Live data from Hacker News

The City of Seattle accidentally gave me 32M emails for $40 (2018)

mchap.io

201–210 of 230 posts

Re: The City of Seattle accidentally gave me 32M emails for $40 (2018)

#201
post #22

The most interesting part of this story is the potential legal risk of holding onto the records that were improperly disclosed. Had the author not notified the city that they had royally screwed up by divulging far more sensitive information than they had realized, they likely would have never realized the error, and he would have been free to do whatever he liked with the data. But once he notified them of their err…

> I think there is a pretty good legal argument that there are categories of data (e.g. trade secrets) that a person can be ordered not to possess.

Agree. You can’t un-ring a bell. You can’t un-tell a secret.

Re: The City of Seattle accidentally gave me 32M emails for $40 (2018)

#202
post #22

The most interesting part of this story is the potential legal risk of holding onto the records that were improperly disclosed. Had the author not notified the city that they had royally screwed up by divulging far more sensitive information than they had realized, they likely would have never realized the error, and he would have been free to do whatever he liked with the data. But once he notified them of their err…

The US doesn't, as far as I'm aware, have any encoded right to one's personal data. Furthermore, copyright in the US does not extend to databases, such as a list of records. So there isn't a clear legal regime under which to prosecute someone for holding onto records they recieved improperly. Physical property and even some coyrightable data would be a different story.

The City said they were going to go for a fraud and abuse case. I have 0 experience with that subject, but I would assume there would have to be an action, or intent of an action, to make it a crime. I wonder if the data simply existing on a hard drive would be enough to convict. Now that I think about it, I don't think I have a strong moral conviction against a judge ordering someone to delete data that contains sensitive information they received in error. Jail time and a fine? Absolutely not. Forcing them to delete (and confirming deletion)? Yes.

Re: The City of Seattle accidentally gave me 32M emails for $40 (2018)

#203

Earlier quoted context omitted.

This is not how the law works. If enriched uranium shows up at your door, you don't just get to hold onto it just because someone screwed up.

Uranium is illegal to possess and is a tangible object. Data is intangible and can be copied. If Matt gave into a request to search his hard drive, said search could extend into other devices, online accounts, etc. And that wouldn't even prove that he no longer possesses the data

Uranium is totally legal to possess.

Re: The City of Seattle accidentally gave me 32M emails for $40 (2018)

#204

Argh. I used to work a lot in open data, including a stint within the open data department of a major city government. This kind of behaviour does nothing to advance the cause. It just perpetuates the belief that open data and FOI are massive waste of time and resources and open legal risks for no good reason. I'm also pretty surprised that people think email metadata from government is legitimate open data. Do you t…

> I'm also pretty surprised that people think email metadata from government is legitimate open data. Do you think it should be public how many times you have emailed government and gotten a response, and to which departments? I don't. on the surface i agree with you. beneath the surface, other governmental units already possess all the metadata for your emails/phone calls, it would be a weird bit of asymmetry to say…

>it would be a weird bit of asymmetry to say it’s okay for them to have your metadata but not for you to have their metadata.

But that's not what this is. This is saying it's ok for them to give your metadata out to anyone who asks.

Re: The City of Seattle accidentally gave me 32M emails for $40 (2018)

#206

Earlier quoted context omitted.

How so? What lawyer would insist on their client getting searched via a warrant?

> If you can just agree with their legal team (and your lawyer) on the stipulations of the search and confirmation, you can't be charged with further crimes if they find anything ("fruit of the poison tree"). This part is completely wrong. “Fruit of the poison tree” only counts if the original search was illegal. If you let them search for something specific, nothing is stopping them from using anything they find, ev…

[dead]

Re: The City of Seattle accidentally gave me 32M emails for $40 (2018)

#207
post #8
post #4

wow! in Europe, this request 1. From address 2. To address 3. bcc addresses 4. cc addresses 5. Time 6. Date correlates person-related information (who was in contact with whom at which date and time). storing it, let alone processing it is only admissible on a need to know basis. even if you jump through the hoop of an officer acting on behalf of Seattle is not a person any more, which is a stretch already, even then…

In the US emails to and from government workers are generally considered public record. It's important for transparency.

Washington State, in particular, has a very broad public records act.

Re: The City of Seattle accidentally gave me 32M emails for $40 (2018)

#208

That was a fun read. Having worked as a sysadmin on the other end I can almost guess how his initial request was received. As many others do they only read part of his request and were dumbfounded by the scale of it. So in their minds he was requesting way too much information and they probably spent days at the water cooler laughing at this guy under wrong pretences. Eventually someone realized their misinterpretati…

I'm also a sysadmin who unfortunately found that attitude familiar. Some IT groups really do create these toxic environments where it's common to make fun of the people they serve.

I certainly don't expect IT groups to bend over backward for every request or be polite in the face of real abuse, but the toxic shit that is said at the water cooler is never that. It's literally insulting people's intelligence or taking pleasure in people's pain, especially if it involves exercising their power over users.

Re: The City of Seattle accidentally gave me 32M emails for $40 (2018)

#209
post #111

Earlier quoted context omitted.

I get it. But as someone who has worked a lot of helpdesk and customer service roles in my life, all I can do is whinge. These departments clearly do not have the processes or experience to respond correctly, so the brunt of the pain is going to fall on inexperienced and overworked public servants whose whole job is to be harassed by citizens. So please be nice!

Heh, the city called me a good samaritan for acting in good faith, plus completely redid their entire process afterwards, including escalation paths to make this sort of thing less aggressive and conflict oriented in the future. So, uh, I'm honestly not sure what to say when things ultimately ended up better in the end. And fwiw, I've worked at a high volume help desk too.

That's basically the opposite of the City of Chicago who did pretty much everything they could do behind the scenes to frustrate and ridicule you just for asking for some public information.

Re: The City of Seattle accidentally gave me 32M emails for $40 (2018)

#210
post #203

Earlier quoted context omitted.

Uranium is illegal to possess and is a tangible object. Data is intangible and can be copied. If Matt gave into a request to search his hard drive, said search could extend into other devices, online accounts, etc. And that wouldn't even prove that he no longer possesses the data

Uranium is totally legal to possess.

With many restrictions.
Post reply on HN