Live data from Hacker News

Black Hat: GDPR privacy law exploited to reveal personal data

bbc.co.uk

231–239 of 239 posts

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#231
post #90

Earlier quoted context omitted.

This is not a problem with GDPR. This is a problem with organizations (companies and governments) treating publicly data as private keys.

If GDPR created new vectors of attack which didn't exist before - there's a problem with GDPR even if there are also problems with organizations. Otherwise, you have just created a perfect excuse for any lawmaker: "my law written with good intentions, so not my problem if there are unintended consequences".

Uhm, the corporations handing out private data to the wrong person, are definitely violating the GDPR or probably some earlier privacy law, because you also weren't supposed to give out people's personal data like that before the GDPR either.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#232

Earlier quoted context omitted.

I had to verify my identity for an online service a while back. They used a third party company that has a mobile phone app essentially for video conferencing; you then call this company via the app and talk to them. They ask you to show your face and move around and to show your ID, including moving it around so they can check that the security hologram (this was an EU passport) is indeed one. So for this kind of ch…

This sounds like something vulnerable to real-time deepfakes in the very near future.

Maybe, but you can say that about anything that is not in-person face-to-face communication along with physically handing over the passport for inspection. I think the process was pretty rigorous for the current state of the art, and infinitely better than the normal approach of mailing around PDFs into which I have pasted a scan of my signature.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#233
post #216

Earlier quoted context omitted.

Isn’t this equivalent to stamping PDFs with your signature like we do elsewhere ? Also the stamp has to be registered to have legal value, which makes it tough to change. But your idea of signing with the result of some personal certificate is very nice. It can be checked by crypto, different everytime, and wouldn’t matter how it is signed, if it’s easy to reproduce the content etc..

> Also the stamp has to be registered to have legal value, which makes it tough to change. This is not actually true. Some stamps need to be registered (for example the stamp for corporation), but personal stamps for most applications don't need to be registered -- even for bank accounts. I have several and I'm always forgetting which one I used for my different bank accounts :-P. One of the strange things about Japa…

As far as I know the registering part is mandatory for legal use but lets the accepting party decide to check it or not.

For instance as you point out for banks you can open an account without any check (you’re giving them money) but you won’t get a mortgage without proof of registration (they’re taking the risk)

At a previous company my boss had his company stamp (a shachihata) in a drawer for us to use when he’s not there. It’s interesting because by the rule of law we would be the one in fault for using someone’s stamp, so it better be for stuff he approved verbally or other ways.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#234

Earlier quoted context omitted.

>you don't need any details about the transcaction beyond the amount and ID. // That's a lot of trust in the merchant services. "What transaction?", then if all you had was a transaction ID what do you do? Also, to process refunds you need to have payment details. In your second case only store the details if people explicitly want you to. You can do repeat customer discounts by sending vouchers for a later order wit…

What do you mean by ""What transaction?", then if all you had was a transaction ID what do you do?" - that's a common process in online stores, you make a contract with an acquiring bank with the default scenario that you won't be processing transactions yourself (as most smallish customers can't or don't want to handle full PCI DSS compliance), then you (or the bank) contracts with one of the merchant gateway provid…

Well, in our shop [no longer open, was a micro-business] someone comes in for a refund, but doesn't have the receipt, there's no way to process a refund except to open the safe and get the receipt because you need to refund the same card and you don't know the card without keeping some record of it.

We've had transactions that failed to upload but were processed normally on the [mobile] card terminal, and we had to give the merchant services details to complete the processing of the transaction. Sometimes a transaction would fail during processing [cardholder not present (CNP), via phone] but we wouldn't realise until the phone was down, so in some cases we contacted the customer (our business required contact details, it couldn't run without them; this was pre-GDPR anyway). Other times the bank network would be out, so we'd be unable to process transactions without keeping customer data (temporarily).

>as most smallish customers can't or don't want to handle full PCI DSS compliance //

The banks were real bastards for this. Despite providing us mobile card terminals that don't connect to local network they required us to pay for PCI compliance audits of local equipment or pay a penalty amount [you could audit it yourself, took me about 8 hours of reading documentation to establish the protocol as they apparently didn't want us to do it but wanted us to pay instead]. The PCI stuff was basically a hidden-cost scam AFAICT.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#235
I can’t believe a drivers license scan is all that is needed for many companies. That means that losing my wallet on the street effectively means that someone can go get my entire digital history.

Why not require the user to request this data while signed in to the service?

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#236
post #74

"Generally if it was an extremely large company - especially tech ones - they tended to do really well," he told the BBC. "Small companies tended to ignore me. "But the kind of mid-sized businesses that knew about GDPR, but maybe didn't have much of a specialised process [to handle requests], failed." This sums up regulatory compliance across the world quite well.

I think this is part of the reason why GDPR needs an exemption for businesses that are too small. This kind of a flaw will be abused more and more and they'll never be able to close this gap with small and medium businesses.

1. Such an exception would be used by large companies to evade the law.

2. Small and medium companies are also committing privacy abuses.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#237
post #236

Earlier quoted context omitted.

I think this is part of the reason why GDPR needs an exemption for businesses that are too small. This kind of a flaw will be abused more and more and they'll never be able to close this gap with small and medium businesses.

1. Such an exception would be used by large companies to evade the law. 2. Small and medium companies are also committing privacy abuses.

1. You can make late companies unable to evade the law.

2. Yeah? But according to this article GDPR actually makes small and medium companies even more dangerous to trust with your information.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#238
post #19

This is a reflection of the fact that we have no good way for someone to digitally prove their identity. Some countries are getting close-ish - Denmark's NemID system, for example, is used by a lot of financial institutions. However, there remains no easy way to make ad-hoc verifiable statements like 'I am John Smith and I authorise you to send this data to xyz@example.org'. Governments, please solve this problem! Es…

In my opinion, we need an open protocol for this. Every government having a separate digital identification tool is a poor solution.

The simplest solution I can imagine is to mimic the solution used to digitally identify companies via HTTPS (certificate authorities), but modified with the intent of identifying a person rather than a company.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#239

Earlier quoted context omitted.

Nope, that's not legally safe -- we've been told by data authorities that the verification methods cannot be "overly burdensome" to the data subject. I live in dread of subject access requests (and thankfully have only had one, and it happened to be really easy to verify).

IIRC they also allow charging the person - for a "reasonable" amount - for the data retrieval process (which I assume would include the "identity verification" part). Maybe using the 3-D Secure protocol (especially the second revision) would be enough to unburden yourself for verifying the identity as Mastercard/Visa/American Express supposedly check it for you. This would work only in some conditions (the data subje…

The ability to charge is only for either (a) additional copies of data or (b) if the request is "manifestly unfounded or excessive." Given that there's no guidance on (b), that eliminates 99.9% of all SARs.
Post reply on HN