What are the chances this will lead to online data privacy reform and corporate accountability for PII for all? or just…some?

    • LOGIC💣@lemmy.world
      link
      fedilink
      English
      arrow-up
      5
      arrow-down
      7
      ·
      21 hours ago

      I intentionally was vague because there are many possible existing ways to accomplish each thing I said, and it is up to the phone company to innovate.

      The simplest way to keep people from guessing phone numbers is to make them very long and sparse. If an autodialer had to dial 1000 invalid numbers before finding a valid number, it would make the endeavor that much harder. This is just a convenient example because the cryptography equivalent is harder to explain, but you could make contact info so hard to guess that it would be basically impossible.

      Probably the easiest way to explain how to keep people from passing contact info is to imagine a two step process like facebook has. If I pass your facebook username to someone else, they don’t automatically become your friend. The cryptographic equivalent would involve a chain of trust, but again, harder to explain.

        • Natanael@infosec.pub
          link
          fedilink
          English
          arrow-up
          1
          ·
          15 hours ago

          Literally just use existing standards (STIR/STUN) with some filtering by source network, etc

      • AwesomeLowlander@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        3
        ·
        18 hours ago

        Still not seeing how it would work. You’re dropping random bits of the system and saying it would work but it’s too complicated for you to explain, so there’s really nothing to discuss.

        • WhyJiffie@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          2
          ·
          edit-2
          14 hours ago

          not op but signal has basically solved this. users are not just randomly accessible by anyone. they can share a long URL that contains an ID, or make a short username they like and pass around to people. and even then the recipient has to accept being contacted by each other user

          true that signal now relies on the phone number system for trust and safety, but that’s not core to how signal works, it could be replaced if they really wanted.

          • AwesomeLowlander@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            1
            ·
            14 hours ago

            At that point, you (well, not you per se) are basically suggesting to replace the telephone system with a Signal-esque system. Which would break a billion things in real life, for little to no gain.

            • WhyJiffie@sh.itjust.works
              link
              fedilink
              English
              arrow-up
              1
              ·
              11 hours ago

              any change would break a billion things in real life, so we could at least have a proper replacement.

              the problem with signal here is that it’s centralized, probably couldn’t even handle the load besides other problems. but that’s solvable, like look at simplex which is similar