Live data from Hacker News

Stockholm parents built their own school app, then the city called the cops

wired.co.uk

331–340 of 357 posts

Re: Stockholm parents built their own school app, then the city called the cops

#331

Earlier quoted context omitted.

Thanks! Well we have already made the source code open and free and also encouraged the city to release an app with our source code as base. They weren’t interested in that. They would rather license the app, support and maintenance to us. We have quoted a fixed sum per month for that service and we plan to use that money to reimburse everyone sending PR:s we merge.

> We have quoted a fixed sum per month for that service and we plan to use that money to reimburse everyone sending PR:s we merge How interesting :- ) I wonder how you'll distribute the thanks-for-the-feature (PR) money — e.g. per PR, or per lines (hmm I guess not) or maybe some impact / "severity" system like for bug bounties? (but this time "feature bounties") (From Sweden me too. How nice that you built the app an…

If you view your idealised version of the app as "the app" and everywhere it doesn't currently match reality as a bug, you can just use a bug bounty system for it and it will make intuitive sense for everyone :)

Re: Stockholm parents built their own school app, then the city called the cops

#332
post #237

Earlier quoted context omitted.

I'm not sure I follow why that would matter. Their constitution says once data has been released, it is no longer their property (because it's a public institution). They created a way to access the data, so the data has been released to the parents and so the data now belongs to the parents. The parents own the data and as such it would seem to follow they can access it anyway they want.

It matters because the definition of data breach is very broad. For example, if I run a website and tell you that you may not browse my website but you continue to browse my website you may be guilty of data breach. If I tell you not to login to my website but you still login because I forgot to disable your account you very likely is guilty of data breach. Since the city didn't publish their information through an A…

> you may be guilty of data breach.

No, you may not in this case :) That is why people keep emphasising the way in which the data was published. This is Sweden, not the US.

> the city didn't publish their information through an API

Yes, they did.

> and also explicitly stated that they did not want Christian's app to access their information

If you cannot reasonably be said to have circumvented any technical measures to secure the data (cryptographic keys, some sort of login, IP range blocks, etc) it is not a breach. In that case, it is just you consuming what is there for everyone (like unencrypted wifi - harvesting those signals using SDRs is not an issue because you are not bypassing any security), which is okay.

Edit: Legally okay, that is. How you feel about it ethically is up to you, I'm not talking about that.

Re: Stockholm parents built their own school app, then the city called the cops

#333
post #265

Earlier quoted context omitted.

A website is an API (poorly designed). The only way to not make an API out of publicly available data, is to encrypt it. Then nobody can read it unless they have the right keys.

If you encrypt it, you have to, at some point, also send the keys to the user. The key has the same legal protection as the rest of the document so encrypting the data has no implication on the legal discussion.

No, because if those keys have to be extracted from elsewhere to bypass a security measure it becomes a breach. The way the documents are published and the way in which they are accessed are relevant to the discussion.

Re: Stockholm parents built their own school app, then the city called the cops

#334

Earlier quoted context omitted.

Thanks for the explanation but I believe there’s been a misunderstanding. By pension off I meant is there a possibility for someone mediocre, or promoted beyond their level of competence, to be immediately dismissed with a generous pension. And to replace them with someone else selected for fixing the problem?

You mean what happenen in the US when a cop shot an undercover cop and promptly retired to prevent himself from getting into more trouble? https://www.youtube.com/watch?v=4fQcjmt2Q_o This policy won't help.

How do you know it wasn’t a forced retirement, i.e. an unofficial punishment?

Re: Stockholm parents built their own school app, then the city called the cops

#335

Earlier quoted context omitted.

"They will come looking for you, putting a gun to your head telling you to transfer your assets to them" You talk about pragmatism but give a crime scenario out of Hollywood movies. Do you mean bank transfer? Am I transferring a million dollars into an official bank account registered in the criminal's real name? Do you mean I should sign a deed giving them possesion of my house, and that would hold up in court? Any…

I'm talking about things that have happened to people I know personally and things I've read in the news: https://www.expressen.se/kvallsposten/krim/man-misshandlad-o... There are of course other ways to transfer assets than the ones you describe. And yes, one guy was held hostage for weeks: https://www.thelocal.se/20050715/1746-5/

Google Translate says of the first "Count Carl Piper, 73, was robbed in his home at Högestad Castle by robbers." and "Carl Piper is one of Skåne's most profiled nobles."

The second "Bengtsson, 32, was abducted on January 17th in Gothenburg on his way to work at Siba, a family-owned nationwide home electronics retail chain of which he is managing director and which he will one day inherit."

Is your suggestion that if this information weren't public then no one would know that those men were rich and so they wouldn't have been robbed or abducted?

Because 1) poor people get robbed too, and 2) I usually think someone who lives in a castle, is often profiled in the news for one's wealth-related activities; or someone who is the managing director of a large chain store; probably has money - without having to check their tax records.

Were the attackers of Count Carl Piper ever found? You mentioned "foreign criminals" earlier, but why couldn't they be domestic?

Earlier you wrote "Senior citizens are also targeted by criminals in Sweden".

I'm from the US. Senior citizens are also targeted by criminals in US. Eg, see https://www.fbi.gov/scams-and-safety/common-scams-and-crimes... .

There's no need to know the person's age and address - go to a neighborhood with decent-looking houses and knock on doors pretending to offer services like re-roofing or driveway sealing. If the person who answers is old, and alone, try exactly the same technique you mentioned.

Or, take a down-payment for the roofing work then don't do it, like in https://www.stgeorgeutah.com/news/archive/2021/10/07/cgb-sus... .

Re: Stockholm parents built their own school app, then the city called the cops

#336

Earlier quoted context omitted.

Your example assumes that crime (including up to ransom and kidnapping!) in poor neighbourhoods goes unpunished. If that’s the case there are more fundamental things to worry about than salary data…

Most crime goes unpunished, no matter the neighborhood. In 2020, only 14% of investigated crimes against persons in Sweden reached a solution. But that doesn't mean we should ignore all other problems.

In the US, most crime also goes unpunished. The numbers I've found for the US are about 14% too, depending on the crime - https://www.statista.com/statistics/194213/crime-clearance-r... . (Larceny , burglary, and property crimes are far more common than the other crimes.)

Frustratingly, wage theft is very common in the US but not covered under criminal law. Quoting https://www.epi.org/publication/wage-theft-bigger-problem-fo...

> Wage theft—employers’ failure to pay workers money they are legally entitled to—affects far more people than more well-known and feared forms of theft such as bank robberies, convenience store robberies, street and highway robberies, and gas station robberies. Employers steal billions of dollars from their employees each year by working them off the clock, by failing to pay the minimum wage, or by cheating them of overtime pay they have a right to receive. Survey research shows that well over two-thirds of low-wage workers have been the victims of wage theft.

Even in the US, different regions have different ways to measure the clearance rate, and as I pointed out with wage theft, even the concept of what is measured differs between jurisdictions.

I therefore find it hard to judge that a raw number like "14%" is easily comparable with other countries.

In researching this I found https://bra.se/bra-in-english/home/publications/archive/publ... from 2014, which makes a similar point:

> The aim is to find explanations for why Sweden has a lower clearance rate than the other countries, despite the fact that victim surveys show that real crime levels are roughly the same.

> One factor of relevance to differences in the clearance rate is the issue of differences in the way the police register crimes. In Sweden, for example, the method used to count the number of reported offences is less restrictive than those employed in the other countries. Several of the countries also use a definition of cleared offences that differs from that employed in Sweden. In some countries, it is sufficient to have registered a suspect on reasonable grounds for the offence to be considered cleared. In Sweden, however, an individual must either have been prosecuted for the offence or issued with a summary sanction order or a waiver of prosecution.

> Finally, the chapter presents an alternative method of measuring police effectiveness in the countries studied, namely the number of conviction decisions per 1,000 of population. Using this measure, Sweden is no worse than the other five countries; in fact, all of the countries lie at approximately the same level.

In that report the official clearance rates were:

  Sweden 17
  Norway 47
  Denmark 18
  Netherlands 25
  Germany 54
  England & Wales 27 / 29
but, for example, "in the Netherlands, as in Germany and Norway, offences are for the most part reported at a police station or at the crime scene. It is also possible to report an offence by telephone or via the internet, but this happens far less often than in Sweden."

Or, in Germany, "If the police consider that a reported incident does not meet these requirements, it is not registered as an offence in the crime statistics. In addition, statistics on reported offences do not include open cases.", and "The procedure employed to produce offence counts is also more restrictive than in Sweden, and employs the principal offence meth-od. Thus, if a perpetrator assaults two men on the same occasion, this is only counted as a single offence in Germany, while in Sweden it would be counted as two separate offences."

These are just some of ways that biases the official statistics in ways that make it difficult to compare numbers directly.

Re: Stockholm parents built their own school app, then the city called the cops

#337

Earlier quoted context omitted.

I mean that Han Chinese is a specific ethnicity. It's a documented thing: https://en.wikipedia.org/wiki/Genetic_history_of_East_Asians... > the northern and southern Han Chinese are genetically closest to each other and it finds that the genetic characteristics of present-day northern Han Chinese were already formed as early as three thousand years ago in the Central Plain area.[22]

If you look at the history of Han Chinese, they called themselves many different names. >Among some southern Han Chinese varieties such as Cantonese, Hakka and Minnan, a different term exists – Tang Chinese (Chinese: 唐人; pinyin: Táng Rén, literally "the people of Tang"), derived from the later Tang dynasty, regarded as another zenith of Chinese civilization. >The term "Huaxia" was used by Confucius's contemporaries,…

I think we may agree on some level but be stuck on semantics. There is an ethnic group XYZ living in and historically originating from what is today China. This is documented and scientifically backed. This group's name is homonymous with a separate idea in everyday speech; let's call that other idea ABC. ABC is essentially the name of a nation, which as you know doesn't have to do with genetics.

When I say Han, I'm referring to the genetic group XYZ. I understand that some people say Han and mean the nation ABC. I also agree that calling all people from the modern country of China Han is propaganda and "Han"-washes (to make a parallel to white-wash) a number of different ethnicities and cultures.

To bring it back to the original points:

> (you) “Han Chinese” isn’t based on genetics it’s many different races that call themselves Han because they share culture

> (me) Not quite. Han Chinese is a specific ethnicity. But it is true that "Chinese” isn’t based on genetics, it’s many different races that call themselves "Chinese" because they share culture. Or to cover all cases, it's many different races that the Chinese government calls "Chinese" to push a facade of homogeneity, marginalize minority peoples like Uyghurs, and marginalize minority languages and cultures in China that aren't Han Chinese, though their current nationality is Chinese.

You were talking about the ABC Han, or Han as the name of the Han nation, while I was talking about the Han ethnicity. I don't think we really disagreed, just got tripped up on semantics. Although if you still disagree with the scientific belief that there is a Han ethnicity in spite of all the data, then I think we can't go much further here.

Re: Stockholm parents built their own school app, then the city called the cops

#338
What a shame! In my opinion publicly accessible API is simply public. The can attempt to block access from "un-approved" clients server-side but that's it. It is like saying my website is accessible only from Firefox and it is illegal to access it from Chrome or Safari.

Re: Stockholm parents built their own school app, then the city called the cops

#339

Earlier quoted context omitted.

It matters because the definition of data breach is very broad. For example, if I run a website and tell you that you may not browse my website but you continue to browse my website you may be guilty of data breach. If I tell you not to login to my website but you still login because I forgot to disable your account you very likely is guilty of data breach. Since the city didn't publish their information through an A…

> you may be guilty of data breach. No, you may not in this case :) That is why people keep emphasising the way in which the data was published. This is Sweden, not the US. > the city didn't publish their information through an API Yes, they did. > and also explicitly stated that they did not want Christian's app to access their information If you cannot reasonably be said to have circumvented any technical measures…

> No, you may not in this case :) That is why people keep emphasising the way in which the data was published. This is Sweden, not the US.

Here is the relevant paragraph:

"För dataintrång döms den som olovligen bereder sig tillgång till en uppgift som är avsedd för automatisk behandling eller olovligen ändrar, utplånar, blockerar eller i register för in sådan uppgift"

The requisites are: "olovligen", "bereder sig tillgång till", and "uppgift som är avsedd för automatisk behandling". Christian's app full fills the requisites.

API means "Application Programming Interface" and if you think the city created or intended to create such a thing you don't know what an API is.

> If you cannot reasonably be said to have circumvented any technical measures to secure the data (cryptographic keys, some sort of login, IP range blocks, etc) it is not a breach.

You have no idea what you are talking about. There are several precedents that show that circumventing technical measures is not required for data breach to have occurred.

Re: Stockholm parents built their own school app, then the city called the cops

#340
post #288

Earlier quoted context omitted.

> How I parse it and present it is up to me as citizen I know technologists like to think that way but very often the law doesn't work like that. They will think about intent - was the intent to give you the raw data or was the intent to convey a specific representation of it that may omit some parts or further transform or presentation layer changes to achieve a different final result to what the raw data would have…

> convey a specific representation ... is the "public document" you have access to, not the raw data Seems you're saying it might be illegal to convert a HTML file to PDF format, or to use a screen reader to read the text. I wonder in which country you are (where apparently there can be laws like that)

An app that parses a news sites articles, removes all advertisements from it, and adds its own might very well be illegal in some jurisdictions.
Post reply on HN