Privacy by Default - EuroIA 2016

98
Lutz Schmitt @luxux – EuroIA Summit 2016 Amsterdam PRIVACY BY DEFAULT illustration by Lutz Schmitt – licensed under cc-nc-by 4.0

Transcript of Privacy by Default - EuroIA 2016

Page 1: Privacy by Default - EuroIA 2016

Lutz Schmitt – @luxux – EuroIA Summit 2016 Amsterdam

PRIVACY BY DEFAULT

illustration by Lutz Schmitt – licensed under cc-nc-by 4.0

Page 2: Privacy by Default - EuroIA 2016

The concept was created a good 10 years ago.

illustration by Lutz Schmitt – licensed under cc-nc-by 4.0

Page 3: Privacy by Default - EuroIA 2016

I added the missing parts for a

future world with ambient intelligence,

that I would want to live in.

illustration by Lutz Schmitt – licensed under cc-nc-by 4.0

Page 4: Privacy by Default - EuroIA 2016

Diagram by Claire Rowland. Used with permission.

Facets of IoT UX by Claire Rowland

Social Normative Norms that form society and regulate human interaction

Technology Design Rules how technology must work,

to ensure the social norms invisible

Page 5: Privacy by Default - EuroIA 2016

Diagram by Claire Rowland. Used with permission.

Social Normative Norms that form society and regulate human interaction

Technology Design Rules how technology must work,

to ensure the social norms invisible

This talk is about the foundation

for all of this

Page 6: Privacy by Default - EuroIA 2016

PREPARATIONS

Page 7: Privacy by Default - EuroIA 2016

security is fundamental

Page 8: Privacy by Default - EuroIA 2016

ultimately, it‘s all about trust

Page 9: Privacy by Default - EuroIA 2016

https://twitter.com/MetroUK/status/776150782194376704

Page 10: Privacy by Default - EuroIA 2016

PREPARATIONS:

PRIVACY

Page 11: Privacy by Default - EuroIA 2016

the right to be let alone

Page 12: Privacy by Default - EuroIA 2016

1. The right to privacy does not prohibit any

publication … which is of public … interest

4. The right to privacy ceases upon the

publication of the facts by the individual,

or with his consent.

Limitations of the Right to Privacy

Page 13: Privacy by Default - EuroIA 2016

the need for privacy is individual

Page 14: Privacy by Default - EuroIA 2016

Alan Westin in Privacy and Freedom, 1967

Page 15: Privacy by Default - EuroIA 2016

• Solitude

• Intimacy

• Anonymity

• Reserve

STATES OF PRIVACY

Alan Westin in Privacy and Freedom, 1967

Page 16: Privacy by Default - EuroIA 2016

• Solitude

• Intimacy

• Anonymity

• Reserve

• Pseudonymity

STATES OF PRIVACY EXTENDED

Page 17: Privacy by Default - EuroIA 2016

privacy can only

be violated by other persons!?

Page 18: Privacy by Default - EuroIA 2016

Source: https://www.hackread.com/samsung-smart-tv-listening-conversations/

Page 19: Privacy by Default - EuroIA 2016

No one shall be subjected to arbitrary

interference with his privacy, family, home

or correspondence, nor to attacks upon his

honour and reputation. Everyone has the

right to the protection of the law against

such interference or attacks.

Article 12

Universal Declaration of Human Rights

http://www.un.org/en/universal-declaration-human-rights/

Page 20: Privacy by Default - EuroIA 2016

PREPARATIONS:

INTERNET

Page 21: Privacy by Default - EuroIA 2016

THE INTERNET AS OF TODAY

Page 22: Privacy by Default - EuroIA 2016

SOME SERVICE OWNED

BY A COMPANY

Page 23: Privacy by Default - EuroIA 2016

User

User

User

WE GO INTO THIS SPHERE

TO BECOME A USER

Page 24: Privacy by Default - EuroIA 2016

User

User

User

THE SPHERE DEFINES THE

MEANS OF INTERACTION

Page 25: Privacy by Default - EuroIA 2016

photo by Becky Striepe on flickr.com licensed under cc-by-nc-sa 2.0

the internet is

not a public place

Page 26: Privacy by Default - EuroIA 2016

photo by Tom Borowski on flickr.com licensed under cc-by-nc 2.0

Facebook is Mark

Zuckerbergs living room

Page 27: Privacy by Default - EuroIA 2016

and this happens to continue

Page 28: Privacy by Default - EuroIA 2016

PREPARATIONS:

INTERNET OF THINGS

Page 29: Privacy by Default - EuroIA 2016

synonyms

Page 30: Privacy by Default - EuroIA 2016
Page 31: Privacy by Default - EuroIA 2016

photo by Philips. Released as press release.

Remote controlling your lightbulbs

Page 32: Privacy by Default - EuroIA 2016

photo by revolv. Released in the press kit.

devices that need a cloud connection

Page 33: Privacy by Default - EuroIA 2016

photo amazon.com. product shot. Used under fair use policy.

we have reached zero effective cost

Page 34: Privacy by Default - EuroIA 2016

THE VISION FOR THE

INTERNET OF THINGS

THAT HOOKED ME

Page 35: Privacy by Default - EuroIA 2016

photo by Sarah Leo on flickr.com – licensed under cc-by-sa 2.0

Mark Weiser, The Computer for the 21st Century, 1991

Page 36: Privacy by Default - EuroIA 2016

WHAT WE NEED TO

SOLVE

Page 37: Privacy by Default - EuroIA 2016

DEFINING

CHALLENGE #1

Page 38: Privacy by Default - EuroIA 2016

a friend with lack of knowledge

Page 39: Privacy by Default - EuroIA 2016

photo by Juan Ignacio Sánchez Lara on flickr. Licensed under cc-by-nc-sa-2

the ambient intelligence won‘t

come with a power button

Page 40: Privacy by Default - EuroIA 2016

how must the IoT work,

Page 41: Privacy by Default - EuroIA 2016

DEFINING

CHALLENGE #2

Page 42: Privacy by Default - EuroIA 2016

Mark Weiser, The Computer for the 21st Century, 1991

Page 43: Privacy by Default - EuroIA 2016

we need to trust and believe,

Page 44: Privacy by Default - EuroIA 2016

Arthur C. Clarke, Hazards of Prophecy 1962

Page 45: Privacy by Default - EuroIA 2016

How do we design this magic reality,

Page 46: Privacy by Default - EuroIA 2016

DEFINING

CHALLENGE #3

Page 47: Privacy by Default - EuroIA 2016

decisions and

setups all the time

Page 48: Privacy by Default - EuroIA 2016

staying in control

or at least informed

Page 49: Privacy by Default - EuroIA 2016

INTERACTION

OVERLOAD

Page 50: Privacy by Default - EuroIA 2016

DEFINING

CHALLENGE #4

Page 51: Privacy by Default - EuroIA 2016

Screenshot. Source: the internet

lack of balance

Page 52: Privacy by Default - EuroIA 2016

what means of balancing do we need

Page 53: Privacy by Default - EuroIA 2016

• Design magic that empowers people

• Avoid interaction overload

• Staying in control without pulling the plug

• Implement means of balancing interests

CHALLENGES FOR THE

INTERNET OF THINGS

Page 54: Privacy by Default - EuroIA 2016

GUIDELINES FOR THE

INTERNET OF THINGS

TO ENABLE PRIVACY

Page 55: Privacy by Default - EuroIA 2016

TECHNOLOGY

MUST BE SECURE

Page 56: Privacy by Default - EuroIA 2016

THE NETWORK

MUST BE

Page 57: Privacy by Default - EuroIA 2016

EVERYTHING

MUST BE CONNECTED

Page 58: Privacy by Default - EuroIA 2016

EVERYTHING

MUST BE IDENTIFIABLE

Page 59: Privacy by Default - EuroIA 2016

COMMUNICATION

MUST BE DENIABLE

Page 60: Privacy by Default - EuroIA 2016

A PERSONS INTENT

MUST BE KNOWN

Page 61: Privacy by Default - EuroIA 2016

DECISIONS

MUST BE REVERSABLE

Page 62: Privacy by Default - EuroIA 2016

a concept for privacy in a world with the internet of things

PRIVACY BY DEFAULT

illustration by Lutz Schmitt – licensed under cc-nc-by 4.0

Page 63: Privacy by Default - EuroIA 2016

Privacy is the choice, who we trust

enough to provide information and

allow communication with

Page 64: Privacy by Default - EuroIA 2016

CHARLOTTE

Ms. HOPKINS

ANONYMOUS

Page 65: Privacy by Default - EuroIA 2016

introducing identity

Page 66: Privacy by Default - EuroIA 2016

our identity

representation changes

Page 67: Privacy by Default - EuroIA 2016

PSEUDO IDENTITIES

CORE IDENTITY

PUBLIC IDENTITY

CONTEXTUAL IDENTITIES

Our true unique self Our pretended

selves

Our contextual true selves

Our non-private self

Page 68: Privacy by Default - EuroIA 2016

these identities are a basic rule set

Page 69: Privacy by Default - EuroIA 2016

SERVICE

OBJECT

LOCA-TION

PERSON

INSTI-TUTION

everything and everybody

needs that identity structure

ANIMAL

Page 70: Privacy by Default - EuroIA 2016

identity

Page 71: Privacy by Default - EuroIA 2016

only ownage allows

Page 72: Privacy by Default - EuroIA 2016

Source: https://www.hackread.com/samsung-smart-tv-listening-conversations/

Page 73: Privacy by Default - EuroIA 2016

Our pretended selves

IDENTITIES CAN BE OWNED

phone

diary

Bitcoin vallet

house

Page 74: Privacy by Default - EuroIA 2016

interaction is ultimately

between persons

Page 75: Privacy by Default - EuroIA 2016

of course a person

mustn‘t be human

Page 76: Privacy by Default - EuroIA 2016

introducing

privacy spheres

Page 77: Privacy by Default - EuroIA 2016

PUBLIC

RESERVED

INTIMATE

PERSONAL ONLY YOU

WITH ACTIVE GRANT

WITH PASSIVE GRANT

EVERYBODY

privacy spheres

Page 78: Privacy by Default - EuroIA 2016

CORE IDENTITY

CONTEXTUAL IDENTITY – HOME OWNER

CONTEXTUAL IDENTITY – WORK

INTIMATE RESERVED PUBLIC PERSONAL

secret diary

pictures from last night

work certificates

grant home control

fitness tracker data

pseudo contact details

geo location

shirt‘s product info

work contact details

coffee maker‘s fill status

shirt‘s unique ID

pictures from THAT night

second Bitcoin vallet

Page 79: Privacy by Default - EuroIA 2016

INTIMATE RESERVED PUBLIC PERSONAL

personal data

personal data

personal data

right to management

body data

identification & communication

body data

object data

Identification & communication

usage data

identification

personal data

wealth data and transaction id

Page 80: Privacy by Default - EuroIA 2016

similar data may not be exposed

Page 81: Privacy by Default - EuroIA 2016

INTIMATE RESERVED PUBLIC PERSONAL

personal data 1

personal data 2

Page 82: Privacy by Default - EuroIA 2016

every identity has a default

Page 83: Privacy by Default - EuroIA 2016

INTIMATE RESERVED PUBLIC PERSONAL

Right to manage

Right to use

Unique identification

object info

sensor data

Page 84: Privacy by Default - EuroIA 2016

combining identity and privacy spheres

Page 85: Privacy by Default - EuroIA 2016

CORE IDENTITY

CONTEXTUAL IDENTITY – HOME OWNER

CONTEXTUAL IDENTITY – WORK

INTIMATE RESERVED PUBLIC PERSONAL

CORE ID – UID24298723459

PSEUDO ID – MADAMEPOMPADILLE

CONTEXTUAL ID – HR42CHOPKINS

PUBLIC IDENTITY

Page 86: Privacy by Default - EuroIA 2016

INTIMATE RESERVED PUBLIC PERSONAL

CORE ID – UID24298723459 Right to manage

Right to use

Unique identification

object info

sensor data

Page 87: Privacy by Default - EuroIA 2016

INTIMATE RESERVED PUBLIC PERSONAL

CORE ID – UID24298723459 Right to manage

Right to use

Unique identification

object info

sensor data

Page 88: Privacy by Default - EuroIA 2016

relationships

Page 89: Privacy by Default - EuroIA 2016

only similar identities may interact

me you OK

Page 90: Privacy by Default - EuroIA 2016

me you NO

Page 91: Privacy by Default - EuroIA 2016

those who initiate

communication

Page 92: Privacy by Default - EuroIA 2016

INTIMATE RESERVED PUBLIC INTIMATE RESERVED

OK, automatic rules apply

Page 93: Privacy by Default - EuroIA 2016

INTIMATE RESERVED PUBLIC INTIMATE RESERVED

maybe OK, person’s decision

needed

Page 94: Privacy by Default - EuroIA 2016

actually the idea of privacy is simple

Page 95: Privacy by Default - EuroIA 2016

but I see that it won‘t make

it easier to design products

Page 96: Privacy by Default - EuroIA 2016

and there are complicated

social issues to solve

Page 97: Privacy by Default - EuroIA 2016

finally,

I agree on the universal human rights

Page 98: Privacy by Default - EuroIA 2016

photo by mere41782 on flickr.com – licensed under cc by nd 2.0

Now go out there and

build a future

I want to live in.

Please.

@luxux www.lutzschmitt.com