Live data from Hacker News

The City of Seattle Accidentally Gave Me 32M Emails for $40

mchap.io

121–130 of 239 posts

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#121
post #11

This whole exercise seems more damaging than constructive, and I don't really like the author's smug tone, as if he deserves praise.

Disagree. Obviously there was a bug in the system, the author simply uncovered it. I'd rather have a smug white/grey hat than a malicious black hat. Now the system is all the more secure thanks to his actions.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#122

Earlier quoted context omitted.

Because private tech companies fight like mad to avoid paying taxes to public city operations? Citizens too, probably. Nobody likes taxes. And the best/brightest tech workers gravitate to the higher private salaries. It’s not a technical problem - those are easier.

I live in DC, land of the professional Fed. At the absolute highest level and after adjusting for location, the most a DC Fed could earn is $164,200. No surprise that anyone with serious technical talent--and by extension, market value--doesn't want such a job.

True, but consider some folks are content with a 38 hour week, may have automated large chunks of their job, and find the demands of working for a big public sector organization far less than that of a similar role in a private sector tech company.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#123

Earlier quoted context omitted.

FWIW I think you should not have done that, though I understand the temptation. At the first indication that the data was not what you requested and contained more than you - or they - bargained for you should have stopped looking at it and alerted both the sender and the relevant data protection authorities in so far as those are a functioning entity where you live to tell them they have an 'accidental disclosure' o…

If someone accidentally sends me information I owe them no duty of confidence. I'm under no obligation to notify them. It is entirely their problem. The idea that the OP is at fault for looking at data which the city had already published has no basis in law.

Ethics aside, ideally you're right. In reality though you're wrong because you just described a key function of the CFAA

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#124
post #48

I'm very surprised they gave out this information. I'm not talking about the mistake, I mean the actual request. In the UK I don't think you could even get a production order for this. Like, it's effectively getting Communications Data simultaneously against thousands of people not suspected of any crimes?? Like, do people know that by emailing their local government their email address is now free for scammers to re…

I have never assumed that an email address I gave the government would be protected. I would also not assume that the contents of any email I sent would be in any way protected either. The government is collectively owned. Your police record, where you live, who you're married to, and whether or not you voted last election are publicly available. I would rather all of that be protected in some way, but I think it's c…

> I have never assumed that an email address I gave the government would be protected. I would also not assume that the contents of any email I sent would be in any way protected either.

That's because you're not corresponding with case officers and police officers.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#125
post #43

A few years ago I found a random SSD on the ground while on a walk with my son. The drive contained unencrypted records which squarly fall under HIPPA. I also did the right thing and returned it to the proper owner and told them about how their mdb files were readable by anyone. The same exact thing happened. They thanked me and then their lawyers nicely asked me to clone my hard drive and sign a bunch of shit. It wa…

Handling these kinds of things anonymously is the only reasonable way to protect yourself.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#126
post #41

Somewhat related, I'm constantly shocked (maybe I shouldn't be anymore) at the tech ineptitude of cities that are supposed to be big tech hubs. I live in Seattle, and my regular tech complaint is we can't get the buses connected to an app that is accurate within +-10 minutes. I know it doesn't sound like much, but how much tech brainpower is here, and why isn't that tech shining more clearly?

Have you used the OneBusAway app? It's accurate for the buses I take. Is it inaccurate for your routes?

OBA, Transit, Apple Maps, and King County Trip Planner all use the same back end data sources (though Transit adds users who are volunteering their location with the Go feature in its app) so they should all be similar to each other.

Ever since the major overhaul of data in mid-2015 that tried to fix the "ghost bus" problem (a bus would show as being on the wrong trip pair) and the "never-ending terminal" problem (arrival times for stops very near a route's terminal would show as many minutes delayed or early until the bus actually started moving), I've been quite pleased with the quality of real-time data.

There are always going to be inaccuracies, though. At peak, Sound Transit / OneBusAway are trying to track a couple thousand vehicles across many miles in unpredictable traffic and weather. That it works at all is a minor miracle in my eyes.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#127
post #83
post #80

Earlier quoted context omitted.

I don't think it's good enough to say « it's still on the shoulders of the city for choosing the vendors ». If I write a piece of software which is technically capable of meeting its requirements if you read the manual carefully enough, but in practice the intended users can't figure out how to do so, that piece of software is no good. Similarly if the market is in principle providing IT vendors who are capable of pr…

Do you have a viable method to fix the problems you describe? If not, then we're still left with it being on the shoulders of the city. Ultimately, it's really hard to police that the vendors don't make crap solutions. If the market fails to figure out which are crap, the market may have failed, but I don't have any ideas that would succeed better. Edit: and let me say that I posited that the issue isn't market force…

Principally: start punishing the corrupt vendors; don't assume that reputation mechanisms will ensure that non-corrupt ones will eventually outcompete the corrupt ones.

Just as you have to build software for the users you have not the users you feel you deserve, we need a service industry that works for the service-commissioning agents we have.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#129
post #123

Earlier quoted context omitted.

If someone accidentally sends me information I owe them no duty of confidence. I'm under no obligation to notify them. It is entirely their problem. The idea that the OP is at fault for looking at data which the city had already published has no basis in law.

Ethics aside, ideally you're right. In reality though you're wrong because you just described a key function of the CFAA

The city sent him a link with the intention he would download it, and he did. There's no crime there.

Having legally downloaded the data he looked at it. There's no crime there either.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#130

I'm very surprised they gave out this information. I'm not talking about the mistake, I mean the actual request. In the UK I don't think you could even get a production order for this. Like, it's effectively getting Communications Data simultaneously against thousands of people not suspected of any crimes?? Like, do people know that by emailing their local government their email address is now free for scammers to re…

The part I found even more strange is that people are sending their credit card numbers and other personal information through e-mail...

It's not strange, I too send my cc number and personal information through email because I consider the risk is sufficiently small. Likewise I told people who want to send me these information to just use email
Post reply on HN