Live data from Hacker News

SparkFun Gets A Subpoena

sparkfun.com

21–30 of 55 posts

Re: SparkFun Gets A Subpoena

#21
post #7

SparkFun is lucky that the subpoena was for one of their products being used in a credit card skimmer and not an improvised cruise missile. Also, protip for criminals: make your own circuit boards without identifying marks.

This is not the first time[1] we've had issues with our products showing up in the news for less than stellar reasons - luckily nothing as awful as an explosive device. As Nate said in the article, we know our parts can be used for good or for evil. If only there was less of the latter... [1] http://www.sparkfun.com/news/308

Christopher Tappin claims he didn't know the batteries were going to be used for evil.

(http://www.guardian.co.uk/world/2012/apr/27/chris-tappin-den...)

Re: SparkFun Gets A Subpoena

#22
> 7. Complete credit card numbers used on Order(s)

Can you fail PCI compliance if you're able and do this? What if you use a third party system such as Stripe where you have no access to the full credit card number?

Re: SparkFun Gets A Subpoena

#24
post #21

Earlier quoted context omitted.

This is not the first time[1] we've had issues with our products showing up in the news for less than stellar reasons - luckily nothing as awful as an explosive device. As Nate said in the article, we know our parts can be used for good or for evil. If only there was less of the latter... [1] http://www.sparkfun.com/news/308

Christopher Tappin claims he didn't know the batteries were going to be used for evil. ( http://www.guardian.co.uk/world/2012/apr/27/chris-tappin-den... )

I'm not entirely sure what you're getting at here. Should we stop selling Arduinos because they can be programmed for nefarious purposes, in addition to lowering the barrier to entry for embedded electronics in the classroom? How about spools of wire because wire can be made a part of something far more sinister than we can imagine? Should Apple stop selling the iPhone because it's also bluetooth-enabled?

I understand where you're coming from, but think it's entirely ungrounded in this case. We actively work with the DHS on export control. There is a very real risk involved in selling the products we do, but I don't think that should stop us from our goal of education and - right there at the bottom of every page on our site - sharing ingenuity.

Re: SparkFun Gets A Subpoena

#25
post #22

> 7. Complete credit card numbers used on Order(s) Can you fail PCI compliance if you're able and do this? What if you use a third party system such as Stripe where you have no access to the full credit card number?

Neither credit card numbers nor IP addresses were included because we don’t retain that information for our own protection as an organization.

In general, you can not be compelled to produce something which you do not have. This is why you see legislation proposed with mandatory retention policies for various businesses.

Re: SparkFun Gets A Subpoena

#26
post #6

As a result, about 20 customers that had purchased a specific device at sparkfun that had delivery in Georgia had their information given to the police to use in this investigation. I really want the people running the skim operation caught, but I agree with Nate (the sparkfun guy) that it is a very fine line harassing the others that are (most likely) blameless. Am I reading this correctly that then these 20 people…

> Am I reading this correctly that then these 20 people have their info in the public record after this trial closes?

Nope. The subpoena is in the public record. The data SparkFun sent in response to the subpoena is not in the public record. It will just go to the investigators who are trying to track down the credit card thieves.

If the investigation leads to someone being charged with a crime, and that leads to a trial, the proceedings of that trial will be in the public record, but there would be no reason for the information for the customers NOT charged with the crime to be entered into the record at that trial.

I doubt that anyone will be harassed over this, unless we use a very loose definition of harassment. Most likely the investigators will take the list of customers, look up these people to see if any of them have a record of prior criminal activity, and concentrate on those.

If they do question the rest, mostly likely the investigators will simply ask them what they purchased the board for. The customer will then enthusiastically launch into a description of the neat gadget they built and insist on showing it to the investigator and explaining in excruciating detail exactly how it works. The investigator will see the SparkFun board, see that the device is obviously not a credit card scanner, and try to figure out how to escape the enthusiastic hobbyist without being rude to him.

Re: SparkFun Gets A Subpoena

#27
post #6

As a result, about 20 customers that had purchased a specific device at sparkfun that had delivery in Georgia had their information given to the police to use in this investigation. I really want the people running the skim operation caught, but I agree with Nate (the sparkfun guy) that it is a very fine line harassing the others that are (most likely) blameless. Am I reading this correctly that then these 20 people…

Having one's private information placed into (assuredly sealed) evidence in a criminal trial is hardly "harassment". This is what subpoenas are for: evidence exists that might constitute proof of a crime, and courts have (and have always had) the authority to demand its production. There's nothing unique here. If these were 20 paper records from a vacuum tube supplier in 1939, surely the court would have requested (and gotten) the same thing.

Re: SparkFun Gets A Subpoena

#28
post #26
post #6

As a result, about 20 customers that had purchased a specific device at sparkfun that had delivery in Georgia had their information given to the police to use in this investigation. I really want the people running the skim operation caught, but I agree with Nate (the sparkfun guy) that it is a very fine line harassing the others that are (most likely) blameless. Am I reading this correctly that then these 20 people…

> Am I reading this correctly that then these 20 people have their info in the public record after this trial closes? Nope. The subpoena is in the public record. The data SparkFun sent in response to the subpoena is not in the public record. It will just go to the investigators who are trying to track down the credit card thieves. If the investigation leads to someone being charged with a crime, and that leads to a t…

Most likely the investigators will take the list of customers, look up these people to see if any of them have a record of prior criminal activity, and concentrate on those.

Or other things. Was someone who's name was on the list seen hanging around the places where the skimmers were installed lots? Was the money being sent (however roundabouty) to anyone on the list? etc.

Re: SparkFun Gets A Subpoena

#29
post #9

Earlier quoted context omitted.

I'm all for helping the police, I'd be pretty willing to give them information in a case like this. But I'm amazed their initial subpoena was for ALL orders from Georgia for a multi-month period. That's an amazingly wide net.

I suspect that the police in this case have no idea how big sparkfun is or how much business they do.

More likely, they just ask for everything in the hopes that they don't miss anything, and then rely on the targeted business to try to argue down the scope of the subpoena. The police have no incentive to try and limit the scope because they don't care about protecting the privacy of the people they're investigating.

Re: SparkFun Gets A Subpoena

#30
post #8

I have a question. Are companies required to hold certain information about their customers? Or can a company simply answer a subpoena with "We don't store that information."?

It depends. Some countries have laws creating data retention requirements — in some contexts, for some time periods (with mandatory expiration in the EU), with sharing conditional on some purposes (hopefully for reasons relating to serious crime, but with some laws suspecting or detecting copyright infringement is good enough), with varying degrees of judicial review and oversight of bad-faith requests.

https://en.wikipedia.org/wiki/Telecommunications_data_retent... (concerns telcos, e-mail hosts, and web-hosts)

The USA doesn't have a law like that, but it doesn't have a right to privacy either (there is a law about the privacy of correspondence that the NSA and telcos have ignored), so this sort of data retention law is sidestepped by a few large actors “voluntarily” collecting and sharing information. National security letters, gag orders, and whatever power incited AT&T to first do large scale warrantless interception mean that there can be a lot of abuse with little consequences for the participants. This might also apply to smaller actors, although less publicised (I don't know if there's any bad publicity the US government would care about). If you collect it, you might end up sharing it.

Post reply on HN