Live data from Hacker News

Black Hat: GDPR privacy law exploited to reveal personal data

bbc.co.uk

111–120 of 239 posts

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#111

Earlier quoted context omitted.

> Same problem. There is still no Linux client, for example. There was[0]. Maybe you can revive it, since it is a pain-point? > It's a different API. Having read the BankId specs, they're "different" APIs in only in how the session is initiated. You're still challenged to enter the PIN for the certificate, which prompts the response to the authentication request. In other words, BankId and Mobile Bank Id are presenti…

> There was[0]. Maybe you can revive it, since it is a pain-point? No. This is a problem that was intentionally caused by Finansiell ID-teknik, and I'm not going to get into cat-and-mouse game to fix their for-profit product. > Having read the BankId specs, they're "different" APIs in only in how the session is initiated. You're still challenged to enter the PIN for the certificate, which prompts the response to the…

>No. This is a problem that was intentionally caused by Finansiell ID-teknik, and I'm not going to get into cat-and-mouse game to fix their for-profit product.

You're - literally - on "Hacker News" complaining about the lack of a product. You were given one that you could easily fix to suit your aforementioned needs/demands and was a principal complaint against BankId but, instead, you want BankId to write the Linux app for you because... ...profits? This makes no sense; especially, when you would already have a hefty baseline of code to work with.

>They're different in that a service that takes Mobile BankID does not automatically support the desktop version, or vice versa.

Does not automatically doesn't - implicitly - mean that it's disallowed. You seem to be confusing the two concepts, here.

>Whether the API is similar after that doesn't matter.

We're - literally - talking about the API being the same because you made it a point that it was different. Either it matters or it doesn't. Pick one.

>Off the top of my head, Swish and Hemfrid only accept Mobile BankID, with no alternate authentication options. Swedbank accepts Mobile BankID or their custom OTP hardware token, but not desktop BankID.

O.k.? We're still in the swamplands of those are problems created by the app developers and not BankId, correct..? I'm not sure I'm following how the app designers' decisions are the fault of BankId...

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#112

Earlier quoted context omitted.

I don't think that what you describe is incompatible with GDPR. In general GDPR allows and requires you to use 'all reasonable measures to verify the identity', and in your particular scenario requiring the same authentication that you usually use would be considered reasonable, and it's likely the only possible reasonable measure - if what you say is all you store, then it's impossible to distinguish between two dif…

Yeah, there is some weird subtext to the argument, that for some reason account access shouldn't count as secure verification? I guess this all hinges on the idea that to implement GDPR all you need to do is set up an email adress and handle all requests manually, only to then discover that: actually, identity management via plaintext email is a bit tricky.

If someone loses their password and asks for their data under the GDPR it's an open question whether the site can simply say "sorry, there's no longer any way for us to verify you are who you say you are".

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#113
post #17

This is horrible. So right now, in order to get access to data for a certain person, you need to hack your way through a few of the potential services he is using and drive from there. 1. The data might have things like IDs (ie: Crypto exchanges). 2. You can use that data to ask for more data. If you got a copy of his passport, now you can ask for more with this new piece. 3. Looks like some people still store passwo…

Interesting that you consistently refer to the target as "he" as if women weren't a major target of this kind of campaign.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#114

Earlier quoted context omitted.

Government officials created an untenable law in the name of the technological boogey man?!

Hey now. Mass surveillance, data breaches, and non-consensual data sale are absolutely issues, and will continue to be. This isn’t a boogey man, this is real, and it’s entirely the technology industry’s fault. Maybe we wouldn’t have to deal with the GDPR if we treated data as a liability from the beginning.

This isn’t a boogey man, this is real, and it’s entirely the technology industry’s fault.

I agree there are real dangers, but I don't think blaming it entirely on the tech industry is fair. The financial services industry has been profiling as much as it could get away with forever. Government security services and the like obviously do this sort of thing as well. Modern technology has made these things easier and surely provides a generous source of additional data to both of the above groups, and targeted ads have created another not entirely welcome variation on the theme, but modern technology is hardly the original source of creepy data-hoarding behaviour.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#115

Earlier quoted context omitted.

This was actually one of the risks we identified when looking at GDPR for my own businesses last year. Given that in some cases all we have is an online account with minimal personal details, how can we possibly verify their identity to an acceptable standard if someone does send us a GDPR subject access request of any kind? If they have some sort of account with us already and that has associated ID and security che…

> we don't have any special knowledge of what official government-issued ID looks like in every country where we have customers, nor the human resources or automated technology to investigate in detail whether any ID that is sent might be faked. This sounds like one of the risks of doing international business. If you can't follow the laws then don't play.

If you can't follow the laws then don't play.

That's an unhelpful argument if there is no reasonable way to determine what the laws are and/or to comply with them.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#116
post #105

Earlier quoted context omitted.

I wouldn't agree that the medium sized companies tried to comply with the GDPR and failed. Yes, they tried to comply with that particular request but the failures suggest that they didn't even try to be GDPR compliant in the first place - if they had done so, then they would have had assigned a data protection officer who would have long ago asked themselves the question "what do we do in case of a personal informati…

I keep hearing on Hacker News how easy it is to be GDPR compliant and that any company following good privacy practices should have no problems. Then I see stuff like: >if they had done so, then they would have had assigned a data protection officer who would have long ago asked themselves the question "what do we do in case of a personal information request?" If I have to hire/create an entirely new position at my c…

In most places it's not a full time position but simply a designation on who's the responsible person.

However, the reason why it's not talked much in context with GDPR compliance is that's not really a new GDPR requirement - it has been a mandatory requirement already in the previous privacy laws; any EU company handling private data had to have a designated DPO for many years before GDPR and that's a nonnegotiable basic requirement if you want to handle such data. If a company doesn't have this, then they weren't permitted to handle private data even before GDPR was concieved. GDPR added some more rights to consumers (such as this right to request) which would require the existing DPO's to adjust procedures.

I mean, does it seem likely to you that your company can implement proper, secure handling of private data without having someone responsible for it? This very discussion shows that it takes some attention and specialized knowledge.

And if you can't pay the 'table stakes', then you're not allowed to 'play the game' - this has many parallels with other regulations. Just as it's reasonable to shut down restaurants for gross hygiene violations and prevent them from operating until/unless they can't handle food properly, it's reasonable to shut down data processing activities for gross 'data hygiene' violations, and prevent them from operating until/unless they can handle private data properly. Just as you can't do various construction and industrial activities without having a designated occupational hazard person (not necessarily full-time), you can't handle private data processing without a designated data protection person. There's nothing novel here.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#117

Earlier quoted context omitted.

> it also makes companies think twice whether it's really necessary and worth it The simple fact that someone has an account at a service can be private information. For anything requiring even a modicum of persistence, keeping these data is tough to avoid. I think most of HN agrees GDPR’s goals are good. It was just sloppily drafted, passed and implemented.

GDPR does not care about privacy. It cares about personal identification. Such as full name and address, and a bunch of other protected things. Why would any random service request, process or more importantly store these?

That’s simply not the law. The official guidance (https://gdpr.eu/eu-gdpr-personal-data/) is that even just an IP address or a license plate number are sufficient to count as identifying a person.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#118
post #90
post #17

This is horrible. So right now, in order to get access to data for a certain person, you need to hack your way through a few of the potential services he is using and drive from there. 1. The data might have things like IDs (ie: Crypto exchanges). 2. You can use that data to ask for more data. If you got a copy of his passport, now you can ask for more with this new piece. 3. Looks like some people still store passwo…

This is not a problem with GDPR. This is a problem with organizations (companies and governments) treating publicly data as private keys.

Moreover, it's a problem with the current state of "identity" as a whole. Most of the data received in the article - passports, addresses, phone numbers, credit cards - does not change very often. Some documents expire, but even then it could be valid for another 3 - 10 years.

We need to move to a system that allows rapid expiry of PII data. Then it will not matter if someone is able to social engineer this data from all these companies. By the time the data leaves the companies HQ, it is already out of date and therefore impossible to use with new services.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#119

Earlier quoted context omitted.

Fake IDs in EU don't really work, since anyone who really cares (banks, police, ...) will just read the info from the machine readable zone and run that against the relevant database. So EU IDs are more like a web-server session cookie, you can't just make one up. There are online services who also provide this for a cost: https://www.idcheck.io

Those just analyze photos for photoshop artifacts for a CYA receipt. They don't verify that the ID info is real. That's next to useless under identity fraud / attacks any more sophisticated than MS Paint level skills. You're severely underplaying how easy it is to fake documentation and the attacks it enables.

I had to verify my identity for an online service a while back. They used a third party company that has a mobile phone app essentially for video conferencing; you then call this company via the app and talk to them. They ask you to show your face and move around and to show your ID, including moving it around so they can check that the security hologram (this was an EU passport) is indeed one. So for this kind of check MS Paint skills would not be enough by far.

I guess they had no way of verifying that the ID info is real, but apparently this process was trustworthy enough for their client.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#120

Earlier quoted context omitted.

To me it sounds a bit dubious that you can both have a valid reason for keeping personal information about someone and not have a valid way of verifying that you are actually communicating with them. What sort of agreement can you enter with someone if you don't know who they are?

> To me it sounds a bit dubious that you can both have a valid reason for keeping personal information about someone and not have a valid way of verifying that you are actually communicating with them. Suppose I run a matchmaking site that stores a real name, username, and sexual orientation for registered users. To avoid over-collecting data, that's all I require. I don't need strong verification at this stage becau…

Why would you need a real name? You shouldn't collect it.
Post reply on HN