Live data from Hacker News

The City of Seattle Accidentally Gave Me 32M Emails for $40

mchap.io

41–50 of 239 posts

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#41
Somewhat related, I'm constantly shocked (maybe I shouldn't be anymore) at the tech ineptitude of cities that are supposed to be big tech hubs. I live in Seattle, and my regular tech complaint is we can't get the buses connected to an app that is accurate within +-10 minutes. I know it doesn't sound like much, but how much tech brainpower is here, and why isn't that tech shining more clearly?

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#42

The writer has fessed up to reading a lot of the emails. As evidenced by summarizing the content (e.g. cheating spouses, zabbix etc.). Wouldn't the responsible thing to do be stop reading the emails once you realise what is going on?

I probably only spent 30 minutes looking at it and used a few regular expressions to look for anything interesting. The point there was to understand the extent of the leak so that I could raise it in the intent of being taken seriously.

A search for "(Fuck|Shit|Bitch)" can go a long way.

For what it's worth, I used to work at an investment bank spending 30hr/week diving through logs with unix tools, so finding interesting information quickly is something I've learned to do quickly.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#43
A few years ago I found a random SSD on the ground while on a walk with my son. The drive contained unencrypted records which squarly fall under HIPPA. I also did the right thing and returned it to the proper owner and told them about how their mdb files were readable by anyone.

The same exact thing happened. They thanked me and then their lawyers nicely asked me to clone my hard drive and sign a bunch of shit.

It was not fun at all. A lot of them thought that I hacked something.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#44
post #41

Somewhat related, I'm constantly shocked (maybe I shouldn't be anymore) at the tech ineptitude of cities that are supposed to be big tech hubs. I live in Seattle, and my regular tech complaint is we can't get the buses connected to an app that is accurate within +-10 minutes. I know it doesn't sound like much, but how much tech brainpower is here, and why isn't that tech shining more clearly?

Because private tech companies fight like mad to avoid paying taxes to public city operations? Citizens too, probably. Nobody likes taxes.

And the best/brightest tech workers gravitate to the higher private salaries.

It’s not a technical problem - those are easier.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#45

I'm very surprised they gave out this information. I'm not talking about the mistake, I mean the actual request. In the UK I don't think you could even get a production order for this. Like, it's effectively getting Communications Data simultaneously against thousands of people not suspected of any crimes?? Like, do people know that by emailing their local government their email address is now free for scammers to re…

Yes, you are as far as I can see correct. The request should have been rejected as overbroad and against data privacy laws (in so far as they exist), or the purpose of the request could have been verified and then they might have seen whether or not there was another way to let the requester do their work without giving them the data they requested (see another comment of mine for one suggestion).

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#46
post #41

Somewhat related, I'm constantly shocked (maybe I shouldn't be anymore) at the tech ineptitude of cities that are supposed to be big tech hubs. I live in Seattle, and my regular tech complaint is we can't get the buses connected to an app that is accurate within +-10 minutes. I know it doesn't sound like much, but how much tech brainpower is here, and why isn't that tech shining more clearly?

Because the problem isn't tech, but business models. No amount of tech brainpower can help when bus operators think of their schedules as data to be sold instead of given away for free.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#47
post #42

The writer has fessed up to reading a lot of the emails. As evidenced by summarizing the content (e.g. cheating spouses, zabbix etc.). Wouldn't the responsible thing to do be stop reading the emails once you realise what is going on?

I probably only spent 30 minutes looking at it and used a few regular expressions to look for anything interesting. The point there was to understand the extent of the leak so that I could raise it in the intent of being taken seriously. A search for "(Fuck|Shit|Bitch)" can go a long way. For what it's worth, I used to work at an investment bank spending 30hr/week diving through logs with unix tools, so finding inter…

FWIW I think you should not have done that, though I understand the temptation.

At the first indication that the data was not what you requested and contained more than you - or they - bargained for you should have stopped looking at it and alerted both the sender and the relevant data protection authorities in so far as those are a functioning entity where you live to tell them they have an 'accidental disclosure' on their hands. Essentially your blog post documents something that is pretty strong proof you are not able to deal with confidential information properly.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#48

I'm very surprised they gave out this information. I'm not talking about the mistake, I mean the actual request. In the UK I don't think you could even get a production order for this. Like, it's effectively getting Communications Data simultaneously against thousands of people not suspected of any crimes?? Like, do people know that by emailing their local government their email address is now free for scammers to re…

I have never assumed that an email address I gave the government would be protected. I would also not assume that the contents of any email I sent would be in any way protected either. The government is collectively owned. Your police record, where you live, who you're married to, and whether or not you voted last election are publicly available. I would rather all of that be protected in some way, but I think it's common knowledge that a lot about you is made public to anyone who wants to walk down to the courthouse. In fact, if you want to take a trip to Hawaii, you can drop in and see a copy of Obama's famously "missing" birth certificate. I am rather shocked that credit card numbers are being emailed about.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#49

I'm very surprised they gave out this information. I'm not talking about the mistake, I mean the actual request. In the UK I don't think you could even get a production order for this. Like, it's effectively getting Communications Data simultaneously against thousands of people not suspected of any crimes?? Like, do people know that by emailing their local government their email address is now free for scammers to re…

The Washington State Public Records Act, which this request was made under, states its spirit very unambiguously:

  The people of this state do not yield their sovereignty to the agencies that
  serve them. The people, in delegating authority, do not give their public
  servants the right to decide what is good for the people to know and what is
  not good for them to know. The people insist on remaining informed so that
  they may maintain control over the instruments that they have created. This
  chapter shall be liberally construed and its exemptions narrowly construed
  to promote this public policy and to assure that the public interest will be
  fully protected. In the event of conflict between the provisions of this
  chapter and any other act, the provisions of this chapter shall govern.
http://app.leg.wa.gov/RCW/default.aspx?cite=42.56.030

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#50
post #43

A few years ago I found a random SSD on the ground while on a walk with my son. The drive contained unencrypted records which squarly fall under HIPPA. I also did the right thing and returned it to the proper owner and told them about how their mdb files were readable by anyone. The same exact thing happened. They thanked me and then their lawyers nicely asked me to clone my hard drive and sign a bunch of shit. It wa…

The type of organization that would store HIPPA encumbered data unencrypted, which based on my brief reading is not legal anymore, is not one that would operate in a reasonable (or legal) manner. Sadly, that seems to be most organizations that fall under HIPPA, compliance is a box to be checked while expending as little resources and effort as possible.

How they reacted to your kind action is sad, and depressingly common. I hope you told them to pound sand, and contacted whoever the data protection authorities were in your state. There needs to be much more aggressive enforcement of HIPPA and similar data protection laws, CYA bull like you encountered should not be happening.

Article I ran across: https://info.townsendsecurity.com/bid/74330/Does-HIPAA-Requi...

Post reply on HN