Live data from Hacker News

Despite decades of hacking attacks, companies leave sensitive data unprotected

propublica.org

1–10 of 45 posts

Re: Despite decades of hacking attacks, companies leave sensitive data unprotected

#2
As I see it there's two things at play here that feed into one another:

1. The re-framing by financial institutions of them being defrauded as "identity theft" and pushing this responsibility onto their customers.

2. Because of the above, the data can be valuable, incentivizing the compromise.

Re 1: Note that credit card companies have had this problem for ages and treated it as fraud for decades, which is why established card companies can have very reasonable processes to cancel transactions, mark some as fraudulent, and probably why they have reversible transactions. However, because of the rest of the industry card companies now appear to be jumping on board with the "identity theft" concept.

By collectively not treating it seriously and essentially letting it happen and inconveniencing their customers instead of the vendors, banks have essentially washed their hands of it and give zero incentives to the vendors to seriously try to protect the data. If every transaction marked fraudulent meant the vendor didn't get the money, there would be a lot more serious action here.

Re: Despite decades of hacking attacks, companies leave sensitive data unprotected

#4

As I see it there's two things at play here that feed into one another: 1. The re-framing by financial institutions of them being defrauded as "identity theft" and pushing this responsibility onto their customers. 2. Because of the above, the data can be valuable, incentivizing the compromise. Re 1: Note that credit card companies have had this problem for ages and treated it as fraud for decades, which is why establ…

I'm not sure I agree with your last point. The merchants have historically been powerless but the merchant side bank ends up patching things up to fix it's own costs. Often this patching means penalizing merchants with products that are fun to buy fraudulently for failures that originated or could only have been detected at the buyer's bank.

Re: Despite decades of hacking attacks, companies leave sensitive data unprotected

#5

As I see it there's two things at play here that feed into one another: 1. The re-framing by financial institutions of them being defrauded as "identity theft" and pushing this responsibility onto their customers. 2. Because of the above, the data can be valuable, incentivizing the compromise. Re 1: Note that credit card companies have had this problem for ages and treated it as fraud for decades, which is why establ…

agree - add to that a system side-effect -- with strong consumer protection and easily reversed transactions, plus the financial policy to cover the dollars involved, that leads to a big increase of crooked insiders doing the fraud transactions. Without evidence, I believe that VISA and MasterCard in the early days, found that the massive money they made on consumer credit was worth the sort-of-unstoppable insider scamming as a "cost of doing business"

Re: Despite decades of hacking attacks, companies leave sensitive data unprotected

#6
post #3

This is what happens when there are zero legal repercussions for companies with sloppy data security. Regulatory capture strikes again.

Literally the only reason any company invests actual time into data security is HIPAA, GDPR and SOX. I keep wondering why people haven't demanded more regulation after all their SSNs got leaked

Re: Despite decades of hacking attacks, companies leave sensitive data unprotected

#7
post #3

This is what happens when there are zero legal repercussions for companies with sloppy data security. Regulatory capture strikes again.

Literally the only reason any company invests actual time into data security is HIPAA, GDPR and SOX. I keep wondering why people haven't demanded more regulation after all their SSNs got leaked

[deleted]

Re: Despite decades of hacking attacks, companies leave sensitive data unprotected

#8
post #3

This is what happens when there are zero legal repercussions for companies with sloppy data security. Regulatory capture strikes again.

Literally the only reason any company invests actual time into data security is HIPAA, GDPR and SOX. I keep wondering why people haven't demanded more regulation after all their SSNs got leaked

Because there are very few regulations that can effectively capture the intent of the rules instead of "tick boxes" that might or might not mean very much.

Sure, "has firewall" is pretty effective but how do you encapsulate how it should be managed effectively?

What happens when a system that was supposedly secure installed by a previous employee fails? The company's fault? How would they know? The employee's fault? Maybe they thought it was good but were simply wrong?

I think a more fundamental approach would be to set mandatory qualifications for IT workers/devs to ensure a base-level of security/understanding. I know great web devs who don't know about web app security - that shouldn't be possible. It wouldn't be perfect but it would be easier to do refreshers/regular testing for things that people should already have learned, just like train drivers do.

Re: Despite decades of hacking attacks, companies leave sensitive data unprotected

#9

As I see it there's two things at play here that feed into one another: 1. The re-framing by financial institutions of them being defrauded as "identity theft" and pushing this responsibility onto their customers. 2. Because of the above, the data can be valuable, incentivizing the compromise. Re 1: Note that credit card companies have had this problem for ages and treated it as fraud for decades, which is why establ…

“Damn you, masquerading as hundreds, if not thousands, of customers! How dare you steal their identities!”

— Mitchell & Webb, Identity Theft (https://www.youtube.com/watch?v=-c57WKxeELY)

Re: Despite decades of hacking attacks, companies leave sensitive data unprotected

#10
post #3

This is what happens when there are zero legal repercussions for companies with sloppy data security. Regulatory capture strikes again.

Literally the only reason any company invests actual time into data security is HIPAA, GDPR and SOX. I keep wondering why people haven't demanded more regulation after all their SSNs got leaked

Who do you ask?

Politicians will say it’s the companies responsibility, and you should talk to them. Companies will say that they follow all data protection laws and that policy discussions should be up to the government.

Post reply on HN