Live data from Hacker News

The City of Seattle Accidentally Gave Me 32M Emails for $40

mchap.io

101–110 of 239 posts

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#101

Earlier quoted context omitted.

The part I found even more strange is that people are sending their credit card numbers and other personal information through e-mail...

Are you really shocked by this? I guess you have never worked on a corporate email system! People do this all of the time. 1) They don't realise email is not secure 2) When you explain point 1, all of the other solutions seem like too much hassle so they email anyway. 3) You can tell your customers not to email you CC numbers, you can even refuse them, but they will keep sending them

Or they think it's an acceptable risk... $50 liability limit.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#102

I'm very surprised they gave out this information. I'm not talking about the mistake, I mean the actual request. In the UK I don't think you could even get a production order for this. Like, it's effectively getting Communications Data simultaneously against thousands of people not suspected of any crimes?? Like, do people know that by emailing their local government their email address is now free for scammers to re…

The answer is that no, that request should not be filled, and certainly not in that way.

From a FOI POV, email is tough because it straddles a line between “record”, deliberative material and conversation. Everyone hates sharing email because it is always trouble.

In this case, they didn’t have a good process in place and nobody did a privilege or other review. The hint there is the police material — most police records are trivially made exempt from foi in most places.

But to your point, there are many categories of communication with government where there is literally no expectation of privacy. If you email the zoning board something, you should fully expect to see the entire email in a public record somewhere.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#103
FTA:

>Seattle's first response included a bit of gobsmackery that I’ve almost become used to

Brit here. I'm always amused that 'gobsmack' and its derived words are still used these days, more so across the Atlantic.

Roughly translated: lost for words, typically for a short time.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#104
post #100

Earlier quoted context omitted.

Yes, you are as far as I can see correct. The request should have been rejected as overbroad and against data privacy laws (in so far as they exist), or the purpose of the request could have been verified and then they might have seen whether or not there was another way to let the requester do their work without giving them the data they requested (see another comment of mine for one suggestion).

That's not how FOIA works. It's a good thing too. Government employees almost always fight FOIA requests. There aren't many subjective tools (e.g. overbroad) and you're certainly not required to say why you're making the request. Data privacy laws in the US are unfortunately minimal. The bigger problem comes from imbalance -- if the government and corporations have lists of names, people need them to in order to be a…

Commercial organizations at least are known to implement maximum allowed retention strategies, such as having their staff not keep archived email beyond three months, presumably so it doesn't embarrassingly show up when it's legally unfavorable. Not quite the same, but along the same lines.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#105

I find the writer to be a bit of a dick in his responses. Yes, the city IT may not be at the same level as Google engineers, but there’s no need to mock their ballpark estimates, and after the mistake there’s no need to be a jerk about it. Be forthright about the error. Consider being on the other side of this, due to a careless mistake the data for many people is exposed on a random strangers hard drive. Asking for…

Assuming the authors version of events to be true, I think he was being as reasonable as possible when confronted with obvious incompetence and hostility from public servants. This probably happens a lot in the world of FOIA.

I do want to recognize that not all local governments behave the way described. When I was recently called for jury duty, I discovered a vulnerability in the city's jury duty online portal that would've let anyone get the PII of anyone ever called for jury duty via that system. I immediately called the county IT department, and they took me very seriously and thanked me for the report. They later emailed me back to tell me they worked with the vendor to close the vulnerability. I was extremely impressed with their professionalism and wish that all local governments could be so responsive.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#106

Interesting dataset. Data like this can be used to identify strong links between contractors and government officials. One problem is that the metadata should have only contained anonymized entries for the email addresses of the counterparties of the Seattle.gov addresses, the article leaves this unclear. Another potential problem is that if a case of corruption or nepotism is identified that has not been passed to t…

I'm not sure I could disagree with you more. At least in the US there is a very strong expectation that communications between governmental employees is non-private except in very special circumstances. You'll note Matt says that the Police and Human Services departments have not responded, I'd guess thats not an accident because police records and personnel/medical records are largely exempt from FOIA requests.

Further, the idea that sleuths (amateur seems pejorative in this case) are working with city governments to battle corruption does not hold up to Matt's (or other journalists) experience. By and large the governments only provide the data because they are required to, and we have made sure they are required to by representative legislative action.

Had the IT dept. in Seattle not made an obvious mistake this would likely have not been a story at all and the data would have been an interesting data set for informed democratic functions.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#107

I'm very surprised they gave out this information. I'm not talking about the mistake, I mean the actual request. In the UK I don't think you could even get a production order for this. Like, it's effectively getting Communications Data simultaneously against thousands of people not suspected of any crimes?? Like, do people know that by emailing their local government their email address is now free for scammers to re…

The part I found even more strange is that people are sending their credit card numbers and other personal information through e-mail...

In practice, the bad guys are not getting credit card numbers by monitoring unencrypted plain text email connections. They're doing it by getting the information in bulk straight out of databases at the destination (either by hacking or by getting unscrupulous employees to sell them data dumps). My opinion is that the risk factor in sending a CC number over email is much smaller than the risk of giving it to the destination organisation in the first place. And even if you do get unlucky, as a consumer you don't usually end up out of pocket for fraudulent transactions on your card.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#109

Earlier quoted context omitted.

I'm curious what his actual legal exposure would have been if he hadn't folded. I feel like they should have offered to compensate the author for his time in their initial request - if someone wanted to perform forensic scans on my hard drives it would be a huge inconvenience.

Pretty massive. An accidental release where the party released to is known and unwilling to perform a remedial action can go anywhere from a slap on the wrist to a criminal investigation. That doesn't mean there will be a conviction, but de-escalation would seem to be a wise course of action in such cases.

De-escalation? Sure.

Allow a third-party forensics company hired and beholden to a presumed-hostile counterparty unfettered access to your hard drives because of their own lack of care or incompetence? Hell no!

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#110

I find the writer to be a bit of a dick in his responses. Yes, the city IT may not be at the same level as Google engineers, but there’s no need to mock their ballpark estimates, and after the mistake there’s no need to be a jerk about it. Be forthright about the error. Consider being on the other side of this, due to a careless mistake the data for many people is exposed on a random strangers hard drive. Asking for…

> Asking for an independent third party verification is reasonable.

Asking for it may be reasonable, demanding it certainly isn't. You can't demand that somebody gives a third party access to their hard drive.

First, it's completely unreasonable from a privacy aspect. Given the level of personal data most people store or process on their computers, it is even less reasonable than asking someone to have a third party dig through their house to "verify" that they don't have something.

Second, it's completely unreasonable because it's pointless against a malicious actor - they could have cloned the disk before deleting the data and there would be no way to detect it.

It does make sense only to confirm that the data wasn't accidentally left on the disk due to an insecure erasure method. When dealing with someone competent with computers, the proper solution (which they ultimately arrived at) is to have him describe the method he used to delete it, possibly ask him to verify it (e.g. via some form of "dd | grep"), and that's it.

Post reply on HN