Live data from Hacker News

Ask HN: Found a leak of US citizens personal data. Should I report it?

news.ycombinator.com

1–10 of 85 posts

Ask HN: Found a leak of US citizens personal data. Should I report it?

#1
Security research is my hobby. Yesterday I found a pretty big (estimated at tens of thousands of records) data leak. Full name, date of birth, mail, phone, address. Nothing to do with the company. The company in California, I'm in Canada.

It's a data operator its customers are other companies from different states in the US. Texas, California, Florida and others.

I don't think I have the right to download all the leaked data. But my several checks showed that all clients and end-user data is available.

What should I do about it?

Re: Ask HN: Found a leak of US citizens personal data. Should I report it?

#2
I would try reporting it to the company, maybe also the FBI or FTC, or if you aren't too comfortable contacting them, you can try also contacting someone like Brian Krebs who presumably knows who to contact about data leaks of this nature. (Krebs' contact form: https://krebsonsecurity.com/about/ )

Re: Ask HN: Found a leak of US citizens personal data. Should I report it?

#3

I would try reporting it to the company, maybe also the FBI or FTC, or if you aren't too comfortable contacting them, you can try also contacting someone like Brian Krebs who presumably knows who to contact about data leaks of this nature. (Krebs' contact form: https://krebsonsecurity.com/about/ )

You could also check https://iapp.org/resources/article/state-data-breach-notific... and report it to state authorities in the relevant states (whichever you think those are). These notifications are usually supposed to be made by the company responsible for the data breach, but I imagine some of the state authorities would be interested to get a third-party report too.

Re: Ask HN: Found a leak of US citizens personal data. Should I report it?

#4
I'd question whether the potential blowback of doing the right thing is actually worth it.

Some organisations will be grateful for your help and you get that warm feeling that comes with knowing you've helped to protect peoples data. But, when it goes wrong and you become the target of the organisation's ire, the personal consequences can be severe.

Example: https://news.ycombinator.com/item?id=29745960

Re: Ask HN: Found a leak of US citizens personal data. Should I report it?

#6

I'd question whether the potential blowback of doing the right thing is actually worth it. Some organisations will be grateful for your help and you get that warm feeling that comes with knowing you've helped to protect peoples data. But, when it goes wrong and you become the target of the organisation's ire, the personal consequences can be severe. Example: https://news.ycombinator.com/item?id=29745960

I absolutely agree. It is unlikely that I will be thanked for such an act.

Destroy the reputation of a company with 10+ years of experience on the market. And force dozens of other companies across the U.S. to apologize to their customers for leaking data.

Not to mention lawsuits and fines for such a leak.

Re: Ask HN: Found a leak of US citizens personal data. Should I report it?

#7
If you want to do the right thing and help fix it use a burner phone to send proof and let someone else break the news who actually has something to gain from it. Like a news agency local to the company perhaps. You have nothing to gain and a lot to lose.

Re: Ask HN: Found a leak of US citizens personal data. Should I report it?

#8

I'd question whether the potential blowback of doing the right thing is actually worth it. Some organisations will be grateful for your help and you get that warm feeling that comes with knowing you've helped to protect peoples data. But, when it goes wrong and you become the target of the organisation's ire, the personal consequences can be severe. Example: https://news.ycombinator.com/item?id=29745960

I absolutely agree. It is unlikely that I will be thanked for such an act. Destroy the reputation of a company with 10+ years of experience on the market. And force dozens of other companies across the U.S. to apologize to their customers for leaking data. Not to mention lawsuits and fines for such a leak.

How about this for an idea:

1. Find the least-incriminating/reputationally damaging records within whatever quantum of the data you are prepared to look at

2. Make a website (with a landing page like for security bugs >.>), Tor site, pastebin dump or whatever else that seems reasonable

3. Publish 1-10% of the data (!)

4. Encourage the site to do the news rounds

5. Explicitly email the company to be concretely sure they know about the site (maybe even do the CC bomb thing, for extra overkill bonus points)

6. Provide contact info with clear indication you will promptly provide all info to an adequately verified third party

The leak should disappear within the hour presumably.

Naturally, brain-breaking levels of self-protection would necessarily need to be employed, to guard against incompetent/egoistic retaliation (and the systemic resources large organizations effectively own). Make the Protonmail address from a VPN over a VPN over Tor, for example. Or perhaps start with a voice-scrambled VoIP call before committing to a video chat. Good luck here, basically.

Post reply on HN