The City of Seattle Accidentally Gave Me 32M Emails for $40
41–50 of 239 posts
Re: The City of Seattle Accidentally Gave Me 32M Emails for $40
#42The writer has fessed up to reading a lot of the emails. As evidenced by summarizing the content (e.g. cheating spouses, zabbix etc.). Wouldn't the responsible thing to do be stop reading the emails once you realise what is going on?
A search for "(Fuck|Shit|Bitch)" can go a long way.
For what it's worth, I used to work at an investment bank spending 30hr/week diving through logs with unix tools, so finding interesting information quickly is something I've learned to do quickly.
Re: The City of Seattle Accidentally Gave Me 32M Emails for $40
#43The same exact thing happened. They thanked me and then their lawyers nicely asked me to clone my hard drive and sign a bunch of shit.
It was not fun at all. A lot of them thought that I hacked something.
Re: The City of Seattle Accidentally Gave Me 32M Emails for $40
#44Somewhat related, I'm constantly shocked (maybe I shouldn't be anymore) at the tech ineptitude of cities that are supposed to be big tech hubs. I live in Seattle, and my regular tech complaint is we can't get the buses connected to an app that is accurate within +-10 minutes. I know it doesn't sound like much, but how much tech brainpower is here, and why isn't that tech shining more clearly?
And the best/brightest tech workers gravitate to the higher private salaries.
It’s not a technical problem - those are easier.
Re: The City of Seattle Accidentally Gave Me 32M Emails for $40
#45I'm very surprised they gave out this information. I'm not talking about the mistake, I mean the actual request. In the UK I don't think you could even get a production order for this. Like, it's effectively getting Communications Data simultaneously against thousands of people not suspected of any crimes?? Like, do people know that by emailing their local government their email address is now free for scammers to re…
Re: The City of Seattle Accidentally Gave Me 32M Emails for $40
#46Somewhat related, I'm constantly shocked (maybe I shouldn't be anymore) at the tech ineptitude of cities that are supposed to be big tech hubs. I live in Seattle, and my regular tech complaint is we can't get the buses connected to an app that is accurate within +-10 minutes. I know it doesn't sound like much, but how much tech brainpower is here, and why isn't that tech shining more clearly?
Re: The City of Seattle Accidentally Gave Me 32M Emails for $40
#47The writer has fessed up to reading a lot of the emails. As evidenced by summarizing the content (e.g. cheating spouses, zabbix etc.). Wouldn't the responsible thing to do be stop reading the emails once you realise what is going on?
I probably only spent 30 minutes looking at it and used a few regular expressions to look for anything interesting. The point there was to understand the extent of the leak so that I could raise it in the intent of being taken seriously. A search for "(Fuck|Shit|Bitch)" can go a long way. For what it's worth, I used to work at an investment bank spending 30hr/week diving through logs with unix tools, so finding inter…
At the first indication that the data was not what you requested and contained more than you - or they - bargained for you should have stopped looking at it and alerted both the sender and the relevant data protection authorities in so far as those are a functioning entity where you live to tell them they have an 'accidental disclosure' on their hands. Essentially your blog post documents something that is pretty strong proof you are not able to deal with confidential information properly.
Re: The City of Seattle Accidentally Gave Me 32M Emails for $40
#48I'm very surprised they gave out this information. I'm not talking about the mistake, I mean the actual request. In the UK I don't think you could even get a production order for this. Like, it's effectively getting Communications Data simultaneously against thousands of people not suspected of any crimes?? Like, do people know that by emailing their local government their email address is now free for scammers to re…
Re: The City of Seattle Accidentally Gave Me 32M Emails for $40
#49I'm very surprised they gave out this information. I'm not talking about the mistake, I mean the actual request. In the UK I don't think you could even get a production order for this. Like, it's effectively getting Communications Data simultaneously against thousands of people not suspected of any crimes?? Like, do people know that by emailing their local government their email address is now free for scammers to re…
The people of this state do not yield their sovereignty to the agencies that
serve them. The people, in delegating authority, do not give their public
servants the right to decide what is good for the people to know and what is
not good for them to know. The people insist on remaining informed so that
they may maintain control over the instruments that they have created. This
chapter shall be liberally construed and its exemptions narrowly construed
to promote this public policy and to assure that the public interest will be
fully protected. In the event of conflict between the provisions of this
chapter and any other act, the provisions of this chapter shall govern.
http://app.leg.wa.gov/RCW/default.aspx?cite=42.56.030Re: The City of Seattle Accidentally Gave Me 32M Emails for $40
#50A few years ago I found a random SSD on the ground while on a walk with my son. The drive contained unencrypted records which squarly fall under HIPPA. I also did the right thing and returned it to the proper owner and told them about how their mdb files were readable by anyone. The same exact thing happened. They thanked me and then their lawyers nicely asked me to clone my hard drive and sign a bunch of shit. It wa…
How they reacted to your kind action is sad, and depressingly common. I hope you told them to pound sand, and contacted whoever the data protection authorities were in your state. There needs to be much more aggressive enforcement of HIPPA and similar data protection laws, CYA bull like you encountered should not be happening.
Article I ran across: https://info.townsendsecurity.com/bid/74330/Does-HIPAA-Requi...