6 ms·
I find the writer to be a bit of a dick in his responses. Yes, the city IT may not be at the same level as Google engineers, but there’s no need to mock their b
by united893 8y ago
I find the writer to be a bit of a dick in his responses. Yes, the city IT may not be at the same level as Google engineers, but there’s no need to mock their ballpark estimates, and after the mistake there’s no need to be a jerk about it. Be forthright about the error.
Consider being on the other side of this, due to a careless mistake the data for many people is exposed on a random strangers hard drive. Asking for an independent third party verification is reasonable.
Bringing lawyers in the mix was also unnecessary. And if more people follow in the authors actions then the state level FOIA laws may be put at risk over the long term.
- patd 8y agoFor the ballpark estimate, I think they just wanted for the request to go away by quoting an insanely high price.
- united893 8y agoIt was a reasonable ballpark. Let's say a city prosecutor was working on a organized crime case that involves the FBI and other people. Based on timing of emails this would leak the list of people working on the case, maybe informants and put them at risk. We all lost our collective shit when NSA said they're only collecting metadata. Metadata is Data.
- Johnny555 8y agoSince they revised the cost for the data they actually sent him down from $33M to $56 (90 days of data at $1.25 for 2 days data), was a ballpark estimate that's over 500,000 times higher than the actual cost really reasonable?
- jakobegger 8y agoThe ballpark estimate was for checking the full text of each and every email (which was a misunderstanding -- the author wanted metadata only).
- slavik81 8y agoThe actual cost of servicing this request was much greater than the $56 estimate.
- late2part 8y agoEspecially after the city made a mistake!
- nzealand 8y ago$32M is not a cost the requestor bears, but an estimate of the cost the city bears. IT estimated the requestor fees to be $21k/year assuming 10TB of data. Clearly, IT were estimating the costs of releasing all email text, because FOIA mistakenly changed the words "please provide the following information:" to "including metadata:" Once they figured out the request was for header information only, the city came back with an estimate of under $60.
- jacquesm 8y ago> Metadata is Data And in many cases metadata is just as useful as the payload, in some cases even more useful.
- cheeze 8y agoLong long term resident with a connection to local government They don't have a choice. Seattle IT is so underfunded that hands are tied because there isn't any resourcing. On one hand, you have to respond to all of these requests (and rightfully so, as it's the law.) On the other, you have no money for your department because it has no funding because the citizens didn't want to spend the money. The person who did this isn't malicious. Just very overworked and did a data pull wrong. They probably didn't give a shit to check because their job kinda sucks and they have too much to do already.
- StudentStuff 8y agoA good chunk of this is caused by our city repeatedly choosing awful vendors that bilk the city for crazy amounts of money, and provide trash as the final product. City Light and the new meters/new billing system are great examples, all the new power meters have no encryption, and use FSK for modulation. Asking City Light about this got me a response that FSK was the encryption, and the gal was dumbfounded when I pointed her to the Wikipedia article on FSK. On the billing side, an Oracle salesman ran off with over $100 million in city funds for what is essentially a CRUD app, and the worst part is they didn't bother to customize this system, just forklifting this in place and letting the chips fall where they may. The prior billing system had quite a bit of data validation and business logic that has yet to be implemented or replicated on this new system. The same actions when you call customer service now take significantly longer. Both these vendors fleeced the city for broken, insecure systems, and neither is having to face the music for it. Worst part is, eventually someone may attempt a fairly trivial exploit of either system, which could wreak havoc in our city.
- PakG1 8y agoThe vendors may be horrible, but it's still on the shoulders of the city for choosing the vendors. This is really down to the fact that most decision makers have no idea how to understand or differentiate between options. It's been like this for decades. When a secretary of state doesn't know the risks in running a private independent email server and how to ensure those risks don't become issues, how do expect much lower level city governments to make any better decisions. Honestly, the IT workers are often underappreciated, underpaid, and underskilled. I usually don't blame the IT people. If they could work at FANG, they would. If they get into a rut where they end up not caring anymore, it sucks. But let's put blame where it belongs, it's on leadership to develop a culture where people care and on leadership to invest money and resources accordingly. Edit: though I shall add that it unfortunately is sometimes not possible to build a new culture without firing incumbents. That one is a really unfortunate situation. It's not the fault of low-skilled IT workers if they are enabled and rewarded for poor skills and attitudes. But if an organization wants to make good cultures, it sometimes requires hard decisions. Still don't blame the workers, just like I don't blame factory workers that get automated. It's just an unfortunate thing that can happen that most people don't deserve.
- edoceo 8y agoThese kinds of actions are why the bill mentioned at the end of the article were put forth in WA (vetoed by Gov)
- newman8r 8y agoI'm curious what his actual legal exposure would have been if he hadn't folded. I feel like they should have offered to compensate the author for his time in their initial request - if someone wanted to perform forensic scans on my hard drives it would be a huge inconvenience.
- newsbinator 8y agoI'd be curious what his legal exposure would be if he were a person off the street, who didn't have a lawyer handy.
- smelendez 8y agoIt is also a legal issue, depending on what else is on the drives. Imagine having to call your employers or clients and tell them that data under NDA is being turned over to Seattle's auditors. Worst case, they'd want to know exactly what data was at risk, which would trigger more demands for forensic audits and more duty to notify.
- jacquesm 8y agoPretty massive. An accidental release where the party released to is known and unwilling to perform a remedial action can go anywhere from a slap on the wrist to a criminal investigation. That doesn't mean there will be a conviction, but de-escalation would seem to be a wise course of action in such cases.
- sokoloff 8y agoDe-escalation? Sure. Allow a third-party forensics company hired and beholden to a presumed-hostile counterparty unfettered access to your hard drives because of their own lack of care or incompetence? Hell no!
- low_tech_love 8y agoHow was a lawyer unnecessary? He was threatened after doing the right thing..!
- emerongi 8y agoAbsolutely. If anyone reading this ends up in a similar situation: please involve lawyers. It's the single best move the author did in this whole mess.
- jacquesm 8y agoYour point would have been made better without name-calling. You are asking for leniency on the side of the officials, yet do not seem to be willing to apply the same standard to the requester. Yes, it could have been handled better, but that applies equally to both sides. Anybody that does FOI requests that have the potential to retrieve a lot of sensitive data due to mis-understandings or mistakes (which is pretty much all of them) should handle the data carefully until they have verified upon receipt that it is what it should be and that the data is not somehow more sensitive than intended. The author did ok in that respect, could have still done better and the city would have been served better by refusing the request as stated until order by a judge to release it based on the grounds that it is an overbroad request, which will result in the release of privacy sensitive information if fulfilled.
- kiallmacinnes 8y ago> Asking for an independent third party verification is reasonable. Not really, for the same reason they never should have sent the excess data in the first place... Why should he give up his privacy to some 3rd party company to help cover up their mistake?
- JorgeGT 8y agoPlus it opens up dangerous precedence. "Oops, here's some confidential data you never asked for, let me send a couple guys to scan your hard drives".
- stephengillie 8y agoCorrupt cops do sometimes plant evidence. This isn't much different.
- tvanantwerp 8y agoAssuming the authors version of events to be true, I think he was being as reasonable as possible when confronted with obvious incompetence and hostility from public servants. This probably happens a lot in the world of FOIA. I do want to recognize that not all local governments behave the way described. When I was recently called for jury duty, I discovered a vulnerability in the city's jury duty online portal that would've let anyone get the PII of anyone ever called for jury duty via that system. I immediately called the county IT department, and they took me very seriously and thanked me for the report. They later emailed me back to tell me they worked with the vendor to close the vulnerability. I was extremely impressed with their professionalism and wish that all local governments could be so responsive.
- tgsovlerkhgsel 8y ago> Asking for an independent third party verification is reasonable. Asking for it may be reasonable, demanding it certainly isn't. You can't demand that somebody gives a third party access to their hard drive. First, it's completely unreasonable from a privacy aspect. Given the level of personal data most people store or process on their computers, it is even less reasonable than asking someone to have a third party dig through their house to "verify" that they don't have something. Second, it's completely unreasonable because it's pointless against a malicious actor - they could have cloned the disk before deleting the data and there would be no way to detect it. It does make sense only to confirm that the data wasn't accidentally left on the disk due to an insecure erasure method. When dealing with someone competent with computers, the proper solution (which they ultimately arrived at) is to have him describe the method he used to delete it, possibly ask him to verify it (e.g. via some form of "dd | grep"), and that's it.
- deleted 8y ago[deleted]