Live data from Hacker News

Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

wired.com

91–100 of 307 posts

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#91
post #23

"exposes" here is quite a strange term, because their entire business is selling that same data. The only difference is that it was briefly available without a price tag.

That assumes they would sell to absolutely any group including terrorists, hate groups and sanctioned countries.

At least without the leak they have the option to refuse.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#92
Information inequity. Whomever has access to this data had an advantage on 340M people, and opportunity to understand and influence them.

I think the antithesis of would be information redistribution. Everybody should be entitled to access all of this information if anyone has it. Just for fun lets say the only caveat is that all information access is also public and linked to each identity.

Do you think its better off in the hands of the highest bidders???

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#93
post #14

When will this stop? When's the last straw? If I gave a bank 100 dollars, and they lost it, I'd have avenues with which to pursue some sort of justice. If I give a company my data, and they lose it, oh well. I wish all personal data was treated like HIPAA, at a minimum.

Liability piercing the corporate veil to executives, shareholders, creditors, vendors, and clients/customers.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#94
post #83

Earlier quoted context omitted.

> what's the alternative? Absolute liability for data losses. Exactis lost 360 million peoples' data. They should be able to (a) form a class and (b) extract money damages from Exactis without having to prove specific harm, which is difficult to do with data loss. A good model is Illinois' Biometric Information Privacy Act [1]. Broaden the the definition from "biometric identifier" to a longer--but still specific--li…

That's basically what GDPR does. It broadens the scope of what is considered sensitive info and slaps a fine on people PRIOR to a breach. If a breach is found, then any breach of GDPR means EU can come after that company and hurt them seriously.

A fine and a lawsuit are very different things, especially with 340M people involved [even a $340M fine would only be $1/person]; fines don't usually go to the people injured by it, which would make sense with personal data being leaked. A fine also misses companies who are "doing what the law says" but still have some horrible flaw anyways. If you are _genuinely_ responsible for the data, meaning if something happens to it you are liable for it, then you often take more care of it above and beyond, than for simply complying with rules.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#95

Earlier quoted context omitted.

I'm suggesting that the alternative is a modification of the GDPR. It has a lot of great aspects, and some aspects that are kinda terrible.

It seems like the biggest issue with GDPR is that it’s comes from Europe and not the US? Historically speaking, Europe has in many issues come to agreement on technically solutions and industrial standards many years ahead of the US. For example, Europe was first on texting on the mobile network while the US (single country) took years to come to a standard. I think it will be the same with regards to GDPR. You (US)…

That's not the biggest issue that I have with the GDPR. In fact, I'm totally OK with someone doing a better job than the US at regulating privacy. However, I have some complaints about the GDPR, and there isn't very much discussion about the details; most people appear to think about it as "all or nothing" or "Europe good, USA bad" or "everything looks clear to me so what's the problem?" instead of discussing the details. You can see all of these opinions in this very discussion.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#96
post #66

I still can't understand why leaking SSN should do me harms. These are primary key, not crediential. But everybody is treating them as crediential.

Tell me about it. We need a government account that grants access to banks and utilities via oauth or some other cryptographic protocol that allows revocation at will.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#97
post #14

When will this stop? When's the last straw? If I gave a bank 100 dollars, and they lost it, I'd have avenues with which to pursue some sort of justice. If I give a company my data, and they lose it, oh well. I wish all personal data was treated like HIPAA, at a minimum.

Same flawed logic as in online piracy. No one lost your data, they still have it, but someone else made a copy.

What was lost wasn't the data, but its confidence and control over it.

The pedantism is unhelpful.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#98
post #42

Earlier quoted context omitted.

Let's discuss how we can fix this. I'm actually considering leaving my job of 8 years for a probably to be doomed privacy startup. Either way, I'm interested in solutions and more importantly working towards them, even for free.

Figure out a way to make the data collected useless. You can't hide and block every attempt to track, collect and generally have your privacy invaded. But it may be possible to throw a wrench in the gears by making so much noise the data is low quality.

Or increasing costs of holding, exchanging, or using it.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#99

This is laughable. Data security is a fairy-tale. We've all been bought and sold and there is nothing any of us can do to fix it.

One common theme of all these companies is that they don't want to pay for good talent in security.
Post reply on HN