Live data from Hacker News

The City of Seattle Accidentally Gave Me 32M Emails for $40

mchap.io

141–150 of 239 posts

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#141

I'm very surprised they gave out this information. I'm not talking about the mistake, I mean the actual request. In the UK I don't think you could even get a production order for this. Like, it's effectively getting Communications Data simultaneously against thousands of people not suspected of any crimes?? Like, do people know that by emailing their local government their email address is now free for scammers to re…

Yes, you are as far as I can see correct. The request should have been rejected as overbroad and against data privacy laws (in so far as they exist), or the purpose of the request could have been verified and then they might have seen whether or not there was another way to let the requester do their work without giving them the data they requested (see another comment of mine for one suggestion).

No, the Washington State law does not allow for agencies to reject requests on the basis of being overly broad or against data privacy laws. There are specific exemptions (e.g. library records), and for records that may contain personal info (like someone emailing the mayor and including their own credit card number), it is up to the agency to redact such info. However, the agency can charge the requester for that work.

Moreover, the requester is not required to give a reason for the request.

https://www.muckrock.com/place/united-states-of-america/wash...

https://www.rcfp.org/washington-open-government-guide/ii-exe...

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#142

Earlier quoted context omitted.

FWIW I think you should not have done that, though I understand the temptation. At the first indication that the data was not what you requested and contained more than you - or they - bargained for you should have stopped looking at it and alerted both the sender and the relevant data protection authorities in so far as those are a functioning entity where you live to tell them they have an 'accidental disclosure' o…

Just curious, are there established guidelines that are broadly accepted and that lay out how to proceed? Or is it really just down to the "I think you should" on Hacker News? (No snark intended here.)

Accidental disclosure is a gray area, and once you are aware of it being an accidental disclosure you will want to make sure that you do not make things worse through your actions.

There are a number of moving parts here:

- The disclosure was clearly not the intended result

- The recipient could - and in fact did - realize this

- The recipient was in contact with the sender

- The recipient had some easy means to redress the situation

Given all of the above, if you then dig in and start looking at the data I think you are crossing a line. At a minimum a legal professional should have been consulted before further examination of the data, once it became obvious something was wrong.

In the end it would have been down to a judge to decide whether that crosses the line in a criminal sense but I would be loathe to find out the hard way. Pick your battles and all that.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#143

I'm very surprised they gave out this information. I'm not talking about the mistake, I mean the actual request. In the UK I don't think you could even get a production order for this. Like, it's effectively getting Communications Data simultaneously against thousands of people not suspected of any crimes?? Like, do people know that by emailing their local government their email address is now free for scammers to re…

Similar story. I worked at a polling company out of college owned by a Standford professor. My first task: After a poll is finished online, match that with voter records (using emails and addresses). My first question was: "Well, that is a cool idea, but, there is no way the government would release a huge database of every california voter and their party affiliation. Let alone, the users entering in online poll inf…

Voter registration is considered public information in many states. Some states even provide the entire database on their website to download. However, voter registration does not include who a person voted for in an election. You are free to augment the database with your own data, of course.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#144
post #141

Earlier quoted context omitted.

Yes, you are as far as I can see correct. The request should have been rejected as overbroad and against data privacy laws (in so far as they exist), or the purpose of the request could have been verified and then they might have seen whether or not there was another way to let the requester do their work without giving them the data they requested (see another comment of mine for one suggestion).

No, the Washington State law does not allow for agencies to reject requests on the basis of being overly broad or against data privacy laws. There are specific exemptions (e.g. library records), and for records that may contain personal info (like someone emailing the mayor and including their own credit card number), it is up to the agency to redact such info. However, the agency can charge the requester for that wo…

Ok, so in that case redaction would have been the way to go here. But the request as it is actually harms the privacy of large numbers of individuals which is not what the FOI laws are supposed to be used for.

Also, of course Seattle could reject the request, they could simply say: "Without an explicit court order to release this information we will not do so", and that would be that. It would then be upon the petitioner to ask the courts to force the release of the information requested, if the petitioner felt his rights had been violated. In the present situation the city is opening itself up to liability because of the privacy of all the people they have exposed (and more so because of the mistake). FOI does not mean 'every piece of data the government has should be released to the requester', the goal is increased transparency of government, not privacy violation of citizens using the FOI requests as an end-run around any kind of privacy law.

There is a tension between those two and typically the legal branch will determine where exactly the line is, when in doubt: go to court.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#145
post #49

I'm very surprised they gave out this information. I'm not talking about the mistake, I mean the actual request. In the UK I don't think you could even get a production order for this. Like, it's effectively getting Communications Data simultaneously against thousands of people not suspected of any crimes?? Like, do people know that by emailing their local government their email address is now free for scammers to re…

The Washington State Public Records Act, which this request was made under, states its spirit very unambiguously: The people of this state do not yield their sovereignty to the agencies that serve them. The people, in delegating authority, do not give their public servants the right to decide what is good for the people to know and what is not good for them to know. The people insist on remaining informed so that the…

Beautifully put. This information is _there_ whether we like it or not. I’d rather have as much access to it as a government employee than none at all.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#146

I'm very surprised they gave out this information. I'm not talking about the mistake, I mean the actual request. In the UK I don't think you could even get a production order for this. Like, it's effectively getting Communications Data simultaneously against thousands of people not suspected of any crimes?? Like, do people know that by emailing their local government their email address is now free for scammers to re…

> Could I request this data myself, then start emailing them scam emails

Yes, bad actors can find malicious uses for a dataset. Not sure what that has to do with FOI. Are you suggesting that people who email the government expect their email to remain private, even as that email may be forwarded to a number of agencies and employees?

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#147

Interesting dataset. Data like this can be used to identify strong links between contractors and government officials. One problem is that the metadata should have only contained anonymized entries for the email addresses of the counterparties of the Seattle.gov addresses, the article leaves this unclear. Another potential problem is that if a case of corruption or nepotism is identified that has not been passed to t…

I'm not sure I could disagree with you more. At least in the US there is a very strong expectation that communications between governmental employees is non-private except in very special circumstances. You'll note Matt says that the Police and Human Services departments have not responded, I'd guess thats not an accident because police records and personnel/medical records are largely exempt from FOIA requests. Furt…

> between governmental employees

The request contains the names of private individuals through BCC and CC headers requested and exactly when they communicated with which government officials.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#148
post #116

Interesting dataset. Data like this can be used to identify strong links between contractors and government officials. One problem is that the metadata should have only contained anonymized entries for the email addresses of the counterparties of the Seattle.gov addresses, the article leaves this unclear. Another potential problem is that if a case of corruption or nepotism is identified that has not been passed to t…

The linked Kaggle dataset https://www.kaggle.com/foiachap/seattle-email-metadata/ shows that the final returned data are Excel tables with content which looks like this: Sender or Created by: "Herring, Kaya" Recipients in To line: Ortiz, Piper; Jones, Raphael Recipients in Cc line: Valdez, Khloe Recipients in Bcc line: Sent: 3/23/17 18:08 (I changed the names to random ones)

I suspected as much. So the names are out there. Pretty sloppy.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#149
post #48

I'm very surprised they gave out this information. I'm not talking about the mistake, I mean the actual request. In the UK I don't think you could even get a production order for this. Like, it's effectively getting Communications Data simultaneously against thousands of people not suspected of any crimes?? Like, do people know that by emailing their local government their email address is now free for scammers to re…

I have never assumed that an email address I gave the government would be protected. I would also not assume that the contents of any email I sent would be in any way protected either. The government is collectively owned. Your police record, where you live, who you're married to, and whether or not you voted last election are publicly available. I would rather all of that be protected in some way, but I think it's c…

Maybe you need the GDPR.

When governments in the EU started digitizing their data like 20 years ago, it used to be that lots of personal data would end up published on official websites, either in the form of scanned PDFs that Google would gladly OCR and index, or in directly readable formats. Since then, the EU has cracked down on all of that, and you can no longer search for someone's phone number in order to get their full name, address, date of birth and ID. Even data that used to be available just 10 years ago, now has been removed.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#150
post #141

Earlier quoted context omitted.

No, the Washington State law does not allow for agencies to reject requests on the basis of being overly broad or against data privacy laws. There are specific exemptions (e.g. library records), and for records that may contain personal info (like someone emailing the mayor and including their own credit card number), it is up to the agency to redact such info. However, the agency can charge the requester for that wo…

Ok, so in that case redaction would have been the way to go here. But the request as it is actually harms the privacy of large numbers of individuals which is not what the FOI laws are supposed to be used for. Also, of course Seattle could reject the request, they could simply say: "Without an explicit court order to release this information we will not do so", and that would be that. It would then be upon the petiti…

But Seattle cannot summarily reject the request -- they have to follow the law, and the law does not require FOI requesters to get an explicit court order, e.g. a subpoena, for this information or for any other valid request. I mean, yes, the city of Seattle could try to reject the request, and the requester could sue and win in court after the judge finds that the city acted illegally. But that's like saying Seattle police "can" just arbitrarily arrest and imprison people, and fight the subsequent lawsuits.

Because the FOI law exists, the city does not open itself to liability in releasing records, except when it accidentally releases records that are mandated to be private, which I'm not even sure is the situation here.

Increased transparency is almost always a tradeoff with privacy. I don't disagree with you that the law may be abused for commercial or malicious intent, but it is up to the legislature to propose a bill that curbs FOI. Until then, the government cannot just deny valid requests because they don't approve of the requester or the requester's purported motives.

Post reply on HN