Live data from Hacker News

The City of Seattle Accidentally Gave Me 32M Emails for $40

mchap.io

171–180 of 239 posts

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#171

I'm very surprised they gave out this information. I'm not talking about the mistake, I mean the actual request. In the UK I don't think you could even get a production order for this. Like, it's effectively getting Communications Data simultaneously against thousands of people not suspected of any crimes?? Like, do people know that by emailing their local government their email address is now free for scammers to re…

> do people know that by emailing their local government their email address is now free for scammers to request under FOI?

Florida, which has fairly broad open records laws, at least makes this extremely clear:

http://www.leg.state.fl.us/Statutes/index.cfm?App_mode=Displ...

> Any agency, as defined in s. 119.011, or legislative entity that operates a website and uses electronic mail shall post the following statement in a conspicuous location on its website:

> Under Florida law, e-mail addresses are public records. If you do not want your e-mail address released in response to a public records request, do not send electronic mail to this entity. Instead, contact this office by phone or in writing.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#172

Earlier quoted context omitted.

> Your police record, where you live, who you're married to, and whether or not you voted last election are publicly available. This is highly country specific. For the marriage record, I checked the laws in Germany, and (except for your own records) you have to present a "legal interest", which seems to be stricter than a "legitimate interest" (i.e. probably you need the information to enforce your rights, not just…

In the UK, as far as I know of those only marriage records is open. Police records can be obtained by your employer, but even then most minor (sentence less than 4 years) offenses are eventually considered spent and not disclosed to most roles. The electoral role (addresses) is open by default, but you can opt-out (though can still be used for certain narrow purposes), and as far as I know there is no way to check if…

You can opt out of allowing use of the electoral role for marketing - you can't opt out of political use.

You can also not be on the role but you cant vote in that case.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#173
post #143

Earlier quoted context omitted.

Similar story. I worked at a polling company out of college owned by a Standford professor. My first task: After a poll is finished online, match that with voter records (using emails and addresses). My first question was: "Well, that is a cool idea, but, there is no way the government would release a huge database of every california voter and their party affiliation. Let alone, the users entering in online poll inf…

Voter registration is considered public information in many states. Some states even provide the entire database on their website to download. However, voter registration does not include who a person voted for in an election. You are free to augment the database with your own data, of course.

I don't even understand why party affiliation is tracked by the state. What's that good for other than entrenching the two party state? Parties should have their own member lists.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#174

Earlier quoted context omitted.

My phone was dead at the time, so I was using my desktop with google hangouts for the call. I was not booted from the call. My internet died. End of story. I work from home, so my internet going down is a big deal for my livelihood and all that. I'm not saying that something suspicious happened, but I figured it was an interesting thing to happen. You're frankly thinking into it too much.

> You're frankly thinking into it too much. I think that was my line.

Pot kettle black, I guess.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#175
post #171

I'm very surprised they gave out this information. I'm not talking about the mistake, I mean the actual request. In the UK I don't think you could even get a production order for this. Like, it's effectively getting Communications Data simultaneously against thousands of people not suspected of any crimes?? Like, do people know that by emailing their local government their email address is now free for scammers to re…

> do people know that by emailing their local government their email address is now free for scammers to request under FOI? Florida, which has fairly broad open records laws, at least makes this extremely clear: http://www.leg.state.fl.us/Statutes/index.cfm?App_mode=Displ... > Any agency, as defined in s. 119.011, or legislative entity that operates a website and uses electronic mail shall post the following statemen…

Why is it like that? Do they give out your phone number or postal address if you contact them via those channels?

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#176
post #150

Earlier quoted context omitted.

But Seattle cannot summarily reject the request -- they have to follow the law, and the law does not require FOI requesters to get an explicit court order, e.g. a subpoena, for this information or for any other valid request. I mean, yes, the city of Seattle could try to reject the request, and the requester could sue and win in court after the judge finds that the city acted illegally. But that's like saying Seattle…

> which I'm not even sure is the situation here That's the key bit right there. So, if you are not sure - and they are also not sure - then they could ask for a ruling before releasing. Err on the side of caution is good practice when it comes to releasing data. I just looked at the dataset and it is full of information that I would normally consider to be private, which private citizens contact which government offi…

Say an ex finds the new address of a former partner then goes around and shoots them dead.

BTW I am not being hyperbolic here there was a case where this happened when I worked for BT - someone as a favor looked someone's new address up for a friend which resulted in a murder.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#177
post #143

Earlier quoted context omitted.

Voter registration is considered public information in many states. Some states even provide the entire database on their website to download. However, voter registration does not include who a person voted for in an election. You are free to augment the database with your own data, of course.

I don't even understand why party affiliation is tracked by the state. What's that good for other than entrenching the two party state? Parties should have their own member lists.

Mostly for primary eligibility. It also allows for things like ensuring that poll watchers etc are available in a equitable way.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#178
post #171

Earlier quoted context omitted.

> do people know that by emailing their local government their email address is now free for scammers to request under FOI? Florida, which has fairly broad open records laws, at least makes this extremely clear: http://www.leg.state.fl.us/Statutes/index.cfm?App_mode=Displ... > Any agency, as defined in s. 119.011, or legislative entity that operates a website and uses electronic mail shall post the following statemen…

Why is it like that? Do they give out your phone number or postal address if you contact them via those channels?

I suppose they treat e-mail addresses as street addresses. Public and not tied to anything else by default (you know it exists but not who is assigned to)

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#179
post #161

Earlier quoted context omitted.

Sorry, what I'm not sure about is whether an agency is liable if it releases exempt information. Exemptions allow an agency to deny a request, but the agency still has discretion whether or not to follow the exemption. > So, if you are not sure - and they are also not sure - then they could ask for a ruling before releasing. Err on the side of caution is good practice when it comes to releasing data. Again, that is s…

> based on requester identity or motivation No, but they should decide based on the data requested. And in this case the data requested is none of the requesters business since it involves the privacy of other citizens . Which definitely could be in contravention of other laws and in cases like that judges usually get to decide which weighs heavier. If I were a civil servant faced with a request that releases informa…

> they should decide based on the data requested

I agree with this -- of course a request can be rejected if it requests something that is explicitly exempted in the law. The metadata of emails to public agencies is currently not exempt from Washington state law.

> And in this case the data requested is none of the requesters business since it involves the privacy of other citizens.

OK, but that is not your or the state government's decision to make. The law does not allow for the government to make a unilateral judgment on whether something is "none of the requesters business" -- isn't it patently obvious how this could be abused?

> If I were a civil servant faced with a request that releases information that I felt would infringe on some other law I would definitely not decide to be the one to make the call and release it without a sign-off.

Sure, if you don't know the law exactly (most employees don't), then you consult your agency's FOI officer, who would then tell you whether the request is valid. If it is valid, and you decide to reject it anyway, you'd probably be fired (I don't think most state FOI laws provide criminal penalties for violating FOI).

I'm not a Washington historian, but I'm assuming the FOI law was passed because legislators had actual scenarios and use-cases in mind. For example, being able to request the emails sent and received by a government employee is useful if you want to know who contacted that employee about an issue, such as a regulatory enforcement action. Maybe there are clear-cut cases where a received email is obviously not work or issue-related, such as emails from that employee's mom. But what if the mom is herself a lobbyist or other influential official? Or how about an email from a guy talking about going golfing and getting a few beers? Is that just personal? What if the guy emails every week about going golfing on his dime, and the guy happens to be a businessperson waiting for regulatory approval on some project?

Apparently, the myriad of ways for unwanted behavior to be expressed via email are so plentiful that legislators decided to err on the side of transparency, because it would be too easy for officials to shut down requests and deny transparency all but to those with the means to sue (usually, corporations and journalists). It is not up to a civil servant to decide otherwise; likewise, the law protects the civil servant from liability for following a lawful request.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#180
post #100

Earlier quoted context omitted.

Yes, you are as far as I can see correct. The request should have been rejected as overbroad and against data privacy laws (in so far as they exist), or the purpose of the request could have been verified and then they might have seen whether or not there was another way to let the requester do their work without giving them the data they requested (see another comment of mine for one suggestion).

That's not how FOIA works. It's a good thing too. Government employees almost always fight FOIA requests. There aren't many subjective tools (e.g. overbroad) and you're certainly not required to say why you're making the request. Data privacy laws in the US are unfortunately minimal. The bigger problem comes from imbalance -- if the government and corporations have lists of names, people need them to in order to be a…

Email is really difficult because retention law and regulation is based on a topic.

To meet federal requirements, information about procuring equipment with certain grants must be maintained for 10 years. Caseworker notes for a minor who is a ward of the state may be required to be kept for 20 years after the 18th birthday.

If a record is deemed in scope and topical, an employee could be committing a crime by deleting that email. As a result, the easy answer is retain.

Post reply on HN