Live data from Hacker News

Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

wired.com

261–270 of 307 posts

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#261
post #229

Earlier quoted context omitted.

I think the root of the argument about small firms was not about employee count, but that small firms typically do not have the resources to comply. But what is Exactis’ annual profit? Maybe they did have the financial resources.

If you don’t have the resources to be a good steward of a dataset, you don’t have the resources to gather and store that data in the first place, even if it may seem easy to do so.

I would agree.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#262
post #189

Earlier quoted context omitted.

Courts will always base their decisions on case law, and I suspect that you can reasonably expect a certain kind of GDPR case law to arise, given what the standing case law is already.

The EU has a civil law system where the US has a common law system. Common law gives judges an active role in developing rules; civil law is based on fixed codes and statutes. Case law is not binding in the EU.

> Common law gives judges an active role in developing rules; civil law is based on fixed codes and statutes.

This is a dramatic and misleading oversimplification. Under civil law systems, judges still do have great leeway with interpreting and applying regulations. And under common law, it's not really true that judges have an active role in developing rules - they have the ability to interpret them in the contexts of cases which come up, but they don't legislate. The closest thing that they can do (aside from overturning provisions) is to introduce limitations or tests on existing law that is challenged, but even then they're mostly only allowed to do that to the extent that they are using the tests to connect the law back to the Constitution or other existing legislation.

Case law is not binding in civil law (at least not to the same degree as it is under common law), but does definitely play a significant role.

Furthermore, it's flat-out wrong to say that "case law is not binding in the EU". The Republic of Ireland and the UK both use common law, under which case law is binding. Not only are UK court decisions are enforceable across the entire EU, but UK law is actually the jurisdiction for a lot of contracts and agreements within the EU, similar to how New York is the chosen jurisdiction for a lot of contracts or even international treaties that are enforced worldwide, whether or not the parties are based in New York.

Even if you're referring specifically to legislation passed by the European Parliament itself, it's still not really correct to say that case law isn't binding. The European Parliament is an international body held together by international treaties, and while EU courts might have decided to use civil law in interpreting legislation passed by the European Pariament itself, that doesn't mean that case law does not come into play, either in countries with common law systems or even in countries with civil law systems. It's way more complicated than that.

This is, incidentally, one of the problems that Brexit is currently introducing: it's unclear whether parties that have elected to govern their contracts under UK law will continue to be able to do so with the expectation of enforceability.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#263
William Pearson

CTO

Will is a highly accomplished IT Executive designing and developing self-service software applications built on BIG Data, running in Cloud Infrastructure in highly secure environments, leveraging analytics and yielding high profits and rapid growth.

He is responsible for technology strategy which includes highly accurate and automated data processing, cloud infrastructure, MS Azure platform-as-a-service, Cloudera / Hadoop Data Management Platform, APIs, Marketing Automation Platform, Analytics, and Digital Marketing.

( http://www.exactis.com/about-us/ )

highly ironic

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#264

Earlier quoted context omitted.

Who exactly should go to jail, and what would that help? For all the do-something-ism in the world, doing "something" often amounts to making things worse, while allowing actual avenues for improvement to fester.

What will help?

Find a way to use the unique position of the operators of this database to assist those affected in preventing identity theft and other threats which are worsened by the leak. Maybe figure out if there is money out there to account for the cost of that.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#265
post #187
post #178

Earlier quoted context omitted.

The "you won't get big fines if you try your best" thing isn't in the law. I believe you that it is probably true, but it relies on the reasonableness of all current and future regulators. I don't like that.

It is in the law. It’s one of the basic principles of law. By its very nature, however, you cannot nail such a thing down and define it precisely beforehand.

The law only says regulators should think about your intentions when assessing penalties (among many other factors).

Is there anything stopping a regulator from deciding an unintentional violation is "only" a company-destroying 5M euro fine instead of the full 10M? In fact, couldn't it still be a 10M fine? Or should I expect to be let off with a warning? Seems like I'm depending on the good will of the regulators of every single EU member state...

I do not think it's impossible to write a law that says fines for minor and unintentional violations are limited by statue.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#266
post #258

Earlier quoted context omitted.

It's a leak because there wasn't an invoice attached to what would otherwise be business as usual: the data being obtained by sketchy third parties.

Marketing companies are sketchy third parties.

That was a significant component of my point.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#267

Earlier quoted context omitted.

I don't think it's so much that software devs take it "lightly". In my experience as a infosec consultant, the bigger problem is that most software devs are too cocky when it comes to security. Most think that security is just a subdomain of computer science (it is not!), and that because they took a crypto class in college, they are 100% qualified to handle the security themselves. They think they are taking it seri…

This. I worked with an end-to-end encrypted communications company for 5 years, and learned a vast amount more about crypto, attack vectors, and security holes than I did in the previous decade or two, but I would never claim to be a security or crypto expert, or even competent at it. In fact, I almost certainly know only a tiny fraction of what the actual experts in that company knew, but a number of people have tol…

[deleted]

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#268

Earlier quoted context omitted.

That’s career suicide and it likely would come with let’s make an example out of you sentencing (depending where lived).

The researcher was using Shodan to probe the entire range of IP addresses allocated in the USA. He found an unprotected site and queried it knowing it should not have been accessible. He queried the personal info on specific people that WIRED asked him about. He revealed data to a third party ("a sample of the data Troia shared [with WIRED]"). An argument could be made that every step above was illegal. I don't agree…

That argument you propose isn't popular opinion though. He is taking risks if people in power choose to push an agenda but it's totally different in risk if he goes the other path of illustrating something to average joe.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#270

Earlier quoted context omitted.

"Missed opportunity" ? People can be stabbed in the back if they go into dark alleys without watching behind them. Let's stab a few people who go into these alleys so that everyone will be afraid to do so and we have an opportunity to prevent people being stabbed in future by making them aware. Why would you possibly think this is a good idea? The idea is to prevent pain, not cause more pain in some bizarre attempt a…

I actually agree with the parent's perspective. As I see it, there are three potential states for sensitive data: 1. Secured and private. This is data not exposed in any breach. 2. Unsecured and private. This is data which has been exposed in a breach, and which must be sought out by the reasonably tech savvy. 3. Unsecured and public. This is data which has been exposed and can be easily used by anyone. We want all s…

I think this should be called the 'haveibeenpwned' philosophy or the 'Troy Hunt paradigm'
Post reply on HN