Live data from Hacker News

Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

wired.com

191–200 of 307 posts

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#191

Earlier quoted context omitted.

The French CNIL just fined an association for 75,000 € for a leak in their data. It was a 2017 case, but I guess it will reflect what can happen ?

Can you link to this? Searching for "CNIL", "75,000" and "2017" doesn't turn up anything useful.

https://www.lexpress.fr/actualites/1/styles/protection-des-d...

tl;dr: a non-profit got fined 75K€ because their website leaked 42,562 private documents from their users. Anyone could modify numbers in the URL and read other users' documents. The documents included passports, tax information, identity documents, and more.

EDIT: better source: https://www.cnil.fr/fr/sanction-de-75-000-euros-pour-une-att...

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#192
post #149

I think that the right title should be "Marketing Firm Exactis Exposed a Personal Info Database with with 340M Records on Internet". This is not a leak, at least there is no evidence of it yet. While this does not downplay this security "mishap", there is still big difference between "someone rob a bank" and "bank left their vaults open". OTOH, it would be interesting to know how did they get hold on such data.

Unusually for me I find your pedantry here too quibbling - even if the bank is left open taking the money is still theft (robbery is with threats/force in my jurisdiction, UK).

Except what happened here was someone left the vault open and a passerby called the bank and the cops to let them know.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#193
post #42

Earlier quoted context omitted.

Let's discuss how we can fix this. I'm actually considering leaving my job of 8 years for a probably to be doomed privacy startup. Either way, I'm interested in solutions and more importantly working towards them, even for free.

Legislation. We need legal repercussions for people who wantonly mishandle our personal information. Sorry, but the market can’t help us. This kind of shit needs to be illegal yesterday. It’s just impossible because we have a Congress that is so remarkably out of touch that they won’t do anything about it.

Uhmm, actually Congress is very much in touch...

With corporate interests.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#194
post #169

A lot of people complained that GDPR was too onerous on small firms and that they should be exempt. According to LinkedIn https://ie.linkedin.com/company/exactis-llc Exactis has just 10 employees (obviously some error possible. Call it 15-20?) Now do you think small firms can’t hold large quantities of damaging data?

That sounds a lot like "I told you so" tone when I still disagree with you. But in case you're here to talk about it and not just to assert your version of the truth, no, I don't think anyone ever claimed that small corps are a loophole. Then big corps would just delegate it to a shell company and be done with it. European law is, to the best of my knowledge, fairly reasonable: if you do something wrong regarding pri…

On HN, it's people associated with businesses in the latter category that seem to be complaining the most.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#195

Earlier quoted context omitted.

> When will this stop? When's the last straw? When the top folks in the US government are personally affected. Until then, "congressional hearings" and presidential ambivalence is the most action we'll get out of them. Most people don't really understand what the significance of these events are.

> When the top folks in the US government are personally affected The OPM breach covered a lot of powerful senior people.

Not only that, but the Russian site exposed[dot]su has published personal information, including SSNs, about a lot of powerful people, including Michelle Obama, Robert Mueller, Eric Holder, and Hillary Clinton.

https://krebsonsecurity.com/2014/03/who-built-the-id-theft-s...

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#196

Earlier quoted context omitted.

How is a regular person supposed to even know if their data was in this particular leak?

> How is a regular person supposed to even know if their data was in this particular leak? Reporting requirements. If you find out you're breached, you have to notify everyone involved--plus their states' attorneys general--within N days. If you find out you're breached and fail to notify at least one attorney general, that becomes a criminal liability for those who knew but didn't act. I was working with Albany on a…

It was tabled due to lack of Equifax-related outreach from voters.

I suspect this is because the very people who would be the most vocal about this issue are also the most politically cynical, and would never think to reach out to their representatives. That's a damn shame, if true.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#197

Earlier quoted context omitted.

Legislation. We need legal repercussions for people who wantonly mishandle our personal information. Sorry, but the market can’t help us. This kind of shit needs to be illegal yesterday. It’s just impossible because we have a Congress that is so remarkably out of touch that they won’t do anything about it.

Government funded elections might solve most of our society’s spiraling issues but we can’t have any clue what the value would be until we try it. And of course we can’t make honest claims to democracy until then either.

As an uninformed observer, one of the biggest issues I see is the US two party system. Do you think government funding would help with that? I've always seen it more as a weakness of the general US electoral FPTP system.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#198
post #27

Earlier quoted context omitted.

That's the depressing part. I usually shop at Meijer because they were the last grocery left without annoying loyalty cards. As of this year, I've began receiving in the mail coupons for specific items I'd bought there. So either my credit card company has sold my data, or it was 'stolen' when they scanned my license to buy beer at some point(they require scanning the license, not DOB entry). I'm tired of this.

The credit card info is called "level 3 data" and they in some cases have line item by line item detail. Not just "spend $24.89 at Meijer store #349" but each individual thing, e.g. you bought 2 avocados.

I wonder if the credit card companies have access to line-item level 3 data if we use ApplePay?

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#199

Earlier quoted context omitted.

Unusually for me I find your pedantry here too quibbling - even if the bank is left open taking the money is still theft (robbery is with threats/force in my jurisdiction, UK).

The point is there's no evidence a robbery occurred. Someone phoned the bank and told them they saw the vault was left open and that they had better count the money. Nobody knows whether anything was taken yet.

What is messed up is if the firm doesn't have sufficient visibility/logging, they can claim "no evidence" the data was accessed (purely because they Had their eyes closed). IMHO that is negligent - but sadly the various laws tend to support it.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#200

Earlier quoted context omitted.

Unusually for me I find your pedantry here too quibbling - even if the bank is left open taking the money is still theft (robbery is with threats/force in my jurisdiction, UK).

The point is there's no evidence a robbery occurred. Someone phoned the bank and told them they saw the vault was left open and that they had better count the money. Nobody knows whether anything was taken yet.

The problem here is it may be impossible to know if anything was taken.

If theft occurs at a bank, the money is gone. If I steal information, the information is still there. Knowledge of theft is completely dependent on a logging system capturing the correct information.

Post reply on HN