12 ms·
We’ve lost control of our personal data, including 33M NetProspex records
- Corrado 10y agoI got a warning this morning from HaveIBeenPwnd and this article was in the breach email. Considering the current US political environment and the recent article by Tim Berners Lee, this spam list is extra scary.
- jacquesm 10y agoI am aware of one EU entity that sits on a mountain of such data (and much worse, in fact) with very little in terms of security. I'm simply waiting for the day when there will be a hack like this on the European continent, it's scary what sits in lightly protected databases, especially if you consider the probable sources of data like this and that - at least in Europe - it would be illegal to create such a DB without the consent of those whose information is stored in them. We've lost control is the perfect way to describe things.
- orf 10y agoWhich entity, and have you reported them to anyone?
- psion_ 10y agoI think part of Troy's argument is that buying and selling this sort of information is technically legal - ergo making reporting pointless. I guess the other side of that argument means that mentioning who sells it shouldn't be a problem either.
- arjie 10y agoNot everywhere. Significantly it's not legal to be moving EU Personal Data out of the EU. And these guys are going to get hit hard (including personal liability for their privacy officers). It would be responsible of OP to report it to them but theirs no real obligation for him to do so. It's on them to protect it.
- samat 10y agoIt might be legal, google for "us eu safe harbor privacy framework". But you need a consent to collect that data in the first place.
- arjie 10y agoYou were certainly right (and still are, depending on how you read your comment). I'm not a lawyer, but I believe that Safe Harbor is no longer safe to rely on (since a 2015 ruling). There's Privacy Shield and the soon to come into force GDPR, though, which have restrictions like the one you mention.
- jacquesm 10y ago> including personal liability for their privacy officers Hah, there's one big assumption you are making there...
- luca_ing 10y agoIf it's really as dire as you say, you must blow the whistle on this. The German commissioner for data protection might be interested: https://www.bfdi.bund.de/DE/Service/Kontakt/kontakt_node.html https://www.bfdi.bund.de/DE/Service/Kontakt/kontakt_node.htm... In case you'd rather not do it through official channels (or in addition, just to keep them on their toes), may I suggest: https://www.heise.de/tippgeber/ https://www.heise.de/tippgeber/ https://securedrop.theguardian.com/ https://securedrop.theguardian.com/
- mschuster91 10y ago> it would be illegal to create such a DB without the consent of those whose information is stored in them. I can imagine such an entity, at least in Germany: the Schufa, a credit rating service. It's impossible to open bank accounts, get credit or phone/internet contracts without all this going into their DB. Better hope they secure their systems. Credit rating companies are, from their model of business, rotten to the core - and pose an extremely high risk these days where everything is computerized.
- lucaspiller 10y agoExperian are the UK equivalent - it's exactly the same, everything you do involving credit goes through them.
- ransom1538 10y agoI am simply waiting for the github hack. This will be a disaster of epic proportions. The crown jewel.
- overcast 10y agoYep, that will be the internet crusher.
- estro 10y agoHow so? I'm genuinely curious.
- overcast 10y agoAccess to all private Github repos??
- estro 10y agoYeah that's a fair point
- bsenftner 10y agoThe exact reason many don't repo there.
- BoorishBears 10y agoI've seen plenty of places with this mindset. Instead of risking their data in the motherlode of hacks occurring against Github they setup on-premise Github/Gitlab/Bitbucket/etc. then let the servers go unpatched, stay several versions behind, don't bother setting up authentication roles properly and give people more access than intended. There are plenty of places doing on-premise right, but I definitely trust Github over the average undermaintained on-premise installation.
- JBiserkov 10y agoAnd all the keys/passwords stored there!
- chadscira 10y agoIs there any way to check if we are in this dump?
- dwightgunning 10y agoFrom a writing point of view, I found it an interesting choice to simply use "author" instead of "Tim Berners-Lee" when attributing the quote in the opening paragraph. Surely dropping TBL by name would give more immediate credibility and encourage the reader to continue.
- kitd 10y agoOTOH, leaving it til after encourages the reader to reassess their initial reaction to the quote.
- EGreg 10y agoI wrote on this same topic a few years ago, might interest some: http://magarshak.com/blog/?p=169 http://magarshak.com/blog/?p=169
- jgalt212 10y agoI fail to see the difference between PII for expensive purchase (NetProspex) and PII for cheap purchase (River City, and whoever else is using the stolen data for gain).
- josephcooney 10y agoThe type of people that make expensive purchases (and therefore probably have more money) might be a more attractive target to criminals.
- inthewoods 10y agoRecognizing that my comment here is unrelated to the central question around whether companies should have this data, the irony for NetPropex (and the hundreds of other companies in the same business) of this kind of data availability is that it results in a lot of cold emails and phone calls that largely go ignored. Thus, as the data has become more widespread, it has become less valuable. Buying a list of people to contact, in my experience, is like throwing money in the trash.
- grp 10y ago.. and is good when you are the trash..
- bambax 10y ago> CSV file containing JSON data Wat?
- BoorishBears 10y agoJSON Object,JSON Object,... I guess? Maybe the records were exported one at a time and formatted for excel vs in an array for programmatic access
- madenine 10y agoThat's usual context where I see it. Often ends up with csv's where you have columns of the data people are interested in and one column containing all the metadata bundled up in JSON as a string. Its not great to work with.
- devopsproject 10y agopeople want to put "json" on their resume but cant be bothered to spend 10 minutes to learn how to actually use it. You end up with stuff like this.
- sathackr 10y agoI've stopped giving my information to entities that don't need it. I use fake account information where it is legally permissible and the system is requiring some input to proceed. When I get asked for my phone number, zip code, email address's etc... At checkout in stores, I give a polite "no thank you". Which usually results in a huff and/or an eye roll from the cashier, as if I'm expected to give this info for the privilege of shopping there. If the information sources dry up or are of sufficiently low quality, the market value is significantly reduced, as would be the incentive to collect and store such information.
- vijayr 10y agoThere is this big electronics store in NYC - I bought something small (batteries or something) and at the checkout, the cashier refused to bill me, unless I gave my phone number or email. When I asked why he needs that info his answer was "so we can verify when/if you return the product", and he had no answer when I said "that is what the bill is for, isn't it?". Unwilling to hold up the line, I left without purchasing anything. Point is, no one before me had issues with giving that info, no one bothered to ask. Unless many people start asking questions, nothing will change, and I don't think most people care. At the high school level, kids should be taught topics like privacy, civil rights etc - that might help at least a bit
- grecy 10y agoI'm living on the road now, and don't have a phone. I find it fascinating the reactions I get, and the people who refuse to help me with stuff when I say I don't have a phone, or a number I can be reached at. When push really, really comes to shove, I give them a number from somewhere I lived 10+ years ago.
- sn41 10y agoSlightly offtopic. But would love to hear more about the adjustments you have to make to live on the road. Are you self-employed?
- marktangotango 10y agoAwesome advertisement for netprospex, a lot of people would pay a lot of money for that data. I'm sure their phones are ringing off the hook this week. I'm sure this is unintended, but that's the reality as I see it.
- ycombinete 10y agoI guess that native advertising is effective regardless of intention.
- freehunter 10y agoNative advertising is very effective. I run a local lifestyle brand as a side project and native advertising is the only type of advertising we have. I even put "Sponsored Content" and "We were invited to eat at this restaurant in exchange for a review" and I've still had people comment that they don't know how we can afford to do all of this stuff and we don't even sell anything or have ads! People don't make the connection between "sponsored content" and "advertising", or catch on to the fact that we get basically all of our stuff for free (at worst) or that we're actually paid to write about it (at best). But I'm happy because no one visiting my site is getting a virus from shitty third-party ads.
- username223 10y agoDo you say "in exchange for a review," or "in exchange for a positive review?" There's a reason newspapers' editorial and advertising departments are separate.
- freehunter 10y agoMy contracts with local businesses do not guarantee a positive review. Usually the agreement is along the lines of "have to write so many words with so many pictures and mention the article on X, Y, and Z social media outlets X number of times over the course of Y many days", but I and my other writers reserve the right to say whatever we want to say in that article. Obviously it's bad for business to badmouth stuff we got for free, so we're actually pretty picky about what we accept. If I don't like eating at a restaurant, I won't accept free stuff from them on behalf of the business. I've been offered services by a hair salon in town but it doesn't line up with my demographic so I won't accept the contract because I wouldn't want to write about them. I've turned down two offers from the local bowling alley because I'm not going to have much nice to say about it. But no one is guaranteed to get a good review. I've written some reviews I would describe as "hopeful", in that "I'm hopeful they'll get better soon" mostly with regards to brand new restaurants where the kitchen is still finding its groove. Everything that I write is my opinion and is clearly marked as such, even while it's also marked as something I was given for free in exchange for my honest opinion.
- shamaku 10y agoAt some point we will have to trust our fellow men. The sooner the better for all.
- nilved 10y agoThat is never going to happen
- joshpadnick 10y agoI believe our current paradigm for how data is stored is fundamentally broken. The author is right that when you choose to use a service you have no real control over how they use your data. Frankly, companies aren't even accountable to uphold their own privacy policies since no one actively monitors them (except perhaps in the context of HIPAA, PCI, etc.) What I'd love to see is a marketplace of "personal data banks" that would work like this: - The bank maintains an isolated database of every major database vendor. The databases are isolated to a single consumer. - The bank exposes API endpoints of every major database to companies like Facebook or new SaaS startups. Those companies now agree -- when requested -- to write your data not to their private database but to the bank's database that is private to you. - You, the consumer, pay the bank a modest monthly fee to control who can access that data, and even optionally cut off access to the original "generator" of data. I guess this still suffers from the need to trust that Facebook is abiding by your request that all data be written to the bank, and network latency becomes a real issue. So maybe it's not the right business model, but it's an important problem to solve.
- hardwaresofton 10y agoTaking that one step further, maybe if someone wrote that kind of tool, basically an API for your personal data that you can run locally, maybe they could scale it up to what you're describing? It would require a massive paradigm shift in how the internet works in practice, but image a world where: 1. You sign up for some new social network/thing that requires your data 2. You point it at your own personal (or hosted) info server 3. The service promises/or the use of the personal info server stipulates states that the data should never be stored longer than the lifetime of a relevant transaction 4. The social network queries your data maybe once a day (or more depending on whatever kind of work it does), announces itself, and can be cut off when you want. Of course, things don't sell these days with just privacy these days, but there's some upside to a service like this ironically due to it's centralization -- you could sell the user on "only enter your address/personal/credit card info once, have it available everywhere with one click, no long login forms"
- nbadg 10y agoYou're just shifting the trust to the "data bank". What if it gets hacked, or ignores its ToS, or some rogue employee with database access copies your PII, or... ? Trust is dead; it doesn't scale. End of story. I don't like the idea of a "data bank" or "data brokerage" any more than I like the idea of facebook; either way, someone else holds the keys to my castle. But third-party servers aren't going anywhere, so we have to find a way forward. I've come to the conclusion that the only possible way for someone (or something) to maintain control over data is to encrypt it at all times when not in use. It's exactly the idea of a "data bank" like you're describing, but you become the bank. One of the key struggles with this approach is that it requires a tremendous amount of client-side code; calling it a paradigm shift is a profound understatement. It doesn't matter how snazzy your encrypted-dist-web product is unless you present a compelling economic reason for companies to switch to it, to justify the extreme expenditure of capital necessitated by the technical switchover. Even here, though, once you share something with eg. Facebook, you can only hope they don't fuck it up. That's just the way the world (unavoidably) works; once you share something with someone, they have every capability to do whatever they please with it. You have only the social expectation that they don't, and if they violate that expectation, your only recourse is to stop communicating with them. But I do think, in a world where we actually have autonomy over our data (partly, again, because it necessitates client-side code), it is possible to make the consequences of data misuse so disastrous for a company that it stops being economically viable for them to do so. The key thing we've lost is that agency to make decisions about data. I've no problem with informed, consensual sharing, but in today's world re: data, "informed consent" is nonexistant.
- brazzledazzle 10y agoI think I've finally found the source of my constant influx of spam. It won't fix the downstream sources like resellers but at least I can ask Netprospex to remove me. But since they aren't the ones directly spamming me do they have to comply?
- devy 10y agoPretty sure recruiters mining this kind of data as well.
- jerianasmith 10y agoI too firmly believe that Privacy should score higher than business interest. If you do not wish to share such information, a polite "NO, Thanks" is much better.