Live data from Hacker News

Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

wired.com

111–120 of 307 posts

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#111

Earlier quoted context omitted.

It seems like the biggest issue with GDPR is that it’s comes from Europe and not the US? Historically speaking, Europe has in many issues come to agreement on technically solutions and industrial standards many years ahead of the US. For example, Europe was first on texting on the mobile network while the US (single country) took years to come to a standard. I think it will be the same with regards to GDPR. You (US)…

That's not the biggest issue that I have with the GDPR. In fact, I'm totally OK with someone doing a better job than the US at regulating privacy. However, I have some complaints about the GDPR, and there isn't very much discussion about the details; most people appear to think about it as "all or nothing" or "Europe good, USA bad" or "everything looks clear to me so what's the problem?" instead of discussing the det…

> I have some complaints about the GDPR, and there isn't very much discussion about the details

There has been an enormous amount of discussion. It's been law for years and it's the amalgamation of various European countries individual DPR.

What exactly is your snowflake complaint that you think hasn't been discussed yet?

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#112

Earlier quoted context omitted.

Mastercard and Visa [1] sell this data in aggregate to firms via brokers like Bluekai, to allow for ad-targeting. I don't believe it'll be feasible to purchase just one person's purchase data [easily], but if you knew who you wanted to get to, it should be possible to narrow the targeting to get to them [1] http://www.oracle.com/us/solutions/cloud/data-directory-2810... [ctrl+F + mastercard]

Wouldn't a GDPR request to Visa or MasterCard in the EU get me this data?

That's what I was thinking. Would be awesome for personal budgeting...

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#113

Earlier quoted context omitted.

> what's the alternative? Absolute liability for data losses. Exactis lost 360 million peoples' data. They should be able to (a) form a class and (b) extract money damages from Exactis without having to prove specific harm, which is difficult to do with data loss. A good model is Illinois' Biometric Information Privacy Act [1]. Broaden the the definition from "biometric identifier" to a longer--but still specific--li…

How is a regular person supposed to even know if their data was in this particular leak?

A responsible company might be expected to put up some sort of portal that allows a user to check if they've been compromised.

Of course, "responsible" and "data aggregation company" rarely belong in the same sentence...

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#114
post #51

Earlier quoted context omitted.

Congress grilled Equifax and nothing. Average person saw Equifax commercial on “hey be smart we will keep your info safe with alerts” and thought “wow this company cares about my data” when its precisely opposite. If the congress is unable or doesnt want to draft a bill to stop predators from milking money off of your data, then that money probably ends up in their pocket some way. Or at least some of it. Please dont…

In my ideal mind, I'd keep my job, it's pretty lax as long as I deliver. But I want to fix privacy. I'm working with a guy I respect, who is also all about privacy, but I just don't think his model works. Ideally I'll donate some dev time for free, but if I saw even a glimmer of hope, I'd go all in. We can't trust congress, we need a private sector movement. I'm offering my services for free to anyone in the space, g…

> We need a private sector movement.

You should reach out to a venture called Equifax. They are providing customer alerts for data breaches and a premiere data protection service.

Your imagination is working against you here. The obvious and well-known reason that congress is ineffective is they work for the private sector, who is the disease; not the cure.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#115

Earlier quoted context omitted.

> what's the alternative? Absolute liability for data losses. Exactis lost 360 million peoples' data. They should be able to (a) form a class and (b) extract money damages from Exactis without having to prove specific harm, which is difficult to do with data loss. A good model is Illinois' Biometric Information Privacy Act [1]. Broaden the the definition from "biometric identifier" to a longer--but still specific--li…

How is a regular person supposed to even know if their data was in this particular leak?

> How is a regular person supposed to even know if their data was in this particular leak?

Reporting requirements. If you find out you're breached, you have to notify everyone involved--plus their states' attorneys general--within N days. If you find out you're breached and fail to notify at least one attorney general, that becomes a criminal liability for those who knew but didn't act.

I was working with Albany on a law in this form (notice only) after the Equifax breach. It was tabled due to lack of Equifax-related outreach from voters.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#116
So what are the odds someone at Exactis was paid off to loosen the access controls and provide relevant access info to the buyer?

A lot of people would probably do that for a chunk of money.

Starting to think that with databases like this, any configuration change that involves exposure to the internet should involve two company officers turning keys like in a nuclear missile launch.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#117

This is laughable. Data security is a fairy-tale. We've all been bought and sold and there is nothing any of us can do to fix it.

Erm, not opening up this fucking Elasticsearch instance to the entire internet would be a pretty easy way to get like 90% of the way there. I do operations. I can tell you exactly how not to make rookie mistakes like this. But security isn’t sexy, and it isn’t profitable, so it falls by the wayside.

Perhaps someone was paid to open the Elasticsearch to the entire internet so that the buyer could grab the data.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#118

Earlier quoted context omitted.

It seems like the biggest issue with GDPR is that it’s comes from Europe and not the US? Historically speaking, Europe has in many issues come to agreement on technically solutions and industrial standards many years ahead of the US. For example, Europe was first on texting on the mobile network while the US (single country) took years to come to a standard. I think it will be the same with regards to GDPR. You (US)…

That's not the biggest issue that I have with the GDPR. In fact, I'm totally OK with someone doing a better job than the US at regulating privacy. However, I have some complaints about the GDPR, and there isn't very much discussion about the details; most people appear to think about it as "all or nothing" or "Europe good, USA bad" or "everything looks clear to me so what's the problem?" instead of discussing the det…

You're creating or contributing to the problem you say exists, parent above was not refusing discussion and literally asked you what alternative you have in mind, so he was open to them.

But after going several answers deep you still haven't listed any specific complaints and instead complain that nobody discuss them. This really make no sense.

So, feel free to explain what specific things you dislike, why, and how else you would have done it, and then people would be able to discuss them with you and exchange opinion.

Saying "it's not possible to talk about x" when you don't even try to really isn't the way.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#119

Earlier quoted context omitted.

A fine and a lawsuit are very different things, especially with 340M people involved [even a $340M fine would only be $1/person]; fines don't usually go to the people injured by it, which would make sense with personal data being leaked. A fine also misses companies who are "doing what the law says" but still have some horrible flaw anyways. If you are _genuinely_ responsible for the data, meaning if something happen…

Many european countries (including Germany) have no class action lawsuits, so unless you want 340 million separate lawsuits, you’ll have to either use fines, or accept that this will go unpunished.

Just because there are no class action lawsuits doesn't mean you can't take collective legal action. It's been a long time since I lived in Germany, so I can't cite any recent examples, but 20 years ago there were lawsuits in Germany of broad groups.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#120
post #34

Earlier quoted context omitted.

It was discovered by a white hat; he didn't publicise a data dump.

s/white/ass/. A white hat, in the context of these surveillance companies, would be Tyler Durden.

Could you please not post unsubstantive comments here?
Post reply on HN