Live data from Hacker News

Patient details of 'any Australian' for sale on darknet

theguardian.com

51–58 of 58 posts

Re: Patient details of 'any Australian' for sale on darknet

#51
My bet is it is a compromised client certificate from a doctor or hospital.

The authorities will query the audit logs to determine who accessed the journalists record and revoke the cert.

The log will show the other leaked records, which the authorities will report to the victims.

The investigation into how those records were leaked will land several people in jail, as it is easily traceable to the credential.

Bad idea, darknet vendor! Selling data this traceable is sure to get you v&

Re: Patient details of 'any Australian' for sale on darknet

#52

On a related note, I've recently had two UK banks request more personal documents from me, and a video, for anti-fraud or anti-laundering, blah, blah reasons. When, not if, they get hacked, the intruders will have even greater ability to abuse my identity. Data protection acts are barking up the wrong tree - what we need are data limitation acts to require corporations to store as little data as possible.

If they get hacked next time they'll ask you even more info.

Re: Patient details of 'any Australian' for sale on darknet

#54
post #40

Earlier quoted context omitted.

They tried blaming it on that, but it was just incompetence. They didn't even buy DDoS protection services. There's more details on the inside story of the Census here: https://risky.biz/censusfailupdate/

"DDoS protection services" are a racket. Build the thing right and you don't want or need them.

You haven't worked in a govt department have you. In one meeting the BA Ministry lead fell asleep and actually started snoring. In another, the ministry infrastructure architect said, "oh, that thing, I've lost the word, what is it?" - "a server?".

As an ex antipodean govt contractor, I'm not even kidding. Many other stories of complete fuckwits who had no right to touch a keyboard, never mind run things. My conclusion was anyone with any smarts was completely bamboozled by the abject incompetence and left to the private sector, leaving behind the above characters. Unbelievable, but true. Saying that, don't believe me, get a job there and I see for yourself :)

Re: Patient details of 'any Australian' for sale on darknet

#55

My bet is it is a compromised client certificate from a doctor or hospital. The authorities will query the audit logs to determine who accessed the journalists record and revoke the cert. The log will show the other leaked records, which the authorities will report to the victims. The investigation into how those records were leaked will land several people in jail, as it is easily traceable to the credential. Bad id…

You are implying that they have such logs. I'm fairly sure you will find they do not.

Re: Patient details of 'any Australian' for sale on darknet

#56
post #40

Earlier quoted context omitted.

"DDoS protection services" are a racket. Build the thing right and you don't want or need them.

You haven't worked in a govt department have you. In one meeting the BA Ministry lead fell asleep and actually started snoring. In another, the ministry infrastructure architect said, "oh, that thing, I've lost the word, what is it?" - "a server?". As an ex antipodean govt contractor, I'm not even kidding. Many other stories of complete fuckwits who had no right to touch a keyboard, never mind run things. My conclusi…

Requiring them to buy DDoS protection would be part of the problem, not the solution.

Re: Patient details of 'any Australian' for sale on darknet

#57
post #38

Earlier quoted context omitted.

Privacy has never been a priority for the Australian government - its citizens simply don't have the right. So there really shouldn't be much surprise over this. More importantly is that this story should educate Australians as to just how much their government values their privacy - sure, this will be hailed as a reason for even more political oversight over technological processes, but only for as long as there isn…

Australia has much stricter privacy laws than many countries, and has had them for a relatively long time (starting in 1988 and updated since). The privacy laws apply to government agencies and any non-government organisation with > $3m in turnover. https://www.oaic.gov.au/privacy-law/privacy-act/australian-p...

Cool. All I need to get around this is a (Until its in a Bill of Rights, its not protected. Also: see the Australian Constitution - not worth the paper its printed on)

Re: Patient details of 'any Australian' for sale on darknet

#58
post #57

Earlier quoted context omitted.

Australia has much stricter privacy laws than many countries, and has had them for a relatively long time (starting in 1988 and updated since). The privacy laws apply to government agencies and any non-government organisation with > $3m in turnover. https://www.oaic.gov.au/privacy-law/privacy-act/australian-p...

Cool. All I need to get around this is a (Until its in a Bill of Rights, its not protected. Also: see the Australian Constitution - not worth the paper its printed on)

You might wish to consult a lawyer about your theories.

In general, the legal opinions of non-lawyers are not worth the paper they're printed on.

Post reply on HN