Live data from Hacker News

The City of Seattle Accidentally Gave Me 32M Emails for $40

mchap.io

31–40 of 239 posts

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#31

Earlier quoted context omitted.

It was a reasonable ballpark. Let's say a city prosecutor was working on a organized crime case that involves the FBI and other people. Based on timing of emails this would leak the list of people working on the case, maybe informants and put them at risk. We all lost our collective shit when NSA said they're only collecting metadata. Metadata is Data.

Since they revised the cost for the data they actually sent him down from $33M to $56 (90 days of data at $1.25 for 2 days data), was a ballpark estimate that's over 500,000 times higher than the actual cost really reasonable?

The ballpark estimate was for checking the full text of each and every email (which was a misunderstanding -- the author wanted metadata only).

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#32
I'm very surprised they gave out this information. I'm not talking about the mistake, I mean the actual request. In the UK I don't think you could even get a production order for this. Like, it's effectively getting Communications Data simultaneously against thousands of people not suspected of any crimes??

Like, do people know that by emailing their local government their email address is now free for scammers to request under FOI? Could I request this data myself, then start emailing them scam emails "I know you contacted us in June, could you call me on 555-1223 etc"

This seems totally against the spirit of FOI

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#33

I find the writer to be a bit of a dick in his responses. Yes, the city IT may not be at the same level as Google engineers, but there’s no need to mock their ballpark estimates, and after the mistake there’s no need to be a jerk about it. Be forthright about the error. Consider being on the other side of this, due to a careless mistake the data for many people is exposed on a random strangers hard drive. Asking for…

I'm curious what his actual legal exposure would have been if he hadn't folded. I feel like they should have offered to compensate the author for his time in their initial request - if someone wanted to perform forensic scans on my hard drives it would be a huge inconvenience.

I'd be curious what his legal exposure would be if he were a person off the street, who didn't have a lawyer handy.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#34

I find the writer to be a bit of a dick in his responses. Yes, the city IT may not be at the same level as Google engineers, but there’s no need to mock their ballpark estimates, and after the mistake there’s no need to be a jerk about it. Be forthright about the error. Consider being on the other side of this, due to a careless mistake the data for many people is exposed on a random strangers hard drive. Asking for…

I'm curious what his actual legal exposure would have been if he hadn't folded. I feel like they should have offered to compensate the author for his time in their initial request - if someone wanted to perform forensic scans on my hard drives it would be a huge inconvenience.

It is also a legal issue, depending on what else is on the drives. Imagine having to call your employers or clients and tell them that data under NDA is being turned over to Seattle's auditors.

Worst case, they'd want to know exactly what data was at risk, which would trigger more demands for forensic audits and more duty to notify.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#35
post #30

The writer has fessed up to reading a lot of the emails. As evidenced by summarizing the content (e.g. cheating spouses, zabbix etc.). Wouldn't the responsible thing to do be stop reading the emails once you realise what is going on?

I had the same thought - he seems to have indulged in the data quite a bit to come up with such a thourough analysis.

I would love to hear his explanation for why he thought reading through them all was necessary. I'm not surprised the city requested 3rd party proof he had deleted them, he clearly demonstrated a fascination with their contents

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#36

Earlier quoted context omitted.

It was a reasonable ballpark. Let's say a city prosecutor was working on a organized crime case that involves the FBI and other people. Based on timing of emails this would leak the list of people working on the case, maybe informants and put them at risk. We all lost our collective shit when NSA said they're only collecting metadata. Metadata is Data.

Since they revised the cost for the data they actually sent him down from $33M to $56 (90 days of data at $1.25 for 2 days data), was a ballpark estimate that's over 500,000 times higher than the actual cost really reasonable?

The actual cost of servicing this request was much greater than the $56 estimate.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#37
post #18

Author of article has no background/understanding of the "sunshine" laws in effect in WA. Those laws may (do) explain a lot of why things go this way with any/all FOIA in WA. Source: 100s of FOIA requests to various WA government agencies.

Could you be a little more precise? As is this is just a vacuous statement about how you know more than the author.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#38
> Seattle was approaching the problem as if they were pursuing Computer Fraud And Abuse (CFAA) charges. For information that they sent. Jiminey Cricket..

> So, I deleted the files.

Isn't it great to live in a country where we have generic felonies that governments can apply to just about anything involving a computer and ruin your life?

Land of the "free" and the home of the 'fraid.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#39
post #15

I find the writer to be a bit of a dick in his responses. Yes, the city IT may not be at the same level as Google engineers, but there’s no need to mock their ballpark estimates, and after the mistake there’s no need to be a jerk about it. Be forthright about the error. Consider being on the other side of this, due to a careless mistake the data for many people is exposed on a random strangers hard drive. Asking for…

For the ballpark estimate, I think they just wanted for the request to go away by quoting an insanely high price.

Long long term resident with a connection to local government

They don't have a choice. Seattle IT is so underfunded that hands are tied because there isn't any resourcing.

On one hand, you have to respond to all of these requests (and rightfully so, as it's the law.) On the other, you have no money for your department because it has no funding because the citizens didn't want to spend the money.

The person who did this isn't malicious. Just very overworked and did a data pull wrong. They probably didn't give a shit to check because their job kinda sucks and they have too much to do already.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#40

I find the writer to be a bit of a dick in his responses. Yes, the city IT may not be at the same level as Google engineers, but there’s no need to mock their ballpark estimates, and after the mistake there’s no need to be a jerk about it. Be forthright about the error. Consider being on the other side of this, due to a careless mistake the data for many people is exposed on a random strangers hard drive. Asking for…

How was a lawyer unnecessary? He was threatened after doing the right thing..!
Post reply on HN