Live data from Hacker News

Black Hat: GDPR privacy law exploited to reveal personal data

bbc.co.uk

151–160 of 239 posts

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#151
post #8

Earlier quoted context omitted.

Do you know of any companies that handle the whole process, similar to how stripe handles the whole purchasing process?

Can you elaborate by what do you mean with "the whole process"? If you have some internal processes that handle the data, then you can't really separate and outsource the "GDPR part" without outsourcing the whole business process that handles the data - e.g. if you ship goods, then handling of adresses can't (IMHO) be separated from the shipping, if you run a website, then the handling of all the related privacy issu…

The general idea in my head is that instead of each company needing a department to handle GDPR, they outsource the department to the third party. Because of the company's size, I would assume the third party could handle more then one company at a time, lowering costs. Yes this wouldn't solve liability, but it reduces the chance there will be mistakes, like those mentioned in the article.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#152
post #2

This is pretty appalling, really: "Overall, of the 83 firms known to have held data... 24% supplied personal information without verifying the requester's identity." Want someone else's personal data? No need to "hack into" any systems; just ask for it!

Verifying identity is a very hard problem.

That should not lead to an "open by default" policy.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#153

Earlier quoted context omitted.

BankID is horrible. It's coupled to your phone's OS, so as it becomes even more mandatory you're stuck carrying around an iOS or Android device, even if your primary phone is something like a Librem 5. It also doesn't support anyway to delegate access, either to people ("my partner should have access to this bank account") or computers ("I want to back up my incoming govt. messages automatically").

Not to mention that all providers of Mobile Bank ID (which, as you mentioned, is by far the most widely supported one) are private companies, mostly banks, which have no duty to take you on as a customer. If you for whatever reason can't or won't get an account with a Swedish bank, you're effectively cut out from large parts of online services. I really think the government needs to realize they should provide ID iss…

They already did realise: https://www.regeringen.se/pressmeddelanden/2019/03/utredning...

The existing Skatteverket ID card contains an e-ID (from a private provider) as well, but alas only Skatteverket support it for some reason.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#154

Earlier quoted context omitted.

One of the major goals of GDPR is to discourage firms from retaining personal data in the first place. It did not used to cost them anything so they kept it regardless of its use. Now that there are big risks to keeping it these firms have to think twice about it. This "cobra effect" is one more reason NOT to retain personal information in the first place.

I'll let you in on a secret. For government institutions which in general have huge amounts of information about you and are notoriously bad at security. They don't even get fined with the GDPR. The worst that can happen to them is bad press. So the institution that has all the healthcare data of all German citizens can not get fined under the GDPR. Same with any other KdöR https://de.wikipedia.org/wiki/K%C3%B6rpersc…

I've heard of local GDPR complaints and enforcement actions (no fines yet, in administrative proceedings) against various state agencies, municipalities and also hospitals, so it does apply to state institutions at least to a certain extent. They have it a bit easier with the reasons for processing, as usually there's an existing law that mandates (and thus allows) the data processing they do, so they usually don't need consent, but the other requirements should apply.

Why wouldn't GDPR apply to german KdöR? I'm not aware of any exemptions in GDPR that could apply to them; governments can make specific local exceptions for national security, defense, judicial process, etc needs (https://gdpr-info.eu/art-23-gdpr/) but Germany shouldn't be able to simply exempt all their KdöR.

One thing is that in some jurisdictions public institutions can't be required to pay fines to the regulator (because transfering money from one gov't pocket to another doesn't make that much sense), however, you can still get an administrative ruling forcing them to change their policies, and if your rights have been violated, then you're entitled to compensation, the "can't be fined" only applies to stuff they'd owe the regulator, not regarding harmed individuals.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#155

Earlier quoted context omitted.

It depends on the circumstances of each scenario, but it would be completely reasonable if large numbers of smallish companies acknowledge that they lack the capacity to handle personal data properly and the recommended strategy for GDPR compliance is that they should simply stop requesting and storing that data. That's not a reasonable strategy at all. Any company doing more than selling basic goods in person for ca…

"Any company doing more than selling basic goods in person for cash probably needs to process some level of personal data for legitimate reasons." is a bit tricky, and I'm not certain that it's true. I'd say that many common business processes use personal data for reasons of tradition, but don't really need it. 1) "Selling for cash" - accepting credit cards and wire transfers (paying by check isn't really a thing in…

>you don't need any details about the transcaction beyond the amount and ID. //

That's a lot of trust in the merchant services. "What transaction?", then if all you had was a transaction ID what do you do?

Also, to process refunds you need to have payment details.

In your second case only store the details if people explicitly want you to. You can do repeat customer discounts by sending vouchers for a later order with the present order confirmation. (You can't restrict discounts to those who give up their PII if I'm reading things right.)

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#156
post #121

Earlier quoted context omitted.

Interesting that you consistently refer to the target as "he" as if women weren't a major target of this kind of campaign.

Some people refer to hypothetical people in stories as the same sex as the person describing the story. I'm not positive, but I imagine the parent is also a "he". I don't consider this important at all, and I think you're being pedantic.

I guess I agree it's a form of pedantry, but once you're a bit used to reading singular "they" (and it's hard to escape nowadays) you get used to it, and the opposite starts looking weird. Also, it's pedantry that seems to actually be socially beneficial: https://www.theguardian.com/science/2019/aug/05/he-she-or-ge... (I don't agree with everything being done for "gender-neutral language", especially in German. But this particular case is simple and useful enough in English.)

For whatever it's worth, the reason this tripped me up here was that I had to read the original post several times because I thought that "he" was referring to the attacker (as in the featured article), not to the target. Re-reading it now I don't quite see why I was thinking that.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#157

Earlier quoted context omitted.

What sort of agreement can you enter with someone if you don't know who they are? Have you ever walked into a shop, bought some chocolate with cash, and walked out? There you go, legally binding contract of sale, yet the seller has no idea who the buyer was.

Oh all right, I grant you can enter into agreements that the immediately terminate without any need to establish identity. I was hoever not making an argument by induction, so leaving out the trivial case is not crucial to it.

It might help if you gave a couple of example situations that people could answer for.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#158
post #19

This is a reflection of the fact that we have no good way for someone to digitally prove their identity. Some countries are getting close-ish - Denmark's NemID system, for example, is used by a lot of financial institutions. However, there remains no easy way to make ad-hoc verifiable statements like 'I am John Smith and I authorise you to send this data to xyz@example.org'. Governments, please solve this problem! Es…

Latvia's ID cards support e-signing of digital documents, so I could have a pdf "I authorise you to send this data to xyz@example.org" and sign it so that the recipient can securely verify that this was signed by Name Surname ID123. Estonia has it quite similar, I'm not certain if it's technically the same standard or something slightly different.

By EU law it's basically the same.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#159
post #2

This is pretty appalling, really: "Overall, of the 83 firms known to have held data... 24% supplied personal information without verifying the requester's identity." Want someone else's personal data? No need to "hack into" any systems; just ask for it!

From a business’s perspective it's a lot worse to get sued for not complying with GDPR rather than for a side effect of complying with it.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#160

Earlier quoted context omitted.

That is well covered within GDPR scope. Retaining data to fulfill legal obligations is allowed. One common related example is invoice data.

But then "just don't keep the data" is not an effective response to these attacks of requesting someone else's data.

Yes, it requires people to be trained in this area to make these judgements ... imagine that!
Post reply on HN