zlacker

[return to "Hack Club: A story in three acts (a.k.a., the shit sandwich)"]
1. blende+Sb[view] [source] 2025-11-13 13:01:00
>>alexkr+(OP)
Wow! Just wow! Just as I think the situation cannot get any worse, the OP reveals even worse things going on. I know the UX of this blog and the lack of capitalization is going to turn many people off! But I urge you to power through and read the whole OP anyway.

Use reader mode, block Javascript or whatever it takes. Give the author a break. They're a teenager. What kind of websites were you making as a teenager? I'm sure one of those dark background websites with MARQUEEs and BLINKs with glaring contrast colors! So give them a break. Behind the annoying UX is an article about serious and appalling privacy and security issues.

Like read this:

> i raised this with chris, who's a full-time staff member (not a teenager), and he insisted that exposing physical addresses and sensitive info was "just a vuln" not a breach. said he's "never heard the term 'data breach' used that way" and... also relied on chatgpt instead of actual legal advice.

Actually this Chris guy has a point. I don't call it breach either. It's PII data exposure but it is a serious exposure. So I don't 100% agree with the OP but the cavalier attitude towards security coming from the staff of a legitimate organization is appalling.

It's just mind boggling that an organization handling PII data has such appalling privacy and security lapses and they still remain arrogantly indignant about it making bold claims about laws they don't understand, why, because ChatGPT told them so? Cherry on top is they are employing teenagers to answer legal questions! Not kidding! Just read the OP! Unbelievable!

◧◩
2. hrimfa+1D[view] [source] 2025-11-13 15:33:09
>>blende+Sb
> Actually this Chris guy has a point. I don't call it breach either. It's PII data exposure but it is a serious exposure.

At least California defines it as

> unencrypted personal information, as defined, was acquired, or reasonably believed to have been acquired, by an unauthorized person.

https://oag.ca.gov/privacy/databreach/reporting

◧◩◪
3. bo1024+qu1[view] [source] 2025-11-13 19:28:00
>>hrimfa+1D
So I guess if you authorize the entire world to read the data, it’s not a breach.
◧◩◪◨
4. SigmaE+E42[view] [source] 2025-11-13 22:41:54
>>bo1024+qu1
If nobody reads the data it is not a breach.
[go to top]