Live data from Hacker News

Black Hat: GDPR privacy law exploited to reveal personal data

bbc.co.uk

61–70 of 239 posts

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#61

Earlier quoted context omitted.

Remember that a GDPR request is going to typically come electronically. You won't have a physical item to examine for all its anti-counterfeiting features - you're probably going to have a photograph from a mobile phone to look at.

To me it sounds a bit dubious that you can both have a valid reason for keeping personal information about someone and not have a valid way of verifying that you are actually communicating with them. What sort of agreement can you enter with someone if you don't know who they are?

> To me it sounds a bit dubious that you can both have a valid reason for keeping personal information about someone and not have a valid way of verifying that you are actually communicating with them.

Suppose I run a matchmaking site that stores a real name, username, and sexual orientation for registered users.

To avoid over-collecting data, that's all I require. I don't need strong verification at this stage because there's little risk if someone creates a fraudulent account, and collecting strong verification can add other data security risks.

However, if someone demands the data already in the system, it's of a presumably real person. And revealing whether user X is gay can be very sensitive information.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#62
this is peanuts. one eu country government decided it needed approval under gdpr from hospital patients before treatment/surgery/etc. this denied service to a bunch of (tech) illiterate people, bringing the budget back in line.

another one: due to gdpr, violent thugs hired by the police to hurt protesters cannot be named. it would apparently trample on their rights.

gdpr is, as forecasted, a complete mess. a mess that is exploited by corrupt eu governments to great effect.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#63
post #5

> "But the kind of mid-sized businesses that knew about GDPR, but maybe didn't have much of a specialised process [to handle requests], failed." I wonder if there is a market for selling GDPR compliance / advising services. Some company that makes sure your doing everything right, and inspects the requests for validity.

I think that's exactly the problem -- small/medium companies can't really afford to hire someone to do GDPR compliance (or at least, do it well). It's textbook regulatory capture.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#64
post #2

This is pretty appalling, really: "Overall, of the 83 firms known to have held data... 24% supplied personal information without verifying the requester's identity." Want someone else's personal data? No need to "hack into" any systems; just ask for it!

This was actually one of the risks we identified when looking at GDPR for my own businesses last year. Given that in some cases all we have is an online account with minimal personal details, how can we possibly verify their identity to an acceptable standard if someone does send us a GDPR subject access request of any kind? If they have some sort of account with us already and that has associated ID and security che…

> Even if someone were willing to send us "strong" ID

Amusing that legislation intended to improve privacy is normalising sending IDs to sites one doesn’t trust enough to keep one’s personal data.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#65
post #19

This is a reflection of the fact that we have no good way for someone to digitally prove their identity. Some countries are getting close-ish - Denmark's NemID system, for example, is used by a lot of financial institutions. However, there remains no easy way to make ad-hoc verifiable statements like 'I am John Smith and I authorise you to send this data to xyz@example.org'. Governments, please solve this problem! Es…

Italy's "PEC"[1] (Posta Elettronica Certificata, or Certified Electronic Mail) comes pretty close. There's even an RFC[2] for it. In order to get one, an individual has to prove their identity via a government-issued ID (ID card or passport), and that email address can henceforth be used to send emails for all official correspondence as if it were certified/verified mail, with the added bonus that both parties "know"…

[deleted]

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#66

Earlier quoted context omitted.

To me it sounds a bit dubious that you can both have a valid reason for keeping personal information about someone and not have a valid way of verifying that you are actually communicating with them. What sort of agreement can you enter with someone if you don't know who they are?

> To me it sounds a bit dubious that you can both have a valid reason for keeping personal information about someone and not have a valid way of verifying that you are actually communicating with them. Suppose I run a matchmaking site that stores a real name, username, and sexual orientation for registered users. To avoid over-collecting data, that's all I require. I don't need strong verification at this stage becau…

I don't think that what you describe is incompatible with GDPR.

In general GDPR allows and requires you to use 'all reasonable measures to verify the identity', and in your particular scenario requiring the same authentication that you usually use would be considered reasonable, and it's likely the only possible reasonable measure - if what you say is all you store, then it's impossible to distinguish between two different John Smiths making such requests, and https://gdpr-info.eu/recitals/no-64/ recommends that you should not request more info just for the purpose of these requests.

In this scenario where the information was provided by the users themselves (if you had collected them otherwise from third parties, that'd be a very different issue) simply putting a link "download your data here" on your site for authenticated users would be a reasonable solution; and it matches https://gdpr-info.eu/recitals/no-63/ recommendation "Where possible, the controller should be able to provide remote access to a secure system which would provide the data subject with direct access to his or her personal data."

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#67
post #2

This is pretty appalling, really: "Overall, of the 83 firms known to have held data... 24% supplied personal information without verifying the requester's identity." Want someone else's personal data? No need to "hack into" any systems; just ask for it!

This was actually one of the risks we identified when looking at GDPR for my own businesses last year. Given that in some cases all we have is an online account with minimal personal details, how can we possibly verify their identity to an acceptable standard if someone does send us a GDPR subject access request of any kind? If they have some sort of account with us already and that has associated ID and security che…

The email used during registration is sufficient. If you don't have email then username+password.

If they don't have that they don't get access to data. They need to be able to prove who they are and reasonably that is the same information that is used during registration.

If password is lost then tough luck.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#68

Earlier quoted context omitted.

You can install it on your PC or Mac instead if you want, and it is not the only e-ID in Sweden (alas the others aren't so widely adopted, but that should change if/when the new government ID happens). Access delegation not being part of BankID itself is a feature not a deficiency, it would undermine the concept of secure digital ID if someone else could digitally impersonate you with it. Instead, services can choose…

> You can install it on your PC or Mac if you want. 1. Same problem. There is still no Linux client, for example. 2. It's a different API. Most services specifically require Mobile BankID these days. Desktop (regular) BankID won't work there. 3. Many applications are only useful on the go, such as Swish. > Access delegation not being part of BankID itself is a feature not a deficiency, it would undermine the concept…

> It's a different API. Most services specifically require Mobile BankID these days. Desktop (regular) BankID won't work there.

I'm not sure which point you're referring to with the mention of differing API. Mobile BankID is the same API as regular BankID (but services can choose which they accept); as for other Swedish e-ID services, there are aggregator services.

Re: most, really? There are some that don't accept non-mobile BankID, but it is uncommon in my experience.

> There is also already a clear precedent to allow delegation of access that require strong authentication IRL.

Sure, but what does that have to do with BankID itself? Both in-person and online, it is the service that decides whether someone else can act for you. And various services do offer this: I can let others access my tax records or prescription medicine records online.

I don't think it's unreasonable for services to want to know who they're dealing with. In real life, if someone else shows my ID at postnord, they have to show their own ID too.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#70

Earlier quoted context omitted.

You can install it on your PC or Mac instead if you want, and it is not the only e-ID in Sweden (alas the others aren't so widely adopted, but that should change if/when the new government ID happens). Access delegation not being part of BankID itself is a feature not a deficiency, it would undermine the concept of secure digital ID if someone else could digitally impersonate you with it. Instead, services can choose…

> You can install it on your PC or Mac if you want. 1. Same problem. There is still no Linux client, for example. 2. It's a different API. Most services specifically require Mobile BankID these days. Desktop (regular) BankID won't work there. 3. Many applications are only useful on the go, such as Swish. > Access delegation not being part of BankID itself is a feature not a deficiency, it would undermine the concept…

> There is also already a clear precedent to allow delegation of access that require strong authentication IRL. For example, PostNord allows you to retrieve someone else's mail as long as you provide ID for both yourself and the recipient.

They have the same service in their app with BankID + QR code (at least for packages).

Post reply on HN