Wow that MoveIT hack sure was bad. How did they manage to keep from becoming a punching bag like SolarWinds? Also the title should probably clarify this is Delta Dental of California.
The title is borderline click-bait: I have had Delta Dental insurance at every employer, so I clicked through to read more, but I've never lived in California or been employed by a California company.
Delta Dental says data breach exposed info of 7M people
101–110 of 152 posts
Re: Delta Dental says data breach exposed info of 7M people
#102Earlier quoted context omitted.
Yeah... it's a complete PITA. I also had the 'we can't freeze right now' and it took a few days of verification and eventually having to call them to get it all sorted. My reasoning is it's better to do this before a bad person has your account rather than during.
Why are you doing so much work to save some third party money when they get defrauded?
Re: Delta Dental says data breach exposed info of 7M people
#103> who had their names, financial account numbers, and credit/debit card numbers, including security codes, exposed. Delta Dental should be rightly and truly f'd for that one. Storing security codes at all is totally forbidden by PCI rules. Delta Dental should have their ability to process credit cards completely revoked for this egregious breach.
I use delta dental. What does this mean? Why would they store my CC info when I’m paying directly to my dentist and delta dental is also paying the dentist? How does my CC info get transferred to the insurer? There’s no such transaction afaik.
Re: Delta Dental says data breach exposed info of 7M people
#104Surely the data breaches we hear about are the tip of the iceberg? Just think of what needs to happen after a hack for you to hear about it: - someone at the company needs to be aware it has happened. - they need to accurately identify what was accessed. - they need to disclose that this has happened. - it needs to be visible enough that it gets picked up and talked about. Each step of that funnel must have some drop…
Re: Delta Dental says data breach exposed info of 7M people
#105Re: Delta Dental says data breach exposed info of 7M people
#106Earlier quoted context omitted.
The real question is why online credit card payments still involve using the whole card number, as opposed to some message signed by the card's private key authorizing certain spending limits for a retailer.
Online retailers almost surely do better by allowing easy use of credit cards by even the least technical 5% of Americans than they would from a lower fraud system that required a moderate or higher level of technical acumen to operate. Suppose I'm at a computer ready to buy a PS5 on BestBuy's site. What's the complexity now vs under a proposed private-key system? What's the loss in conversion rate on the latter?
Re: Delta Dental says data breach exposed info of 7M people
#107Earlier quoted context omitted.
Why they are doing their own payments processing is beyond me. Is it just too expensive to use someone like Stripe?
I was going to ask something similar. Especially US companies seems rather fond of storing credit card information, but I never seem it done in Denmark, regardless of the size of the company. The most common solution is to let your payment processor deal with those sorts of things, you just have a token, which can only be used to deposit money into your account. So even if it's stolen or leaked, you can transfer the…
Re: Delta Dental says data breach exposed info of 7M people
#108Earlier quoted context omitted.
You're not wrong, but GP is saying that 3 digits is a pretty weak 'security' code and gas station skimmers are on the tail end of the threat model compared to exfil of data at any point in the processing chain.
I tried to better clarify what I'm saying in [1]. I'm not saying the small number of digits makes it insecure, it's that "moar numbers" is not really adding anything in terms of multi-factor or secrecy. Instead of knowing N digits, you merely need to know N+M digits. It is not changing the nature of the secret. 1: https://news.ycombinator.com/item?id=38655609
https://randomoracle.wordpress.com/2012/08/25/cvv1-cvv2-cvv3...
I totally see why it just seems like "moar numbers" though, and I find them unnecessarily annoying. I wish they could reduce the complexity (maybe letters, colors or shapes, something more human-compatible), but there's just too much legacy code with too little benefit.
Re: Delta Dental says data breach exposed info of 7M people
#109Earlier quoted context omitted.
At one time it was routine to have your SSN and Drivers License # printed on your checks. And in 1988 my student ID number as university was my SSN.
But 1988 is officially The Past, ask any millennial, my self image can’t deal with the fact that our anecdotes objectively belong side-by-side.