Live data from Hacker News

CEO of data privacy company Onerep.com founded dozens of people-search firms

krebsonsecurity.com

71–80 of 160 posts

Re: CEO of data privacy company Onerep.com founded dozens of people-search firms

#71

Earlier quoted context omitted.

That is probably the bigger story right here. Not trusting scammy businesses is easy. Getting fooled by big name like Mozilla a different story.

Mozilla has never been trustworthy. The Mozilla Foundation is probably what most people are confusing it for, the nonprofit that actually cares, but Mozilla the corporation just wants money.

You’re partly right. MoCo only cares about money. MoFo though is/was Mitchell’s political slush fund. TBD how things will shake out once there is a permanent CEO but Mitchell is remaining chair of the foundation. She’s also got really deep ties to how MoCo is funded (google) so it’s likely the new CEO will be her puppet.

Re: CEO of data privacy company Onerep.com founded dozens of people-search firms

#72
post #38

Earlier quoted context omitted.

Related, proofpoint is notorious for this as well. They will block your mail server without cause, forcing you through their process of delisting. Pay and your problems magically go away. Proofpoint was consistently the only block hit.

Tbf putting up cash is a great signal for 'not a spammer'.

True, but not the only method. You’d be surprised how many spammers drop with greylisting enabled.

Re: CEO of data privacy company Onerep.com founded dozens of people-search firms

#73
post #34

Earlier quoted context omitted.

I had a suspicion these services actually do more harm than good, even if they're well intentioned and not actively running a data collection scheme. But this is really a chicken-egg situation. How do you tell companies to delete your information without telling them what identifies your information? It's in these companies' interest to make this as difficult as possible, so a solution based on data hashes is highly…

Ideally a regulator would intervene, demanding that the data provider prove that each person in their database has explicitly opted in. That should be really easy for these companies -- it's just another record to include in our files. If they can't prove it, they must delete all related data.

What does proof look like?

On past projects we've recorded the time the user submitted a from (with a checked consent checkbox), but this doens't feel like rigorous proof.

Re: CEO of data privacy company Onerep.com founded dozens of people-search firms

#74
post #34

Earlier quoted context omitted.

I had a suspicion these services actually do more harm than good, even if they're well intentioned and not actively running a data collection scheme. But this is really a chicken-egg situation. How do you tell companies to delete your information without telling them what identifies your information? It's in these companies' interest to make this as difficult as possible, so a solution based on data hashes is highly…

Ideally a regulator would intervene, demanding that the data provider prove that each person in their database has explicitly opted in. That should be really easy for these companies -- it's just another record to include in our files. If they can't prove it, they must delete all related data.

And when they autofill that value with 1, because they obviously got all of that data legitimately? Will consumers be asked to prove a negative?

Even test cases will run into data sharing issues.

Re: CEO of data privacy company Onerep.com founded dozens of people-search firms

#75
post #46
post #30

Earlier quoted context omitted.

It’s racketeering

this seems to fit the definition. In many cases, the potential problem may be caused by the same party that offers to solve it, but that fact may be concealed, with the intent to engender continual patronage. https://en.wikipedia.org/wiki/Racketeering

See also https://en.m.wikipedia.org/wiki/Worldcoin

Re: CEO of data privacy company Onerep.com founded dozens of people-search firms

#76
post #18

Earlier quoted context omitted.

I don't understand the logic. They're more private for admitting that they don't respect your privacy?

Microsoft and Google don't even try to hide the fact they will siphon your data, whether you like it or not. You can turn off some of the egregious siphoning, but that's about it. Mozilla meanwhile claims to be the champion of digital privacy, marketing Firefox as the private browser of choice along with a host of ostensibly privacy products such as VPN, all the while also siphoning data. Turning it all off requires…

I don't think that's what the word "private" means. It's not the same thing as "honest".

Compare the data. Mozilla may be less honest than Google and Microsoft (a premise I also disagree with), but they are demonstrably harvesting much less data.

Re: CEO of data privacy company Onerep.com founded dozens of people-search firms

#78
post #68

A not-so-secret dirty little secret is that many of the reputation management agencies also own many of the public records websites that publish mug shots, court records, and so on. When you hire them to remove that information from the internet it puts you into a cycle of being removed from one or two of their website and added to something else. You end up in a never-ending game of whack-a-mole. Complete with month…

Isn't this just a white-hat/black-hat hacker dynamic, except in this case the latter is legal?

Well, both hats ostensibly are at least doing real work (finding vulnerabilities).

Re: CEO of data privacy company Onerep.com founded dozens of people-search firms

#79
post #34

Earlier quoted context omitted.

I had a suspicion these services actually do more harm than good, even if they're well intentioned and not actively running a data collection scheme. But this is really a chicken-egg situation. How do you tell companies to delete your information without telling them what identifies your information? It's in these companies' interest to make this as difficult as possible, so a solution based on data hashes is highly…

Ideally a regulator would intervene, demanding that the data provider prove that each person in their database has explicitly opted in. That should be really easy for these companies -- it's just another record to include in our files. If they can't prove it, they must delete all related data.

Why not just outlaw data brokers entirely?
Post reply on HN