Live data from Hacker News

The City of Seattle accidentally gave me 32M emails for $40 (2018)

mchap.io

41–50 of 230 posts

Re: The City of Seattle accidentally gave me 32M emails for $40 (2018)

#41
post #8

Earlier quoted context omitted.

In the US emails to and from government workers are generally considered public record. It's important for transparency.

I agree that government records should be open and are good for transparency. The problem comes when people don't realize that something they're doing would put all of the personal information they've submitted into the public record, or when it's required to do this to access a service. In Washington, and Seattle specifically, doing something as simple as reserving a park space or signing up for a constituent newsle…

The counterpoint is that as a citizen, I should be able to find out who keeps renting out the park and ruining the grass because ultimately, we the people hold the government accountable.

In the early years of the rollout of federal income tax, the government lacked an IRS to enforce the code. They addressed the issue by making income tax filings public knowledge, so that if individuals saw that, for instance, their neighbor was claiming poverty income on their spacious mansion with the new well-appointed carriage house, they could sic the feds on them. Today, many states still post the voter rolls (and their status, such as "out of town for this election") at voting places because it's considered to be part of the public's right to defend the vote by noticing that Steve said he'd be out of town (or moved last month), but here he is in the voting line; is he trying to double-vote?

Re: The City of Seattle accidentally gave me 32M emails for $40 (2018)

#42

If you can't load the blog: - He FOIA'd all metadata of emails to and from the City of Seattle. - The city IT department pushed back, saying that their policy was to hand-review each email for privacy, and this was 32m emails. - They later acquiesced and just dumped all of the meta-data into files and sent it over - They didn't realize email-preview was also meta-data, which included the first 256 char of each email.…

> The job seems awful How hard can it be to do a sanity check of the metadata?

The dataset was so large they were probably not opening up the files before sending them over. It was clearly a rookie mistake by someone who had never had to do this stuff before and wouldn't have known what to look for.

Again, the vast majority of the emails were automated alert/spam emails. So it's unclear if a random sample of the data would have turned up anything interesting to look at if you didn't know what you were looking for.

Re: The City of Seattle accidentally gave me 32M emails for $40 (2018)

#43

Government IT is famously expensive, and so often a disaster. I recently needed to open an account with a local agency. The fun started with two date fields on the web form, which turned out (trial and error) to require different formats. I finally received my credentials, but they didn't work. Assuming that the password was likely the problem, I tried the password reset function, only to get a 404 error. The person…

It’s funny because I once had to hand edit the form on an experian website to sign up because their stupid UI wouldn’t let me enter in a date in the right format

Re: The City of Seattle accidentally gave me 32M emails for $40 (2018)

#44
post #22

The most interesting part of this story is the potential legal risk of holding onto the records that were improperly disclosed. Had the author not notified the city that they had royally screwed up by divulging far more sensitive information than they had realized, they likely would have never realized the error, and he would have been free to do whatever he liked with the data. But once he notified them of their err…

> They thanked me for bringing the situation to their attention and all that, but the mood of the call was as if both parties had a knife behind their back. Somewhere towards the end of the call, I asked them if it was okay to keep the emails. Why not at least ask, right? >...This isn't something I'm even remotely cool with, so we ended the call a couple minutes later, and agreed to have our lawyers speak going forwa…

I wouldn't call the city asking for the writer to agree to a warrantless search "acting in very good faith".

Re: The City of Seattle accidentally gave me 32M emails for $40 (2018)

#45
post #22

The most interesting part of this story is the potential legal risk of holding onto the records that were improperly disclosed. Had the author not notified the city that they had royally screwed up by divulging far more sensitive information than they had realized, they likely would have never realized the error, and he would have been free to do whatever he liked with the data. But once he notified them of their err…

> They thanked me for bringing the situation to their attention and all that, but the mood of the call was as if both parties had a knife behind their back. Somewhere towards the end of the call, I asked them if it was okay to keep the emails. Why not at least ask, right? >...This isn't something I'm even remotely cool with, so we ended the call a couple minutes later, and agreed to have our lawyers speak going forwa…

I would refuse to cooperate with the third party auditor as well. No one gets to scan my hard drive without a court order. And even then, I wouldn't provide the decryption passphrase unless I was legally required to.

Even though there isn't anything illegal or incriminating on my hard drive (as far as I know, anyway), I wouldn't agree to let someone violate my privacy for a mistake they made.

Regardless, this whole thing would be "verification theater". OP could have copied the records out to a flash drive before deleting them from the hard drive, and hid it in his floorboards, and there'd be no record he did that. Third-party audit would say "yep, looks like the files have been deleted off the hard drive", and that would be that.

Also, "good faith"? The lawyer OP ended up talking to said that their behavior seemed to indicate they were moving in the direction of CFAA charges. While we can't know that for certain, that's quite the opposite of good faith.

Re: The City of Seattle accidentally gave me 32M emails for $40 (2018)

#46

Earlier quoted context omitted.

> The job seems awful How hard can it be to do a sanity check of the metadata?

The dataset was so large they were probably not opening up the files before sending them over. It was clearly a rookie mistake by someone who had never had to do this stuff before and wouldn't have known what to look for. Again, the vast majority of the emails were automated alert/spam emails. So it's unclear if a random sample of the data would have turned up anything interesting to look at if you didn't know what y…

I don't agree, I think opening any of the files would have made it immediately apparent that the first 256 chars of each email were included, if that's indeed what happened as the article said.

Re: The City of Seattle accidentally gave me 32M emails for $40 (2018)

#47
That was a fun read.

Having worked as a sysadmin on the other end I can almost guess how his initial request was received.

As many others do they only read part of his request and were dumbfounded by the scale of it. So in their minds he was requesting way too much information and they probably spent days at the water cooler laughing at this guy under wrong pretences.

Eventually someone realized their misinterpretation and proceeded to make the dire mistake of exporting the e-mail headers with a cut off at a hard coded value I'm assuming. Instead of parsing out the headers from the email.

And it wasn't until he pointed this out to them that they started taking him seriously. :D

Re: The City of Seattle accidentally gave me 32M emails for $40 (2018)

#48
post #22

The most interesting part of this story is the potential legal risk of holding onto the records that were improperly disclosed. Had the author not notified the city that they had royally screwed up by divulging far more sensitive information than they had realized, they likely would have never realized the error, and he would have been free to do whatever he liked with the data. But once he notified them of their err…

> They thanked me for bringing the situation to their attention and all that, but the mood of the call was as if both parties had a knife behind their back. Somewhere towards the end of the call, I asked them if it was okay to keep the emails. Why not at least ask, right? >...This isn't something I'm even remotely cool with, so we ended the call a couple minutes later, and agreed to have our lawyers speak going forwa…

OP could have easily copied the contents to another disk or remote server if they were malicious, and then still complied with the search. There is no way to prove the data was never moved to another system. That is besides the point that their mistake should not become his problem to deal with.

Re: The City of Seattle accidentally gave me 32M emails for $40 (2018)

#49
post #22

The most interesting part of this story is the potential legal risk of holding onto the records that were improperly disclosed. Had the author not notified the city that they had royally screwed up by divulging far more sensitive information than they had realized, they likely would have never realized the error, and he would have been free to do whatever he liked with the data. But once he notified them of their err…

> They thanked me for bringing the situation to their attention and all that, but the mood of the call was as if both parties had a knife behind their back. Somewhere towards the end of the call, I asked them if it was okay to keep the emails. Why not at least ask, right? >...This isn't something I'm even remotely cool with, so we ended the call a couple minutes later, and agreed to have our lawyers speak going forwa…

>… and refused to cooperate with the third party auditor

Well, yeah. No way I am letting someone scan and archive my drives/data to correct their mistake. They broke other people’s privacy and now they want to break mine? Pound sand.

Even if they could prove my drives had been wiped, that would do nothing to prove it had not been otherwise copied elsewhere.

Re: The City of Seattle accidentally gave me 32M emails for $40 (2018)

#50
post #12

What happens if he refused the lawyer request to scan his hard drive?

Criminal proceedings.

Honestly, the city had no way of knowing that he hadn't already sold the entire dataset on Silk Road, so they were instilling a huge amount of trust that he was being a "Good Samaritan".

Post reply on HN