Live data from Hacker News

Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

wired.com

281–290 of 307 posts

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#281
Why exactly are people not paying more attention to projects like MaidSAFE which are working diligently to solve these problems once and for all?

Why do we assume we have to make an arbitrary choice of landlord to trust just so we can get basic things done on the Internet?

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#282

Oh, man, another missed opportunity to make the average Joe Six-Pack become aware of data aggregation and privacy violations. If the researcher had downloaded the 2TB of data and published it as a torrent, then laymen might care. When someone can query the list and see his own personal information being broadcast, they will understand. When they realize that anyone can look up the address, phone, and all sorts of oth…

While I think it's the most effective to leak the data of the persons that are able to change the rules and pursue justice in this case, I do think that these exact people will try everything in their power to make an example out of you - the leaker - and you'll end up as a second Aaron Swartz.

Also I think it's interesting that people say it is "leaked" while what actually happened is that the price of this data got lowered to zero for a few lucky souls.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#283

Don't forget that you leaked all that info in the first place. Do you use ad-blocker, vpn, private browsing, same on the phone too? All privacy settings in facebook, avoiging gmail and google? No? At least teach your kids to.

You go through all that trouble, and yet ... you have a Facebook account?

Anyway, the info being leaked here isn't dependent on browsing history. Companies have been gathering these sorts of profiles far longer than most people have been using the Internet. The only way to avoid it is not just to never have Internet access at all, but never have a credit card or a bank account, never own a house or sign a lease, never drive a car, never register to vote, etc. If you do any of those things, even temporarily, you could be leaking information that can't be unleaked.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#284
post #223

Earlier quoted context omitted.

I've been a proponent of this idea: Make companies "super-liable" for any data beyond the data they (actually) need for the functioning of the service that is stolen in a data breach from their servers. This would hopefully not just encourage more companies to believe that data is "toxic" [1] and treat it as a liability , not as an asset, but it would also encourage them to adopt end-to-end encryption in as many type…

The data in this case is their only asset. They are a data broker, and their entire existence is predicated on the idea that this data is valuable to them. I think we need to teach people that their data is valuable, likely dangerous in the hands of others, and not to spew it all over the web. Kinda like we did before FB convinced everybody to use their real names.

>The data in this case is their only asset. They are a data broker, and their entire existence is predicated on the idea that this data is valuable to them.

Other than them, who cares? If you want to put people in harm's way, you should accept the consequences when harm occurs.

>I think we need to teach people that their data is valuable, likely dangerous in the hands of others, and not to spew it all over the web. Kinda like we did before FB convinced everybody to use their real names.

No, it's much easier to hold the companies accountable, and they should be held accountable. No company that suffers a "data breach" should have the resources to exist after the breach. Society should punish them out of existence, because they are known cancers.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#285
post #272

Earlier quoted context omitted.

"Missed opportunity" ? People can be stabbed in the back if they go into dark alleys without watching behind them. Let's stab a few people who go into these alleys so that everyone will be afraid to do so and we have an opportunity to prevent people being stabbed in future by making them aware. Why would you possibly think this is a good idea? The idea is to prevent pain, not cause more pain in some bizarre attempt a…

Your analogy misrepresents the grandfather's point. A closer analogy for his argument might be: - Some high number X of dark alley stabbings occur each year. - But alleys still "feel" safe to people, because the stabbings aren't well-publicized. So people don't know to avoid them and the rate X remains the same. - Let's publicize alley stabbings in an emotionally impactful way, so people know to avoid alleys and we c…

I don't think this is correct. For all the people who would have their data exposed in a public torrent, their data is likely safe at present and just needs to be removed from that website. If you put it in a torrent, you're hurting all of those people in a very direct way - you're the one stabbing them in the back.

What the authors here did is correct - they've publicized the issue. Releasing this data as a torrent is not 'publicizing' anything - it is stabbing millions of people in the back, and then waiting for the crowds to come and gape at the dead bodies.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#286

Earlier quoted context omitted.

"Missed opportunity" ? People can be stabbed in the back if they go into dark alleys without watching behind them. Let's stab a few people who go into these alleys so that everyone will be afraid to do so and we have an opportunity to prevent people being stabbed in future by making them aware. Why would you possibly think this is a good idea? The idea is to prevent pain, not cause more pain in some bizarre attempt a…

There is logic at play here, even if you disagree with the approach behind executing it. It's pretty simple psychology that when your neighbor gets robbed it "hits home" with you more than hearing about nameless people on the news suffering the same fate.

Doesn't mean you go rob people's houses.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#287
post #224

As a US citizen, traveling in the EU, what rights do I have under GDPR? Can request data and erasure from Exactis while abroad?

No, as a US citizen you have no such GDPR protection. If Exactis operates also in the EU, Eu citizens may request their data or erasure of their data from Exactis.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#288

Earlier quoted context omitted.

I actually agree with the parent's perspective. As I see it, there are three potential states for sensitive data: 1. Secured and private. This is data not exposed in any breach. 2. Unsecured and private. This is data which has been exposed in a breach, and which must be sought out by the reasonably tech savvy. 3. Unsecured and public. This is data which has been exposed and can be easily used by anyone. We want all s…

I think this should be called the 'haveibeenpwned' philosophy or the 'Troy Hunt paradigm'

No, because Troy Hunt and HIBP will not allow you to search the contents of the breaches. He is explicitly against this philosophy.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#289

Earlier quoted context omitted.

I don't think it's so much that software devs take it "lightly". In my experience as a infosec consultant, the bigger problem is that most software devs are too cocky when it comes to security. Most think that security is just a subdomain of computer science (it is not!), and that because they took a crypto class in college, they are 100% qualified to handle the security themselves. They think they are taking it seri…

I think you're missing the point. It's not about security, it's about data.

Ah, you're right. I skimmed over the top level comment and missed that. My bad.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#290
post #184

Earlier quoted context omitted.

> my data Data about you is not (necessarily) data you own. I'm not saying it's right, but any reasonable discussion has to take this legal landscape into account.

That is not the European view. Data about you is owned by you, not by the company that collected or processed it.

I don't think that's exactly right. You certainly have some say in how it's used, but I don't think it's built on a notion of "ownership".
Post reply on HN