Hacker News new | ask | show | jobs
by necovek 520 days ago
I believe you should work to limit exposure of sensitive information like SSN: while it's ok to allow search by an exact SSN, you should probably not display it unless the requestor already knows what it is.

OTOH, if you have really succesfully worked to make this database public domain and do publish it somewhere (and you did, as I can see at https://archive.org/details/BIRLS_database), this wouldn't be of much help against any malicious actors out there.

But really, it seems the burden is on VA if there are non-deceased persons in the database since they have done a bad job of maintaining the data, and they would be liable for any leakage of information (unless Reclaim the Records was aware of any in particular). Even so, RTR might have put themselves out on the fence for some lawsuits against them too.

1 comments

The VA worked to confirm that everyone in this dataset is deceased, in order to satisfy the judge’s order, and produced an internal document about how they did it — which we then FOIAed and posted online too. (It’s up on the site, next to the legal paperwork.) The veterans and their SSNs are believed to have been deceased prior to mid-2020, checked by the VA’s internal datasets as well as public data sets such as the SSDMF. And SSNs of deceased people are *not private*, since they are never reused. The Social Security Administration also makes copies of all deceased peoples’ original SS-5 applications available to the public under FOIA.
Have you ever worried about your impact on veterans? Maybe not a concern?
The veterans in the data set are all deceased, and I have not heard any complaints from them so far.
The VA who you sued does serve vets with whatever money they dont spend fighting you.
The VA is obligated to follow the law as it relates to open records. Broadly speaking, America actively chooses to treat vets poorly. Call your Congressional rep (who directly controls policy that controls funding) versus taking your feelings out on your fellow citizen working for little or no pay to encourage government accountability as it relates to their legal obligations.
So you would prefer I sue the VA?! They tried to preserve my families' privacy and reduce risk to current heirs like me. No, doxxing the dead cause "letter of the law matters" for some stupid side project like this is far from commendable. I will bet those of us with a lot of family in there, especially recently deceased, will feel very different than you or the CEO of doxx the dead.