Live data from Hacker News

Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

wired.com

51–60 of 307 posts

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#51
post #42

Earlier quoted context omitted.

Let's discuss how we can fix this. I'm actually considering leaving my job of 8 years for a probably to be doomed privacy startup. Either way, I'm interested in solutions and more importantly working towards them, even for free.

Congress grilled Equifax and nothing. Average person saw Equifax commercial on “hey be smart we will keep your info safe with alerts” and thought “wow this company cares about my data” when its precisely opposite. If the congress is unable or doesnt want to draft a bill to stop predators from milking money off of your data, then that money probably ends up in their pocket some way. Or at least some of it. Please dont…

In my ideal mind, I'd keep my job, it's pretty lax as long as I deliver. But I want to fix privacy. I'm working with a guy I respect, who is also all about privacy, but I just don't think his model works. Ideally I'll donate some dev time for free, but if I saw even a glimmer of hope, I'd go all in. We can't trust congress, we need a private sector movement. I'm offering my services for free to anyone in the space, generally speaking.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#52
post #50
post #14

When will this stop? When's the last straw? If I gave a bank 100 dollars, and they lost it, I'd have avenues with which to pursue some sort of justice. If I give a company my data, and they lose it, oh well. I wish all personal data was treated like HIPAA, at a minimum.

> If I give a company my data, and they lose it, oh well. I wish all personal data was treated like HIPAA, at a minimum. And yet, when GDPR tries to address the issue, HN is full of "blocking the damned EU users completely" and "stop stifling honest companies".

It's almost as if the issue is more complicated than the solution represented by the GDPR.

I mean, I'm a "tin hat" privacy nut in the USA, but that doesn't mean that I'm a fan of 100% of the GDPR. It has plusses and minuses. It'd be nice to have a conversation about them.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#53
post #14

When will this stop? When's the last straw? If I gave a bank 100 dollars, and they lost it, I'd have avenues with which to pursue some sort of justice. If I give a company my data, and they lose it, oh well. I wish all personal data was treated like HIPAA, at a minimum.

>If I give a company my data, In some cases you're not knowingly giving them your data either.

I just signed a rental agreement for an apartment in the US and in the fine print it says that they can share your data with whoever they want. You can't even opt out. Pretty fucked up.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#54
post #42

Earlier quoted context omitted.

Let's discuss how we can fix this. I'm actually considering leaving my job of 8 years for a probably to be doomed privacy startup. Either way, I'm interested in solutions and more importantly working towards them, even for free.

Congress grilled Equifax and nothing. Average person saw Equifax commercial on “hey be smart we will keep your info safe with alerts” and thought “wow this company cares about my data” when its precisely opposite. If the congress is unable or doesnt want to draft a bill to stop predators from milking money off of your data, then that money probably ends up in their pocket some way. Or at least some of it. Please dont…

Do you have any data to support your claim about what the average person thought about Equifax and Congress? I have a lot of strong opinions about privacy, but I'm also resigned to the fact that most people don't care about it as much as I do. So I don't guess what they're thinking.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#55

spoiler alert: nobody goes to jail.

In all seriousness, what law (in the US) has this company broken? I'm assuming all the data they got was somehow obtained through legal channels in the first place? People may be up in arms about this being a "breach", but think about it: they're a "data brokerage" company. Consider this breach a sale price of $0. My point is what should be scary is that all of this data is bought and sold about all of us, all the ti…

Maybe libel?

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#56
post #27

Earlier quoted context omitted.

That's the depressing part. I usually shop at Meijer because they were the last grocery left without annoying loyalty cards. As of this year, I've began receiving in the mail coupons for specific items I'd bought there. So either my credit card company has sold my data, or it was 'stolen' when they scanned my license to buy beer at some point(they require scanning the license, not DOB entry). I'm tired of this.

The credit card info is called "level 3 data" and they in some cases have line item by line item detail. Not just "spend $24.89 at Meijer store #349" but each individual thing, e.g. you bought 2 avocados.

How does this work with Apple Pay, which doesn't tell the retailer who the consumer is? Does the retailer sell the info, or the credit card company?

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#57
post #50

Earlier quoted context omitted.

> If I give a company my data, and they lose it, oh well. I wish all personal data was treated like HIPAA, at a minimum. And yet, when GDPR tries to address the issue, HN is full of "blocking the damned EU users completely" and "stop stifling honest companies".

It's almost as if the issue is more complicated than the solution represented by the GDPR. I mean, I'm a "tin hat" privacy nut in the USA, but that doesn't mean that I'm a fan of 100% of the GDPR. It has plusses and minuses. It'd be nice to have a conversation about them.

The question though is what's the alternative? The IT industry has failed spectacularly in protecting citizens' personal data. I'm not a fan of EU bureaucracy, but it looks as if they are on the right side of history on this one.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#58
post #42

Earlier quoted context omitted.

Let's discuss how we can fix this. I'm actually considering leaving my job of 8 years for a probably to be doomed privacy startup. Either way, I'm interested in solutions and more importantly working towards them, even for free.

Legislation. We need legal repercussions for people who wantonly mishandle our personal information. Sorry, but the market can’t help us. This kind of shit needs to be illegal yesterday. It’s just impossible because we have a Congress that is so remarkably out of touch that they won’t do anything about it.

How so many people are convinced the market will save them from the marker given the last 300 years oh history is beyond me.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#59
post #17

What is the source of this data? Without more information I can only assume they are scraping public records just like sites like Spokeo etc. Perhaps with some data analysis thrown in. So I don't see much of a personal concern; especially since their business model appears to be selling this very data!

I think you're a bit confused by what data Spokeo has. Most of it is generated on the fly when you do a query, by scraping other sources.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#60
post #14

When will this stop? When's the last straw? If I gave a bank 100 dollars, and they lost it, I'd have avenues with which to pursue some sort of justice. If I give a company my data, and they lose it, oh well. I wish all personal data was treated like HIPAA, at a minimum.

Why do you think this can be stopped ? Think it through. You can't stop data loss until you can guarantee platform security. You can't do that until you prevent developers from creating bugs and security flaws in the first place. You can only do that unless you have either perfect tools to catch all the issues or a perfect testing regime. It's basically an unsolvable problem.

It's definitely solvable. You pass laws that make it very costly for businesses to expose personal data. Businesses are rational actors (for the most part) and will adjust accordingly, for example by not collecting the data in the first place.
Post reply on HN