Live data from Hacker News

SparkFun Gets A Subpoena

sparkfun.com

51–55 of 55 posts

Re: SparkFun Gets A Subpoena

#51
What gives me a bit of hope is the fact that after the scary letter with a lot of legalese, SparkFun and the Police Department were able to just talk about it as people and do what was best for everyone. The police was not interested in having to sift through a big pile of irrelevant data; SparkFun was not comfortable handing over sensitive information of innocent customers. I wish it were more common that people just talk and cut the crap.

Re: SparkFun Gets A Subpoena

#52
post #29

Earlier quoted context omitted.

I suspect that the police in this case have no idea how big sparkfun is or how much business they do.

More likely, they just ask for everything in the hopes that they don't miss anything, and then rely on the targeted business to try to argue down the scope of the subpoena. The police have no incentive to try and limit the scope because they don't care about protecting the privacy of the people they're investigating.

> they don't care about protecting the privacy of the people they're investigating.

That seems like an overbroad generalization. All else being equal, I'm sure the police don't want to compromise people's privacy. To be sure it's not their top priority, and if they had to choose between missing important data and dragging too many innocent people into an investigation they will probably err on the side of too much data.

Even if the police don't much care about privacy, there are a lot of people who do. For example, there's no way a court would let any of this subpoenaed evidence into the record unless it was specifically relevant to a charge being brought.

Re: SparkFun Gets A Subpoena

#53
post #46
post #6

As a result, about 20 customers that had purchased a specific device at sparkfun that had delivery in Georgia had their information given to the police to use in this investigation. I really want the people running the skim operation caught, but I agree with Nate (the sparkfun guy) that it is a very fine line harassing the others that are (most likely) blameless. Am I reading this correctly that then these 20 people…

In a different case, it was their BlueSmirf module http://www.sparkfun.com/tutorial/news/SparkFun-PINScam.pdf

Which is interesting, because you'd think that credit card scammers would buy Bluetooth modules in bulk from Chinese sellers that are both cheaper and harder to subpoena.

Re: SparkFun Gets A Subpoena

#54
post #38
post #35

Earlier quoted context omitted.

You think all the police and courts and attorneys and judges and clerks and secretaries have a completely set up, and working private key infrastructure? You know that the police routinely handle & store information that people would kill to get at (hint: mobsters)? Do you not think they know how to protect information like this? If you were to email it encrypted, you'd have to send a follow email with the decryption…

The fact that they don't have anything more secure than unencrypted email gives reason to doubt that they know how to protect information like that. An encrypted mail attachment would be a start -- if you use a second channel to deliver the secret key, e.g. call them up to tell them the password.

OK so you doubt their means. Look at the ends. Have there been many security breeches from the police/courts? Is this a large threat to personal security? I don't think so. Hence I think they must be doing something right here.

Re: SparkFun Gets A Subpoena

#55
post #54
post #38

Earlier quoted context omitted.

The fact that they don't have anything more secure than unencrypted email gives reason to doubt that they know how to protect information like that. An encrypted mail attachment would be a start -- if you use a second channel to deliver the secret key, e.g. call them up to tell them the password.

OK so you doubt their means. Look at the ends. Have there been many security breeches from the police/courts? Is this a large threat to personal security? I don't think so. Hence I think they must be doing something right here.

The following is just one group's public releases, spanning about 5 months, at approx 20gb.

https://thepiratebay.se/user/AntiSecurity/

Just because you don't hear about vulnerabilities and attacks, doesn't mean they don't happen.

Post reply on HN