« Misogynistic sphaghetti western song... | Orphan Works Initial Comments » |
Redaction gone bad...
privacyCrap. I'm getting tired of this... First, a laptop was stolen that had a sizeable chunk of the personal information covering Berkeley graduate students, including mine. Now, the Library of Congress has posted my information on a publicly available website... and the information of anyone else who submitted an orphan works comment via email.
A little help here?
UPDATE [2005-04-01 13:25:38]: So I've finally heard from the LoC and they've recognized that this vulnerability affects ALL the comments posted on the Orphan Works site and they're currently working on a fix:
Dear Mr. Hall: [...]
Thank you for pointing out the vulnerability of the format in which the orphan works comments have been made available. Since you expressed a concern about your contact information directly to us yesterday via the "orphanworks@loc.gov" email address, we temporarily removed your comment as a precaution. We hope to have your comment re-posted shortly.
As for the rest of the comments, we are aware of the same vulnerability and we are currently working on a solution that should solve this problem.
Thanks for your interest in the orphan works study.
Matt Skelton
Matthew Skelton
U.S. Copyright Office
Office of Policy & International Affairs
Library of Congress
101 Independence Ave., SE
Washington, D.C. 20559
UPDATE [2005-04-01 17:39:37]: The comments on the Orphan Works site now appear to be properly redacted (I haven't checked the contents of the current ZIP file).
...
I suppose I'll have to call the LoC in the morning. Read on for the email I just sent the LoC:
You have managed to post hundreds of comment documents that have been improperly redacted!!!
My personal information - and it appears the personal information of all of us who submitted comments to the LoC's notice of inquiry on orphaned works[1] via email - is now publicly posted on your website.
For background, see this (I am the Joe Hall that the author, Matthew, refers to):
WYSINWYG or Improper Redaction Techniques http://faktory.org/m/blog/archives/2005/03/30/improper-redaction-techniques/
I would appreciate knowing how you intend to remedy this situation. Taking down the files seems like a wise first step. In the long run, you should NOT INCLUDE personal information in files! Simply highlighting over redacted content will not remove that content from the document and it is easily available to anyone!
Joseph Lorenzo Hall
[1]: http://www.copyright.gov/orphan/comments/index.html
While writing abstracts of the comments to the USCO, I noticed that the comment of Craig Froehle still contains contact info. (I saw the info in a flash before white got rendered over it.) I haven't checked any other files.
BTW, the font size of this comment box is incredibly tiny.