Slashdot Log In
The Face of One AOL Searcher Exposed
Posted by
CmdrTaco
on Wed Aug 09, 2006 07:26 AM
from the knew-it-wouldn't-take-long dept.
from the knew-it-wouldn't-take-long dept.
Juha-Matti Laurio writes "No. 4417749 conducted hundreds of searches over a three-month period on topics ranging from "numb fingers" to "60 single men" to "dog that urinates on everything., report NYT journalists Michael Barbaro and Tom Zeller Jr., but with a permission from Mrs. Thelma Arnold, 62. "Those are my searches," she said, after a reporter read part of the list to her, continues the article."
This discussion has been archived.
No new comments can be posted.
The Face of One AOL Searcher Exposed
|
Log In/Create an Account
| Top
| 315 comments
(Spill at 50!) | Index Only
| Search Discussion
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
What a ho (Score:5, Funny)
At her age. I think she should be happy with a couple, but 60... gotta admire her!
SQL injection target? (Score:5, Informative)
http://www.aolsearchdatabase.com/ [aolsearchdatabase.com]
I did a search on there this morning, and it displays the SQL statement for me, which is very handy...
Select SQL_CALC_FOUND_ROWS * from search_data WHERE match (anon_id,query,click_url) against ('4417749 ') LIMIT 0,30
Interestingly, if you do the standard SQL injection, searching for something like "4417749') LIMIT 0,30; DROP TABLE SQL_CALC_FOUND_ROWS;--", I bet you will screw it up for them. Kids, don't try this at home. I'd never encourage people to do something illegal!
The point of this posting is:
Learn about SQL Injection, and protect against it.
Don't display your SQL query to your users.
If you don't know what SQL injection is, try a simple example: Search for "1','0" (skip the double quotes, but not the single quotes) and you'll see it in action without causing harm.
Hmm (Score:5, Funny)
(http://slashdot.org/ | Last Journal: Monday March 05 2007, @10:11AM)
User 48956332 HTML 4, whats the big deal
User 48956332 Howto use sandboxen in development
User 48956332 What is CSS
User 48956332 Unit testing
User 48956332 Spelcheking
User 48956332 Why is Digg growing so fast?
Re:Hmm (Score:5, Funny)
User 48956332 Preventing Dupes.
User 48956332 Preventing Dupes.
User 48956332 Preventing Dupes.
Re:Hmm (Score:5, Funny)
(http://www.kiobi.com/)
Note the timestamps of the last two lines, sounds like he had, well, an evening that did not go as planned
Search string (Score:5, Funny)
But at least it looks like my code isn't the only place invaded by quote-abducting aliens.
Nothing we can do! (Score:5, Insightful)
What a load... there is plenty you can do AOL. You can promise not to release this data again, you can actively hunt for it on the web. You can promise to delete your copy. You can promise that you won't keep data like this anymore. You can implement better security policies so that you know where your data is, and what is hapenning with it. You can limit the people who have access to posting stuff on your website.
Useless bastards!
Re:Nothing we can do! (Score:5, Insightful)
(http://robvincent.net/ | Last Journal: Tuesday October 09, @01:55PM)
Re:Nothing we can do! (Score:5, Insightful)
(http://robots.org.uk/)
Re:Nothing we can do! (Score:5, Insightful)
(http://slashdot.org/)
The data is out there, what exactly could they do? Erase it from peoples hard drives, remove it from all the pipes that its in, drug everyone who has seen it?
The fact they have this data is one thing, releasing it to the public is another.
When it is data that they *care* about, corporations seem able to do plenty. If it's their source code, the code to decss, TimeWarnerAol's labels' mp3 files, the latest incriminating memos/emails ... they are positively rabid about protecting it. Cease and desist orders fall like rain, sites get shut down, people get sued for millions and prosecuted to the fullest extent of the law. But if it's their customers' data, like these searches, their email addresses, their credit card numbers, etc. They just shrug and say "Oh well. What canya do?"
It's typical, frustrating, and complete bullshit. If the privacy laws were enforced and these corporations were punished for such egregious mishandling of our data maybe then they might think they can do something. But unless it directly affects them, they just are not going to care and will continue to take no precautions.
Re:Nothing we can do! (Score:4, Funny)
(http://brett.jungblut.net/)
Tubes, my friend. Tubes.
Re:Nothing we can do! (Score:5, Insightful)
(Last Journal: Wednesday December 07 2005, @07:15PM)
Re:Nothing we can do! (Score:5, Insightful)
(http://conceptjunkie.blogspot.com/ | Last Journal: Monday August 25 2003, @10:22PM)
"Not keeping data like this" doesn't make any sense at all and doesn't accomplish any good for customers. Indeed there is great value in understanding what searches are made and how the search process can be improved. Keeping this kind of data secure is sufficient in my mind. The last two sentences are something I would agree with.
I just have to wonder who would be stupid enough to not realize the ramifications of doing this. It doesn't take "thorough vetting" to figure out that this would cause a firestorm of bad publicity.
Of course, the real lesson here is: Don't do anything on the Internet you wouldn't want your mother to find out about. There is no anonymity on the Web. It doesn't take a stupid decision by a large company to prove this.
Torpark (Score:5, Informative)
(http://slashdot.org/~eldavojohn/ | Last Journal: Tuesday October 16, @03:26PM)
Keep those IPs changing so they can't track and accumulate your searches I guess. I don't want a dossier of my searches available to the public.
Re:Torpark (Score:5, Insightful)
(http://www.nexusuk.org/)
Whilest protecting your privacy does, on the surface, seem like a good thing, I wonder if it might count against you if you were ever suspected of a crime. We've already seen 'he has some encrypted data' used as evidence (even though the contents of the encrypted file weren't known) in one successful conviction, I suspect 'he's using privacy protection software called Tor' may go down the same way.
Remember, only people who have something to hide care about protecting their privacy.
Privacy as evidence of nefarious character (Score:5, Insightful)
(http://tooi.org/ | Last Journal: Monday July 24 2006, @08:50AM)
This is exactly why I think it's so critical to evangelize with regard to using privacy measures. I want my mother, Aunt Sally, and 8-year old neice to be using TrueCrypt and Tor at a minimum (or, something providing similar functionality). Privacy / anonymity suites need to become as commonplace as antivirus, firewall and anti-spam software.
Helping strong privacy measures become the status-quo serves other important goals too. It makes it more politically costly to try to legislate them out of use, and it reduces the usefulness of developing new data mining programs that require person:transaction relationships - both for the government and for private industry.
In short, when everyone's Aunt Sally can be expected to have countermeasures against activity monitoring running on her home PC, the world will have become a safer place for all of us.
Re:Torpark (Score:5, Insightful)
A customer of AOL searching through AOL has their searches linked to you as an individual. If you search through google then they get your IP address, and your ISP knows which IP address links to which individual at any one time (open Wifi networks aside). But at least the same company doesnt know both.
The data AOL released was the equivalent of any other search engine releasing its searches with IP addresses, so the same damage could be done by any other search engines logs, but imagine how much a marketing company would pay for that info from AOL with the personal details for each user included (i.e. Age, Sex, location etc.).
Re:Torpark (Score:4, Insightful)
(http://www.traxel.com/)
Your ISP has access to everything you do online unless you're using an encrypted channel like SSL. Your HTTP requests go through your ISPs routers, which see all. Not just search terms, everything. Cox will see this submission when I send it through, and has seen each preview. Cox sees every email I send, including the full content and any attachments. Some ISPs may not be recording it, but for AOL a big part of their business is selling aggregated data to advertisers, and enterprise grade storage costs a few dollars a gig. They'd be stupid to throw away HTTP requests, and I'd lay 20 to 1 odds that they are not. At least until we have laws that require them to. But then, I think we're more like to have laws that require them to keep the data. The EU already does.
Everything you do online is watched. It's just a question of whether you can trust your ISP. We currently lack any serious accountability for privacy breaches. The public is blissfully ignorant, and the government, far from promoting privacy, actually wants the data. In fact, depending on how far you think Epic/Carnivore/TIA goes, they already have it. Your phone records are protected by federal law, and they have those. What of data that isn't protected? Do you think they don't have it?
1 down, 24.9999 million to go... (Score:5, Insightful)
(http://covertcreations.com/)
Re:1 down, 24.9999 million to go... (Score:5, Insightful)
That is sad. "Funny" sure. But "Insightful?"
Here's the person's searches in question:
17556639 how to kill your wife
17556639 how to kill your wife
17556639 wife killer
17556639 how to kill a wife
17556639 poop
17556639 dead people
17556639 pictures of dead people
17556639 killed people
17556639 dead pictures
17556639 dead pictures
17556639 dead pictures
17556639 murder photo
17556639 steak and cheese
17556639 photo of death
17556639 photo of death
17556639 death
17556639 dead people photos
17556639 photo of dead people
17556639 www.murderdpeople.com
17556639 decapatated photos
17556639 decapatated photos
17556639 car crashes3
17556639 car crashes3
17556639 car crash photo
If you want this person investigated, you are worse than the "thought police." First off, it's clear (to me, at least) that this guy isn't thinking about killing anyone. He just wants to see some gory photos. "steakandcheese" is a site like rotten.com. Even if he is thinking about killing someone, that's OK. There's a comment further down on the site you linked to that I find to be "insightful" about an old twilight zone episode. The main character could read minds and he reads the mind of a bank security guard who is thinking about robbing the bank! He has the man investigated, but nothing comes out of it. In the end, the guard admits he was thinking about robbing the bank... in fact he's thought about it almost every day. It's just a fantasy he has to make the day go faster... not something he'd ever act on.
And having been a regular visitor to rotten.com in the past myself, I know that just wanting to see some of the reality of death that we tend to keep hidden in American society is not a crime. It's not even thinking of a crime. It's perfectly natural and healthy curiosity. Neither is daydreaming about terrible things you would never do -- or want to have happen -- in real life. Fantasy is normal and healthy.
In fact, if you've never been to rotten.com or a similar site, I'd recommend you go sometime.
Re:1 down, 24.9999 million to go... (Score:4, Insightful)
(http://www.spamgourmet.com/)
Hello, I'm user 17556639, and I'm a crime novelist.
Actually, I'm not but it is simply not up to AOL or the government or anybody to snoop into my business without probable cause. And probable cause is limited to the government, the rest stay the fuck out of my business.
Anything taken out of context can look completely different, and it simply is NOT the duty of a citizen to chronically prove their innocence.
A) Its sometimes impossible to prove that I was home alone asleep.
B) I'm innocent until proven guilty. Even after being charged and possibly jailed until my court time.
So, yes, I'm one of those "Fuck the children" people. I'm one of those people that respects my privacy. I'm one of those people that believes in free speech. Yes, I vote libertarian too.
but with permission... (Score:5, Funny)
In other words, the journalists tracked down about 20 AOL searchers, but Mrs Arnold was the only one to give permission for the article as hers was the only search term list that didn't include 'midget porn'.
Re:but with permission... (Score:4, Funny)
(http://www.uio.no/~jaris)
Who uses AOL? (Score:3, Funny)
(http://andrewman327.stumbleupon.com/ | Last Journal: Wednesday August 09 2006, @02:31PM)
I don't know how the NYT reporters were able to track her down. After all, this describes most AOL users!
Legal Standing? (Score:3, Interesting)
(http://www.infinitystyles.com/)
Now what kind of legal recourse can people expect from these search results? Can the man who searched for ways to kill his wife be tracked down? How about all of the paedophiles who searched for child pr0n? Oh, I can just see all of the "Come on AOL, think of the children...tell us who that was..." How closely tied are these numbers to the user's AOL Accounts, I mean, I'm sure AOL left themselves some tie to the user in their copy. What's stopping feds from making many major busts on people?
AOL - "Bypassing the 5th Amendment for You!" (Score:3, Interesting)
AOL has went one step further and given their customer's information to the world. I googled the news to see if this story is being reported in the mainstream media, and it is minimally (minimal b/c of TimeWarner?) but I have to laugh as it is characterized as a "goof" and a "gaffe". Laughably understated and nice words for something that at best can be described as sheer bumbling negligence and at worst as a breach of privacy of the worst sort.
Even more ironic, the first news story to pop up on google has nothing to do with this but is:
"AOL offers free security software"
http://www.vnunet.com/vnunet/news/2161980/aol-off
Quick! (Score:4, Funny)
"Officer, those searches can't be mine, I'm not an 18 year old lesbian movie actress!"
She should stay at AOL (Score:4, Funny)
(http://slashdot.org/)
She shouldn't. There's absolutely no way AOL will ever do anything like that again. On the other hand, if she switches to another online provider, who still hasn't been burned, it's a quite a bit more likely they'll screw up like this as well. She'd be "safer" staying at AOL.
Re:She should stay at AOL (Score:5, Funny)
At the end of the article, she says she's cancelling her AOL account as a result.
Correction, she's going to try to cancel her AOL account.
Oblig. Prisoner (Score:5, Funny)
(http://ettlz.blogspot.com/ | Last Journal: Sunday February 12 2006, @06:53PM)
You're on AOL.
What do you want?
Search information.
Whose side are you on?
That would be telling. We want information. Information. Information.
You won't get it.
By hook or by crook, we will.
Who are you?
The new ad-funded AOL Number 2.
Who is Number 1?
You are Number 4417749.
I am not a number -- I am a free gran!
Technology in the NY Times (Score:5, Interesting)
(http://www.mobydisk.com/)
won't hurt yahoo (Score:3, Funny)
21528558 http com yahoo com wont hurt wont yahoo 2006-04-21 15:31:20
I'm amazed by the masses of stupid search strings that are given, why are so many search strings complete (or non working) http adresses? (e.g. www.yahoo.com) Seems like a lousy database to me anyway.
AOL's apology vs. Dilbert's boss (Score:5, Funny)
(http://khendron.com/)
"This was a screw up, and we're angry and upset about it. It was an innocent enough attempt to reach out to the academic community with new research tools, but it was obviously not appropriately vetted..."
This is sounding very much like Dilbert's boss's public apology made years ago:
"It was wrong for us to sell keyboards with no 'Q' We're sorry. We're morons. We're dumber than squirrels. We hear voices and do what they command. I have broccoli in my socks. "
user 4417749's Search Records (Score:5, Funny)
4417749 60 single men
4417749 dog that urinates on everything
4417749 landscapers in Lilburn, Ga
4417749 bill arnold
4417749 carpet shampoo rental
4417749 julie arnold
4417749 stan arnold
4417749 homes sold in shadow lake subdivision gwinnett county georgia
4417749 gwinnet county animal services
4417749 stan arnold
4417749 pecan pie recipes
4417749 McGyver DVDs
4417749 pet euthanasia services
The most importane part of TFA (Score:3, Interesting)
Now, what can we do?
How about making sure "this conversation" happens, and continues to happen.
And not just here on /.
How to achieve change (Score:4, Interesting)
(http://www.infinitystyles.com/)
This is beyond 1984 / Reality of danger, promise (Score:3, Interesting)
(http://telebody.com | Last Journal: Tuesday July 30 2002, @07:28AM)
This is very scary data, though also chock full of interesting info, interesting taken in many different ways. It was easy to find a number of people referencing my small home town of about 20,000 people. I shiver to imagine say a wife using AOL at home and her geek husband searching this stuff at work (not my problem).
Suffice it to say, the data is FULL of personally identifying information. AOL is not telling the truth. Heck, Google even gives you an address if you give it a phone number, people are used to typing people's names into the search box. And if you search for a given ID you can follow their trains of thought over time and it can be shattering; everyone looks for their own family online.. I even found an unknown relative that way once. AOL should hire some clueful people and get them into the loop, but it's too late for some people.
Incidentally, I found one of the most interesting words is "should". That, and "cocktail dresses" but I'm not going to get into that one. You see it turns out that not only do people sometimes unintentionally paste info from mail or webpages into the search field, they also ask questions that normally they might just write on paper and throw in the trash, or give up worrying about. So what AOL has done is closer to taping a confessional, what someone might ask of God or their doctor, or just worry endlessly about, and release it! What infants! It seems to say something about why doctors and priests have a professional code and know how to keep things private. Here are some search phrases, I'm not putting any in that have a person's name but you can probably get the idea from this.
what the fuck should i name my fetus
my nose is bleeding from cocaine what should i do
baby has something stuck in his foot what should i do
my mom is a hooker what should i do
how to tell a wife her husband is having an affair with you
caught my wife cheating
my wife cheated on me with a guy with a huge cock now what
spy on the wife
get revenge from a wife cheater
catch your wife having an affair
my cheating wife
got caught cheating on my wife and now she trying to take my kids away
my wife and kids are living with an ex con
very sexy baby nice pics i wanna c more lol u should take a look at my pic s tell me what ya think if u wanna chat my yahoo is lets get it mane and my aim is mhsplaya8
should a spouse stay married to a sex addict
should i let my son inlaw fuck me
i should have used a condom
dude read this its reallllly weird body hi. my name is kimi. it's too late now. you shouldn't have opened this bulletin but since you did you will die tonight if you dont keep reading. well i'm 19. i don't have eye lashes and i dont have a nose. pr
what should i do about heart palpitations after smoking crack
should a man go to a strip club the girlfriend is upset
should i see a married man
should i tell the other man's wife
should i confront my wife's adultery partner
mom showed me how to masterbate
why my girlfriend should give me head
should i buy extended warranty on my laptop
an employee jokes all day long what should i do
should parents let their children become stars
l want some pill to dead
l want to kill myself pill sleep
i want to kill myself
should i kill myself
i need someone to help me before i kill myself
help no one loves me i want to kill myself
best way to kill myself
i want to kill myself indiana hotline
god please my heart hurts help
l need to talk with a fbi
should informants be identified
Now maybe people will understand what AOL has done.
I am posting this because: