Post #4060081
2026-07-24 09:43 UTC
Replies (2)
-
@regen_studio@mastodon.social 2026-07-24 11:32
This, exactly. Privacy-by-design isn't a feature you add at the end, it's a line-zero architecture choice: what you never collect, you never have to protect, breach, or explain. We build everything this way and honestly it's simpler, not harder. Thanks for the reminder.
-
@joby@hachyderm.io 2026-07-24 19:43
@r_alb@mastodon.social Yup. I build web apps at a university and one of my central tenets over the years has always been "we can't accidentally leak what we don't have." Collecting RSVPs for an event, the form has fields for phone number and mailing address? Have we ever once used that information for anything? No? Gone from the form. Why were we even doing that? The list of graduates includes students with privacy flags on their accounts and the site filters them out at runtime? What happens if somebody breaks that someday? Now we've leaked the names of all these students who are hiding from stalkers or whatever. That's a disaster. Why not just delete those records from the database and filter them out during the import process entirely so our site cannot possibly even know they exist in the first place?