The Face of One AOL Searcher Exposed
Juha-Matti Laurio writes "No. 4417749 conducted hundreds of searches over a three-month period on topics ranging from "numb fingers" to "60 single men" to "dog that urinates on everything., report NYT journalists Michael Barbaro and Tom Zeller Jr., but with a permission from Mrs. Thelma Arnold, 62. "Those are my searches," she said, after a reporter read part of the list to her, continues the article."
"60 single men"
At her age. I think she should be happy with a couple, but 60... gotta admire her!
User 48956332 Perl For Dummies
User 48956332 HTML 4, whats the big deal
User 48956332 Howto use sandboxen in development
User 48956332 What is CSS
User 48956332 Unit testing
User 48956332 Spelcheking
User 48956332 Why is Digg growing so fast?
Wax-Museum Fire Results In Hundreds Of New Danny DeVito Statues
But at least it looks like my code isn't the only place invaded by quote-abducting aliens.
The creatures outside looked from Alt-Right to Antifa; but already it was impossible to say which was which.
Asked about Ms. Arnold, an AOL spokesman, Andrew Weinstein, reiterated the companys position that the data release was a mistake. We apologize specifically to her, he said. There is not a whole lot we can do.
What a load... there is plenty you can do AOL. You can promise not to release this data again, you can actively hunt for it on the web. You can promise to delete your copy. You can promise that you won't keep data like this anymore. You can implement better security policies so that you know where your data is, and what is hapenning with it. You can limit the people who have access to posting stuff on your website.
Useless bastards!
I guess this just goes to show that you should be using something like Torpark even when merely conducting an online search. It's a shame but if you value your privacy, I guess it's necessary.
Keep those IPs changing so they can't track and accumulate your searches I guess. I don't want a dossier of my searches available to the public.
My work here is dung.
In other words, the journalists tracked down about 20 AOL searchers, but Mrs Arnold was the only one to give permission for the article as hers was the only search term list that didn't include 'midget porn'.
Where am I?
You're on AOL.
What do you want?
Search information.
Whose side are you on?
That would be telling. We want information. Information. Information.
You won't get it.
By hook or by crook, we will.
Who are you?
The new ad-funded AOL Number 2.
Who is Number 1?
You are Number 4417749.
I am not a number -- I am a free gran!
At the end of the article, she says she's cancelling her AOL account as a result.
Correction, she's going to try to cancel her AOL account.
From AOL's public apology
"This was a screw up, and we're angry and upset about it. It was an innocent enough attempt to reach out to the academic community with new research tools, but it was obviously not appropriately vetted..."
This is sounding very much like Dilbert's boss's public apology made years ago:
"It was wrong for us to sell keyboards with no 'Q' We're sorry. We're morons. We're dumber than squirrels. We hear voices and do what they command. I have broccoli in my socks. "
Life is like a web application. Sometime you need cookies just to get by.
4417749 numb fingers
4417749 60 single men
4417749 dog that urinates on everything
4417749 landscapers in Lilburn, Ga
4417749 bill arnold
4417749 carpet shampoo rental
4417749 julie arnold
4417749 stan arnold
4417749 homes sold in shadow lake subdivision gwinnett county georgia
4417749 gwinnet county animal services
4417749 stan arnold
4417749 pecan pie recipes
4417749 McGyver DVDs
4417749 pet euthanasia services
What?
http://www.aolsearchdatabase.com/
I did a search on there this morning, and it displays the SQL statement for me, which is very handy...
Select SQL_CALC_FOUND_ROWS * from search_data WHERE match (anon_id,query,click_url) against ('4417749 ') LIMIT 0,30
Interestingly, if you do the standard SQL injection, searching for something like "4417749') LIMIT 0,30; DROP TABLE SQL_CALC_FOUND_ROWS;--", I bet you will screw it up for them. Kids, don't try this at home. I'd never encourage people to do something illegal!
The point of this posting is:
Learn about SQL Injection, and protect against it.
Don't display your SQL query to your users.
If you don't know what SQL injection is, try a simple example: Search for "1','0" (skip the double quotes, but not the single quotes) and you'll see it in action without causing harm.
After reading through all of the 0+ modded comments, I've seen everyone saying "God, I wish there was something that could be done to stop this from happening again". You want to see it stop? Find something that ties your local congressmen to their search histories on AOL. Contact them with that information. I can almost guarantee you that if you find enough dirt on enough congressmen/senators, you'll see legislation passed requiring that Search companies not keep records of searches. It quickly changes from "Think of the children" to "Think of saving my ass from dirt that can be used against me next election year"
Warning: Corny karma killing post above.
You raise an important and oft-overlooked point.
This is exactly why I think it's so critical to evangelize with regard to using privacy measures. I want my mother, Aunt Sally, and 8-year old neice to be using TrueCrypt and Tor at a minimum (or, something providing similar functionality). Privacy / anonymity suites need to become as commonplace as antivirus, firewall and anti-spam software.
Helping strong privacy measures become the status-quo serves other important goals too. It makes it more politically costly to try to legislate them out of use, and it reduces the usefulness of developing new data mining programs that require person:transaction relationships - both for the government and for private industry.
In short, when everyone's Aunt Sally can be expected to have countermeasures against activity monitoring running on her home PC, the world will have become a safer place for all of us.
Pi Ran Out