Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> If the amount of data is large enough and with enough parameters, removing PII doesn't do anything to protect privacy.

Honestly it doesn't have to be that large. We see this all the time with data websites or apps collect. Sure, you remove John Smith's name, but you still have his GPS coordinates. For the school, you remove Professor Smith's name, but you have a professor who teaches CS 123 and has 4 graduate students. You bet you can guess who that is.

I really do support open data, especially about public institutions, but at the same time we are in an era where this information is quite powerful. Seems to make a case for something like homeomorphic encryption or something, but will that even stop these collisions?



The appropriate notion here seems to be Differential Privacy, which is a mathematical definition informally saying "a scrambling of the dataset that is information theoretically indistinguishable from that where one arbitrary person is added or removed". It's a surprisingly deep topic, with entire (very good!) textbooks dedicated to it.

PDF (entirely legal): https://www.cis.upenn.edu/~aaroth/Papers/privacybook.pdf




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: