Live data from Hacker News

Black Hat: GDPR privacy law exploited to reveal personal data

bbc.co.uk

201–210 of 239 posts

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#201
post #152

Earlier quoted context omitted.

That should not lead to an "open by default" policy.

Maybe European regulators should have considered that before writing this law.

They did by writing the eIDAS regulation.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#202

Earlier quoted context omitted.

Nope, that's not legally safe -- we've been told by data authorities that the verification methods cannot be "overly burdensome" to the data subject. I live in dread of subject access requests (and thankfully have only had one, and it happened to be really easy to verify).

IIRC they also allow charging the person - for a "reasonable" amount - for the data retrieval process (which I assume would include the "identity verification" part). Maybe using the 3-D Secure protocol (especially the second revision) would be enough to unburden yourself for verifying the identity as Mastercard/Visa/American Express supposedly check it for you. This would work only in some conditions (the data subje…

Just as a fun tidbit, I've grown accustomed to using Estonia's banklinks, and then like approx. 10 years after that the 3D-secure system starts appearing on foreign sites that almost provides the same functionality - it's nice to see finally some steps taken but damn, it's basically 20 years behind what everyone could have had.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#203
post #52

Earlier quoted context omitted.

One of the major goals of GDPR is to discourage firms from retaining personal data in the first place. It did not used to cost them anything so they kept it regardless of its use. Now that there are big risks to keeping it these firms have to think twice about it. This "cobra effect" is one more reason NOT to retain personal information in the first place.

This does nothing to discourage keeping data around. A company does not care if they, while following best-effort GDPR practice, release data to a hacker that causes harm to a user. They can simply hide behind the GDPR legislation to say “we did nothing wrong, the law is broken, we were trying our best, we accept no liability”

Disclosing data to an individual because you make no attempts to verify their identity is in itself a GDPR violation. As far as the GDPR is concerned it doesn't matter whether you were hacked or whether your employees recklessly exposed information to individuals. The only difference is scale and scope.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#204
post #90

Earlier quoted context omitted.

This is not a problem with GDPR. This is a problem with organizations (companies and governments) treating publicly data as private keys.

Moreover, it's a problem with the current state of "identity" as a whole. Most of the data received in the article - passports, addresses, phone numbers, credit cards - does not change very often. Some documents expire, but even then it could be valid for another 3 - 10 years. We need to move to a system that allows rapid expiry of PII data. Then it will not matter if someone is able to social engineer this data from…

I had a thought awhile back. In the vast majority of uses, identity is exactly the issue. Yet in the vast majority of compromises or problems, the problem is correlation and combination of data. By this I mean it seems to me that, say, the Social Security Administration needs to be able to identify a citizen in order to know whether and how much they need to pay a person of a certain identity to avoid paying the wrong amount, the wrong person, double-paying, etc. There does not need to exist an identity which spreads beyond that. Your credit card company does not need to use the same identity and a unique identity which functions solely within the context of the credit card account is all that is needed. Instead, we have identities that get spread across multiple services even though there is never any actual need to relate or correlate the activity across those services. This seems like the sort of situation that cryptography can solve, although obviously there would be a lot of usability work to be done. But it seems to me that cryptographically unrelatable distinct identities which has only 1 possible point of aggregation (you) is what is needed.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#205
post #193

Earlier quoted context omitted.

Too bad the rest of the EU doesn't live in Estonia, it would have made GDPR much better.

In my country (Oz) we had a referendum a few decades back about a national ID card, which failed to pass. I for one am against any form of centralised ID system. The basic premise (of the time) was, "if you want to know me, here I am". The government department of Birth, Deaths and Marriages goes to some lengths to ensure that these 3 things are not tied to any one number. Ironically, the government got what it wante…

Any centralized identity system solves a problem we don't have. It doesn't simply serve to identify a person. It serves to aggregate an identity and tie together extremely disparate and unrelated data. It enables a data leak or abuse to not just compromise one service, but all of them at once. If there is a leak of data from, say, a dating site that involves dumping the public keys of the users alongside the user activity associated with it, then the credit card company and electric company and water company and the gaming forum you signed up for and multitudes of other utterly unrelated organizations now have the ability to correlate your dating activity with your activity on their service. The identities on all of those separate systems being the same identity is the problem a centralized system solves. And it's a problem we have never had.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#206
post #17

This is horrible. So right now, in order to get access to data for a certain person, you need to hack your way through a few of the potential services he is using and drive from there. 1. The data might have things like IDs (ie: Crypto exchanges). 2. You can use that data to ask for more data. If you got a copy of his passport, now you can ask for more with this new piece. 3. Looks like some people still store passwo…

One of the major goals of GDPR is to discourage firms from retaining personal data in the first place. It did not used to cost them anything so they kept it regardless of its use. Now that there are big risks to keeping it these firms have to think twice about it. This "cobra effect" is one more reason NOT to retain personal information in the first place.

I'm not sure why everybody here seems to think that sites need to fork over all date they have on store via e-mail if a registered user requests it via e-mail.

A site could easily be compliant by answering general questions (this is what kind of data we have, this is how we collect it, this is what we need it for, this is our legal basis) via e-mail but requiring data exports to be performed via the site itself.

The GDPR actually encourages sites to provide automated self-serve data export mechanisms. The entire point of being able to request a copy of your data is data portability.

"But what if the user never signed up?", I hear some people ask. Why did you collect their data in the first place? If you collect sensitive data like that described in the BBC article, you better have explicit consent and if you have explicit verifiable consent, you should be able to verify a request is made using the same identity that granted the consent (be it an e-mail, a phone call or a signature). So just ask for that again.

Also, if you can't easily comply with a data request because the data is so sensitive and the identity can't easily be verified, you can still explicitly say so. Describe the kind of data you have and offer to delete it, then offer whatever form of authentication is adequate given the level of sensitivity of the data in question should they still demand it.

I'm not sure why some people seem to think this is particularly unreasonable. Just because it isn't code, doesn't mean you have to reinvent authentication from scratch. Think of how you identify someone before you agree to store their data. You already do that for all other business processes, why should data requests be any different?

EDIT: Also if you figure you can't easily verify someone's identity after you took their data, that sounds like a good reason not to take their data in the first place. And that's the entire point of the GDPR: minimising personal data. The GDPR makes personal data toxic and that's intentional. Just like toxic substances you need special precautions for handling and storing it, and you probably want to avoid both unless absolutely necessary.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#207

Earlier quoted context omitted.

One of the major goals of GDPR is to discourage firms from retaining personal data in the first place. It did not used to cost them anything so they kept it regardless of its use. Now that there are big risks to keeping it these firms have to think twice about it. This "cobra effect" is one more reason NOT to retain personal information in the first place.

I'll let you in on a secret. For government institutions which in general have huge amounts of information about you and are notoriously bad at security. They don't even get fined with the GDPR. The worst that can happen to them is bad press. So the institution that has all the healthcare data of all German citizens can not get fined under the GDPR. Same with any other KdöR https://de.wikipedia.org/wiki/K%C3%B6rpersc…

> weird, any explanation for the downvotes?

Yes, you're simply wrong. Government agencies do not have a blanket exemption from GDPR rules. There are some difference, and EU countries have some autonomy in the particulars. But as a general principle, the rules are the same: data may only be stored to fulfil a valid purpose, processing and transmission require consent, etc.

Fines don't make any sense in that regard because the government is never fined: first, because it wouldn't make much sense, as fines are payable to that very government anyway. But also because government officials are simply expected to respect court verdicts without the neccessity of fines.

If you don't trust that system you're out of luck, because it's how every single other protection you have against the government is and has been enforced since the inception of "the rule of law".

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#208

Earlier quoted context omitted.

Government officials created an untenable law in the name of the technological boogey man?!

Not bogey. Misuse of personal days it's happening daily, but the law is not exactly super great. Better than nothing I suppose.

I think whether the current implementation of GDPR is better than nothing is still up for debate. The intention is mostly good, but the execution leaves an immense amount to be desired (as evidenced by common threads like this) and disproportionately affects/burdens small businesses.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#209
post #29

Earlier quoted context omitted.

This was actually one of the risks we identified when looking at GDPR for my own businesses last year. Given that in some cases all we have is an online account with minimal personal details, how can we possibly verify their identity to an acceptable standard if someone does send us a GDPR subject access request of any kind? If they have some sort of account with us already and that has associated ID and security che…

One option would be to evaluate if it would be safe to delete the data. In that case you could offer to delete the data. Countries typically have some expensive way to proof identity. So, delete or actually proof who you are. Of course, sending a message to, say, a know email address that to intent to do that helps avoiding angry customers. If you cannot delete the data because it is valuable to the customer, then ju…

"Hi, I'd like to request all my user data under the username phicoh." --> "I've forgotten the password to my account; would you just delete it instead then?"

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#210

Earlier quoted context omitted.

Those just analyze photos for photoshop artifacts for a CYA receipt. They don't verify that the ID info is real. That's next to useless under identity fraud / attacks any more sophisticated than MS Paint level skills. You're severely underplaying how easy it is to fake documentation and the attacks it enables.

I had to verify my identity for an online service a while back. They used a third party company that has a mobile phone app essentially for video conferencing; you then call this company via the app and talk to them. They ask you to show your face and move around and to show your ID, including moving it around so they can check that the security hologram (this was an EU passport) is indeed one. So for this kind of ch…

This sounds like something vulnerable to real-time deepfakes in the very near future.
Post reply on HN