Live data from Hacker News

Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

wired.com

21–30 of 307 posts

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#22

spoiler alert: nobody goes to jail.

In all seriousness, what law (in the US) has this company broken? I'm assuming all the data they got was somehow obtained through legal channels in the first place?

People may be up in arms about this being a "breach", but think about it: they're a "data brokerage" company. Consider this breach a sale price of $0. My point is what should be scary is that all of this data is bought and sold about all of us, all the time, in the first place.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#25
post #14

When will this stop? When's the last straw? If I gave a bank 100 dollars, and they lost it, I'd have avenues with which to pursue some sort of justice. If I give a company my data, and they lose it, oh well. I wish all personal data was treated like HIPAA, at a minimum.

>If I give a company my data,

In some cases you're not knowingly giving them your data either.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#26
post #18

> "I don’t know where the data is coming from, but it’s one of the most comprehensive collections I’ve ever seen" > Each record contains entries that go far beyond contact information and public records to include more than 400 variables on a vast range of specific characteristics: whether the person smokes, their religion, whether they have dogs or cats, and interests as varied as scuba diving and plus-size apparel.…

Accuracy doesn't matter.

Imagine you're a pastor at a church and a datadump claims you're an atheist. Maybe you can convince people it's a mistake, maybe you can't.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#27
post #14

When will this stop? When's the last straw? If I gave a bank 100 dollars, and they lost it, I'd have avenues with which to pursue some sort of justice. If I give a company my data, and they lose it, oh well. I wish all personal data was treated like HIPAA, at a minimum.

>If I give a company my data, In some cases you're not knowingly giving them your data either.

That's the depressing part. I usually shop at Meijer because they were the last grocery left without annoying loyalty cards. As of this year, I've began receiving in the mail coupons for specific items I'd bought there. So either my credit card company has sold my data, or it was 'stolen' when they scanned my license to buy beer at some point(they require scanning the license, not DOB entry). I'm tired of this.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#28
post #14

When will this stop? When's the last straw? If I gave a bank 100 dollars, and they lost it, I'd have avenues with which to pursue some sort of justice. If I give a company my data, and they lose it, oh well. I wish all personal data was treated like HIPAA, at a minimum.

Why do you think this can be stopped ? Think it through.

You can't stop data loss until you can guarantee platform security. You can't do that until you prevent developers from creating bugs and security flaws in the first place. You can only do that unless you have either perfect tools to catch all the issues or a perfect testing regime.

It's basically an unsolvable problem.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#29
post #2

And... no one will go to jail.

Who exactly should go to jail, and what would that help? For all the do-something-ism in the world, doing "something" often amounts to making things worse, while allowing actual avenues for improvement to fester.

The CEOs of the company.

"Hey, you can get sent to jail for collecting and exposing personal information" would make a lot of people rethink their business models.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#30
post #14

When will this stop? When's the last straw? If I gave a bank 100 dollars, and they lost it, I'd have avenues with which to pursue some sort of justice. If I give a company my data, and they lose it, oh well. I wish all personal data was treated like HIPAA, at a minimum.

Why do you think this can be stopped ? Think it through. You can't stop data loss until you can guarantee platform security. You can't do that until you prevent developers from creating bugs and security flaws in the first place. You can only do that unless you have either perfect tools to catch all the issues or a perfect testing regime. It's basically an unsolvable problem.

That's a defeatist attitude. If you make companies liable for this, they'll start paying more attention to security. I'm not a trained security expert, but did have to explain this year why not to store plain text passwords in a database. Security is seen as secondary to product across the board. We need penalties to change this.
Post reply on HN