Why, in the face of threats, do we humans either spend an inordinate amount of time blaming others, or insist on patching the symptoms instead of solving the root cause?
- Target: I had my credit card data stolen, so let me buy millions of dollars of new PEDs
- ICO: The NHS lost some data, so let’s fine them.
- Rest of the World: The NSA is reading our emails, so let’s encrypt them.
Every one of these reactions has completely missed the point, and are the definitive closing the barn door after the horse has bolted.
Question: Do you tell your deepest secrets to your loved ones in a very loud voice in the middle of a room crowded with strangers? Or do you wait until you’re alone, and even then talk quietly just in case?
And yet you think you should have privacy on the Internet? You could not yell any louder than that. Forget your RIGHT to privacy, focus on YOUR ability to KEEP things private.
Even with encryption, who has the best equipment and expertise; you, or the NSA? Or worse; you, or organised crime? They are extremes, so let’s bring it closer to home; you, or your IT admin? How about; you, or your children?
So now, instead of solving the problem, security vendors are going to inundate you with offers to encrypt your data, encrypt your communications, encrypt your very identity, and they will all fail. 2014 should be the Year of Identity Management & Authentication, or to put it more facetiously; The Year of Only You Being You.
Here’s a ridiculously long and complicated analogy of your identity;
Imagine that you are a 1,000 piece puzzle, and when all of the pieces are together, only then can you see the full picture. As the puzzle is broken up and distributed across many hundreds of separate locations, the picture fades from each piece until it’s just plain white. Anyone stealing even a couple of hundred pieces will never be able to re-create you, never know what the picture is, or even where to find the rest of it.
Now, image that access to your most private information was tied to the complete picture, would that not be infinitely better than a username and password, or a 4 digit PIN?
Your true identity, the everything that is you, is made of things that cannot be put into a mechanism for authentication. Yet all we have right now is 3 factors: something you know (password), something you have (physical token), and something you are (biometrics). What about your likes and dislikes? Your future plans? Your everyday interactions?
All of theses things and infinitely more make up your true identity, and until we can come up with a way to get a whole bunch of them into a practical and seamless method of authentication, your data will be at risk, regardless of encryption. Yes, encryption may add a layer of security, somewhat akin to building your fence higher than your neighbours, but any commercial encryption product that will be pushed for home PC or mobile users will be practically useless.
Instead, privacy will come from the exact same source as identity managements’ will; very wide distribution of data with extremely limited ability to piece it all together. Some may disagree with my previous blog on the benefits of ‘profiling’, but you cannot have a robust identity without it. Bitcoin has proved that you do not need single databases/sources of storage for this stuff, the interconnectivity of the Internet’s individual systems can provide that with the right front end.
So, bottom line; don’t waste your money on expensive encryption solutions unless those solutions are performing the above distribution (bitcloud for example), but then it’s not encryption as we know it, it’s the next generation of privacy.
