Live data from Hacker News

The City of Seattle Accidentally Gave Me 32M Emails for $40

mchap.io

91–100 of 239 posts

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#91

Earlier quoted context omitted.

Since they revised the cost for the data they actually sent him down from $33M to $56 (90 days of data at $1.25 for 2 days data), was a ballpark estimate that's over 500,000 times higher than the actual cost really reasonable?

The actual cost of servicing this request was much greater than the $56 estimate.

Especially after the city made a mistake!

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#92
post #48

I'm very surprised they gave out this information. I'm not talking about the mistake, I mean the actual request. In the UK I don't think you could even get a production order for this. Like, it's effectively getting Communications Data simultaneously against thousands of people not suspected of any crimes?? Like, do people know that by emailing their local government their email address is now free for scammers to re…

I have never assumed that an email address I gave the government would be protected. I would also not assume that the contents of any email I sent would be in any way protected either. The government is collectively owned. Your police record, where you live, who you're married to, and whether or not you voted last election are publicly available. I would rather all of that be protected in some way, but I think it's c…

> Your police record, where you live, who you're married to, and whether or not you voted last election are publicly available.

This is highly country specific. For the marriage record, I checked the laws in Germany, and (except for your own records) you have to present a "legal interest", which seems to be stricter than a "legitimate interest" (i.e. probably you need the information to enforce your rights, not just because you want to do genealogy). I'm pretty sure the others would count as particularly sensitive personal data too.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#93

I'm very surprised they gave out this information. I'm not talking about the mistake, I mean the actual request. In the UK I don't think you could even get a production order for this. Like, it's effectively getting Communications Data simultaneously against thousands of people not suspected of any crimes?? Like, do people know that by emailing their local government their email address is now free for scammers to re…

The part I found even more strange is that people are sending their credit card numbers and other personal information through e-mail...

People laugh at most DLP solutions. I know I used to. But then, I used to think the target was smart people trying to exfiltrate data.

But then I implemented one on a busy mail system, and I started seeing credit card numbers very regularly. I mean, consistently. Even after people have been told why their emails are being bounced and no, I give an "ETA on when it will be fixed".

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#95

I'm very surprised they gave out this information. I'm not talking about the mistake, I mean the actual request. In the UK I don't think you could even get a production order for this. Like, it's effectively getting Communications Data simultaneously against thousands of people not suspected of any crimes?? Like, do people know that by emailing their local government their email address is now free for scammers to re…

The part I found even more strange is that people are sending their credit card numbers and other personal information through e-mail...

Are you really shocked by this? I guess you have never worked on a corporate email system! People do this all of the time.

1) They don't realise email is not secure

2) When you explain point 1, all of the other solutions seem like too much hassle so they email anyway.

3) You can tell your customers not to email you CC numbers, you can even refuse them, but they will keep sending them

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#96
post #71

Earlier quoted context omitted.

> Asking for an independent third party verification is reasonable. Not really, for the same reason they never should have sent the excess data in the first place... Why should he give up his privacy to some 3rd party company to help cover up their mistake?

Plus it opens up dangerous precedence. "Oops, here's some confidential data you never asked for, let me send a couple guys to scan your hard drives".

Corrupt cops do sometimes plant evidence. This isn't much different.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#97
post #39

Earlier quoted context omitted.

Long long term resident with a connection to local government They don't have a choice. Seattle IT is so underfunded that hands are tied because there isn't any resourcing. On one hand, you have to respond to all of these requests (and rightfully so, as it's the law.) On the other, you have no money for your department because it has no funding because the citizens didn't want to spend the money. The person who did t…

A good chunk of this is caused by our city repeatedly choosing awful vendors that bilk the city for crazy amounts of money, and provide trash as the final product. City Light and the new meters/new billing system are great examples, all the new power meters have no encryption, and use FSK for modulation. Asking City Light about this got me a response that FSK was the encryption, and the gal was dumbfounded when I poi…

> Wikipedia article on FSK

https://en.m.wikipedia.org/wiki/Frequency-shift_keying

> The demodulation of a binary FSK signal can be done using the Goertzel algorithm very efficiently, even on low-power microcontrollers.

The source links to the TI page for the MSP430, named because it originally sold for $4.30. While the original link is dead, an internet search reveals many side and college projects using this technique.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#98
post #39

Earlier quoted context omitted.

Long long term resident with a connection to local government They don't have a choice. Seattle IT is so underfunded that hands are tied because there isn't any resourcing. On one hand, you have to respond to all of these requests (and rightfully so, as it's the law.) On the other, you have no money for your department because it has no funding because the citizens didn't want to spend the money. The person who did t…

A good chunk of this is caused by our city repeatedly choosing awful vendors that bilk the city for crazy amounts of money, and provide trash as the final product. City Light and the new meters/new billing system are great examples, all the new power meters have no encryption, and use FSK for modulation. Asking City Light about this got me a response that FSK was the encryption, and the gal was dumbfounded when I poi…

>A good chunk of this is caused by our city repeatedly choosing awful vendors that bilk the city for crazy amounts of money, and provide trash as the final product.

How much of this is voters voting for politicians who are good at what is essentially a popularity contest instead of politicians who are capable of signing decent contracts? As long as voters don't care enough to change their voting habits this will continue to happen.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#99

I can't tell whether this is a testament to the incompetence of public IT operations or an indictment of public records keeping practice. Maybe both?

Also has a good example of hostile FOIA officers. I have filed about two dozen FOIA requests, and the vast majority were fine, though usually slow. Earlier this year one longstanding request of mine was rejected because they claimed the document I wanted was export controlled. Two months later I sent in an appeal where I showed that the document in question was not export controlled (I filed another FOIA with a separ…

I've requested thousands from all over the United States, big and small municipalities. The responses and individuals ranged from a small contingent of extremely professional, organized, helpful, and all around wonderful people to many and more abysmal, unorganized, uneducated, tech-illiterate, and downright incompetent folks.

I can't remember how many times I'd point the person I was attempting to request the information from directly to their sample version or official space where they said they were the holders of said datas I was looking for which also provided the instructions to specifically call them to request the data. I know from my POV (as a tech worker) it may seem silly to expect anything like that from them but what I was asking for was akin to an excel spreadsheet full of information they absolutely do have and it required no legwork, no generation of new materials, no gathering of data from multiple ancient sources.

It was all material / datas each individual municipality was making money, hand over fist, every month of every year -- the sample datas most municipalities had was evidence of that. I was basically asking them for the collection of the entire data, publicly traded info, and most were convinced they didn't have it. A product of laziness is what I'd chalk it up to because the individuals and municipalities that were awesome to work with and more than helpful seemed to take pride in their work and getting said data was easier than the majority of things involving interfacing with the government at any level usually winds up being like.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#100

I'm very surprised they gave out this information. I'm not talking about the mistake, I mean the actual request. In the UK I don't think you could even get a production order for this. Like, it's effectively getting Communications Data simultaneously against thousands of people not suspected of any crimes?? Like, do people know that by emailing their local government their email address is now free for scammers to re…

Yes, you are as far as I can see correct. The request should have been rejected as overbroad and against data privacy laws (in so far as they exist), or the purpose of the request could have been verified and then they might have seen whether or not there was another way to let the requester do their work without giving them the data they requested (see another comment of mine for one suggestion).

That's not how FOIA works. It's a good thing too. Government employees almost always fight FOIA requests. There aren't many subjective tools (e.g. overbroad) and you're certainly not required to say why you're making the request.

Data privacy laws in the US are unfortunately minimal. The bigger problem comes from imbalance -- if the government and corporations have lists of names, people need them to in order to be able to work together and organize.

If you don't think this information should go out in FOIA requests, the tool to accomplish that is data destruction. Government could wipe old emails once no longer relevant.

Post reply on HN