Live data from Hacker News

The City of Seattle accidentally gave me 32M emails for $40 (2018)

mchap.io

31–40 of 230 posts

Re: The City of Seattle accidentally gave me 32M emails for $40 (2018)

#31

If you can't load the blog: - He FOIA'd all metadata of emails to and from the City of Seattle. - The city IT department pushed back, saying that their policy was to hand-review each email for privacy, and this was 32m emails. - They later acquiesced and just dumped all of the meta-data into files and sent it over - They didn't realize email-preview was also meta-data, which included the first 256 char of each email.…

> The job seems awful

How hard can it be to do a sanity check of the metadata?

Re: The City of Seattle accidentally gave me 32M emails for $40 (2018)

#32
post #14
post #13

This is an old post from 2018

Yep, someone in a separate thread was curious about similar work so I figured I'd post it again. Edited the title to make it clear it's from 2018.

Specifically, someone had asked how a "single line of Powershell" could be useful in a FOIA request (in the marshell thread I think). This is the example.

Re: The City of Seattle accidentally gave me 32M emails for $40 (2018)

#33

If you can't load the blog: - He FOIA'd all metadata of emails to and from the City of Seattle. - The city IT department pushed back, saying that their policy was to hand-review each email for privacy, and this was 32m emails. - They later acquiesced and just dumped all of the meta-data into files and sent it over - They didn't realize email-preview was also meta-data, which included the first 256 char of each email.…

[deleted]

Re: The City of Seattle accidentally gave me 32M emails for $40 (2018)

#34
post #22

The most interesting part of this story is the potential legal risk of holding onto the records that were improperly disclosed. Had the author not notified the city that they had royally screwed up by divulging far more sensitive information than they had realized, they likely would have never realized the error, and he would have been free to do whatever he liked with the data. But once he notified them of their err…

> and he would have been free to do whatever he liked with the data.

I think that's a pretty strong assertion.

Re: The City of Seattle accidentally gave me 32M emails for $40 (2018)

#35

If you can't load the blog: - He FOIA'd all metadata of emails to and from the City of Seattle. - The city IT department pushed back, saying that their policy was to hand-review each email for privacy, and this was 32m emails. - They later acquiesced and just dumped all of the meta-data into files and sent it over - They didn't realize email-preview was also meta-data, which included the first 256 char of each email.…

I suppose this is why some gov officials use weird aliases for emails. It’s not on the up and up but it avoids disclosing potentially embarrassing or illegal activities…

Re: The City of Seattle accidentally gave me 32M emails for $40 (2018)

#36
post #2

Hah, that's a much simpler title. :)

How do I find more information out about FOIA requests?

Also, in your post I think you mentioned "FOIA junkies" or something along those lines, this implies to me there's a community of people who understand this stuff and talk about it. That sounds really interesting to join. Is there a subreddit or something?

Re: The City of Seattle accidentally gave me 32M emails for $40 (2018)

#37
post #22

The most interesting part of this story is the potential legal risk of holding onto the records that were improperly disclosed. Had the author not notified the city that they had royally screwed up by divulging far more sensitive information than they had realized, they likely would have never realized the error, and he would have been free to do whatever he liked with the data. But once he notified them of their err…

> They thanked me for bringing the situation to their attention and all that, but the mood of the call was as if both parties had a knife behind their back. Somewhere towards the end of the call, I asked them if it was okay to keep the emails. Why not at least ask, right?

>...This isn't something I'm even remotely cool with, so we ended the call a couple minutes later, and agreed to have our lawyers speak going forward.

Honestly, the city was acting in very good faith, but OP decided to troll them and refused to cooperate with the third party auditor. To this day we have to kind of accept the affidavit he signed that data is gone.

Re: The City of Seattle accidentally gave me 32M emails for $40 (2018)

#38
post #4

wow! in Europe, this request 1. From address 2. To address 3. bcc addresses 4. cc addresses 5. Time 6. Date correlates person-related information (who was in contact with whom at which date and time). storing it, let alone processing it is only admissible on a need to know basis. even if you jump through the hoop of an officer acting on behalf of Seattle is not a person any more, which is a stretch already, even then…

So, email addresses kind of suffer from the same problem as Social Security numbers - they were never designed to be private information! But they have been forced to fit that role. And, you know, cities have no problem giving out personal information all of the time. Your personal address, or whoever owns property in a city, is a matter of public record. And so the city has no problem handing out your name and addre…

> So, email addresses kind of suffer from the same problem as Social Security numbers - they were never designed to be private information!

I would have considered my personal From and To associations to be private information since my email address started with ...utzoo!

Re: The City of Seattle accidentally gave me 32M emails for $40 (2018)

#39
post #26

Earlier quoted context omitted.

The author's email is at the bottom of their post if you need to reach them to tell them off about their failings from 5 years ago.

Its the author, and idk if the snide extra bit about informing them about their failings from 5 years ago makes any sense. This was posted today.

Bro the date right under the title on the article says "March 27, 2019"

Re: The City of Seattle accidentally gave me 32M emails for $40 (2018)

#40
post #22

The most interesting part of this story is the potential legal risk of holding onto the records that were improperly disclosed. Had the author not notified the city that they had royally screwed up by divulging far more sensitive information than they had realized, they likely would have never realized the error, and he would have been free to do whatever he liked with the data. But once he notified them of their err…

> Had the author not notified the city that they had royally screwed up by divulging far more sensitive information than they had realized, they likely would have never realized the error...

That would be incredibly risky, though. If the city did later realize their error, they would likely assume malice on the part of OP for not telling them about it. If we think his treatment after telling them wasn't great, imagine how bad it would be otherwise.

> ... and he would have been free to do whatever he liked with the data.

I don't think that necessarily follows. He could -- and likely would -- get in a lot of trouble for publishing the extra data.

Post reply on HN