Under FCRA, your employer or potential employer must get permission from you before performing any credit report (which includes a salary report).
>You must give your consent for reports to be provided to employers. A consumer reporting agency may not give out information about you to your employer, or a potential employer, without your written consent given to the employer. Written consent generally is not required in the trucking industry. For more information, go to www.ftc.gov/credit.
It's an indicator that the market needs to be more discerning about consumer needs. There is a lot of dry powder waiting to be deployed in the VC industry, so expect to see more specious stuff get funded until LPs decide that they can generate returns elsewhere.
>Within the new European GDPR framework, IP addresses are to be considered as personally identifiable information,...
My understanding is that many of these details are yet to be settled with GDPR. The case referenced above was not interpreted under GDPR, which has yet to take effect. The definitions of personally identifiable data data rather vague, and precedent has not been set. A quick search showed conflicting opinions, but one perspective to consider is quoted below:
> In addition, businesses should note that Recital 26 to the recently adopted EU General Data Protection Regulation ("GDPR") states that the test for whether a person is "identifiable" (considered in detail above) depends upon "all the means reasonably likely to be used" to identify that person. The CJEU in Breyer did not directly consider the issue of likelihood of identification. If the BRD was not reasonably likely attempt to identify Mr Breyer from his IP address, this could potentially give rise to a different analysis under the GDPR. Consequently, it may be necessary for the CJEU to revisit this issue after enforcement of the GDPR begins on 25 May 2018.
This is a few years old, so if you know of some new decision or regulation that clarifies it would be great to know!
The GDPR does not provide a list of data types that are considered personal or not personal, instead it uses a definition which states what criteria need to be met for data to be personal and gives a list of relevant categories, which explicitly includes "online identifiers":
Now, you could of course argue that often it's not possible to infer the identity of a person given an IP address (e.g. because it is a dynamically allocated IP address by an ISP or an IP address of a proxy server through which many users connect to the Internet) and therefore store it, it would be very hard to impossible though (IMHO) to ascertain that none of the IP addresses which you store could be used to identify a specific person (what e.g. if there are 5 % static IPs in your data?). This in turn would make treating all of your IPs as non-personal data a risky business to say the least, as there will almost certainly be a way to identify at least some of your users from their IP addresses. The fact that you don't know about a particular way of doing this identification is not relevant for this.
My advice: If you do not use a very robust method for making sure that all the IPs you store are non-identifiable I would recommend not storing them at all (or at least truncating them to 24 bits, which does also not always eliminate deanonymization risk though).
While unlikely a factor in this case, I wouldn't be so quick to trust National Geographic as it is a for-profit company owned by 21st Century Fox (of Fox News fame). Its credibility shouldn't be categorized on equal footing as Nature.
I love the idea of zero-knowledge password proofs. Others can chime in on the approach you've proposed, but I have a more practical concern about developing critical mass.
How do you break through the chicken and egg problem of not enough users using or not enough browsers supporting this capability?
Browsers that support the password-nonce argument sign as I described. Browsers that don't support it pass through the password and the server performs the ZKPP key generation (this is no worse than the current system of hashing passwords). So servers can implement this immediately without worrying about breaking in non-supporting browsers.
After adoption by a few major sites, browsers can add a warning that the server didn't send a password nonce and the password will be passed to the server so the user has to click "Okay" before it gets submitted. This can be escalated to more severe messages to pressure more sites to comply.
Right, but it's more than electric money. The OP mentions it's electric money that:
1) has assured/immutable transactions (unlike CCs) - This may or may not be a good thing from a purchaser perspective on seller fraud.
2) is available to all individuals (unlike banks) - Again, which may or may not be a good thing if you're worried about money from/to the grey/black market.
This is a good list of inputs, though I think immutable public timestamps is the only one that was impossible pre-blockchain, and it's not clear what the value of this is.
I'd argue that the rest of them were not impossible before blockchain. From my perspective blockchain just makes these easier/cheaper.
>I've also never had a full-time job as I jumped straight from my BS to a PhD.
Not having any work experience means you'll go through "University Recruiting" (vs experienced hire) recruiting channels at any large company. This gives you tremendous freedom to explore a variety of careers as employers will only be able to judge you by your academic credentials and you won't be pigeon-holed by your professional experience. Use this to your advantage and explore as many careers & companies as possible.
Your internship will be your first professional anchor point so choose wisely - you may consider starting with a broader, more general software engineering experience before specializing to keep your options open.
>You must give your consent for reports to be provided to employers. A consumer reporting agency may not give out information about you to your employer, or a potential employer, without your written consent given to the employer. Written consent generally is not required in the trucking industry. For more information, go to www.ftc.gov/credit.
https://www.consumer.ftc.gov/articles/pdf-0096-fair-credit-r...