'Suicides' over Ashley Madison hack
bbc.com
bbc.com
That's about 1% of 30 million, or about 0.1/day, or 3 weeks for those 2 suicides. I bet any deviation from the average isn't statistically significant (in fact, for 2 suicides, ¿almost? no 'background' suicide level will be statistically significant)
On the other hand, I do expect that Canadian police didn't base their claim on nothing. Chances are they found suicide notes, or something similar.
Actually, they didn’t claim anything, and only talked about unconfirmed reports (https://twitter.com/TorontoPolice/status/635816932474814464, http://www.cbc.ca/news/canada/toronto/ashley-madison-hack-2-...)
But in the UK there has been a rise in rate of suicide amoung people already known to MH services, so we need to be a bit careful not to put all the "blame" on help seeking behaviours.
(I'm interested in other anti-stigma organisations, where ever they're based and whatever demographic they target.)
[1] Calmzone is currently banned from Facebook. I don't know why. https://www.thecalmzone.net/
http://softenthefckup.com.au/ -- they don't censor the word on the website.
Not to mention it tends to be rather expensive and of limited value.
Same for the military. The 'success rate' for military suicides is higher partially because of ready access to the means.
"Jumping off things" would be "falls and fracture", and it's not a common method for completed suicide. About 4% of registered deaths are "jumping off things". Drowning is a bit more, about 4%. Poisoning is about 20% and hanging, strangulation and suffocation is about 56%. (The rest has the unhelpful title of "other". I'm not sure what that means.)
Drive a car fast. Just a lethal. Sometimes you hear about car accidents with only one car involved and the young male driver was the only fatality. Sometimes it's an accident. Sometimes it's someone ending it all.
Males don't self-harm and overall don't signal their discomfort until it's too late.
http://www.suicide.org/suicide-statistics.html
This PDF says that there are 25 attempts for every suicide:
http://www.cdc.gov/ViolencePrevention/pdf/Suicide_DataSheet-...
I had no idea it was that high!
(This is from office for national statistics data)
1. They leave suicide notes where they explicitly attribute it to the hack. Then, the probability that it is due to the Ashley Madison hack becomes = 1. The question then becomes, did the 'outing' push them over the edge. Especially so, if they attribute taking their life to multiple reasons.
2. If it is not attributed to the 'outing', then one has to carefully see what the probabilities of suicide are in their particular cross-section of population and also consider other risk factors. The numbers someone else quoted here, 16/100,000 is an average. It is fallacious to assume that this number uniformly applicable to the population as a whole. You have to consider prior probabilities for each individual. These priors can possibly be computed based on the individual's medical history, socio-economic background, geographical location, etc. with importance assigned in that order. I would imagine medical conditions would play a big role. For example, if an 'outed' person with no history of depression, etc. from a hyper-religious family commits suicide, it is quite likely that it was because of the 'outing' in the absence of explicit attribution in a suicide letter, etc. If a person has on his/her history previous suicide attempts, depression, etc. the marginal probability that it was solely due to the Ashley Madison outing would probably be lower.
Maybe we should wait until we have some kind of confirmation before discussing this?
Two Ashley Madison clients are reported to have taken
their lives after hackers published their details
according to police in Canada.
While police certainly can make mistakes and even tell lies, this sounds like confirmation to me.Bets on whether the "sophisticated" attack turned out to be a run-of-the-mill employee phishing e-mail or a brute force attack on an unsecured server with root login?
The hard part is:
- exfiltrating large amounts of data without detection
- not getting caught afterwards
Does a suicide potentially move this from willful civil negligence into the realm of criminal negligence? Nonfeasance?
Leaving my doors and windows open is stupid but not an invitation to go rummaging thru my stuff.
Your friends pay you money to permanently dispose of the evidence of their marital affair
You just leave the evidence at your house instead
You leave your doors and windows open
Now its still not your fault that people came in and rummaged through your stuff; but surely its you who are to blame for never disposing of the evidence as you promised (and accepted payment for)?
Its an interesting component to what is otherwise extremely simple.
If i paid a document shredding company to shred my documents and months later that company gets broken into and all my documents are released...
Surely i blame the shredding company as much, if not more, than i blame the thieves.
I don't really have a position or idea on what this all makes ashley madison guilty of from a criminal or civil law perspective - but i certainly feel that there are punishable actions taken by ashley madison in this whole mess
Both of those are separate issues from leaving the information laying about.
In the original case, I might be stupid, but the interlopers are wrong to assume that they had an invitation to stuff laying about. They are, in fact, burglars.
Even with your addition, they are still burglars. However, I am liable for either 1) failing to destroy said information/stuff and/or 2) failing to do so within the specified timeframe, if the burglary happened after that timeframe.
The blame to the burglars remains the same in either case.
Honestly, I'm sort of enjoying a fat cuppa shadenfreude tempered by the knowledge that it is, for the most part, really none of my damn business what someone else does with their naughty bits.
It'd be hard to argue that it conduct that disregarded human life, though.
You may be right that many companies behave this way, but they at least pretend that they don't. The companies I've worked for have always been extremely conscientious about honoring data-related terms, even if no user would ever know. The fear of getting sued is strong.
In any case: when I say that Avid Life is nowhere near the bottom quartile for companies when it comes to security, you can take that to the bank. Or, don't, if you're worried about taking things to places that won't lose your data in a breach. I guess you can take your data to Facebook in that case.
Given backups and billing records and stored message histories and so on, its not really a question of 'deleting an account'. More like 'making an account no longer visible/available to the current interface'. Nobody thought they'd wipe any disks or anything, in anticipation of a big data breach, right?
Whilst that is true, we equally don't want to be completely ruling it out. An investigation should be conducted regarding the actual attack, and perhaps their handling of the leak. Did they even notify all users?
edit: also, as others have implied, 2 suicides out of 40 million is not that high (I don't mean to downplay the tragedy - all suicides are horrible) - but IMO you'd have a hard time proving the Ashley Madison hack was really the only cause, and not the final straw for somebody who was already in a bad place mentally. If I were to tell someone that their spouse was cheating, and their spouse commits suicide, would I be criminally negligent?
Note that I'm not playing with people's identities, but even then, you have to ask whether they were paying to delete the availability of their user data or the actual database records (somewhere in the contract?).
http://krebsonsecurity.com/2015/08/leaked-ashleymadison-emai...