Live data from Hacker News

120M American Households Exposed In 'Massive' ConsumerView Database Leak

forbes.com

71–80 of 163 posts

Re: 120M American Households Exposed In 'Massive' ConsumerView Database Leak

#71
> He found the data was sitting in an Amazon Web Services storage "bucket," left open to anyone with an account,

This is hard to believe. S3 bucket names are unique. I can't make a bucket named `bucket`; I'd have to call it `dashkb-bucket` or something (a common convention is to prefix with your company's domain)... anyway...

The point is: for the bucket to be named `bucket` Alteryx must have had one of the very first AWS accounts, and from there isn't it reasonable to assume this bucket has been exposed for many years?

Re: 120M American Households Exposed In 'Massive' ConsumerView Database Leak

#72
post #54

Earlier quoted context omitted.

If it doesn't need to be insured, you could just spin off a smaller entity responsible for holding the data for you, and shut the company down if the data leaks. You can do the same if insurance is required of course, but any brand new 'personal data holding' company would likely have very high insurance premiums to offset the risk.

> If it doesn't need to be insured, you could just spin off a smaller entity responsible for holding the data for you, and shut the company down if the data leaks If this is possible without insurance then it’s possible with, and every insurance company will mandate the structure to limit payouts. Mandating insurance simple entrenches the insurers. Why, for instance, would you want to require Apple purchase insurance…

> If this is possible without insurance then it’s possible with, and every insurance company will mandate the structure to limit payouts.

You can't limit insurance payouts this way, because the entity has to carry the insurance. You only limit the exposure of the larger entity after the assets of the liable entity, including any insurance coverage, are exhausted. But the more the mandatory insurance level is, the less likely spinning off to protect the parent is to ever be valuable, and it never protects the insurer, so they won't mandate it.

Re: 120M American Households Exposed In 'Massive' ConsumerView Database Leak

#73
post #59

Earlier quoted context omitted.

> You do know it is impossible thwart all data breaches right? As RcouF1uZ4gsC's proposal contains measures to be taken when it happens, I strongly suspect that he does, in fact, know that. > Zero-day attacks are still bound to occur... Geniuses are on the offensive side. Most of the breaches have required neither of these. The goal is to improve the practice of security to the point where the only successful attacks…

> I strongly suspect that he does, in fact, know that. His proposals imply that he does not in fact realize that zero-day attacks occur. Negligence is one thing, but having state of the art security systems and still being punished for a breach is another thing. A state sponsored group with enough time and money can repeatedly infiltrate a system. A tax certainly wont solve the problem

I think you're missing the point entirely.

If your business is such that a tax penalty on a breach would make you no longer able to afford to do business, then you have two options: 1) don't store the data in the first place - your risk no goes to 0 2) scrap your business plan as the cost of holding the data given the impossibility of preventing every breach is greater than the economic value it would generate

Today you don't have to really think about what the cost of losing the data is because your portion of it is 0. That's stupid. It's like every startup deciding to include a new type of coffee machine that includes a small nuclear reactor - sure, we can't prevent all possible disaster scenarios, but the marketing people and data people REALLY LIKE having this type of coffee available, and the government isn't giving us any reason NOT to have it, so why not?!

So if a tax either makes you put money aside to account for the risk, or shuts down a bunch of frivolous examples of personal data collection, it's solved a huge part of the problem.

Re: 120M American Households Exposed In 'Massive' ConsumerView Database Leak

#74

Personal data right now is considered an asset. It needs to be seen as a liability. Maybe the solution is a data tax. You pay a set amount every year for every piece of personal data you have. If you buy personal data from another company, you still have to pay the tax for the data you acquired. If you have a breach of data, your tax goes up for a period of 10 years. In addition, every piece of personal data needs to…

Personal data is already a liability in the medical space. How’s HIPAA made that any different? Are those databases breached just as often, but of little interest?

A relative of mine works in IT for a non-US hospital. (Avoiding naming it because of backlash potential, both for him and myself.)

When he started there, as bottom level IT support, he had access to everything. Admin passwords, doctor's passwords, he could write prescriptions and put a doctor's name on it. He could order anything and everything, and send it anywhere. He could read your medical files, if you were a patient there at any time. There were no restrictions, only some logging.

The place is only >>this weekI don't know what it's like in the US, but where he is there should be regular audits and criminal negligence charges for this kind of thing.

Re: 120M American Households Exposed In 'Massive' ConsumerView Database Leak

#75
post #30

Personal data right now is considered an asset. It needs to be seen as a liability. Maybe the solution is a data tax. You pay a set amount every year for every piece of personal data you have. If you buy personal data from another company, you still have to pay the tax for the data you acquired. If you have a breach of data, your tax goes up for a period of 10 years. In addition, every piece of personal data needs to…

> Maybe the solution is a data tax Credit reporting and debt is a dumpster fire that needs to be rebuilt from scratch. We need a new system where knowing the right pieces of information does not allow you to buy a car in someone else's name.

> We need a new system where knowing the right pieces of information does not allow you to buy a car in someone else's name.

Identity is information. Ownership as a coherent social process is contingent on shared information.

Re: 120M American Households Exposed In 'Massive' ConsumerView Database Leak

#76

Personal data right now is considered an asset. It needs to be seen as a liability. Maybe the solution is a data tax. You pay a set amount every year for every piece of personal data you have. If you buy personal data from another company, you still have to pay the tax for the data you acquired. If you have a breach of data, your tax goes up for a period of 10 years. In addition, every piece of personal data needs to…

Keeping personal data is fine. The issue is that everyone involved with handling the data has a cavalier attitude. They just shrug when it is leaked because it is no skin of their back.

The solution: lawsuits. The laws need to be relaxed where if a company leaks data, we are entitled to damages. Just like if someone assaults you on the street you are entitled to damages.

The most famous case is McDonald's. When their hot coffee scalded a woman, she was awarded damages. Suddenly, everyone food serving establishment too care to make sure the temperature was right, printed warning labels, and told customers to be careful...it's hot.

Pretty sure if some of these companies get stiffed with huge fines, everyone will take notice and clean up their act.

Re: 120M American Households Exposed In 'Massive' ConsumerView Database Leak

#77

Apparently anyone who wants this data can simply purchase it from Experian. The leak doesn't change anything except the price.

Back in the day (20 years ago) you could buy a CD with everyone's name, address, phone number and so on..

Re: 120M American Households Exposed In 'Massive' ConsumerView Database Leak

#78

Personal data right now is considered an asset. It needs to be seen as a liability. Maybe the solution is a data tax. You pay a set amount every year for every piece of personal data you have. If you buy personal data from another company, you still have to pay the tax for the data you acquired. If you have a breach of data, your tax goes up for a period of 10 years. In addition, every piece of personal data needs to…

Troy Hunt just published and article today (Dec 19th) titled "Fixing Data Breaches Part 2: Data Ownership & Minimisation" , which discusses this exact topic [1]. The entire post is worth a read, but he offers an excellent summary:

> Summary This whole post is about giving control of data back to the rightful owners and minimising the impact on them when a breach occurs. This is equal parts a fundamentally simple objective to achieve and one that is enormously difficult. It's simple not to request that someone provides their date of birth to a cat forum; neither the site nor the user themselves lose anything by not collecting this data. Yet it remains a difficult objective because not only do so many services continue to view our data as an asset, they never expect to be the victim of a data breach which then turns that data into a liability.

[1] https://www.troyhunt.com/fixing-data-breaches-part-2-data-ow...

Re: 120M American Households Exposed In 'Massive' ConsumerView Database Leak

#79
post #74

Earlier quoted context omitted.

Personal data is already a liability in the medical space. How’s HIPAA made that any different? Are those databases breached just as often, but of little interest?

A relative of mine works in IT for a non-US hospital. (Avoiding naming it because of backlash potential, both for him and myself.) When he started there, as bottom level IT support, he had access to everything. Admin passwords, doctor's passwords, he could write prescriptions and put a doctor's name on it. He could order anything and everything, and send it anywhere. He could read your medical files, if you were a pa…

For the first 100 years, we just arrested folks who actually faked records or stole things. Now we do it if they don't make it impossible?

I know, networks change everything. But inside a secure facility its often (always) the case that personal integrity (and maybe some audits) is used to ensure correctness most of the time.

Somebody working in a hospital could steal prescriptions off of patient's tables, could lift wallets and purses, heck could even take a knife and attack people. But instead of hobbling everybody and locking everything up, we instead trust folks. And take action when somebody un-trustworthy violates that.

Re: 120M American Households Exposed In 'Massive' ConsumerView Database Leak

#80

Earlier quoted context omitted.

How would we go about making the data worthless?

As others have said on other comments on this article, everyone has to stop using that data ( all of it) for purposes of verifying that you are who you claim to be. My initial thought was "good luck with that", but maybe, in an ironic sort of way, these breaches are going to force that to happen. "You say someone opened a credit card in my name, and you want me to pay for what they charged? What data did they use to…

It would be nice if they always had to show a chain of evidence that clearly shows what data they got where with what authorization.
Post reply on HN