Live data from Hacker News

The City of Seattle Accidentally Gave Me 32M Emails for $40

mchap.io

201–210 of 239 posts

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#201

Interesting dataset. Data like this can be used to identify strong links between contractors and government officials. One problem is that the metadata should have only contained anonymized entries for the email addresses of the counterparties of the Seattle.gov addresses, the article leaves this unclear. Another potential problem is that if a case of corruption or nepotism is identified that has not been passed to t…

release only anonymized data to protect the identities of the people working for the city

No thanks, that's an invitation to further corruption. Let me put that in context; recently a group of people were pushing a local authority to adjust its policy on the public release of arrestee's photos (aka mugshots). The group felt it was being selectively used for political purposes which the police and city council denied.

FOIA requests revealed that the authorities were unhappy with their public image as it related to law enforcement and decided to use mugshots as part of a social media campaign to change public perception. Can't have a social media campaign without any content, so people were arrested on nonsense charges that were subsequently dropped, so as to generate mugshots that could be publicized.

Thanks to the FOIA requests members of the public were able to confront the city council with specific names and dates of the people who drafted, approved, and implemented this policy, which information will also be central to future litigation on the topic.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#202

Earlier quoted context omitted.

I'm not sure I could disagree with you more. At least in the US there is a very strong expectation that communications between governmental employees is non-private except in very special circumstances. You'll note Matt says that the Police and Human Services departments have not responded, I'd guess thats not an accident because police records and personnel/medical records are largely exempt from FOIA requests. Furt…

> between governmental employees The request contains the names of private individuals through BCC and CC headers requested and exactly when they communicated with which government officials.

Fine by me.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#203
post #39
post #15

Earlier quoted context omitted.

For the ballpark estimate, I think they just wanted for the request to go away by quoting an insanely high price.

Long long term resident with a connection to local government They don't have a choice. Seattle IT is so underfunded that hands are tied because there isn't any resourcing. On one hand, you have to respond to all of these requests (and rightfully so, as it's the law.) On the other, you have no money for your department because it has no funding because the citizens didn't want to spend the money. The person who did t…

I heard from my city solicitor (whose office handles these FOIA requests) that one issue they have is that when people make requests of other city departments the default response is “go make a FOIA request” even in straightforward situations where they could easily give out the info directly (and used to, before the FOIA was passed). He said it’s annoying because it ends up putting a lot more workload on everyone.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#204
post #187

Earlier quoted context omitted.

Yes, though neither of those include who you actually voted for.

Reflect on the fact that 'didn't vote recently' is being used as we speak to suppress voting in the upcoming election. For non-US readers, every state has a Secretary fo State who rather than doing any kind of foreign affairs work like the federal office of that name, primarily oversees paperwork and particularly elections. These Secretaries of State are elected offices and highly politicized, since officeholders can…

I agree, and in that context, having name, party affiliation, and last_voted_at be public record would be the only way for an independent organization to gauge the impact per party of the disenfranchisement.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#205
post #51

Earlier quoted context omitted.

Also has a good example of hostile FOIA officers. I have filed about two dozen FOIA requests, and the vast majority were fine, though usually slow. Earlier this year one longstanding request of mine was rejected because they claimed the document I wanted was export controlled. Two months later I sent in an appeal where I showed that the document in question was not export controlled (I filed another FOIA with a separ…

Never attribute to malice that which is adequately explained by stupidity.

I used to abide by this until it dawned on me that malicious people often use stupid people as a cat's paw to conceal liability. A careless disregard for the truth is itself a form of dishonesty. This argument is laid out very effectively in philosopher Harry Frankfurt's delightful short book On Bullshit.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#206

To me, the most interesting thing in this entire post is the following: > Funny enough, in the middle of that question, my internet died and interrupted the call for the first time in the six months I lived in that house. Odd. It came back ten minutes later, and I dialed back into the conference line, but the mood of the call pretty much 180’d. I find that when strange things happen like this, they’re hardly coincide…

That's speculative without any proof and I personally think it is a weak point in the article. I do conference calls several times per week and the number of times I've been accidentally booted out of the room are numerous. Also, once they realized they had left the room of course they would continue to discuss the case and it is obvious they had to consider all possibilities, including the recipient releasing the in…

Also, once they realized they had left the room of course they would continue to discuss the case and it is obvious they had to consider all possibilities, including the recipient releasing the information to others, hence the 180.

You're saying the natural default behavior is to assume the worst about someone and draw a conclusion in their absence, as opposed to suspending discussion briefly while trying to get the person back on the phone? That seems like a very bad-faith approach to negotiation or discussion, given that the legal liabilities are something that were so easy to identify in advance.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#207

It's clear they didn't have expertise to do it, and I'm tired of reading people that know way more looking down at others over it and assuming they don't want to comply. If they hiding something and malicious, the end result wouldn't have been to send way too much, but I don't see the author realizing this fast enough.

If they hiding something and malicious, the end result wouldn't have been to send way too much

Wrong. Dumping a vast pile of irrelevant information at the last possible moment to obscure something embarrassing is a very common tactic in commercial litigation.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#208
post #43

A few years ago I found a random SSD on the ground while on a walk with my son. The drive contained unencrypted records which squarly fall under HIPPA. I also did the right thing and returned it to the proper owner and told them about how their mdb files were readable by anyone. The same exact thing happened. They thanked me and then their lawyers nicely asked me to clone my hard drive and sign a bunch of shit. It wa…

Handling these kinds of things anonymously is the only reasonable way to protect yourself.

Is there a service that supports this? Like, get it to a security researcher, wipe it from your drive, and have the security researcher handle returning the data and providing a basic education (or reporting the data loss to the appropriate authorities.)

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#209
post #149
post #48

Earlier quoted context omitted.

I have never assumed that an email address I gave the government would be protected. I would also not assume that the contents of any email I sent would be in any way protected either. The government is collectively owned. Your police record, where you live, who you're married to, and whether or not you voted last election are publicly available. I would rather all of that be protected in some way, but I think it's c…

Maybe you need the GDPR. When governments in the EU started digitizing their data like 20 years ago, it used to be that lots of personal data would end up published on official websites, either in the form of scanned PDFs that Google would gladly OCR and index, or in directly readable formats. Since then, the EU has cracked down on all of that, and you can no longer search for someone's phone number in order to get t…

GDPR largely does not regulate what governments do with data.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#210
post #48

Earlier quoted context omitted.

I have never assumed that an email address I gave the government would be protected. I would also not assume that the contents of any email I sent would be in any way protected either. The government is collectively owned. Your police record, where you live, who you're married to, and whether or not you voted last election are publicly available. I would rather all of that be protected in some way, but I think it's c…

> I have never assumed that an email address I gave the government would be protected. I would also not assume that the contents of any email I sent would be in any way protected either. That's because you're not corresponding with case officers and police officers.

Note that human services & the police dept. did not respond. Likely because they are exempt from foia requests.
Post reply on HN