CEO of data privacy company Onerep.com founded dozens of people-search firms
krebsonsecurity.com
krebsonsecurity.com
You end up in a never-ending game of whack-a-mole. Complete with monthly fees.
Pay and your problems magically go away. Proofpoint was consistently the only block hit.
In many cases, the potential problem may be caused by the same party that offers to solve it, but that fact may be concealed, with the intent to engender continual patronage.
They control the supply (the sites with your info) and the demand (the sites you can go through to request it get taken down)
/s, obviously
You know, those entities that hoover up any and all info on you, that you cannot opt out of, maintain information whether its accurate or not and refuse to delete obviously erroneous data, then release it *all* to the world by being extremely poor stewards of said data, then charging you for credit monitoring for the rest of your life, since your immutable info just got shared with assholes.
Guess who owns most/all of the credit monitoring entities?
Edit: typo...words are hard.
Additionally, if you haven't, freeze your credit at all bureaus including LexisNexis.
I wish you good luck opting out. I'm not talking about what the law says, I'm talking about how they act.
Technically, you can dispute incorrect info. What that dispute amounts to is the bureau asking the entity if it's accurate. No proof needed. If they say it's accurate, then you're stuck with it, until you jump through many, many more hoops.
I guess we could say it’s the data privacy mafia.
Some places don't allow use of smart phone. They actually ask you check your phone into a coat check type thing at door! One journalist friend often leaves the smart phone at home.
putting all that on a device that you don't control and that "strangers" at apple or google can access or make changes to at any time, and without any notice to you and without any permission from you sounds like a step backwards in security and privacy.
Cabaret at the Kit Kat club in London places a sticker over any camera lens. The Burnt City, an immersive theatrical experience, makes you place your phone in a pouch that is then sealed with a tamper evident fastening before you enter the venue.
It wasn't paranoia it was a healthy dose of "if this is possible, someone is doing it"
Turned out they in fact were doing it.
Everything else is fair game apparently.
But this is really a chicken-egg situation. How do you tell companies to delete your information without telling them what identifies your information? It's in these companies' interest to make this as difficult as possible, so a solution based on data hashes is highly unlikely to appear out of their good will alone. This requires strict regulation and high fines.
There's also the issue of proving ownership of the data requested for deletion. Even in the EU with the GDPR, which is arguably the most progressive data privacy regulation we have, companies routinely violate this by requesting even more personal information from the requester.
Even test cases will run into data sharing issues.
amazingly enough the law is more clever than programmers assume it is, and the clever dodges programmers come up with tend to be seen through and just lead to jail time.
Prime Exhibit - https://en.wikipedia.org/wiki/Hans_Reiser
Then when it fell apart he dropped back to arguing he just looked guilty because he was too smart to look innocent or something https://yro.slashdot.org/story/08/02/23/2218256/hans-reiser-...
https://www.eastbaytimes.com/2010/08/02/review-from-a-report... >He thought he was smarter than everyone else, but ultimately he was not
However, I would ban surveys because they can lead people to vote for the wrong person due to social pressure.
On past projects we've recorded the time the user submitted a from (with a checked consent checkbox), but this doens't feel like rigorous proof.
Given that these companies, like Incogni and DeleteMe, are now sponsoring big time YouTubers I'd imagine they are soon going to get a much closer look. At minimum, they are making far more people aware of the situation and data out there. Even though many of the VPNs fall far short of the promises, it is setting a strong signal that people care about privacy and entering the public lexicon is the first step. I hope these can be a catalyst towards more state or federal privacy protection.
I've wondered about this too.
I have a common enough name that about 2/3 of the info data brokers have on me is garbage.
If every data broker could be relied on to faithfully delete my info I would sign up for Optery or Incogni today. I don't, because if even one of those 2/3 is a bad actor I'm just expending effort to clean up their data.
Specifically, the data I don't want them to have.
https://www.mozilla.org/en-US/about/legal/terms/subscription...
I think this is one of the problems of organisations not doing anything themselves, and offloading responsibility and liability to both external partners.
If you trusted Mozilla Monitor with your personal data, their legal contact information is listed on their terms page: https://www.mozilla.org/en-US/about/legal/terms/subscription...
The same terms page you agreed to which both limited their liability to $500, and granted them indemnification from liability.
The problem is there are 200+ data brokers out there and I don't have time to deal with that many.
https://www.optery.com/optery-statement-following-investigat...
We have a 'downgrade to a free tier' option if you are paying and want to take a break from the service. We delete all data if you decide to cancel, but you can join back any time. If it's not clear from the username, I'm on the team.
My first priority is not having my personal info listed on the internet; ethics of where my money is going is second.
One question: Do you know if they pay the data brokers a percentage?
They submit opt-out removals though, so one would think that if they paid the data broker they would not have to go through that trouble?
It involved phone call to an Indian call-center. While remaining polite (not easy) but persistent, I had to listen to multiple dumb pitches about their "services". I stuck with it and in the end they removed my name but indicated it "may" come back.
That was in 2018. My name no longer appears when searching their website. I do, however, get MULTIPLE garbage emails per day from mylife indicating "changes" about my profile and that of my family and neighbors.
I have avoided dealing with 3rd parties for this stuff. In addition to the fact that they may, as Krebs indicated, racketeer with the scummy brokers there's ALSO another concern: Some of them PAY the data brokers a percentage of the fees they collect to remove names. The last thing I want is for these bastards to get any money for their activities.
BTW, the founder and CEO of Mylife.com is Jeffrey Tinsley. He appears to have made quite a fortune doing this data-broker shit.
--
My first thought was: "why stick all this info in a readme and not some nice json list I could scrape".
I then thought: "maybe I can just have my AI friend scan the readme and do all the opt-out work for me"
Since it seems very difficult to try to get a leaked identity removed, maybe try to hide a tree in the forest?
> For example, the disaster surrounding London’s new Routemaster city buses disappeared into the depths of the web after Johnson made completely nonsensical statements in the media about building model buses from wine crates. Coverage of these statements triggered a flood of search queries on Google that displaced negative search queries and Google Suggest results related to Boris Johnson.
> Research showed that before the wine crate buses interview, 100% of Google Suggest and search results on page one that were displayed in connection with Boris Johnson had negative connotations. After the interview, it was only 20%.
> Additionally, when news broke that British Government members had flouted Covid guidelines to meet for wine and cheese during a ‘work meeting’, it was seized upon by the British press as “partygate.” Soon after, Johnson was quoted in interview saying, “I don’t work from home. The cheese will distract you.” As a result, negative coverage of the British Government’s party-gate incidents were glossed over by search suggestions and results, and keywords with negative connotations no longer appeared in Google Suggest prompts.
Source: https://blog.searchmetrics.com/us/cheese-wine-and-whistles-m...
> There is one thing that is absolutely certain about throwing a dead cat on the dining room table – and I don’t mean that people will be outraged, alarmed, disgusted. That is true, but irrelevant. The key point, says my Australian friend, is that everyone will shout, ‘Jeez, mate, there’s a dead cat on the table!’ In other words, they will be talking about the dead cat – the thing you want them to talk about – and they will not be talking about the issue that has been causing you so much grief.
- Boris Johnson
But seriously - trading both sides (or, selling protection, as the case may be) is quite a profitable business model.
(I'm just a user, not associated with them.)
And I don’t see the other party doing anything equivalent, from giant flags on pickup trucks, to roadside merchandise stalls, to pick up truck convoys that harass and bully other candidates on the road…
I guess the liberal equivalent is driving a Prius or something. Both sides, right..?
Ask anyone about there political merchandise and they will never see it as just "merch" but as a fundamental truth that is pivotal to there way of life they they feel is being threatened. It's much like calling someone's religious garments or iconography just merchandise and is a very closed minded point of view.
Guarantee someone's already selling some Jacked Up Joe merch already.
There's always someone selling merch though, a few years back a rather famous/infamous politician in NZ, Winston Peters, came out of left field to win a by-election in the electorate of Northland that the ruling National party government expected to win easy, the same party that had snubbed his offers to work together.
So people started selling "King in the North" t-shirts with ol Winnie photoshopped onto Jon Snow. I, being honest, nearly bought one, because you had to admire his schtick.
So yeah, there's always merch.
But, AFAIK, at least no-one is selling Joe Biden fan art NFTs yet. It's like a double grift.
And obviously Trump loves the merch far more because he gets a cut.
It’s not quite comparable though - this is deliberately deceiving a market into acquiring a service they didn’t need, which is basically racketeering.
Do they just scam people by compiling whatever is available on search engines? In one or two cases, I have seen them at least giving the house address or family member details right. So there seems to be more at play.
Same for court/criminal records, marriage records (in some states), etc.
None of the online privacy protection programs truly work. (except for 1)
Paying money so you don’t get roughed up looks pretty much the same whether it’s a bandit or a king doing it.
Unless you're in the UK, though, King Charles is not exactly asking for anything from you.
Once organized crime gets big enough, it's really difficult to distinguish from a weak government.
Once organized crime gets really big, it stops being crime and persists on organization alone.
If they get too powerful, we just drop the "para" on that name.
There really is an XKCD for everything
How about https://crscpa.com/blog/how-much-profit-can-a-nonprofit-make...
I've been involved in the development of B2B SaaS solutions, and there are a few providers, such as ZoomInfo, Apollo, and Clearbit, that greatly assist the sales team in gaining a deeper understanding of customers. It seems that venture capitalists love those businesses.
Has anyone attempted to create similar companies that offer Data as a Service?
https://news.ycombinator.com/item?id=39698546
and using that to automate the unsub from trackers:
-->
This really needs to be used to make a tool to automate all the "delete my data" requests and have users map out deleting their data/PII etc from data brokers to a git something and people can submit the recipes to delete your personal data.
I just did so on one of the more terrible ones yesterday - and the dark pattern was it would put you in captcha-loops... and youd have to reload/retry several times before stopped asking you firehydrant bus traffic motorcycle crosswalk over and over.
but to save unsub/delete me scripts with this would be nifty.
A recipe bounty would be neat - for example - Optery found me in more PII dbs than I expected - and it would be cool for people to see which brokers they are found in and there is a bounty list for all the brokers people are finding for someone to create a Delete-Me for each thing, so that one hopefully has the help of many to navigate the minefield of dark patterns in such.
Your best bet is what the government minister mentioned elsewhere in this thread did. Generate noise. So much noise that none of your "PII" is even remotely accurate.
You can't hide, but you can paint an incredibly inaccurate picture.
How do you reasonably do this? You would have to spend an incredible amount of effort creating fake data everywhere, without having any clue if what you're doing is even working. With new AI tools and technologies it's likely that someone with enough resources and motivation would be able to filter out the signal from the noise anyway.
I currently lean towards just minimizing my digital footprint, and carefully choosing the hardware and software I use. It still takes a lot of effort and sacrifice, and I don't expect this method to be foolproof, but at least it's reasonably manageable. At some point you do have to accept that absolute privacy is impossible in the modern world, even if you shun all technology.
You answered your own question.
And even with AI, it would take a considerable amount of effort to flood all public channels with fake data. Do you do this via APIs for every service? Do you generate image and video as well? You would still have no idea whether your efforts are actually working.
Not to mention that using this approach contributes noise to an already noisy medium. Your fight with an imaginary enemy worsens the online experience for everyone else. We have enough junk on the internet as it is.
By being rich enough to hire dedicated companies who provide this service. Reputation management it is sometimes called.
It’s largely unnecessary for corporate owned domains. You know who owns it from the website they publish.