Database containing details of 56M US residents found on the public internet
theregister.co.uk
theregister.co.uk
And that is exactly how the Europeans feel when their health records are handled by Google and the TSA wants to know their Facebook handle: what initially appeared as a nice-to-have is now all over a sudden a government source of data no one anticipated...
Edit - oh darn, I forgot Ancestry.com and 23andMe, which are even worse examples: US police has full access to all DNA samples provided by anyone in the past. That is 20 million DNA samples. Not name or age - full genetic info...
The fact that my DNA can somehow turn up at the scene of a crime somewhere and the police can query the sample I sent to Ancestry x years ago, well, let's say that I already knew that risk going into it and it will have to be what it will have to be.
In our lifetimes, I'm not seeing a way for us to dismantle the forces that are pushing for such a big surveillance state.
Therefore, by definition, you can either find a way to cope within that surveillance state, or you can move to somewhere so remote and hidden that you can't be caught doing what they don't like.
It reads like 'people like me are out there and don't care, so if you do you have to move to the remaining square kilometers of Jungle'
The US does not collect everyone's DNA at birth, and there would be some pushback against that. But there isn't against 23 and me because few care about others.
Noob question, but how does this work?
Those murderers found through 23 and me data? They didn't submit their DNA, their family members did.
but the process of investigating and questioning led investigators, family members, and through rumor / whispering and news articles to discover that one of the grandparents (of a well known family) had cheated and birthed a love child that was assumed to be of whatever family name.. and then they had kids - and they all had positions in the town.. but now the truth was known that none of those grand kids, their families, etc were actually part of the whatever-family-name dynasty.
A whole group of people and a town and some industries changed forever because dna is similar (and much dna is not as well) - and the use of this technique roping in and affecting others that had nothing to do with alleged crime - certainly can have other real world consequences.
This happened in 2018... https://www.washingtonpost.com/news/true-crime/wp/2018/04/27...
To me, that is the real threat - false positives. myopic reliance on the database, and an assumption the computer is always correct.
The problem with this is that by submitting your DNA, you're not handwaving away your own privacy - you're also making the decision for your relatives as well to handwave away their privacy.
>In our lifetimes, I'm not seeing a way for us to dismantle the forces that are pushing for such a big surveillance state.
"It's hard so why even bother trying". Yeah, fuck this milquetoast line of thought, to be frank. The cost of liberty is eternal vigilance. Don't engage in the sort of activity that lays the groundwork for totalitarian surveillance.
It's like saying we shouldn't use cell phones and GPS because if our phones somehow interact with each other, your location data is given to my phone, and then my phone is less secure than yours and leaks both of our info to the government.
The only fault occurring here is the government's decision to gain access to and use this data
Seems like a non-story to me. If you put it out there, someone is collecting, cleaning, and selling it. The fix in this particular scenario is to put less online.
Is it the information that's the problem or is the problem what others are willing to do with that information?
In cases like this the issue lies not in the specific datatypes, but the aggregation thereof.
I think most reactionary pro-privacy responses (the HN default perspective) really stem from a complicated internalization of data gathering/use capabilities that has been adjusted over time combined with a lizard brain feeling of invasiveness. Because almost always no one particularly gives a crap about YOU and your specific data, but they may profit from and misuse your information in passing or in aggregate.
It is a lot like the feeling of having your car broken into or house robbed. You feel personally violated but more than likely you are a victim of circumstance. It can be hard to distinguish between faceless identification for (ad network data gathering, for the most part) and the risks of general data availability that makes anyone as capable as an old P. I. (especially when data leaks conflate the two).
It's really amazing how much time people spend these days trying to gather information on people, considering how useless it is. I don't mean mass surveillance, I mean like people that you want to do business with individually.
Note you can achieve a lot of this privacy benefit much more easily by transferring ownership of your house to a living trust (where your name isn't on the name of the trust). For companies that just scrape and correlate info (as opposed to doing a targeted search), that is good enough.
I was looking on some before just curious and I noticed some information was inaccurate. Like looked up an old address, it said a dead relative used to live with us, when they never did. Then another site said one of our neighbors were a sex offender when not true.
Then there’s companies like LexisNexis too that have massive databases on people too. I think they have a way to run people’s credit without it actually showing up on people’s reports as I heard car dealers can get info on people credit without it showing up as a pull, so not sure if maybe it’s like a cached version of a credit report sold and traded.
Remembering watching some clips years ago on all these big data brokers on YouTube. Last I heard some of these companies won’t even delete your information unless you are a police officer who felt your life was in danger. Seems to still have a similar policy. https://www.lexisnexis.com/en-us/privacy/for-consumers/opt-o...
I was looking at one site about red light camera tickets since there's been debates over them, some states even outlawed them. But looking at one of the examples, some county didn't even have a secure website to put in license and credit card info. Chrome even put a warning next to the address bar. Not sure why they are allowed to process credit cards since a private website would have to be compliance with PCI. But I guess some areas are more technical than others.
Property transfers are posted in the newspaper.
We don't really have county courts here, just judicial districts which are all operated by the state. (We have no county governments)
As mentioned in the article, this is all public data that probably any script kiddie with enough time could write scrapers for. It's a non-story. What's different is that (some) people somehow expect that this public data is as hard to collect and correlate as it was 30 years ago. Those days are long gone, and people should realize it.
Has anyone ever tried de-duplicating and matching up records between multiple leaks to build user/person profiles?
I guess with enough unique keys, compute power and time you could build a reasonably accurate profile of a person by matching up email addresses, phone number or SN numbers?
Would probably make identify thief and fraud a lot easier going forwards.
I think one of the bigger issues in generating profiles on ~325 million people would be merging tons of incomplete data and lots of old/outdated data. Not to say that you couldn't use some machine learning to fill in the blanks, but I'm sure most if the big data/analytics companies are already doing that.
For example:
>Each record contains entries that go far beyond contact information and public records to include more than 400 variables on a vast range of specific characteristics: whether the person smokes, their religion, whether they have dogs or cats, and interests as varied as scuba diving and plus-size apparel.
https://www.wired.com/story/exactis-database-leak-340-millio...
HN Discussion: https://news.ycombinator.com/item?id=17421140
Secondly the location of the database was not disclosed by the researcher, so he can't exactly load it into haveibeenpwned
Disclaimer: i'm one of the creators of the service.
The only “victim” here is CheckPeople, but I doubt that this will have any impact on their business.