Live data from Hacker News

Delta Dental says data breach exposed info of 7M people

bleepingcomputer.com

71–80 of 152 posts

Re: Delta Dental says data breach exposed info of 7M people

#71
post #32

Earlier quoted context omitted.

The real question is why online credit card payments still involve using the whole card number, as opposed to some message signed by the card's private key authorizing certain spending limits for a retailer.

That’s exactly what we have in the Netherlands — there is a system where you can go to check out, using iDeal. It gives you a QR code at checkout, which you can scan with a banking app on your phone. It shows on your phone the amount you’re sending, and to whom, with a button to approve or deny. You can also set it up as a recurring payment in the app and say “authorize this same payment automatically in the future,…

Yet another example of NL's actual understanding of the public and common good

I miss thee dearly!

Re: Delta Dental says data breach exposed info of 7M people

#72

> who had their names, financial account numbers, and credit/debit card numbers, including security codes, exposed. Delta Dental should be rightly and truly f'd for that one. Storing security codes at all is totally forbidden by PCI rules. Delta Dental should have their ability to process credit cards completely revoked for this egregious breach.

Why they are doing their own payments processing is beyond me. Is it just too expensive to use someone like Stripe?

I was going to ask something similar. Especially US companies seems rather fond of storing credit card information, but I never seem it done in Denmark, regardless of the size of the company. The most common solution is to let your payment processor deal with those sorts of things, you just have a token, which can only be used to deposit money into your account. So even if it's stolen or leaked, you can transfer the money back, they can't be transferred to a third party.

Why on earth you'd want to deal with credit card information and the attacks it attracts is beyond me. It's not like you're locked to the your provider, the tokens can be transferred... Not easily, but it can be done.

And no, companies would never pay Stripes asking price. You can negotiate much much lower rates with companies like Valitor/Rapyd or certain banks.

Re: Delta Dental says data breach exposed info of 7M people

#73
post #63

I’ll never forget when a Citibank employee that processes mortgage applications asked me for my credit card over email. They also had a “secure messaging center” that would take your message, put it in a PDF, password protect the PDF, and then send it to the email address along with instructions for them to login to the website to get the PDF password. The list goes on of bad things banks do with security and is a bl…

The entire home-buying process (in the US, at least) seems to be built on shady-looking ways to nickel and dime people. I remember telling friends when going through it that it'd be easy to scam me because I got so used to urgent requests to pay some fee for inspections or legal stuff or whatever that I'd just shell out the money without asking questions.

It's got nothing on medical billing. Seemingly random bills from entities you may never have heard of showing up months later even when you paid a shitload (thousands) up-front.

[EDIT] Oh and they may not put enough info on the bill to figure out WTF it's even for, without calling them. It'll have some uselessly-generic single-line item for what was probably multiple things, but you'll have to spend an hour on hold to find out what you're supposed to be paying for.

Re: Delta Dental says data breach exposed info of 7M people

#74

It’s super fun and cool that dentistry is controlled by a cartel and we just let it happen out in the open. It is NOT insurance, because there is no risk pooling or coverage for adverse events. It’s just a payment plan that sets prices unilaterally.

Are acute and not universal dental operations like a root canal, crown, abscess op not adverse events for which there can be risk pooling?

Re: Delta Dental says data breach exposed info of 7M people

#75
post #74

It’s super fun and cool that dentistry is controlled by a cartel and we just let it happen out in the open. It is NOT insurance, because there is no risk pooling or coverage for adverse events. It’s just a payment plan that sets prices unilaterally.

Are acute and not universal dental operations like a root canal, crown, abscess op not adverse events for which there can be risk pooling?

They are, and that is not what Delta “insurance” covers.

Re: Delta Dental says data breach exposed info of 7M people

#76

> who had their names, financial account numbers, and credit/debit card numbers, including security codes, exposed. Delta Dental should be rightly and truly f'd for that one. Storing security codes at all is totally forbidden by PCI rules. Delta Dental should have their ability to process credit cards completely revoked for this egregious breach.

> Storing security codes at all is totally forbidden by PCI rules. It's kind of silly though. They are no more "secret" than your credit card number itself or expiration date. Once you give it out once or hand your credit card to literally anyone, it's out. Now instead of acquiring N numbers, the hacker needs to acquire N+3 (or N+4) numbers. Our payment system needs something like: struct { string credit_card_number;…

if no one is storing it, they don't have it. If someone is storing it, it increases the likelihood that they can acquire it.

perfect is the enemy of good.

Re: Delta Dental says data breach exposed info of 7M people

#77
post #11

Earlier quoted context omitted.

It's totally forbidden by PCI rules as well as common sense. Wayyyy back in 2002, I worked at a startup making a billing product. A customer asked for a screen to be able to see CC numbers for their own customers, and our response was a flat no. Any sensitive data was encrypted and sequestered, and security codes were absolutely not stored. In my current role at a startup, when a conflict between schedule/time or con…

> A customer asked for a screen to be able to see CC numbers for their own customers I'd be curious what reason they had.

In 2002? Probably something now-crazy like “how else will I process returns?”

It is not directly related, but as a hopefully funny semi-related anecdote, the federal government stopped states from putting social security numbers on drivers licenses in 2004. Renewals frequency depends on the state, but it is typically in the 4-8 year range, so plausibly until 2012 people were going around showing their SSN to anybody that needed to see ID.

I specifically remember this caused stressful situations as a teenager working retail, people justifiably didn’t want to show an ID when doing returns because it had their SSN. A credit card number is hardly anything comparably!

This all seems absurd nowadays, but the past is not really that long ago.

Re: Delta Dental says data breach exposed info of 7M people

#78

Earlier quoted context omitted.

I assume they kept these in a database, which was sent or exported in some way to use Move-IT to transfer somewhere else. The hack was at Move-IT's servers I think, which allowed people to read the contents. The question I have is was this information encrypted by DD or did they just assume Move-IT was safe? If the latter, it's pretty stupid.

I’ve done a lot of research into HIPAA (I work in a dental-adjacent field) and my guess is that it’s almost certainly the latter – an assumption, maybe based on something they were told. But it’s still on them regardless of whether they were deceived or simply didn’t ask. There have been very few dental practices who have paid fines for HIPAA violations and one that stands out is one who hired a document shredding fi…

Not USA, but we had a case where the discarded unshredded health files somehow ended up being used in a movie shoot for “special effects” and strewn all over a street somewhere.

https://decisions.ipc.on.ca/ipc-cipvp/phipa/en/item/135056/i...

Another where a manager lit a big bonfire at home but put in too much at a time and they asteroided around in burnt and unburnt manner.

Pre-tech breaches :)

Re: Delta Dental says data breach exposed info of 7M people

#79
Scary thing about this is that Delta Dental is multi-state entity, but Delta Dental of California is the entity that handles federal employee benefits, so it likely leaked sensitive details about many federal employees if it contained their entire subscriber base.

Re: Delta Dental says data breach exposed info of 7M people

#80
post #32

Earlier quoted context omitted.

The real question is why online credit card payments still involve using the whole card number, as opposed to some message signed by the card's private key authorizing certain spending limits for a retailer.

Because smart card readers aren't very common on home computers.

It’s a weird skeuomorphism that online payments are even related to physical cards. It should just be through your online banking account.
Post reply on HN