The alternative is that the email address is correct and Matt is redirecting his domain to another Matt Chapman, which would be totally hilarious.
The City of Seattle Accidentally Gave Me 32M Emails for $40
151–160 of 239 posts
Re: The City of Seattle Accidentally Gave Me 32M Emails for $40
#152Earlier quoted context omitted.
FWIW I think you should not have done that, though I understand the temptation. At the first indication that the data was not what you requested and contained more than you - or they - bargained for you should have stopped looking at it and alerted both the sender and the relevant data protection authorities in so far as those are a functioning entity where you live to tell them they have an 'accidental disclosure' o…
If someone accidentally sends me information I owe them no duty of confidence. I'm under no obligation to notify them. It is entirely their problem. The idea that the OP is at fault for looking at data which the city had already published has no basis in law.
This simply isn't true. If someone accidentally sends you information that you know you shouldn't be privy to, you should delete it. Unless perhaps you are Nelson Muntz.
Re: The City of Seattle Accidentally Gave Me 32M Emails for $40
#153A few years ago I found a random SSD on the ground while on a walk with my son. The drive contained unencrypted records which squarly fall under HIPPA. I also did the right thing and returned it to the proper owner and told them about how their mdb files were readable by anyone. The same exact thing happened. They thanked me and then their lawyers nicely asked me to clone my hard drive and sign a bunch of shit. It wa…
Did you actually give them that clone and sign the documents? Or did you give push back like in the article? It feels to me like they shouldn't have much of a leg to stand on.
You found an drive, tried to return it and then we’re subject to an illegal search? Or you consented to a search that would have otherwise been illegal?
Re: The City of Seattle Accidentally Gave Me 32M Emails for $40
#154I can't tell whether this is a testament to the incompetence of public IT operations or an indictment of public records keeping practice. Maybe both?
Well, like most of Seattle's efforts, it gets fucked up, mostly because it is from Seattle. Note: I am a Seattle resident and I expect nothing less.
Re: The City of Seattle Accidentally Gave Me 32M Emails for $40
#155Earlier quoted context omitted.
Well, like most of Seattle's efforts, it gets fucked up, mostly because it is from Seattle. Note: I am a Seattle resident and I expect nothing less.
Have you lived anywhere else, like, say, the northeast? Seattle is a shockingly well run municipality among American cities of size.
Re: The City of Seattle Accidentally Gave Me 32M Emails for $40
#156I'm very surprised they gave out this information. I'm not talking about the mistake, I mean the actual request. In the UK I don't think you could even get a production order for this. Like, it's effectively getting Communications Data simultaneously against thousands of people not suspected of any crimes?? Like, do people know that by emailing their local government their email address is now free for scammers to re…
The part I found even more strange is that people are sending their credit card numbers and other personal information through e-mail...
https://www.theverge.com/2015/2/10/8013531/jeb-bush-florida-...
As it turned out, the cache of thousands of emails contained things that are hard to anticipate. Including people emailing their SSN, or talking about their employment/medical issues; the former is possible to filter out computationally, the latter would require manual review and judgment. Bush was criticized, and in response, he took down the emails temporarily until employees could clean them up. But AFAIK, he didn't do anything illegal, because he mirrored exactly what was available from the state official archive which, again AFAIK, did not alter its copy.
This is similar to AOL's release of its search logs. It thought anonymizing user identities would provide anonymity, but they did not realize that some users write very personal things into the search box: https://en.wikipedia.org/wiki/AOL_search_data_leak
Re: The City of Seattle Accidentally Gave Me 32M Emails for $40
#157Author of article has no background/understanding of the "sunshine" laws in effect in WA. Those laws may (do) explain a lot of why things go this way with any/all FOIA in WA. Source: 100s of FOIA requests to various WA government agencies.
Can you provide more details? What is it about WA sunshine laws that make the government misunderstand a request, overestimate the cost of providing the requested data, and then provide data that was not requested resulting in a breach of disclosure laws?
https://www.rcfp.org/browse-media-law-resources/news/city-mu...
It's because Washington agencies are required to cover reasonable attorneys fees for their opponents after losing open records lawsuits (one of the factors in our FOIA laws)
So when Author sent the request to Seattle, they have this above cited example (and 100s of others across the the State) where a mistake could create a lawsuit the costs this loads of money.
Did you know that the burden is on the agency to establish that its denial of inspection is proper?
Did you know that the court could award you an amount between $5 and $100 a day for each day that access to the records was denied.
So, if they don't give you everything you ask for you can sue. And it's easy (relatively) to win in WA for that because of our FOIA laws, then the agency has to pay for the lawyers and a penalty for delay of the records. For emails that means $5 * (Days of Delay) * (Number of Records).
In short, if Seattle fucked up this FOIA request, denied or delayed -- that could have cost them millions of dollars.
The author didn't understand that and (like a fool) blames the city and city-workers.
Re: The City of Seattle Accidentally Gave Me 32M Emails for $40
#158Author of article has no background/understanding of the "sunshine" laws in effect in WA. Those laws may (do) explain a lot of why things go this way with any/all FOIA in WA. Source: 100s of FOIA requests to various WA government agencies.
Could you be a little more precise? As is this is just a vacuous statement about how you know more than the author.
Re: The City of Seattle Accidentally Gave Me 32M Emails for $40
#159Earlier quoted context omitted.
Ok, so in that case redaction would have been the way to go here. But the request as it is actually harms the privacy of large numbers of individuals which is not what the FOI laws are supposed to be used for. Also, of course Seattle could reject the request, they could simply say: "Without an explicit court order to release this information we will not do so", and that would be that. It would then be upon the petiti…
But Seattle cannot summarily reject the request -- they have to follow the law, and the law does not require FOI requesters to get an explicit court order, e.g. a subpoena, for this information or for any other valid request. I mean, yes, the city of Seattle could try to reject the request, and the requester could sue and win in court after the judge finds that the city acted illegally. But that's like saying Seattle…
That's the key bit right there. So, if you are not sure - and they are also not sure - then they could ask for a ruling before releasing. Err on the side of caution is good practice when it comes to releasing data.
I just looked at the dataset and it is full of information that I would normally consider to be private, which private citizens contact which government officials and when is in principle not something that should be disclosed to all callers in a format of their choosing.
What's to stop you from asking for stuff that infringes other people's privacy? I'm all for a more open government but 'anything goes' FOI requests are only a little bit less dangerous than non-transparency.
There is some middle ground to be found here.
Re: The City of Seattle Accidentally Gave Me 32M Emails for $40
#160Earlier quoted context omitted.
The part I found even more strange is that people are sending their credit card numbers and other personal information through e-mail...
Are you really shocked by this? I guess you have never worked on a corporate email system! People do this all of the time. 1) They don't realise email is not secure 2) When you explain point 1, all of the other solutions seem like too much hassle so they email anyway. 3) You can tell your customers not to email you CC numbers, you can even refuse them, but they will keep sending them
The Payment Card Industry Data Security Standard (PCI DSS) that you have to agree to follow in order to be allowed to process credit cards requires secure storage of all the cards you store--not just the cards that you intended to store or just cards that come in through channels you intended for receiving cards.
This is a serious issue to take into account when choosing your chat system, ticketing system, and email system because you can't just ignore those wayward credit cards. If you choose systems whose developers did not consider this and failed to provide good tools for finding and redacting unrequested, unwanted sensitive information you will end up having to hack such tools into the system yourself.