Live data from Hacker News

Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

wired.com

231–240 of 307 posts

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#231

Oh, man, another missed opportunity to make the average Joe Six-Pack become aware of data aggregation and privacy violations. If the researcher had downloaded the 2TB of data and published it as a torrent, then laymen might care. When someone can query the list and see his own personal information being broadcast, they will understand. When they realize that anyone can look up the address, phone, and all sorts of oth…

For many people, the benefit of being able to look up information is greater than the cost of letting other people have this ability - most people still won't care too much even if they know their data is published in this way. (For example, most people were willing to have their home telephone number published in a phone book)

For some people, the cost of letting other people look up your information is overwhelmingly huge - this is why privacy should be regulated.

We don't really "all suffer" the same - some people suffer disproportionately (stalking, harassment, abuse).

Publishing the data as a torrent is unlikely to change people's opinion, but will almost certainly harm people.

Don't take this approach.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#232

It's interesting that we consider this a leak only when the marketing firm loses the data. If we lived in a just society we would consider it a leak once the marketing firm got the data.

> It's interesting that we consider this a leak only when the marketing firm loses the data.

We don't consider this a leak when the marketing firm loses its data. It's only a leak when we find out that the marketing firm has lost control of its data.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#233
post #229

A lot of people complained that GDPR was too onerous on small firms and that they should be exempt. According to LinkedIn https://ie.linkedin.com/company/exactis-llc Exactis has just 10 employees (obviously some error possible. Call it 15-20?) Now do you think small firms can’t hold large quantities of damaging data?

I think the root of the argument about small firms was not about employee count, but that small firms typically do not have the resources to comply. But what is Exactis’ annual profit? Maybe they did have the financial resources.

If you don’t have the resources to be a good steward of a dataset, you don’t have the resources to gather and store that data in the first place, even if it may seem easy to do so.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#234

Oh, man, another missed opportunity to make the average Joe Six-Pack become aware of data aggregation and privacy violations. If the researcher had downloaded the 2TB of data and published it as a torrent, then laymen might care. When someone can query the list and see his own personal information being broadcast, they will understand. When they realize that anyone can look up the address, phone, and all sorts of oth…

For many people, the benefit of being able to look up information is greater than the cost of letting other people have this ability - most people still won't care too much even if they know their data is published in this way. (For example, most people were willing to have their home telephone number published in a phone book) For some people, the cost of letting other people look up your information is overwhelming…

[deleted]

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#235

Oh, man, another missed opportunity to make the average Joe Six-Pack become aware of data aggregation and privacy violations. If the researcher had downloaded the 2TB of data and published it as a torrent, then laymen might care. When someone can query the list and see his own personal information being broadcast, they will understand. When they realize that anyone can look up the address, phone, and all sorts of oth…

That’s career suicide and it likely would come with let’s make an example out of you sentencing (depending where lived).

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#236
post #145
post #138

Earlier quoted context omitted.

Companies are in some cases (in many cases actually) perfectly allowed to collect user information and from a business perspective would be stupid not to do. Every time you use a loyalty card that information is collected and yes it's used to understand you and perhaps even influence you, to buy certain products. Buying diapers? Have a look at these baby toys. Most people will throw their personal information out the…

When did I buy diapers from Exactis? I’ve never even heard of them. I know exactly what my Safeway card is used for. I also deliberately do not register my phone number or other information to it. Of course they can probably associate it with my credit card but these things are easy to reason about. The real problem is combining all these datasets in one place for the purpose of perpetuating information asymmetry as…

In your example does Safeway need to do all the data analysis on their own? Why can’t they contract out to others to analyze the rewards card data. Rarely do I know every subcontractor a business I interact with is using at the time.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#237
post #223

It's interesting that we consider this a leak only when the marketing firm loses the data. If we lived in a just society we would consider it a leak once the marketing firm got the data.

I've been a proponent of this idea: Make companies "super-liable" for any data beyond the data they (actually) need for the functioning of the service that is stolen in a data breach from their servers. This would hopefully not just encourage more companies to believe that data is "toxic" [1] and treat it as a liability , not as an asset, but it would also encourage them to adopt end-to-end encryption in as many type…

The data in this case is their only asset. They are a data broker, and their entire existence is predicated on the idea that this data is valuable to them.

I think we need to teach people that their data is valuable, likely dangerous in the hands of others, and not to spew it all over the web. Kinda like we did before FB convinced everybody to use their real names.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#238

Earlier quoted context omitted.

> I’d love to search this database for the details of top people at privacy-violating companies and publish them. Who defines "privacy-violating"? Jumping into the mud because you feel aggrieved just makes you look like a pig.

Facebook? Equifax? Ad networks? Basically anyone who profits off user data and makes it difficult/impossible to opt-out.

This is pretty silly, you're going to publish something everyone already knows? What do you think that's going to accomplish? Most of these companies are publicly traded and finding top people in the private companies is just a Google search away. This business is all done out in the open.

You can even force the companies subjected to the FCRA[1] to give you a report on exactly what they have on you.

[1] They are subject to the FCRA if the data is sold to companies who make use of it in credit, employment, and housing decisions.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#239
post #17

What is the source of this data? Without more information I can only assume they are scraping public records just like sites like Spokeo etc. Perhaps with some data analysis thrown in. So I don't see much of a personal concern; especially since their business model appears to be selling this very data!

I think you're a bit confused by what data Spokeo has. Most of it is generated on the fly when you do a query, by scraping other sources.

That's what I mean though.

If this data comes from just scraping other sources that are freely and publicly available and applying some shitty data analysis on it, why should I be particularly concerned? The data itself is already out there for someone to find if they wanted to or even buy it from this company if they are too lazy to scrape themselves.

However, the source of the data wasn't in the article.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#240
post #238

Earlier quoted context omitted.

Facebook? Equifax? Ad networks? Basically anyone who profits off user data and makes it difficult/impossible to opt-out.

This is pretty silly, you're going to publish something everyone already knows? What do you think that's going to accomplish? Most of these companies are publicly traded and finding top people in the private companies is just a Google search away. This business is all done out in the open. You can even force the companies subjected to the FCRA[1] to give you a report on exactly what they have on you. [1] They are sub…

It's not all that silly actually. Politicians and corporate CEOs make the decision but rarely are on the receiving end of the fall-out. By concentrating on them and by distilling out that information from a much larger body of data enough of an embarrassment could be put together that they might start to pay attention.

As long as all those needles are safe in the haystack they can be ignored, a stack of needles on the other hand is not so easily ignored.

Post reply on HN