Live data from Hacker News

Black Hat: GDPR privacy law exploited to reveal personal data

bbc.co.uk

211–220 of 239 posts

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#211
A lot of the risk of this kind of thing could be greatly reduced if the law were changed so that for data that you should already have about yourself the company only has to tell you whether they have that data.

For example, I know my birth date. A company that also has my birth date should be able to just tell me that they have my birth date. They should not have to tell me the actual date.

Most of the data mentioned in the article is like this: credit card information, login and password information, social security number, stays in hotels, train journeys, high school grades, and maiden name.

Companies like credit reporting agencies that keep such data and share it with others would need to be an exception, so that you could check that they aren't giving out incorrect information about you.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#212

Earlier quoted context omitted.

Verifying identity is a very hard problem.

Understood, but: So, when one train operator asked for a photocopy of a passport, he convinced it instead to accept a postmarked envelope addressed to the "victim". A postmarked envelope? This is baffling to me.

The art of social engineering. The person doing this was a dab-hand at it or else they would not have done what they did.

You can have a plausible excuse for not having your passport - left at parent's house or accidentally in storage.

Driver's license - "I am a cyclist!"

Electricity bill - "My housemate pays all the bills!"

Bank statement - "I only do online banking!"

Electoral roll? - "Don't vote!"

But HR sent me a letter about an update to the company pension plan - will that do?

Yes! - sends through postmarked envelope picture. By that stage the confidence trick has succeeded so 'we know the guy and he is legit'.

You can get this far to get a mobile phone contract which counts as good as a utility bill in terms of supplementary proof of ID. This can then be used to get a deposit only bank account for 'savings'. This can then be just about enough ID to have almost created a person!!!

But with GDPR social engineering you can have it all so much easier.

There was so much panic about GDPR and purging every decent contact from the company newsletter list that no company thought through a thing about how to deal with GDPR information requests. Hubris at its finest.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#213
post #5

> "But the kind of mid-sized businesses that knew about GDPR, but maybe didn't have much of a specialised process [to handle requests], failed." I wonder if there is a market for selling GDPR compliance / advising services. Some company that makes sure your doing everything right, and inspects the requests for validity.

There definitely is. The problem right is now is that a huge number of them are prohibitively expensive. I paid $2,000 for GDPR advising for a $7k/mo MRR app and was quoted $25,000 to advise/assist through the entire implementation (of which I'd still have to do myself). It sounded like it's also necessary to hire someone to receive data requests, which would probably cost more (but seems super possible to provide as a service to many companies).

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#214
post #184

Earlier quoted context omitted.

Flaws like this? https://arstechnica.com/information-technology/2017/10/crypt... I support such uses of smartcards, but we have to be disciplined regarding our assumptions about non-repudiation.

I'd rather not start compiling a list of password-username database thefts, credential stuffings, identity thefts, forged paper signatures, the time lost to inefficient paper procedures, secrets stolen due to how hard it is to encrypt things etc. etc. etc. Of course we have to be disciplined, but other things can't even remotely reach the security such a solution provides. Your comment has very FUD-y undertones, risi…

I'm extremely enthusiastic about smartcards, even trying to build a startup around making it easier to deploy and build services around smartcard-based authentication and key management. I agree that in terms of overall security they're incomparable to the existing mess. But, fair point--I flubbed attempting to articulate a tangentially related concern.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#215
post #19

This is a reflection of the fact that we have no good way for someone to digitally prove their identity. Some countries are getting close-ish - Denmark's NemID system, for example, is used by a lot of financial institutions. However, there remains no easy way to make ad-hoc verifiable statements like 'I am John Smith and I authorise you to send this data to xyz@example.org'. Governments, please solve this problem! Es…

In this case, the solution is easy. The user most likely already has an account, so just ask for the account password. If the users claims they lost the password, then do a classic password recovery via email.

Of course it's tricky for organizations storing data about users without an account. (eg. Facebook or Google, not sure how they could handle that at all, even with government ids)

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#216

Earlier quoted context omitted.

Moreover, it's a problem with the current state of "identity" as a whole. Most of the data received in the article - passports, addresses, phone numbers, credit cards - does not change very often. Some documents expire, but even then it could be valid for another 3 - 10 years. We need to move to a system that allows rapid expiry of PII data. Then it will not matter if someone is able to social engineer this data from…

I've heard that in Japan, stamping with your personal stamp is accepted (and perhaps sometimes even required?). They have made electronic gadgets that store their stamps as images so that they can directly sign (stamp) an electronic document (using a specific input device). I think we should have something like this, but with a personal certificate instead of an image. Of course I guess it requires some logistics (lo…

Isn’t this equivalent to stamping PDFs with your signature like we do elsewhere ?

Also the stamp has to be registered to have legal value, which makes it tough to change.

But your idea of signing with the result of some personal certificate is very nice. It can be checked by crypto, different everytime, and wouldn’t matter how it is signed, if it’s easy to reproduce the content etc..

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#217

Earlier quoted context omitted.

Moreover, it's a problem with the current state of "identity" as a whole. Most of the data received in the article - passports, addresses, phone numbers, credit cards - does not change very often. Some documents expire, but even then it could be valid for another 3 - 10 years. We need to move to a system that allows rapid expiry of PII data. Then it will not matter if someone is able to social engineer this data from…

I've heard that in Japan, stamping with your personal stamp is accepted (and perhaps sometimes even required?). They have made electronic gadgets that store their stamps as images so that they can directly sign (stamp) an electronic document (using a specific input device). I think we should have something like this, but with a personal certificate instead of an image. Of course I guess it requires some logistics (lo…

Too bad anyone can access your stamp if you simply lose it. When I first saw the stamp thing for myself, I couldn't fathom how anyone would consider that secure. Better than a signature? Maybe. But easily reproducible and too tangible to consider safe.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#218

Earlier quoted context omitted.

"Selling for cash" - accepting credit cards and wire transfers (paying by check isn't really a thing in most of EU) doesn't necessarily require you to store PII. How are you going to identify the source of a wire transfer if you don't have a customer to match it against? Also, if you're selling online then anything service-like is already caught by the EU VAT place-of-supply rules (which require verification of the b…

"How are you going to identify the source of a wire transfer if you don't have a customer to match it against?" Already in current practice you generally don't identify the source, you identify the order # or invoice # in the transfer details and ignore the payer which can be and often is different from the ordering customer (family members, companies paying some bills, etc), the payer information currently gets used…

My point is that I'd like all these companies to do their best to treat these purchases as if they were anonymous. But your point about VAT rules is a valid issue that might have wider implications about the general necessity to store data.

Yes, you still have VAT records to keep. You also need to prove that you provided all required information to the customer under the consumer protection rules or you can end up having to refund everything going back quite a long time. All these protection rules require accompanying record-keeping as evidence of compliance, which unfortunately is going to undermine your hope to make even simple transactions anonymous in many cases.

that's absolutely not an issue, that might be the case for card-not-present transactions but for as long as I can remember every single pizza courier or similar would use a wireless terminal to get a chip&pin (or now contactless) card-present authorisation which can't really be disputed in this way.

Do you often go into a pizza place and witness a card present transaction to pay for a delivery order? :-)

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#219

Earlier quoted context omitted.

> At least here in Norway you can get a standalone hardware 2-factor key. You can get the key embedded on a smartcard, but it's still coupled to their proprietary driver (which only works on Windows or macOS, of course). It's also a separate API and not as widely supported as Mobile BankID.

> You can get the key embedded on a smartcard, but it's still coupled to their proprietary driver (which only works on Windows or macOS, of course). Maybe it is different where you live but the standalone hardware key I mention is standalone: You open the website, enter your national id, find your token generator, enter pin code for hardware token, read your token, type it into the bank web site, and enter your passw…

> Maybe it is different where you live but the standalone hardware key I mention is standalone: You open the website, enter your national id, find your token generator, enter pin code for hardware token, read your token, type it into the bank web site, and enter your password ib a different field.

That sounds completely different. "BankID På Kort" is basically the same experience as using an OpenPGP smartcard: it prompts you to insert the card, enter your PIN, and everything else is handled in the background.

Many banks here (and at least Nordea used the CC for this) also support manual challenge/response auth like you describe, but this is unrelated to BankID and seems to generally be considered deprecated.

> And the thing you describe seems to be very very different and I'm confident there's only one BankID product in the Nordic countries, so either it is implemented in a very different way with your bank or we aren't talking about the same thing.

From what I can tell, Swedish and Norwegian BankID are completely separate. NorBankID seems to be operated by Vipps[0] (a consortium of norwegian banks) and have existed since 2004, while SweBankID is owned by Finansiell ID-Teknik[1] (a consortium of swedish banks) since 2002.

They also don't share the logo, or seem to have any ties between their websites.

> Around here hardware tokens were supported before mobile BankID was even a thing. They are still available everywhere I log in.

Each bank generally had their own hardware tokens since before BankID (and still do).

Government services usually also support Telia's NetID (which is similar to BankID På Kort, but at least seems to provide a Linux driver).

However, BankID is also starting to become popular for services that would otherwise have been fine with plain old username/password authentication, rather than implementing U2F or TOTP. These services usually don't put a lot of thought into their implementation, and don't tend to implement alternative auth methods. Older services will support username/password for existing users, but expect it to be considered deprecated. Examples of this category would be Hallon (mobile network), Hemfrid (home cleaning service), or Kivra (crappy email without the federation).

> As for why I care, I find that BankID is a good idea, reasonably implemented, so I don't think it is OK to trash it

Don't let decent be the enemy of good.

[0]: https://www.bankid.no/privat/om-oss/

[1]: https://www.bankid.com/en/om-oss/about-finansiell-id-teknik

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#220

Earlier quoted context omitted.

"How are you going to identify the source of a wire transfer if you don't have a customer to match it against?" Already in current practice you generally don't identify the source, you identify the order # or invoice # in the transfer details and ignore the payer which can be and often is different from the ordering customer (family members, companies paying some bills, etc), the payer information currently gets used…

My point is that I'd like all these companies to do their best to treat these purchases as if they were anonymous. But your point about VAT rules is a valid issue that might have wider implications about the general necessity to store data. Yes, you still have VAT records to keep. You also need to prove that you provided all required information to the customer under the consumer protection rules or you can end up ha…

> Do you often go into a pizza place and witness a card present transaction to pay for a delivery order? :-)

Yes, that's exactly what I'm saying, almost all the pizza/goods delivery/taxi/whatever are card-present transactions; whenever I order something like a pizza for delivery, the delivery dude arrives at my door with a wireless card terminal and I pay with my card present (chip+pin or contactless if the amount is small) upon receiving the pizza, and this has beeen this way for so many years now already that I don't remember when they switched from the earlier model, now businesses such as these usually don't have card-not-present acquiring contracts, possibly for cost or fraud reasons as both these things are worse if you have card-not-present permitted.

Post reply on HN