Live data from Hacker News

Ask HN: Who really gives your personal info to Intelius, Instant Checkmate, etc?

news.ycombinator.com

201–210 of 256 posts

Re: Ask HN: Who really gives your personal info to Intelius, Instant Checkmate, etc?

#201

Earlier quoted context omitted.

Temporary postal mail forewards. USPS NCOA (Change of Address) file is another major data source. https://www.forbes.com/sites/adamtanner/2013/07/08/how-the-p...

Thanks for the tip, from the link: "There is, however, a loophole that keeps data brokers from accessing your updated address. When you fill out the online form to change an address, you can indicate a temporary change that provides six months of forwarding that can then be extended for another six months. That information, unlike the changes marked as permanent, is not included in the master list sold to data broker…

Correct.

(I've mentioned the temporary forwards tip elsewhere in the thread myself.)

Re: Ask HN: Who really gives your personal info to Intelius, Instant Checkmate, etc?

#202
post #65

Earlier quoted context omitted.

> So what happens when there is a high profile case and the court fears for the jurors' lives? Jurors' identities are not generally a secret.[0] There are exceptions, but those exceptions do not extend to wiping that person's data from things like pharmacy and gas station reward card databases. Honestly your entire premise shows a lack of understanding of how the criminal justice system works. > Are you literally say…

What if I told you there are countries where you can use a credit card, and still have reasonable expectations about privacy, where the information gatherer must erase personal information on demand and bears the burden of erasing it and notifying everyone they sold the information to erase it too?

id like to know which ones? id consider relocating.

Re: Ask HN: Who really gives your personal info to Intelius, Instant Checkmate, etc?

#203
post #173
post #152

Earlier quoted context omitted.

I just started doing the wildcard domain thing last month, I'm happier knowing that I can shut the taps. I get annoyed just knowing that there's spam in my spam list. First time I was on the phone with a customer service rep. after using the @ .com format I was asked if i was sure my email address was correct. I lol'ed and told them not to worry about it.

I use random 20 char string for the local part. That way there's no question about the leak. Spammers use a lot of dictionary words in the local part of the email address, so it's better to have a random string. If you're using password manager anyway, there's no reason not to make email/username random too. For smaller e-shops you might find some with actively exploited 0days this way. I did.

That is useful, but how do you manage to remember the mappings? I want to know what random string corresponds to what service without having to search my password manager.

The best of both worlds would be random local part + a Chrome extension that manages the mappings. The Chrome extension can then replace the local part in Google Inbox with the corresponding site name.

Re: Ask HN: Who really gives your personal info to Intelius, Instant Checkmate, etc?

#204
Information acquired from a number of sources, including working in the data industry (a decade or two back), privacy advocacy, working in Web space, research of my own, stories over beers, legal experiences, etc.

There's a large information-brokerage industry. If you want to find it, investigating the question from the consumption side (as in: who will sell me this information) should turn up the larger players, most of whom are already listed in this thread. https://news.ycombinator.com/item?id=13804795

The big players are much of the business: Power laws work here as anywhere else, and heading off the larger sources is pretty effective.

The value of individual data isn't all that great. Which leads to one of the major PITAs of this industry: there's a lot of invalid, false, or stale data around. The incentives to fix it simply don't exist.

The now-defunct Internet Junkbuster used to have a print-your-own set of letter templates which could be sent to various marketing organisations. Doing that in the early 2000s dropped my own junk-mail volumes tremendously, and for years afterward. I suspect SafeShepherd operates somewhat similarly. Finding and hitting the direct marketing association(s) was a big part of that.

Putting a fraud hold on your credit reports (TansUnion, EquiFax, Experian) is useful.

Any account-based activities or activities in which you are specifically identified are fodder for capture. Credit cards, checks (Luddite! ... hang in there), "loyalty" cards. Gyms and pizza, as noted.

Facebook, which should go without saying. LinkedIn profiles.

Any online information service which has ever been hacked. (For safety, assume all of them.)

Online purchases. Through both the marketplace and your credit card.

Court and other public records are manually reviewed and entered.

Various school and alumni associations. Organisations such as Classmates.com, MyLife, etc., front-ended to skip-tracing and similar organisations (info via direct communications).

Your auto smog testing station. There's an outfit known as ISO, Insurance Services Office, who has a unit that tracks down odometer mileage data. They glean that by buying the state smog check data, which is indexed by VIN and drivers license in mose cases. The notion is that miles driven is an excellent proxy for insurance risk. https://en.m.wikipedia.org/wiki/Insurance_Services_Office

The US Post Office NCOA (change of address) form, as noted. File a temporary COA to avoid getting listed.

Used to be you could submit a "pornographic materials" request to the USPO to have circulars and such removed from your delivery. Though online sources suggest it's possible to block 3rd class mail (Yahoo answers). That's more an annoyance than privacy issue.

Magazine subscriptions.

Request of any organisations you do business that they not share your information. Use telltales to determine which do (additions to your address, name, etc.).

And, if the state of affairs bothers you, get on your government representatives to do something about it. Data are liability, and there's far too much of it floating around. The US in particular has taken an exceptionally piecemeal approach to the problem (video store rental records are protected, bookstore and pharmacy records are not).

Request comprehensive data privacy regulations, with teeth.

Re: Ask HN: Who really gives your personal info to Intelius, Instant Checkmate, etc?

#205
post #130
post #44

Earlier quoted context omitted.

I've considered working on this problem from a business standpoint, but I couldn't figure out a good business model for it. I don't think too many people will pay a monthly fee to have their information removed from these services. My guess is that they would sign up for a month and after their information has been removed, immediately cancel their subscription until they needed to do it again. And a yearly fee seeme…

What about a better business idea. Accept cryptocurrency to shut down these aggregating and re-selling services. Physically, by any means necessary. ANY.

Obligatory reference to https://cryptome.org/ap.htm

Re: Ask HN: Who really gives your personal info to Intelius, Instant Checkmate, etc?

#206

I've had the misfortune to be present for an in-person demo of a verification service nearly a decade ago. It involved those relationship questions ("Which one of the following people have you not lived with in the last 5 years?") that are incredibly creepy. I was shocked that they had so much data on me -- I have no debt, no credit cards, no house, no car, no bills, and I had always entered informal rent agreements…

Do we forget that not long ago everyone's name, address, and phone number was published in the phone book (unless you paid extra for an unlisted number), and hospital admissions were published in the daily newspaper. It used to be unremarkable, and now people shriek "privacy!!" when it's discovered that some mundane detail about their life is not a closely held secret.

The phonebook was a paper-based system, with significant costs to look up and act on information at scale. You needed the books, the researchers, and the time to find and act on specific numbers.

The numbers weren't widely cross-referenced across multiple other identifier databases: shopping, driving, voting, location to 1m accuracy and 30s time precision.

Every household, small business, mafioso, or political operative didn't have a full copy of the archive, and the ability to deploy it at a moment's notice.

Or in short: scale and costs matter. In fact they dominate all other effects.

Your objection is both meaningless and betrays a profound failure of undrestanding and sympathy.

Re: Ask HN: Who really gives your personal info to Intelius, Instant Checkmate, etc?

#207

If anyone reading this thread is interested: I would pay non-trivial amounts of money on a regular basis for a service that systematically worked to eliminate records like these (and the sources they draw from), as well as chasing down sources of junk mail and the lists they ultimately draw from. The value would depend on effectiveness, and on the degree to which the service clearly reported exactly what they did. Ca…

> junk mail

Back in the day, junk mail often had "Return Service Requested", and senders had to pay return postage. So we would tape address labels to cardboard-wrapped bricks, and mark them as "moved with no forwarding address". But that doesn't work anymore.

Re: Ask HN: Who really gives your personal info to Intelius, Instant Checkmate, etc?

#208

Earlier quoted context omitted.

It's possible that the business could be so successful that everyone uses it, the services selling this information all run out of customers and go out of business, none of them come up with newer and more evil ways to do this, and you run out of potential customers. In which case: mission accomplished , retire on your giant pile of money and bask in the knowledge that you made a far better place. (Avoid scenarios in…

>the USPS has a detailed process for formally putting a company on notice for mailing someone who has specifically unsubscribed, and that process ends in massive fines for continued mailing to that person. I read a report of someone doing that to stop receiving persistent Dell catalogs.) I would love to learn this process! I've repeatedly asked for a certain mailing to stop and it hasn't ceased.

You want a USPS form 1500 (https://about.usps.com/forms/ps1500.pdf). The intended use is for reporting obscene mail but the decision about whether something is objectionable is left up to the addressee (Rowan v. United States Post Office Department - https://www.law.cornell.edu/supremecourt/text/397/728).

Re: Ask HN: Who really gives your personal info to Intelius, Instant Checkmate, etc?

#209

Earlier quoted context omitted.

Do we forget that not long ago everyone's name, address, and phone number was published in the phone book (unless you paid extra for an unlisted number), and hospital admissions were published in the daily newspaper. It used to be unremarkable, and now people shriek "privacy!!" when it's discovered that some mundane detail about their life is not a closely held secret.

No we don't forget. Those systems were analog and could only be scaled to a certain extent, after which you ran into management overhead. So in the example given by the OP, dominoes would not be updating your name in the directory. That would be data that evaporated and never made it to record. To increase the contrast - whole new types of clustering and analysis are now possible, at the moment a new data point is re…

i once worked on a project (about 15 years ago) where we had access to a reverse phone book listing that was generated in part by having a copy of every distinct paper phonebook in the US (also things like school directories) sent overseas to be hand entered (2-3 times for QC). A "nice" feature of it was that the address info was also geocoded so we could answer questions like "Who are my closest 100 neighbors and what are their home phone numbers?". Between that and Google buying the archives of usenet[1] in the same basic timeframe I realized that if it's written down its not likely to stay private for long.

Edit: add citation [1] https://en.wikipedia.org/wiki/Google_Groups#Deja_News

Re: Ask HN: Who really gives your personal info to Intelius, Instant Checkmate, etc?

#210

If Google aggressively delisted shitty companies like this, the problem would go away. There's no value for society in these shit services that make people register and pay to have their profiles taken down.

Then again, Google and Facebook are the biggest aggregators among them. Admittedly, they don't sell raw access to their data.
Post reply on HN