Live data from Hacker News

The City of Seattle Accidentally Gave Me 32M Emails for $40

mchap.io

71–80 of 239 posts

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#71

I find the writer to be a bit of a dick in his responses. Yes, the city IT may not be at the same level as Google engineers, but there’s no need to mock their ballpark estimates, and after the mistake there’s no need to be a jerk about it. Be forthright about the error. Consider being on the other side of this, due to a careless mistake the data for many people is exposed on a random strangers hard drive. Asking for…

> Asking for an independent third party verification is reasonable. Not really, for the same reason they never should have sent the excess data in the first place... Why should he give up his privacy to some 3rd party company to help cover up their mistake?

Plus it opens up dangerous precedence. "Oops, here's some confidential data you never asked for, let me send a couple guys to scan your hard drives".

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#72
post #41

Somewhat related, I'm constantly shocked (maybe I shouldn't be anymore) at the tech ineptitude of cities that are supposed to be big tech hubs. I live in Seattle, and my regular tech complaint is we can't get the buses connected to an app that is accurate within +-10 minutes. I know it doesn't sound like much, but how much tech brainpower is here, and why isn't that tech shining more clearly?

Have you used the OneBusAway app? It's accurate for the buses I take. Is it inaccurate for your routes?

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#73
post #48

I'm very surprised they gave out this information. I'm not talking about the mistake, I mean the actual request. In the UK I don't think you could even get a production order for this. Like, it's effectively getting Communications Data simultaneously against thousands of people not suspected of any crimes?? Like, do people know that by emailing their local government their email address is now free for scammers to re…

I have never assumed that an email address I gave the government would be protected. I would also not assume that the contents of any email I sent would be in any way protected either. The government is collectively owned. Your police record, where you live, who you're married to, and whether or not you voted last election are publicly available. I would rather all of that be protected in some way, but I think it's c…

> I have never assumed that an email address I gave the government would be protected. I would also not assume that the contents of any email I sent would be in any way protected either.

I have similar assumptions, but what about the less technically inclined citizens?

Moreover, I wouldn't be surprised if the ploy described by the OP:

> Could I request this data myself, then start emailing them scam emails "I know you contacted us in June, could you call me on 555-1223 etc"

would work on me. Really, it would take me checking DKIM and/or SPF to notice such an email. And from this story it seems likely the city of Seattle doesn't actually implement DKIM or SPF.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#74
post #70

Earlier quoted context omitted.

Because it is just the timing that makes you say this, and I highly doubt the city of Seattle can - on a moments notice, no less - pull the plug on any residential internet connection. If true, that would be a far bigger news item than the rest of your story.

Who knows. It was strange for me, too.

Think about it: you see your internet connection dying as proof when they could have just as easily booted you from the conference call raising much less suspicion. I see it as proof of the opposite, they had a far easier and more direct means at their disposal to achieve the effect you say they desired. So I really do not believe that it was anything other than bad timing, all that it would take for this to happen is for your provider to reset a router somewhere.

My residential connection here is pretty good, even so it goes up and down at least once every week or so whenever some firmware update is pushed to the router.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#75

Interesting dataset. Data like this can be used to identify strong links between contractors and government officials. One problem is that the metadata should have only contained anonymized entries for the email addresses of the counterparties of the Seattle.gov addresses, the article leaves this unclear. Another potential problem is that if a case of corruption or nepotism is identified that has not been passed to t…

hash@hash alone isn't enough. Keyed hashes, with a secret key might work.

The issue with hash@hash is that it is still possible to see whether a given person sent an email. Moreover, there are probably similar issues as with hashed_known_hosts as described in [1]. In short, the space of possible emails might be small enough to just brute-force search for all e-mails.

[1] https://news.ycombinator.com/item?id=18082033

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#76

I was quoted almost $200k for a similar request for emails. I was trying to investigate a shady real estate deal, and they made it as difficult as possible. I was never actually able to get the information I requested. I'm completely disgusted and fed up with corruption.

Perhaps try and sell the story with some of the investigative podcasts / blogs? An apparent cover-up gets as much attraction as uncovered corruption. (As well it should).

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#77
post #43

A few years ago I found a random SSD on the ground while on a walk with my son. The drive contained unencrypted records which squarly fall under HIPPA. I also did the right thing and returned it to the proper owner and told them about how their mdb files were readable by anyone. The same exact thing happened. They thanked me and then their lawyers nicely asked me to clone my hard drive and sign a bunch of shit. It wa…

The type of organization that would store HIPPA encumbered data unencrypted, which based on my brief reading is not legal anymore, is not one that would operate in a reasonable (or legal) manner. Sadly, that seems to be most organizations that fall under HIPPA, compliance is a box to be checked while expending as little resources and effort as possible. How they reacted to your kind action is sad, and depressingly co…

Guys, it's HIPAA not HIPPA.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#78
post #43

A few years ago I found a random SSD on the ground while on a walk with my son. The drive contained unencrypted records which squarly fall under HIPPA. I also did the right thing and returned it to the proper owner and told them about how their mdb files were readable by anyone. The same exact thing happened. They thanked me and then their lawyers nicely asked me to clone my hard drive and sign a bunch of shit. It wa…

Did you actually give them that clone and sign the documents? Or did you give push back like in the article?

It feels to me like they shouldn't have much of a leg to stand on.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#79
post #41

Somewhat related, I'm constantly shocked (maybe I shouldn't be anymore) at the tech ineptitude of cities that are supposed to be big tech hubs. I live in Seattle, and my regular tech complaint is we can't get the buses connected to an app that is accurate within +-10 minutes. I know it doesn't sound like much, but how much tech brainpower is here, and why isn't that tech shining more clearly?

If you are an IT professional in a tech-hub, do you want to work for a bit IT company or for the municipality?

In a similar vein, do you think the municipality wages are competitive with those from the tech companies?

I could see how being a tech-hub would function to draw a lot of talent out of a municipality.

Re: The City of Seattle Accidentally Gave Me 32M Emails for $40

#80
post #67

Earlier quoted context omitted.

A good chunk of this is caused by our city repeatedly choosing awful vendors that bilk the city for crazy amounts of money, and provide trash as the final product. City Light and the new meters/new billing system are great examples, all the new power meters have no encryption, and use FSK for modulation. Asking City Light about this got me a response that FSK was the encryption, and the gal was dumbfounded when I poi…

The vendors may be horrible, but it's still on the shoulders of the city for choosing the vendors. This is really down to the fact that most decision makers have no idea how to understand or differentiate between options. It's been like this for decades. When a secretary of state doesn't know the risks in running a private independent email server and how to ensure those risks don't become issues, how do expect much…

I don't think it's good enough to say « it's still on the shoulders of the city for choosing the vendors ».

If I write a piece of software which is technically capable of meeting its requirements if you read the manual carefully enough, but in practice the intended users can't figure out how to do so, that piece of software is no good.

Similarly if the market is in principle providing IT vendors who are capable of providing a decent service, but in practice the purchasers can't figure out which ones they are or how to make them do so, the market has failed.

Post reply on HN