Live data from Hacker News

Black Hat: GDPR privacy law exploited to reveal personal data

bbc.co.uk

191–200 of 239 posts

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#191

Earlier quoted context omitted.

Yeah, there is some weird subtext to the argument, that for some reason account access shouldn't count as secure verification? I guess this all hinges on the idea that to implement GDPR all you need to do is set up an email adress and handle all requests manually, only to then discover that: actually, identity management via plaintext email is a bit tricky.

Yeah, there is some weird subtext to the argument, that for some reason account access shouldn't count as secure verification? It's not in dispute that account access using known good credentials would be reasonable verification. But people forget passwords or mistype email addresses or lose access to email accounts, and they still have legal rights as data subjects under the GDPR. So, it also matters whether other f…

This does seem quite explicit - "If you have some reasonable means of confirming someone's identity in response to a request under GDPR" then you have to use them even if they're not your preferred means. In the scenario proposed above the company wouldn't have to confirm the identity only because they can't.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#192
post #91

Earlier quoted context omitted.

I doubt that a black-hat attacker is going to file a lawsuit to obtain someone else's personal information.

> I doubt that a black-hat attacker is going to file a lawsuit If you tell someone requesting their own data under GDPR “tough luck, you lost your password,” that could invite remedies under the law.

What are they going to sue for? "I can’t identify myself but still want the data of some random person I claim to be"?

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#193
post #188

Earlier quoted context omitted.

How is that not a problem with GDPR? They passed a law which relies on technology which does not exist. There is no way to safely and reliably identify an individual electronically.

Unless you live in Estonia, where each citizen has a private key (on a smart card) and can electronically sign things to prove identity. Governments could work with big tech players to confirm that certain Gmail/Facebook accounts are linked to one, and only one, national identity. Then through OAuth, you could use that to login anywhere else, proving you are a real person with exactly one ID (which needen't be reveal…

Too bad the rest of the EU doesn't live in Estonia, it would have made GDPR much better.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#194

Earlier quoted context omitted.

My point is that BankID should have something similar for any BankID action.

It wouldn't work, because services using BankID want a (presumably contractually-obligated) assurance that only that particular person is using the service. If someone else can be authorised use your ID, it undermines that. They could still add such a feature of course, but they would need to inform and have the co-operation of services when someone else is using the ID, so it wouldn't be widely supported.

It would be awesome if the could do it like:

Person A initiates and signs request to delegate for Person B. Person B receives the delegation request and signs it, which produces a positive response. The response (containing Person B's signature= is then 'wrapped' in Person A's request and is only sent on the to destination.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#195
post #184

Earlier quoted context omitted.

Yes, it's officially supported by providing everyone the possibility to sign documents with it. It was made an EU-wide standard in 2016 https://www.etsi.org/deliver/etsi_en/319100_319199/31916201/... but previous iterations have existed since 2002. The person you replied to is pretty much right, Estonian ID-card has solved 99.99% of authentication and signing problems for it's citizens, the support is mandated by law…

Flaws like this? https://arstechnica.com/information-technology/2017/10/crypt... I support such uses of smartcards, but we have to be disciplined regarding our assumptions about non-repudiation.

I'd rather not start compiling a list of password-username database thefts, credential stuffings, identity thefts, forged paper signatures, the time lost to inefficient paper procedures, secrets stolen due to how hard it is to encrypt things etc. etc. etc.

Of course we have to be disciplined, but other things can't even remotely reach the security such a solution provides. Your comment has very FUD-y undertones, rising concern about a very minor thing if you actually look at how much it solves and how much better it is compared to other widespread applications.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#196
post #193

Earlier quoted context omitted.

Unless you live in Estonia, where each citizen has a private key (on a smart card) and can electronically sign things to prove identity. Governments could work with big tech players to confirm that certain Gmail/Facebook accounts are linked to one, and only one, national identity. Then through OAuth, you could use that to login anywhere else, proving you are a real person with exactly one ID (which needen't be reveal…

Too bad the rest of the EU doesn't live in Estonia, it would have made GDPR much better.

In my country (Oz) we had a referendum a few decades back about a national ID card, which failed to pass. I for one am against any form of centralised ID system. The basic premise (of the time) was, "if you want to know me, here I am". The government department of Birth, Deaths and Marriages goes to some lengths to ensure that these 3 things are not tied to any one number. Ironically, the government got what it wanted when it introduced a Tax File Number and has bled into some other systems like banking, but thankfully it's not as bad as the U.S's SSN.

I seem to recall reading here on HN a few weeks back how surnames came into existence: it was because the (? Italian) government wanted to track taxes. Before that everyone had several ways of naming themselves: John, John son of Joe, John of someplace, John the carpenter, etc. Personally, I really like that because I'm not just "one thing", but am a person who has different aspects.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#197

Earlier quoted context omitted.

> No. This is a problem that was intentionally caused by Finansiell ID-teknik, and I'm not going to get into cat-and-mouse game to fix their for-profit product. You're - literally - on "Hacker News" complaining about the lack of a product. You were given one that you could easily fix to suit your aforementioned needs/demands and was a principal complaint against BankId but, instead, you want BankId to write the Linux…

> You're - literally - on "Hacker News" complaining about the lack of a product. You were given one that you could easily fix to suit your aforementioned needs/demands and was a principal complaint against BankId but, instead, you want BankId to write the Linux app for you because... ...profits? This makes no sense; especially, when you would already have a hefty baseline of code to work with. That's like saying jail…

>You won't get lasting improvement without changing the mindset of the powers that be.

I'm confused: Do you believe that whining about it on HN will accomplish that?

>You're saying service developers can put in the work to support both desktop and mobile BankID. I'm saying most of them are lazy and don't bother. Those two statements are not incompatible.

I am, am I? I thought I was saying that you're being assumptive because that's actually what I was saying: You're equating a potential to an emphatic and it doesn't work that way.

>Similar and compatible are very different things.

Now you're just being obtuse and ignoring the entire premise that they're the same - much less have you decidedly chosen whether it matters or not.

>Then again, this whole subdiscussion is irrelevant anyway...

Then why are you replying to it? I think she doth protest too much!

>If BankID had spent more than two seconds designing their API boundaries then the app developers wouldn't have had to care about supporting both in the first place.

According to you, they did design their API boundaries because they're "different APIs". As a byproduct, they must've spent more than two-second designing it to accomplish that, yeah?

The mental gymnastics you're performing must be tiring. I feel for you, I really do.

I do have to concede that you are correct in one point: The whole sub-discussion is irrelevant, namely because your opinion is obviously in the minority and you can't maintain a static viewpoint on anything so far - except to say "bankid sucks"; which isn't substantive.

If you ever change your mind about fixing your problem, I believe this might help in that endeavour:

https://www.bankid.com/assets/bankid/rp/bankid-relying-party...

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#198

“Bad implementation of GDPRs information rights” would be the more correct but less clickbaity headline IMHO. The funny twist being that these bad implementations are a GDPR violation too and can be punishable under GDPR.

The funny twist is that it seems pretty hard/even impossible to handle GDPR laws and could be punishable under GDPR to have enough verification.

All you know about a user is its name. How can you verify someone identity while still not being "overly burdensome" (which is required by GDPR)?

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#199
Can anyone here who's experienced with GDPR's provisions talk about the extent any given company is allowed to go to verify the identity of someone requesting information?

I'd hate it if someone pulls a "I'd like to be forgotten" request on me without said organization absolutely verifying my identity. If would seem that if they complied, they wouldn't be able to undo the operation...

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#200
post #193

Earlier quoted context omitted.

Too bad the rest of the EU doesn't live in Estonia, it would have made GDPR much better.

In my country (Oz) we had a referendum a few decades back about a national ID card, which failed to pass. I for one am against any form of centralised ID system. The basic premise (of the time) was, "if you want to know me, here I am". The government department of Birth, Deaths and Marriages goes to some lengths to ensure that these 3 things are not tied to any one number. Ironically, the government got what it wante…

You reap what you sow unfortunately. The fact is that the government still keeps track of you but you just have a boatload of downsides by not having a proper system citizens can use.
Post reply on HN