Automated updates: 2022-08-21

This commit is contained in:
John Colagioia 2022-08-21 07:02:25 -04:00
parent b6a7b55215
commit b071e8e868
2 changed files with 78 additions and 1 deletions

View File

@ -12,7 +12,7 @@ proofed: true
This week, our [Free Culture Book Club]({% post_url 2020-05-02-freeculture %}) plays **Starborn**.
![The cover for the game](/blog/assets/starborn-cover.png "")
![The cover for the game](/blog/assets/starborn-cover.png "This cover would have flopped on the shelves, but for modern interactive fiction, it seems decent enough.")
To give this series some sense of organization, here are some basic facts without much in the way of context.

77
2022-08-21-records-2.md Normal file
View File

@ -0,0 +1,77 @@
---
layout: post
title: Public Records, Privacy, People-Search Antics, One Year Later
date: 2022-08-21 07:01:03-0400
categories:
tags: [privacy]
summary: My experiences digging through public records websites
thumbnail: /blog/assets/computer-work-light-abstract-people-woman-819322-pxhere.com.png
update: [
'2021-08-01-records.md'
]
offset: -14%
proofed: true
---
A little over a year ago, started the process of [removing information from people-search sites]({% post_url 2021-08-01-records %}).
![A photograph of a man taking a picture of a woman taking a picture of something](/blog/assets/computer-work-light-abstract-people-woman-819322-pxhere.com.png "Spoiler: The real stalker rides overhead in his invisible airship.")
As promised then, I have posted monthly updates about my experiences in keeping up with this in the [**Entropy Arbitrage** newsletter](https://www.buymeacoffee.com/jcolag/posts), and---OK, not *quite* as promised, since I "called my shot" for July instead of August---this post follows up on that post.
## Summary of Experiences
If you've followed [the **Entropy Arbitrage** newsletter](https://www.buymeacoffee.com/jcolag), then you probably know that I followed the process of searching for my private data online a total of thirteen times---fourteen including yesterday, specifically to confirm that things haven't suddenly changed and time the process---and requested removal of anything that I considered too accurate or too precise.
{% pull a much more exciting life than I actually lead %}
I make the distinction of precision and accuracy, because I opted to leave bogus information behind. If you search for me, you'll find me living in multiple states, sometimes in office buildings, varying in age from my thirties to nearly eighty, and possibly maintaining multiple secret identities. I figure that this buys me some time, if valid information shows up. If a new address shows up, it *might* have some use, or it might come from yet more garbage. If an address vanishes, the site *might* have done so at my request, or maybe because they discovered a problem. Plus, it helps me imagine a much more exciting life than I actually lead.
**Note**: I have the luxury of acting cavalier about this bogus data, because it all falls into categories that I can identify as either benign or clear computer error. If you can't identify the source of something, then you should investigate it as possible identity theft, since that does happen.
## New Information and Analysis
That said, a year later, the process looks slightly different from how it worked previously.
{% pull from multiple hours to about twenty minutes|left %}
Primarily, and probably most heartening, once I grew accustomed to the process and the results, the time required to take care of this dropped from multiple hours to about twenty minutes. Some sites still waste time on lengthy interstitial animations about how secretive and sleazy you should see their work, but I also see far fewer of them than existed last year. But beyond that, the web browser already had the URLs in the history, and I had less thinking and analysis to do.
Also, many sites have finally put obstacles in the way of searches. Several major search-sites now require a state to narrow down the search, for example, meaning that someone who moves across state lines has turned one search into fifty. A couple of sites took down their public-facing search entirely.
Other issues, however, persist.
For example, almost every site wants to look as salacious as possible. They make a point of telling you that they plan to search criminal records and dating sites, especially. One goes so far as to claim that their results will probably include nudity. Several also make you agree to Terms of Service demanding that you refuse to use the provided information for illegal reasons, a rather explicit hint that the site exists primarily to *enable* those uses: "I can't stop you if you do, but try not to fire someone based on their address or family."
Also, every site *desperately* wants to keep our data available. The entire business model involves teasing scandalous results for every search, to maximize the chances that searches will result in the sale of a full profile. I can't describe it in any way other than [extortion](https://en.wikipedia.org/wiki/Extortion), honestly.
Because of the extortion motivation, they vary the removal process, but always making sure to have us waste time. At one end, you have sites that require at least one [CAPTCHA](https://en.wikipedia.org/wiki/CAPTCHA) to submit your request for removal, then confirming your e-mail address for them. At the other end, *Social Catfish* in particular demands that you prove that you have a right to privacy, verify the correctness of the information that you want removed (thus making it more valuable), and...I actually don't know what comes next, because I filed complaints about them and threatened to sue, at that point.
## Ongoing Plan
As mentioned, I have now gone through this process once per month for fourteen months. In that time, I've learned that data seems to propagate when significant life events occur to leak or expose data to these companies. Otherwise, though, not much seems to change significantly.
For example, when a family member moved, the various sites began to associate me with their old apartment. I would bet that most of the correct information about me got its last significant update when I bought my last car, though I haven't tested that theory.
Based on this theory, because I have the "cushion" of [chaff](https://en.wikipedia.org/wiki/Chaff_%28countermeasure%29) information to waste the time of anybody searching for me, and because my threat model doesn't suggest any immediate concerns, that suggests how to handle this going forward:
* I'll still make routine searches on (probably) a quarterly basis. I can afford to waste half an hour of a Saturday, every three months, just in case I have a broken model of how this works.
* For any significant life-event requiring paperwork that might come up, I'll drop back to monthly for a while, to track that spread.
* Maybe annually, I should search for new articles on this topic, to compare their list of sites with mine.
* When I contact my elected representatives---I've unfortunately slacked off on that---make sure to mention the danger that these sites pose, and point to the California privacy regulations that we need to build on.
The first two *should* get me what I want. The third should make sure that my process doesn't get too far out of step with the threat. And the final item might make the rest of this work obsolete, if handled correctly.
## Final Thoughts
Following up on that last bullet point, I said last year:
> Nobody should be using your home address as a “teaser” to sell subscriptions. You shouldnt be responsible for finding each of those companies, hoping that they abide by current privacy laws, and jump through the hoops that they put in place to request removal, while worrying that the request doesnt convince them that youre more valuable. Your local government shouldnt be helping them, by providing information on everybody in the area to anyone who files a request. This business model simply shouldnt exist...
These sites put people in danger. Politicians and journalists routinely get death threats. Domestic abusers often outright stalk their victims. Anybody voicing progressive opinions online will receive some harassment. We shouldn't have businesses that *profit* from that danger, because they will find ways to amplify it, in the name of profits.
Until then, however, we need to put the work in individually, to protect ourselves.
* * *
**Credits**: The header image is [untitled](https://pxhere.com/en/photo/819322) by an uncredited PxHere photographer, released under the terms of the [Creative Commons CC0 1.0 Universal Public Domain Dedication](https://creativecommons.org/publicdomain/zero/1.0/).