And, they made fun of RMS... He was telling you what the future holds. This is just a trailer of what is to come.
Information wants to be free. That includes information you don't want to be free.
Marketing Firm Exactis Leaked a Personal Info Database with 340M Records
101–110 of 307 posts
Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records
#102Earlier quoted context omitted.
> what's the alternative? Absolute liability for data losses. Exactis lost 360 million peoples' data. They should be able to (a) form a class and (b) extract money damages from Exactis without having to prove specific harm, which is difficult to do with data loss. A good model is Illinois' Biometric Information Privacy Act [1]. Broaden the the definition from "biometric identifier" to a longer--but still specific--li…
That's basically what GDPR does. It broadens the scope of what is considered sensitive info and slaps a fine on people PRIOR to a breach. If a breach is found, then any breach of GDPR means EU can come after that company and hurt them seriously.
Replace EU by "the data/privacy regulator of the country in question"
Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records
#103Earlier quoted context omitted.
I agree, it is really unfortunate that even people within the software development profession take these issues so lightly.
I don't think it's so much that software devs take it "lightly". In my experience as a infosec consultant, the bigger problem is that most software devs are too cocky when it comes to security. Most think that security is just a subdomain of computer science (it is not!), and that because they took a crypto class in college, they are 100% qualified to handle the security themselves. They think they are taking it seri…
In fact, I almost certainly know only a tiny fraction of what the actual experts in that company knew, but a number of people have told me that I know a lot more about it than the average developer.
That scares me, and if people flame someone for recommending that a dedicated security expert be hired by companies that handle sensitive data, I can only conclude it is out of ignorance - of what's out there, and what's possible.
On the other hand, there are economic realities to consider, especially in early-stage, underfunded startups. What do they do about this?
Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records
#104> "I don’t know where the data is coming from, but it’s one of the most comprehensive collections I’ve ever seen" > Each record contains entries that go far beyond contact information and public records to include more than 400 variables on a vast range of specific characteristics: whether the person smokes, their religion, whether they have dogs or cats, and interests as varied as scuba diving and plus-size apparel.…
Birth certificates. Creditworthiness.
At the age of 54, Sigmund Arywitz was a healthy American success story. He was making $30,000 a year as executive secretary and treasurer of the Los Angeles County Federation of Labor, AFL-CIO, his family was sound, his reputation high on all counts, and he had just finished eight prestigious years in Sacramento as state labor commissioner under Gov. Edmund G. (Pat) Brown. But something was awry. In the space of one year, five Los Angeles department stores refused Sig Arywitz charge accounts, and a major car-leasing company turned him down for credit -- even though he had a walletful of oil-company and other credit cards and had always paid his bills on time....
1970
http://www.thedailybeast.com/articles/2013/06/11/is-privacy-...
See also: Cardinal Richelieu.
Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records
#105Earlier quoted context omitted.
The question though is what's the alternative? The IT industry has failed spectacularly in protecting citizens' personal data. I'm not a fan of EU bureaucracy, but it looks as if they are on the right side of history on this one.
> what's the alternative? Absolute liability for data losses. Exactis lost 360 million peoples' data. They should be able to (a) form a class and (b) extract money damages from Exactis without having to prove specific harm, which is difficult to do with data loss. A good model is Illinois' Biometric Information Privacy Act [1]. Broaden the the definition from "biometric identifier" to a longer--but still specific--li…
Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records
#106Earlier quoted context omitted.
I agree, it is really unfortunate that even people within the software development profession take these issues so lightly.
I don't think it's so much that software devs take it "lightly". In my experience as a infosec consultant, the bigger problem is that most software devs are too cocky when it comes to security. Most think that security is just a subdomain of computer science (it is not!), and that because they took a crypto class in college, they are 100% qualified to handle the security themselves. They think they are taking it seri…
Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records
#107Earlier quoted context omitted.
That's basically what GDPR does. It broadens the scope of what is considered sensitive info and slaps a fine on people PRIOR to a breach. If a breach is found, then any breach of GDPR means EU can come after that company and hurt them seriously.
A fine and a lawsuit are very different things, especially with 340M people involved [even a $340M fine would only be $1/person]; fines don't usually go to the people injured by it, which would make sense with personal data being leaked. A fine also misses companies who are "doing what the law says" but still have some horrible flaw anyways. If you are _genuinely_ responsible for the data, meaning if something happen…
Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records
#108Earlier quoted context omitted.
Let's discuss how we can fix this. I'm actually considering leaving my job of 8 years for a probably to be doomed privacy startup. Either way, I'm interested in solutions and more importantly working towards them, even for free.
Figure out a way to make the data collected useless. You can't hide and block every attempt to track, collect and generally have your privacy invaded. But it may be possible to throw a wrench in the gears by making so much noise the data is low quality.
Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records
#109Every American's DNA was leaked and a malicious AI bot is making a customized oncovirus for each if they visit Washington, D.C. "Oops, our bad. Here's a coupon half-off Tamiflu." Externalities of data breaches keep increasing.
Re: Marketing Firm Exactis Leaked a Personal Info Database with 340M Records
#110Earlier quoted context omitted.
That's basically what GDPR does. It broadens the scope of what is considered sensitive info and slaps a fine on people PRIOR to a breach. If a breach is found, then any breach of GDPR means EU can come after that company and hurt them seriously.
A fine and a lawsuit are very different things, especially with 340M people involved [even a $340M fine would only be $1/person]; fines don't usually go to the people injured by it, which would make sense with personal data being leaked. A fine also misses companies who are "doing what the law says" but still have some horrible flaw anyways. If you are _genuinely_ responsible for the data, meaning if something happen…
Well they do. Our government takes money through fines and taxes and uses it to build infrastructure and provide services.
> which would make sense with personal data being leaked.
My preference would be that personal data not be leaked at all. Ideally the warnings and fines kick in long before that happens.
> A fine also misses companies who are "doing what the law says" but still have some horrible flaw anyways.
What example are you thinking of?
The GDPR is quite broad and open to interpretation by both sides.
> If you are _genuinely_ responsible for the data, meaning if something happens to it you are liable for it, then you often take more care of it above and beyond, than for simply complying with rules.
That's what the GDPR does.
Requiring people to lawyer up to make the company responsible is far weaker.