Privacy vs. Security
The oldest argument against privacy is that it costs us security. The argument has it backwards.
Security advocates tend to claim that privacy is impossible to achieve if we want true security. Privacy advocates do not claim the reverse, that security is impossible if we want true privacy. That asymmetry is worth examining.
What the privacy advocate wants is a world where, when you arrive in a physical or digital space:
- by default, you are not recognizable from your previous interactions with other spaces, and
- if you choose, you are not recognizable from your previous interactions with that space.
At first glance there is real tension between this and several security measures. If registered sex offenders can enter spaces with children without being re-identified, how do we keep those spaces safe?
The privacy-invasive answer is facial recognition, already widely deployed in some societies. Your face becomes a universal identifier; every interaction in every place can, in principle, be traced back to you. The tracking problem is solved, at the cost of everything the privacy advocate wanted.
Make the face the identifier and every space reports to the same dossier. The park, the library, and the forum stop being separate places. Each visit becomes one more thread in a single web that traces back to you.
To enter one space, you are asked to hand over all of it. Name, date of birth, address, registry status. The question was narrow, but the demand is your whole biography.
Notice what the safety question actually requires. Not longitudinal identification, just one bit: this person is not on the registry. An anonymous credential can prove that single fact and nothing else.
Each space learns the answer it needs and learns nothing more. No thread connects your visit to the park with your visit to the forum. You stay unrecognizable by default, and the spaces stay safe.
Tracking was never free. Its price is security, because every dossier is a database that someone can breach, misuse, or quietly read. Data that does not exist cannot leak. The single bit is the more secure design, not the less.
A single bit
But notice what the safety question actually requires. We don’t need longitudinal identification. We need one bit.
When you enter a space with children in it, you could present an anonymous credential proving that you hold a government-issued identity document whose name does not appear on the public offender registry, without revealing who you are or anything else about your identity. The verifier learns the one fact it needs and nothing more. This is not speculative technology; it is what anonymous credentials are for.
”But tracking is free”
The security advocate now objects: you’ve imposed a cost on everyone, whereas pervasive tracking is free: “good” people don’t have to do anything to be marked safe. And surely these anonymous documents invite fraud: people will share credentials, and because the documents are never shown directly, forgery will be easier.
The reply is that tracking is not free. Its price is precisely security.
If I cannot guarantee that my movements and preferences are not being tracked, my basic operational security is at risk. “We are the good guys,” says whoever holds the data. But there are no such neat dichotomies. The majority of sexual assaults happen near the victim’s home, committed by people they know. If we can’t tell who the good guys are among friends and family, how can we tell among the enormous population of public and private employees with access to tracking data? Significant numbers of police officers have been shown to be perpetrators of domestic violence; and they are, definitionally, supposed to be the good guys. Should anyone have access to data tracking their own family’s movements?
The most advanced version of the tracking position proposes to confine the data inside special, very private computers, where programs decide whether someone has violated a policy. But who writes the programs? How do we know the data inside cannot leak? The privacy advocate’s position is that the existence of this data anywhere a human can plausibly access it is an unacceptable security risk.
As for fraud: today’s identity documents are shown, photographed, and scanned by everyone for the purposes of tracking, and identity fraud is already severe: your information can be transcribed straight off the records onto a new document. Fraud risks deserve mitigation in any identity system. They are not unique to the privacy-preserving ones.
The false tension
As an advocate for both privacy and security, my hope is that this tension will eventually be seen to have been false all along. Privacy is required for security. The security we will feel in a private world will outstrip the security we only thought we felt in a surveilled one.