We've got to stop sending files to each other

2 days ago 4

Another day, another data breach.

the spreadsheet, initially shared in 2022, and thought to contain data related to a small number of applicants, had contained hidden data related to more than 18,000 people. 

ICO statement in response to 2022 MoD data breach

Why are people still sending files to each other? I remember having a stand-up argument a decade ago with a project manager who wanted us to email a completed Word template to him every day. He'd then spend hours merging the various documents together. He couldn't get his head around the collaborative document suite the company had purchased a licence for. I tried showing him that we could give specific people write-access to the document and they could edit it live. No more emailing back-and-forth.

It just didn't stick. It wasn't that he was ignorant about what computers could do, but his entire mental model was built around files. Discrete packets of data with a fixed metaphor from the real world.

Collaborative online documents don't have an easy analogue analogue. It is rare to see a dozen people scribbling on the same whiteboard or using the same typewriter keyboard.

Permissions are another things that aren't intuitive. The idea that only specific people can see something doesn't match our expectations of paper. Sure, anyone could grab a pen and deface it, that's why we have one person in charge of the "master copy".

Copy. What a hateful word.

The modern workforce shouldn't be flinging copies to each other. A copy is outdated the moment it is downloaded. A copy has no protection against illicit reading. A copy can never be revoked.

Data shouldn't live in a file on a laptop. It shouldn't be a single file on a network share. Data is a living beast. Data needs to live in a database - not an Excel file. Access should be granted for each according to their needs.

I see the same issue in the WeTransfer kerfuffle. Very Serious People saying it was intolerable that the untrusted 3rd party they were using to share Very Sensitive Information was going to read that information.

At which point you have to throw up your hands and ask why people are sending files to each other in the year of Our Lord 2025?!?!? If you have a sensitive file, use proper access controls. Or at least use a password so the FTP-as-a-service provider can't steal your IP.

And git! Don't get me started on git! The best minds of a generation stuck in a paradigm of downloading files to their local machine, making changes, then emailing git pushing them up to be approved? Madness!

Look, there are some times when you need a local copy. I want my own copy of my insurance documents - but that's not a living doc; it is an agreed artefact. Sure, it's handy to have access when there's no network connection - but that's what background sync is for. OK, you're on Office 365 and I'm on Google - so we'll have to work a little harder to set up access.

But all of this is possible!

We rant and rave about the 💾 icon being a skeuomorph. But the very concept of an individual file is also a skeuomorph! Data are not stored on paper files. There is no such thing as a filesystem directory - it's just a convention to make computing palatable for people born in the 20th century who lived in a world of A4 paper and manilla folders.

Modern computing is still stuck in the past. Our computers are like cars which have been designed to carry a bale of hay to mop up the horse-piss.

Read Entire Article