5 ms·
> Some of data was much more detailed than just the email address and included personally identifiable information (PII) ... ‘Emailrecords’ was structured to i
by alxmdev 8y ago
> Some of data was much more detailed than just the email address and included personally identifiable information (PII) ... ‘Emailrecords’ was structured to include zip / phone / address / gender / email / user IP / DOB
How messed up is it that random 3rd parties collect and assemble all this information to begin with, leaks aside? Sounds to me like all this data fell into unscrupulous hands way before any hackers may have found it on the public internet.
- satya71 8y agoI've seen a demo where given my email address they could pull up my name, address, profession, age, and I forget what else. Yes, it's already in unscrupulous hands.
- WillPostForFood 8y agoFacebook?
- unreal37 8y agoLinkedIn.
- groestl 8y agoFullContact? Although it's "Enhanced Contact API" has been discontinued.
- Pristina 8y agopeople were so afraid of BIGTECHs getting their hands on all your personal data. When in reality, a 13 year old can just ask around on some forums and get it.
- thejohnconway 8y agoThe 13 year old can get it because BIGTECH collected it and shared it carelessly, no?
- dspillett 8y ago> collected it and shared it carelessly Or often, as in this case, collected it and stored it carelessly so someone else could get in and use or share it at will.
- tiimbz 8y agoI've seen that too. This API for example [0] called "email enrichment" where I got my full name back, based on email address. Edit: Added main company link providing this API [1] [0] https://app.livestorm.co/api/v1/utils/email-enrichment/?email=emailaddresshere https://app.livestorm.co/api/v1/utils/email-enrichment/?emai... [1] https://docs.enrich.email/ https://docs.enrich.email/
- kaoD 8y agoMy data is empty, even though I'm not that paranoid about privacy (but I do take some care). This specific API seems pretty innocuous. They're not doing black magic, it's just aggregating data that people willingly put out there about themselves. I'm sure I'm out there in many datasets with stolen (or just "shared") information.
- distances 8y ago> This specific API seems pretty innocuous. They're not doing black magic, it's just aggregating data that people willingly put out there about themselves. That's has always been illegal in my country though (you can't even keep a record of people with pen and paper), and now with GDPR would of course be illegal with actual consequences if it contains data about EU citizens.
- tomgp 8y ago>now with GDPR would of course be illegal with actual consequences if it contains data about EU citizens. which, as an EU citizen, I can confirm it does
- mises 8y agoRegardless, they're not based in Europe. Unless they do business in the EU, they can't touch them. This is due to the fact that extradition requires something to be a crime in both countries, so unless the EU has assets to seize, nothing they can do. And if they try, any American court will be very leery of setting the precedent that Brussels can tell Americans what to do in any sense, particularly with respect to data stored on their servers.
- mathnmusic 8y agoSome companies in this space: Clearbit, FullContact
- sbhn 8y agoEquifax and every other latest fintech startup who believes there amazing data slurping ml/ai idea is going to change the world
- cm2012 8y ago30 years ago you could already buy almost all of this + estimated income and education on 90% of americans. It's how credit card companies know who to send mail to.
- sbarre 8y agoI was going to say this is nothing new.. 20 years ago my first roommate worked for a company that did direct mail marketing, and they regularly engaged a "cleaning" firm that would scrub and update their mailing lists. This company had a huge databases of information on people (name/work/address/DOB/income/etc) and they would send them data and they would clean it up. Now they would not give them any new data, they could only update records they already owned. Back then in Canada there were apparently only a small handful of well-known cleaners like this who traded on their reputation for accuracy and dataset completeness..
- redcalx 8y agoYeh, I assume this a GDPR violation in the EU (I mean the business model seems like it violates GDPR, let alone the actual data breach).
- StavrosK 8y agoDoes anyone have this dump, or at least a way to check exactly which of my data was in it? HIBP doesn't tell you, unfortunately, even though it definitely could, since I have verified my email address with them.