Live data from Hacker News

Black Hat: GDPR privacy law exploited to reveal personal data

bbc.co.uk

1–10 of 239 posts

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#3
post #2

This is pretty appalling, really: "Overall, of the 83 firms known to have held data... 24% supplied personal information without verifying the requester's identity." Want someone else's personal data? No need to "hack into" any systems; just ask for it!

This was actually one of the risks we identified when looking at GDPR for my own businesses last year. Given that in some cases all we have is an online account with minimal personal details, how can we possibly verify their identity to an acceptable standard if someone does send us a GDPR subject access request of any kind? If they have some sort of account with us already and that has associated ID and security checks, that's one thing, but what if they don't or they claim to have forgotten their password etc?

Even if someone were willing to send us "strong" ID, we don't have any special knowledge of what official government-issued ID looks like in every country where we have customers, nor the human resources or automated technology to investigate in detail whether any ID that is sent might be faked. At best, we could find an image of a passport/driving licence/whatever from that person's country and see if what they've sent us looks about right and matches any personal details we do have for the data subject.

Our disturbing conclusion was that if someone did ever send us certain types of request in connection with certain accounts, there might be no action we could safely take to resolve the situation that would definitely be lawful. If we get scammed by fake ID then we're breaking the law. If we don't accept ID that is real and comply with the subject request, we're also breaking the law.

Fortunately the affected services aren't doing anything particularly exciting or risky with personal data either, so it seems unlikely that any serious harm would come to anyone whatever happened in our case. However, the same basic issue surely affects many other data controllers/processors, and they won't necessarily be such unlikely targets as the research here shows. I haven't yet found any practical guidance from the regulators on what would be considered reasonable in this sort of situation.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#4
> Mr Pavur says he believes he did not break the law himself while conducting the trial

This is a bit odd. I know his partner consented to this, but this doesn't seem like it should be enough to make this not identity fraud.

Obviously the research Pavur carried out is extremely valuable and the mid-sized companies failing to follow proper procedure are the real problem here, but it still seems like it would be technically illegal.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#5
> "But the kind of mid-sized businesses that knew about GDPR, but maybe didn't have much of a specialised process [to handle requests], failed."

I wonder if there is a market for selling GDPR compliance / advising services. Some company that makes sure your doing everything right, and inspects the requests for validity.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#6
post #5

> "But the kind of mid-sized businesses that knew about GDPR, but maybe didn't have much of a specialised process [to handle requests], failed." I wonder if there is a market for selling GDPR compliance / advising services. Some company that makes sure your doing everything right, and inspects the requests for validity.

There are quite a few firms offering compliance / advisory services, including ones that'll host the data request forms etc. for you.

I'm not aware of any willing to take on the liability of verifying identities as part of that, though.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#8
post #6
post #5

> "But the kind of mid-sized businesses that knew about GDPR, but maybe didn't have much of a specialised process [to handle requests], failed." I wonder if there is a market for selling GDPR compliance / advising services. Some company that makes sure your doing everything right, and inspects the requests for validity.

There are quite a few firms offering compliance / advisory services, including ones that'll host the data request forms etc. for you. I'm not aware of any willing to take on the liability of verifying identities as part of that, though.

Do you know of any companies that handle the whole process, similar to how stripe handles the whole purchasing process?

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#9
post #4

> Mr Pavur says he believes he did not break the law himself while conducting the trial This is a bit odd. I know his partner consented to this, but this doesn't seem like it should be enough to make this not identity fraud. Obviously the research Pavur carried out is extremely valuable and the mid-sized companies failing to follow proper procedure are the real problem here, but it still seems like it would be techni…

Fraud (in the UK at least) requires an intention to gain for yourself, so he would probably be alright.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#10
post #8
post #6

Earlier quoted context omitted.

There are quite a few firms offering compliance / advisory services, including ones that'll host the data request forms etc. for you. I'm not aware of any willing to take on the liability of verifying identities as part of that, though.

Do you know of any companies that handle the whole process, similar to how stripe handles the whole purchasing process?

I'm sure one of the major consulting shops like Accenture would be willing to do it (poorly, and for insane amounts of money, of course). I'm not aware of any SaaS style offerings, though.
Post reply on HN