Live data from Hacker News

The City of Seattle Accidentally Gave Me 32M Emails for $40

mchap.io

161–170 of 239 posts

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#161
post #150

Earlier quoted context omitted.

But Seattle cannot summarily reject the request -- they have to follow the law, and the law does not require FOI requesters to get an explicit court order, e.g. a subpoena, for this information or for any other valid request. I mean, yes, the city of Seattle could try to reject the request, and the requester could sue and win in court after the judge finds that the city acted illegally. But that's like saying Seattle…

> which I'm not even sure is the situation here That's the key bit right there. So, if you are not sure - and they are also not sure - then they could ask for a ruling before releasing. Err on the side of caution is good practice when it comes to releasing data. I just looked at the dataset and it is full of information that I would normally consider to be private, which private citizens contact which government offi…

Sorry, what I'm not sure about is whether an agency is liable if it releases exempt information. Exemptions allow an agency to deny a request, but the agency still has discretion whether or not to follow the exemption.

> So, if you are not sure - and they are also not sure - then they could ask for a ruling before releasing. Err on the side of caution is good practice when it comes to releasing data.

Again, that is simply not how the law works. Some years ago, elected Washington state legislators and the governor decided the law should make these tradeoffs between transparency and privacy. And until subsequent legislators get together and decide otherwise, that is the law of the land. Washington government agencies do not have discretion to reject requests based on requester identity or motivation, period, nor can they make up their own reasons for exemptions.

The "middle ground" has already been decided -- that's ostensibly how the law got written and signed in the first place. Your line of argument would allow literally any government employee to make arbitrary rejections -- the law was codified to prevent exactly that situation.

Your concerns are no different than concerns raised about freedom of speech and the press (and of course, the right to bear arms, but let's not follow that tangent for now) -- e.g. "I'm all for people being able to express themselves, but what if those people say incredibly hurtful and damaging things?". The legislature can pass laws that limit those rights (e.g. defamation laws), and courts interpret whether those laws follow the Constitution, but it is not up to the executive branch (i.e. government agencies) to ignore the law because they disagree with it.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#162
post #70

Earlier quoted context omitted.

Who knows. It was strange for me, too.

Think about it: you see your internet connection dying as proof when they could have just as easily booted you from the conference call raising much less suspicion. I see it as proof of the opposite, they had a far easier and more direct means at their disposal to achieve the effect you say they desired. So I really do not believe that it was anything other than bad timing, all that it would take for this to happen i…

My phone was dead at the time, so I was using my desktop with google hangouts for the call. I was not booted from the call. My internet died. End of story.

I work from home, so my internet going down is a big deal for my livelihood and all that. I'm not saying that something suspicious happened, but I figured it was an interesting thing to happen. You're frankly thinking into it too much.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#163
post #161

Earlier quoted context omitted.

> which I'm not even sure is the situation here That's the key bit right there. So, if you are not sure - and they are also not sure - then they could ask for a ruling before releasing. Err on the side of caution is good practice when it comes to releasing data. I just looked at the dataset and it is full of information that I would normally consider to be private, which private citizens contact which government offi…

Sorry, what I'm not sure about is whether an agency is liable if it releases exempt information. Exemptions allow an agency to deny a request, but the agency still has discretion whether or not to follow the exemption. > So, if you are not sure - and they are also not sure - then they could ask for a ruling before releasing. Err on the side of caution is good practice when it comes to releasing data. Again, that is s…

> based on requester identity or motivation

No, but they should decide based on the data requested. And in this case the data requested is none of the requesters business since it involves the privacy of other citizens.

Which definitely could be in contravention of other laws and in cases like that judges usually get to decide which weighs heavier. If I were a civil servant faced with a request that releases information that I felt would infringe on some other law I would definitely not decide to be the one to make the call and release it without a sign-off.

There isn't just one law at work here.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#164

I'm very surprised they gave out this information. I'm not talking about the mistake, I mean the actual request. In the UK I don't think you could even get a production order for this. Like, it's effectively getting Communications Data simultaneously against thousands of people not suspected of any crimes?? Like, do people know that by emailing their local government their email address is now free for scammers to re…

Similar story. I worked at a polling company out of college owned by a Standford professor. My first task: After a poll is finished online, match that with voter records (using emails and addresses). My first question was: "Well, that is a cool idea, but, there is no way the government would release a huge database of every california voter and their party affiliation. Let alone, the users entering in online poll inf…

Standford?

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#165
post #116

Earlier quoted context omitted.

The linked Kaggle dataset https://www.kaggle.com/foiachap/seattle-email-metadata/ shows that the final returned data are Excel tables with content which looks like this: Sender or Created by: "Herring, Kaya" Recipients in To line: Ortiz, Piper; Jones, Raphael Recipients in Cc line: Valdez, Khloe Recipients in Bcc line: Sent: 3/23/17 18:08 (I changed the names to random ones)

I suspected as much. So the names are out there. Pretty sloppy.

It's not sloppy, it's what the law allows for. You seem to have a misunderstanding in stating "the metadata should have only contained anonymized entries for the email addresses of the counterparties." That's simply incorrect in terms of what is allowed under law and for the request, though there is some variation state-to-state as to their FOIA.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#166

I'm confused, why was he looking for this information?

He mentions that he had previously requested this info in Chicago. This is the relevant previous blog post:

https://mchap.io/a-tale-about-requesting-chicagos-mayors-off...

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#167

Earlier quoted context omitted.

The type of organization that would store HIPPA encumbered data unencrypted, which based on my brief reading is not legal anymore, is not one that would operate in a reasonable (or legal) manner. Sadly, that seems to be most organizations that fall under HIPPA, compliance is a box to be checked while expending as little resources and effort as possible. How they reacted to your kind action is sad, and depressingly co…

Guys, it's HIPAA not HIPPA.

This is an interesting case. I always pronounced HIPAA as "hee-pah". That has the advantage of approximating the spelling, but the disadvantage that it's not really a natural way for an English word to be pronounced.

People in the medical field, who deal with HIPAA all the time, pronounce it as if it was spelled HIPPA. It's a short step from there to actually spelling it HIPPA.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#168

In case Matt Chapman is reading this -- the contact email at the bottom of the page (matt@mchap.com) is probably not correct, given that the domain mchap.com redirects to an australian photographer. The alternative is that the email address is correct and Matt is redirecting his domain to another Matt Chapman, which would be totally hilarious.

Ah! Thanks!

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#169

Earlier quoted context omitted.

Think about it: you see your internet connection dying as proof when they could have just as easily booted you from the conference call raising much less suspicion. I see it as proof of the opposite, they had a far easier and more direct means at their disposal to achieve the effect you say they desired. So I really do not believe that it was anything other than bad timing, all that it would take for this to happen i…

My phone was dead at the time, so I was using my desktop with google hangouts for the call. I was not booted from the call. My internet died. End of story. I work from home, so my internet going down is a big deal for my livelihood and all that. I'm not saying that something suspicious happened, but I figured it was an interesting thing to happen. You're frankly thinking into it too much.

> You're frankly thinking into it too much.

I think that was my line.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#170
post #157

Earlier quoted context omitted.

Can you provide more details? What is it about WA sunshine laws that make the government misunderstand a request, overestimate the cost of providing the requested data, and then provide data that was not requested resulting in a breach of disclosure laws?

Remember when Shoreline had to pay out ~$500k because of mistakes they made on a FOIA request? https://www.rcfp.org/browse-media-law-resources/news/city-mu... It's because Washington agencies are required to cover reasonable attorneys fees for their opponents after losing open records lawsuits (one of the factors in our FOIA laws) So when Author sent the request to Seattle, they have this above cited example (and 100…

> In short, if Seattle fucked up this FOIA request, denied or delayed -- that could have cost them millions of dollars.

Sorry, but that sounds like bullshit. The Washington law provides for agencies to take reasonable time on a request, especially one a request that is complicated and broad. In fact, unlike the FOI law for federal and other states, the Washington law does not proscribe the number of days that an agency must respond by, only that they be made "promptly":

http://app.leg.wa.gov/RCW/default.aspx?cite=42.56.520

The city of Shoreline did not have to pay out $500K "because of mistakes they made on a FOIA request", not according to what you posted:

> The City of Shoreline will have to reimburse $438,555 to cover the plaintiffs' costs as Washington agencies are required to cover reasonable attorneys fees for their opponents after losing open records lawsuits. Shoreline also agreed last year to pay a $100,000 statutory penalty after the court found that the city violated the state public records act.

They paid $438K for fighting the request for seven years. They paid an additional $100K penalty because they were have found to violated the law. They did not pay for "mistakes", at least not mistakes in good faith.

Post reply on HN