Data Broker Opt-Out List
github.com
github.com
I'm shocked that Microsoft which is primarily bases on trust as far as corporate stuff is concerned went for linkedin. I hope they sell them or just burn them.
Nothing good can ever come out of linkedin they have less ethics than facebook and twitter.
It's the lowest rung of where nation states target and you've just handed it to them on a platter.
As horrible as it sounds you all sort of deserve it for selling your soul to such a horrendous platform hellbent on fucking with its users. For some reason we're all worried about tiktok now though.
And the little shot of dopamine they get from being LinkedIn popular would probably make them happy to answer any questions you have about things they left out.
Go ahead and set yourself up a Tomcat cluster, an internal Tomcat cluster, some Oracle databases, and even go so far as to reverse-engineer a UI and maybe a data model if we're being extra ambitious.
A business, you still will not have.
eg not paid employees, any anyone who "volunteers" to help out.
The many failure scenarios for that combined with peoples (sensitive) private information are mind boggling.
You might think facebook behaves pathologically but linked-in takes it to a new level!
Download your data. https://www.linkedin.com/help/linkedin/answer/50191/download...
Close your account. https://www.linkedin.com/help/linkedin/answer/63
They repurposed user login details to silently rerouted all the user’s email through their servers for scanning and mining.
That seems like a pretty dark pattern to me. To my knowledge no one got fired for unethical behaviour over that.
The company seems to have a “don’t get caught” attitude to privacy.
Regardless of their intentions, I don't understand how anyone could have thought that was a good idea.
>They repurposed user login details to silently rerouted all the user’s email through their servers for scanning and mining.
Isn't that technically not mitm? That would imply the user was using linkedin as a mail client/proxy or something. This is closer to fraud or phishing.
Best guess is someone there messed up when they merged some internal email lists.
They then maintained this connection indefinitely without telling the user and also used it to spam people under your name.
They used this system to send my ex-girlfriend an invite to join me on LinkedIn. Absolutely repulsive and infuriating.
Don't trust Microsoft.
*
Hello,
To comply with various privacy laws, we require the completion of this form to remove the person profile you have mentioned. If you would like to delete your personal profile page, please complete this form here.
Best, Erika
----
Dear Erika,
thank you for the information.
I have never signed up to this site and therefore do _not_ consent to any information about me being stored on your systems and I do not care who creates these profiles. It is your responsibility under GDPR not to store information about me without my explicit consent and I therefore kindly ask for information about me to be deleted, further I expect any future profiles about me to be blocked from getting created and such info not to be stored also in the future.
In case information is not deleted within 30 days I will hand over this matter to my lawyer and also file a report with my data protection commissioner in the EU.
best regards,
----
dear <...>,
Thank you for contacting Crunchbase!
Please note, if you have an active trial or subscription we recommend that you cancel first before moving forward. Instructions on how to cancel your trial here. And instructions on how to cancel your subscription here.
If you would like to download or permanently delete your user account information, please complete this form here.
If you would like to delete your personal profile page, please complete this form here.
If you would like to deactivate your user account, please reply to this email to deactivate your account. You can contact support@crunchbase.com if you wish to reactivate your account at a later date.
Keep in mind, your user account is the private information that you can use to control your billing, login information, and alerts. A profile page is what displays externally on Crunchbase - these are completely separate. Because Crunchbase is a crowdsourced platform, any registered user can add or edit any profile page - profiles are not explicitly linked to any user.
Please feel free to reach out if you have any additional questions - we'll be happy to help!
Best,
Erika
APOLLO
Dear Alex,
On behalf of Apollo, we are pleased to assist you in exercising your access rights under GDPR and/or CCPA. You may exercise your access rights as follows.
If you wish to remove the personal information that we have that is tied to your email address, then please respond to this communication by submitting the attached Identify Verification Form. We will then respond to your access request upon further email verification.
Why we require this: We require the above because GDPR and CCPA asks that we verify your identity to a reasonable degree of certainty before providing information: this is important, to avoid providing personal information to someone “spoofing” an identity. We believe this process provides that reasonable certainty while avoiding having consumers send us personal government IDs, which contain sensitive information and which we prefer not to receive. (And, unlike companies that deal directly with you, it’s not possible for us to verify you based on our prior relationship – like, by having you list your last movies watched, clothes purchased, or trips booked.)
If you prefer to avoid the above process, you can learn detailed information about the categories of personal information that Apollo collects, and how we source it, sell it, and use it for business purposes, by reviewing our Privacy Policy (available at: https://www.apollo.io/privacy). That Privacy Policy also will tell you how to easily opt out of our marketing databases.
Thank you for your interest in our business and data practices.
Threatening to tattle to an imaginary lawyer just gets you written off as an angry whack job.
Not commenting on the particulars of this case (you might be right in this particular instance), as a general statement this is not true. Consent is only one of several possible legal grounds for processing personal data. Generally, data controllers want to avoid it if possible in lieu of more convenient grounds. Nitpicking more, explicit consent is mentioned only as a processing ground for so called special category data, i.e. certain sensitive data, e.g. health data, requiring an additional legal ground.
Lists of people who invested in companies, culled from public disclosures, or names of corporate board members and such, aren’t the same thing as private PII.
... is irrelevant IIRC. He's asking How.
I don't know why any company relies on data from the big credit reporting agencies.
I pulled my credit reports for the first time just a couple of months ago, and they were all wildly different from each other, and also wildly inaccurate, each in its own way.
There was nothing bad in my report, fortunately. But just the information was so wrong. One agency had my work history all the way back to 1995, but for some reason was missing any of the jobs I had between about 1997 and 2003. One had my residency history back to 1977, but was missing the place I lived just three years ago. None of them were 100% right in any category, but always in my favor. And none of them really had a complete list of my currently open credit accounts.
One thing they all fail at is addresses. If you have a simple address like 123 Main Street, Anywhere, USA, then it's fine. But as soon as you break from that pattern by having an apartment number, or a street name with more than one word, or a street suffix other than "street" or "drive," or a directional, or a city that is commonly abbreviated (St. Paul versus Saint Paul), it all comes apart.
One place I lived had a simple address like "1234 Some Place Drive, Apartment 123B," and two of the agencies mangled it into "123 Some 12." I know addresses are hard, but both the Postal Service and Google have an API for this stuff.
- Put in a mail forwarding card with your name from a former address to a random real address like a Starbucks, Taco Bell, apartment complex w/o unit number, etc.
- Change the billing address of a credit card or utility and allow to sit for one billing cycle. Works best if you have e-statements. They will send a physical confirmation to the address and it will most likely go in the trash but not guaranteed.
- once a quarter you can update your information with the credit bureaus and they will Happily record it. Later you can say you never lived there and they will remove the info - but only from the databases used in credit decisions
These are the ones most effective because there is almost no filtering, just a bunch of automated processes collecting and distributing. Just make sure there are one or two “facts” that the data quality algorithms can use to link your “new” data with existing profiles.
if you have the time, you should make a complimentary “solution” read me page for this post.
deletion really does seem to be an unwinnable proposition, so flooding with false data is a great approach. can this be automated?
Anyway, one of the verifiers is past addresses, so this sort of thing could prove a problem when applying for jobs in the UK.
Tories gotta tory - put a private firm between people and job applications, demand they give all their ID data to that firm. Oh, and the firms all have recent mass data leaks.
It's a core part of several gov departments (passports, drivers licensing, benefits, taxes) to be able to ID people and the gov have all the data with which to do it. Crazy.
Perhaps, but I would have assumed creating a USPS mail forward under false pretenses like this would be fraudulent. They seem to take such thing seriously.
GP also mentions in a sibling comment about what to do if you need address verification for something else (which is presumably of value):
> All you need is a passport or driver’s license and a utility bill with current address dated within 60 days. Most of the time the utility bill can be a “photocopy” and you just change the date or address to what you need. DMV is about the only place that needs an original document and will be familiar with what bills from your area look and feel like (because they most likely live nearby also and routinely handle documents from people in the same area as you).
Doctoring a document like this also seems illegal.
how is value defined in this context?
Generally, in court, "value" means "market value" expressed in the currency of the court's country. Often the penalties for various levels of fraud are based on the value (= market value) of the gain -- for example, hypothetically, the law might state that if the value was under $1,000 it's a misdemeanor rather than a felony or that if the value was under $100 you can't be sentenced to prison time.
Something like my own privacy which has value only to one person (me) does not have market value.
[edit: added two paragraphs]
> but you can flood them with false information and they will record it and keep it forever.
how would you do this?
ZoomInfo (public company) for example provides a free plugin for sales people which is scanning email for all the email signatures and then they sell all that data to their customers. Even crazier is they take data from their customer’s CRM systems.
DiscoverOrg is buying data from third parties without really knowing how they got the data.
There are a bunch of apps and browser plugins that read your emails or contacts and then those companies sell that data to third parties like these data brokers. I use very few browser plugins because of this threat.
If you have somehow acquired a list of contacts you can get a lot of these companies to purchase it with very few questions.
I ended up selling him the one web site that didn't have a mailing list and only rudimentary social media presences. I bought a new car and moved to a better city with the money.
https://ec.europa.eu/info/law/law-topic/data-protection/refo...
I don't think it applies to EU citizens overseas IMO. At least I haven't signed up for anything that asked if I was an EU citizen or not.
Would get really messy because there are lots of EU citizens out there that don't know it through jus sanguinis.
Meanwhile a lot of financial institutions do ask if you're a US citizen because it ups their reporting requirements.
How did they get it?
If I opt out, doesn't it confirm that what they have is accurate and make my data even more valuable?
Given the nature of these sites, isn't it sketchy to provide DL to opt out or am I being paranoid?
Can I ask by what law?
Even re: California, are you sure CCPA implies these data brokers have to respect your opt-out for this particular purpose? (For reference, the opt-outs existed before CCPA and I believe GDPR as well... so you're saying they gained teeth afterward?)
Yeah, I don't know why engineers are so pedantically committed to giving these companies more valuable information about you.
For a short period of time I even had a website dedicated to calling them out on their bullshit practices, and went in to their Facebook page and posted the link everytime there were any questions about it.
I even got a threatening takedown email, to which I kindly restated what I had written on the page: that I would not pay postage to Germany to unsubscribe and that the page would go down either when I got an official notice that I was unsubscribed from everything or when I hadn't received any marketing email for 6 months.
In the end I spent much more time than needed to GDPR-request all information they had on me and detailed information how it was used. Only to ask them to remove all of it in the end.
Given the pandemic, plausible economic collapse, Brexit, and so many other things going on in the world right now, I wouldn't hold my breath.
It's the fact that we exist in a middle ground between proper regulation and a proper free market. Either of those, and we'd be able to do fine. As it is, we get the downsides of both.
There will always be an information and power asymmetry between ordinary people/consumers and special interests/corporations.
Sure, people could form consumer rights groups, boycott companies with unconscionable data collection policies, demand a sane and afforable health care system, etc. But people have a limited attention budget. It's just too hard to care about everything, so people don't.
That's also why we don't have proper regulation; if we cared about having a functional, efficient government we would, but we don't really care that much.
With this being the case, more small companies would be able to compete, at least in theory.
That being said, I believe you are correct. It just seems that the only way to improve things is to get to the point where people do think before purchasing, regardless of the state of State.
As far as having an efficient state goes, I would find it more likely that it's not going to happen because those in power have incentive to maintain the current status. It both provides opportunities for corruption and gives an excellent platform to run on.
Important is that you choose which pros and cons you find important.
However, the way things currently stand now in a middle ground appears far from optimal. There is too much lobbying for there to be enough regulation to be effective, but too much regulation for there to be proper competition. While I believe a middle of the road approach could work, in our current circumstance it isn't.
My ideal path would be to go to a complete free market, and rebuild regulation from there. While rebuilding regulation, actually have legislators listen to experts, and ban lobbying. This will never happen of course, but I can dream.
Edit: Make tone less authoritative, because I need to work on that.
Your response is mostly hyperbole, and indicated an axe to grind. You can be against deregulation, but it's not applicable to the question posed.
There were no data gathering laws "dismantled" in the name of "deregulation." You statement is false.
What is happening here is what has always happened: Laws are almost always a step behind technology. Only very rarely are conditions prohibited by legislation before an offense is committed.
GDPR and the California thing are good steps in the right direction, but they're just the landing of a very long staircase. Hopefully we'll get to the top eventually.
Erm no. 2008 was directly linked to Greenspan (Fed), Freddie Mac (Federal) and Fannie Mae (Federal), all government run entities, which stopped making proper risk evaluation when issuing loans. That's not deregulation, that's a problem with how these government agencies actually functioned.
https://www.fool.com/investing/dividends-income/2008/09/10/t...
> If not the boldest of the group, then at least the most public, Greenspan, the man many are now blaming for the housing bubble (there were a brave few that piped up years ago), has refused to go quietly into his well-padded retirement. The man charged with providing the country with a financial voice of reason fell far short, so much so that it might be comical if it weren't so tragic.
> Greenspan's denial of the possibility of a housing bubble has been widely derided in the past year, but a single statement could be excused as human error. However, a quick scan shows that this wasn't a single event. He also promoted the adoption and expansion of adjustable-rate mortgage (ARM) products in early 2004, when short-term rates were at or near historic lows. That same year he claimed, "securitization by Fannie and Freddie allows mortgage originators to separate themselves from almost all aspects of risk associated with mortgage lending." And separate themselves they did, ceasing to perform any kind of due diligence as to the ability of borrowers to pay for the homes they were buying.
The FCIC placed significant blame for the crisis on deregulation, reporting: "We conclude widespread failures in financial regulation and supervision proved devastating to the stability of the nation’s financial markets. The sentries were not at their posts, in no small part due to the widely accepted faith in the self-correcting nature of the markets and the ability of financial institutions to effectively police themselves."
https://en.wikipedia.org/wiki/Government_policies_and_the_su...
Well sort of yes. But that's first order thinking. The underlying engine that drove those institutions to failure was the deregulation of the banks.
It's a mystery to me.
Most HN commenters constantly whine how "data wants to be free" (no IP, no patents, no copyrights...), but when it comes to their own data they act like crony capitalilsts of the worst order and want to enlist the State to help them ensure exclusive, monopolistic rights to that data.
Make up your mind, busybodies!
This “bend your mind”, “drink your own medicine now” wittiness borrowed by the postmodernist crowd is the essence of current alt-right rhetoric.
I guess we're lucky that most of these SEO-saavy brokers seem to at least pay lip service to US/EU laws (or even do so voluntarily, since I think only a handful of states actually restrict selling your publicly-available or personal information online).
I shudder to think about what's floating around for sale on the dark web or companies hosted in countries that don't care about US law.
If this worked then anyone could opt out anyone else, which some people would object to. I think that's the loophole they use to force you to provide even more info.
This seems odd. I'm curious if anyone has substantiated it? PrivacyDuck seems deeply ethical, and I would assume they would inform users if this was the case.
Here is their guide for reference, that walks you through exactly what they do: https://www.privacyduck.com/resources/ (Assuming I understand correctly what they are saying; please correct me if I'm wrong!)
The worst part imhop is that your opt-out is often not respected over time when new data flows in (including voting records scraped so get ready for November).
Of course, you can always pay deleteme to do it for you. the real solution here is better-crafted legislation and a re-definition of public record information when it is published virtually.
i expect this to take ~5 years, but optimistic we can get there.
Edit to add: I did read the other comments. joindeleteme seems like a scam/money grab. Yearly sub that autorenews, and a BBB rating displayed? Give me a real tech service.
With enough updates and utility, that I'd consider a monthly subscription for.
> We monitor each data broker website for your personal information every three months, providing you with four DeleteMe Privacy Reports per year. [3]
For those of you who do want to remove all of the info yourself, I've found this is also a good resource: https://inteltechniques.com/data/workbook.pdf
Checkout CircleBack which is a free tool that scrapes your email for contacts for you. Now look at their CEO. He also owns a data broker. I am sure he is selling the CircleBack data.
There are just two possible outcomes.
Default to David Brin style radical transparency. With a pay-for-privacy grift on top.
Or we get serious about privacy. That means translucent databases (hash all PII, just like password files), Real ID (no anon, no bots, registered alias ok), and extend property rights to our personal data (it's my data, pay me).
Like oh yeah, double glazing, yeah, send an appraiser to my house, can I have a phone number in case I need to cancel? What company ID badge will the appraiser have?
I don't get many calls through though.
I wish I got calls like this, it seems like it could be a lot of fun.
What kind of stuff are they usually looking for? What would be the best ways of fucking with them?
Are they dumb enough to be somehow enticed or tricked into downloading an executable from the "victim" system and running it on their own systems?
*The only calls I get are the car warranty scam and the credit card debt scam. Unfortunately, not much entertainment value to be had with those.
Short of deleting it...