Live data from Hacker News

The City of Seattle accidentally gave me 32M emails for $40 (2018)

mchap.io

111–120 of 230 posts

Re: The City of Seattle accidentally gave me 32M emails for $40 (2018)

#111
post #100

Earlier quoted context omitted.

This was definitely not my first rodeo and I like to think I've done a good job in acting in good faith in future similar instances [1] for example. Every time I've reported something, the other side acts differently every single time. Sometimes they're friendly, sometimes they put out obvious traps ("prove it that you found HIPAA sensitive info"), and sometimes they're just thankful it didn't go worse. You gotta rea…

I get it. But as someone who has worked a lot of helpdesk and customer service roles in my life, all I can do is whinge. These departments clearly do not have the processes or experience to respond correctly, so the brunt of the pain is going to fall on inexperienced and overworked public servants whose whole job is to be harassed by citizens. So please be nice!

Heh, the city called me a good samaritan for acting in good faith, plus completely redid their entire process afterwards, including escalation paths to make this sort of thing less aggressive and conflict oriented in the future. So, uh, I'm honestly not sure what to say when things ultimately ended up better in the end.

And fwiw, I've worked at a high volume help desk too.

Re: The City of Seattle accidentally gave me 32M emails for $40 (2018)

#112
post #77

Wow, this person seems really annoying and entitled.

Annoying, no, but very much entitled.

As in, he (like everybody else) is legally entitled to have access to records our government is responsible for making available, in the interest of transparency and accountability. Be thankful there are people out there volunteering to do the testing necessary to make sure our rights are working properly.

Re: The City of Seattle accidentally gave me 32M emails for $40 (2018)

#113
post #65

The real point of the story: Security researchers get FUCKED, hard. They're treated as evil bad hackers who will destroy everything. Why? Cause they made people look bad. The real answer? It was provided as public records. So slap-em into public. Fuck 'em. (Or, sell it to a gray hat data broker and get paid.)

Case in point: https://www.infosecurity-magazine.com/news/missouri-governor...

Re: The City of Seattle accidentally gave me 32M emails for $40 (2018)

#114
post #22

The most interesting part of this story is the potential legal risk of holding onto the records that were improperly disclosed. Had the author not notified the city that they had royally screwed up by divulging far more sensitive information than they had realized, they likely would have never realized the error, and he would have been free to do whatever he liked with the data. But once he notified them of their err…

> They thanked me for bringing the situation to their attention and all that, but the mood of the call was as if both parties had a knife behind their back. Somewhere towards the end of the call, I asked them if it was okay to keep the emails. Why not at least ask, right? >...This isn't something I'm even remotely cool with, so we ended the call a couple minutes later, and agreed to have our lawyers speak going forwa…

As it should be- think of the possible abuse if a government entity could send you private information 'by mistake', and then be able to mandate a search of your property for that info.

Re: The City of Seattle accidentally gave me 32M emails for $40 (2018)

#116

Earlier quoted context omitted.

You cannot get a warrant without probably cause that a crime has been committed. So asking for a warrant to search your computer is literally asking to be charged with a crime. IANAL, but demanding a prosecutor and judge be involved when dealing with an IT department is really dumb. If you can just agree with their legal team (and your lawyer) on the stipulations of the search and confirmation, you can't be charged w…

> You cannot get a warrant without probably cause that a crime has been committed. So asking for a warrant to search your computer is literally asking to be charged with a crime. That is just completely 100% wrong. Warrants are not (or at least, shouldn't be, your mileage may vary based on your local authorities) issued like candy. Prosecutors and judges issue warrants when there is probable cause to search in the ev…

WA state says you cannot issue a warrant without reference to a specific crime: https://app.leg.wa.gov/RCW/default.aspx?cite=10.79.035

So regardless, by demanding a warrant you would be insisting that the IT Department declare a crime had been committed in the first place. Even if you wanted to defend the legality of you holding onto ill-gotten data, why would you want to get the prosecutor involved at all? Getting a warrant on your property is the worst possible outcome here.

I agree you shouldn't do anything without a lawyer closing looking over the stipulation. But demanding a warrant is probably the dumbest available option. Especially when they already know you have the thing they are looking for!

Re: The City of Seattle accidentally gave me 32M emails for $40 (2018)

#117
For all emails sent to/from any Seattle owned email address in 2017, please provide the following information:

1. From address 2. To address 3. bcc addresses 4. cc addresses 5. Time 6. Date

Is this really a reasonable request that the government is expected to answer? Doesn't this expose a bunch of private information about government employees and the people they interact with? I understand this post (and apparently the law) takes this as completely normal thing, but it seems really weird to me.

Some examples:

* exact times people are getting in/out the office (eg. the time in the morning when a person first answers an email from their boss)

* full information about holidays taken by all employees (eg. days/weeks during which no emails are sent)

* friendships or relationships (eg. any communication between employees that doesn't follow from the hierarchy or from team delineations)

* information from criminal investigations (eg. an investigator sending an email to the parking fine department probably means one of the cases they're working on is related to parking fines)

This all seems a huge privacy leak? Should this stuff even be called "metadata" if so much can be derived from it?

Re: The City of Seattle accidentally gave me 32M emails for $40 (2018)

#118
post #77

Wow, this person seems really annoying and entitled.

Really? Do you agree this data should cost 30 million dollars to retrieve? Do you agree that 10tb of storage should cost 1000s of dollars? Would you be mad if someone sent you data you did not ask for and then threatened legal action if you did not grant full access to your personal data in return? I don't agree with all his takes. It's absurd he toyed with the idea of asking to keep this data, for instance... But I…

Sounds like he was fucking with people who work for Seattle and then acting indignant and affronted when he gleaned even the slightest bit of irritation or frustration in response.

Re: The City of Seattle accidentally gave me 32M emails for $40 (2018)

#119

Earlier quoted context omitted.

> You cannot get a warrant without probably cause that a crime has been committed. So asking for a warrant to search your computer is literally asking to be charged with a crime. That is just completely 100% wrong. Warrants are not (or at least, shouldn't be, your mileage may vary based on your local authorities) issued like candy. Prosecutors and judges issue warrants when there is probable cause to search in the ev…

WA state says you cannot issue a warrant without reference to a specific crime: https://app.leg.wa.gov/RCW/default.aspx?cite=10.79.035 So regardless, by demanding a warrant you would be insisting that the IT Department declare a crime had been committed in the first place. Even if you wanted to defend the legality of you holding onto ill-gotten data, why would you want to get the prosecutor involved at all? Getting a…

>Especially when they already know you have the thing they are looking for!

I disagree, the conversation went that they wanted to Verify it was deleted. That is totally out of grounds for the city to want. The data in this case is contraband, but it was leaked by the city, and hosted by the city in the FOIA portal.

It totally misses the point, you should never consent to a search to verify you don't have it, especially to a third party. Ever. They want to poke and prod around, then it's a warrant and strict chain of custody. None of this third party forsenic firm stuff.

Re: The City of Seattle accidentally gave me 32M emails for $40 (2018)

#120
post #96

This is why city council member Dan Strauss, when going door to door campaigning, gives out his personal Gmail address rather than his city of Seattle address. Is this legal? It sure doesn't seem ethical

He's implicitly admitting that he conducts civic business via his Gmail account. That means his Gmail account contains public records and is thus subject to FOIA requests.

I'm not sure if city councilors are subject to such public scrutiny but it's still really stupid.

Post reply on HN