Live data from Hacker News

Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

wired.com

141–150 of 307 posts

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#142
post #99

This is laughable. Data security is a fairy-tale. We've all been bought and sold and there is nothing any of us can do to fix it.

One common theme of all these companies is that they don't want to pay for good talent in security.

The problem is how they get those data and not how securely they are kept.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#143
post #27

Earlier quoted context omitted.

That's the depressing part. I usually shop at Meijer because they were the last grocery left without annoying loyalty cards. As of this year, I've began receiving in the mail coupons for specific items I'd bought there. So either my credit card company has sold my data, or it was 'stolen' when they scanned my license to buy beer at some point(they require scanning the license, not DOB entry). I'm tired of this.

The credit card info is called "level 3 data" and they in some cases have line item by line item detail. Not just "spend $24.89 at Meijer store #349" but each individual thing, e.g. you bought 2 avocados.

usually there is only space for group ids of items rather than individual item details.

but i guess it might be different for different acquirers.

the purpose of loyalty cards is that the messages are usually acquired or processed on non-bank systems so they can go into much greater detail and include individual sale item details

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#144
post #138

Information inequity. Whomever has access to this data had an advantage on 340M people, and opportunity to understand and influence them. I think the antithesis of would be information redistribution. Everybody should be entitled to access all of this information if anyone has it. Just for fun lets say the only caveat is that all information access is also public and linked to each identity. Do you think its better o…

Companies are in some cases (in many cases actually) perfectly allowed to collect user information and from a business perspective would be stupid not to do. Every time you use a loyalty card that information is collected and yes it's used to understand you and perhaps even influence you, to buy certain products. Buying diapers? Have a look at these baby toys. Most people will throw their personal information out the…

There is a difference between a company collecting information related to its transactions and a data aggregator.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#145
post #138

Information inequity. Whomever has access to this data had an advantage on 340M people, and opportunity to understand and influence them. I think the antithesis of would be information redistribution. Everybody should be entitled to access all of this information if anyone has it. Just for fun lets say the only caveat is that all information access is also public and linked to each identity. Do you think its better o…

Companies are in some cases (in many cases actually) perfectly allowed to collect user information and from a business perspective would be stupid not to do. Every time you use a loyalty card that information is collected and yes it's used to understand you and perhaps even influence you, to buy certain products. Buying diapers? Have a look at these baby toys. Most people will throw their personal information out the…

When did I buy diapers from Exactis? I’ve never even heard of them.

I know exactly what my Safeway card is used for. I also deliberately do not register my phone number or other information to it. Of course they can probably associate it with my credit card but these things are easy to reason about.

The real problem is combining all these datasets in one place for the purpose of perpetuating information asymmetry as a product.

So actually yes, the problem is that this dataset of every single American exists.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#146
post #27

Earlier quoted context omitted.

>If I give a company my data, In some cases you're not knowingly giving them your data either.

That's the depressing part. I usually shop at Meijer because they were the last grocery left without annoying loyalty cards. As of this year, I've began receiving in the mail coupons for specific items I'd bought there. So either my credit card company has sold my data, or it was 'stolen' when they scanned my license to buy beer at some point(they require scanning the license, not DOB entry). I'm tired of this.

I have no problem with loyalty cards. It helps the store work more efficiently and sell me more relevant products. I have a problem when the loyalty card is tied to my identity and any data from anywhere else.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#147

Earlier quoted context omitted.

I don't think it's so much that software devs take it "lightly". In my experience as a infosec consultant, the bigger problem is that most software devs are too cocky when it comes to security. Most think that security is just a subdomain of computer science (it is not!), and that because they took a crypto class in college, they are 100% qualified to handle the security themselves. They think they are taking it seri…

This. I worked with an end-to-end encrypted communications company for 5 years, and learned a vast amount more about crypto, attack vectors, and security holes than I did in the previous decade or two, but I would never claim to be a security or crypto expert, or even competent at it. In fact, I almost certainly know only a tiny fraction of what the actual experts in that company knew, but a number of people have tol…

Where can mere mortals get an overview of just what you know? A lay of the land, scope, just to frame up what these problems really look like.

Its hard to even think about these things for those of us working at low levels, firmware, embedded, etc...

Your comment got me to thinking about what I don't know. Which is a whole lot.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#148
post #145
post #138

Earlier quoted context omitted.

Companies are in some cases (in many cases actually) perfectly allowed to collect user information and from a business perspective would be stupid not to do. Every time you use a loyalty card that information is collected and yes it's used to understand you and perhaps even influence you, to buy certain products. Buying diapers? Have a look at these baby toys. Most people will throw their personal information out the…

When did I buy diapers from Exactis? I’ve never even heard of them. I know exactly what my Safeway card is used for. I also deliberately do not register my phone number or other information to it. Of course they can probably associate it with my credit card but these things are easy to reason about. The real problem is combining all these datasets in one place for the purpose of perpetuating information asymmetry as…

Safeway may outsource the collection and management of this data to a third party and that company may have a lot of clients and hence records of a lot of people.

I have no idea if that's what Exactis is / does and people may not be aware of this, but it's the reality.

EDIT looks like Exactis gets information on users through cookies, which is not the scenario I wanted to highlight.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#149
I think that the right title should be "Marketing Firm Exactis Exposed a Personal Info Database with with 340M Records on Internet". This is not a leak, at least there is no evidence of it yet. While this does not downplay this security "mishap", there is still big difference between "someone rob a bank" and "bank left their vaults open".

OTOH, it would be interesting to know how did they get hold on such data.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#150
post #4

With reasonable verification, anyone confirmed to be a part of this breach should be given access to the data, if only for good will. It's a sad state to see that the recklessness (or incompetence) of one entity, and at that a private one, can quickly become a domino in a chain that ends in toppling a person's privacy. They advertise themselves as having the most accurate data (why wouldn't they advertise themselves…

Much more than just personal privacy. When CEOs, politicians, judges and generals use the internet too do you really want to be the guy/a company that gives them that call? The incentives are all messed up.
Post reply on HN