Live data from Hacker News

Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

wired.com

161–170 of 307 posts

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#161

Earlier quoted context omitted.

Wouldn't a GDPR request to Visa or MasterCard in the EU get me this data?

That's what I was thinking. Would be awesome for personal budgeting...

Well, they have to provide it digital, if they already have it digital. So yeah. Anyone wanna integrate the format they can deliver with e.g. GNUCash or so?

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#163
post #149

I think that the right title should be "Marketing Firm Exactis Exposed a Personal Info Database with with 340M Records on Internet". This is not a leak, at least there is no evidence of it yet. While this does not downplay this security "mishap", there is still big difference between "someone rob a bank" and "bank left their vaults open". OTOH, it would be interesting to know how did they get hold on such data.

Unusually for me I find your pedantry here too quibbling - even if the bank is left open taking the money is still theft (robbery is with threats/force in my jurisdiction, UK).

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#164

Earlier quoted context omitted.

In America, they simply do not know the last 300 years of history.

Practically everyone knows about the second world war, but nothing is being done about rising fascism. It has nothing to do with not knowing, it's just stupidity.

What do you suppose can be done about it?

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#165

Earlier quoted context omitted.

Same flawed logic as in online piracy. No one lost your data, they still have it, but someone else made a copy.

A rather irrelevant nitpick to this discussion. Let's not pretend we didn't know what lost meant in this context. And of course it's the process of making a copy that's the issue.

Actual I think it's worth picking that nit because it emphasises that the company who leaked the data, allowed its exfiltration, still have the data.

That emphasis is twofold: 1) they can do it again, because 2) they didn't lose anything.

The corollaries being that their incentives aren't aligned with the people whose data is leaked, the company don't need to spend on avoiding leaks because they're not harmed beyond a little (bad) PR.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#166
post #23

"exposes" here is quite a strange term, because their entire business is selling that same data. The only difference is that it was briefly available without a price tag.

That assumes they would sell to absolutely any group including terrorists, hate groups and sanctioned countries. At least without the leak they have the option to refuse.

You think they care beyond the colour of the money? Ha, welcome to capitalism my sweet Summer child.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#167
post #149

I think that the right title should be "Marketing Firm Exactis Exposed a Personal Info Database with with 340M Records on Internet". This is not a leak, at least there is no evidence of it yet. While this does not downplay this security "mishap", there is still big difference between "someone rob a bank" and "bank left their vaults open". OTOH, it would be interesting to know how did they get hold on such data.

Unusually for me I find your pedantry here too quibbling - even if the bank is left open taking the money is still theft (robbery is with threats/force in my jurisdiction, UK).

The point is there's no evidence a robbery occurred. Someone phoned the bank and told them they saw the vault was left open and that they had better count the money. Nobody knows whether anything was taken yet.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#169

A lot of people complained that GDPR was too onerous on small firms and that they should be exempt. According to LinkedIn https://ie.linkedin.com/company/exactis-llc Exactis has just 10 employees (obviously some error possible. Call it 15-20?) Now do you think small firms can’t hold large quantities of damaging data?

That sounds a lot like "I told you so" tone when I still disagree with you. But in case you're here to talk about it and not just to assert your version of the truth, no, I don't think anyone ever claimed that small corps are a loophole. Then big corps would just delegate it to a shell company and be done with it. European law is, to the best of my knowledge, fairly reasonable: if you do something wrong regarding privacy either because you didn't know (like, you tried to follow GDPR but missed something) or do a small thing, you won't get ridiculous fines. But if you're a 10 person company working with huge amounts of personal data and you were grossly negligent, then of course they'll look at that differently from a 10 man company that produces pencils for retailers and incorrectly stored customer's delivery addresses.
Post reply on HN