Every other week we hear about the latest database that has been hacked, leaking our email addresses, our phone number, our home address and more. There’s hardly a person on the planet who uses software online that hasn’t had some of their data leaked.
Crank calls, offers to sell crypto, cold emails from unscrupulous actors. Just out there for anyone to share. And all we can do is shrug.
HOW ARE WE OK WITH THIS?
Encryption technology is a mature field at this point. Every major software environment ships with advanced tools to encrypt data. Large companies who don’t sell fruit have forged a path as stewards of data, unlike other companies who have acted as data brokers, and we have collectively conceded a false truth: we don't care.
The first question anyone should ask of their software vendor is: how is it encrypted?
In the sorry absence of that question, every software vendor should ask themselves: do I want this data?
Unless it’s absolutely paramount to have access, the answer should always be no.
A weaker version of "encrypt everything" can also be: "separate everything" so that no customer data is mixed, and the attack surface for any customer is limited to just that customer.