/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

As companies comply with privacy laws like GDPR and CCPA, many have insecure practices for giving users their data and some outsource user identity verification

but it could let snoops & hackers see it too. Researchers have proved they can use access rights to get other people's files & @jeanqasaur had her Spotify data downloaded by a miscreant: https://www.nytimes.com/... Gus Hurwitz / @gushurwitz : Yep. And anyone who didn't see this coming shouldn't be in the business of writing laws. https://twitter.com/... Thomas Brewster / @iblametom : I hope someone downloads my Spotify data and gives me some kudos for my listening habits https://twitter.com/... Debra J. Farber / @privacyguru : Yep, GDPR's data subject access requests (DSAR) also created this new attack vector. New data rights become company obligations with new risks and technical challenges. https://twitter.com/... Lynne d Johnson / @lynneluvah : With privacy regs like #CCPA and #GDPR, accessing your data means giving up more personal info. But it's a necessary safeguard, as researchers have proven that hackers (or possibly even—god forbid—friends) could request your data. https://www.nytimes.com/... via @shareaholic @nytimesbusiness : To get access to your secret data file, you may have to give up more personal data https://www.nytimes.com/... Joseph Cox / @josephfcox : People moaning about having to verify their identity in order to download their wealth of data from a company is epitome of threat modelling. What, you want any rando to be able to do it? https://twitter.com/... David Carroll / @profcarroll : When I tried to encourage other US voters to request their Cambridge Analytica data using UK law similar to the #CCPA most people balked at the requirement to provide identity verification information. #DataRights https://www.nytimes.com/... via @kashhill Kashmir Hill / @kashhill : Many people seeking their secret score files have emailed me upset about the info the cos want in exchange for their files. Like forcing them to “look happy” in a selfie. There's a reason! The companies don't want creepers to get your file. https://www.nytimes.com/... https://twitter.com/...

New York Times Kashmir Hill

Context & Ripple Effects

After the post-Cambridge Analytica collapse in trust over personal data, regulators handed users a legal right to their own files — GDPR's data subject access requests and CCPA equivalents — and companies built pipelines to comply. This reporting shows the pipes leak: researchers demonstrated attackers can abuse those same access rights to pull down other people's user files, and Jean Qasaur's Spotify data was downloaded by a stranger through exactly this route.

The irony is structural rather than incidental: the law mandates fast, low-friction data handover, while verifying who is actually asking was left as an afterthought — with many firms outsourcing identity checks entirely.

First-order effects

  • Companies fulfilling GDPR and CCPA requests — Spotify among them, per the Qasaur incident — now face documented cases where an impostor's request yields another person's private files, forcing immediate rework of request-handling and identity verification.
  • The outsourced identity-verification vendors these firms rely on become a named point of failure: whoever verifies the requester effectively controls access to everyone's data.

Second-order effects

  • Compliance teams will have to trade away some of the mandated speed and low friction — adding verification steps that slow legitimate DSAR fulfillment and raise per-request costs across every covered company.
  • Vendors selling identity-proofing for data-subject requests gain a compliance-driven market, while firms that can't verify cheaply may consolidate customer data behind fewer, better-defended custodians — the direction argued in [[a:929312|proposals for a central custodian such as Apple holding personal data under GDPR-style rules]].

Third-order effects

  • If abuse of access rights keeps surfacing, privacy statutes will likely be amended to mandate requester verification — shifting the regulatory design question from 'how fast must data be returned' to 'who may ask,' a tension running through the broader wave of 50+ countries moving to control digital data.
  • The episode reframes data rights as a security boundary: every new statutory right to obtain data expands the attack surface, meaning future privacy legislation will be written with adversaries, not just consumers, as the model requester.

The trend: Privacy laws that grant individuals rights over their data are colliding with security reality, forcing a redesign of identity verification wherever regulated data handover meets an unverified requester.

Discussion

  • @kashhill Kashmir Hill on x
    California's new privacy law lets you see & delete your data—but it could let snoops & hackers see it too. Researchers have proved they can use access rights to get other people's files & @jeanqasaur had her Spotify data downloaded by a miscreant: https://www.nytimes.com/...
  • @gushurwitz Gus Hurwitz on x
    Yep. And anyone who didn't see this coming shouldn't be in the business of writing laws. https://twitter.com/...
  • @iblametom Thomas Brewster on x
    I hope someone downloads my Spotify data and gives me some kudos for my listening habits https://twitter.com/...
  • @privacyguru Debra J. Farber on x
    Yep, GDPR's data subject access requests (DSAR) also created this new attack vector. New data rights become company obligations with new risks and technical challenges. https://twitter.com/...
  • @lynneluvah Lynne d Johnson on x
    With privacy regs like #CCPA and #GDPR, accessing your data means giving up more personal info. But it's a necessary safeguard, as researchers have proven that hackers (or possibly even—god forbid—friends) could request your data. https://www.nytimes.com/... via @shareaholic
  • @nytimesbusiness @nytimesbusiness on x
    To get access to your secret data file, you may have to give up more personal data https://www.nytimes.com/...
  • @josephfcox Joseph Cox on x
    People moaning about having to verify their identity in order to download their wealth of data from a company is epitome of threat modelling. What, you want any rando to be able to do it? https://twitter.com/...
  • @profcarroll David Carroll on x
    When I tried to encourage other US voters to request their Cambridge Analytica data using UK law similar to the #CCPA most people balked at the requirement to provide identity verification information. #DataRights https://www.nytimes.com/... via @kashhill
  • @kashhill Kashmir Hill on x
    Many people seeking their secret score files have emailed me upset about the info the cos want in exchange for their files. Like forcing them to “look happy” in a selfie. There's a reason! The companies don't want creepers to get your file. https://www.nytimes.com/... https://twi…