Live data from Hacker News

Black Hat: GDPR privacy law exploited to reveal personal data

bbc.co.uk

31–40 of 239 posts

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#31
post #17

This is horrible. So right now, in order to get access to data for a certain person, you need to hack your way through a few of the potential services he is using and drive from there. 1. The data might have things like IDs (ie: Crypto exchanges). 2. You can use that data to ask for more data. If you got a copy of his passport, now you can ask for more with this new piece. 3. Looks like some people still store passwo…

One of the major goals of GDPR is to discourage firms from retaining personal data in the first place. It did not used to cost them anything so they kept it regardless of its use. Now that there are big risks to keeping it these firms have to think twice about it.

This "cobra effect" is one more reason NOT to retain personal information in the first place.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#32
The main benefit of GDPR is that it forced companies to audit their policies and procedures to have slightly more hygienic data practices.

The downside is that it made social engineering easier. What this guy did was nothing new. But now those businesses were compelled to help him instead of ignore him until he pestered them enough.

Good job government regulators! You just made the most common fraud even easier!

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#33
post #19

This is a reflection of the fact that we have no good way for someone to digitally prove their identity. Some countries are getting close-ish - Denmark's NemID system, for example, is used by a lot of financial institutions. However, there remains no easy way to make ad-hoc verifiable statements like 'I am John Smith and I authorise you to send this data to xyz@example.org'. Governments, please solve this problem! Es…

Italy's "PEC"[1] (Posta Elettronica Certificata, or Certified Electronic Mail) comes pretty close. There's even an RFC[2] for it. In order to get one, an individual has to prove their identity via a government-issued ID (ID card or passport), and that email address can henceforth be used to send emails for all official correspondence as if it were certified/verified mail, with the added bonus that both parties "know"…

Denmark has a similar service called eBoks, but it's a proprietary SaaS product rather than an open standard. What's the user experience like with the Italian system? Does every company support it?

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#34
post #21
post #19

This is a reflection of the fact that we have no good way for someone to digitally prove their identity. Some countries are getting close-ish - Denmark's NemID system, for example, is used by a lot of financial institutions. However, there remains no easy way to make ad-hoc verifiable statements like 'I am John Smith and I authorise you to send this data to xyz@example.org'. Governments, please solve this problem! Es…

Sweden's BankID is quite good too.

BankID is horrible.

It's coupled to your phone's OS, so as it becomes even more mandatory you're stuck carrying around an iOS or Android device, even if your primary phone is something like a Librem 5.

It also doesn't support anyway to delegate access, either to people ("my partner should have access to this bank account") or computers ("I want to back up my incoming govt. messages automatically").

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#35

Earlier quoted context omitted.

This was actually one of the risks we identified when looking at GDPR for my own businesses last year. Given that in some cases all we have is an online account with minimal personal details, how can we possibly verify their identity to an acceptable standard if someone does send us a GDPR subject access request of any kind? If they have some sort of account with us already and that has associated ID and security che…

> we don't have any special knowledge of what official government-issued ID looks like in every country where we have customers, nor the human resources or automated technology to investigate in detail whether any ID that is sent might be faked. This sounds like one of the risks of doing international business. If you can't follow the laws then don't play.

OP sounds like he was trying hard to navigate and follow the law? The problem is he ended up finding no reasonable solution that both protected his users privacy while also following the rules, and was disturbed by the implications of it all considering it was supposed to protect them in the first place. Those are very valid criticisms.

Simply dismissing everyone who shows concern about a law as mere law dodgers or foreign bad actors disinterested in following the local law is unhelpful and borderline anti-intellectual.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#36
This is the problem with overly aggressive legislation. The big companies performed well, the small companies ignored the law, and the medium sized companies tried to comply and failed. You can’t legislate good behavior because people will always find a way around the laws. The legal philosophy behind GDPR seems to be nothing more than to make everyone a criminal and then choose who to prosecute, and in that case why have laws at all rather than letting law enforcement punish whoever they choose?

At the end of the day this incentivizes big companies to comply with the laws because they can afford the necessary legal teams and the laws provide a moat to their entrenched power. It incentivizes small companies to ignore the laws just like the move fast and break things mentality of Silicon Valley. The people it hurts are the medium sized, growing companies who are best positioned to fight the big monopolies but are now being held back by well meaning but over burdensome legislation.

The good side of GDPR is that it’s trying to advocate for consumer privacy, which overall is a good thing. The issue is that it’s not a legal problem. In the same way you can’t declare drugs to be illegal and expect the supply of drugs to instantly disappear, you can’t declare misuse of data illegal and expect the same. As long as the data has value there will be a market for it, so why not draft sensible regulations instead of trying to solve the problem with laws.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#37

Earlier quoted context omitted.

This was actually one of the risks we identified when looking at GDPR for my own businesses last year. Given that in some cases all we have is an online account with minimal personal details, how can we possibly verify their identity to an acceptable standard if someone does send us a GDPR subject access request of any kind? If they have some sort of account with us already and that has associated ID and security che…

> we don't have any special knowledge of what official government-issued ID looks like in every country where we have customers, nor the human resources or automated technology to investigate in detail whether any ID that is sent might be faked. This sounds like one of the risks of doing international business. If you can't follow the laws then don't play.

Frankly, no one has the resources to do this reliably, and the identity theft consequences are potentially enormous.

It's fairly easy to get a reasonably convincing fake ID. High schoolers manage it all the time.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#38
post #17

This is horrible. So right now, in order to get access to data for a certain person, you need to hack your way through a few of the potential services he is using and drive from there. 1. The data might have things like IDs (ie: Crypto exchanges). 2. You can use that data to ask for more data. If you got a copy of his passport, now you can ask for more with this new piece. 3. Looks like some people still store passwo…

One of the major goals of GDPR is to discourage firms from retaining personal data in the first place. It did not used to cost them anything so they kept it regardless of its use. Now that there are big risks to keeping it these firms have to think twice about it. This "cobra effect" is one more reason NOT to retain personal information in the first place.

And yet other laws require the collection and retention of sensitive user data, in particular any service that allows for transmission of large amounts of money (crypto exchanges were a good example).

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#39
post #23
post #11

Earlier quoted context omitted.

Regardless it would then be a bad law since almost all criminal law looks at intent and reasonable expectations of how a citizen should act. We don’t need to keep replaying the vilification of security researcher game just because it involves the flawed gov systems imposed on technology itself instead of just technology. The end goal is the same, the privacy and security of end users.

Agreed. I hope any jury would nullify such a law. AKA "perverse verdict" in the UK?

I’d never trust a jury for any highly technical matter such as this. Prosecutors have shown they can be highly effectively at spinning even the most basic security research into sounding like serious criminal behaviour (like punishing someone with serious jail time for incrementing the id number in a URL and finding other users personal profiles completely unprotected).

You only gamble on juries for stuff like murder trials and similar basic crimes.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#40

Earlier quoted context omitted.

This was actually one of the risks we identified when looking at GDPR for my own businesses last year. Given that in some cases all we have is an online account with minimal personal details, how can we possibly verify their identity to an acceptable standard if someone does send us a GDPR subject access request of any kind? If they have some sort of account with us already and that has associated ID and security che…

> we don't have any special knowledge of what official government-issued ID looks like in every country where we have customers, nor the human resources or automated technology to investigate in detail whether any ID that is sent might be faked. This sounds like one of the risks of doing international business. If you can't follow the laws then don't play.

> If you can't follow the laws then don't play.

This is the subtext of the GDPR. Bluntly, they only want HugeCos providing services on the internet, anyone worth fewer than around 10 digits can suck it.

This isn't limited to Europe, of course. Most governments are coming around to the idea that there are too many printing presses.

Post reply on HN