MERCH!
Giant Bomb - a website about video games and the people that make them

A Violation

by ahoodedfigure

Just a few weeks ago, the address of one of my email accounts was stolen (along with many other peoples' accounts across several different, popular websites. A list and an excellent essay about this event is here ), and I felt a bit violated by that. I'd given the mailing list I had signed up for very little information, so only the email address had been stolen, although if I'd given the compa...

Just a few weeks ago, the address of one of my email accounts was stolen (along with many other peoples' accounts across several different, popular websites. A list and an excellent essay about this event is here), and I felt a bit violated by that. I'd given the mailing list I had signed up for very little information, so only the email address had been stolen, although if I'd given the company more, more would have been taken by the thieves who did it.

It's interesting that in conversations I have with people about taking data off the internet, many people balk at my harsh language for calling the taking of information, which still might exist afterward, as theft. They say if you take a book from a store it's theft, but if you take a copy of a work that's digitally reproduced, theft doesn't quite fit. I know that there are some restrictions for talking about this sort of thing on the forum, but I have this strange, tangled attempt at definition in mind when I think about the recent crisis for the Playstation Network.

It's not just email addresses and unique account names that were stolen, but pretty much everything you could imagine you might give such a company, including, although it's not been confirmed as I type this, credit card numbers.  I thought I had it bad a few weeks ago, but an old email address is nothing compared to this, and anyone who has been affected has my sympathies.

Personal information is often gathered to help a company better market to its customers, and to make sure that their identity isn't stolen, so it makes me wonder if there isn't some other way this information can be stored, distributed over several datastores for example. The email address theft I mention in the top paragraph was from a site external to the companies who use it, called Epsilon, which maintained a database of all their clients' customers, whether or not the customer, say, had stopped subscribing to the email newsletter they'd originally signed up for.  The lesson is, of course, that we are vulnerable every time we send information over the internet, and that includes mere browsing at pages, not to mention sending credit card numbers.

There is no guarantee that what we send won't be intercepted, either in transit or at the source, but it's sobering to see such widespread loss of privacy, and makes me wonder, like the author of the article above, if this sort of breach of security counts as a breach of contract and a violation of trust. We depend upon the companies whom we supply with our personal information to give us some level of security in return, and many of us would rather not have to give them any information at all except we are often asked to give it to get any sort of support. Some games even require full registration to even be able to play them, so we're sort of forced into these situations in order to continue our hobby.

I realize it's in vogue right now to talk about all the wonderful marketing potential, and the national security potential, of all of this data that powerful groups are collecting, but even if every member of those organizations use this information with the utmost responsibility, that doesn't mean that this information can't still be obtained by third parties. Maybe events like these will force us weakling users, and the conglomerates who want our information, to be more cautious, and more discerning. I try not to be cynical after events such as this, but it's difficult not to be.