7
you are viewing a single comment's thread
view the rest of the comments
[-] who@feddit.org 2 points 5 hours ago* (last edited 5 hours ago)

Tom Kemp, CalPrivacy Executive Director: That data is stored in kind of five separate areas and it's hashed...

As written, that means they are storing personal info, along with a hash of said info. If that is indeed the case, it's bad news for privacy.

It is possible he meant to say that they only store the hashes, which would be a bit better. The surrounding text kind of implies this is the case, but doesn't explicitly say so, making it unclear whether these assurances are honest or just weasel words.

It's also possible that the hashes are calculated in the web browser, with the original data never sent over the network at all. This would much better, although I would be (pleasantly) surprised if this is the case. Even if it is, a hash of low-entropy data with well-known ranges, like a phone number, is trivial to reverse through brute force. I wonder if their system handles phone numbers in some better way.

In any case, California's DROP does seem interesting. I would like to know exactly how it and its adjacent systems handle personal information. If anyone here can link authoritative info, please do.

Tom Kemp, CalPrivacy Executive Director: Brokers who don't comply face fines of $200 per day, per incident.

This seems potentially good, if violations are actually discovered and the fines are quickly and meaningfully enforced. I guess time will tell. Prison time for executives, in addition to the fines, would be better.

this post was submitted on 16 Sep 2026
7 points (73.3% liked)

Privacy

5167 readers
418 users here now

Icon base by Lorc under CC BY 3.0 with modifications to add a gradient

founded 3 years ago
MODERATORS