{"id":5740,"date":"2018-03-22T21:19:05","date_gmt":"2018-03-22T21:19:05","guid":{"rendered":"https:\/\/davidgerard.co.uk\/blockchain\/?p=5740"},"modified":"2021-02-13T15:47:51","modified_gmt":"2021-02-13T15:47:51","slug":"blockchain-identity-cambridge-analytica-but-on-the-blockchain","status":"publish","type":"post","link":"https:\/\/davidgerard.co.uk\/blockchain\/2018\/03\/22\/blockchain-identity-cambridge-analytica-but-on-the-blockchain\/","title":{"rendered":"Blockchain identity: Cambridge Analytica, but on the blockchain"},"content":{"rendered":"<p>Nobody much uses blockchains for real work \u2014 they don&#8217;t work very well in practice, they utterly fail to scale, and the most famous and widely-used one, Bitcoin, uses more energy than entire countries.<\/p>\n<p>So their fantasy life is <em>amazing<\/em>.<\/p>\n<h3>The fabulous claims of Blockchain!<\/h3>\n<p>Most of the fantastic claims for Blockchain\u2122 originated as fantastic claims for Bitcoin. I detail some of the claims that carried over in <a href=\"https:\/\/davidgerard.co.uk\/blockchain\/table-of-contents\/\">chapter 3<\/a> of <a href=\"https:\/\/davidgerard.co.uk\/blockchain\/book\/\">the book:<\/a><\/p>\n<ul>\n<li>totally decentralised, there&#8217;s no central controller that you have to trust!<\/li>\n<li>immune to bad actors!<\/li>\n<li>the blockchain is immutable and incorruptible!<\/li>\n<li>money can flow instantly and internationally for near-free!<\/li>\n<li>will destroy hierarchies and the present order of<a href=\"https:\/\/davidgerard.co.uk\/blockchain\/the-conspiracist-gold-bug-economics-of-bitcoin\/\"> corrupt governments and banks!<\/a><\/li>\n<\/ul>\n<p>And from the smart contract hype (chapter 10):<\/p>\n<ul>\n<li><em>smart contracts<\/em> will do all your back-office work for free &#8230; out there somewhere &#8230; <em>on the blockchain!<\/em><\/li>\n<li>no human element in resolving disputes!<\/li>\n<\/ul>\n<p>What happened was that Bitcoin had failed at decentralisation by early 2014 (three miners control over 50% of the mining) and at free and instant flow of money by mid-2015 (the transaction clog, and the stupendous power usage). It also inexplicably failed to replace goverments or banks.<\/p>\n<p>(Bitcoin did succeed at immutability, which is why it&#8217;s got <a href=\"https:\/\/blog.acolyer.org\/2018\/03\/19\/a-quantitive-analysis-of-the-impact-of-arbitrary-blockchain-content-on-bitcoin\/\">illegal pornography on it that nobody can remove.<\/a>)<\/p>\n<p>But the promises crossed over to business blockchain promotion \u2014 where unlikely claims are put forward, with the implication that you can get not just one, but all, of these unlikely things, and all at the same time.<\/p>\n<p>The attraction is the hope that your business or your organisation can work more efficiently. Any organisation has bureaucracy, and if you make it work better you can achieve more with less.<\/p>\n<p>The trouble is that prospective users hear the hype, and assume the hypotheticals are real products that exist now \u2014 when &#8220;the blockchain could&#8221; is a phrase that really means &#8220;the blockchain doesn&#8217;t.&#8221;<\/p>\n<p>The way this works is:<\/p>\n<ol>\n<li>come up with some things that magical flying unicorn ponies could do;<\/li>\n<li>detail the many astounding consequences and use cases for these magical flying unicorn pony byproducts;<\/li>\n<li>write a report stressing the importance of closing the magical flying unicorn pony gap;<\/li>\n<li>ignore that magic doesn&#8217;t happen, and flying unicorn ponies don&#8217;t exist.<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/davidgerard.co.uk\/blockchain\/2018\/03\/22\/blockchain-identity-cambridge-analytica-but-on-the-blockchain\/un-usage-of-blockchain-p1\/\" rel=\"attachment wp-att-5753\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-5753\" src=\"https:\/\/davidgerard.co.uk\/blockchain\/wp-content\/uploads\/2018\/03\/un-usage-of-blockchain-p1.jpg\" alt=\"\" width=\"600\" height=\"450\" srcset=\"https:\/\/davidgerard.co.uk\/blockchain\/wp-content\/uploads\/2018\/03\/un-usage-of-blockchain-p1.jpg 600w, https:\/\/davidgerard.co.uk\/blockchain\/wp-content\/uploads\/2018\/03\/un-usage-of-blockchain-p1-300x225.jpg 300w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<h3>Examples: the United Nations buys the hype<\/h3>\n<p>Here&#8217;s a real-life example from <a href=\"http:\/\/www.unwomen.org\/en\/news\/stories\/2018\/2\/news-event-blockchain-technology-and-humanitarian-action\">&#8220;UN Women and partners to pilot blockchain technology in humanitarian action,&#8221;<\/a> from February 2018:<\/p>\n<blockquote><p>Blockchain is a distributed database of immutable digital records that can be accessed from anywhere. It offers users the ability to build and maintain immutable and secure records and to directly transfer digital assets without the need for intermediaries and associated costs.<\/p><\/blockquote>\n<p>Pretty good for a database structure. You never hear Postgres advocates <a href=\"https:\/\/wiki.postgresql.org\/wiki\/Oracle_to_Postgres_Conversion\">talking like this.<\/a> (Though MongoDB advocates <a href=\"https:\/\/www.youtube.com\/watch?v=b2F-DItXtZs\">used to get a bit strident.<\/a>)<\/p>\n<p>I found an astounding presentation from the United Nations Office of Information and Communications Technology, August 2017: <a href=\"https:\/\/unite.un.org\/sites\/unite.un.org\/files\/session_3_b_blockchain_un_initiatives_final.pdf\">&#8220;Usage of Blockchain in the UN System.&#8221;<\/a><\/p>\n<p>Page 3 is a big splash: &#8220;<strong>15<\/strong> UN entities carrying out Blockchain initiatives.&#8221; Page 4 reveals that three are proofs-of-concept, one is a <a href=\"https:\/\/en.wikipedia.org\/wiki\/Hackathon\">hackathon<\/a> event, ten are discussions and white papers on the <em>possibilities<\/em>, and one is funding for other people to posit possibilities.<\/p>\n<p>The only production system listed is the World Food Programme blockchain initiative\u00a0\u2014 which, as I&#8217;ve <a href=\"https:\/\/davidgerard.co.uk\/blockchain\/2017\/11\/26\/the-world-food-programmes-much-publicised-blockchain-has-one-participant-i-e-its-a-database\/\">detailed previously,<\/a> is a &#8220;blockchain&#8221; system with &#8230; a single user. That is to say, a database.<\/p>\n<p>The WFP\u00a0initiative is a good programme, with some startling efficiency gains \u2014 but all the gains are because they brought funds disbursement in-house, rather than because they&#8217;re running a private Ethereum instance as their back-end database.<\/p>\n<p>Also mentioned in the presentation is the UN Conference on <span class=\"il\">Trade<\/span> and <span class=\"il\">Development<\/span>&#8216;s &#8220;e-<span class=\"il\">Trade<\/span> for All&#8221; initiative, proudly based on the Estonian &#8220;blockchain&#8221; solution\u00a0\u2014 the one that <a href=\"https:\/\/davidgerard.co.uk\/blockchain\/2017\/09\/06\/estonias-smartcard-security-problem-is-probably-not-blockchain-related-but-what-is-estonias-blockchain\/\">isn&#8217;t even a blockchain,<\/a> except in the marketing buzzword sense.<\/p>\n<p>(I went to the <a href=\"http:\/\/unctad.org\/en\/Pages\/Home.aspx\">UNCTAD<\/a> and <a href=\"https:\/\/etradeforall.org\/\">e-Trade for All<\/a> sites, and couldn&#8217;t find anything about e-Trade for All being &#8220;blockchain&#8221; related. In fact, this presentation appears to be the only source of the claim that blockchains are involved.)<\/p>\n<h3>A complete surveillance panopticon, but on the blockchain<\/h3>\n<p>There are a disconcerting number of initiatives that are pretty much Cambridge Analytica on the blockchain. Lots of blockchain promoters still think a <a href=\"https:\/\/en.wikipedia.org\/wiki\/Panopticon\">panopticon<\/a> containing ALL THE PERSONAL DATA, <em>forever, immutably,<\/em> is a <em>good<\/em> idea and not a terrible one.<\/p>\n<p>The UN High Commission on Refugees recently posted <a href=\"http:\/\/www.unhcr.org\/blogs\/promise-hype-provides-blockchain-safe-identity\/\">&#8220;Promise or hype: Provides Blockchain a Safe Identity?&#8221;<\/a> It&#8217;s very technically vague and conditional:<\/p>\n<blockquote><p>Blockchain technology and strong encryption seem to be new tools for setting up a globally applicable system of digital proofs of identity, relevant for any kind of personal data (birth, health, citizenship, education and so on).<\/p><\/blockquote>\n<p>It includes claims that are somewhere between &#8220;wrong&#8221; and <a href=\"https:\/\/rationalwiki.org\/wiki\/Not_even_wrong\">&#8220;not even wrong,&#8221;<\/a> like this one:<\/p>\n<blockquote><p>Users\u2019 identities within a ledger are encrypted and therefore known only to the users themselves. These encrypted and verified identities are not stored on a centralized corporate, governmental or institutional server (ripe for hacking). Instead, blockchain technology allows personal information to be stored on the relevant decentralized ledger, while cryptographic hashing creates an unbreakable layer of safety.<\/p><\/blockquote>\n<p>This is a confusion of multiple misunderstood ideas, with the hope that <em>magic happens<\/em> and they can get the result they want from it.<\/p>\n<p>The striking thing about this proposal is that it would require the entire population of the world \u2014 all seven billion of us \u2014 to store our personal information on a single blockchain. Unchangeably, too.<\/p>\n<p>This is fundamentally the <a href=\"https:\/\/www.theguardian.com\/uk-news\/2018\/mar\/22\/cambridge-analytica-scandal-the-biggest-revelations-so-far\">Cambridge Analytica scandal,<\/a> on the blockchain. You can say &#8220;no, no, we&#8217;re using it for <em>good<\/em> causes!&#8221; \u2014 but it&#8217;s still a horrifyingly dangerous pile of highly personal data, that some foolish person has decided would be a good idea to put onto a <em>single public database<\/em> existing in <em>thousands of copies<\/em>. This would be a personal data time bomb.<\/p>\n<p>(The World Food Programme&#8217;s blockchain initiative literally proposed putting everyone&#8217;s <em>iris scans<\/em> onto the <em>public<\/em> Ethereum blockchain.)<\/p>\n<p>Our greatest protection against the Orwellian consequences of universal blockchain-based surveillance is that none of this is in any way technically feasible, and our businesses and nonprofits are being sold a pup.<\/p>\n<h3>&#8220;Decentralised&#8221; means &#8220;what? <em>Our<\/em> responsibility?&#8221;<\/h3>\n<p>It&#8217;s also entirely senseless for a single organsation, responsible for a system, to claim a decentralised blockchain with no human responsibility is an <em>advantage<\/em>.<\/p>\n<p>It&#8217;s an abrogation of responsibility. This is what the claim of being &#8220;decentralised&#8221; and immune to corruption by human agency leads to \u2014 the vague notion that there&#8217;s no central agency running the thing, if it&#8217;s on a <em>blockchain<\/em>.<\/p>\n<p>Smart contracts won&#8217;t help you here either. &#8220;The algorithm did it&#8221; is accepted as an excuse less and less these days.<\/p>\n<p>Are you claiming that your organisation&#8217;s database is somehow not under your control? It&#8217;s entirely unclear how this would be an acceptable claim in a dispute, if <em>you<\/em> chose to put your data on a blockchain and use it as your back-end database.<\/p>\n<p>It&#8217;s important to note that the panopticon-like plans would be a GDPR nightmare in Europe. The <a href=\"https:\/\/en.wikipedia.org\/wiki\/General_Data_Protection_Regulation\">General Data Protection Regulation<\/a> requires that any personal information must be\u00a0<em>removed<\/em> from a database (very broadly defined) that you control, on request from the subject \u2014 with maximum penalties for noncompliance of\u00a0\u20ac20 million, or 4% of\u00a0<em>global<\/em> turnover.<\/p>\n<p>If that database is a blockchain being used by your organisation\u00a0\u2014 then you&#8217;ve just made the job of removal all but impossible. For no advantage to you.<\/p>\n<p>And there&#8217;s no excuse to export to other countries what we wouldn&#8217;t put up with here.<\/p>\n<h3>The good bit: the data structure<\/h3>\n<p>There are genuine uses for blockchain-like databases \u2014 the append-only ledger, made cryptographically tamper-evident. We&#8217;ve had this data construct for decades, and it&#8217;s been very useful where it&#8217;s appropriate.<\/p>\n<p>It&#8217;s just like an accounting ledger that you can only add to, and not alter previous entries. If you want public assurance, you can distribute complete copies of the ledger for others to check over.<\/p>\n<p>If you do need to go and alter previous entries, it&#8217;s a huge faff\u00a0\u2014 you have to declare a <a href=\"https:\/\/en.wikipedia.org\/wiki\/Flag_day_(computing)\">flag day,<\/a> and say &#8220;here&#8217;s the new version, use this one&#8221;\u00a0\u2014 but it&#8217;s quite doable. (And really, you&#8217;d want it to be difficult, but not impossible.)<\/p>\n<p>As I say in <a href=\"https:\/\/davidgerard.co.uk\/blockchain\/business-bafflegab-but-on-the-blockchain\/\">chapter 11<\/a> of the book, there are things being sold as &#8220;blockchain&#8221; that are pretty much just the useful data structure. If these are popularised under the name &#8220;blockchain,&#8221; I can live with that.<\/p>\n<p>And then they&#8217;ll be known to people outside the programmers in your technology department \u2014 who almost certainly save their programs in one popular use case for this data structure, <a href=\"https:\/\/en.wikipedia.org\/wiki\/Git\">Git.<\/a><\/p>\n<p>When you&#8217;re looking into blockchain systems, bring along your most cynical system administrator. Get them to ask the salesperson lots of pointed questions.<\/p>\n<br><br><div align=\"center\"><p><a href=\"https:\/\/www.patreon.com\/bePatron?u=8420236\"><img src=\"https:\/\/davidgerard.co.uk\/blockchain\/wp-content\/uploads\/2021\/10\/become_a_patron_button.svg\" alt=\"Become a Patron!\" title=\"Become a Patron!\" width=217 height=51><\/a><br><p style=\"align:center;\" class=\"patreon-badge\"><i>Your subscriptions keep this site going. <a href=\"https:\/\/www.patreon.com\/bePatron?u=8420236\">Sign up today!<\/a><\/i><\/p><\/div>","protected":false},"excerpt":{"rendered":"<p>We&#8217;ve been reminded in the past week just how dangerous vast collections of personal data can be. They won&#8217;t be less dangerous on a blockchain.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[74,542,491,541,540,274],"class_list":["post-5740","post","type-post","status-publish","format-standard","hentry","category-uncategorised","tag-blockchain","tag-cambridge-analytica","tag-gdpr","tag-unhcr","tag-united-nations","tag-world-food-programme"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/posts\/5740","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/comments?post=5740"}],"version-history":[{"count":50,"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/posts\/5740\/revisions"}],"predecessor-version":[{"id":18750,"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/posts\/5740\/revisions\/18750"}],"wp:attachment":[{"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/media?parent=5740"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/categories?post=5740"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/tags?post=5740"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}