Slashdot Mirror


EFF Files Complaint with FTC Over AOL Data Leak

Quincy A. writes "Last week's exposure of search data on over 500,000 AOL users was a gigantic embarrassment for the company. It may be about to get worse, as the EFF has filed a complaint with the FTC over the incident. 'Citing AOL's own Network Privacy Policy, the EFF says that the company failed to "implement reasonable and appropriate measures to protect personal consumer information from public disclosure."' Among other things, the complaint asks AOL to notify all users affected by the data disclosure via certified mail and provide free credit monitoring for a year."

12 of 114 comments (clear)

  1. While I am surprised the EFF took the case by umm+qasr · · Score: 4, Interesting

    I'm happy that AOL will be help *somewhat* accountable.

    1. Re:While I am surprised the EFF took the case by deviantphil · · Score: 4, Insightful

      The accountability they take in the future might be less than inspiring. From the article:

      It is certain that AOL will vigorously contest the EFF's complaint, with the linchpin of its defense being that the whole thing was a horrible idea from AOL's new research unit that will never be repeated. Unfortunately, horrible ideas can have real-world ramifications, and even though AOL is "deeply sorry" and swears it will never happen again, there need to be some safeguards in place to prevent a recurrence.

      I wonder what would happen to a murder defendant that tried to use that defense. "I'm sorry your Honor....my left hand pulled the trigger without my permission. It won't happen again! I promise!

      Bottom line, respondeat superior says it is their unit, their employees, THE COMPANY is responsible.

  2. Why do they even have this stuff? by Skadet · · Score: 4, Insightful
    Among the list of remedies proposed by the EFF include [...] hav[ing] the FTC bar [AOL] from storing users' search activities "except where necessary... to the rendition of AOL's services or the protection of AOL rights and property." At most, AOL should only be allowed to keep 14 days' worth of data, argues the EFF.
    Why do they keep such logs, anyway? If it's to help tailor results better, or to help sell advertising, then why is it correlated with a user ID? My company, for example, saves a keyword search history, but there is no user-identfiable information correlated with it. And it's plenty of information for our needs.

    If nothing else, it's a terrible, terrible reminder that no matter where you are, no matter what you're searching for, someone could be watching.

    1. Re:Why do they even have this stuff? by pclminion · · Score: 5, Interesting

      Why do they keep such logs, anyway? If it's to help tailor results better, or to help sell advertising, then why is it correlated with a user ID? My company, for example, saves a keyword search history, but there is no user-identfiable information correlated with it. And it's plenty of information for our needs.

      First, the search database doesn't list AOL user IDs. It lists "unique IDs" for each user, but they are not correlated to whatever AOL's internal "User ID" is. But to assume that sanitizing the data by changing or completely removing user IDs will make people safe is boneheaded.

      Let's start with a grep for social security numbers. I've blipped out the actual numbers themselves, but that's not much help for these poor folks, since anybody can get their hands on the database:

      • find robert williams akron oh 44306 XXX-XX-XXXX
      • birth certificate for debra ann collins 1-28-59 ss XXX-XX-XXXX
      • locate keith ivan thompson born 3 may 64 social security XXX-XX-XXXX last address was XXXXXX colorado
      • kristy nicole vega hammond la. social secruity number XXX-XX-XXXX birth date 03 08 81 drivers license number la. XXXXXXXXX address XXXXXXXX.

      Moving on, check out this fascinating query:

      • all i can say is you looked amazing in that photo. i would love to get achanceto know you. expect a call from me soon. are you looking for a friend or a companian just for future reference

      Looks like somebody accidentally copy-pasted a portion of their private communication (email or IM, perhaps) into the search query box and clicked "Submit." Now their private thoughts are available for all to see. You'd be AMAZED at the stuff you'll find in these logs. The idea that by removing usernames/IDs from data is "instant sanitization" is naive and dangerous. There is more than enough information in many of these queries to identify specific individuals and examine EVERYTHING they have searched for in the past 6 months.

      (I do question the sanity and intelligence of some of the people who submitted queries like the ones above, but ultimately this is not their fault.)

  3. I've been meaning to make a donation. by Anonymous Coward · · Score: 5, Informative

    While I'm demonstrating my support, I thought I'd suggest some of you do the same.

    Have you shown your support? EFF

  4. Donate to these people by MobyDisk · · Score: 4, Insightful


    The EFF is the "stop 1984 from happening" fund. If you read Slashdot, you know why you should be a member.
    </soapbox>

    1. Re:Donate to these people by avalys · · Score: 4, Insightful

      Don't forget the ACLU.

      Electronic freedom is nice, but freedom in the real world is all that matters in the end.

      --
      This space intentionally left blank.
    2. Re:Donate to these people by eipgam · · Score: 4, Insightful
    3. Re:Donate to these people by Just+Some+Guy · · Score: 4, Insightful

      And while we're at it, the NRA (for that amendment the ACLU forgot about).

      --
      Dewey, what part of this looks like authorities should be involved?
  5. Re:So EFF stands for the free exchange of informat by Recovering+Hater · · Score: 4, Informative

    No, troll. From their main page : "What is EFF? EFF is a nonprofit group of passionate people -- lawyers, technologists, volunteers, and visionaries -- working to protect your digital rights.

    --
    My humor is probably your flamebait
  6. Re:So EFF stands for the free exchange of informat by megaditto · · Score: 4, Insightful

    The Government and the Corporations do not have a Constitutional right to privacy.

    Hence all consumer (people) data must be treated as private by default, whereas the Government data must be treated as inherently public.

    The EFF opposes the recent drive to turn this principle inside-out.

    --
    Obama likes poor people so much, he wants to make more of them.
  7. Relief doesn't match mistake by dysk · · Score: 4, Informative

    Yes, AOL made a mistake by releasing that information. They've admitted to the mistake, apologized, and I doubt anyone will try to do this again.

    On the other hand, one needs to recognize that they didn't release the information for the purposes of making money, or defrauding the customers, or anything else. They collected the data in order to help a researcher write an extremely informative paper[pdf] about human behavior as it relates to searches. That researcher decided that other's might benefit from the information, and convinced AOL to make it publically available. It turns out that that was a huge lapse in judgement, but nonetheless, intentions are also important and while criticizing AOL, we should also complement them for their effort to interface with the academic community.

    AOL has been punished enough in the press. Given the circumstances I don't think that any legal action is necessary.