Earlier quoted context omitted.
How do you distinguish someone who was lax with their security from someone who actually takes it seriously and still got hacked?
You can't :) There is a huge Market for Lemons ( https://en.wikipedia.org/wiki/The_Market_for_Lemons ) style scenario in IT systems with relation to security. Everyone will say "we take security seriously", but there's no way for ordinary consumers (or indeed most companies) to determine what the company meant by their statement, and to evaluate the relative security of the systems of two companies. This could actual…
Gigabytes of user data from hack of Patreon donations site dumped online
91–100 of 151 posts
Re: Gigabytes of user data from hack of Patreon donations site dumped online
#92Re: Gigabytes of user data from hack of Patreon donations site dumped online
#93That's pretty devastating to anybody who gave up their data to support things they enjoy. I would really like to see services getting hit with massive fines so they actually "take security very seriously" before they get owned. It's far too late to care about it now, there's a lot of compromising data in that leak.
I'm not sure how compromising the data is... if you're referring to the display of what people support, that's public information. For instance here's my user profile. https://www.patreon.com/user?u=632496&pat=1 you can find it with one targeted google search
Re: Gigabytes of user data from hack of Patreon donations site dumped online
#94All the data breaches lately have demonstrated the need for some kind of professional engineering license to ensure compliance with best practices. Even if your app is meaningless in and of itself, a data breach can reveal Personally Identifying Information or credentials for other sites and accounts. There's too much of a "code cowboy" mentality out there right now. As a community we've become very feature-driven an…
Re: Gigabytes of user data from hack of Patreon donations site dumped online
#95Apparently they were compromised via a publicly exposed Werkzeug debugger: http://labs.detectify.com/post/130332638391/how-patreon-got-...
Re: Gigabytes of user data from hack of Patreon donations site dumped online
#96It seems that when Subbable was acquired by Patreon, they got the user information, and possibly password database, too. I can't log in to Patreon with my Subbable password, but my email address is definitely in the breach.
Makes me glad I use a password manager.
It's also a sobering reminder of the permanence of user data. You have to trust the competence of not only the service you use now, but any company that owns that service down the road. (Not that Subbable was necessarily more secure than Patreon.)
Re: Gigabytes of user data from hack of Patreon donations site dumped online
#97Apparently they were compromised via a publicly exposed Werkzeug debugger: http://labs.detectify.com/post/130332638391/how-patreon-got-...
There's almost no hack needed here, as the article says, they basically opened up remote code execution to anyone. That's shockingly bad.
Re: Gigabytes of user data from hack of Patreon donations site dumped online
#98Earlier quoted context omitted.
I don't think they're particularly informed if they aren't aware of password managers.
I'm aware, I just can't be bothered. Every time I create an account I ask myself "do I care if this gets compromised?". If the answer is no, then it gets a standard password.
Re: Gigabytes of user data from hack of Patreon donations site dumped online
#99All the data breaches lately have demonstrated the need for some kind of professional engineering license to ensure compliance with best practices. Even if your app is meaningless in and of itself, a data breach can reveal Personally Identifying Information or credentials for other sites and accounts. There's too much of a "code cowboy" mentality out there right now. As a community we've become very feature-driven an…
If we are going to put collective political effort into stemming the tide of data leaks and hacks, I would much rather put it into finding and punishing the people who steal the data than the people who are trying to create a productive service and get hacked through less than perfect security.
As Schneier puts it - security is a process. The process doesn't have to be perfect, but there needs to be one. If your process is drastically substandard, someone need to be liable for that. The need for a standards group and a single point of liability follow logically from that, just as it does with other engineered systems. Under HIPAA an individual must be designated a "security officer", and that role should extend to other systems that store Personally Identifying Information as well.
I think the real point of disagreement with many people is about the significance of a data breach. In my opinion (and the standards of the EU) anything that leaks Personally Identifying Information is significant. It doesn't matter if it's leaking from an app that sends fart noises to your friends, only that it can be tied to you or your other accounts. If you really need to be storing PII then there needs to be a requirement to do it securely (meaning in accordance with secure best-practices). Otherwise, again, nobody does it until it's too late.
A good read: https://www.schneier.com/essays/archives/2000/04/the_process...
Re: Gigabytes of user data from hack of Patreon donations site dumped online
#100Believe it or not, this re-inforces my commitment to SoundCloud, which isn't monetized (yet), thereby keeping listeners' financial information off the table for the present.