IA Summit 2017

STATES OF PRIVACYaccording to Alan Westin

SOLITUDE privacy of individuals

INTIMACY privacy of groups

ANONYMITY unidentifiability in public

RESERVE (psychological) barriers / resilience

Page 18: Privacy by Default - IA Summit 2017

STATES OF PRIVACYaccording to Alan Westin, extended by me

SOLITUDE privacy of individuals

INTIMACY privacy of groups

ANONYMITY unidentifiability in public

RESERVE (psychological) barriers / resilience

PSEUDONYMITY choice of identification

Page 19: Privacy by Default - IA Summit 2017

No one shall be subjected to arbitrary

interference with his privacy, family, home or

correspondence, nor to attacks upon his

honour and reputation. Everyone has the right

to the protection of the law against such

interference or attacks.

Article 12

Universal Declaration of Human Rights

http://www.un.org/en/universal-declaration-human-rights/

Page 20: Privacy by Default - IA Summit 2017

ABOUT THE

INTERNET

Page 21: Privacy by Default - IA Summit 2017

THE INTERNET

IS BROKEN.

Page 22: Privacy by Default - IA Summit 2017

photo by Wally Gobetz on flickr.com licensed under cc-by-nc-nd 2.0

the internet is not a public place

Page 23: Privacy by Default - IA Summit 2017

Facebook isMark Zuckerberg‘s living room.

photo by Danny Howard on flickr.com licensed under cc-by-nc 2.0

His living room, his rules.

Page 24: Privacy by Default - IA Summit 2017

photo by Wally Gobetz on flickr.com licensed under cc-by-nc-nd 2.0

the internet is not freeneither as in freedom, nor as in free beer

Page 25: Privacy by Default - IA Summit 2017

remember the fight fornet neutrality?

photo by NewbleRunner on flickr.com licensed under cc-by-sa 2.0

Page 26: Privacy by Default - IA Summit 2017

and it‘s getting worsewith the Internet of Things

Page 27: Privacy by Default - IA Summit 2017

ABOUT

THE INTERNET

OF THINGS

Page 28: Privacy by Default - IA Summit 2017
Page 29: Privacy by Default - IA Summit 2017

photo by Philips. Released as press material. All rights reserved.

Remote controlling your lightbulbs,is not the IoT. It‘s remote controlling your lightbulbs.

Page 30: Privacy by Default - IA Summit 2017

photo by revolv. Press material.

are not the Internet of Things. That‘s just DRM for the physical world.

devices that need a cloud connection

Page 31: Privacy by Default - IA Summit 2017

Source: https://www.hackread.com/samsung-smart-tv-listening-conversations/

Page 32: Privacy by Default - IA Summit 2017

illustration by Lutz Schmitt published under cc-by-nc 4.0

we have reached zero effective cost

Page 33: Privacy by Default - IA Summit 2017

THE VISION FOR THE

INTERNET OF THINGS

THAT HOOKED ME

computers begin to be inseperably weavedinto the fabric of our physical reality

illustration by Lutz Schmitt published under cc-by-nc 4.0

Page 34: Privacy by Default - IA Summit 2017

photo by Sarah Leo on flickr.com – licensed under cc-by-sa 2.0

Mark Weiser, The Computer for the 21st Century, 1991

Page 35: Privacy by Default - IA Summit 2017

SOME ISSUESTHAT NEED TO BE SOLVED

Page 36: Privacy by Default - IA Summit 2017

ISSUE #1

Page 37: Privacy by Default - IA Summit 2017

a friend, on how to use smartphones and stay private

Page 38: Privacy by Default - IA Summit 2017

AMBIENT INTELLIGENCE WON‘T COME WITH A POWER BUTTON

photo by Juan Ignacio Sánchez Lara on flickr. Licensed under cc-by-nc-sa-2

Page 39: Privacy by Default - IA Summit 2017

WHAT MEANS OF CONTROL CAN BE ESTABLISHEDIf shutting down is no option anymore?

Still from 2001: A Space Odyssey. Source: https://youtu.be/l2c_rSLXq6U

Page 40: Privacy by Default - IA Summit 2017

ISSUE #2

Page 41: Privacy by Default - IA Summit 2017

we need to trust and believethe more technology develops, the less we are able understand

photo 7th gen Intel Core die by Intel Corp. Source: Presskit release on 2017-01-03

Page 42: Privacy by Default - IA Summit 2017

Arthur C. Clarke, Hazards of Prophecy, 1962

Page 43: Privacy by Default - IA Summit 2017

Still from Her. Source: Press material.

How do we design this magic reality,that people mustn‘t fear it, but are empowered?

Page 44: Privacy by Default - IA Summit 2017

ISSUE #3

Page 45: Privacy by Default - IA Summit 2017

decisions and setups all the timemay it be an app, a website, a washing machine or else

Page 46: Privacy by Default - IA Summit 2017

teaching and answering computersis a sisyphean task already

Page 47: Privacy by Default - IA Summit 2017

HOW CAN WE AVOID

INTERACTIONOVERLOAD

?

Page 48: Privacy by Default - IA Summit 2017

ISSUE #4

Page 49: Privacy by Default - IA Summit 2017

the IoT is dissolving our placesand meanings of the physical world

Page 50: Privacy by Default - IA Summit 2017

Photo by Deraman Uskratzt on flickr.com. Licensed under cc-by-sa 2.0.

How must we architect the virtual dimension of things and places,that our perception of reality won‘t be broken?

Page 51: Privacy by Default - IA Summit 2017

ISSUE #5

Page 52: Privacy by Default - IA Summit 2017

mass surveillance is a realityand those in control are not willing to let it go

Photo by Jeremy Brooks on flickr.com. Licensed under cc-by-nc 2.0.

Page 53: Privacy by Default - IA Summit 2017

Screenshot. Source: the internet

between individual interests and those of corporations, governments and the public

WE LACK BALANCE

Page 54: Privacy by Default - IA Summit 2017

HOW CAN WE ESTABLISH A FAIR BALANCE,instead of increasing the unequality?

Page 55: Privacy by Default - IA Summit 2017

PRECONDITIONS FOR THE

INTERNET (OF THINGS)

TO HAVE ANY KIND OF

PRIVACY AT ALL.

Page 56: Privacy by Default - IA Summit 2017

TECHNOLOGY

MUST BESECURE

Page 57: Privacy by Default - IA Summit 2017

THE NETWORK

MUST BEPUBLIC

Page 58: Privacy by Default - IA Summit 2017

EVERYTHING

IDENTIFIABLEMUST BE

Page 59: Privacy by Default - IA Summit 2017

COMMUNICATION

REFUSABLEMUST BE

Page 60: Privacy by Default - IA Summit 2017

A PERSON‘S INTENT

KNOWNMUST BE

Page 61: Privacy by Default - IA Summit 2017

A CONCEPT FOR PRIVACY IN A WORLD WITH THE INTERNET OF THINGSPRIVACY BY DEFAULT

illustration by Lutz Schmitt – licensed under cc-by-nd 4.0

Page 62: Privacy by Default - IA Summit 2017
Page 63: Privacy by Default - IA Summit 2017
Page 64: Privacy by Default - IA Summit 2017

INTRODUCINGIDENTITY

Page 65: Privacy by Default - IA Summit 2017

IDENTITY IS WHO WE AREto ourselves and to others

Page 66: Privacy by Default - IA Summit 2017

WE HAVE MANY IDENTITIESfriend, professional, internet troll, public speaker, …

Page 67: Privacy by Default - IA Summit 2017

PSEUDOIDENTITIES

COREIDENTITY

PUBLICIDENTITY

FACTUALIDENTITIES

UNIQUE TRUE SELF

GENERAL PUBLIC APPEARANCE

CONTEXTUAL TRUE SELVES

CONTEXTUAL PRETENDED SELVES

Page 68: Privacy by Default - IA Summit 2017

unverifyable & questionable

verifyable & trustworthy

PSEUDOIDENTITIES

COREIDENTITY

PUBLICIDENTITY

FACTUALIDENTITIES

Page 69: Privacy by Default - IA Summit 2017

PSEUDOIDENTITIES

COREIDENTITY

PUBLICIDENTITY

FACTUALIDENTITIES

A HUMAN PERSON‘S IDENTITY SET

Page 70: Privacy by Default - IA Summit 2017

this identity model is the basic rule setto define our virtual behaviour and representation and

that allows to manage different situations

Page 71: Privacy by Default - IA Summit 2017

EVERYBODY AND EVERYTHINGNEEDS AN IDENTITY STRUCTURE

staterepresentation

companies & organisations

artificialintelligences

objects

animals

places

Page 72: Privacy by Default - IA Summit 2017

THE WHOLE COMMUNICATION CHAIN IDENTIFIABLE

Page 73: Privacy by Default - IA Summit 2017

EVERYTHING IS OWNED BY PERSONS

Page 74: Privacy by Default - IA Summit 2017

THE WHOLE COMMUNICATION CHAIN IDENTIFIABLE

Page 75: Privacy by Default - IA Summit 2017

COMMUNICATION IS ALWAYS BETWEEN PERSONS

Page 76: Privacy by Default - IA Summit 2017

IDENTITIES REACT ON THE CONTEXT

Page 77: Privacy by Default - IA Summit 2017

INTRODUCINGPRIVACY SPHERESThe boundaries of communication

Page 78: Privacy by Default - IA Summit 2017

PUBLIC

RESERVED

INTIMATE

PERSONAL ONLY YOU

WITH ACTIVE GRANT

WITH PASSIVE GRANT

EVERYBODY

privacy spheres

Page 79: Privacy by Default - IA Summit 2017

INTIMATE RESERVED PUBLICPERSONAL

secretdiary

pictures from last night

employeeID

granthomeaccess

homeaccess

pseudocontactdetails

geolocation

shirt‘sproductinfo

workcontactdetails

coffeemaker‘sfill status

shirt‘suniqueID

THATpictures

bitcoinvallet

Page 80: Privacy by Default - IA Summit 2017

by default similar data may not be exposedto a more open level of privacy,

without the person‘s intent.

Page 81: Privacy by Default - IA Summit 2017

INTIMATE RESERVED PUBLICPERSONAL

diaryentry 1

diaryentry 2

Page 82: Privacy by Default - IA Summit 2017

EVERY IDENTITY HAS A DEFAULT,where data or rights are located

Page 83: Privacy by Default - IA Summit 2017

INTIMATE RESERVED PUBLICPERSONAL

right tomanageuse

right touse

sensordata

uniqueID

objectinfo

Page 84: Privacy by Default - IA Summit 2017

combining identity and privacy spheres

Page 85: Privacy by Default - IA Summit 2017

INTIMATE RESERVED PUBLICPERSONAL

UID24298723459

MADAMEPOMPADILLE

HR42CHOPKINS

PUBLIC IDENTITY

Page 86: Privacy by Default - IA Summit 2017

INTIMATE RESERVED PUBLICPERSONAL

UID24298723459right tomanageuse

right touse

sensordata

uniqueID

objectinfo

Page 87: Privacy by Default - IA Summit 2017

INTIMATE RESERVED PUBLICPERSONAL

UID24298723459right tomanageuse

right touse

sensordata

uniqueID

objectinfo

Page 88: Privacy by Default - IA Summit 2017

IDENTITYCOMMUNICATION

Page 89: Privacy by Default - IA Summit 2017

INTIMATE RESERVED PUBLIC INTIMATERESERVED

Page 90: Privacy by Default - IA Summit 2017

OK, but rules apply

INTIMATE RESERVED PUBLIC INTIMATERESERVED

Page 91: Privacy by Default - IA Summit 2017

person’s active grant needed

INTIMATE RESERVED PUBLIC INTIMATERESERVED

Page 92: Privacy by Default - IA Summit 2017

no response at all

INTIMATE RESERVED PUBLIC INTIMATERESERVED

Page 93: Privacy by Default - IA Summit 2017

“I CREATED THE WWW TO CONNECT PEOPLE NOT MACHINES“

Sir Tim Berners-Lee

Page 94: Privacy by Default - IA Summit 2017

CONCLUSION

Page 95: Privacy by Default - IA Summit 2017

privacy is vital to societyand a human right to everyone

Page 96: Privacy by Default - IA Summit 2017

the IoT will happenand this is a great thing

Page 97: Privacy by Default - IA Summit 2017

we need to solve those privacy issuesand I‘m sure we can

Page 98: Privacy by Default - IA Summit 2017

photo by mere41782 on flickr.com – licensed under cc by nd 2.0

LET US BUILD A MAGIC FUTURE,

NOT A DYSTOPIA.

THANK YOU.

@luxux www.lutzschmitt.comPhoto by Rick Schwartz on flickr.com. Licensed under cc-by-nc 2.0.