Live data from Hacker News

Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

wired.com

81–90 of 307 posts

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#81
post #34
post #13

Is there a torrent yet? I want to lookup my own data.

It was discovered by a white hat; he didn't publicise a data dump.

s/white/ass/.

A white hat, in the context of these surveillance companies, would be Tyler Durden.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#83

Earlier quoted context omitted.

The question though is what's the alternative? The IT industry has failed spectacularly in protecting citizens' personal data. I'm not a fan of EU bureaucracy, but it looks as if they are on the right side of history on this one.

> what's the alternative? Absolute liability for data losses. Exactis lost 360 million peoples' data. They should be able to (a) form a class and (b) extract money damages from Exactis without having to prove specific harm, which is difficult to do with data loss. A good model is Illinois' Biometric Information Privacy Act [1]. Broaden the the definition from "biometric identifier" to a longer--but still specific--li…

That's basically what GDPR does. It broadens the scope of what is considered sensitive info and slaps a fine on people PRIOR to a breach. If a breach is found, then any breach of GDPR means EU can come after that company and hurt them seriously.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#84

Earlier quoted context omitted.

Do you have any data to support your claim about what the average person thought about Equifax and Congress? I have a lot of strong opinions about privacy, but I'm also resigned to the fact that most people don't care about it as much as I do. So I don't guess what they're thinking.

> Do you have any data to support your claim about what the average person thought about Equifax Here you go, first result in Google: https://morningconsult.com/2018/01/16/months-after-data-brea...

The claim was:

> Average person saw Equifax commercial on “hey be smart we will keep your info safe with alerts” and thought “wow this company cares about my data” when its precisely opposite.

The result you cite is a general consumer favorability rating for Equifax, which is different than this particular claim. People who didn't hear anything about Equifax and Congress are included in the general consumer poll. I'm not trying to nitpick, I'm just pointing at a lack of data for this particular claim.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#85
post #23

"exposes" here is quite a strange term, because their entire business is selling that same data. The only difference is that it was briefly available without a price tag.

Exactly! The only thing a "breach" changes is allowing us to actually see the files that Stasi 2.0 are keeping!

I'm much more worried about the persistent legally-blessed attacks against our decision making (eg advertising) and financial independence (eg price discrimination), than about receiving backscatter from uncoordinated randos defrauding banks et al. Banks who are responsible for much of this surveillance infrastructure in the first place.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#87
post #14

When will this stop? When's the last straw? If I gave a bank 100 dollars, and they lost it, I'd have avenues with which to pursue some sort of justice. If I give a company my data, and they lose it, oh well. I wish all personal data was treated like HIPAA, at a minimum.

The problem is that you can use data an infinite amount of times, but spend money only once.

Data are facts, money is a repository of value. With a bank, you are the customer. With marketing, you are the product.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#88

Earlier quoted context omitted.

The question though is what's the alternative? The IT industry has failed spectacularly in protecting citizens' personal data. I'm not a fan of EU bureaucracy, but it looks as if they are on the right side of history on this one.

I'm suggesting that the alternative is a modification of the GDPR. It has a lot of great aspects, and some aspects that are kinda terrible.

It seems like the biggest issue with GDPR is that it’s comes from Europe and not the US? Historically speaking, Europe has in many issues come to agreement on technically solutions and industrial standards many years ahead of the US.

For example, Europe was first on texting on the mobile network while the US (single country) took years to come to a standard.

I think it will be the same with regards to GDPR. You (US) will discuss this for years and come up with a different law.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#89
post #18

> "I don’t know where the data is coming from, but it’s one of the most comprehensive collections I’ve ever seen" > Each record contains entries that go far beyond contact information and public records to include more than 400 variables on a vast range of specific characteristics: whether the person smokes, their religion, whether they have dogs or cats, and interests as varied as scuba diving and plus-size apparel.…

> so not necessarily super accurate.

Even worse. Many people say they “don’t have anything to hide” because they too haven’t considered the vast consequences regardless of having something to hide. For starters, when the data is inaccurate, you might have something to hide that even you didn’t know about, and it could be responsible for all sorts of events and opportunities in your life both public and private without you even knowing. Things that give you an different life experience than your friends to an unknown degree. This sort of lack of knowledge, control, deprivation of explanation or closure etc. would be the lived experience of chaos and it’s one of the most frightening parts.

Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records

#90
post #45

Earlier quoted context omitted.

Is this data available to mortals? I don't even have digital itemized receipts for credit card purchases, and it's my purchase!

Mastercard and Visa [1] sell this data in aggregate to firms via brokers like Bluekai, to allow for ad-targeting. I don't believe it'll be feasible to purchase just one person's purchase data [easily], but if you knew who you wanted to get to, it should be possible to narrow the targeting to get to them [1] http://www.oracle.com/us/solutions/cloud/data-directory-2810... [ctrl+F + mastercard]

Wouldn't a GDPR request to Visa or MasterCard in the EU get me this data?
Post reply on HN