Earlier quoted context omitted.
That should not lead to an "open by default" policy.
Maybe European regulators should have considered that before writing this law.
Black Hat: GDPR privacy law exploited to reveal personal data
201–210 of 239 posts
Re: Black Hat: GDPR privacy law exploited to reveal personal data
#202Earlier quoted context omitted.
Nope, that's not legally safe -- we've been told by data authorities that the verification methods cannot be "overly burdensome" to the data subject. I live in dread of subject access requests (and thankfully have only had one, and it happened to be really easy to verify).
IIRC they also allow charging the person - for a "reasonable" amount - for the data retrieval process (which I assume would include the "identity verification" part). Maybe using the 3-D Secure protocol (especially the second revision) would be enough to unburden yourself for verifying the identity as Mastercard/Visa/American Express supposedly check it for you. This would work only in some conditions (the data subje…
Re: Black Hat: GDPR privacy law exploited to reveal personal data
#203Earlier quoted context omitted.
One of the major goals of GDPR is to discourage firms from retaining personal data in the first place. It did not used to cost them anything so they kept it regardless of its use. Now that there are big risks to keeping it these firms have to think twice about it. This "cobra effect" is one more reason NOT to retain personal information in the first place.
This does nothing to discourage keeping data around. A company does not care if they, while following best-effort GDPR practice, release data to a hacker that causes harm to a user. They can simply hide behind the GDPR legislation to say “we did nothing wrong, the law is broken, we were trying our best, we accept no liability”
Re: Black Hat: GDPR privacy law exploited to reveal personal data
#204Earlier quoted context omitted.
This is not a problem with GDPR. This is a problem with organizations (companies and governments) treating publicly data as private keys.
Moreover, it's a problem with the current state of "identity" as a whole. Most of the data received in the article - passports, addresses, phone numbers, credit cards - does not change very often. Some documents expire, but even then it could be valid for another 3 - 10 years. We need to move to a system that allows rapid expiry of PII data. Then it will not matter if someone is able to social engineer this data from…
Re: Black Hat: GDPR privacy law exploited to reveal personal data
#205Earlier quoted context omitted.
Too bad the rest of the EU doesn't live in Estonia, it would have made GDPR much better.
In my country (Oz) we had a referendum a few decades back about a national ID card, which failed to pass. I for one am against any form of centralised ID system. The basic premise (of the time) was, "if you want to know me, here I am". The government department of Birth, Deaths and Marriages goes to some lengths to ensure that these 3 things are not tied to any one number. Ironically, the government got what it wante…
Re: Black Hat: GDPR privacy law exploited to reveal personal data
#206This is horrible. So right now, in order to get access to data for a certain person, you need to hack your way through a few of the potential services he is using and drive from there. 1. The data might have things like IDs (ie: Crypto exchanges). 2. You can use that data to ask for more data. If you got a copy of his passport, now you can ask for more with this new piece. 3. Looks like some people still store passwo…
One of the major goals of GDPR is to discourage firms from retaining personal data in the first place. It did not used to cost them anything so they kept it regardless of its use. Now that there are big risks to keeping it these firms have to think twice about it. This "cobra effect" is one more reason NOT to retain personal information in the first place.
A site could easily be compliant by answering general questions (this is what kind of data we have, this is how we collect it, this is what we need it for, this is our legal basis) via e-mail but requiring data exports to be performed via the site itself.
The GDPR actually encourages sites to provide automated self-serve data export mechanisms. The entire point of being able to request a copy of your data is data portability.
"But what if the user never signed up?", I hear some people ask. Why did you collect their data in the first place? If you collect sensitive data like that described in the BBC article, you better have explicit consent and if you have explicit verifiable consent, you should be able to verify a request is made using the same identity that granted the consent (be it an e-mail, a phone call or a signature). So just ask for that again.
Also, if you can't easily comply with a data request because the data is so sensitive and the identity can't easily be verified, you can still explicitly say so. Describe the kind of data you have and offer to delete it, then offer whatever form of authentication is adequate given the level of sensitivity of the data in question should they still demand it.
I'm not sure why some people seem to think this is particularly unreasonable. Just because it isn't code, doesn't mean you have to reinvent authentication from scratch. Think of how you identify someone before you agree to store their data. You already do that for all other business processes, why should data requests be any different?
EDIT: Also if you figure you can't easily verify someone's identity after you took their data, that sounds like a good reason not to take their data in the first place. And that's the entire point of the GDPR: minimising personal data. The GDPR makes personal data toxic and that's intentional. Just like toxic substances you need special precautions for handling and storing it, and you probably want to avoid both unless absolutely necessary.
Re: Black Hat: GDPR privacy law exploited to reveal personal data
#207Earlier quoted context omitted.
One of the major goals of GDPR is to discourage firms from retaining personal data in the first place. It did not used to cost them anything so they kept it regardless of its use. Now that there are big risks to keeping it these firms have to think twice about it. This "cobra effect" is one more reason NOT to retain personal information in the first place.
I'll let you in on a secret. For government institutions which in general have huge amounts of information about you and are notoriously bad at security. They don't even get fined with the GDPR. The worst that can happen to them is bad press. So the institution that has all the healthcare data of all German citizens can not get fined under the GDPR. Same with any other KdöR https://de.wikipedia.org/wiki/K%C3%B6rpersc…
Yes, you're simply wrong. Government agencies do not have a blanket exemption from GDPR rules. There are some difference, and EU countries have some autonomy in the particulars. But as a general principle, the rules are the same: data may only be stored to fulfil a valid purpose, processing and transmission require consent, etc.
Fines don't make any sense in that regard because the government is never fined: first, because it wouldn't make much sense, as fines are payable to that very government anyway. But also because government officials are simply expected to respect court verdicts without the neccessity of fines.
If you don't trust that system you're out of luck, because it's how every single other protection you have against the government is and has been enforced since the inception of "the rule of law".
Re: Black Hat: GDPR privacy law exploited to reveal personal data
#208Earlier quoted context omitted.
Government officials created an untenable law in the name of the technological boogey man?!
Not bogey. Misuse of personal days it's happening daily, but the law is not exactly super great. Better than nothing I suppose.
Re: Black Hat: GDPR privacy law exploited to reveal personal data
#209Earlier quoted context omitted.
This was actually one of the risks we identified when looking at GDPR for my own businesses last year. Given that in some cases all we have is an online account with minimal personal details, how can we possibly verify their identity to an acceptable standard if someone does send us a GDPR subject access request of any kind? If they have some sort of account with us already and that has associated ID and security che…
One option would be to evaluate if it would be safe to delete the data. In that case you could offer to delete the data. Countries typically have some expensive way to proof identity. So, delete or actually proof who you are. Of course, sending a message to, say, a know email address that to intent to do that helps avoiding angry customers. If you cannot delete the data because it is valuable to the customer, then ju…
Re: Black Hat: GDPR privacy law exploited to reveal personal data
#210Earlier quoted context omitted.
Those just analyze photos for photoshop artifacts for a CYA receipt. They don't verify that the ID info is real. That's next to useless under identity fraud / attacks any more sophisticated than MS Paint level skills. You're severely underplaying how easy it is to fake documentation and the attacks it enables.
I had to verify my identity for an online service a while back. They used a third party company that has a mobile phone app essentially for video conferencing; you then call this company via the app and talk to them. They ask you to show your face and move around and to show your ID, including moving it around so they can check that the security hologram (this was an EU passport) is indeed one. So for this kind of ch…