You are going to visit example.com, a site which you have an account.
You think your clipboard have the string "example.com". But while the browser opened, you clicked your password manager and already copied the password for it. (or for the sake of the example, you might have been typing an email you didn't not want to share, maybe it had financial information about your IPO... I am going with password as it is clearly something you want and need to keep private)
When Chrome opens, you click the address bar and paste. See your mistake, press backspace a few types, type example.com and press return. Now google has on it's logs (and associated to your user profile) your example.com's password and you never had any feedback that it was sent, unless there was search results for your password (let's hope not)!
Had you used firefox with autocomplete off (which you should) you would have seen the mistake before pressing return. or if you did press return, it would have been very clear to you that you just sent your password to google.
So, defend it all you want, but it is a dark pattern that logs everything you type on a somewhat unrelated field and only show you feedback on certain cases. It is worlds apart from typing your credit card on amazon!
The funny thing about places where @ mean a unit of weight, is that the word is kept for reading emails out loud.
You spell emails as "me arroba domain dot com", which sounds to the native ear almost like "me kilogram domain dot com", but is completely normal nowadays.
the term "pizzagate" was part of the disinformation to throw the actual investigation under the bus.
The press focused on a leaked report that it all happened in a small pizza place. While it effectively (for the leakers) killed progress of the investigation (the one which consequences are being talked now in this thread, so it was very much real) it also gave a catchy name for a while, that cause real investigative reports to jump in.
fake news is a very interesting problem to follow.
Not talking about a hacker. I am stating that the described hash dance offers no exclusion from GDPR as saying "we promise we won't look" would do.
My point about brute forcing being useless, is that you hold all the information needed to re-create the hash. All but one tiny piece that is the random number. so brute force is a very effective O(<tiny piece size>). And since it is stored in your locally available data, there is no rate constraints.
"Hey company in shenzen that i suspect is a shady front to illegal data mining business, do you have any data on me? i'm john doe, living at 123 naive st #42, phone number 555-555-555, national registry number 1234556. You can reply to me on this same email address. thank you. PS: maybe i filled this in an webform, so please do not attach this new info to all the traffic/behaviour you previously collected from your TV on this same IP address"
If a search query on your data would contain all the components of the original hash, i don't have to walk backwards and break the hash. i just have to hash my query terms in the same way.
Also I suggested you store the daily hash forever. But even if you really erase it every day, as you say, If you or an attacker makes the same request every day at a predetermined time, when you/they get your logs, you/they can use that predictable request to get the daily secret too.
I consider the information to be stored in plain text, and that you would have to have requested permission just the same. You pretty much have an identifiable user (via IP/UA/access time) stored in your logs.
Anonymization is removal of information, not encoding it in a convoluted hash.
This is still logging everything the GDPR says you can't without asking for consent, but you made your search convoluted (but not less efficient if you have all the pieces) to (suggest|lie?) that you need to break the hash and that's why you don't need consent.
None of the information you are using on the hash wouldn't be in the search query itself! ip, user agent, path, date, etc. So there is no way to reverse the hash. You just hash your search query and compare in O(1) time.
The only piece of information that realistically makes the hash slightly difficult to get is the random number refreshed every day. But either you store it (and i have no reason to believe you do not) or it make the brute force effort trivial as I only need to generate the hash with that variable now.
You think in terms of theoretical society that is either On or Off. No place is like that.
You missed the point that the people fleeing is already stealing tax and are likely the bad parts of the system themselves. They are fleeing from others like them and the justice, to begin with. If the system will collapse or not, i doubt that cross their mind.
> This isn’t super easy to see because it’s hidden in a bunch of cultural stuff we just take for granted.
This is why sociologist mostly clump all the ism (capitalism, socialism, etc) into religion. They work within the same framework.
If someone said "give all the poor people money to improve the life of a rich person who owns thousands of hotels" you would trhow that person out of the window. Now dress it in the complex Myths, which the article tries to unwrap, and everyone buys!
that's a very bad analogy. Apps waste way more bandwidth. It's better if you turn it around: "unlimited gas for you 4mpg hummer. But we will nickel and dime you if you try to ever fill up the 1L reserve tank on your electric scooter"
* github has no ads, yet. But microsoft is the 3rd largest.