Live data from Hacker News

Launch HN: Optery (YC W22) – Remove your personal info from the internet

news.ycombinator.com

61–70 of 150 posts

Re: Launch HN: Optery (YC W22) – Remove your personal info from the internet

#61

Earlier quoted context omitted.

I dont think it will be deep in the google index, if one knows where to look https://www.judyrecords.com/

They disabled search on the site due to some concerns from state AGs, so it's useless at the moment.

We submit complaints to the FTC and state attorney generals offices for non-compliant data brokers all the time. They don't move very fast, but its so great when they finally take action. I highly recommend anyone experiencing pushback from data brokers to submit complaints to the FTC and your state attorney general's office immediately. It does help. We have a little more information about this on the Optery Help Desk here:

https://help.optery.com/en/article/coverage-limitations-for-...

Re: Launch HN: Optery (YC W22) – Remove your personal info from the internet

#62
post #56
post #16

Earlier quoted context omitted.

Anyone can submit opt outs, with, or without, a service like ours. The vast majority of data brokers do remove the information after an opt out request is submitted. Unfortunately, over time, many data brokers start adding it back. The CCPA (California's Privacy Law) permits a data broker to stop honoring an opt out after 12 months. To answer your question though, yes, in order to get these companies to remove your i…

> in order to get these companies to remove your info, you have to submit an opt out that identifies who you are. I wonder if you could build an opt-out service or protocol where you share a hash of your personal information instead of the info itself. With the hash you can identify matching records but you cannot create a record from the hash. If Optery bought full datasets from databrokers, it could use a hash to i…

> With the hash you can identify matching records but you cannot create a record from the hash.

I always chuckle when I see someone saying this. A buddy of mine (email marketer) tried to convince me that his 50 million large email database is "well protected" because they are using "industry standard md5 encryption". Of course its not encryption but rather hashing. He was so sure of his, erm, encryption, that he send me the whole database and said "here, crack it".

I found a large hacked Facebook email database online, run few python scripts to weed us most combinations of usernames (name+numbers, numbers+name, numbers+some random chars, etc) and some 1000 generic email domains names (like gmail.com, yahoo.com, etc). It took my regular i9 five days to go thru the whole 50M of md5s and compare each combination of usernames + domains names. Oh boy his shock when I returned some 70% "unencrypted" plain text emails back to him :)

Bottom line is, if there is some "industry standard" of hashing data, then there are ways to unhash it. Yes in many cases it may be in millions of years to circle thru all possibilities, but if your standard is first name + last name + email address (and all caps), then you can easily plug database of names and download millions of email records online and narrow down your hashing search greatly.

Re: Launch HN: Optery (YC W22) – Remove your personal info from the internet

#63
post #16
post #3

I don't see how this can work at a fundamental level. You're telling me that to remove my info I have to essentially give (through your service) all these companies & data brokers my info so they can opt me out, and actually trust them that they'll do so? If anything, opting out is a signal that you may actually be of more interest to them than not doing anything. If these companies can also infer that the request is…

Anyone can submit opt outs, with, or without, a service like ours. The vast majority of data brokers do remove the information after an opt out request is submitted. Unfortunately, over time, many data brokers start adding it back. The CCPA (California's Privacy Law) permits a data broker to stop honoring an opt out after 12 months. To answer your question though, yes, in order to get these companies to remove your i…

The CCPA (California's Privacy Law) permits a data broker to stop honoring an opt out after 12 months.

Does this mean users have to keep opting out every 12 months? If yes, that sounds...dumb, isn't it? Maybe I am not understanding this correctly, is there a reason behind this 12 month period? Even if they wanted to let data brokers add the data back, 12 months seems too short a time. What am I missing?

Why is every bad thing opt out instead of opt in? This is so backwards...

Re: Launch HN: Optery (YC W22) – Remove your personal info from the internet

#64
post #35

I have this problem, except that my phone number is associated with my old company. So I get dozens of spam phone calls every week from sales people believing that they are calling the switchboard for the company, and asking to be connected to some random executive. Would Optery be able to help with that?

Yes – Optery definitely helps with this, but it’s not a silver bullet yet. If your phone number is already out there circulating, I would recommend:

(a) Start by opting out of as many of the data brokers as you can, in particular the B2B contacts data brokers that are most likely the source of these unwanted phone calls like RocketReach, ContactOut, Clearbit, Hunter.io, LeadIQ, ZoomInfo, etc. Many of these data brokers Optery already covers, but others we are still in the process of adding to coverage.

(b) You can use Optery to opt out of a large chunk of these data brokers (200+ as of today), but you might need to supplement that with your own effort until we can catch up to the rest of them. We’re constantly adding more data brokers to our list of covered every month.

(c) Update your visibility settings on LinkedIn. A lot of information gets leaked out onto the web from LinkedIn, and in particular into the B2B contacts data brokers mentioned above: https://www.linkedin.com/help/linkedin/answer/a523134/visibi...

(d) Do not include your phone number or title on your email signature – many of the B2B contacts data brokers have data co-ops where all of their millions of customers share contacts and they parse through the email signatures in your email

(e) After you have done all of the above, and have reduced the footprint and presence of your phone number in these different places, change your phone number.

Re: Launch HN: Optery (YC W22) – Remove your personal info from the internet

#65
post #63
post #16

Earlier quoted context omitted.

Anyone can submit opt outs, with, or without, a service like ours. The vast majority of data brokers do remove the information after an opt out request is submitted. Unfortunately, over time, many data brokers start adding it back. The CCPA (California's Privacy Law) permits a data broker to stop honoring an opt out after 12 months. To answer your question though, yes, in order to get these companies to remove your i…

The CCPA (California's Privacy Law) permits a data broker to stop honoring an opt out after 12 months. Does this mean users have to keep opting out every 12 months? If yes, that sounds...dumb, isn't it? Maybe I am not understanding this correctly, is there a reason behind this 12 month period? Even if they wanted to let data brokers add the data back, 12 months seems too short a time. What am I missing? Why is every…

Here's the exact text from Section 1798.135(a)(5) of the CCPA: "For a consumer who has opted-out of the sale of the consumer’s personal information, respect the consumer’s decision to opt-out for at least 12 months before requesting that the consumer authorize the sale of the consumer’s personal information."

Data brokers can often have a very liberal interpretation of what it means for the consumer to "authorize" the sale of their personal information. I would guess 99% of data sales were never actually “authorized” by the consumer to begin with, and are usually done through some backdoor implicit authorization that the consumer has no knowledge of whatsoever.

> Does this mean users have to keep opting out every 12 months? If yes, that sounds...dumb, isn't it? Maybe I am not understanding this correctly, is there a reason behind this 12 month period? Even if they wanted to let data brokers add the data back, 12 months seems too short a time. What am I missing?

Although it often causes harm and is often considered evil, there is a lot of economic value that results from the free flow of data. U.S. lawmakers recognize this and its partly why they’re so reluctant to pass strict privacy laws like they have in Europe. The other reason is that lobbyists for deep pocketed tech companies water down privacy laws significantly before they can pass. Even with the 12 month expiration, the CCPA is the strictest privacy law in the U.S., and most U.S. citizens have basically no data privacy rights whatsoever.

How long a data broker honors an opt out is highly variable by the data broker. But yes, in general, you have to continue monitoring these companies and re-submitting opt out requests over time, that's what Optery does with its ongoing scanning and removal technology. We have a little more info on this topic here:

https://help.optery.com/en/article/when-my-data-is-removed-f...

Re: Launch HN: Optery (YC W22) – Remove your personal info from the internet

#66
Have you thought of a family plan for a family and kids all living at one address? Also niche organizational plans like police departments, law practices, therapists, hospitals, etc? Or ones for lawyers, therapists, etc to buy for themselves? I know a lot of those people just want their name only associated with their professional office addresses, never a home address, and their are rating and professional directories that they do want to stay on.

Also people trying it out might give fake names to start, you should let people be able to change their name in settings vs. making it uneditable after signup.

Also another things is email & email domain privacy. Some nerds & organizations have an entire domain as their email set that they don't want in directories, marketing spam lists, etc either, kind of like https://haveibeenpwned.com/

Re: Launch HN: Optery (YC W22) – Remove your personal info from the internet

#67
post #42

Earlier quoted context omitted.

You can have your old HN comments deleted by emailing the mods. There's limits to how much they'll delete, but they definitely don't want you to get into trouble over something you posted on HN.

>There's limits to how much they'll delete Yes it's a huge problem. Many of us (or maybe just me?) would not have been so candid on HN had we known our comments would be indelibly preserved forever with no option for deletion. The stated reasons for this policy I've seen from 'dang amount to "we don't like the look of a bunch of comment chains with [deleted] everywhere" which I find insulting. I have a suspicion that…

They are perfectly able to add features to the site, and would absolutely add a feature if they thought it was as important as you think this one is.

I get the feeling you've never actually attempted to engage with them in good faith, because they're willing to put in quite a lot of work to dissociate you from your comments while leaving the comment intact. In case you missed it, https://news.ycombinator.com/item?id=23623799 is linked from the FAQ.

Re: Launch HN: Optery (YC W22) – Remove your personal info from the internet

#68
Do you have data on the efficacy of your solution?

How many fewer spam and phishing attempts do your customers receive vs non-customers? What is the rate of successful identity theft against your users vs a similarly technical and privacy conscience control group?

I love this idea, but you’re asking me to spend more money a month than many streaming services. To command that type of price you’re going to need to show actual data on risk reduction and not hand wave some claims about spam and phishing. So I wonder who your target customer is? For a higher profile person spending $300 a year to automate some opsec is trivial. For broader consumers perhaps less so, especially without hard data on efficacy.

Can you point to quantifiable effects of your service?

Re: Launch HN: Optery (YC W22) – Remove your personal info from the internet

#69
post #52

I was excited to see a service like this. I hate data brokers and have tried to go to somewhat-great (good?) lengths to obfuscate my personal info, including using e-mails that expose services selling/giving out my info. I signed up and was surprised to see 202 different brokers were offering my info. However, when I looked at the "More Info" drop-down on each, I noticed the last name was incorrect. So I looked at my…

Thanks for trying it out. One thing to clarify is that we list out each data broker we cover, regardless of whether or not your profile was found or not. We do this partly to support our Free Basic users that use the data broker links in the dashboard to QA and verify their own opt out work (or the opt out work of other services). So just because you see a data broker in your dashboard, does not mean we are implying…

This is super sketchy. Even the modal you describe is misleading:

>> “External links help with self-service opt outs and provide visibility into where your info is posted online, but are not always perfect.”

That is 100% misleading when you are linking to every data broker regardless of whether or not someone is in their database.

Re: Launch HN: Optery (YC W22) – Remove your personal info from the internet

#70
post #16
post #3

I don't see how this can work at a fundamental level. You're telling me that to remove my info I have to essentially give (through your service) all these companies & data brokers my info so they can opt me out, and actually trust them that they'll do so? If anything, opting out is a signal that you may actually be of more interest to them than not doing anything. If these companies can also infer that the request is…

Anyone can submit opt outs, with, or without, a service like ours. The vast majority of data brokers do remove the information after an opt out request is submitted. Unfortunately, over time, many data brokers start adding it back. The CCPA (California's Privacy Law) permits a data broker to stop honoring an opt out after 12 months. To answer your question though, yes, in order to get these companies to remove your i…

I think it can be a great service but have the same question as above.

Why did you opt-out for VC? This seems to be a perfect candidate for a profitable and sustainable business because you don't really need a complicated infra or another 2 years to build an enterprise grade product. (unless I am missing something).

Thank you!

Post reply on HN