Privacy for the next billion because it is Overdue

[Music]

hi

person of interest so person of interest

is a science fiction

crime drama cereal that i have used to

be really hooked on to

you know it has at its center something

called the machine

it’s been programmed by this reclusive

brilliant billionaire called harold

finch

the machine is like the proverbial big

brother it knows

everything about everyone the machine is

used to solve

crime problems and terror

potential terrorist attacks and stuff

like that

i would in fact recommend that you watch

it if you haven’t already

now what if i told you that what was

portrayed

in person of interest is not really

science fiction but a reality

a reality that is several orders more

intrusive than what the machine already

was

and that there is not one single machine

but millions of them

big and small spread out over the world

and that you and i are a living

breathing part of this reality now that

would become a tad worrisome

wouldn’t it see anecdotally we already

know that whatever we do online is

is tracked processed recorded

analyzed and so on right we feel a bit

scooped

when we talk about going on a vacation

to goa while catching up over a cup of

coffee with a friend and then next thing

we start seeing

ads for um flights to goa and

hotels in goa for on all our online

fields

right but how does this really happen

let’s peep into one world which is a

world of apps

now an app typically talks to the phone

via

something called permissions permissions

are like the vehicle wire which

data is extracted by the app from the

phone

and certain activities on the phone are

kicked off by the app

okay i like to think of uh permissions

like the good old sipping straw that we

use

while drinking from a glass of juice you

know

it’s the the straw through which data

comes out

and it’s also the straw through which

you can you know blow bubbles into the

juice as well right through

kick off some activity in the form now

most permissions are required by the

uh app for the for the app to function

okay

some of these permissions however are

what are

called highly dangerous permissions and

why are they dangerous because of the

kind of data that they have access to

or the kind of activities that they can

kick off on the phone

can severely compromise the individual’s

privacy

for example accessing your camera

accessing your microphone

or taking reading all your sms’s or

taking a look at your calendar

or your contacts now that is something

which would be intrusive

right now the story doesn’t end with

permissions and spookiness

okay all apps also have something called

external sdks which are actually pieces

of code

that are embedded in the app to create

some kind of functionality

okay now mind you these belong to folks

who are different from your app maker

okay think of

sdks as those yummy chocolate chips that

are there in your favorite ice cream

they blend so well yet they give a

little added flavor to the ice cream as

well right

now the only sar bit in these

sdk stories is that they also

get access to all the sensitive data

that gets extracted via permissions by

the app in which they are embedded

okay and now and each of them further

processes

it and store you know shares it further

and then that gets worried some think of

the number of apps you have on your

phone right and this is just

the world of apps and folds but if you

think about it the reality

is that anything out there that is smart

or anything that is online is hungrily

sucking up data about you

every app every site you visit

every smart device that is scattered

around your house

you know your smart tv the smart speaker

even the smart

doll that your daughter probably

interacts with

um the smart car um you know the

traffic’s with

embedded iot on the road the garbage

cans your smart electricity meter

the shops that you walk past with the

sensors embedded in it

every single payment that you make

or using a card or whether it’s online

or offline

every time you scan your fingerprint

even when you’re say for example

visiting a friend in her apartment

complex right

in fact when you think about it you to

think

really hard about where your data is

not being collected today you know in my

head

um i picture this phenomena like a giant

invisible

vacuum cleaner that surrounds me sucking

up data about me

all the time okay

now often when i talk about this people

find it tough to believe you know the

common refrain is that oh is this really

happening in

india so let’s take a look at some data

uh you know my company does an annual

study of

the state of privacy of indian mobile

apps and websites

and the results of the study actually

never failed to stun me

every single year despite me being in

the privacy profession

you know the study essentially tells me

that the few apps that i have loaded on

my phone

to make my life simple are enough to

have or have all of me stand exposed

for example 71 percent of the apps

on my phone know exactly where i am at

every given point in time and no these

are not

the you know taxi healing apps or the

food delivery apps

my bank knows my wallet knows my music

app knows

my news app knows okay

um approximately six out of the ten apps

on my phone have access to my camera

half of them can read my contacts

half of them can record audio so what is

left

and if i say that i will avoid my phone

and let’s say just use the browser and

the web interface

life is not very different over there

for example

on an average indian website there are

22 external parties those locus like

those chocolate chips

which are embedded in a regular app you

know and i’m not talking social media

and all that

okay in fact i should share with you

something that i’ve

not really shared with anybody before um

you know five years ago i was building

this picture of myself

in the year 2025 um i’m of course

several kilos

lighter i finally get that

silver nose stud that i’ve been planning

for a while

uh just that it has smart sensors built

into it that tracks my

body’s parameters and sends them to my

dock

um i finally listen to my friends and

get myself a smart

pair of spectacles which also allow me

to

record some stuff that goes on in my

meetings

um i have this fancy car which senses my

mood every single time i board and based

on that plays me some music

at the same time checks my calendar and

decides the destination

and lets my driver know accordingly

meanwhile the fridge and the

cupboard in my home have figured out

what needs to be reordered and

have placed an order automatically with

my favorite online grocery vendor

right i mean it sounded fun five years

ago today

it’s a nightmare i’m furiously

backpedaling on that dream

and uh i don’t want to go anywhere near

there

okay but the big question is

so what so what if all this data about

you

is out there what happens to this data

well at the very least it is used to

track you

profile you and build very detailed

digital personas about you

which are then further traded and used

in real time auctions by various people

who does this well these are actually

huge interconnected networks of

advertisers data brokers

profilers analysts publishers and what

have you

basically thousands of companies all

interconnected into one

tight integrated ecosystem

believe me it’s a 227 billion dollar

industry worldwide today okay and

businesses pick this up to serve you

ads to suggest products to cater to your

preferences

and so on so that’s good isn’t

it maybe but it doesn’t stop with this

the same data is used to decide

for you what you see what you read

what you watch what you hear and so on

so the news that you see is often

different from the news that your

neighbor sees

because you have two different digital

personas or if you run a search the

results that you get

are different from the results that your

colleague gets

because you have two different digital

identities

so what happens as a result of this

again the question is so what what’s the

big deal right

over a period of time this all leads to

us living in what are called engineered

eco chambers

you know um have you ever wondered

for example why do you keep seeing feeds

from people who agree with you who have

opinions or beliefs which are similar to

yours

and you don’t hear from people who have

contradictory ideas so often

is because you live in that eco chamber

and you haven’t created that echo

chamber somebody else has created that

for you

right an extreme example of how this can

pan out was the whole cambridge analytic

scandal that happened you know where

entire elections were

engineered because of this ability

and mind you that happened five years

ago so imagine

how advanced and sophisticated we are in

today’s

world right the sad

reality is that today we as individuals

have completely completely

lost control over our data

in our delight of getting everything

free online we have missed the

fundamental point

that is that we have become the product

and not actually the product that we use

i’m going to say it again we have become

the product

just that instead of paying with cash

we are paying with our data to use

certain for free facilities online

that’s the only difference

okay but the only way

this can be controlled is by bringing in

laws and regulations and standards

and best practices across the entire

ecosystem

and where very sadly india

is really lagging behind

we are a country of over a billion

mobile phones

digital india is galloping ahead smart

cities smart governance digital payments

and whatnot

all of this is spewing for data that is

being

sucked up by that all-encompassing

vacuum cleaner around us

and this data is available for the

whole world to do whatever they feel

like with it

okay which is why we urgently

need our data protection and privacy law

okay you know when i when i talk of

privacy in india many people

counter it by saying oh privacy in india

is a joke

you know we are a country where we give

our entire life history to the strangers

sitting next to us

on the plane or bus or

train right but that is missing the

whole point

for the next 10 generations we’ll keep

sharing our life histories with the

stranger next to us on the planet

but while we are swapping life stories

you know the gadgets and the

surroundings around us are sucking up

our own

oh you know all our data and flashing it

out to the whole world to play around

with it

with us having no control over it that

my friends is the problem and

that is why it is beyond time

it is long overdue that the next

billion people start taking control

back over their most precious commodity

their personal data thank you

[Music]

[音乐]

,有兴趣的人,所以有兴趣的人

是一部科幻

犯罪剧麦片,我

曾经非常迷恋

你知道它的中心有一个

叫做机器

的东西,它是由这位

名叫哈罗德·芬奇的隐居的才华横溢的亿万富翁编程的

这台机器就像众所周知的

老大哥,它对

每个人都了如指掌,这台机器被

用来解决

犯罪问题和

潜在的恐怖袭击之类的事情

,如果你现在还没有,

我会建议你观看

,如果我告诉你的话 你说

,感兴趣的人所描绘的并不是真正的

科幻小说,而是

一个现实,一个

比机器已经存在的东西更具侵入性的现实,

并且没有一台机器,

而是数以百万计的机器

,大大小小的分散在 世界

,你和我

现在是这个现实的一个活生生的呼吸部分,这

将变得有点令人担忧,

难道不是我们已经知道的

轶事 既然我们在网上所做的任何事情都会

被跟踪处理记录

分析等等,

当我们谈到去

果阿度假时

和朋友一起喝杯咖啡然后接下来

我们开始看到

广告时,我们会觉得有点被挖走了 嗯,飞往果阿的航班和果

阿的酒店,在我们所有的在线

领域都是

正确的,但这是如何真正发生的,

让我们窥视一个世界,这是一个

应用程序的世界,

现在一个应用程序通常

通过

一种叫做权限的东西与手机通话

权限就像车辆

连接应用程序从手机中提取哪些数据,

手机上的某些活动

由应用程序启动

好吧,我喜欢考虑呃权限,

比如我们

在喝一杯果汁时使用的老式吸管,你

知道

这是 数据

出来

的吸管,它也是

你可以知道的吸管,你可以

通过

现在大多数权限的形式启动一些活动来将气泡吹入果汁中

uh 应用程序需要 uh 应用程序才能正常运行

这些权限中的一些权限是

所谓的高度危险权限,

为什么它们是危险的,

因为他们有权访问的数据

类型或他们可以进行的活动类型

开始打电话

可能会严重损害个人的

隐私

,例如访问您的相机

访问您的麦克风

或阅读您所有的短信

或查看您的日历

或您的联系人现在

这将是侵入性的事情

现在故事没有 以

权限和诡异结尾

好吧所有应用程序也有一些称为

外部 sdks 的东西,它们

实际上是嵌入在应用程序中以创建

某种功能的代码片段,

现在请注意,这些属于

与您的应用程序制造商不同

的人

sdks 作为

您最喜欢的冰淇淋中的那些美味巧克力片,

它们混合得很好,但它们又增加了

一点风味 现在也喜欢冰淇淋

它和你知道的商店进一步分享它

,然后让一些人担心

你手机上的应用程序数量

,这只是

应用程序和折叠的世界,但如果你

仔细想想,现实

是那里的任何东西 是智能的

或任何在线的东西都在

贪婪地收集关于你的数据

你访问的每个应用程序每个网站

你家中散落的每个智能设备

你知道你的智能电视智能扬声器

甚至

是你女儿可能

与智能

娃娃互动的智能娃娃 汽车 嗯,您知道

道路上

嵌入物联网的交通

垃圾桶 您的智能电表

您走过的商店,其中

嵌入了传感器

每次付款 每次扫描指纹时,您都会制作

或使用卡片,或者它是在线

还是离线,

即使您说,例如

在她的公寓大楼里拜访一位朋友

,事实上,当您考虑它时,您会

认真考虑您的数据在哪里

今天没有被收集,你知道在我的

脑海里,

嗯,我把这种现象想象成一个巨大的

隐形

真空吸尘器,它围绕着我,一直在

吸取关于我的数据,

好吧,

现在经常当我谈论这个时,人们

很难相信你知道

共同点 请记住,哦,这真的

发生在

印度吗?所以让我们来看看一些数据,

嗯,你知道我的公司每年都会

对印度移动

应用程序和

网站的隐私状况进行研究,研究结果实际上

从来没有让我感到震惊

每一年,尽管我

从事隐私行业,但

你知道这项研究基本上告诉我

,我在手机上加载的少数应用程序

让我的生活变得简单,足以

拥有或 h 例如,我是否所有人都暴露

在我的手机上,我手机上 71% 的应用程序都知道我在

每个给定时间点的确切位置,不,这些

不是你知道的出租车治疗应用程序或

我的银行知道的送餐应用程序我的钱包知道我的 音乐

应用知道

我的新闻应用知道

好吧 我手机上的十个应用中大约有六个

可以访问我的相机 其中

一半可以读取我的联系人

一半可以录制音频 所以

剩下的

还有如果我说我会避开我的 电话

,假设只是使用浏览器

,网络界面的

生活在那里并没有太大的不同

,例如

在一个普通的印度网站上,有

22 个外部方,这些位置就像

嵌入在你知道的常规应用程序中的巧克力片一样

,我是 不谈论社交媒体

好吧,事实上我应该和你分享

一些我

之前没有真正与任何人分享过的东西,

你知道五年前我在 2025 年建立

自己的这张照片,

嗯,我

当然是 体重减轻了 1

公斤 我终于得到

了我已经计划

了一段时间的

银色鼻钉

一副智能

眼镜,它还可以让我

记录一些在我的会议中发生的事情

嗯,我有这辆漂亮的汽车,

每次我登车时都能感觉到我的心情,并

在此基础上播放一些音乐

,同时检查我的日历和

决定目的地

并让我的司机相应地知道

同时我家的冰箱和

橱柜已经

弄清楚需要重新订购的东西并

自动向

我最喜欢的在线杂货供应商下订单

我的意思是五年前听起来很有趣

今天

它是一个 噩梦,我正在疯狂地

倒退那个梦想

,呃,我不想去那里附近的任何地方

好吧,但最大的问题

是,如果所有关于你的数据

都在那里怎么办? 至少不会很好地处理这些数据

,它用于

跟踪您的

个人资料并建立

关于您的非常详细的数字角色

,然后进一步交易

并由做得很好的各种人在实时拍卖中使用

这些实际上是

巨大的互连网络

广告商 数据经纪人

分析员 分析师 出版商和你

有什么

基本上成千上万的公司都

互连成一个

紧密集成的生态系统

相信我,今天这是一个全球价值 2270 亿美元

的行业

依此类推,这很好,不是

吗,但它并不止于此。

相同的数据用于

为您决定您看到什么您阅读

什么您看到您听到什么等等,

所以您看到的新闻是 通常

与您的邻居看到的新闻不同,

因为您有两个不同的数字

角色,或者如果您运行搜索

,您得到的结果

是不同的 nt 从你的同事得到的结果中

得到,

因为你有两个不同的数字

身份,

所以这又会发生什么

问题是,

在一段时间内有什么大不了的,这一切都导致

我们生活在所谓的工程中

你知道的生态室你有没有想过

,例如,为什么你总是看到

那些同意你的人的提要,他们的

观点或信仰与你相似,

而你却没有听到那些经常有矛盾想法的人的消息,这

是因为你 住在那个生态室里

,你还没有创造那个回声

室,别人已经为你创造了一个

对你来说

正确的极端例子,那

就是发生的整个剑桥分析

丑闻,你知道

整个选举是在哪里

设计的,因为这种能力

请注意五年前发生的事情

,想象

一下我们在当今世界是多么先进和复杂

,可悲的

现实是,今天我们作为个人 我们

已经完全

失去了对我们数据的控制,因为

我们很高兴

在线上免费提供所有东西我们错过了

基本点

,即我们已经成为产品,

而不是我们使用的产品

该产品

不是用现金支付,而是

用我们的数据支付以使用

某些免费的在线设施

,这是唯一的区别,

唯一可以控制的方法是在整个系统中引入

法律法规、标准

和最佳实践

生态系统

和非常可悲的是,印度

确实落后了

我们是一个拥有超过 10 亿

部手机的国家

数字印度正在飞速前进 智能

城市 智能治理 数字支付

等等

所有这些都在喷涌而出,这些数据正在

被无所不包的事物所吸收

我们周围的真空吸尘器

,这些数据可供

全世界

使用,

可以随心所欲,这就是我们迫切需要 我

需要我们的数据保护和隐私法,

好吧,当我

在印度谈论隐私时,很多人

反驳说,哦,印度的隐私

是个笑话,

你知道我们是一个国家,我们将

整个生活历史都交给了坐在那儿的陌生人

在我们

旁边的飞机、公共汽车或

火车上,但

对于接下来的 10

代人来说,这已经失去了意义 小工具和

我们周围的环境正在吸收

我们自己的

哦,你知道我们所有的数据,并将其

闪现到全世界

,让我们无法控制它,

我的朋友是问题所在,

这就是它超越的原因

早就该下一个

十亿人开始

控制他们最宝贵的商品

他们的个人数据谢谢

[音乐]