I got a warning this morning from HaveIBeenPwnd and this article was in the breach email. Considering the current US political environment and the recent article by Tim Berners Lee, this spam list is extra scary.
I am aware of one EU entity that sits on a mountain of such data (and much worse, in fact) with very little in terms of security.
I'm simply waiting for the day when there will be a hack like this on the European continent, it's scary what sits in lightly protected databases, especially if you consider the probable sources of data like this and that - at least in Europe - it would be illegal to create such a DB without the consent of those whose information is stored in them.
We've lost control is the perfect way to describe things.
Not everywhere. Significantly it's not legal to be moving EU Personal Data out of the EU. And these guys are going to get hit hard (including personal liability for their privacy officers). It would be responsible of OP to report it to them but theirs no real obligation for him to do so. It's on them to protect it.
You were certainly right (and still are, depending on how you read your comment). I'm not a lawyer, but I believe that Safe Harbor is no longer safe to rely on (since a 2015 ruling). There's Privacy Shield and the soon to come into force GDPR, though, which have restrictions like the one you mention.
As someone who is going through a data protection audit with his company: They take the process very seriously and ask some tough questions. It's better to be prepared and play it right from day 1. Proper documentation matters as well.
> it would be illegal to create such a DB without the consent of those whose information is stored in them.
I can imagine such an entity, at least in Germany: the Schufa, a credit rating service. It's impossible to open bank accounts, get credit or phone/internet contracts without all this going into their DB.
Better hope they secure their systems. Credit rating companies are, from their model of business, rotten to the core - and pose an extremely high risk these days where everything is computerized.
Instead of risking their data in the motherlode of hacks occurring against Github they setup on-premise Github/Gitlab/Bitbucket/etc. then let the servers go unpatched, stay several versions behind, don't bother setting up authentication roles properly and give people more access than intended.
There are plenty of places doing on-premise right, but I definitely trust Github over the average undermaintained on-premise installation.
I was about to say "who in their right mind stores PW info in github?" before I realized I've worked several projects that do just that. Crazy decisions, but at least as a small mitigation, all that PW data needs access to a VPC to be useful, and that access isn't part of GitHub. Still not good practice by any means.
Having come up working on classified systems, it pains me greatly to see such lax security.
Plenty of people already fell for the "mirror your dot-files to Github" fad, which dumped vast quantities of exploitable data into public repos. Amazon somewhat mitigated the leaked AWS keys, but who knows how many other passwords, etc. went unfixed?
From a writing point of view, I found it an interesting choice to simply use "author" instead of "Tim Berners-Lee" when attributing the quote in the opening paragraph. Surely dropping TBL by name would give more immediate credibility and encourage the reader to continue.
I fail to see the difference between PII for expensive purchase (NetProspex) and PII for cheap purchase (River City, and whoever else is using the stolen data for gain).
Recognizing that my comment here is unrelated to the central question around whether companies should have this data, the irony for NetPropex (and the hundreds of other companies in the same business) of this kind of data availability is that it results in a lot of cold emails and phone calls that largely go ignored. Thus, as the data has become more widespread, it has become less valuable. Buying a list of people to contact, in my experience, is like throwing money in the trash.
That's usual context where I see it. Often ends up with csv's where you have columns of the data people are interested in and one column containing all the metadata bundled up in JSON as a string.
I've stopped giving my information to entities that don't need it.
I use fake account information where it is legally permissible and the system is requiring some input to proceed.
When I get asked for my phone number, zip code, email address's etc... At checkout in stores, I give a polite "no thank you". Which usually results in a huff and/or an eye roll from the cashier, as if I'm expected to give this info for the privilege of shopping there.
If the information sources dry up or are of sufficiently low quality, the market value is significantly reduced, as would be the incentive to collect and store such information.
There is this big electronics store in NYC - I bought something small (batteries or something) and at the checkout, the cashier refused to bill me, unless I gave my phone number or email. When I asked why he needs that info his answer was "so we can verify when/if you return the product", and he had no answer when I said "that is what the bill is for, isn't it?". Unwilling to hold up the line, I left without purchasing anything.
Point is, no one before me had issues with giving that info, no one bothered to ask. Unless many people start asking questions, nothing will change, and I don't think most people care.
At the high school level, kids should be taught topics like privacy, civil rights etc - that might help at least a bit
I'm living on the road now, and don't have a phone.
I find it fascinating the reactions I get, and the people who refuse to help me with stuff when I say I don't have a phone, or a number I can be reached at.
When push really, really comes to shove, I give them a number from somewhere I lived 10+ years ago.
NerdVittles has info and a place to get you started if you want to get into free DIDs, trunking, gvoice voip stuff, etc. you can get numbers without google for free, you just need to dig a bit and learn some Asterisk or buy an ObiHai if you're lazy.
You can rent a US number on Twilio for $1/month and use the free Twimlets service (https://www.twilio.com/labs/twimlets/voicemail) to have calls go straight to voicemail and email you a link to an mp3 of the voicemail message. This is typically the number I give out to any potentially annoying commercial entities.
Doesn't this defeat the point? Sure, you're not giving your phone number to a random third party, but now you're giving a different ad agency (google) information about who's calling you. That actually sounds worse to me.
Well, that's a lot better than my MO. I typically use (911) 911-9111 as the phone number for random sites. I figure that if you trust your automated system so much that you let it auto-dial without looking, you deserve to get chewed out by your local PD. But I like your idea a lot more and I'll start using that one to save the PD the time. Maybe it'll give people a smile when they finally look at the number and realize it.
I use 555-1212 with the appropriate area code. This used to be directory lookup so I figured I could get some recursion going if they really wanted to contact me so badly.
I had the same experience at Harbor Freight. They needed my zip code in case I needed to make a return. I said "that's what the receipt is for...?" and she persisted so I gave her the zip code for the part of town the store is in.
Zip codes are often associated with social and economic status and Harbor Freight is in a really bad zip code. I wasn't about to tell everyone standing in line that I was getting in my $100k SUV and driving to my $500k home in the suburbs after they hear my zip code (none of that is true but that's what you'd expect from the city I live in compared to the city I was shopping in).
Yup. Expensive zip code means a car with expensive stuff inside of it, and a papers that show a house full of expensive stuff that has no one home right now (because the rich owner is out shopping).
How would you know that this house is not full of family members of the owner?
And has this scenario actually happen to anyone? Because I think burglars have better means to be sure which house and when to rob.
Just get a job as a ticketing agent at the airport, you know when people are going on vacation, you know when they're coming back, and most of them show you a driver's license with their address on it when asked for ID.
Why not just drive out to the expensive zip code, and rob the first house that looks empty? Why rob the guy who just bought a thing at the store you're at? What makes him a better target then his neighbor? Or any random house in the area? Who actually burgles when they know people are home?
Are you really surrounded by thieves and killers, and the only thing keeping you safe is that they don't know that you live in a rich part of town?
They know where the rich part of town is... Right?
> Why not just drive out to the expensive zip code, and rob the first house that looks empty?
Presumably because police presence is less, or at least busy, in the less expensive zip code. There isn't just more crime in less affluent areas, it's rampant!
> Are you really surrounded by thieves and killers, and the only thing keeping you safe is that they don't know that you live in a rich part of town?
According to the news, yes, but even that expensive part of town is just a "you won't believe where" teaser away from being right next to you!
In all seriousness, as rational as you consider yourself, it's still an uphill battle against the signals we are bombarded with telling us about all the crime and suffering around us. Humans are great at finding and internalizing patterns from signals, and the pattern here isn't hard to see; the world is getting scarier and scarier every year. Doesn't matter if its true or not, that's still how it feels.
Pretty far fetched. And he doesn't need your zip code if they are intent on robbing you. I dunno--I shop at Harbor Freight in Hayward all the time and it's never once crossed my mind that anyone there is up to no good, or that anyone but the cashier cares about my zip code. Standard parking lot situational awareness that you'd apply anywhere will keep you from being robbed.
EDIT: I applaud the general paranoia, but I think it's just misplaced. You have more to worry from HF aggregating your P.I. than some guy behind you buying tools for his third job.
To follow this thought, most people know just handful of zip codes (if even their own), so if you drop "94303" in front of me, dollar signs are not going to appear in my eyes because it's Palo Alto, CA (multi-million dollar tiny homes for those not in the Bay Area).
Yes, nowadays people can type that into their phones and find the corresponding neighborhood, but really? Most criminals steal what they can see, not what they think might be there from a zipcode. They're better off just driving to a nice neighborhood and casing the houses whose owners are away.
Of course maybe there are people following you around slowly acquiring your PII so they can steal your identity and drain your 401k.
My first & last name is PII. There is no other person in the US with the same name, and potentially the world. It is handed out everytime I use my credit card.
Escalades are not uncommon in a bad part of town, expensive cars in general are not uncommon. You'll see a Cadillac parked in front of a $35k house, and no one's going to rob them.
You wouldn't walk into a store and shout out how much money you make, would you? Announcing your zip code is effectively the same thing.
Auto loans are at record numbers currently, I know couples who pull down 25k above me and my wife that are "poorer" (renting, saving less) due to auto loans. People are nuts about cars.
People in the US are nuts about spending in general. Wedding rings that cost 6 months salary, cars that cost a few years worth, houses which cost 20 years worth...
Indeed, we bought a home due to the fact that the mortgage was less than rent for a low end apartment. We see it as a way to build net worth and reduce costs, we buy used cars, buy bulk household goods though Amazon. A lot of people have this impression that its impossible to live the life that our parents had today. I'm sure its impossible in the bay area or Manhattan but as a high school drop out who lives in one of the top 100 highest income counties in the US I assure you that a very good standard of living is possible here. The only debt we have is our mortgage.
Not really. Shouting your income bracket would be info in a form everyone is attuned to (dollar amounts), whereas I don't think most people cross reference zip code to avg income on the fly, even if they might roughly know it. Only people sensitive to it might, like real estate brokers and cops. Even if the odd professional criminal might think of this tactic, jacking rich people in the parking lots of hardware stores seems unlikely to be worth the risk.
All of which is to say, I think you're being paranoid and unwarrantedly suspicious of strangers just because you're in the "bad part of town".
In Britain, post codes are much more distinctive and memorable, since they follow a form like "SW7 2DD". The first letters give a city or county, the first number an area within it. The second part a street, business or building.
Most British people would identify that as a London postcode — London is so large, it has several first letter codes.
Most people from London would identify it as a posh area, people familiar with South West London would know it's an extremely posh bit. (It's the Science Museum.)
Outside London and the densest cities it's less accurate, but usually still distinguishes urban and rural areas.
I wouldn't feel unsafe giving my postcode, but they have been used by some street gangs as part of their identity, and therefore define a territory. In cities, the "SW7" bit is usually printed on the street name signs.
True. US gangs totally do the same thing, but more often with phone area codes which are also 3 digits, instead of the more verbose 5 contiguous digit format of zip codes (the US equivalent of a post code). "I'm from the four eight two three four" just doesn't have a great ring to it.
Area codes in graffiti is not a gang thing, it's a graffiti thing. Gangs don't travel (much), they just mark their own territory. No area code necessary.
The $100k Escalade in front of the $35k house is substantially less likely to be robbed than the $100k Escalade in front of the $200k house in the burbs.
You don't have to believe me, look at a crime map or read some statistics.
People who have a decent income and stability aren't likely to be driven to crimes of desperation, such as burglary and robbery (among many others), so even without statistics you can imagine why it would be true.
"Persons in poor households at or below the Federal Poverty Level (FPL) (39.8 per 1,000) had more than double the rate of violent victimization as persons in high-income households (16.9 per 1,000)."
This is why I don't usually withhold such information - I deliberately present invalid (but sane) data. if they care so much about market research, they should be prepared for some dirty data on the way. I value my privacy much higher than their business interests.
I think a lot of people, myself included will just straight up lie, use bullshit accounts, give bullshit zip codes, etc. It's often times easier, gets less looks and gets the job done in a straight up utilitarian sense.
I read about a guy who had a similar experience in (I think) RadioShack many years ago. The cashier asked for his address, and they guy questioned why it was needed, and would they be sending him junk mail? The cashier made an excuse for what it was needed for and said that "no, they wouldn't be using the address to send junk mail to".
The customer wrote on the back of the cheque (I said it was a long time ago) a minimal contract that said something like "By accepting this cheque RadioShack agrees that they won't send any junk mail to the provided address, if any is sent a fee of $100 will be payable" (paraphrasing).
RadioShack ultimately sent the guy junk mail, and the guy asked for his $100 which I think they ultimately gave him.
When asked for such information at checkout, including if I have a <xyz> preferred shopper card, I've found that a quick & polite "no, thank you" is effective.
It's clear to the sales clerk that I just want to be on my way--conveying that I do not wish to share such information, that I don't have a preferred shopper card, and, most importantly, that I don't want to hear their sales pitch.
If required to provide a phone number, I just increment the last digit by 1. I feel for whoever has that number :-).
may or may not know that it is pretty universally applicable as a phone lookup for most rewards cards. Just prefix with a popular area code, e.g. 415 (Bay Area) or 212 (NYC).
Naturally, you won't get any of the rewards, but it does protect your privacy, and with some annoying retailers, still gets you the member discount.
Teaching kids about those things would make them less effective consumers, more effective voters, and much harder for parents to instill a given viewpoint in.
Critical thinking isn't going to take off in a country dominated by people who profit from its absence.
As far as phone numbers go, a number of grocery stores and other chains (e.g. pet stores, etc.) offer discounts if you provide them with one. What I do is give them my google voice number (a service I don't use at all) instead. That way I'm able to recall the number but I'm not exposing anything personal and still reap the benefits of in-store discounts.
I think it probably comes down to them not caring rather than them not catching on. They are just following the prompts that pop up, it's not like they actually care about that info.
> When I get asked for my phone number, zip code, email address's etc... At checkout in stores, I give a polite "no thank you". Which usually results in a huff and/or an eye roll from the cashier, as if I'm expected to give this info for the privilege of shopping there.
For the most part I don't even get the huff and eye roll anymore, they just hit cancel, input the store's postal code or something else and move on.
Though I once had a cashier insist I give her my postal code after giving the polite no, she gave me some "I need it... for the system" or something. When I started giving an obviously fake one, I got the huff and eye roll. I wonder how many people would have caved. Hopefully just a new cashier who didn't know the appropriate thing to do in the case that I didn't want to provide details.
I have found at places where cashiers are aggressive to get info a simple "negative" response shuts them down effectively. "No thanks" is always followed by more attempts. For groceries, I do want the discount so a pseudonym + city park address + state lottery hotline gives them a unique identity for metric analysis while sparing me the marketing harrasment.
I've never had a sale not be processed like that before, but I can see it happening these days. I typically put down 123 Fake St., (911) 911-9111 as the phone number (though now switching to 867-5309 as other commenters pointed out it gets the point across just as well without local PD having to waste time), and I try to inject as much random noise into the race/sex boxes as I can. I have heard that putting down the name of the company as your middle name helps out too, but I have not seen anything happen (maybe it works then). Does anyone else have any other ideas or tips for 'hacking' about in these systems?
Bit of free advice... learn an address and memorize it. Make it unrelated to your real life, and use that. It's easier because when automatic checks (or cashiers) get it, they don't say "Uhhhh... no."
Sure, I can understand that, but my advice is still broadly useful. Increasingly the forms websites use to collect information do a spot-check on the address, or at least the zip code. It helps to have one in mind that you can quickly use, along with some dedicated webmail.
If you also happen to be someone who struggles in the social arena, it's a way to avoid even the most unlikely of conflicts.
> Which usually results in a huff and/or an eye roll from the cashier
Why do so many people online seem to need to demonstrate that they are some how persecuted (even if in the slightest, most inconsequential way) for taking a particular stance on something. It happens in this way so frequently that I honestly don't believe it at all. For years I've been doing exactly what you describe -- saying, "no thank you" to data requests at checkout -- and I've never noticed anyone appear to care in the slightest.
It doesn't make your story more believable or you more sympathetic nor does it make society looks any more crazy. It's just a weird detail that is probably not true and doesn't need to be included.
I will second OP's comment, because this does happen, so maybe ratchet down your rhetoric a bit..
When I politely refuse to give out my personal information when buying things, I regularly (but not always) either get a confused look, an annoyed look, or additional pressure to give the information (i.e. "oh it's just for warranty, everyone gives it")..
Just because you've never had this happen to you doesn't mean it doesn't happen, or that OP is making it up.
By saying it has never happened to me I perhaps communicated incorrectly that I think it never happens. That is certainly not the case. I guess what I take issue with is this idea that it "usually" happens. I do not believe that more often than not a someone in retail or the service industry rolls their eyes at a customer because they don't want to give up their email address. If that is really true then perhaps OP is less polite about his turn down than he says.
I would say that, anecdotally for myself, I get a "bad reaction" more often than "no reaction" when I refuse to give up PII to a cashier, and again speaking only for myself I am always polite about it (because I know they're just following the company policies).
This may be because I know that at least some companies incentivize employees to capture this information, so when you refuse to give it up, they are in fact losing out on some kind of compensation or bonus..
Every time I tried to explain to the lady at the till at Fantastic Sam's that I didn't want to give a phone number, I got a blank look; usually a manager had to come over and help them because they literally had no idea what to do when someone didn't want to give them a phone number just for the privilege of getting their hair cut. At one point I had someone tell me I literally wasn't allowed to get a haircut without providing them with a phone number.
Thankfully, my new barbershop doesn't care in the slightest; they will put me on a chair, cut my hair, and take my money. That's all I've ever wanted out of that particular relationship.
I've never really thought of my phone number as private- they used to be published in phone directories, or via operator assistance. I suppose one may want to have a number, like Google Voice or similar service, that was 'unlisted' and you would only give it to a select group.
The bigger concern for me is companies using the number to track me.
I develop a trick where I would alter one letter in my last name and then keep a track which company got which alteration.
It was funny experiment and I tell you boy Victoria Secret is not in business of selling lingerie - they are in business of selling your data!
My wife wanted me to order something from them about year ago and I used my trick on them too. 3 months later all sort of companies start spamming my mailbox with all kind of stuff including Deer tractors (!!!) When I called to find out where they got my info from, they said they can't tell me because they cannot validate my identity as of if Im exact person who says I am. I even offer to send my ID via fax and eventually show up at their office and I was told "this is not how we work". The only thing they could do for me is to opt me out.
I take some small joy in using the shared 234-567-8901 account at Vons/Safeway, and sometimes even get a gas discount. I've also used my parents' long-disconnected land line number. If you dislike this kind of creepy surveillance, don't just block it -- poison the database.
Awesome advertisement for netprospex, a lot of people would pay a lot of money for that data. I'm sure their phones are ringing off the hook this week. I'm sure this is unintended, but that's the reality as I see it.
Native advertising is very effective. I run a local lifestyle brand as a side project and native advertising is the only type of advertising we have. I even put "Sponsored Content" and "We were invited to eat at this restaurant in exchange for a review" and I've still had people comment that they don't know how we can afford to do all of this stuff and we don't even sell anything or have ads! People don't make the connection between "sponsored content" and "advertising", or catch on to the fact that we get basically all of our stuff for free (at worst) or that we're actually paid to write about it (at best).
But I'm happy because no one visiting my site is getting a virus from shitty third-party ads.
Do you say "in exchange for a review," or "in exchange for a positive review?" There's a reason newspapers' editorial and advertising departments are separate.
My contracts with local businesses do not guarantee a positive review. Usually the agreement is along the lines of "have to write so many words with so many pictures and mention the article on X, Y, and Z social media outlets X number of times over the course of Y many days", but I and my other writers reserve the right to say whatever we want to say in that article.
Obviously it's bad for business to badmouth stuff we got for free, so we're actually pretty picky about what we accept. If I don't like eating at a restaurant, I won't accept free stuff from them on behalf of the business. I've been offered services by a hair salon in town but it doesn't line up with my demographic so I won't accept the contract because I wouldn't want to write about them. I've turned down two offers from the local bowling alley because I'm not going to have much nice to say about it.
But no one is guaranteed to get a good review. I've written some reviews I would describe as "hopeful", in that "I'm hopeful they'll get better soon" mostly with regards to brand new restaurants where the kitchen is still finding its groove. Everything that I write is my opinion and is clearly marked as such, even while it's also marked as something I was given for free in exchange for my honest opinion.
> I've turned down two offers from the local bowling alley because I'm not going to have much nice to say about it.
To maintain your credibility, you should review it pro bono; for bonus points, note that they previously tried to pay you twice. Otherwise it would be honest to clearly disclose that you mostly/only write positive reviews, albeit via selection bias rather than outright lying.
I've written product reviews before, always either for stuff I bought or stuff received via an intermediary (i.e. X sends me Y's thing, I send my review to X). The whole "sponsored content" model makes me long for the days of flashing banner ads.
Oh don't worry I have a whole section linked in the header that lists out our advertising policy so readers can see the same terms I offer to sponsors. It even details my "anti-clickbait" policy where my headlines are guaranteed to be descriptive. I also do a lot that I don't get paid for and is not marked as sponsored content. Again on those I don't go negative, whether I'm being paid or not, whether I've been asked to write something or not. There's just enough negativity in the media that I don't want to contribute to that: what I'm selling is the way I want my city to make people feel. You should be happy to live here, let me show you how that's done. I'd link you to it so you could see all the details but it's personally identifying right down to my first name and the street I live on in my city, so I'm not comfortable linking my HN name with that.
It's funny to me that whenever I mention this side project on HN it always gets a lot of interest from people wondering if I'm being honest to my readers and giving advice of how I can be more honest. Guess it goes to show that there isn't a lot of honesty left in this world.
> There's just enough negativity in the media that I don't want to contribute to that... I'd link you to it so you could see all the details but it's personally identifying
I respect that. But 90% of everything is crap, and this is a forum created to worship shameless hustling. Negative reviews are important.
I believe our current paradigm for how data is stored is fundamentally broken. The author is right that when you choose to use a service you have no real control over how they use your data. Frankly, companies aren't even accountable to uphold their own privacy policies since no one actively monitors them (except perhaps in the context of HIPAA, PCI, etc.)
What I'd love to see is a marketplace of "personal data banks" that would work like this:
- The bank maintains an isolated database of every major database vendor. The databases are isolated to a single consumer.
- The bank exposes API endpoints of every major database to companies like Facebook or new SaaS startups. Those companies now agree -- when requested -- to write your data not to their private database but to the bank's database that is private to you.
- You, the consumer, pay the bank a modest monthly fee to control who can access that data, and even optionally cut off access to the original "generator" of data.
I guess this still suffers from the need to trust that Facebook is abiding by your request that all data be written to the bank, and network latency becomes a real issue. So maybe it's not the right business model, but it's an important problem to solve.
Taking that one step further, maybe if someone wrote that kind of tool, basically an API for your personal data that you can run locally, maybe they could scale it up to what you're describing?
It would require a massive paradigm shift in how the internet works in practice, but image a world where:
1. You sign up for some new social network/thing that requires your data
2. You point it at your own personal (or hosted) info server
3. The service promises/or the use of the personal info server stipulates states that the data should never be stored longer than the lifetime of a relevant transaction
4. The social network queries your data maybe once a day (or more depending on whatever kind of work it does), announces itself, and can be cut off when you want.
Of course, things don't sell these days with just privacy these days, but there's some upside to a service like this ironically due to it's centralization -- you could sell the user on "only enter your address/personal/credit card info once, have it available everywhere with one click, no long login forms"
You're just shifting the trust to the "data bank". What if it gets hacked, or ignores its ToS, or some rogue employee with database access copies your PII, or... ?
Trust is dead; it doesn't scale. End of story. I don't like the idea of a "data bank" or "data brokerage" any more than I like the idea of facebook; either way, someone else holds the keys to my castle. But third-party servers aren't going anywhere, so we have to find a way forward.
I've come to the conclusion that the only possible way for someone (or something) to maintain control over data is to encrypt it at all times when not in use. It's exactly the idea of a "data bank" like you're describing, but you become the bank. One of the key struggles with this approach is that it requires a tremendous amount of client-side code; calling it a paradigm shift is a profound understatement. It doesn't matter how snazzy your encrypted-dist-web product is unless you present a compelling economic reason for companies to switch to it, to justify the extreme expenditure of capital necessitated by the technical switchover.
Even here, though, once you share something with eg. Facebook, you can only hope they don't fuck it up. That's just the way the world (unavoidably) works; once you share something with someone, they have every capability to do whatever they please with it. You have only the social expectation that they don't, and if they violate that expectation, your only recourse is to stop communicating with them. But I do think, in a world where we actually have autonomy over our data (partly, again, because it necessitates client-side code), it is possible to make the consequences of data misuse so disastrous for a company that it stops being economically viable for them to do so.
The key thing we've lost is that agency to make decisions about data. I've no problem with informed, consensual sharing, but in today's world re: data, "informed consent" is nonexistant.
I think I've finally found the source of my constant influx of spam. It won't fix the downstream sources like resellers but at least I can ask Netprospex to remove me. But since they aren't the ones directly spamming me do they have to comply?
I too firmly believe that Privacy should score higher than business interest. If you do not wish to share such information, a polite "NO, Thanks" is much better.
144 comments
[ 4.0 ms ] story [ 202 ms ] threadI'm simply waiting for the day when there will be a hack like this on the European continent, it's scary what sits in lightly protected databases, especially if you consider the probable sources of data like this and that - at least in Europe - it would be illegal to create such a DB without the consent of those whose information is stored in them.
We've lost control is the perfect way to describe things.
I guess the other side of that argument means that mentioning who sells it shouldn't be a problem either.
But you need a consent to collect that data in the first place.
Hah, there's one big assumption you are making there...
The German commissioner for data protection might be interested:
https://www.bfdi.bund.de/DE/Service/Kontakt/kontakt_node.htm...
In case you'd rather not do it through official channels (or in addition, just to keep them on their toes), may I suggest:
https://www.heise.de/tippgeber/
https://securedrop.theguardian.com/
I can imagine such an entity, at least in Germany: the Schufa, a credit rating service. It's impossible to open bank accounts, get credit or phone/internet contracts without all this going into their DB.
Better hope they secure their systems. Credit rating companies are, from their model of business, rotten to the core - and pose an extremely high risk these days where everything is computerized.
Instead of risking their data in the motherlode of hacks occurring against Github they setup on-premise Github/Gitlab/Bitbucket/etc. then let the servers go unpatched, stay several versions behind, don't bother setting up authentication roles properly and give people more access than intended.
There are plenty of places doing on-premise right, but I definitely trust Github over the average undermaintained on-premise installation.
Having come up working on classified systems, it pains me greatly to see such lax security.
http://magarshak.com/blog/?p=169
Wat?
I guess? Maybe the records were exported one at a time and formatted for excel vs in an array for programmatic access
Its not great to work with.
I use fake account information where it is legally permissible and the system is requiring some input to proceed.
When I get asked for my phone number, zip code, email address's etc... At checkout in stores, I give a polite "no thank you". Which usually results in a huff and/or an eye roll from the cashier, as if I'm expected to give this info for the privilege of shopping there.
If the information sources dry up or are of sufficiently low quality, the market value is significantly reduced, as would be the incentive to collect and store such information.
Point is, no one before me had issues with giving that info, no one bothered to ask. Unless many people start asking questions, nothing will change, and I don't think most people care.
At the high school level, kids should be taught topics like privacy, civil rights etc - that might help at least a bit
I find it fascinating the reactions I get, and the people who refuse to help me with stuff when I say I don't have a phone, or a number I can be reached at.
When push really, really comes to shove, I give them a number from somewhere I lived 10+ years ago.
I did the same thing a few years ago, drove from Alaska to Argentina over 2 years.
Best decisions I have ever made.
I'm http://theroadchoseme.com if you're interested in what I'm doing. Here are my thoughts on saving money: http://theroadchoseme.com/work-less-to-live-your-dreams
Good luck!
https://www.troyhunt.com/going-dark-online-privacy-and-anony...
Someone has ALWAYS registered it before me.. I have never had it not in the system..
https://en.m.wikipedia.org/wiki/555_(telephone_number)
Zip codes are often associated with social and economic status and Harbor Freight is in a really bad zip code. I wasn't about to tell everyone standing in line that I was getting in my $100k SUV and driving to my $500k home in the suburbs after they hear my zip code (none of that is true but that's what you'd expect from the city I live in compared to the city I was shopping in).
I consider myself a privacy nut but zip code is not something I care to get bent out of shape over. Give a fake one and move on with your life.
Are you really surrounded by thieves and killers, and the only thing keeping you safe is that they don't know that you live in a rich part of town?
They know where the rich part of town is... Right?
Presumably because police presence is less, or at least busy, in the less expensive zip code. There isn't just more crime in less affluent areas, it's rampant!
> Are you really surrounded by thieves and killers, and the only thing keeping you safe is that they don't know that you live in a rich part of town?
According to the news, yes, but even that expensive part of town is just a "you won't believe where" teaser away from being right next to you!
In all seriousness, as rational as you consider yourself, it's still an uphill battle against the signals we are bombarded with telling us about all the crime and suffering around us. Humans are great at finding and internalizing patterns from signals, and the pattern here isn't hard to see; the world is getting scarier and scarier every year. Doesn't matter if its true or not, that's still how it feels.
EDIT: I applaud the general paranoia, but I think it's just misplaced. You have more to worry from HF aggregating your P.I. than some guy behind you buying tools for his third job.
Yes, nowadays people can type that into their phones and find the corresponding neighborhood, but really? Most criminals steal what they can see, not what they think might be there from a zipcode. They're better off just driving to a nice neighborhood and casing the houses whose owners are away.
Of course maybe there are people following you around slowly acquiring your PII so they can steal your identity and drain your 401k.
Years later I discover to my dismay that I handed out that information voluntary, to my current standards I do consider it PII.
Unless I'm getting trolled, in which case, excellent satire.
You wouldn't walk into a store and shout out how much money you make, would you? Announcing your zip code is effectively the same thing.
All of which is to say, I think you're being paranoid and unwarrantedly suspicious of strangers just because you're in the "bad part of town".
Most British people would identify that as a London postcode — London is so large, it has several first letter codes.
Most people from London would identify it as a posh area, people familiar with South West London would know it's an extremely posh bit. (It's the Science Museum.)
Outside London and the densest cities it's less accurate, but usually still distinguishes urban and rural areas.
Example: https://en.wikipedia.org/wiki/LE_postcode_area
I wouldn't feel unsafe giving my postcode, but they have been used by some street gangs as part of their identity, and therefore define a territory. In cities, the "SW7" bit is usually printed on the street name signs.
But realistically, poorer areas = more crime
I don't believe this for a second.
People who have a decent income and stability aren't likely to be driven to crimes of desperation, such as burglary and robbery (among many others), so even without statistics you can imagine why it would be true.
"Persons in poor households at or below the Federal Poverty Level (FPL) (39.8 per 1,000) had more than double the rate of violent victimization as persons in high-income households (16.9 per 1,000)."
https://webcache.googleusercontent.com/search?q=cache:WrnC-F...
http://www.economist.com/news/science-and-technology/2161330...
This isn't my theory and it isn't new, so I'm not sure why you don't believe it.
[1] https://www.reddit.com/r/itslenny/
The customer wrote on the back of the cheque (I said it was a long time ago) a minimal contract that said something like "By accepting this cheque RadioShack agrees that they won't send any junk mail to the provided address, if any is sent a fee of $100 will be payable" (paraphrasing).
RadioShack ultimately sent the guy junk mail, and the guy asked for his $100 which I think they ultimately gave him.
It's clear to the sales clerk that I just want to be on my way--conveying that I do not wish to share such information, that I don't have a preferred shopper card, and, most importantly, that I don't want to hear their sales pitch.
If required to provide a phone number, I just increment the last digit by 1. I feel for whoever has that number :-).
may or may not know that it is pretty universally applicable as a phone lookup for most rewards cards. Just prefix with a popular area code, e.g. 415 (Bay Area) or 212 (NYC).
Naturally, you won't get any of the rewards, but it does protect your privacy, and with some annoying retailers, still gets you the member discount.
"Thank you for shopping with <store>, Mister Mouse."
Critical thinking isn't going to take off in a country dominated by people who profit from its absence.
I asked if everything was okay and he said he'd never seen so many entries using the same phone number.
Couldn't help but laugh when I realized he had no idea why so many people had used it.
... except you are. It's an identifier that allows separate transactions to be correlated.
I never know whether to be sad or glad cashiers no longer catch on when I give my phone number as "[area code] 555-1212".
For the most part I don't even get the huff and eye roll anymore, they just hit cancel, input the store's postal code or something else and move on.
Though I once had a cashier insist I give her my postal code after giving the polite no, she gave me some "I need it... for the system" or something. When I started giving an obviously fake one, I got the huff and eye roll. I wonder how many people would have caved. Hopefully just a new cashier who didn't know the appropriate thing to do in the case that I didn't want to provide details.
One address, with zip code.
If you also happen to be someone who struggles in the social arena, it's a way to avoid even the most unlikely of conflicts.
Why do so many people online seem to need to demonstrate that they are some how persecuted (even if in the slightest, most inconsequential way) for taking a particular stance on something. It happens in this way so frequently that I honestly don't believe it at all. For years I've been doing exactly what you describe -- saying, "no thank you" to data requests at checkout -- and I've never noticed anyone appear to care in the slightest.
It doesn't make your story more believable or you more sympathetic nor does it make society looks any more crazy. It's just a weird detail that is probably not true and doesn't need to be included.
When I politely refuse to give out my personal information when buying things, I regularly (but not always) either get a confused look, an annoyed look, or additional pressure to give the information (i.e. "oh it's just for warranty, everyone gives it")..
Just because you've never had this happen to you doesn't mean it doesn't happen, or that OP is making it up.
This may be because I know that at least some companies incentivize employees to capture this information, so when you refuse to give it up, they are in fact losing out on some kind of compensation or bonus..
Thankfully, my new barbershop doesn't care in the slightest; they will put me on a chair, cut my hair, and take my money. That's all I've ever wanted out of that particular relationship.
The bigger concern for me is companies using the number to track me.
It was funny experiment and I tell you boy Victoria Secret is not in business of selling lingerie - they are in business of selling your data!
My wife wanted me to order something from them about year ago and I used my trick on them too. 3 months later all sort of companies start spamming my mailbox with all kind of stuff including Deer tractors (!!!) When I called to find out where they got my info from, they said they can't tell me because they cannot validate my identity as of if Im exact person who says I am. I even offer to send my ID via fax and eventually show up at their office and I was told "this is not how we work". The only thing they could do for me is to opt me out.
But I'm happy because no one visiting my site is getting a virus from shitty third-party ads.
Obviously it's bad for business to badmouth stuff we got for free, so we're actually pretty picky about what we accept. If I don't like eating at a restaurant, I won't accept free stuff from them on behalf of the business. I've been offered services by a hair salon in town but it doesn't line up with my demographic so I won't accept the contract because I wouldn't want to write about them. I've turned down two offers from the local bowling alley because I'm not going to have much nice to say about it.
But no one is guaranteed to get a good review. I've written some reviews I would describe as "hopeful", in that "I'm hopeful they'll get better soon" mostly with regards to brand new restaurants where the kitchen is still finding its groove. Everything that I write is my opinion and is clearly marked as such, even while it's also marked as something I was given for free in exchange for my honest opinion.
To maintain your credibility, you should review it pro bono; for bonus points, note that they previously tried to pay you twice. Otherwise it would be honest to clearly disclose that you mostly/only write positive reviews, albeit via selection bias rather than outright lying.
I've written product reviews before, always either for stuff I bought or stuff received via an intermediary (i.e. X sends me Y's thing, I send my review to X). The whole "sponsored content" model makes me long for the days of flashing banner ads.
It's funny to me that whenever I mention this side project on HN it always gets a lot of interest from people wondering if I'm being honest to my readers and giving advice of how I can be more honest. Guess it goes to show that there isn't a lot of honesty left in this world.
I respect that. But 90% of everything is crap, and this is a forum created to worship shameless hustling. Negative reviews are important.
What I'd love to see is a marketplace of "personal data banks" that would work like this:
- The bank maintains an isolated database of every major database vendor. The databases are isolated to a single consumer.
- The bank exposes API endpoints of every major database to companies like Facebook or new SaaS startups. Those companies now agree -- when requested -- to write your data not to their private database but to the bank's database that is private to you.
- You, the consumer, pay the bank a modest monthly fee to control who can access that data, and even optionally cut off access to the original "generator" of data.
I guess this still suffers from the need to trust that Facebook is abiding by your request that all data be written to the bank, and network latency becomes a real issue. So maybe it's not the right business model, but it's an important problem to solve.
It would require a massive paradigm shift in how the internet works in practice, but image a world where:
1. You sign up for some new social network/thing that requires your data
2. You point it at your own personal (or hosted) info server
3. The service promises/or the use of the personal info server stipulates states that the data should never be stored longer than the lifetime of a relevant transaction
4. The social network queries your data maybe once a day (or more depending on whatever kind of work it does), announces itself, and can be cut off when you want.
Of course, things don't sell these days with just privacy these days, but there's some upside to a service like this ironically due to it's centralization -- you could sell the user on "only enter your address/personal/credit card info once, have it available everywhere with one click, no long login forms"
Trust is dead; it doesn't scale. End of story. I don't like the idea of a "data bank" or "data brokerage" any more than I like the idea of facebook; either way, someone else holds the keys to my castle. But third-party servers aren't going anywhere, so we have to find a way forward.
I've come to the conclusion that the only possible way for someone (or something) to maintain control over data is to encrypt it at all times when not in use. It's exactly the idea of a "data bank" like you're describing, but you become the bank. One of the key struggles with this approach is that it requires a tremendous amount of client-side code; calling it a paradigm shift is a profound understatement. It doesn't matter how snazzy your encrypted-dist-web product is unless you present a compelling economic reason for companies to switch to it, to justify the extreme expenditure of capital necessitated by the technical switchover.
Even here, though, once you share something with eg. Facebook, you can only hope they don't fuck it up. That's just the way the world (unavoidably) works; once you share something with someone, they have every capability to do whatever they please with it. You have only the social expectation that they don't, and if they violate that expectation, your only recourse is to stop communicating with them. But I do think, in a world where we actually have autonomy over our data (partly, again, because it necessitates client-side code), it is possible to make the consequences of data misuse so disastrous for a company that it stops being economically viable for them to do so.
The key thing we've lost is that agency to make decisions about data. I've no problem with informed, consensual sharing, but in today's world re: data, "informed consent" is nonexistant.