Why do we assume we have to make an arbitrary choice of landlord to trust just so we can get basic things done on the Internet?
Marketing Firm Exactis Leaked a Personal Info Database with 340M Records
281–290 of 307 posts
Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records
#282Oh, man, another missed opportunity to make the average Joe Six-Pack become aware of data aggregation and privacy violations. If the researcher had downloaded the 2TB of data and published it as a torrent, then laymen might care. When someone can query the list and see his own personal information being broadcast, they will understand. When they realize that anyone can look up the address, phone, and all sorts of oth…
Also I think it's interesting that people say it is "leaked" while what actually happened is that the price of this data got lowered to zero for a few lucky souls.
Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records
#283Don't forget that you leaked all that info in the first place. Do you use ad-blocker, vpn, private browsing, same on the phone too? All privacy settings in facebook, avoiging gmail and google? No? At least teach your kids to.
Anyway, the info being leaked here isn't dependent on browsing history. Companies have been gathering these sorts of profiles far longer than most people have been using the Internet. The only way to avoid it is not just to never have Internet access at all, but never have a credit card or a bank account, never own a house or sign a lease, never drive a car, never register to vote, etc. If you do any of those things, even temporarily, you could be leaking information that can't be unleaked.
Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records
#284Earlier quoted context omitted.
I've been a proponent of this idea: Make companies "super-liable" for any data beyond the data they (actually) need for the functioning of the service that is stolen in a data breach from their servers. This would hopefully not just encourage more companies to believe that data is "toxic" [1] and treat it as a liability , not as an asset, but it would also encourage them to adopt end-to-end encryption in as many type…
The data in this case is their only asset. They are a data broker, and their entire existence is predicated on the idea that this data is valuable to them. I think we need to teach people that their data is valuable, likely dangerous in the hands of others, and not to spew it all over the web. Kinda like we did before FB convinced everybody to use their real names.
Other than them, who cares? If you want to put people in harm's way, you should accept the consequences when harm occurs.
>I think we need to teach people that their data is valuable, likely dangerous in the hands of others, and not to spew it all over the web. Kinda like we did before FB convinced everybody to use their real names.
No, it's much easier to hold the companies accountable, and they should be held accountable. No company that suffers a "data breach" should have the resources to exist after the breach. Society should punish them out of existence, because they are known cancers.
Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records
#285Earlier quoted context omitted.
"Missed opportunity" ? People can be stabbed in the back if they go into dark alleys without watching behind them. Let's stab a few people who go into these alleys so that everyone will be afraid to do so and we have an opportunity to prevent people being stabbed in future by making them aware. Why would you possibly think this is a good idea? The idea is to prevent pain, not cause more pain in some bizarre attempt a…
Your analogy misrepresents the grandfather's point. A closer analogy for his argument might be: - Some high number X of dark alley stabbings occur each year. - But alleys still "feel" safe to people, because the stabbings aren't well-publicized. So people don't know to avoid them and the rate X remains the same. - Let's publicize alley stabbings in an emotionally impactful way, so people know to avoid alleys and we c…
What the authors here did is correct - they've publicized the issue. Releasing this data as a torrent is not 'publicizing' anything - it is stabbing millions of people in the back, and then waiting for the crowds to come and gape at the dead bodies.
Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records
#286Earlier quoted context omitted.
"Missed opportunity" ? People can be stabbed in the back if they go into dark alleys without watching behind them. Let's stab a few people who go into these alleys so that everyone will be afraid to do so and we have an opportunity to prevent people being stabbed in future by making them aware. Why would you possibly think this is a good idea? The idea is to prevent pain, not cause more pain in some bizarre attempt a…
There is logic at play here, even if you disagree with the approach behind executing it. It's pretty simple psychology that when your neighbor gets robbed it "hits home" with you more than hearing about nameless people on the news suffering the same fate.
Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records
#287As a US citizen, traveling in the EU, what rights do I have under GDPR? Can request data and erasure from Exactis while abroad?
Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records
#288Earlier quoted context omitted.
I actually agree with the parent's perspective. As I see it, there are three potential states for sensitive data: 1. Secured and private. This is data not exposed in any breach. 2. Unsecured and private. This is data which has been exposed in a breach, and which must be sought out by the reasonably tech savvy. 3. Unsecured and public. This is data which has been exposed and can be easily used by anyone. We want all s…
I think this should be called the 'haveibeenpwned' philosophy or the 'Troy Hunt paradigm'
Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records
#289Earlier quoted context omitted.
I don't think it's so much that software devs take it "lightly". In my experience as a infosec consultant, the bigger problem is that most software devs are too cocky when it comes to security. Most think that security is just a subdomain of computer science (it is not!), and that because they took a crypto class in college, they are 100% qualified to handle the security themselves. They think they are taking it seri…
I think you're missing the point. It's not about security, it's about data.
Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records
#290Earlier quoted context omitted.
> my data Data about you is not (necessarily) data you own. I'm not saying it's right, but any reasonable discussion has to take this legal landscape into account.
That is not the European view. Data about you is owned by you, not by the company that collected or processed it.