privacy is almost easy! - unesco...according to this definition, differential privacy is a condition...

11
Privacy is Almost Easy! 2 nd European MIL forum Riga, 27.06.2016. Kārlis Podiņš, CERT.LV

Upload: others

Post on 27-Jun-2020

1 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Privacy is Almost Easy! - UNESCO...According to this definition, differential privacy is a condition on the release mechanism (i.e., the trusted party releasing information about the

Privacy is Almost Easy!

2nd European MIL forum Riga, 27.06.2016.Kārlis Podiņš, CERT.LV

Page 2: Privacy is Almost Easy! - UNESCO...According to this definition, differential privacy is a condition on the release mechanism (i.e., the trusted party releasing information about the

CERT.LV

Page 3: Privacy is Almost Easy! - UNESCO...According to this definition, differential privacy is a condition on the release mechanism (i.e., the trusted party releasing information about the
Page 4: Privacy is Almost Easy! - UNESCO...According to this definition, differential privacy is a condition on the release mechanism (i.e., the trusted party releasing information about the

• Someone's right to keep their personal matters and relationships secret

• Freedom from unauthorized intrusion

– Sources: Merriam-Webster and Cambridge

Privacy

Page 5: Privacy is Almost Easy! - UNESCO...According to this definition, differential privacy is a condition on the release mechanism (i.e., the trusted party releasing information about the

• Legally correct

• Totally broken

• NOR consumer protection board performance

– 33 popular apps

– 900 pages

– >30 hours

Data Sale – All of You Have AGREED to it

Page 6: Privacy is Almost Easy! - UNESCO...According to this definition, differential privacy is a condition on the release mechanism (i.e., the trusted party releasing information about the

Industrial-Scale Privacy Breach

Page 7: Privacy is Almost Easy! - UNESCO...According to this definition, differential privacy is a condition on the release mechanism (i.e., the trusted party releasing information about the

How is Privacy Compromised?

User disclosure

User agreement = data sale

Hacking

Advanced methods

Page 8: Privacy is Almost Easy! - UNESCO...According to this definition, differential privacy is a condition on the release mechanism (i.e., the trusted party releasing information about the

• 2006 Netflix publishes some anonymized ratings

– 100M movie rating records

– 480k users

• Attacker model:

– A few movies watched by target

– Approximate timeframes

• Targeted deanonymization possible (Narayanan&Shmatikov 2008)

What Can Go Wrong?

Page 9: Privacy is Almost Easy! - UNESCO...According to this definition, differential privacy is a condition on the release mechanism (i.e., the trusted party releasing information about the

Differential Privacy

Page 10: Privacy is Almost Easy! - UNESCO...According to this definition, differential privacy is a condition on the release mechanism (i.e., the trusted party releasing information about the

Take-away

• Privacy – it's almost easy!

Page 11: Privacy is Almost Easy! - UNESCO...According to this definition, differential privacy is a condition on the release mechanism (i.e., the trusted party releasing information about the

Thank You