Live data from Hacker News

Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

wired.com

121–130 of 307 posts

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#121
post #110

Earlier quoted context omitted.

A fine and a lawsuit are very different things, especially with 340M people involved [even a $340M fine would only be $1/person]; fines don't usually go to the people injured by it, which would make sense with personal data being leaked. A fine also misses companies who are "doing what the law says" but still have some horrible flaw anyways. If you are _genuinely_ responsible for the data, meaning if something happen…

> fines don't usually go to the people injured by it, Well they do. Our government takes money through fines and taxes and uses it to build infrastructure and provide services. > which would make sense with personal data being leaked. My preference would be that personal data not be leaked at all. Ideally the warnings and fines kick in long before that happens. > A fine also misses companies who are "doing what the l…

> My preference would be that personal data not be leaked at all

Me too! But not at any cost. This discussion involves thinking about scope (both in who and what is regulated), penalties (both in frequency and magnitude) and pre-emptive enforcement, if any. The trade-offs are far-reaching. A conservative approach is prudent. (It's also politically resilient.)

> GDPR is quite broad and open to interpretation by both sides

That's a sin and a virtue.

> Requiring people to lawyer up to make the company responsible is far weaker

This, too, is a sin and a virtue. The sin is it may allow bad deeds to go unpunished. But presently, everything is going unpunished. The virtue is in its prudence. It's unlikely to cause systemic harm, and we can observe its case law to more-precisely draft the next wave of rules.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#122
post #99

This is laughable. Data security is a fairy-tale. We've all been bought and sold and there is nothing any of us can do to fix it.

One common theme of all these companies is that they don't want to pay for good talent in security.

> they don't want to pay for good talent in security

To be fair, I'm not sure they made the wrong choice.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#123

Earlier quoted context omitted.

>If I give a company my data, In some cases you're not knowingly giving them your data either.

I just signed a rental agreement for an apartment in the US and in the fine print it says that they can share your data with whoever they want. You can't even opt out. Pretty fucked up.

I bought a car earlier this year. Exciting purchase. We had got to the final bit before they hand over the keys and there was some paperwork to sign. On page 3 was the small print about us agreeing to give our data to everyone.

So I refused and made it clear I would walk away. The sales guy went though the whole ‘it’s not a problem, I’ve bought cars from here and haven’t got spammed’. In the end he had to get a manager and it turned out that the option could be removed from the contract, three menus down in the system.

Sounds like no one had ever asked before. I imagine GDPR will have changed this to opt-in.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#124
post #66

I still can't understand why leaking SSN should do me harms. These are primary key, not crediential. But everybody is treating them as crediential.

The reasons for this isn't your privacy. But still it can match you as a person even if your other data is defect or incomplete. A good primary key.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#125
post #14

When will this stop? When's the last straw? If I gave a bank 100 dollars, and they lost it, I'd have avenues with which to pursue some sort of justice. If I give a company my data, and they lose it, oh well. I wish all personal data was treated like HIPAA, at a minimum.

You could do business with places in the EU, where you are covered by EU's stronger data protection law. If an EU based company do stuff with the personal data of US citizens in the US, then the GDPR (etc) applies to that EU company.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#126

This is laughable. Data security is a fairy-tale. We've all been bought and sold and there is nothing any of us can do to fix it.

Erm, not opening up this fucking Elasticsearch instance to the entire internet would be a pretty easy way to get like 90% of the way there. I do operations. I can tell you exactly how not to make rookie mistakes like this. But security isn’t sexy, and it isn’t profitable, so it falls by the wayside.

> I do operations. I can tell you exactly how not to make rookie mistakes like this

But you guys are expensive and management can't tell what you do, so we invented devops to make the developers do it. It worked perfectly until it didn't.

Seriously though, as a dev with script kiddie levels of pen-testing skills it's amazing the amount of potential exploits out there. Even where I work with sensitive data it's assumed that the only attack vector is external.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#128
post #110

Earlier quoted context omitted.

A fine and a lawsuit are very different things, especially with 340M people involved [even a $340M fine would only be $1/person]; fines don't usually go to the people injured by it, which would make sense with personal data being leaked. A fine also misses companies who are "doing what the law says" but still have some horrible flaw anyways. If you are _genuinely_ responsible for the data, meaning if something happen…

> fines don't usually go to the people injured by it, Well they do. Our government takes money through fines and taxes and uses it to build infrastructure and provide services. > which would make sense with personal data being leaked. My preference would be that personal data not be leaked at all. Ideally the warnings and fines kick in long before that happens. > A fine also misses companies who are "doing what the l…

>Our government takes money through fines and taxes and uses it to build infrastructure and provide services.

Using fines to fund public services creates perverse incentives though, especially where the fines go directly to the agency that brings the case.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#129
post #110

Earlier quoted context omitted.

A fine and a lawsuit are very different things, especially with 340M people involved [even a $340M fine would only be $1/person]; fines don't usually go to the people injured by it, which would make sense with personal data being leaked. A fine also misses companies who are "doing what the law says" but still have some horrible flaw anyways. If you are _genuinely_ responsible for the data, meaning if something happen…

> fines don't usually go to the people injured by it, Well they do. Our government takes money through fines and taxes and uses it to build infrastructure and provide services. > which would make sense with personal data being leaked. My preference would be that personal data not be leaked at all. Ideally the warnings and fines kick in long before that happens. > A fine also misses companies who are "doing what the l…

> > fines don't usually go to the people injured by it,

> Well they do. Our government takes money through fines and taxes and uses it to build infrastructure and provide services.

That's only true if you consider the public at large to be equivalent to any individual member of the public, or if you believe only the government is "injured" by a data breach.

If I stole all your money and repaid it in fines to the government instead of directly to you, would you consider the matter settled?

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#130
post #14

When will this stop? When's the last straw? If I gave a bank 100 dollars, and they lost it, I'd have avenues with which to pursue some sort of justice. If I give a company my data, and they lose it, oh well. I wish all personal data was treated like HIPAA, at a minimum.

> When will this stop? When's the last straw? When the top folks in the US government are personally affected. Until then, "congressional hearings" and presidential ambivalence is the most action we'll get out of them. Most people don't really understand what the significance of these events are.

Thoughts and prayers.
Post reply on HN