Earlier quoted context omitted.
Yeah, there is some weird subtext to the argument, that for some reason account access shouldn't count as secure verification? I guess this all hinges on the idea that to implement GDPR all you need to do is set up an email adress and handle all requests manually, only to then discover that: actually, identity management via plaintext email is a bit tricky.
Yeah, there is some weird subtext to the argument, that for some reason account access shouldn't count as secure verification? It's not in dispute that account access using known good credentials would be reasonable verification. But people forget passwords or mistype email addresses or lose access to email accounts, and they still have legal rights as data subjects under the GDPR. So, it also matters whether other f…
Black Hat: GDPR privacy law exploited to reveal personal data
191–200 of 239 posts
Re: Black Hat: GDPR privacy law exploited to reveal personal data
#192Earlier quoted context omitted.
I doubt that a black-hat attacker is going to file a lawsuit to obtain someone else's personal information.
> I doubt that a black-hat attacker is going to file a lawsuit If you tell someone requesting their own data under GDPR “tough luck, you lost your password,” that could invite remedies under the law.
Re: Black Hat: GDPR privacy law exploited to reveal personal data
#193Earlier quoted context omitted.
How is that not a problem with GDPR? They passed a law which relies on technology which does not exist. There is no way to safely and reliably identify an individual electronically.
Unless you live in Estonia, where each citizen has a private key (on a smart card) and can electronically sign things to prove identity. Governments could work with big tech players to confirm that certain Gmail/Facebook accounts are linked to one, and only one, national identity. Then through OAuth, you could use that to login anywhere else, proving you are a real person with exactly one ID (which needen't be reveal…
Re: Black Hat: GDPR privacy law exploited to reveal personal data
#194Earlier quoted context omitted.
My point is that BankID should have something similar for any BankID action.
It wouldn't work, because services using BankID want a (presumably contractually-obligated) assurance that only that particular person is using the service. If someone else can be authorised use your ID, it undermines that. They could still add such a feature of course, but they would need to inform and have the co-operation of services when someone else is using the ID, so it wouldn't be widely supported.
Person A initiates and signs request to delegate for Person B. Person B receives the delegation request and signs it, which produces a positive response. The response (containing Person B's signature= is then 'wrapped' in Person A's request and is only sent on the to destination.
Re: Black Hat: GDPR privacy law exploited to reveal personal data
#195Earlier quoted context omitted.
Yes, it's officially supported by providing everyone the possibility to sign documents with it. It was made an EU-wide standard in 2016 https://www.etsi.org/deliver/etsi_en/319100_319199/31916201/... but previous iterations have existed since 2002. The person you replied to is pretty much right, Estonian ID-card has solved 99.99% of authentication and signing problems for it's citizens, the support is mandated by law…
Flaws like this? https://arstechnica.com/information-technology/2017/10/crypt... I support such uses of smartcards, but we have to be disciplined regarding our assumptions about non-repudiation.
Of course we have to be disciplined, but other things can't even remotely reach the security such a solution provides. Your comment has very FUD-y undertones, rising concern about a very minor thing if you actually look at how much it solves and how much better it is compared to other widespread applications.
Re: Black Hat: GDPR privacy law exploited to reveal personal data
#196Earlier quoted context omitted.
Unless you live in Estonia, where each citizen has a private key (on a smart card) and can electronically sign things to prove identity. Governments could work with big tech players to confirm that certain Gmail/Facebook accounts are linked to one, and only one, national identity. Then through OAuth, you could use that to login anywhere else, proving you are a real person with exactly one ID (which needen't be reveal…
Too bad the rest of the EU doesn't live in Estonia, it would have made GDPR much better.
I seem to recall reading here on HN a few weeks back how surnames came into existence: it was because the (? Italian) government wanted to track taxes. Before that everyone had several ways of naming themselves: John, John son of Joe, John of someplace, John the carpenter, etc. Personally, I really like that because I'm not just "one thing", but am a person who has different aspects.
Re: Black Hat: GDPR privacy law exploited to reveal personal data
#197Earlier quoted context omitted.
> No. This is a problem that was intentionally caused by Finansiell ID-teknik, and I'm not going to get into cat-and-mouse game to fix their for-profit product. You're - literally - on "Hacker News" complaining about the lack of a product. You were given one that you could easily fix to suit your aforementioned needs/demands and was a principal complaint against BankId but, instead, you want BankId to write the Linux…
> You're - literally - on "Hacker News" complaining about the lack of a product. You were given one that you could easily fix to suit your aforementioned needs/demands and was a principal complaint against BankId but, instead, you want BankId to write the Linux app for you because... ...profits? This makes no sense; especially, when you would already have a hefty baseline of code to work with. That's like saying jail…
I'm confused: Do you believe that whining about it on HN will accomplish that?
>You're saying service developers can put in the work to support both desktop and mobile BankID. I'm saying most of them are lazy and don't bother. Those two statements are not incompatible.
I am, am I? I thought I was saying that you're being assumptive because that's actually what I was saying: You're equating a potential to an emphatic and it doesn't work that way.
>Similar and compatible are very different things.
Now you're just being obtuse and ignoring the entire premise that they're the same - much less have you decidedly chosen whether it matters or not.
>Then again, this whole subdiscussion is irrelevant anyway...
Then why are you replying to it? I think she doth protest too much!
>If BankID had spent more than two seconds designing their API boundaries then the app developers wouldn't have had to care about supporting both in the first place.
According to you, they did design their API boundaries because they're "different APIs". As a byproduct, they must've spent more than two-second designing it to accomplish that, yeah?
The mental gymnastics you're performing must be tiring. I feel for you, I really do.
I do have to concede that you are correct in one point: The whole sub-discussion is irrelevant, namely because your opinion is obviously in the minority and you can't maintain a static viewpoint on anything so far - except to say "bankid sucks"; which isn't substantive.
If you ever change your mind about fixing your problem, I believe this might help in that endeavour:
https://www.bankid.com/assets/bankid/rp/bankid-relying-party...
Re: Black Hat: GDPR privacy law exploited to reveal personal data
#198“Bad implementation of GDPRs information rights” would be the more correct but less clickbaity headline IMHO. The funny twist being that these bad implementations are a GDPR violation too and can be punishable under GDPR.
All you know about a user is its name. How can you verify someone identity while still not being "overly burdensome" (which is required by GDPR)?
Re: Black Hat: GDPR privacy law exploited to reveal personal data
#199I'd hate it if someone pulls a "I'd like to be forgotten" request on me without said organization absolutely verifying my identity. If would seem that if they complied, they wouldn't be able to undo the operation...
Re: Black Hat: GDPR privacy law exploited to reveal personal data
#200Earlier quoted context omitted.
Too bad the rest of the EU doesn't live in Estonia, it would have made GDPR much better.
In my country (Oz) we had a referendum a few decades back about a national ID card, which failed to pass. I for one am against any form of centralised ID system. The basic premise (of the time) was, "if you want to know me, here I am". The government department of Birth, Deaths and Marriages goes to some lengths to ensure that these 3 things are not tied to any one number. Ironically, the government got what it wante…