I can't tell whether this is a testament to the incompetence of public IT operations or an indictment of public records keeping practice. Maybe both?
Also has a good example of hostile FOIA officers. I have filed about two dozen FOIA requests, and the vast majority were fine, though usually slow. Earlier this year one longstanding request of mine was rejected because they claimed the document I wanted was export controlled. Two months later I sent in an appeal where I showed that the document in question was not export controlled (I filed another FOIA with a separ…
The City of Seattle Accidentally Gave Me 32M Emails for $40
51–60 of 239 posts
Re: The City of Seattle Accidentally Gave Me 32M Emails for $40
#52Earlier quoted context omitted.
For the ballpark estimate, I think they just wanted for the request to go away by quoting an insanely high price.
Long long term resident with a connection to local government They don't have a choice. Seattle IT is so underfunded that hands are tied because there isn't any resourcing. On one hand, you have to respond to all of these requests (and rightfully so, as it's the law.) On the other, you have no money for your department because it has no funding because the citizens didn't want to spend the money. The person who did t…
City Light and the new meters/new billing system are great examples, all the new power meters have no encryption, and use FSK for modulation. Asking City Light about this got me a response that FSK was the encryption, and the gal was dumbfounded when I pointed her to the Wikipedia article on FSK.
On the billing side, an Oracle salesman ran off with over $100 million in city funds for what is essentially a CRUD app, and the worst part is they didn't bother to customize this system, just forklifting this in place and letting the chips fall where they may. The prior billing system had quite a bit of data validation and business logic that has yet to be implemented or replicated on this new system. The same actions when you call customer service now take significantly longer.
Both these vendors fleeced the city for broken, insecure systems, and neither is having to face the music for it. Worst part is, eventually someone may attempt a fairly trivial exploit of either system, which could wreak havoc in our city.
Re: The City of Seattle Accidentally Gave Me 32M Emails for $40
#53> Funny enough, in the middle of that question, my internet died and interrupted the call for the first time in the six months I lived in that house. Odd. It came back ten minutes later, and I dialed back into the conference line, but the mood of the call pretty much 180’d.
I find that when strange things happen like this, they’re hardly coincidence. Did you run a traceroute after the disconnect anywhere? Did you see an IP address change? If so, was it a significant change in the CIDR block it was within?
Re: The City of Seattle Accidentally Gave Me 32M Emails for $40
#54I find the writer to be a bit of a dick in his responses. Yes, the city IT may not be at the same level as Google engineers, but there’s no need to mock their ballpark estimates, and after the mistake there’s no need to be a jerk about it. Be forthright about the error. Consider being on the other side of this, due to a careless mistake the data for many people is exposed on a random strangers hard drive. Asking for…
You are asking for leniency on the side of the officials, yet do not seem to be willing to apply the same standard to the requester. Yes, it could have been handled better, but that applies equally to both sides. Anybody that does FOI requests that have the potential to retrieve a lot of sensitive data due to mis-understandings or mistakes (which is pretty much all of them) should handle the data carefully until they have verified upon receipt that it is what it should be and that the data is not somehow more sensitive than intended.
The author did ok in that respect, could have still done better and the city would have been served better by refusing the request as stated until order by a judge to release it based on the grounds that it is an overbroad request, which will result in the release of privacy sensitive information if fulfilled.
Re: The City of Seattle Accidentally Gave Me 32M Emails for $40
#55I find the writer to be a bit of a dick in his responses. Yes, the city IT may not be at the same level as Google engineers, but there’s no need to mock their ballpark estimates, and after the mistake there’s no need to be a jerk about it. Be forthright about the error. Consider being on the other side of this, due to a careless mistake the data for many people is exposed on a random strangers hard drive. Asking for…
I'm curious what his actual legal exposure would have been if he hadn't folded. I feel like they should have offered to compensate the author for his time in their initial request - if someone wanted to perform forensic scans on my hard drives it would be a huge inconvenience.
Re: The City of Seattle Accidentally Gave Me 32M Emails for $40
#56To me, the most interesting thing in this entire post is the following: > Funny enough, in the middle of that question, my internet died and interrupted the call for the first time in the six months I lived in that house. Odd. It came back ten minutes later, and I dialed back into the conference line, but the mood of the call pretty much 180’d. I find that when strange things happen like this, they’re hardly coincide…
Also, once they realized they had left the room of course they would continue to discuss the case and it is obvious they had to consider all possibilities, including the recipient releasing the information to others, hence the 180.
Re: The City of Seattle Accidentally Gave Me 32M Emails for $40
#57Earlier quoted context omitted.
For the ballpark estimate, I think they just wanted for the request to go away by quoting an insanely high price.
It was a reasonable ballpark. Let's say a city prosecutor was working on a organized crime case that involves the FBI and other people. Based on timing of emails this would leak the list of people working on the case, maybe informants and put them at risk. We all lost our collective shit when NSA said they're only collecting metadata. Metadata is Data.
And in many cases metadata is just as useful as the payload, in some cases even more useful.
Re: The City of Seattle Accidentally Gave Me 32M Emails for $40
#58Earlier quoted context omitted.
I probably only spent 30 minutes looking at it and used a few regular expressions to look for anything interesting. The point there was to understand the extent of the leak so that I could raise it in the intent of being taken seriously. A search for "(Fuck|Shit|Bitch)" can go a long way. For what it's worth, I used to work at an investment bank spending 30hr/week diving through logs with unix tools, so finding inter…
FWIW I think you should not have done that, though I understand the temptation. At the first indication that the data was not what you requested and contained more than you - or they - bargained for you should have stopped looking at it and alerted both the sender and the relevant data protection authorities in so far as those are a functioning entity where you live to tell them they have an 'accidental disclosure' o…
I guess if all that is in those records I’m going to commend the Seattle IT department for their ethics at least.
It’s amazing what people think they can put in emails/messages and have stay secure...
Re: The City of Seattle Accidentally Gave Me 32M Emails for $40
#59Earlier quoted context omitted.
It was a reasonable ballpark. Let's say a city prosecutor was working on a organized crime case that involves the FBI and other people. Based on timing of emails this would leak the list of people working on the case, maybe informants and put them at risk. We all lost our collective shit when NSA said they're only collecting metadata. Metadata is Data.
Since they revised the cost for the data they actually sent him down from $33M to $56 (90 days of data at $1.25 for 2 days data), was a ballpark estimate that's over 500,000 times higher than the actual cost really reasonable?
IT estimated the requestor fees to be $21k/year assuming 10TB of data.
Clearly, IT were estimating the costs of releasing all email text, because FOIA mistakenly changed the words "please provide the following information:" to "including metadata:"
Once they figured out the request was for header information only, the city came back with an estimate of under $60.
Re: The City of Seattle Accidentally Gave Me 32M Emails for $40
#60Earlier quoted context omitted.
FWIW I think you should not have done that, though I understand the temptation. At the first indication that the data was not what you requested and contained more than you - or they - bargained for you should have stopped looking at it and alerted both the sender and the relevant data protection authorities in so far as those are a functioning entity where you live to tell them they have an 'accidental disclosure' o…
If all that information is available in plaintext to the relevant IT department, does it really matter that one other person is party to it? I guess if all that is in those records I’m going to commend the Seattle IT department for their ethics at least. It’s amazing what people think they can put in emails/messages and have stay secure...
One citizens communications with the city should not automatically result in disclosure of the fact that that person communicated with the city to other citizens.
The fact that a communication took place in itself is information, and correlated with things like timestamps and who in the city was contacted a large amount of sensitive information will leak out.