Live data from Hacker News

The City of Seattle Accidentally Gave Me 32M Emails for $40

mchap.io

131–140 of 239 posts

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#131
post #11

This whole exercise seems more damaging than constructive, and I don't really like the author's smug tone, as if he deserves praise.

The smug tone of the paid (with his taxes) government employees combined with their utter incompetence seems more inappropriate.

I find it constructive in that once again it is demonstrated that the narrative that we're governed by rational, competent people and that we should trust and respect our government is very much a mirage, and the 180 turn in the tone of discussions suggests managerial malice running on top of the front line bureaucratic incompetence.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#132
post #101

Earlier quoted context omitted.

Are you really shocked by this? I guess you have never worked on a corporate email system! People do this all of the time. 1) They don't realise email is not secure 2) When you explain point 1, all of the other solutions seem like too much hassle so they email anyway. 3) You can tell your customers not to email you CC numbers, you can even refuse them, but they will keep sending them

Or they think it's an acceptable risk... $50 liability limit.

That's the thing with credit cards. The merchant always ends up paying.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#133
post #51

Earlier quoted context omitted.

Also has a good example of hostile FOIA officers. I have filed about two dozen FOIA requests, and the vast majority were fine, though usually slow. Earlier this year one longstanding request of mine was rejected because they claimed the document I wanted was export controlled. Two months later I sent in an appeal where I showed that the document in question was not export controlled (I filed another FOIA with a separ…

Never attribute to malice that which is adequately explained by stupidity.

I agree, but in this case stupidity can not explain their actions.

The agency processing the FOIA request would get the export control status from the third party I contacted. The third party's software highlights export controlled documents with a red and highly noticeable statement. It would be difficult to believe they thought this was present when it was not.

The request also had actually been transferred several times because no one believes they have the authority to release the document I requested. The other agencies had ample opportunity to reject the request for being export controlled, but none did.

There are some other reasons that I will omit for brevity.

This makes me think that the export controlled claim was a lie meant to kill the request. Most people would stop at what they told me, but I thought it was worth verifying.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#134

I'm very surprised they gave out this information. I'm not talking about the mistake, I mean the actual request. In the UK I don't think you could even get a production order for this. Like, it's effectively getting Communications Data simultaneously against thousands of people not suspected of any crimes?? Like, do people know that by emailing their local government their email address is now free for scammers to re…

Similar story.

I worked at a polling company out of college owned by a Standford professor. My first task: After a poll is finished online, match that with voter records (using emails and addresses).

My first question was: "Well, that is a cool idea, but, there is no way the government would release a huge database of every california voter and their party affiliation. Let alone, the users entering in online poll information would extend that database to include their actual vote. There is no way this is possible.... right?"

Standford professor's response: "Do you want it in CSV?"

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#135

Earlier quoted context omitted.

I live in DC, land of the professional Fed. At the absolute highest level and after adjusting for location, the most a DC Fed could earn is $164,200. No surprise that anyone with serious technical talent--and by extension, market value--doesn't want such a job.

True, but consider some folks are content with a 38 hour week, may have automated large chunks of their job, and find the demands of working for a big public sector organization far less than that of a similar role in a private sector tech company.

If you can manage that, sure, sounds pretty good. But I doubt that's the case most of the time. None of the Feds I've had the chance to talk to sound like they're slacking off.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#136

I'm very surprised they gave out this information. I'm not talking about the mistake, I mean the actual request. In the UK I don't think you could even get a production order for this. Like, it's effectively getting Communications Data simultaneously against thousands of people not suspected of any crimes?? Like, do people know that by emailing their local government their email address is now free for scammers to re…

I have filed both US and UK FIO requests. (But I am not a lawyer.)

I think you are right in the UK. The US law is different and seems to allow this sort of broad request. I have been told before when filing in the US that others may request my contact information, and I have seen lists of FOIA requests received via the FOIA including contact information for requesters.

In the UK, requests need to be fairly narrow as I recall. And the time frames in which the request will be processed also are narrow: 20 business days as I recall. If it would take longer than that you probably would be asked to narrow the request. This is good for me as I typically request individual documents, not huge swarths of data. I requested a classified UK technical report and received a redacted copy within a month as I recall. Much faster than in the US.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#137
post #83

Earlier quoted context omitted.

Do you have a viable method to fix the problems you describe? If not, then we're still left with it being on the shoulders of the city. Ultimately, it's really hard to police that the vendors don't make crap solutions. If the market fails to figure out which are crap, the market may have failed, but I don't have any ideas that would succeed better. Edit: and let me say that I posited that the issue isn't market force…

Principally: start punishing the corrupt vendors; don't assume that reputation mechanisms will ensure that non-corrupt ones will eventually outcompete the corrupt ones. Just as you have to build software for the users you have not the users you feel you deserve, we need a service industry that works for the service-commissioning agents we have.

Again... how would you do it though? Who would do the punishing? How would you enforce the punishment? Would clients build the punishment into the contract? Even if you could do that, the vendors have the advantage of how to construct the contract in their best interests and avoid punishment. Most ideas will go straight back to market forces. Again, the issue is expertise to choose good options, not the existence of market forces.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#138
post #78
post #43

A few years ago I found a random SSD on the ground while on a walk with my son. The drive contained unencrypted records which squarly fall under HIPPA. I also did the right thing and returned it to the proper owner and told them about how their mdb files were readable by anyone. The same exact thing happened. They thanked me and then their lawyers nicely asked me to clone my hard drive and sign a bunch of shit. It wa…

Did you actually give them that clone and sign the documents? Or did you give push back like in the article? It feels to me like they shouldn't have much of a leg to stand on.

I did consider fighting them for about 7 minutes. Then I remembered that they had a legal team paid for by taxpayers, while I had a toddler and a pretty decent, mostly stress free life.

The laptop that I connected thier SSD to was my coding box, so I deleted all the code and secure erased the free space before they cloned it. They gave me shit about it too, because their forensic people saw days without any file activity. When I told them that it was because I removed my IP they responded with "why don't you think you need to do that? We can keep your data from falling into the wrong hands".

Maybe if I was some kind of an activist I would have tried to fight it.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#139
post #78

Earlier quoted context omitted.

Did you actually give them that clone and sign the documents? Or did you give push back like in the article? It feels to me like they shouldn't have much of a leg to stand on.

I did consider fighting them for about 7 minutes. Then I remembered that they had a legal team paid for by taxpayers, while I had a toddler and a pretty decent, mostly stress free life. The laptop that I connected thier SSD to was my coding box, so I deleted all the code and secure erased the free space before they cloned it. They gave me shit about it too, because their forensic people saw days without any file acti…

“We can keep your data from falling into the wrong hands...” just like they did for that drive you found.
Post reply on HN