Live data from Hacker News

Black Hat: GDPR privacy law exploited to reveal personal data

bbc.co.uk

161–170 of 239 posts

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#162
post #152

Earlier quoted context omitted.

Verifying identity is a very hard problem.

That should not lead to an "open by default" policy.

Maybe European regulators should have considered that before writing this law.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#163
post #151

Earlier quoted context omitted.

Can you elaborate by what do you mean with "the whole process"? If you have some internal processes that handle the data, then you can't really separate and outsource the "GDPR part" without outsourcing the whole business process that handles the data - e.g. if you ship goods, then handling of adresses can't (IMHO) be separated from the shipping, if you run a website, then the handling of all the related privacy issu…

The general idea in my head is that instead of each company needing a department to handle GDPR, they outsource the department to the third party. Because of the company's size, I would assume the third party could handle more then one company at a time, lowering costs. Yes this wouldn't solve liability, but it reduces the chance there will be mistakes, like those mentioned in the article.

Yes, that's an option, we have local companies that handle private data protection issues for other companies, that was a thing already pre-GDPR with the earlier data protection legislation but it's now a larger business as the scope has increased.

What they do is somewhat similar to consulting and audit companies - they'll go over your internal processes and/or suggest standard procedures if you don't have any; they'll generally consult with the local data protection authority on particular interpretations and apply them to all their customers, etc. Creating/adapting a procedure for answering customer requests for their data (including the identity verification) would be part of the service; another common service is doing GDPR-policy training for e.g. call center employees. So a thing like that already exists; they won't take over your liability or your processes but they'll review your processes and hand-hold you through any adjustments needed.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#164
post #107
post #19

This is a reflection of the fact that we have no good way for someone to digitally prove their identity. Some countries are getting close-ish - Denmark's NemID system, for example, is used by a lot of financial institutions. However, there remains no easy way to make ad-hoc verifiable statements like 'I am John Smith and I authorise you to send this data to xyz@example.org'. Governments, please solve this problem! Es…

The Netherlands uses DigID, which is effectively a federated identity provider. Problem is that it was originally intended for government use only (recently it's been expanded to include health insurance providers), and it's not accessible for commercial entities. It was also marred by very bureaucratic policies, for example to get information on account usage (e.g. how many times was my account used, from which IP,…

I gather the Dutch company behind DigID, digidentity, is also one of the companies behind UK's "Verify" (used on gov.uk).

Barclays, Post Office Ltd, and Experian are the other options -- if memory serves these 3 all had major security breaches.

I recently had to apply for a criminal records check ("DBS") and the government's DBS (Disclosure and Barring Service) required me to give up all my ID to one of those companies "to identify me" before I could apply; in case someone who was not me was applying for the information.

Aside, it seems they could have allowed anyone to apply (and pay the £25 fee) but only sent the response to a known address, which they could cross check from my tax record and driving license, and ... which details have to be kept current by law.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#165

“Bad implementation of GDPRs information rights” would be the more correct but less clickbaity headline IMHO. The funny twist being that these bad implementations are a GDPR violation too and can be punishable under GDPR.

Even if done correctly, they are just verifying that you bothered to get a photoshopped passport with the targets name in it.

Basically every country needs to run their own PKI for its citizens to even have any hope to legally prove they are who they are. I've so far seen a single well-working solution to the authentication and authorization problem and that is the Estonian ID-card PKI, others are trying to implement it (Finland, Latvia, actually even the EU) but they're basically nearly two decades behind.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#166
post #35

Earlier quoted context omitted.

OP sounds like he was trying hard to navigate and follow the law? The problem is he ended up finding no reasonable solution that both protected his users privacy while also following the rules, and was disturbed by the implications of it all considering it was supposed to protect them in the first place. Those are very valid criticisms. Simply dismissing everyone who shows concern about a law as mere law dodgers or f…

One of the intended goals of GDPR is to reduce the processing of personal data - not only that the companies should do it differently, but that at least half of the companies who currently have my data really shouldn't have it in the first place. It depends on the circumstances of each scenario, but it would be completely reasonable if large numbers of smallish companies acknowledge that they lack the capacity to han…

[deleted]

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#167

Earlier quoted context omitted.

> At least here in Norway you can get a standalone hardware 2-factor key. You can get the key embedded on a smartcard, but it's still coupled to their proprietary driver (which only works on Windows or macOS, of course). It's also a separate API and not as widely supported as Mobile BankID.

Ugh, my Austrian bank is currently trying to force me into using a system like this. The "standard" way is via an Android or iOS app, the "alternative" is via a smartcard reader thing that seems to work with Windows only. They claim that this is mandatory due to some EU regulation, but they conveniently forget to say what regulation that is supposed to be.

It's the Payment Services Directive (PSD2). Username+PW is obsolete and insecure at least 20 years now.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#168
post #26

Earlier quoted context omitted.

> Governments, please solve this problem! I would prefer governments to solve it with competent Software Engineers in the mix and maybe other professionals from the finances and IT security industries, but never one single large entity.

I didn't take that as he wanted legislative representatives and the like to solve it, so much as to make it a matter of focus to enlist the kinds of people you're recommending to provide a solution like this. Personally, I really feel we need a private/public-key kind of system in place for certain things like Social Security Numbers (SSNs) in the US. Such that if a leak also includes an SSN (essentially a public key…

SSN should be just an unique number per person, nothing more, nothing less, never used for identification, only for having an unique number per person. It's impossible to ensure such a number doesn't leak so there also must be 0 consequences in that happening. That would require major legislative change.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#169
post #121

Earlier quoted context omitted.

Some people refer to hypothetical people in stories as the same sex as the person describing the story. I'm not positive, but I imagine the parent is also a "he". I don't consider this important at all, and I think you're being pedantic.

I guess I agree it's a form of pedantry, but once you're a bit used to reading singular "they" (and it's hard to escape nowadays) you get used to it, and the opposite starts looking weird. Also, it's pedantry that seems to actually be socially beneficial: https://www.theguardian.com/science/2019/aug/05/he-she-or-ge... (I don't agree with everything being done for "gender-neutral language", especially in German. But t…

I use non-specific terms like "they" as often as I can, largely because I don't want my audience to be tripped up with superficial distractions. I don't read into other people's wordings with contempt unless I know for certain they're being malicious. I think the saying goes something like... Don't attribute malice where ignorance would suffice...

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#170
post #151

Earlier quoted context omitted.

The general idea in my head is that instead of each company needing a department to handle GDPR, they outsource the department to the third party. Because of the company's size, I would assume the third party could handle more then one company at a time, lowering costs. Yes this wouldn't solve liability, but it reduces the chance there will be mistakes, like those mentioned in the article.

Yes, that's an option, we have local companies that handle private data protection issues for other companies, that was a thing already pre-GDPR with the earlier data protection legislation but it's now a larger business as the scope has increased. What they do is somewhat similar to consulting and audit companies - they'll go over your internal processes and/or suggest standard procedures if you don't have any; they…

I see, thanks for the info!
Post reply on HN