Show HN: Tech Companies That Won't Delete Your Information
secured.fyi
secured.fyi
In trying to delete a few accounts, some services outright refused to delete my info, without giving any reason. Therefore, I've decided in to create a naughty list of tech companies who don't respect your right to your own information.
There are already 261 sites in the list, but let me know if there are any other services you think I should add.
I’m a little confused about the implementation right now. I don’t understand Rank and Score specifically. The columns need some explanation to make it clearer if a higher number is good or bad, what the number is representing, and how it’s calculated.
Also, the ranking list isn't that helpful when 20-some companies are tied for 3rd.
Do you work with any UX designers? Get some feedback from them. It's not about making it pretty as much as it's about presenting the content in a clear way.
btw, have you seen the 2FA List? https://twofactorauth.org/
They have had employees tracking their Ex's whereabouts. They have publicly boasted of being able to identify "rides of shame" after your One-night stand. They collected location information beyond what was necessary to pick you up.
Plus, you know, being union-busting, misogynistic, democracy-undermining, corner-cutting and pedestrian-killing frat boys. But the reasons above seemed to be better tailored to the intent of your list.
What Uber comes down to is, I believe, essentially the same as the famous Zuckerberg chat message: 'They "Trust me". Dump fucks!'. Saying that isn't illegal by itself. But it shows a complete disregard for the publics' interests.
Every single one of Uber's actions could actually be excused. When, for example, Google admitted to capturing unencrypted Wifi traffic picked up by their Street View cars, I was willing to give them the benefit of the doubt, because that explanation seemed more consistent with their past (and future) behaviour than the alternative.
But the sum of Uber's actions leads me to believe they have misunderstood the causality their own motto proclaims, and are now intentionally breaking things in the hope that it will make them move faster.
Which makes me think that they're deactivating your account and basically keeping as much data as they can legally get away with.
Since I doubt any of the other companies on your list are openly ignoring the law and keeping more than permitted, the logical conclusion would be that Uber is just as bad your top contenders.
The only challenge is how to rank them based on ranking factors.
And though not directly related, data breaches do undermine a user’s ability to delete their data. So maybe some kind of formula to quantify data loss.
Just some ideas. Your work thus far is really eye opening and you have my thanks. I had no idea I was trapped in LinkedIn.
I sent in a request asking what steps were necessary to have one's account deleted. I was told this was not possible. This is unreasonable.
And yes, I created this account specifically to post this comment.
However, upvotes are currently private, and cannot be removed after some length of time. I wonder if this would mean they should be made removable (or at least the record of them in a user's account).
A while ago I deleted my account, then recreated my account after a year, and requested a full backup history, this backup had my old contacts from the original Linkedin android app gathered from my old phone without my permission.
They repeatedly said "No, we will not disable your account."
And they keep the last address you ordered from in an uneditable field visible on the website, so you can't scramble it with fake address data. I haven't seen any other retailer do that.
----
Loading failed for the <script> with source “https://secured.fyi/analytics/piwik.js”: naughtylist.html:1
The resource at “https://cdn-images.mailchimp.com/embedcode/horizontal-slim-1... was blocked because tracking protection is enabled: naughtylist.html
Source map error: request failed with status 404 Resource URL: https://secured.fyi/assets/style.css Source Map URL: bulma.css.map
----
What's wrong with a good ol'fashioned HTML table?
code 403
message Requests from referer https://sheets.googleapis.com/v4/spreadsheets/1A3xz8NFWjebuMbGWvy2yUBKcnAmuZSs5JmKq9-JDss8/values/Email?key=AIzaSyCxiboNdLE5nSch2pdwI3blsfvfyss3Y0M are blocked.
status PERMISSION_DENIEDReferrer in FF:
https://sheets.googleapis.com/v4/spreadsheets/1A3xz8NFWjebuMbGWvy2yUBKcnAmuZSs5JmKq9-JDss8/values/Email?key=AIzaSyCxiboNdLE5nSch2pdwI3blsfvfyss3Y0M
Referrer in Chromium: https://secured.fyi/
Btw. I tried deactivating any Addons which might interfere with the requests but it didn't change anything. So probably all users with a modern Firefox will have an empty table.Tox is listed among them. But ToX does not need any information from you. You can create a random id without any of your personal information whatsoever, and share this id with your friends, who will also have a random id.
Tox is not a company.
A clarification is much needed.
In the communication lists it says that security wise is "Bad". Why?
In fact, it would be beneficial for all of us if these lists had some information on why were some of the stuff added to the list. Precisely why is Tox added to the list.
Similar to this discussion we can see that Retroshare is too listed. Again, why?
Please share some URL with reading material why are some of the companies and tech listed at all.
I was not even aware that they kept some of my information. Which information do they keep? Which information about me they will not delete?
In that case Dropbox would be the ones holding data.
There are some limitations to running this on what is essentially a spreadsheet. I want to re-design the system before I add more data, because then it will be easier to make the transition. This is a priority, only limited to how much time I have available.
There is some clarifications in the change log: https://secured.fyi/changelog but all sources will be added once I have the new site ready.
For example, you said that Facebook deletes data partially. What does it mean?
TLDR: Claimed to have deleted everything on 2017-06-08, but they lied.
0. 2017-06-06: Mendeley <mendeley@mail.elsevier.com> email me "Paul, important changes to your Mendeley account ..." I log on and 'delete' my account.
1. 2017-06-07: Mendeley <mendeley@mail.elsevier.com> me "We have deleted your Mendeley profile and data, to delete your full Elsevier account, please email usinfo@elsevier.com"
2. 2017-06-07: I reply to Elsevier <usinfo@elsevier.com> "Please do that for me now - if you've created one for me delete my full Elsevier account from all databases and backups that you have on me, including cold storage."
3. 2017-06-07: Elsevier <usinfo@elsevier.com> email me a ticket number
4. 2017-06-08: ELS-Mendeley Support<support@mendeley.com> email me "This email is to acknowledge the request and to confirm that we have already removed your email address from our database. We have cleared out all data associated with your account across all Mendeley servers. You shouldn’t be receiving any more emails from Mendeley moving forward. Apologies for any inconvenience this may have caused you."
5. 2017-06-11: Elsevier Customer Feedback <research@surveys.elsevier.com> "According to our records you recently contacted <NAME REDACTED> in Elsevier Customer Support. The ID of the support query was 170607-010708. We want to improve the service we provide you. In order to evaluate our current service, we are conducting a brief (3-4 minute) survey. This asks a few questions about your most recent experience of contacting us. Your feedback would be very valuable. ..." I don't click on the link
6. 2017-06-15: Mendeley <mendeley@mail.elsevier.com> email me "Paul, important changes to your Mendeley account" ...
7. 2017-11-11: Mendeley <mendeley@mail.elsevier.com> email me "Paul, identify relevant funding opportunities Hi Paul, Have you logged into Mendeley lately? ..."
Edit: correct dates
That doesn't look like it's from the marketing team - looks just like the original email they sent before I closed my account.
I didn't write it out carefully for you. I wrote it for the OP.
You then engaged with a support representative, who deleted your data and email from their account system. What that representative did not do, clearly, is delete you from the (likely third party held) email system.
Note that the automated emails come from an elsevier domain, and the support email came from a mendeley domain. That is a good sign that you are in multiple systems.
Then, later, you again got automated emails from them. This didn't come from the support person, it came from the automated system the company set up, again likely with a third party and managed by a different team. Unsubscribe from those and they will go away.
https://www.mendeley.com/forgot
Enter a valid email address that has never been registered with Mendeley. You will get the following message: Oops, this email address was not found in our system.
But, if I enter the email I registered I get this message: Thank you. If we have been able to identify your account, an email containing instructions on how to reset your password will be sent to you.
I don't receive an email, but Mendeley password reset can discriminate my previously registered email from random valid email addresses. That would be impossible if that registered email was only known to third parties.Why would that be?
Look what I wrote at point 1.
1. 2017-06-07: Mendeley <mendeley@mail.elsevier.com> me "We have deleted your Mendeley profile and data, to delete your full Elsevier account, please email usinfo@elsevier.com"
So my Mendeley profile and data has gone, and Mendeley have deleted my data from Mendeley servers but it looks to me as though there is a central Elsevier server that still knows my email address.Furthermore, Elsevier Product Insights for Customers password reset
https://e-pic.elsevier.com/forgot
rejects random valid email addresses but recognizes my previously registered email address: Thank you. An email containing instructions on how to reset your password will be sent to you shortly.
And the password reset email actually does get sent to me! Dear null,
You requested to change your password. Click the link below to change your password:
..
Well, what do you know! As far as Elsevier is concerned I do have an account after all!BTW, is this you ?
https://angel.co/aiden-meisterBesides, from a technical perspective archiving PDF invoices and using SQL cascade delete doesn't sound overwhelming in complexity.
I simply overwrote all their details with nonsense, and marked the account as deleted. The account exists, but is about as useful as the fake accounts spammers sometimes make.
One thing that is troubling is that if you have an expired domain with domain lock turned on, they will not delete your account until a year has passed from the non-renewal of the domain. The domain-lock feature cannot be turned off if that domain has been inactive for less than a year unless the domain is renewed. They told me they could not turn it off either so that the account could be closed, but I'm a bit skeptical on that, since it makes no sense that they cannot change the account settings with an authenticated customer making the request. Don't they control their own code? It strikes me as an excuse for them to leave the account open in case you change your mind.
In their favor, I was able to delete payment information immediately. Also, they have very friendly customer service representatives (though friendliness doesn't make up for powerlessness.)
Btw, this is an interesting and good service you are setting up. Thanks for your work!
Thanks, and I've added GoDaddy :)
This is a naughty list is it not? Suggest to please sort by naughtiest first.
"Tech Companies That Won't Delete Your Information Services with the highest scores have the worst policies"
I read this as 20 is worse than 1.
Maybe something along these lines, explicitly explaining 1 is the worse.
"Tech Companies That Won't Delete Your Information Services. Those with the highest rank have the worst policies. A rank of 1 is the worst offender"
I think this is somewhat a problem of English missing a term that unambiguously means "1 is highest".
- Service: Jabber.org
- Protocol: OMEMO
- Software: Gajim
Next, the score seems to be a similar mix up, not so much focused on security but more as a general recommendation as a trade off between number of features and overall security. To me that feels like a bad advise. That way, a very respectable and stable app like Conversations is listed below the protocol it uses (OMEMO) and even below Tox which is officially listed as experimental, just because conversations doesn't support audio or video telephony.
Other privacy related aspects, like the need to register a phone number to use the service, automatic contact list uploads or custom servers, are completely ignored.
There is too much special sauce on the page for me to see the actual list (perhaps one of your critical resources is already on my blacklist or too third partyish).
Thought you may be able to make use of http://backgroundchecks.org/justdeleteme/ to help with your checking. (no affiliation)
Plus it is great when a study like that is reproduced and vetted for drift.
Thanks again for you work.
This makes them sound like they do delete your account information. If there is something specific that they don't delete, it might be best to highlight that.
Also I am unsure what "Track" means.
And how can you Delete Account be unknown? Did you try? If not, how can you claim they are naughty?
Hover of the Tracking text to see the explanation.
There are over 250 services in the list. Those who have the status Unknown didn't mention it clearly on their website. Feel free to make specific suggestions, and I'll make corrections.
Another example of this is sales tax in the US. Several states have laws that tell the seller to collect and remit sales tax on any sales to residents within the state. But for sellers that have no physical presence in that state, the state has no ability to force them to actually do so (or to force them to open up their books and prove one way or the other).
GDPR would be a nice "tool" to validate the actual deletion of personal data.
- I’d rank them on a combination of size and score. - perhaps a link to relevant delete / info page - automatic vs manual (ie do you need to ask support) - whether they have precise info on which information is deleted, and what is kept - a column for claimed gdpr compliance
Slack No No 2
Kayako Yes - Difficult No 0.25
Almost the same level of issues, yet an 8X difference in the score.What do you suggest I change the weight to?
Arbor Network Atlas anti ddos service on the tier one ISP level. Seeing flow samples of most traffic anti DDOS through network flow logs of many major tier one internet networks.
Cloudflare CDN major focal point of internet traffic.