If the 1-day live site is real then it is completely unacceptable. It may be fine to show John from Waikato, or Tim from Auckland, but I suspect there is not more than one Kanwalpreet in Upper Hutt. That person has purchased something and had that information broadcast to the world, which, and I write without even looking at it, is clearly in breach of the privacy act.
-

Kiwis – Get $50 of free Electricity! from FlowerPower at Powershop. Sign up
Selected Companies
Recent Comments
Ricki Kingi on BurgerFuel: value or not? Dave on BNZ Sucks: Verified by Visa… don on If nobody owns your mortgage n… warwick on Who is the biggest bookstore o… Mary on Your time is nigh Ticketek. Re… Mike on Well done NZX diana on If nobody owns your mortgage n… bossalphamonkey on MiniMonos is closing; MinoMons… Jim on MiniMonos is closing; MinoMons… 
Jason Kemp (@dialogC… on Integrity: What to do if your… -
Recent Posts
- Investing on the dot – Syft
- Well done NZX
- MiniMonos is closing; MinoMonsters is hiring.
- Integrity: What to do if your academic paper is challenged
- Electrickery – 10 alternative suggestions for changing NZ’s electricity industry
- New Zealand’s tourists are very very happy
- Can we replace the Tiwai smelter with a data center?
- Let’s stop hurting our container opening dock and warehouse workers
- Stand firm Meridian on Tiwai – we can all win here
- Novopay is Not Found
Top Posts
- If nobody owns your mortgage note then you are in luck
- How to have a US iTunes account on your iPad, iPhone, Apple TV
- Comparing New Zealand to The United States.
- About Lance
- Free Rice: Addictive, but is it a scam?
- Investing on the dot - Syft
- Portfolio
- MiniMonos is closing; MinoMonsters is hiring.
- Contact Lance
- Domain squatting is an asshat thing to do
Tweets
- @dylanbland it’s a personal bugbear as well. My take is not popular - put the price up a lot. Legit users don’t mind paying. @jordantcarter – 14 hours ago
- @jordantcarter sounds like you need a personal trainer. Or an alarm clock app. – 16 hours ago
- @fastchicken do you hook your NAS to the airport, or connect directly? @nikz – 16 hours ago
- @stevenljoyce Aha. Hadn’t linked them together. Those reports are excellent. mbie.govt.nz/what-we-do/bus… – 16 hours ago
- @stevenljoyce Is there an updated version of the Economic Development Action Plan showing progress (with numbers)?: stevenjoyce.co.nz/economic_devel… – 19 hours ago
- @alistairnz It is - next week. I’m pre-positioning the bike in Nelson as I have to be in Dunedin and Auckland Tue and Wed. – 19 hours ago
- @juhasaarinen Sea, forest and grass and sun. Fantastic riding conditions… – 19 hours ago
- Tomorrow I motorcycle to Wellington. I wonder what the weather will be like? http://t.co/Aot1HBYpWi – 19 hours ago
- Pretty exciting to see Pre-registrations arrive for Punakaiki Fund. Here: punakaikifund.co.nz – 22 hours ago
- @rowsell @nzkoz the defining difference is size. Cult small, religion huge. So religion. – 23 hours ago
Top Clicks
History
Subscribe to RSS
Disclaimer
These opinions are my own, and not that of any of my current or former clients.









Hi there,
We proved that the site is real by using the published information to track down and talk to one of the users.
Read more about it here: http://techliberty.org.nz/1-day-finds-that-anonymity-is-hard/
I couldn’t agree more. It is a huge privacy issue especially for those of us with unique (foreign) names. I purchase from 1-day regularly and hey, try googling my name. Off to the PCO we go…
Pretty simple fix – 1-day can simply make it “opt-in”, or even “opt-out” would be better than nothing.
[ ] No I do not wish 1-day to include me in its live map
I suspect the majority of people won’t be too bothered by the fact that they may or may not appear on a real-time map for a few seconds.
What is the point of this?
Privacy isn’t the only issue here, there are serious security considerations.
If someone can get your name and town, they can probably get your street address and phone number from the white pages. This information, plus the information on what you bought and when, provides a lot of ammunition for someone trying to scam via social engineering. Imagine if someone called you on the phone, and they knew what you bought, when you bought it, and the address it was being shipped to. You might be smart enough to question their enquiry, but a lot of people wouldn’t be.
Hiya,
I guess the concept (or idea) is social proof, or some “techy” got a hold of a new idea and said- this is “cool” – wheater it serves a purpose or not!
Paul
Chris – the outcome you describe is one of the key reasons why privacy is protected by law. I.e. breach of personal privacy can have a negative effect on personal security.
1-Day claim to have added an alias feature. http://www.nbr.co.nz/article/shopping-site-tweaks-privacy-busting-feature-133397
However, 1-Day support are unaware of such a thing and just suggested using your first initial instead.
The site continues to post live customer data to the website.
They walk a fine line at 1-day. I bought something on impulse for a friend. Turned out the friend had bought it too so I tried to sell it on Trade Me. Trade Me said it violated copyright law and I wasn’t allowed to sell it through their site!
I’ve also bought an ‘air gun’ through 1-day only to later find out that actual ‘air guns’ require a permit by law. It turned out that what I bought wasn’t an air gun at all, despite being advertised as such on 1-day. I emailed 1-day and they said something along the lines of ‘No we checked with a police supervisor who said we could sell them.’ When I said that contradicted what I read on the police.govt.nz website, they actually said ‘Let’s just agree to leave it there’ and didn’t respond again. Not good.
How daft of 1-day. Why can’t they do it like BookDepository does their ‘watch people’ shop function:
http://www.bookdepository.co.uk/live
eg. ‘Someone in X has bought X’
And if you are screenshotting this and reposting this person’s purchase, then you too are violating the privacy act by publishing it. Although it would have been more in line with your point if you had redacted or altered the personal information first, you could argue that this guy’s info was already in the public domain so it wasn’t private anymore.
I bet Kanwalpreet is happy he didn’t by that male enhancement device instead.
Yes – it was already in the public domain.