Black Hat: GDPR privacy law exploited to reveal personal data
161–170 of 239 posts
Re: Black Hat: GDPR privacy law exploited to reveal personal data
#162Re: Black Hat: GDPR privacy law exploited to reveal personal data
#163Earlier quoted context omitted.
Can you elaborate by what do you mean with "the whole process"? If you have some internal processes that handle the data, then you can't really separate and outsource the "GDPR part" without outsourcing the whole business process that handles the data - e.g. if you ship goods, then handling of adresses can't (IMHO) be separated from the shipping, if you run a website, then the handling of all the related privacy issu…
The general idea in my head is that instead of each company needing a department to handle GDPR, they outsource the department to the third party. Because of the company's size, I would assume the third party could handle more then one company at a time, lowering costs. Yes this wouldn't solve liability, but it reduces the chance there will be mistakes, like those mentioned in the article.
What they do is somewhat similar to consulting and audit companies - they'll go over your internal processes and/or suggest standard procedures if you don't have any; they'll generally consult with the local data protection authority on particular interpretations and apply them to all their customers, etc. Creating/adapting a procedure for answering customer requests for their data (including the identity verification) would be part of the service; another common service is doing GDPR-policy training for e.g. call center employees. So a thing like that already exists; they won't take over your liability or your processes but they'll review your processes and hand-hold you through any adjustments needed.
Re: Black Hat: GDPR privacy law exploited to reveal personal data
#164This is a reflection of the fact that we have no good way for someone to digitally prove their identity. Some countries are getting close-ish - Denmark's NemID system, for example, is used by a lot of financial institutions. However, there remains no easy way to make ad-hoc verifiable statements like 'I am John Smith and I authorise you to send this data to xyz@example.org'. Governments, please solve this problem! Es…
The Netherlands uses DigID, which is effectively a federated identity provider. Problem is that it was originally intended for government use only (recently it's been expanded to include health insurance providers), and it's not accessible for commercial entities. It was also marred by very bureaucratic policies, for example to get information on account usage (e.g. how many times was my account used, from which IP,…
Barclays, Post Office Ltd, and Experian are the other options -- if memory serves these 3 all had major security breaches.
I recently had to apply for a criminal records check ("DBS") and the government's DBS (Disclosure and Barring Service) required me to give up all my ID to one of those companies "to identify me" before I could apply; in case someone who was not me was applying for the information.
Aside, it seems they could have allowed anyone to apply (and pay the £25 fee) but only sent the response to a known address, which they could cross check from my tax record and driving license, and ... which details have to be kept current by law.
Re: Black Hat: GDPR privacy law exploited to reveal personal data
#165“Bad implementation of GDPRs information rights” would be the more correct but less clickbaity headline IMHO. The funny twist being that these bad implementations are a GDPR violation too and can be punishable under GDPR.
Even if done correctly, they are just verifying that you bothered to get a photoshopped passport with the targets name in it.
Re: Black Hat: GDPR privacy law exploited to reveal personal data
#166Earlier quoted context omitted.
OP sounds like he was trying hard to navigate and follow the law? The problem is he ended up finding no reasonable solution that both protected his users privacy while also following the rules, and was disturbed by the implications of it all considering it was supposed to protect them in the first place. Those are very valid criticisms. Simply dismissing everyone who shows concern about a law as mere law dodgers or f…
One of the intended goals of GDPR is to reduce the processing of personal data - not only that the companies should do it differently, but that at least half of the companies who currently have my data really shouldn't have it in the first place. It depends on the circumstances of each scenario, but it would be completely reasonable if large numbers of smallish companies acknowledge that they lack the capacity to han…
Re: Black Hat: GDPR privacy law exploited to reveal personal data
#167Earlier quoted context omitted.
> At least here in Norway you can get a standalone hardware 2-factor key. You can get the key embedded on a smartcard, but it's still coupled to their proprietary driver (which only works on Windows or macOS, of course). It's also a separate API and not as widely supported as Mobile BankID.
Ugh, my Austrian bank is currently trying to force me into using a system like this. The "standard" way is via an Android or iOS app, the "alternative" is via a smartcard reader thing that seems to work with Windows only. They claim that this is mandatory due to some EU regulation, but they conveniently forget to say what regulation that is supposed to be.
Re: Black Hat: GDPR privacy law exploited to reveal personal data
#168Earlier quoted context omitted.
> Governments, please solve this problem! I would prefer governments to solve it with competent Software Engineers in the mix and maybe other professionals from the finances and IT security industries, but never one single large entity.
I didn't take that as he wanted legislative representatives and the like to solve it, so much as to make it a matter of focus to enlist the kinds of people you're recommending to provide a solution like this. Personally, I really feel we need a private/public-key kind of system in place for certain things like Social Security Numbers (SSNs) in the US. Such that if a leak also includes an SSN (essentially a public key…
Re: Black Hat: GDPR privacy law exploited to reveal personal data
#169Earlier quoted context omitted.
Some people refer to hypothetical people in stories as the same sex as the person describing the story. I'm not positive, but I imagine the parent is also a "he". I don't consider this important at all, and I think you're being pedantic.
I guess I agree it's a form of pedantry, but once you're a bit used to reading singular "they" (and it's hard to escape nowadays) you get used to it, and the opposite starts looking weird. Also, it's pedantry that seems to actually be socially beneficial: https://www.theguardian.com/science/2019/aug/05/he-she-or-ge... (I don't agree with everything being done for "gender-neutral language", especially in German. But t…
Re: Black Hat: GDPR privacy law exploited to reveal personal data
#170Earlier quoted context omitted.
The general idea in my head is that instead of each company needing a department to handle GDPR, they outsource the department to the third party. Because of the company's size, I would assume the third party could handle more then one company at a time, lowering costs. Yes this wouldn't solve liability, but it reduces the chance there will be mistakes, like those mentioned in the article.
Yes, that's an option, we have local companies that handle private data protection issues for other companies, that was a thing already pre-GDPR with the earlier data protection legislation but it's now a larger business as the scope has increased. What they do is somewhat similar to consulting and audit companies - they'll go over your internal processes and/or suggest standard procedures if you don't have any; they…