Live data from Hacker News

State Bar of California addresses breach of confidential data

calbar.ca.gov

41–50 of 101 posts

Re: State Bar of California addresses breach of confidential data

#41
post #35
post #26

Earlier quoted context omitted.

Something that stuck out to me about that website is that we really do publish a lot. If you ever had a speeding ticket, that’s a matter of public record now. If you ever had a parking violation, that’s a matter of public record. I mean to be honest, if you just have a car, I can probably find you on that website if I know your name. Also goes for divorces. By and large I agree with your take, but playing around with…

I have owned a car in NY, FL, and CA, have been married, and have received parking violations in all 3 of those states, and my very unique name is not present at all on that website.

Fair. I did search out myself and several others I know. Didn’t find myself, but did find out that there’s a guy with a very similar name to me (different middle name) that likes to live dangerously in the same State but in several different counties racking up speeding violations like there’s no tomorrow.

I was able to find almost every single other person I searched though, chose not to dig into it any further than I could confirm it was someone I actually knew, typically by birth date.

Re: State Bar of California addresses breach of confidential data

#42
post #40

Earlier quoted context omitted.

Not exactly following. Couldn't DMs simply not be E2E encrypted while maintaining encryption for personal info?

End to end encrypted with what key? What if the user changed their password? What if they got a new phone? What if the server is only pretending the user got a new phone to trick you into leaking your messages? All of those problems are solvable, but "simply" is hardly the word I'd use to describe designing a secure end-to-end encrypted application. It's way, way more development effort than just "hash user passwords…

Sorry, still not following. I wrote not E2E encrypted. I'm struggling to understand why messages that are not E2E encrypted would require key management.

Re: State Bar of California addresses breach of confidential data

#43
post #35
post #26

Earlier quoted context omitted.

Something that stuck out to me about that website is that we really do publish a lot. If you ever had a speeding ticket, that’s a matter of public record now. If you ever had a parking violation, that’s a matter of public record. I mean to be honest, if you just have a car, I can probably find you on that website if I know your name. Also goes for divorces. By and large I agree with your take, but playing around with…

I have owned a car in NY, FL, and CA, have been married, and have received parking violations in all 3 of those states, and my very unique name is not present at all on that website.

I think their coverage is still spotty. I'm in California, and searched some names I know. The results came from some counties, but nothing from others. Notably I never saw anything from Los Angeles County, but tons of results from San Bernardino County.

My own name brought up a couple tickets. In 2014 I got a cell phone ticket. There's something kind of funny seeing an all-caps official document explaining that THE PEOPLE OF THE STATE OF CALIFORNIA were all arrayed against me! :)

Re: State Bar of California addresses breach of confidential data

#44
post #39
post #10

> We apologize to anyone who is affected by the website’s unlawful display of nonpublic data Sounds like Missouri teachers SSN leak again... The website that judyrecords scraped, discipline.calbar.ca.gov, contained all of these "nonpublic" records for anyone to see.

It can be legal for you to scrape something yet very illegal to reproduce it. This applies even more when the site you scraped didn't have permission to show the data in the first place. Their mistake does not rise to be your permission; if it was my data, I would have as much a claim against you as them. "The software did it" is not an excuse.

The software didn't do it, indeed. The custodians of the data who allowed private data to be made public did it.

Re: State Bar of California addresses breach of confidential data

#45
post #35
post #26

Earlier quoted context omitted.

Something that stuck out to me about that website is that we really do publish a lot. If you ever had a speeding ticket, that’s a matter of public record now. If you ever had a parking violation, that’s a matter of public record. I mean to be honest, if you just have a car, I can probably find you on that website if I know your name. Also goes for divorces. By and large I agree with your take, but playing around with…

I have owned a car in NY, FL, and CA, have been married, and have received parking violations in all 3 of those states, and my very unique name is not present at all on that website.

AFAIK, a parking ticket would be written against a car/license plate. Obviously that can be attached to a registration if the ticket is unpaid but it's not clear to me that a record of the violation would necessarily have the name attached in the record.

Re: State Bar of California addresses breach of confidential data

#46
post #26

Earlier quoted context omitted.

Something that stuck out to me about that website is that we really do publish a lot. If you ever had a speeding ticket, that’s a matter of public record now. If you ever had a parking violation, that’s a matter of public record. I mean to be honest, if you just have a car, I can probably find you on that website if I know your name. Also goes for divorces. By and large I agree with your take, but playing around with…

I agree there are limits; there are no absolutes in anything. We don't have absolute free speech: you can't slander, commit fraud, conspire to commit a crime, incite a deadly stampede, etc. I think the main concern is that the more powerful the actor (e.g., government is very powerful) the more important transparancy is, and the more vulnerable the actor, the more important privacy is. For example, if an Apple (picki…

So what’s the limiting principle you would use? That’s the problem. I no more care about Apple’s speeding violations than I do Joe Schmo’s, but I probably do care about whether Joe here has a criminal history if I’m interviewing him, and the nature of that history.

You could go by legal entity, just make lawsuits involving corporations public, and lawsuits between individuals private: but while Apple might have global influence, your rich and litigious neighbor in a rural county is probably a more immediate concern to you. Also individuals can sue corporations and corporations can sue individuals.

I’m still inclined to think court records should stay public, but I’m now more interested in seeing if there’s a kind of filter we can put on what we make public than I was two weeks ago.

Re: State Bar of California addresses breach of confidential data

#47
post #30

Earlier quoted context omitted.

I thought something was off about that site. I doesn't seem fair or legal to just publish that data like that. I think in the era of go in and get things things should be "public". Now in the search engine age and data available at your fingertips we need to entirely change our public records laws... Immediately. edit: In fact a HN User said this with NO REPLY from the author of that Show HN: I have some records that…

>> we need to entirely change our public records laws... Immediately. I am certain that many people in government would agree with you - they would LOVE to be able to hide what they are doing and not be held accountable for decisions they make (or don't make). We need more public disclosures, not less, imo. >>So there are records that were once ‘public’ but are no more, but this database makes them public again. This…

> once something is public, and in control of others, it is impossible to make them 'un-public' without violating the 1st amendment.

I do not think that is accurate.

Re: State Bar of California addresses breach of confidential data

#48
post #26

Earlier quoted context omitted.

Something that stuck out to me about that website is that we really do publish a lot. If you ever had a speeding ticket, that’s a matter of public record now. If you ever had a parking violation, that’s a matter of public record. I mean to be honest, if you just have a car, I can probably find you on that website if I know your name. Also goes for divorces. By and large I agree with your take, but playing around with…

I agree there are limits; there are no absolutes in anything. We don't have absolute free speech: you can't slander, commit fraud, conspire to commit a crime, incite a deadly stampede, etc. I think the main concern is that the more powerful the actor (e.g., government is very powerful) the more important transparancy is, and the more vulnerable the actor, the more important privacy is. For example, if an Apple (picki…

With your same example though, now this employee is listed in a bunch of Apple lawsuits and will be unable to ever get a job again because of this kind of search engine.

Re: State Bar of California addresses breach of confidential data

#49
post #30

Earlier quoted context omitted.

I thought something was off about that site. I doesn't seem fair or legal to just publish that data like that. I think in the era of go in and get things things should be "public". Now in the search engine age and data available at your fingertips we need to entirely change our public records laws... Immediately. edit: In fact a HN User said this with NO REPLY from the author of that Show HN: I have some records that…

>> we need to entirely change our public records laws... Immediately. I am certain that many people in government would agree with you - they would LOVE to be able to hide what they are doing and not be held accountable for decisions they make (or don't make). We need more public disclosures, not less, imo. >>So there are records that were once ‘public’ but are no more, but this database makes them public again. This…

> I am certain that many people in government would agree with you - they would LOVE to be able to hide what they are doing and not be held accountable for decisions they make (or don't make). We need more public disclosures, not less, imo.

Agreed 100%, a local court has been making precedents with that and...it's unnerving.

https://www.thv11.com/article/news/politics/routine-gag-orde...

Re: State Bar of California addresses breach of confidential data

#50
Why is it so impossible for these people/organizations to accept that they made a mistake and own up to it? The entire response by the State Bar of California is nothing but a deflection of blame that rests solely on themselves and their chosen vendor(s).

What are they going to do next, call Missouri's governor and ask for the playbook to follow? The humans behind the scenes at the bar are looking incredibly pathetic here.

Post reply on HN