Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> But in an era where every major company database (Facebook, Equifax are front of mind) has been leaked and government organizations are frequently compromised (SolarWinds most notable) I can't help but find some solace that hardened blockchains and clients, and developers who follow stringent procedures, will lead us to more widespread technological stability.

Can you elaborate a bit on this? It reads to me like blockchain will reduce problems of big tech data leaks, but I'm not following how. Or did you mean something else?



Sure, thanks for asking. My reasoning follows a few paths in parallel:

* Distributed data storage like IPFS, built on open source software, should reduce (not eliminate) the number of vulnerabilities to large datasets. Code can be openly audited by many contributors in a way that commercial organizations can't quite support. Minor mistakes are more likely to be caught upstream, reducing the number of possible exploit chains.

* Data ownership, sovereignty, and portability are much more possible in web3 than they have been historically. By reducing friction for no-code users to own, store locally, and selectively grant access to their data, we increase the collective resilience and integrity of data at scale.

* Evolving the incentive layer, whether for open source contributors, or for end users allowing access to data, increases adoption, which encourages a virtuous cycle. Network effects should eventually compound.

* Immediate financial penalties for failure increase the likelihood that application developers and platform operators will prioritize security; historically, security budgets are subject to organizational politics (source: former pentester / digital forensics for 5+ years, many colleagues in the space, much public commentary).

TL;DR transparency decreases vulnerabilities, distributed user data ownership decreases attack surface, incentives increase adoption of these patterns, penalties increase operator diligence.

For instance... I've never again made a mistake like I did in 2017.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: