State Of The Internet/Surveillance Economy/consentandidentity: Difference between revisions

Line 80: Line 80:
'''With whom might we work?'''<br />
'''With whom might we work?'''<br />


New startups working in the digital identity and tracking space. For example, InCountry (15m Series A), OneTrust ($200m at a $1.3bn valuation), TrustArc ($70m), Privitar ($40m), BigID ($80m+ Series B).
* New startups working in the digital identity and tracking space. For example, InCountry (15m Series A), OneTrust ($200m at a $1.3bn valuation), TrustArc ($70m), Privitar ($40m), BigID ($80m+ Series B).
* Progressive advocates in government and civil society, such as Mozilla Fellows like Karolina Iwańska (of the [https://en.panoptykon.org/ Panoptykon Foundation]), Fieke Jansen (of the [https://datajusticelab.org/ Data Justice Lab]), [https://anoukruhaak.com/ Anouk Ruhaak] (data governance and consent) and Richard Whitt ([https://glia.net/project GliaNet]), among others




'''How could we start?'''<br />
'''How could we start?'''<br />


* Build on our simple take on consent through the browser (drawing on the Global Consent Manager Add-on, the Identity Access Management project, and other password manager work) to understand more complex user needs and behaviors around identity and consent.  
These ideas incorporate feedback and builds from employees and community members at Mozilla's January 2020 All Hands.  


* How might we build “zero knowledge proof” algorithms to support user control of these identities and the data flow?  
* Build on our simple take on consent through the browser (drawing on the Global Consent Manager Add-on, the Identity Access Management project, other password manager work, and Fx Accounts) to understand more complex user needs and behaviors around identity, authentication, and consent, including ephemeral or pseudonymous IDs and the differences between 'trust me' and verifiable. What might we learn from the Emerging Markets team's work on phone call and SMS blocking?
 
* How might we build “zero knowledge proof” algorithms to support user control of these identities and the data flow? Check out the academic-led standards collaboration, [https://zkproof.org/ ZKProof] as well as Mozilla 'one per person' proposal.


* What might we build on from Mozilla’s Persona project?  
* What might we build on from Mozilla’s Persona project?  
Line 93: Line 96:
* Map identities to patterns of technology touch points to recognize segmentation.
* Map identities to patterns of technology touch points to recognize segmentation.


* How could we help people generate anonymous identifiers to use online, such as email addresses, phone numbers, and perhaps even credit cards?
* How could we help people generate anonymous identifiers to use online, such as email addresses, phone numbers, and perhaps even credit cards? If done at scale, would this promote even worse behavior from companies and people?
 
* Collaborate with digital media companies and progressive brands to understand how we might foster an advertising system that's not based on invasive profiling, ad fraud, and brand degradation. How might we work with publishers on better consent management platforms/CMPs? And perhaps also with opt-in ad providers, like Good Loop?
 
* Check out Global Public Inclusive Infrastructure’s work in the area of dynamic identities, which are very difficult in practice.
 
* How might Mozilla's [https://github.com/mozilla/blushproof project around improving private browsing] relate? 
 
* Understand and build on the online behaviour of teenagers. They often live and breath multiple identities online and offline.
 
* Review the years of discussion around 'intention casting' from [https://cyber.harvard.edu/projectvrm/Main_Page Project VRM]
 
* How can we move personally identifiable information away from server farms and back to local control?
 
Other observations from All Hands include: <br />
:“Mix up the steps. Create data storage and ownership. Provide a way to consent to transaction via a commons. Don't rely too heavily on the algorithms to start, make that and opt-in an add on later as a premium service?”
 
:“I think this is valuable at disrupting the cost of the data and making it available to startups. This disruption can kill the market of tracking across website as we can have quality and quantity.”
 
:“Identity is a word which those with privilege identify with. How do you diversify and stretch framing so it appeals to low agency groups too?”


* How can we move personally identifiable information away from server farms and back to local control?<br />


===Phase Two: Building Momentum: Collective Consent Manager===
===Phase Two: Building Momentum: Collective Consent Manager===
Line 160: Line 181:
* Legal firms or insurance providers.  
* Legal firms or insurance providers.  
* Startups in the digital consent space.  
* Startups in the digital consent space.  
* Mozilla Fellow Richard Whitt's work with [http://www.glia.net Glia.net's] decentralized ecosystem of digital trust




269

edits