I would try reporting it to the company, maybe also the FBI or FTC, or if you aren't too comfortable contacting them, you can try also contacting someone like Brian Krebs who presumably knows who to contact about data leaks of this nature. (Krebs' contact form: https://krebsonsecurity.com/about/ )
Please do not ever communicate directly with anyone from a federal law enforcement agency. Only talk to them through an attorney. They are most definitely not on your side.
Ask HN: Found a leak of US citizens personal data. Should I report it?
31–40 of 85 posts
Re: Ask HN: Found a leak of US citizens personal data. Should I report it?
#32If it were me I'd honestly do nothing. History has shown it's equally likely to be a lose-lose scenario. Let it remain as-is. If it's related to protecting children or a vulnerable group, maybe report it. Otherwise, whatever. Either way, don't do it in a way that they know it was you who found it.
Re: Ask HN: Found a leak of US citizens personal data. Should I report it?
#33Earlier quoted context omitted.
Please do not ever communicate directly with anyone from a federal law enforcement agency. Only talk to them through an attorney. They are most definitely not on your side.
The guy is from Canada.
Re: Ask HN: Found a leak of US citizens personal data. Should I report it?
#34Earlier quoted context omitted.
Please do not ever communicate directly with anyone from a federal law enforcement agency. Only talk to them through an attorney. They are most definitely not on your side.
The guy is from Canada.
Re: Ask HN: Found a leak of US citizens personal data. Should I report it?
#35Earlier quoted context omitted.
The guy is from Canada.
I'm not really sure what your point is. Because they're Canadian, they can't make a call to the FBI? They're Canadian, so they should report to a Canadian authority about US Citizen data? They're Canadian, so they're funny and this is a joke?
Response was: Please do not ever communicate directly with anyone from a federal law enforcement agency. Only talk to them through an attorney. They are most definitely not on your side.
Then I wrote in response: The guy is from Canada.
So all three of your guesses are wrong. I'm stating that a Canadian has much less to worry about (compared to a US citizen) when contacting a US law enforcement agency about a compromise in the security of a US company that impacts multiple US states.
Re: Ask HN: Found a leak of US citizens personal data. Should I report it?
#36Re: Ask HN: Found a leak of US citizens personal data. Should I report it?
#37Re: Ask HN: Found a leak of US citizens personal data. Should I report it?
#38Do not under any circumstances report the leak with your actual identity. If you want to do so anonymously, go for it. However that said, there is no upside in you reporting the leak, only downside potential.
> there is no upside in you reporting the leak There is - not letting it be - raising awareness and contributing to prevention of a normalization of such things. If everyone would hold "let sleeping dogs lie"/"not my circus, not my monkeys" attitude it would gradually become a norm and this benefits no one (but possibly bad actors). However, exercising caution never hurts, so it shouldn't be a bad idea to reach out a…
It already is a norm. Companies and organizations leak data constantly and there are near zero repercussions. A best a tiny fine that's utterly irrelevant to their fiscal position. An hour of earnings.
Meanwhile individuals who are trying to do good more often than not are accused of hacking, blackmailing, CFAA violations, etc and may end up with serious individual repercussions, fines, fees, or jail.
It's absolutely not worth it on an individual basis. I cannot stress this enough.
Re: Ask HN: Found a leak of US citizens personal data. Should I report it?
#39Re: Ask HN: Found a leak of US citizens personal data. Should I report it?
#40Relevant personal anecdote from the EU: one time I was checking the API of a service I wanted to use and managed to obtain full access to the database which among bunch of PII also contained plaintext passwords. Being a good citizen, I decided to report the problem to national CERT instead of the company, because I had prior experience with such reports where the company reacted with a lawsuit threat. The response from CERT was "While your intents are noble, you just admitted to gaining unauthorized access and we will forward this information to the company if they decide to take legal action".
This was 2 years ago, luckily the company did not press charges, the data in question is still wide open for hacking and I could not care less anymore. Learned my lesson that there is no room for good Samaritans in web security.