Eden argues for a principle he calls "civic hygiene"—the practice of not building surveillance or data systems that *could* easily be repurposed by a hostile future government, even if the current government seems trustworthy. The concrete concern: a sexuality database might serve legitimate public health planning today but become a persecution tool under a different administration. He cites Bruce Schneier's framing and contrasts acceptable databases (vehicle ownership, hard to weaponize) against dangerous ones (religious belief registries, historically used for genocide). The piece treats this as a design principle, not a paranoia claim—build systems assuming adversarial future use, not ideal current intent. It's a 2013 post written in response to specific UK surveillance proposals (web filtering, ISP monitoring, NHS data selling). The actionable takeaway: infrastructure architects should refuse to build high-risk demographic registries regardless of stated benign purpose, because regime change is real and data doesn't disappear. Worth asking: how does this framework handle genuinely useful databases that *are* also genuinely dangerous, where the tradeoff isn't clear-cut?
reply