Live data from Hacker News

Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

wired.com

271–280 of 307 posts

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#271
post #27

Earlier quoted context omitted.

>If I give a company my data, In some cases you're not knowingly giving them your data either.

That's the depressing part. I usually shop at Meijer because they were the last grocery left without annoying loyalty cards. As of this year, I've began receiving in the mail coupons for specific items I'd bought there. So either my credit card company has sold my data, or it was 'stolen' when they scanned my license to buy beer at some point(they require scanning the license, not DOB entry). I'm tired of this.

I usually shop at Meijer because they were the last grocery left without annoying loyalty cards.

(quizzical look)

Are you aware of their MPerks program? Tied to your phone number and an email address, electronic receipts, tracking of your savings, online/in-app clipping of coupons auto-applied at checkout time, automatic "rewards" of $2-3 for every $150 you spend.

The only part of a traditional loyalty card program it doesn't have is making their sale prices apply only with card, but it definitely gives you measurable (and measured) discounts both passively through those "rewards" and actively via the in-app coupons.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#272

Oh, man, another missed opportunity to make the average Joe Six-Pack become aware of data aggregation and privacy violations. If the researcher had downloaded the 2TB of data and published it as a torrent, then laymen might care. When someone can query the list and see his own personal information being broadcast, they will understand. When they realize that anyone can look up the address, phone, and all sorts of oth…

"Missed opportunity" ? People can be stabbed in the back if they go into dark alleys without watching behind them. Let's stab a few people who go into these alleys so that everyone will be afraid to do so and we have an opportunity to prevent people being stabbed in future by making them aware. Why would you possibly think this is a good idea? The idea is to prevent pain, not cause more pain in some bizarre attempt a…

Your analogy misrepresents the grandfather's point. A closer analogy for his argument might be:

- Some high number X of dark alley stabbings occur each year.

- But alleys still "feel" safe to people, because the stabbings aren't well-publicized. So people don't know to avoid them and the rate X remains the same.

- Let's publicize alley stabbings in an emotionally impactful way, so people know to avoid alleys and we can bring X down.

In the actual case at hand, the argument is that you break a few eggs so people understand the issue viscerally, and hope to achieve massive regulatory change because people now actually care. I don't know if it would work, but it's a more reasonable idea than you're making it out to be.

Solving the root problem here is orders of magnitude more important than any single data breach today is.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#273
post #27

Earlier quoted context omitted.

That's the depressing part. I usually shop at Meijer because they were the last grocery left without annoying loyalty cards. As of this year, I've began receiving in the mail coupons for specific items I'd bought there. So either my credit card company has sold my data, or it was 'stolen' when they scanned my license to buy beer at some point(they require scanning the license, not DOB entry). I'm tired of this.

I usually shop at Meijer because they were the last grocery left without annoying loyalty cards. (quizzical look) Are you aware of their MPerks program? Tied to your phone number and an email address, electronic receipts, tracking of your savings, online/in-app clipping of coupons auto-applied at checkout time, automatic "rewards" of $2-3 for every $150 you spend. The only part of a traditional loyalty card program i…

Yeah I'm aware. I am not signed up for them. That's the reason I don't like Kroger, their stuff is way marked up without a card. That said, I figured out a 'trick' of just asking for a card and saying you'll fill out the application at home. Doesn't seem like such a trick now since they're all just tracking me by my payment methods. Oh well.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#274

Oh, man, another missed opportunity to make the average Joe Six-Pack become aware of data aggregation and privacy violations. If the researcher had downloaded the 2TB of data and published it as a torrent, then laymen might care. When someone can query the list and see his own personal information being broadcast, they will understand. When they realize that anyone can look up the address, phone, and all sorts of oth…

In light of my siblings' comments perhaps only lawmakers and their companions ought be exposed in this manner. I'm reminded of the swift enactment of restrictions on videotape rental records sparked by release of Judge Bork's rental records.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#275
post #225

Earlier quoted context omitted.

And what really changed? They used to sell the data, right? Now everybody has it (instead of only a percent). Is that worse?

This is pretty much where I’m at as well, on this issue. I only wish there were social security numbers contained in the breach so that we could stop considering them as personally identifiable info.

I agree with your meaning, and I think it goes beyond that. SSNs really are PII by definition; what we need to do is stop pretending that we can use any kind of PII in general as a form of authentication. Whether it's SSN, mother's maiden name, or any of these inane "security questions" that (thank goodness) finally seem to be receding from their peak, we need to move away from the fundamentally broken "tell me something about yourself that only you would know" model of authentication.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#276
post #145

Earlier quoted context omitted.

When did I buy diapers from Exactis? I’ve never even heard of them. I know exactly what my Safeway card is used for. I also deliberately do not register my phone number or other information to it. Of course they can probably associate it with my credit card but these things are easy to reason about. The real problem is combining all these datasets in one place for the purpose of perpetuating information asymmetry as…

You seem to believe you can ward off information collection efforts by controlling yourself what you do and do not communicate to the rest of the world. While I sincerely admire the quixotic effort, I suspect you are fighting a losing battle. There are countless situations in daily life where you have no choice but to leak some tiny bit of information about yourself to an external database, and from there on, it's ju…

You have misunderstood my comment. I realize I have no control over what Safeway does with my information or if they or someone else correlates it with other datasets. The data Safeway has is fine by me until it is correlated with other datasets.

That leakage may be inevitable but the correlation is not. We just allow it today. GP claimed that the existence of the Exactis dataset was not a problem. I disagree. That dataset exists only because many disparate sets were linked with that inevitable leakage.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#277
post #145
post #138

Earlier quoted context omitted.

Companies are in some cases (in many cases actually) perfectly allowed to collect user information and from a business perspective would be stupid not to do. Every time you use a loyalty card that information is collected and yes it's used to understand you and perhaps even influence you, to buy certain products. Buying diapers? Have a look at these baby toys. Most people will throw their personal information out the…

When did I buy diapers from Exactis? I’ve never even heard of them. I know exactly what my Safeway card is used for. I also deliberately do not register my phone number or other information to it. Of course they can probably associate it with my credit card but these things are easy to reason about. The real problem is combining all these datasets in one place for the purpose of perpetuating information asymmetry as…

>The real problem is combining all these datasets in one place for the purpose of perpetuating information asymmetry as a product.

Rephrased, the real problem is (currently) what happens once it gets combined with that wealth of other data (that's been purchased, shared, snooped and swindled) belonging to our data overlords like Google.

>Of course they can probably associate it with my credit card

Or if you've ever furnished an ID for some age restricted purchase while also using the loyalty card. Then of course theres location data from Android/smartphone, vehicle telemetry (mfg, finance company, mobile data service, OnStar, anti-theft service, insurance co 'safe-driver' tracking device), members of the Telco mafia (VZW,AT&T, etc.), video surveillance providers running facial & license plate recognition, et cetera.

[1]https://www.washingtonpost.com/news/the-switch/wp/2017/05/23...

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#278

Earlier quoted context omitted.

I just signed a rental agreement for an apartment in the US and in the fine print it says that they can share your data with whoever they want. You can't even opt out. Pretty fucked up.

> You can't even opt out I scratched that, and other lines, out of my rental agreement when I rented my New York apartment. The landlord agreed.

I wonder, do they then just enter your data into their database and sell it all anyway? Is there some way for you to ensure it's not included in all the other tenant data they share?

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#279
post #145

Earlier quoted context omitted.

When did I buy diapers from Exactis? I’ve never even heard of them. I know exactly what my Safeway card is used for. I also deliberately do not register my phone number or other information to it. Of course they can probably associate it with my credit card but these things are easy to reason about. The real problem is combining all these datasets in one place for the purpose of perpetuating information asymmetry as…

In your example does Safeway need to do all the data analysis on their own? Why can’t they contract out to others to analyze the rewards card data. Rarely do I know every subcontractor a business I interact with is using at the time.

The issue is not that a third party is involved, the issue is what that third party does with the information.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#280
post #265
post #187

Earlier quoted context omitted.

It is in the law. It’s one of the basic principles of law. By its very nature, however, you cannot nail such a thing down and define it precisely beforehand.

The law only says regulators should think about your intentions when assessing penalties (among many other factors). Is there anything stopping a regulator from deciding an unintentional violation is "only" a company-destroying 5M euro fine instead of the full 10M? In fact, couldn't it still be a 10M fine? Or should I expect to be let off with a warning? Seems like I'm depending on the good will of the regulators of…

That's what makes me nervous about interpretation of GDPR. The EU has 28 member states. Let's say each one of them has a 90% probability of their regulators being reasonable at any given time. Does that mean the chances of the regulators on the whole being reasonable are 0.9^28? (In other words, about 5%?)

As an outsider, I would love to hear that that's not how it works. Do the member states have any checks on each other's enforcement?

Post reply on HN