Full Disclosure

Richard Clayton ukcrypto at chiark.greenend.org.uk
Tue, 29 Apr 2008 14:06:48 +0100


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

In article <A8820BCB-3E47-4E7E-9BD5-0035429AE4F9@batten.eu.org>, Ian
Batten <igb@batten.eu.org> writes

>The contradiction I'm worrying away at is ``Is the Phorm UUID  
>personally identifiable data?''
>
>I'd argue it is.

Phorm could prevent the linkage with a little crypto (viz: they could
fix this aspect of their system if they wished). I don't feel minded to
do all the necessary system design for them, but it's pretty
straightforward so far as I can see.

Of course, it would then be a little harder for anyone to be sure that
their system was doing what they said it was :(  and the crypto wouldn't
solve their "reverse engineer the business model" attack.

- -- 
richard                                              Richard Clayton

They that can give up essential liberty to obtain a little temporary
safety deserve neither liberty nor safety.         Benjamin Franklin

-----BEGIN PGP SIGNATURE-----
Version: PGPsdk version 1.7.1

iQA/AwUBSBcdaJoAxkTY1oPiEQLjTgCg4gvokmKe39RL+FTwpu6DtmS301IAniAu
n247oEQHmjT1vxTId+96zd5A
=m+1V
-----END PGP SIGNATURE-----