Live data from Hacker News

Delta Dental says data breach exposed info of 7M people

bleepingcomputer.com

51–60 of 152 posts

Re: Delta Dental says data breach exposed info of 7M people

#51
I’ll never forget when a Citibank employee that processes mortgage applications asked me for my credit card over email.

They also had a “secure messaging center” that would take your message, put it in a PDF, password protect the PDF, and then send it to the email address along with instructions for them to login to the website to get the PDF password.

The list goes on of bad things banks do with security and is a blatant reminder, “rules for thee but not for me”

Re: Delta Dental says data breach exposed info of 7M people

#52

Surely the data breaches we hear about are the tip of the iceberg? Just think of what needs to happen after a hack for you to hear about it: - someone at the company needs to be aware it has happened. - they need to accurately identify what was accessed. - they need to disclose that this has happened. - it needs to be visible enough that it gets picked up and talked about. Each step of that funnel must have some drop…

Just get into the proper forums and see all the data offered for sale.

Re: Delta Dental says data breach exposed info of 7M people

#53
post #26

Does this only impact people who purchase individual coverage through Delta Dental? I’m assuming employees with employer-sponsored Delta Dental plans have no reason to provide Delta with their credit cards

I have Delta Dental through employer and I'm pretty sure I've never had to give them any CC info. Any copays go directly to the dentist.

Re: Delta Dental says data breach exposed info of 7M people

#54
post #41
post #11

Earlier quoted context omitted.

It's totally forbidden by PCI rules as well as common sense. Wayyyy back in 2002, I worked at a startup making a billing product. A customer asked for a screen to be able to see CC numbers for their own customers, and our response was a flat no. Any sensitive data was encrypted and sequestered, and security codes were absolutely not stored. In my current role at a startup, when a conflict between schedule/time or con…

Out of curiosity, and without naming names, what is people's typical response and what is the dynamic? Data security is hardly ever convenient, and most often vies for resources with other features or quality improvements, especially in a startup seeking to make its fortune. Can people even imagine breach ramifications without having been previously burnt, or is the main incentive to be able to tout compliance?

> or is the main incentive to be able to tout compliance?

At the time I joined, the existing goals were around compliance and checking boxes on security questionnaires, which is exactly the problem I'm trying to solve. Specifically, compliance was driven by the IT/Infra teams and mostly around access to access to cloud infra. That's obviously useless if a db server is locked down and change managed, but the software access the data isn't.

So, the bulk of my efforts in this area have been around bridging the gap from checking boxes to actual compliance with various standards. Fortunately, we rely heavily on data, so it's not a hard sell to properly protect things.

In general, people receive the questions well, as it makes the strong point that there's a big gap between checking a box that people in sales & marketing care about, vs. how any issues arising from not having "real" compliance would be catastrophic and business ending for a company of our size.

Re: Delta Dental says data breach exposed info of 7M people

#55

> who had their names, financial account numbers, and credit/debit card numbers, including security codes, exposed. Delta Dental should be rightly and truly f'd for that one. Storing security codes at all is totally forbidden by PCI rules. Delta Dental should have their ability to process credit cards completely revoked for this egregious breach.

> Storing security codes at all is totally forbidden by PCI rules. It's kind of silly though. They are no more "secret" than your credit card number itself or expiration date. Once you give it out once or hand your credit card to literally anyone, it's out. Now instead of acquiring N numbers, the hacker needs to acquire N+3 (or N+4) numbers. Our payment system needs something like: struct { string credit_card_number;…

For physical transactions, change is happening, but it’s a slow migration. Looks like MasterCard has plans to remove the magnetic stripe [1].

Online, perhaps credit cards will disappear into password managers and mobile payments (Google and Apple Pay, etc.) with ordinary businesses storing very little.

[1] https://www.theverge.com/2021/8/17/22628455/mastercard-magne...

Re: Delta Dental says data breach exposed info of 7M people

#56

Surely the data breaches we hear about are the tip of the iceberg? Just think of what needs to happen after a hack for you to hear about it: - someone at the company needs to be aware it has happened. - they need to accurately identify what was accessed. - they need to disclose that this has happened. - it needs to be visible enough that it gets picked up and talked about. Each step of that funnel must have some drop…

I would honestly guess about 0.1% of bad leaks (e.g. not just email and user name or whatever) are disclosed in the end.

It has to be really hard for the police or card providers to correlate frauds with customer databases.

And like, how do you even notice you are hacked? Unless the hacker sends you extortion messages, which I guess is the main reason for disclosure. Otherwise the hacker can tip off the an attorney and 'pwn' corporate lawyers for real. A risk the lawyers won't take even if the company wanted to.

I sometimes feel lawyers are the only group of workers with real agency ...

Re: Delta Dental says data breach exposed info of 7M people

#57

> who had their names, financial account numbers, and credit/debit card numbers, including security codes, exposed. Delta Dental should be rightly and truly f'd for that one. Storing security codes at all is totally forbidden by PCI rules. Delta Dental should have their ability to process credit cards completely revoked for this egregious breach.

Storing the CVV would be very bad, but the form they’re linking to is ambiguous:

“Information Acquired - Name or other personal identifier in combination with: Financial Account Number or Credit/Debit Card Number (in combination with security code, access code, password or PIN for the account)”

Re: Delta Dental says data breach exposed info of 7M people

#58
post #11

> who had their names, financial account numbers, and credit/debit card numbers, including security codes, exposed. Delta Dental should be rightly and truly f'd for that one. Storing security codes at all is totally forbidden by PCI rules. Delta Dental should have their ability to process credit cards completely revoked for this egregious breach.

It's totally forbidden by PCI rules as well as common sense. Wayyyy back in 2002, I worked at a startup making a billing product. A customer asked for a screen to be able to see CC numbers for their own customers, and our response was a flat no. Any sensitive data was encrypted and sequestered, and security codes were absolutely not stored. In my current role at a startup, when a conflict between schedule/time or con…

> A customer asked for a screen to be able to see CC numbers for their own customers

I'd be curious what reason they had.

Re: Delta Dental says data breach exposed info of 7M people

#59
Sidebar, but does anybody else get incensed by the fact that Delta frequently uses customer’s SSN as their account number? My dentist looked at me like I was crazy when I told them I didn’t want my account information being stored on their computers for that reason.

But maybe in this moronic system, resistance is futile.

Re: Delta Dental says data breach exposed info of 7M people

#60
post #3

Wow that MoveIT hack sure was bad. How did they manage to keep from becoming a punching bag like SolarWinds? Also the title should probably clarify this is Delta Dental of California.

The title is borderline click-bait: I have had Delta Dental insurance at every employer, so I clicked through to read more, but I've never lived in California or been employed by a California company.
Post reply on HN