It has become commonplace for users to have to provide personal information in order to gain access to a service. At the very least, to have an account on any website, the site wants a username and password to protect access to your account. At the other end of the spectrum, companies in the financial, medical, e-commerce, and public sector have vast repositories of data on users.
If organizations have a valid need to know every piece of data that they request and collect and if they respected the data by adequately protecting it and using it only when absolutely necessary, then maybe this vast collection of personal data may be understandable and even acceptable. However, neither of these are actually the case. Companies collect additional data to use for customer profiling and targeted advertising. In 2017, there were 1,579 data breaches where organizations lost control of personal data entrusted to them.
You shouldn’t have to trust anyone else to protect your data. The record clearly shows that organizations with custody of your data misuse it and lose it in data breaches. By embracing edge security, organizations can operate while allowing customers to remain in control of their own personal data.
Why You Shouldn’t Trust Organizations with Your Data
Why shouldn’t you trust organizations with your data? Because they’ve demonstrated time and again that they are not to be trusted. The two main risks of providing personal data to an organization are that they will lose or misuse it.
They Lose It in Data Breaches
The number of data breaches where companies lose personal data of their customers has exploded over the last few years. In 2017, there were 1,579 breaches of people’s personal information. This was a 44.7% increase over the number of data breaches reported in 2016 (which was also a record-breaking year). Data breaches have become more and more common as organizations collect massive repositories of users’ personal data, creating enticing targets for hackers.
Data breaches are not a problem of a single company, industry, or even sector. In 2017, the most famous breach was of Equifax, a credit monitoring company. Equifax was hacked, resulting in the loss of personal information of 145 million people. Breached information included names, Social Security Numbers, addresses and birthdates for all affected people and credit card information for 209,000 Americans.
Another breach showing that companies are not to be trusted with personal data is the
Uber data breach. In late 2016, a hacker breached Uber’s networks and stole information on 57 million Uber users and the driver’s license information of 600,000 American Uber drivers. Rather than report the breach (as required by law in Uber’s home state of California), Uber paid the hacker $100,000 in return for assurances that the data was destroyed (which may violate a US Federal Trade Commission law that prohibits the destruction of forensic evidence during an investigation).
Data breaches are not even limited to the public sector. In 2017, 57% of US government agencies experienced a data breach (up from 34% in 2016). This is the largest percentage for an industry (the average across all industries is 35%). If organizations cannot adequately protect people’s personal data, then why should they be trusted with it?
They Misuse It
It is bad enough that companies collect and then accidentally lose user data in breaches. It’s worse when they collect it with the intent of misusing it without user knowledge or consent.
Organization are not trustworthy guardians of user data because they have proven that they themselves will use it improperly.
In November 2017, a lawsuit was filed in the UK against Google on behalf of 5.4 million iPhone users for bypassing the default privacy settings on the iPhones. In 2011 and 2012, Google had used code designed to trick the Safari browser on the iPhone into revealing the personal data of users.
In September 2017, Facebook was fined by the Spanish Data Protection Agency (AEPD) for multiple counts of failing to inform users how their personal data (gender, religious beliefs, personal tastes, and browsing history) would be used. Facebook also doesn’t publicize how the data collected from browser cookies from websites including a Like button will be used (even if site visitors are not Facebook users). The company also retains user data for 17 months after users close their accounts.
Companies misuse user’s personal data because they have financial incentives to do so. User data can be sold to advertisers and analyzed to better tailor their own product to user needs. Until they are forced to do so, companies will not stop collecting and misusing personal data for their own ends.
Edge Security is the Solution
Edge security is a new paradigm for the collection and storage of personal data that can end companies‘ collection, storage, misuse, and loss of personal data. An organization using edge security has users encrypt their personal data before transmitting it to the organization for storage. Since the organization does not have the ability to access the unencrypted data, there is no possibility that a breach of the organization’s systems will reveal vast troves of personal data.
How Can an Organization Use Data That It Can’t See?
Edge security uses zero-knowledge proofs for authentication. In a zero-knowledge proof, one party can prove to the other that they know some piece of information without revealing what that information is.
To protect access to an account, organizations commonly collect users’ email addresses and passwords. To gain access, the user provides their email address and password and compares it to the one on file with the company. However, it’s not necessary for the company to have the actual email address and password for this type of simple comparison system to work.
In edge security, a user will take the hash of their email address and password and provide both of these to the company. A hash is a function where it is easy to get the output from the input but impossible to get the input from the output. A company can just as easily compare the hash of an email address to their database as the email address itself, but the company does not have the actual data, so it can’t lose or misuse it.
With all of the reports of data breaches and misuse of data, it’s time for companies to do the right thing and stop collecting and storing users’ personal data. Organizations should embrace edge security and allow users to be the sole custodians of their data.