Live data from Hacker News

Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

wired.com

241–250 of 307 posts

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#241

Oh, man, another missed opportunity to make the average Joe Six-Pack become aware of data aggregation and privacy violations. If the researcher had downloaded the 2TB of data and published it as a torrent, then laymen might care. When someone can query the list and see his own personal information being broadcast, they will understand. When they realize that anyone can look up the address, phone, and all sorts of oth…

That’s career suicide and it likely would come with let’s make an example out of you sentencing (depending where lived).

The researcher was using Shodan to probe the entire range of IP addresses allocated in the USA. He found an unprotected site and queried it knowing it should not have been accessible. He queried the personal info on specific people that WIRED asked him about. He revealed data to a third party ("a sample of the data Troia shared [with WIRED]").

An argument could be made that every step above was illegal. I don't agree with that argument, but surely you've heard of (many) cases where people have been prosecuted for things like that.

My point is that he's already taking risks.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#242

Earlier quoted context omitted.

I hope they were not and this data ends up public. I’d love to search this database for the details of top people at privacy-violating companies and publish them.

> I’d love to search this database for the details of top people at privacy-violating companies and publish them. Who defines "privacy-violating"? Jumping into the mud because you feel aggrieved just makes you look like a pig.

It's not mud if you send them an email from a donotreply address saying "my privacy policy has changed, and now I will freely publish your previously private data"

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#243

Earlier quoted context omitted.

That’s career suicide and it likely would come with let’s make an example out of you sentencing (depending where lived).

The researcher was using Shodan to probe the entire range of IP addresses allocated in the USA. He found an unprotected site and queried it knowing it should not have been accessible. He queried the personal info on specific people that WIRED asked him about. He revealed data to a third party ("a sample of the data Troia shared [with WIRED]"). An argument could be made that every step above was illegal. I don't agree…

Then he should have used Tor.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#244
post #223

It's interesting that we consider this a leak only when the marketing firm loses the data. If we lived in a just society we would consider it a leak once the marketing firm got the data.

I've been a proponent of this idea: Make companies "super-liable" for any data beyond the data they (actually) need for the functioning of the service that is stolen in a data breach from their servers. This would hopefully not just encourage more companies to believe that data is "toxic" [1] and treat it as a liability , not as an asset, but it would also encourage them to adopt end-to-end encryption in as many type…

Considering that their entire business model is "selling this data" then this data is actually needed for the functioning of the service.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#245
post #4

With reasonable verification, anyone confirmed to be a part of this breach should be given access to the data, if only for good will. It's a sad state to see that the recklessness (or incompetence) of one entity, and at that a private one, can quickly become a domino in a chain that ends in toppling a person's privacy. They advertise themselves as having the most accurate data (why wouldn't they advertise themselves…

The only real strategy is to totally pollute the information with false and erroneous information, while also setting up ways to prevent tracking and fingerprinting and associating. I am somewhat surprised that someone has not yet really emerged as having developed a business model around assuring privacy. It could be dedicated routers with firewalls and built in VPN that also mask device names, combined with browsers and extensions that intentionally pollute browsing history and fingerprinting data, and sends bogus queries and also allows you to set policies for cookies in a little more user friendly manner to only retain specific cookies of specific domains, etc.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#246

Oh, man, another missed opportunity to make the average Joe Six-Pack become aware of data aggregation and privacy violations. If the researcher had downloaded the 2TB of data and published it as a torrent, then laymen might care. When someone can query the list and see his own personal information being broadcast, they will understand. When they realize that anyone can look up the address, phone, and all sorts of oth…

"Missed opportunity" ?

People can be stabbed in the back if they go into dark alleys without watching behind them. Let's stab a few people who go into these alleys so that everyone will be afraid to do so and we have an opportunity to prevent people being stabbed in future by making them aware.

Why would you possibly think this is a good idea? The idea is to prevent pain, not cause more pain in some bizarre attempt at making people afraid. There's enough privacy violations - we don't need to be making more of them ourselves.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#247

Earlier quoted context omitted.

... if you are European resident.

Correction: if you are physically present in the EU

Just as medical tourism is a thing, are we going to see privacy tourism emerge as an option? Tour operators can start offering packages...

"The sights of Paris and a personal information purge from the 100 largest US collectors"

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#248
Has anyone mapped out all of the data brokers that are active in the US, what information they collect, what their sources are?

I imagine a lot of that info is proprietary, but I'd really like to understand this industry better. It's probably a foolish hope, but I really hope there are a few main choke points that one could opt-out of. If that's not possible, I could always try to inject bad data into the system, if I know what their inputs are.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#249
post #244
post #223

Earlier quoted context omitted.

I've been a proponent of this idea: Make companies "super-liable" for any data beyond the data they (actually) need for the functioning of the service that is stolen in a data breach from their servers. This would hopefully not just encourage more companies to believe that data is "toxic" [1] and treat it as a liability , not as an asset, but it would also encourage them to adopt end-to-end encryption in as many type…

Considering that their entire business model is "selling this data" then this data is actually needed for the functioning of the service.

I don't know that this invalidates mtgx's general point. Right now, data brokers have effectively zero liability, but we don't treat other companies dealing with dangerous or toxic materials the same way. If a company handling money or munitions left their doors wide open, we wouldn't defend their gross negligence, we'd hold them accountable.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#250

Oh, man, another missed opportunity to make the average Joe Six-Pack become aware of data aggregation and privacy violations. If the researcher had downloaded the 2TB of data and published it as a torrent, then laymen might care. When someone can query the list and see his own personal information being broadcast, they will understand. When they realize that anyone can look up the address, phone, and all sorts of oth…

For many people, the benefit of being able to look up information is greater than the cost of letting other people have this ability - most people still won't care too much even if they know their data is published in this way. (For example, most people were willing to have their home telephone number published in a phone book) For some people, the cost of letting other people look up your information is overwhelming…

Everyone has secrets, even if you're not harmed by this data leak illustrating how harmful one could be would move people I think.

Vaccines can give you a fever but we still take them because the short term side effects are worth the long-term benefit. Leaking this type of information to the public operates under the same principle.

Post reply on HN