Live data from Hacker News

Ask HN: Found a leak of US citizens personal data. Should I report it?

news.ycombinator.com

31–40 of 85 posts

Re: Ask HN: Found a leak of US citizens personal data. Should I report it?

#31

I would try reporting it to the company, maybe also the FBI or FTC, or if you aren't too comfortable contacting them, you can try also contacting someone like Brian Krebs who presumably knows who to contact about data leaks of this nature. (Krebs' contact form: https://krebsonsecurity.com/about/ )

Please do not ever communicate directly with anyone from a federal law enforcement agency. Only talk to them through an attorney. They are most definitely not on your side.

The guy is from Canada.

Re: Ask HN: Found a leak of US citizens personal data. Should I report it?

#32

If it were me I'd honestly do nothing. History has shown it's equally likely to be a lose-lose scenario. Let it remain as-is. If it's related to protecting children or a vulnerable group, maybe report it. Otherwise, whatever. Either way, don't do it in a way that they know it was you who found it.

Isn’t any group “vulnerable”? What does that word even mean?

Re: Ask HN: Found a leak of US citizens personal data. Should I report it?

#33

Earlier quoted context omitted.

Please do not ever communicate directly with anyone from a federal law enforcement agency. Only talk to them through an attorney. They are most definitely not on your side.

The guy is from Canada.

I'm not really sure what your point is. Because they're Canadian, they can't make a call to the FBI? They're Canadian, so they should report to a Canadian authority about US Citizen data? They're Canadian, so they're funny and this is a joke?

Re: Ask HN: Found a leak of US citizens personal data. Should I report it?

#34

Earlier quoted context omitted.

Please do not ever communicate directly with anyone from a federal law enforcement agency. Only talk to them through an attorney. They are most definitely not on your side.

The guy is from Canada.

Very my doubt that's going to stop US law enforcement. They go after people all over the world. And if they really want you and your country has an extradition treaty it tends to favour the US side.

Re: Ask HN: Found a leak of US citizens personal data. Should I report it?

#35

Earlier quoted context omitted.

The guy is from Canada.

I'm not really sure what your point is. Because they're Canadian, they can't make a call to the FBI? They're Canadian, so they should report to a Canadian authority about US Citizen data? They're Canadian, so they're funny and this is a joke?

First I wrote: I would try reporting it to the company, maybe also the FBI or FTC

Response was: Please do not ever communicate directly with anyone from a federal law enforcement agency. Only talk to them through an attorney. They are most definitely not on your side.

Then I wrote in response: The guy is from Canada.

So all three of your guesses are wrong. I'm stating that a Canadian has much less to worry about (compared to a US citizen) when contacting a US law enforcement agency about a compromise in the security of a US company that impacts multiple US states.

Re: Ask HN: Found a leak of US citizens personal data. Should I report it?

#37
Do nothing. If you or someone contacts law enforcement, you will be hounded for the rest of your life if you are lucky, if unlucky you will go to prison. You seem like a morally upright person, so selling or leaking the data is also not an option. You are not responsible for the incentives created by the justice system, and inaction in the face of justice system incentives is not morally wrong.

Re: Ask HN: Found a leak of US citizens personal data. Should I report it?

#38

Do not under any circumstances report the leak with your actual identity. If you want to do so anonymously, go for it. However that said, there is no upside in you reporting the leak, only downside potential.

> there is no upside in you reporting the leak There is - not letting it be - raising awareness and contributing to prevention of a normalization of such things. If everyone would hold "let sleeping dogs lie"/"not my circus, not my monkeys" attitude it would gradually become a norm and this benefits no one (but possibly bad actors). However, exercising caution never hurts, so it shouldn't be a bad idea to reach out a…

> it would gradually become a norm

It already is a norm. Companies and organizations leak data constantly and there are near zero repercussions. A best a tiny fine that's utterly irrelevant to their fiscal position. An hour of earnings.

Meanwhile individuals who are trying to do good more often than not are accused of hacking, blackmailing, CFAA violations, etc and may end up with serious individual repercussions, fines, fees, or jail.

It's absolutely not worth it on an individual basis. I cannot stress this enough.

Re: Ask HN: Found a leak of US citizens personal data. Should I report it?

#39
The replies to this post are almost universally depressing. Really? Reporting to the company is so obviously bad for the reporter in the USA? There is no protection from malicious prosecution just for 'reporting' a data breach. That's crazy.

Re: Ask HN: Found a leak of US citizens personal data. Should I report it?

#40
The fact is that you gained unauthorized access to personal information, which might be a criminal offence in your jurisdiction despite your honorable intentions. My advice is to let it go and not implicate yourself any further.

Relevant personal anecdote from the EU: one time I was checking the API of a service I wanted to use and managed to obtain full access to the database which among bunch of PII also contained plaintext passwords. Being a good citizen, I decided to report the problem to national CERT instead of the company, because I had prior experience with such reports where the company reacted with a lawsuit threat. The response from CERT was "While your intents are noble, you just admitted to gaining unauthorized access and we will forward this information to the company if they decide to take legal action".

This was 2 years ago, luckily the company did not press charges, the data in question is still wide open for hacking and I could not care less anymore. Learned my lesson that there is no room for good Samaritans in web security.

Post reply on HN