Live data from Hacker News

Ask HN: Who really gives your personal info to Intelius, Instant Checkmate, etc?

news.ycombinator.com

71–80 of 256 posts

Re: Ask HN: Who really gives your personal info to Intelius, Instant Checkmate, etc?

#71

I saw a great talk by a private investigator at a security conference on this topic, and did some research after the talk to confirm what he was saying. The short version is what you're asking for is going to be an uphill battle. Data aggregation companies don't want to disclose their sources because their services are often used by debt collectors and other organizations who want to find people who don't want to be…

Do you happen to have a link to that talk, or the name of the presenter?

Re: Ask HN: Who really gives your personal info to Intelius, Instant Checkmate, etc?

#72

Have you ever gone to the doctor, signed up for a gym, or signed up for your local grocery store's membership rewards program? That's how they get your information.

I went to Pavilions grocery store the other day, and when I got home, the Facebook app said, "Have you been to Pavilions recently? Click here." I want Facebook to find friends and events nearby me, not track where I go.

I can only imagine all the location data Google, Apple and Facebook is collecting and what they're actually doing with it.

Re: Ask HN: Who really gives your personal info to Intelius, Instant Checkmate, etc?

#73
post #44

If anyone reading this thread is interested: I would pay non-trivial amounts of money on a regular basis for a service that systematically worked to eliminate records like these (and the sources they draw from), as well as chasing down sources of junk mail and the lists they ultimately draw from. The value would depend on effectiveness, and on the degree to which the service clearly reported exactly what they did. Ca…

I've considered working on this problem from a business standpoint, but I couldn't figure out a good business model for it. I don't think too many people will pay a monthly fee to have their information removed from these services. My guess is that they would sign up for a month and after their information has been removed, immediately cancel their subscription until they needed to do it again. And a yearly fee seeme…

It's possible that the business could be so successful that everyone uses it, the services selling this information all run out of customers and go out of business, none of them come up with newer and more evil ways to do this, and you run out of potential customers. In which case: mission accomplished, retire on your giant pile of money and bask in the knowledge that you made a far better place. (Avoid scenarios in which you have perverse incentives to allow the problem to continue.)

But in the meantime, tens of millions of potential customers times any reasonable fee seems more than enough to build a substantial business on.

You could tempt people in with a cheap fee to let them send in a few pictures of junk mail and stop those. (As you get more, find the biggest sources and automate or batch them so that they cost you almost nothing, which will pay for the higher-effort ones. Have an upper bound on effort expended, and tell people that they don't pay if you can't remove them.) You could then track down the underlying sources, and if you successfully identify them, contact the customer, and give them enough information to decide to pay you for a higher-end service to get them removed from those sources (and keep them removed).

The value that gets people to keep paying you would be a steady stream of reports of "we found this source leaking/selling your information, here's what we did about it". It'll take you years to track down all such sources and find paths to remove them; you will likely end up having to fund some legal work and possibly even a lawsuit or two, which will give you a giant pile of publicity.

(As one example of something much easier for a company optimized for the process to do than an individual: the USPS has a detailed process for formally putting a company on notice for mailing someone who has specifically unsubscribed, and that process ends in massive fines for continued mailing to that person. I read a report of someone doing that to stop receiving persistent Dell catalogs.)

If you're sufficiently creative, you could even pitch this as a service to marketing companies. You have a list of people who will not buy anything via direct mail, and who will despise any company that they receive such mail from. Convince the sources of postal spam that removing those people from their list makes the rest of their list more valuable. Convince the downstream customers of those sources that using your list directly is far more convenient for them than dealing with opt-outs from every individual on it.

That also gives people a continued incentive to pay to remain on that list.

Re: Ask HN: Who really gives your personal info to Intelius, Instant Checkmate, etc?

#74
post #44

If anyone reading this thread is interested: I would pay non-trivial amounts of money on a regular basis for a service that systematically worked to eliminate records like these (and the sources they draw from), as well as chasing down sources of junk mail and the lists they ultimately draw from. The value would depend on effectiveness, and on the degree to which the service clearly reported exactly what they did. Ca…

I've considered working on this problem from a business standpoint, but I couldn't figure out a good business model for it. I don't think too many people will pay a monthly fee to have their information removed from these services. My guess is that they would sign up for a month and after their information has been removed, immediately cancel their subscription until they needed to do it again. And a yearly fee seeme…

What about pay-per-record? If you identify 100 records? You could charge $50 (50 cents per record, as an example). Shows the value versus a blanket annual fee. The price-per-record could be reduced for the more records they have, or capped at $100 or something.

Re: Ask HN: Who really gives your personal info to Intelius, Instant Checkmate, etc?

#75

If anyone reading this thread is interested: I would pay non-trivial amounts of money on a regular basis for a service that systematically worked to eliminate records like these (and the sources they draw from), as well as chasing down sources of junk mail and the lists they ultimately draw from. The value would depend on effectiveness, and on the degree to which the service clearly reported exactly what they did. Ca…

I've come across sites like these (SafeShepherd, though it doesn't claim to wipe your information from the "sources", only the sites they see your information on); the problem is I'm not sure I would trust them with something like my driver's license photo. Would you? Or what if they decide to sell your information behind your back later? Edit: Maybe it was a different site that needed your license (I thought it was…

SafeShepherd seems like it's dying. They were active shortly after launch, but it's basically been radio silence ever since. I used to have an account with them, and I didn't find much value from them after the initial cleanup wave (they didn't seem to be keeping up with the new sites that came online).

Re: Ask HN: Who really gives your personal info to Intelius, Instant Checkmate, etc?

#76

Earlier quoted context omitted.

Correct - see http://www.crosspixel.net for example: "Cross Pixel's DMP is powered by our proprietary data relationships with more than 5,500 web sites and mobile apps where we identify and harvest the shopping and researching behaviors on over 650 million unique browsers. Our data partners are leading e-Commerce sites, search directories, comparison shopping engines, coupon sites and toolbars across North America an…

Great answer thanks! I hadn't heard the term DMP

BlueKai is one of the biggest; it's a data marketplace for cookie-tagged data. They were bought by Oracle a few years ago.

Re: Ask HN: Who really gives your personal info to Intelius, Instant Checkmate, etc?

#77
post #65

Earlier quoted context omitted.

That's surprising. So what happens when there is a high profile case and the court fears for the jurors' lives? Or the case itself involves someone whose life will be in danger afterwards? If anybody can find out where these people live then they're toast. The courts have to suppress the information legally somehow, right? If not the old information, at least they need some protection against mining of new informatio…

> So what happens when there is a high profile case and the court fears for the jurors' lives? Jurors' identities are not generally a secret.[0] There are exceptions, but those exceptions do not extend to wiping that person's data from things like pharmacy and gas station reward card databases. Honestly your entire premise shows a lack of understanding of how the criminal justice system works. > Are you literally say…

> Jurors' identities are not generally a secret.[0] There are exceptions

I was talking about the exceptions. If there are exceptions, a way to handle them must exist, is all I was saying.

> but those exceptions do not extend to wiping that person's data from things like pharmacy and gas station reward card databases.

I was asking about the companies who obtain this original information, not pharmacies' or gas stations' databases themselves. I feel like you're not understanding my question?

> Honestly your entire premise shows a lack of understanding of how the criminal justice system works.

Quiet likely (I'm not claiming otherwise; I'm not a lawyer and I haven't exactly been involved in legal proceedings) and I didn't claim otherwise. Also hardly undermines my point. Like I've said in some 3-4 other comments, someone who e.g. starts a new company like InstantCheckmate has to know whom to buy the data from -- like I said, there's no way all of these companies contact all grocery stores and all doctors. That's insane. Someone's gotta be doing the heavy lifting and making money off it. I'm asking who this is. I asked this in the original post. If the court example is wrong or otherwise bothers you just ignore it. If someone not already involved in the business knows to contact these companies to obtain information, someone must know who they are, is all I'm saying. Otherwise they would not exist.

Re: Ask HN: Who really gives your personal info to Intelius, Instant Checkmate, etc?

#78
post #42

Earlier quoted context omitted.

a court needs to control someone's information surely they know who these people are and they can let them know? I think you have a misunderstanding of what a US court can do. A court can only tell a specific party to take some action, and generally only if that party is somehow related to the legal action (such as being a defendant). Generally, there is no judgement that a court can make that can effect unnamed part…

What about this though: >> Or when someone wants to start another one of the higher-level companies -- how do they know which core aggregators to buy from? If that's a secret then how would they find out?

   > If that's a secret then how would they find out?
You don't. I've worked in data acquisition in the past, both buying data and selling it. Sometimes as the original source of truth and sometimes as a middleman that does data cleaning, standardization, appending (from other sources), then selling the derived product downstream.

Companies in that space guard their upstream sources quite heavily, because they don't want to be cut out of the process. You won't find a centralized list of independent data feeds and providers specifically because of that. In one scenario, we were dealing with a substantial rate increase from one supplier. We spent time attempting to source an alternate supplier of that particular type of data, and could only find sources that were several months more stale than we were currently getting (i.e. these people were getting the feed several hops after we were). In the end we paid the rate increase because we couldn't find an alternate source that was as close to the original data provider as our current source. And without knowing who the original data provider was, we couldn't go around our supplier.

The lack of a centralized directory isn't just done to make things opaque for end users, it's done to make things opaque for business competitors as well. It's an industry that's very, very reliant on networking and introductions.

Edited to add: You're also asking a lot of people in here to name specific companies even if they can't give you huge lists. This space is super heavy on NDAs (and trigger happy on enforcing them). If you've actually worked in it, there's simply no way you're able to name drop legally.

Re: Ask HN: Who really gives your personal info to Intelius, Instant Checkmate, etc?

#79
post #55

If you have your own domain name with a wildcard, it's really helpful to enter: someservice@mydomain.com as your email. That way if it leaks you'll know who did it and can setup much more robust rules to block. I'll use the domain name as the main address so I remember which name goes to which site. For physical address mailings, you can hyphenate (or use a middle name) as the service. So First Service-Last as the ad…

I've been doing exactly this for a while. Here is my list of companies that have leaked the email address I gave them to spammers: https://gist.github.com/eligrey/5084991

Re: Ask HN: Who really gives your personal info to Intelius, Instant Checkmate, etc?

#80
post #44

If anyone reading this thread is interested: I would pay non-trivial amounts of money on a regular basis for a service that systematically worked to eliminate records like these (and the sources they draw from), as well as chasing down sources of junk mail and the lists they ultimately draw from. The value would depend on effectiveness, and on the degree to which the service clearly reported exactly what they did. Ca…

I've considered working on this problem from a business standpoint, but I couldn't figure out a good business model for it. I don't think too many people will pay a monthly fee to have their information removed from these services. My guess is that they would sign up for a month and after their information has been removed, immediately cancel their subscription until they needed to do it again. And a yearly fee seeme…

Why not structure the company as a public benefit corporation or a non-profit?
Post reply on HN