Your data is showing.
Agree?
There is an increased focus on privacy of
consumer data.
IronCore | @cipher_sift
Why?
IronCore | @cipher_sift
Breach
Regulation
Decentralization
Madison
Kerndt
Software Engineer,
IronCore Labs
IronCore | @cipher_sift
1 Current state of privacy
(or lack there of)
Breach
Regulation
Decentralization
Data proliferates.
IronCore | @cipher_sift
Breach
Regulation
Decentralization
Spent millions on security
Equifax
High complexity:
new, legacy, & acquired systems
30 chances to stop the breach
Equifax failed to implement an
adequate security program to
protect sensitive data. As a
result, Equifax allowed one of
the largest data breaches in
U.S. history.
Such a breach was entirely
preventable.
“
IronCore | @cipher_sift
@ironcorelabs
Microsoft Bing access to
every user’s list of friends
Facebook claims it doesn’t sell your data — But Facebook GAVE
Netflix & Spotify access to all
users’ private messages
Amazon access to user
contact information
Equifax failed to implement an
adequate security program to
protect sensitive data. As a
result, Equifax allowed one of
the largest data breaches in
U.S. history.
Such a breach was entirely
preventable.
“Considered partners
“extensions of itself” —
not third-parties for
privacy policy
Yahoo access to posts &
friends’ posts
Similar deals with Apple &
Google*
IronCore | @cipher_sift
Facebook stops using GPS
Facebook claims you can opt out of location tracking — but not really.
Instead uses your IP to
geolocate you
You can’t disable location-
based ads
IronCore | @cipher_sift
Companies are irresponsible with data &
undermine consumer trust.
Global public & regulatory backlash.
to
IronCore | @cipher_sift
We are the collateral damage.
IronCore | @cipher_sift
Breach
Regulation
Decentralization
Global privacy laws.
Breach
Regulation
Decentralization
Decentralization of authority
Blockchain technology is part of the backlash — born out of the ethos of…
Reconstruction of behavior
Blockchain gives you the
actual power to affect
change in the world.
“
What we are trying to stop is
simple. We are trying to stop
the abuse of power.
“
Lauri Love
Hacktivist
Vinay Gupta
Mattereum CEO
Freedom of information
IronCore | @cipher_sift
2 Implications on the
software you build
Analyze
Architect
Implement
Analyze
Architect
Implement
Be honest
what data does your software hold?
IronCore | @cipher_sift
Username
Data covered by GDPR & CCPA
Email
IP Addresses
Location
Address
Health
Financials
Sexual orientation
Any
user generated
content
IronCore | @cipher_sift
Analyze
Architect
Implement
GDPR Article 25
Data protection by design & by default.
IronCore | @cipher_sift
Minimization.
IronCore | @cipher_sift
Document
Document your processes to show that you
designed with security and privacy in mind.
IronCore | @cipher_sift
GDPR Article 32
Security of processing.
IronCore | @cipher_sift
Pseudonymisation.
IronCore | @cipher_sift
Weather Channel turns on
location data
Package up data and sell
It’s not right to have consumers
kept in the dark about how
their data is sold and shared
and then leave them unable to
do anything about it.
“
Ron Wyden
Senator of OR.
Trivial to re-identify
Easily reversible deidentified data for sale
IronCore | @cipher_sift
Encryption.
IronCore | @cipher_sift
Analyze
Architect
Implement
Three patterns — how to encrypt sensitive data
1. Server-side proxy
2. Server side application
3. Client-side encryption
IronCore | @cipher_sift
Server-side proxy
{
ACL
Audit
Encryption

Proxy
Application
File Store
IronCore | @cipher_sift
Server-side application
{
ACL
Audit
Application
Encryption

Service
File Store
IronCore | @cipher_sift
Client-side application
{
ACL
Audit
Encryption

Service
Application
Encryption

Service
IronCore | @cipher_sift
Billing 

Service
No access to plaintext even
with access to database
Unavoidable point of access control & logging
Audit for every access
Critically important for
regulatory compliance
{
ACL
Audit
Encryption

Service
IronCore | @cipher_sift
Analyze
Architect
Implement
4 Demo!
GDPR Article 17
Right to erasure.
IronCore | @cipher_sift
Backup solutions that support
GDPR erasure
Backup products with built in GDPR features
IronCore | @cipher_sift
Controlled and audited
access to backups
GDPR Article 7
Conditions for consent.
IronCore | @cipher_sift
Granular consent
Tools to manage granular consent
Tracks legal right to have data
Tracks consent for updates to
privacy policy, retention
periods, and who data is
shared with
IronCore | @cipher_sift
3 Conclusion
Thanks for
being here.
February 7, 2019
Denver, CO
Your data is showing.
IRONCORE LABS
IRONCORELABS.COM | @IRONCORELABS

Your data is showing