140 million people had their entire credit reports/history and all associated information released to the world because Equifax thought having it all accessible, publicly, without changing the goddamn default password was a good idea.
The penalty? Profits.
They immediately bought a credit monitoring agency, then gave everyone 24 months of monitoring, for a lifelong problem. After that 24 months, a large number of people starting paying for the service, because it's a lifelong fucking problem.
Equifax is still in business today, still hoovering up all of that data, with zero recourse by the consumer and when they fucked it up, they made money.
We don't have to worry about bad actors. We have companies doing it for them, happily.
Might have something to do with the GP's choice of words:
> Maybe this is a cynical, defeatist approach
People should also understand that "put onto the Internet" doesn't just mean typing something into a box and hitting the "post" button. It also means:
- "Private" messages that go through an intermediary web service
- All forms of cloud storage, including (especially) your photos
- Any browsing history that can be associated with an IP address that can be tied back to you
A lot of this stuff is one leaked password or SIM swap away from being public data.
I actively manage my footprint now, but I have to admit that getting started was a bit overwhelming. It's roughly on-par with switching over to a password manager for someone who was not using one before. It involves a lot of going through your inbox to locate accounts and then navigating a slew of different patterns for how to shut down your account, or at least to scrub information you don't want revealed from those accounts.
Once you get started, though, maintenance mode is fairly easy. Those "terms of use update" emails are very handy in picking up accounts you forgot you had and shutting them down. That, plus having a couple of templates handy to copy/paste when you get individualized outreach from sales teams.
The hardest part is that the majority of companies seem to have no idea how to comply with requests, which leads me to believe the number of people requesting removal of their data is much, much lower than I would hope or expect. It's generally incompetence, not malice. Or probably more accurately, it can be a complex technical task that requires interdepartmental cooperation to implement a good system, and few companies are jumping up and down to fund expensive or complicated compliance efforts in their sales and marketing teams .
Do you mind elaborating/sharing?
I include a snippet like this one, which is for paper mail:
I'm writing to request that you please remove me from your postal mailings list. I no longer wish to receive your mailings. Please, also, do not rent or sell my name or address to other organizations.
After many experiences of broken CCPA compliance I'm beginning to wonder if there is not a strategic component to the widespread incompetence.
Last night, I tried a CCPA request against keenan.com that a former employer had, apparently, "shared" my information with several years ago. Keenan.com recently sent out data breach announcements to let us know that they failed to properly secure the personal data they collected/hoarded on us via our [past] employers, and I wanted them to tell me what they potentially disclosed and then delete my data. From the email bounce message, they use Microsoft o356 hosted email, and configured their ccpa contact email address they list on the keenan.com website, "ccpa@assuredpartners.com" to only accept mail from internal senders on their own domain(s). Maybe the IT for keenan.com/assuredpartners.com is a clown show (they did hoard data they no longer needed, and failed to secure the data they collected/hoarded), but it seems unlikely that every company, of the many I've encountered with broken CCPA processes, would be similarly incompetent.
Several phone requests to other companies, using the CCPA contact number on their websites were answered by folks who have no idea what the CCPA even is.
One of the largest data brokers in the US failed to remove my data following a CCPA request until I contacted the VP of their legal department directly.
Most of my requests have either encountered (possibly strategic) incompetence as the above, or malicious compliance, where they make the process as time consuming and annoying as they possibly can. E.g., a web form that requires filling out the entire form repeatedly for each right you wish to exercise under the CCPA.
TLDR, maybe evil companies are just being evil?
Like when you “Press 1 to be removed” or “text STOP to opt out” — all it does is move you to the mailing list they have for people who think they’re doing something that has any effect. I’m sure that’s valuable to a lot of marketers.
You may be referring to "hiding your data from your own view" ...
For SoMe and other organizations that have very large databases it is a very common procedure (if not outright "best practice") to NOT delete anything, but in stead "mark as deleted". The data is still there, it is just no longer visible.
Of course such a practice means that your data (even if you think you have deleted it) is still vulnerable to all the standard (and non-standard) issues, from internal data mining over data breaches to governmental requests, etc.
The only surefire way to avoid exposing yourself is to avoid interacting with these services at all.
If you turn off watch history/location history/search history, I assume that Google prevents your local device from saving the history but saves all of the history data to their servers anyway. In my head, I describe my conspiracy theory as "delete your data = prevent only you from using your data".
Obviously doesn't work for anything that needs real phone# or real physical address, but anything to reduce risk of data breach, cross-referencing data, tracking helps.
I also use disposable digital credit card number (from wise.com) for non-mainstream sites.
It's a lot easier than having to navigate the 'delete all my data' maze.