The City of Seattle accidentally gave me 32M emails for $40 (2018)
mchap.io
mchap.io
Had the author not notified the city that they had royally screwed up by divulging far more sensitive information than they had realized, they likely would have never realized the error, and he would have been free to do whatever he liked with the data.
But once he notified them of their error, and they realized that the data was now in the hands of someone who should not have been given access to it, there is an interesting legal question about whether he has the right to keep it.
If this were physical property, or money, then there is a lot of case law around what happens when you find yourself in possession of something that was given to you by what was clearly a mistake. If a car dealer accidentally drops off a new car at your address, but later realizes it was intended for another address, you don't get to keep the car. Likewise, if $100,000 shows up in your bank account because it was mistakenly deposited there, that's gonna get clawed back.
But what about data? Mere information? I think there is a pretty good legal argument that there are categories of data (e.g. trade secrets) that a person can be ordered not to possess. So I think the author made the right call by agreeing to cooperate with the city's request, even if it was the city's own colossal error that put him in that position.
Nevertheless, it would have been nice for the city to reward him for his bringing the issue to their attention, rather than immediately trying to threaten him if they didn't help clean up their mess.
I think that's a pretty strong assertion.
>...This isn't something I'm even remotely cool with, so we ended the call a couple minutes later, and agreed to have our lawyers speak going forward.
Honestly, the city was acting in very good faith, but OP decided to troll them and refused to cooperate with the third party auditor. To this day we have to kind of accept the affidavit he signed that data is gone.
In fact, a workers for the municipality is the very last government level Id want snooping in my house. Next thing I know Im getting fined for having the wrong colored bathroom tiles.
This is not at all true.
For example, if you enter into an agreement with your state to be a foster parent, you also have to agree for the state to inspect your home regularly. It's part of the agreement - no warrant required.
The state is free to make search a condition of an agreement. So if the state wants to say "Agree to a search or we will pursue criminal proceedings", you are free to accept or deny their agreement.
The search we’re talking about here is very much the kind of search that warrants a warrant.
I feel like I am taking crazy pills in this thread and no one has an idea of what a warrant actually is and they are just throwing it around like a magic word.
False. (As, also, is the upthread claim that "A warrant is only required for a police search")
Reasonableness is required for all government search, warrants are usually (but not categorically, there are all kinds of established exceptions to the warrant requirement) required for reasonableness.
Even though there isn't anything illegal or incriminating on my hard drive (as far as I know, anyway), I wouldn't agree to let someone violate my privacy for a mistake they made.
Regardless, this whole thing would be "verification theater". OP could have copied the records out to a flash drive before deleting them from the hard drive, and hid it in his floorboards, and there'd be no record he did that. Third-party audit would say "yep, looks like the files have been deleted off the hard drive", and that would be that.
Also, "good faith"? The lawyer OP ended up talking to said that their behavior seemed to indicate they were moving in the direction of CFAA charges. While we can't know that for certain, that's quite the opposite of good faith.
How do you know I didn't upload it to S3, some torrent, IPFS, or elsewhere?
I'd tell them to fuck off if they want to lay hands on my computer.. or at least come back with a court order.
Taking a moral stand has costs that not everyone can bear.
Well, yeah. No way I am letting someone scan and archive my drives/data to correct their mistake. They broke other people’s privacy and now they want to break mine? Pound sand.
Even if they could prove my drives had been wiped, that would do nothing to prove it had not been otherwise copied elsewhere.
Yeah, who the hell does this guy think he is? We want to explore every nook of his house and he gets uppity? Clearly something to hide.
Demanding a warrant to be searched is not hostile it’s the equivalent of saying no thank you. Hostile is when they have a warrant and you still refuse.
IANAL, but demanding a prosecutor and judge be involved when dealing with an IT department is really dumb. If you can just agree with their legal team (and your lawyer) on the stipulations of the search and confirmation, you can't be charged with further crimes if they find anything ("fruit of the poison tree"). But insisting on getting hit with a warrant means anything they find can be used against you.
That is just completely 100% wrong. Warrants are not (or at least, shouldn't be, your mileage may vary based on your local authorities) issued like candy. Prosecutors and judges issue warrants when there is probable cause to search in the event of a crime being committed by you, or simply being committed within an area to which you have access that the public does not. That does not mean you are being charged with a crime. I would agree that more often than not, if you are having warrants issued for searches of your home or business, a criminal prosecution for you is probably not an unreasonable thing to be concerned about, but these are not the same thing. One absolutely happens without the other all the time.
> If you can just agree with their legal team on the stipulations of the search and confirmation, you can't be charged with further crimes if they find anything
This is the same fallacious thinking as "If I've committed no crime I have nothing to fear from being searched," and that's not the point: the point is it is your right to privacy that they are demanding they now have the right to encroach upon to ensure the secure and to-their-satisfaction destruction of data they erroneously sent you which cannot be performed without some element of highly invasive search, and also cannot be requested without the implication that they don't trust you to have deleted it.
This institution regardless of your individual opinions on it does not have your interest at heart: their negligence has placed the two of you as legal entities on opposing sides of a legal affair that can incredibly easily escalate to a conflict. Your lawyer is your FIRST call in this situation, and after that, you shut the fuck up and let your lawyer do their job.
So regardless, by demanding a warrant you would be insisting that the IT Department declare a crime had been committed in the first place. Even if you wanted to defend the legality of you holding onto ill-gotten data, why would you want to get the prosecutor involved at all? Getting a warrant on your property is the worst possible outcome here.
I agree you shouldn't do anything without a lawyer closing looking over the stipulation. But demanding a warrant is probably the dumbest available option. Especially when they already know you have the thing they are looking for!
I disagree, the conversation went that they wanted to Verify it was deleted. That is totally out of grounds for the city to want. The data in this case is contraband, but it was leaked by the city, and hosted by the city in the FOIA portal.
It totally misses the point, you should never consent to a search to verify you don't have it, especially to a third party. Ever. They want to poke and prod around, then it's a warrant and strict chain of custody. None of this third party forsenic firm stuff.
With the warrant demand talk, I would also say that once you make the demand - you give an address where you recieve service and do not follow up or communicate anymore.
Absolutely. Demanding a warrant is your protection against a weak case. But in this particular case, OP has already told authorities that they possessed contraband. The authorities already have everything they need to exercise a warrant. So insisting on one here is the exact opposite protection.
Again, OP was smart and worked with a lawyer to deescalate.
I would challenge you to find a defense attorney who would, in general, advise you to consent to a search even if you "have nothing to hide."
If you invite law enforcement into your home, and they find probable cause or evidence of another crime, then they get to use that to prosecute you.
You don't get to say "but I had an agreement they would only enter my house for the singular purpose of X."
I'm honestly curious as to what there would be to gain on insisting on a warrant rather than just agree to some deal and avoid criminal proceedings.
This part is completely wrong. “Fruit of the poison tree” only counts if the original search was illegal. If you let them search for something specific, nothing is stopping them from using anything they find, even if it wasn’t what they were searching for (as long as they found it during the normal course of searching for the thing they were supposed to be searching for)
Again, I get that a warrant is a great bar to them searching your stuff. But if they already know you have what they are looking for, a warrant seems bad!
I highly recommend you take an afternoon off and sit in a criminal court room and watch how criminal cases progress through the system. Especially for things like drug crime, and especially when evidence is weak. You will learn so much.
Please do that for yourself?
Bypass anyone’s Fourth Amendment rights with this one weird trick discovered by some guy on HN (civil rights attorneys HATE him!)
Yeah but that's because there are specific laws regulating possession of certain materials (NBC capable, explosives, drug precursors).
Now, enriched uranium is a whole different story.
As long as you don’t hurt anyone with it, or try to blackmail the US with it.
[https://www.law.cornell.edu/uscode/text/18/831]
The 7kg limit is apparently a ‘depleted’ (aka refined/filtered) thing - https://www.nrc.gov/reading-rm/doc-collections/cfr/part040/p...
But commonly misquoted.
7kg is a pretty large quantity.
It can be up to 150lbs a year if extracted from drinking water (!!).
Why do I need to give a contractor access to things on my drives like my work contracts, bank statements, other contracts, encrypted SSH keys, as well as some information other people gave me to keep redundant - because of their mistake?
Especially because the average one of these contractors doesn't tend to exude competency. You know, like the first party I'm talking to which caused this whole disaster?
Especially because it wouldn't help. If I wanted to, I'd have drives they don't know about, or containers they can't recognize.
You gotta realize that we live in a world where people have been prosecuted for using nmap. So we have to ride a fine line between careful and aggressive.
I don't expect this to be a thing that stops happening as I continue sending FOIAs. Recently a police agency released to me thousands of social security numbers from ALPR scans (of all things). When I reported it, they shrugged us off and asked us to redact the documents ourselves. When we refused (why would I accept that liability) to, they redacted more, but left in about 800 more SSNs.
[1] https://www.vice.com/en/article/3aqagy/contractor-exposed-th...
And fwiw, I've worked at a high volume help desk too.
E.g. Your email sent to IT was routed, unread, to another department. That department starts their rudimentary FOIA process which includes submitting IT-Request-4 regarding your specific date and field range. IT-Request-4 does not come with context. Seattle's IT department now specs out adding fields to a production database and adding your custom export to the end-of-day batch. They spec out additional hosting costs because IT-Request-4 was designed as a way to create data pipelines.
At this point there are only three people involved and they each have a different view on what's happening due to a knowledge gap. You could eliminate this (imho) by providing motivation and context in your initial request.
I wonder how these exchanges would look if you sent a 'pre-FOIA' heads up to specific departments in a city, introducing yourself as conducting a large-scale survey of FOIA processes and letting them know your request will revolve around a year's worth of email metadata. It feels like this could be a more collaborative process.
Would you ever use a computer again if someone else of unknown intent had unlimited access to it for an extended period of time? I certainly wouldn't.
The suggested remedy isn't even effective. You can't prove that you deleted something. It could all be on an SD card buried under a rock somewhere, regardless of what the consultant finds.
Frankly, given the track record of cooperation, the first offer should have been "just delete them and sign an affidavit attesting to that" which is exactly what happened.
That would be incredibly risky, though. If the city did later realize their error, they would likely assume malice on the part of OP for not telling them about it. If we think his treatment after telling them wasn't great, imagine how bad it would be otherwise.
> ... and he would have been free to do whatever he liked with the data.
I don't think that necessarily follows. He could -- and likely would -- get in a lot of trouble for publishing the extra data.
Everything is mere information.
https://about.usps.com/publications/pub300a/pub300a_v04_revi...
https://faq.usps.com/s/article/What-Options-Do-I-Have-Regard...
Additional discussion on if they mis-ship things to you:
https://law.stackexchange.com/questions/17533/if-a-retailer-...
Even more confusing, what if the package is FROM the USPS, is addressed to someone else, but accidentally delivered to you?
This is a fascinating blog and I hope you have the time to do and write more articles like this one!
However, there is zero chance I'd acquiesce to a third party high end security contractor like Kroll in to "scan my systems." I found that a little bit disturbing for a city to unleash it's world wide third party contractor on an unsuspecting civilian that was trying to help them out of a _legal mess_ they created.
Agree. You can’t un-ring a bell. You can’t un-tell a secret.
I finally received my credentials, but they didn't work. Assuming that the password was likely the problem, I tried the password reset function, only to get a 404 error.
The person I corresponded with was very polite, but it took three resets on their end, before I could finally log in.
A private company with these issues would go out if business. The government probably just hires another incompetent dweeb, who will have a job for life.
Probably a bit of both. I'd be very nervous about jumping through the hoops that come with supplying to government -- hoops the people working in the government don't want, but ones that have been put in by politicians for various reasons.
No. That is why government IT is not very good. It's a terrible environment to work in, and the pay is not good compared to private sector.
This kind of behaviour does nothing to advance the cause. It just perpetuates the belief that open data and FOI are massive waste of time and resources and open legal risks for no good reason.
I'm also pretty surprised that people think email metadata from government is legitimate open data. Do you think it should be public how many times you have emailed government and gotten a response, and to which departments? I don't.
My go-to phrase for open data is, "open data is a lie". Because at the end of the day, we have zero legal recourse to validate that what is provided through open datasets is complete, both in terms of available columns and available rows. Very rarely will it ever be explained why, or even if, information is missing. And the subsequent effects of that lead to a deep public misunderstanding of what's going on. And much of it is intentional out of explicit fear that the public will misinterpret the data. So we go through FOIA instead and we end up going through legal battles. There's a reason I've had to do ~10 FOIA suits.
tl;dr: open data is nice, but its lack of rigor and accountability makes it effectively useless for anything that requires depth.
They are two very different processes, yes. Open data tends to connect you with technologists and subject matter experts who want to talk about their field. FOI tends to connect you with lawyers and governance gurus who want to find reasons not to give you what you want.
Around here the FOI processes are getting slower and less forthcoming, in defiance of the law, and ridiculous requests like these ones do not help make the case for their support.
Yes, FOI processes are getting slower and yes we're going to keep suing. What other choice do we have? One thing to consider is that SO MUCH of that is a product of gov agencies simply not preparing their documents in a way that makes them FOIAable. So much can be done that simply isn't -- a significant amount of which is very intentional (eg, police records) in an intentional violation of the law.
We're not trying to be dicks in all of this. We just want to know what's going on. So yours (and many others in your position)'s clear desire to think of us as adversaries rather than simply people who want to know what the fuck is going on is blinding your vision.
Get out of your head as a person in government and start thinking as a person who's at least empathetic towards the frustrations of a tired public that constantly lied to, deceived, and fed communications that are perpetually weighed down by legally reviewed PR releases. We can do better, but sure as hell not with your defeated attitude.
> So yours (and many others in your position)'s clear desire to think of us as adversaries rather than simply people who want to know what the fuck is going on is blinding your vision.
Yea, I don't work in his position or any government position, but you are being adversarial. And, whatever you're trying to do, you're being a dick in at least this comment.
I highly recommend you read this (shameless plug), which shows just a sliver of the nonsense that we have to deal with: https://southsideweekly.com/cpd-routinely-denies-foia-reques...
Funny enough, I tried to get a gov job recently. A chief data officer job in a niche group which I think I'd do a damn good job at. They denied me immediately because I don't have a degree, despite my qualifications. So yeah, I actually agree to a point that joining gov can be a way to 'fix things'... but, welp?
But even further, I have tried working with gov agencies on issues I've felt deep anguish towards. In late 2019 I did a significant amount of free data analysis of Chicago's parking tickets for the Chicago mayor's office to show how excessive ticketing can be. They reached out to me, they said they loved the work, but did shit-all with it. Later that year, the mayor ended up doing a 180 on the desire to have more-just ticketing policies. A month after I gave them that analysis, in a FOIA lawsuit trial, the city's counsel threw me under the bus by arguing that my end goal in that litigation is to gain access to their data so that I can modify it. Completely baseless argument that actively ignored that I put significant effort in trying to help with the highest office of the city. For free. So dude? I've fucking tried. In the end the city acted (and acts!) like a bully for the sole purpose of winning their cases. When that's the standard of behavior we receive, it's a damn wonder we even try to make any intentional effort to be kind.
Also, when I've been told over the phone and email countless times, "we are not obligated to answer questions under the law"... even for the most basic of things.. it's pretty clear where the disconnect is.
I could go on with these stories, but since it really sounds like you didn't read the article I shared -- please do, and you might better see where many of us are coming from.
on the surface i agree with you. beneath the surface, other governmental units already possess all the metadata for your emails/phone calls, it would be a weird bit of asymmetry to say it’s okay for them to have your metadata but not for you to have their metadata.
it’s not a perfect mirror, for obvious reasons, but if OP went on to show that this metadata is powerful and push that neither side should be collecting that type of metadata, then that’s a single legitimate use i can think of for this kind of FOIA.
But that's not what this is. This is saying it's ok for them to give your metadata out to anyone who asks.
In Sweden, when you contact the government by web form or mail, they warn you that every communication is by law part of the public record (metadata and contents), and you should not include anything sensitive that you do not want divulged.
Having worked as a sysadmin on the other end I can almost guess how his initial request was received.
As many others do they only read part of his request and were dumbfounded by the scale of it. So in their minds he was requesting way too much information and they probably spent days at the water cooler laughing at this guy under wrong pretences.
Eventually someone realized their misinterpretation and proceeded to make the dire mistake of exporting the e-mail headers with a cut off at a hard coded value I'm assuming. Instead of parsing out the headers from the email.
And it wasn't until he pointed this out to them that they started taking him seriously. :D
I certainly don't expect IT groups to bend over backward for every request or be polite in the face of real abuse, but the toxic shit that is said at the water cooler is never that. It's literally insulting people's intelligence or taking pleasure in people's pain, especially if it involves exercising their power over users.
oh the fun it is to deal with public agencies.
in Europe, this request
1. From address
2. To address
3. bcc addresses
4. cc addresses
5. Time
6. Date
correlates person-related information (who was in contact with whom at which date and time). storing it, let alone processing it is only admissible on a need to know basis. even if you jump through the hoop of an officer acting on behalf of Seattle is not a person any more, which is a stretch already, even then all email addresses outside the Seattle gov domain are completely taboo without a court order and a cause (and being criminal investigator)oh privacy ...
In Washington, and Seattle specifically, doing something as simple as reserving a park space or signing up for a constituent newsletter means a public record has been created. Data brokers and people who want to "just reach out for a simple conversation" and political parties routinely make grabs for this data to populate mailing lists and the like.
That's annoying and shouldn't be a function of public records laws. We exempt utility billing records, even when the utility is owned by a city, and library card data and so on. Asking for a service from the government should be wholly exempt.
In the early years of the rollout of federal income tax, the government lacked an IRS to enforce the code. They addressed the issue by making income tax filings public knowledge, so that if individuals saw that, for instance, their neighbor was claiming poverty income on their spacious mansion with the new well-appointed carriage house, they could sic the feds on them. Today, many states still post the voter rolls (and their status, such as "out of town for this election") at voting places because it's considered to be part of the public's right to defend the vote by noticing that Steve said he'd be out of town (or moved last month), but here he is in the voting line; is he trying to double-vote?
For instance it's incredibly easy to detect double voting if you have to check in at the polling location and send your ballot in in a signed envelope how on earth would it be possible to miss such?
What can happen and does happen to thousands of folks in an election with over a 100M voters is folks plan to be out of town and come back.
Lets be mean. When you thought of this sort of circumstance is an imaginary problem that would have thousands of false positives and zero true positives.
You ably demonstrate why its useless to crowd source election integrity because the crowd doesn't know anything. If you need further evidence look at all the other imaginary election fraud from causes as simple as not understanding things like
- people cast legit votes then die weeks or months later
- people move in area and forget to update their voter registration
- people have the same first and last name as the recently dead/moved/imprisoned/otherwise ineligible
And, you know, cities have no problem giving out personal information all of the time. Your personal address, or whoever owns property in a city, is a matter of public record. And so the city has no problem handing out your name and address to anyone that asks. Your email address is much lower stake.
I would have considered my personal From and To associations to be private information since my email address started with ...utzoo!
[EDIT: to be clear, the following refers to the GP comment referring to in Europe, where as the parent comment is clearly US-centric]
Even if you replaced every distinct e-mail address with an ID or hash or whatever, they would still fall foul of GDPR because that ID or hash would become PII. You might say that's impossible, but for instance, if you knew that you happened to send specific e-mails to people in that dataset, you could correlate the times to discover your own hash, then filter by your hash and use the times to correlate with who you sent them to. Now you know the hashes of everyone you corresponded with, and can do PII-based analysis on that, e.g. how many people e-mailed them and when, whether they responded, who else they e-mailed after receiving those e-mails (so you might be able to start identifying colleagues etc), etc.
PII, even in what looks to be anonymous data, is very valuable to people who are determined to mine it, which is why typically data such as this should only be disclosed in aggregate, and usually after verifying that each aggregated set of data actually covers a large enough group of individuals that also can't be correlated another way.
Whoever the author is has a totally different view of "metadata".
Metadata from my perspective would be "general amount of emails", (possibly) "address blocks (just involved, not from/to/bcc/cc)", "time frames" (with large window averaging), (maybe...) "very vague categories".
I pointed out that no, it includes the non-employees who interact with the government.
You answer...they don't have to use email, therefore everyone who does is a government employee?
No.
My statement is that every interaction with local government in the US generates a public record. This is true even when email is not involved. For example, let’s say that you have purchased a property. The deed is registered with a county government. The tax assessor decides how much property tax you will owe. They record whether you have actually paid that tax or not. All of these records are public information, and there is very little concession to privacy. In the US, there is no expectation of privacy around these records. Anyone in the US can look up these records for any property at all, and your name is there for all to see. The amount you paid for the property is there for all to see, and so on. Your phone number and email address would be there too, except for the fact that they don’t collect or store that information. They don’t need too, because they always do business with you by mail. These days you can also use their website to pay your property tax, or to look up information about a property you are interested in, but that is ancillary.
The same holds true for almost all other ways that you might interact with the government. Building permits and inspections are public records. Arrest warrants are open. Trial records. Water bills are public records, if the water is provided by a utility owned and operated by the government (varies from place to place). Drivers licensing is almost entirely open. Vehicle registration. Bids on providing goods and services to the government are only sealed for a short time; once the winning bidder is selected all of them become public records. All of this is business as usual in the US.
Finally, all of the official communications of government employees and elected officials, whether internal to a government department or not, are public records. That means that if you talk to a mayor, whether by phone or by email or by written letter, and the mayor is acting in an official capacity, then the entirety of your communication is a public record. That includes the type of communication, how it was delivered, your phone number, your email address, etc. All of it is to be recorded and made available to the public upon request.
Of course public records may contain information that is not public. When a member of the public requests a public record, such non–public information should be redacted from the copy that they receive. That includes things like credit card numbers and social–security numbers, but not necessarily phone numbers or email addresses. Especially not the phone numbers or email addresses of the parties to the communication. Maybe it’s different where you’re from, but here those are important parts of the public record. If you want to talk to the mayor but don’t want your email address to become part of the public record, then don’t talk to the mayor via email! Write a letter instead.
If you think that request was bad you should look up the history of LexisNexis. Their bread and butter is requesting data and collecting it all into a single database that you can use to background check anyone the american government vaguely knows about.
There also used to be a site called masscorruption that I'm pretty sure focused on a single county government in massachusetts run by some whacker with an axe to grind. He filed a FOIA request for every image file on a government desktop, which was fulfilled, and he went on to publish the employee's personal images that probably should not have been stored on a govt computer.
At my workplace whenever I put a government employee in the to: line a banner appears in outlook informing me that the message I am writing can be FOIA'd. Especially with local govts you just never know how people are going to get activated and what will be interesting to them.
Not addressing the main thrust of the article I know, but I am genuinely curious: do a lot of people have a "my lawyer" ready to go?
But yes I do agree, it's probably a minority of people that regularly use a specific lawyer.
I figure the number of lawyers willing to do such small favors is in the range of 1% to 10% of the 1.3M (wild guess). So if each of them had 100 friends-and-family "clients", it still wouldn't add up to "pretty common".
Also further reduce your number for adults in the name age bracket as practising lawyers.
Like, I had a few issues with the last place I rented, and during that, I entered the Mieterschutzbund, an association for tenant protection. Through this, I can get access to an hour of consulting with an expert from the association as well as one or two hours of a lawyer specializing in tenant laws. This doesn't take much longer than 1-2 days. So I guess I have a tenancy lawyer on call.
1. From address 2. To address 3. bcc addresses 4. cc addresses 5. Time 6. Date
Is this really a reasonable request that the government is expected to answer? Doesn't this expose a bunch of private information about government employees and the people they interact with? I understand this post (and apparently the law) takes this as completely normal thing, but it seems really weird to me.
Some examples:
* exact times people are getting in/out the office (eg. the time in the morning when a person first answers an email from their boss)
* full information about holidays taken by all employees (eg. days/weeks during which no emails are sent)
* friendships or relationships (eg. any communication between employees that doesn't follow from the hierarchy or from team delineations)
* information from criminal investigations (eg. an investigator sending an email to the parking fine department probably means one of the cases they're working on is related to parking fines)
This all seems a huge privacy leak? Should this stuff even be called "metadata" if so much can be derived from it?
This piece heavily used email metadata requests:
https://southsideweekly.com/lightfoot-pac-paid-consultant-wh...
Security researchers get FUCKED, hard. They're treated as evil bad hackers who will destroy everything.
Why? Cause they made people look bad.
The real answer? It was provided as public records. So slap-em into public. Fuck 'em.
(Or, sell it to a gray hat data broker and get paid.)
Is this legal? It sure doesn't seem ethical
I'm not sure if city councilors are subject to such public scrutiny but it's still really stupid.
So, yeah, using a non-city email address as his campaign contact email seems not only legal and ethical, but probably legally and ethically mandatory.
EDIT: the applicable Washington state statute on political campaign uses of public resources is: https://app.leg.wa.gov/RCW/default.aspx?cite=42.52.180
The main body of the rule is "No state officer or state employee may use or authorize the use of facilities of an agency, directly or indirectly, for the purpose of assisting a campaign for election of a person to an office or for the promotion of or opposition to a ballot proposition. Knowing acquiescence by a person with authority to direct, control, or influence the actions of the state officer or state employee using public resources in violation of this section constitutes a violation of this section. Facilities of an agency include, but are not limited to, use of stationery, postage, machines, and equipment, use of state employees of the agency during working hours, vehicles, office space, publications of the agency, and clientele lists of persons served by the agency."
EDIT AGAIN: Looking at that again, that is specific to state officers or employees, so may not be applicable to city officials, but represents the kind of rule that is commonly in place.
That said, I mostly only make "difficult" FOIA-equivalent requests. Routine requests for specific documents are mostly no trouble here.
https://web.archive.org/web/20230129193630/https://mchap.io/...
Also, in your post I think you mentioned "FOIA junkies" or something along those lines, this implies to me there's a community of people who understand this stuff and talk about it. That sounds really interesting to join. Is there a subreddit or something?
There are definitely groups out there that have collectively caught the "FOIA bug". It's a very fun culture of sharing and holding those in power accountable when they otherwise wouldn't be. I recommend just submitting a random request to a random agency about something you're interested as another alternative starting point. What tends to happen, amusingly, is that once someone submits their first, then something kinda clicks in their head and they submit another, then another... then they sue. It's all very organic and it's very uplifting to see someone grow in this field. We generally try to do our best to teach others what we've learned (tactics, strategy, wording, techniques, etc). So if you pick something up, definitely share the love.
This stuff is really interesting to me for sure! I guess my biggest concerns are kind of just a generic paranoia about "getting on some list" and also the kind of thing that happened in the article. They send you too much info then suddenly are threatening you and are asking to scan your hard drive. Not saying I'm deterred but dealing with government feels like a kind of frightening task at times for some reason!
Had he dug in completely, the city was treating the situation as if they would bring charges under the Computer Fraud and Abuse Act (which I don't think precisely fits, but might have been the only leverage the city had to prevent a potential bad actor from capitalizing on their mistake).
Honestly, the city had no way of knowing that he hadn't already sold the entire dataset on Silk Road, so they were instilling a huge amount of trust that he was being a "Good Samaritan".
I agree with the author's reaction though, and any non-court ordered scanning of my system would have to happen under my supervision, with strict agreement on the how.
- He FOIA'd all metadata of emails to and from the City of Seattle.
- The city IT department pushed back, saying that their policy was to hand-review each email for privacy, and this was 32m emails.
- They later acquiesced and just dumped all of the meta-data into files and sent it over
- They didn't realize email-preview was also meta-data, which included the first 256 char of each email.
- OP informed them that had now committed a very grievous data leak.
- The city fixed the issue and legally pursued OP to ensure the data was deleted.
All say, I am glad I am not a civil servant. The job seems awful.
How hard can it be to do a sanity check of the metadata?
Again, the vast majority of the emails were automated alert/spam emails. So it's unclear if a random sample of the data would have turned up anything interesting to look at if you didn't know what you were looking for.
Opening a file of that size in Excel would probably crash the desktop. And this was probably a lowly admin without a lot of other tools.
The first 256 char of a lot of system emails are going to just have junk html and header tags. If you don't understand that you are looking at HTML, it's not going to be apparent that you are looking at the body of an email.
It's a rookie mistake to be sure, but the admin was clearly unfamiliar with what was being requested.
This isn't even to ensure my data file doesn't include something private, just to ensure that it actually includes what I intended it to, and I didn't do something dumb like put the data in the same field twice, or duplicate the same record over and over, or whatever.
Discovery and FOIA-equivalent requests that I've seen at the SLTT level were handled with the care that is expected for potentially sensitive communications. I'm sure smaller orgs can't do it as well, but Seattle is probably going to have some money for this stuff.
This is an edge case for which they probably didn't have an existing process which means they had to wing it.
https://web.archive.org/web/20231024164822/https://mchap.io/...
I don't agree with all his takes. It's absurd he toyed with the idea of asking to keep this data, for instance... But I think he is rightfully pissed.
Just because they're incompetent doesn't mean the public should suffer for it.
I'll admit I could have been kinder, but I'm not sure I'd call their irritation "slight". You're really downplaying the (clearly intentional) audacity of their response as well as how often these sorts of audacious responses happen. It's hard NOT to get aggressive in these communications when their intentions are clearly rooted in just making me go away. It's a very common pattern and a very frustrating one at that, especially when the gov folks are intentionally obstinate on top of everything else. Here's another example of an agency that started off aggressively and got egg on their face from their hubris to show what I mean:
https://www.muckrock.com/foi/vermont-80/email-metadata-55744...
From:
"The production of the requested records for March 5, required the time of 5 interns (3 unpaid) who all worked 6 hours cutting and pasting the emails from paper copies. This also required staff time to collect and print the emails and review for the security concerns we indicated in an earlier email. The estimated cost, which was not charged to you, was conservatively, $412 for the record we produced:"
To this, followed by the records for free, after I sent them instructions: I have been working with our IT folks and may be able to extract to a spreadsheet to fulfill your request.
But anywho, whenever I teach FOIA stuff these days I always start out with the advice to always be kind. So it's a lesson learned.The entitled prima donnas are the public employees of Seattle that seem to have the attitude that they shouldn't be bothered to do their jobs properly.
What this is is pure scumbaggery using the guise of public service. It's akin to those "first amendment auditors" on YouTube.
He's trying to ensure that governments have processes in place to quickly and effectively serve citizens according to the law.
I actually expect them to serve us with a smile and good manners not unlike the courtesy expected from the good folks at any Chick-Fillet.
As in, he (like everybody else) is legally entitled to have access to records our government is responsible for making available, in the interest of transparency and accountability. Be thankful there are people out there volunteering to do the testing necessary to make sure our rights are working properly.