Live data from Hacker News

Black Hat: GDPR privacy law exploited to reveal personal data

bbc.co.uk

81–90 of 239 posts

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#81
post #2

This is pretty appalling, really: "Overall, of the 83 firms known to have held data... 24% supplied personal information without verifying the requester's identity." Want someone else's personal data? No need to "hack into" any systems; just ask for it!

This was actually one of the risks we identified when looking at GDPR for my own businesses last year. Given that in some cases all we have is an online account with minimal personal details, how can we possibly verify their identity to an acceptable standard if someone does send us a GDPR subject access request of any kind? If they have some sort of account with us already and that has associated ID and security che…

This is nothing new. People could make "subject access requests" before the GDPR, and you could charge up to £10 (in the UK) to reply.

It's perfectly lawful to refuse to disclose anything until you have received reasonable evidence of the person's identity and payment (I don't know if you can still charge under the GDPR -- Edit: Apparently you may not charge for the first copy, but you may for further copies).

Considering the potential risks (including bad PR) and penalties it is better to refuse to disclose data because you have doubts rather than to disclose easily.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#82
post #52

Earlier quoted context omitted.

One of the major goals of GDPR is to discourage firms from retaining personal data in the first place. It did not used to cost them anything so they kept it regardless of its use. Now that there are big risks to keeping it these firms have to think twice about it. This "cobra effect" is one more reason NOT to retain personal information in the first place.

This does nothing to discourage keeping data around. A company does not care if they, while following best-effort GDPR practice, release data to a hacker that causes harm to a user. They can simply hide behind the GDPR legislation to say “we did nothing wrong, the law is broken, we were trying our best, we accept no liability”

They are still liable, the waiver is not acceptable under EU law for personal data.

How big a liability it is, is to be decided in a court of law.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#83
post #19

This is a reflection of the fact that we have no good way for someone to digitally prove their identity. Some countries are getting close-ish - Denmark's NemID system, for example, is used by a lot of financial institutions. However, there remains no easy way to make ad-hoc verifiable statements like 'I am John Smith and I authorise you to send this data to xyz@example.org'. Governments, please solve this problem! Es…

Latvia's ID cards support e-signing of digital documents, so I could have a pdf "I authorise you to send this data to xyz@example.org" and sign it so that the recipient can securely verify that this was signed by Name Surname ID123.

Estonia has it quite similar, I'm not certain if it's technically the same standard or something slightly different.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#84

Earlier quoted context omitted.

That seems weird, from what I see in Europe, ID forgery is quite rare; making a convincing fake ID is about as difficult (or more difficult) as making convincing fake money, as pretty much the same anti-counterfeiting measures are used; and carries about the same consequences as counterfeiting money. It's possible, but not cheap or widespread - there are a bunch of ways how you could get money or stuff with a fake ID…

Fake IDs in EU don't really work, since anyone who really cares (banks, police, ...) will just read the info from the machine readable zone and run that against the relevant database. So EU IDs are more like a web-server session cookie, you can't just make one up. There are online services who also provide this for a cost: https://www.idcheck.io

Those just analyze photos for photoshop artifacts for a CYA receipt. They don't verify that the ID info is real.

That's next to useless under identity fraud / attacks any more sophisticated than MS Paint level skills. You're severely underplaying how easy it is to fake documentation and the attacks it enables.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#85

Earlier quoted context omitted.

> You can install it on your PC or Mac if you want. 1. Same problem. There is still no Linux client, for example. 2. It's a different API. Most services specifically require Mobile BankID these days. Desktop (regular) BankID won't work there. 3. Many applications are only useful on the go, such as Swish. > Access delegation not being part of BankID itself is a feature not a deficiency, it would undermine the concept…

> Same problem. There is still no Linux client, for example. There was[0]. Maybe you can revive it, since it is a pain-point? > It's a different API. Having read the BankId specs, they're "different" APIs in only in how the session is initiated. You're still challenged to enter the PIN for the certificate, which prompts the response to the authentication request. In other words, BankId and Mobile Bank Id are presenti…

Nordea requires Mobile BankID to log into their online banking, but they also let you log in with a card reader and do the challenge/response codes thing. I assume desktops/laptops aren't secure enough for their taste.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#86

Earlier quoted context omitted.

Hasn't Estonia solved this with their national ID smart card?

Yes. A lot of Estonians use it daily to log in to their bank accounts, give digital signatures, deal with government business, check their health data etc. All you need is your ID card and your PIN codes.

[deleted]

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#87
post #70

Earlier quoted context omitted.

> You can install it on your PC or Mac if you want. 1. Same problem. There is still no Linux client, for example. 2. It's a different API. Most services specifically require Mobile BankID these days. Desktop (regular) BankID won't work there. 3. Many applications are only useful on the go, such as Swish. > Access delegation not being part of BankID itself is a feature not a deficiency, it would undermine the concept…

> There is also already a clear precedent to allow delegation of access that require strong authentication IRL. For example, PostNord allows you to retrieve someone else's mail as long as you provide ID for both yourself and the recipient. They have the same service in their app with BankID + QR code (at least for packages).

My point is that BankID should have something similar for any BankID action.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#88
post #21
post #19

This is a reflection of the fact that we have no good way for someone to digitally prove their identity. Some countries are getting close-ish - Denmark's NemID system, for example, is used by a lot of financial institutions. However, there remains no easy way to make ad-hoc verifiable statements like 'I am John Smith and I authorise you to send this data to xyz@example.org'. Governments, please solve this problem! Es…

Sweden's BankID is quite good too.

Fun-filled fact: It's also in Norway[0], now, as well.

[0] - https://www.bankid.no/bedrift/

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#89

Earlier quoted context omitted.

This was actually one of the risks we identified when looking at GDPR for my own businesses last year. Given that in some cases all we have is an online account with minimal personal details, how can we possibly verify their identity to an acceptable standard if someone does send us a GDPR subject access request of any kind? If they have some sort of account with us already and that has associated ID and security che…

Government officials created an untenable law in the name of the technological boogey man?!

Not bogey. Misuse of personal days it's happening daily, but the law is not exactly super great. Better than nothing I suppose.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#90
post #17

This is horrible. So right now, in order to get access to data for a certain person, you need to hack your way through a few of the potential services he is using and drive from there. 1. The data might have things like IDs (ie: Crypto exchanges). 2. You can use that data to ask for more data. If you got a copy of his passport, now you can ask for more with this new piece. 3. Looks like some people still store passwo…

This is not a problem with GDPR. This is a problem with organizations (companies and governments) treating publicly data as private keys.
Post reply on HN