Live data from Hacker News

Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

wired.com

71–80 of 307 posts

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#71
post #45

Earlier quoted context omitted.

The credit card info is called "level 3 data" and they in some cases have line item by line item detail. Not just "spend $24.89 at Meijer store #349" but each individual thing, e.g. you bought 2 avocados.

Is this data available to mortals? I don't even have digital itemized receipts for credit card purchases, and it's my purchase!

Mastercard and Visa [1] sell this data in aggregate to firms via brokers like Bluekai, to allow for ad-targeting.

I don't believe it'll be feasible to purchase just one person's purchase data [easily], but if you knew who you wanted to get to, it should be possible to narrow the targeting to get to them

[1] http://www.oracle.com/us/solutions/cloud/data-directory-2810... [ctrl+F + mastercard]

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#72

This is laughable. Data security is a fairy-tale. We've all been bought and sold and there is nothing any of us can do to fix it.

Erm, not opening up this fucking Elasticsearch instance to the entire internet would be a pretty easy way to get like 90% of the way there. I do operations. I can tell you exactly how not to make rookie mistakes like this. But security isn’t sexy, and it isn’t profitable, so it falls by the wayside.

The problem isn’t that these people are incompetent at network security (they are), the problem is that these people had your data to begin with. Data security is impossible because there is a massive shadow market for your entire life history and no amount of privacy setting theater will make up for the fact that your personal data is currently the target of an insatiable feeding frenzy.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#73

Earlier quoted context omitted.

It's almost as if the issue is more complicated than the solution represented by the GDPR. I mean, I'm a "tin hat" privacy nut in the USA, but that doesn't mean that I'm a fan of 100% of the GDPR. It has plusses and minuses. It'd be nice to have a conversation about them.

The question though is what's the alternative? The IT industry has failed spectacularly in protecting citizens' personal data. I'm not a fan of EU bureaucracy, but it looks as if they are on the right side of history on this one.

I'm suggesting that the alternative is a modification of the GDPR. It has a lot of great aspects, and some aspects that are kinda terrible.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#74
post #44

Earlier quoted context omitted.

From what I know, it started a few years ago; but not all big stores had the equipment in place to send it (the cc processors give them a discount for sending the line-item level 3 data). With the advent of the chip and pin cards in the USA, it seems logical that just about everyone upgraded to equipment that does support it; which might explain why you are only seeing this in the past year.

So, this seems a little opposite of what I meant. Naive me always assumed I pay with a card, the store gets my cc info to charge and we part ways. I'm getting in the mail ads from Meijer, for items I buy frequently. This tells me they were able to extract my home address and name from my credit card. Is that accurate?

Yes, these data are all available, if you are willing to pay to get those.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#75
post #50
post #14

When will this stop? When's the last straw? If I gave a bank 100 dollars, and they lost it, I'd have avenues with which to pursue some sort of justice. If I give a company my data, and they lose it, oh well. I wish all personal data was treated like HIPAA, at a minimum.

> If I give a company my data, and they lose it, oh well. I wish all personal data was treated like HIPAA, at a minimum. And yet, when GDPR tries to address the issue, HN is full of "blocking the damned EU users completely" and "stop stifling honest companies".

As someone who owns services which had to provide our data for customers as part of GDPR I was super happy to oblige.

The work sucked, but I was more than happy to help our customers get their data from us.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#77

Earlier quoted context omitted.

Congress grilled Equifax and nothing. Average person saw Equifax commercial on “hey be smart we will keep your info safe with alerts” and thought “wow this company cares about my data” when its precisely opposite. If the congress is unable or doesnt want to draft a bill to stop predators from milking money off of your data, then that money probably ends up in their pocket some way. Or at least some of it. Please dont…

Do you have any data to support your claim about what the average person thought about Equifax and Congress? I have a lot of strong opinions about privacy, but I'm also resigned to the fact that most people don't care about it as much as I do. So I don't guess what they're thinking.

> Do you have any data to support your claim about what the average person thought about Equifax

Here you go, first result in Google:

https://morningconsult.com/2018/01/16/months-after-data-brea...

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#78
post #50

Earlier quoted context omitted.

> If I give a company my data, and they lose it, oh well. I wish all personal data was treated like HIPAA, at a minimum. And yet, when GDPR tries to address the issue, HN is full of "blocking the damned EU users completely" and "stop stifling honest companies".

It's almost as if the issue is more complicated than the solution represented by the GDPR. I mean, I'm a "tin hat" privacy nut in the USA, but that doesn't mean that I'm a fan of 100% of the GDPR. It has plusses and minuses. It'd be nice to have a conversation about them.

The issue isn't complicated at all. Regardless of any country's laws. Don't use my personal information for anything other than verifying my identity or record keeping. Don't give it to anyone, don't sell it to anyone, don't use it for marketing bullshit, dont analyze it to find out how to sell me things, or how to trap me in targetted advertising (which I block anyway because you have no right to spam me with them or waste my bandwidth) or filter bubbles. If you can't do that when fuck off, there's no reason I should do business with you.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#79
post #32
post #8

And, they made fun of RMS... He was telling you what the future holds. This is just a trailer of what is to come.

I agree, it is really unfortunate that even people within the software development profession take these issues so lightly.

I don't think it's so much that software devs take it "lightly". In my experience as a infosec consultant, the bigger problem is that most software devs are too cocky when it comes to security. Most think that security is just a subdomain of computer science (it is not!), and that because they took a crypto class in college, they are 100% qualified to handle the security themselves. They think they are taking it seriously, but they don't understand that knowing how to write software does not make you an expert in securing software.

Most devs don't seem to acknowledge that good security requires having a separate, dedicated person/team to handle it, just like how you would hire a lawyer rather than having your software devs handle legal issues.

I once posted on HN that every company that deals with sensitive data, big or small, must have a dedicated security person/team. My comment was downvoted/flagged, and I was bombarded with responses like "why would we waste the money on a security person? my dev team already knows to encrypt passwords".

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#80
post #14

When will this stop? When's the last straw? If I gave a bank 100 dollars, and they lost it, I'd have avenues with which to pursue some sort of justice. If I give a company my data, and they lose it, oh well. I wish all personal data was treated like HIPAA, at a minimum.

Same flawed logic as in online piracy. No one lost your data, they still have it, but someone else made a copy.

A rather irrelevant nitpick to this discussion. Let's not pretend we didn't know what lost meant in this context. And of course it's the process of making a copy that's the issue.
Post reply on HN