Live data from Hacker News

Delta Dental says data breach exposed info of 7M people

bleepingcomputer.com

121–130 of 152 posts

Re: Delta Dental says data breach exposed info of 7M people

#121
post #69
post #21

Earlier quoted context omitted.

TBH, I know of at least one other breach that everyone got hit by too...afaik it was never made public though. It's been a while since I was told the story, so bear with me. It was Experian. They shipped tape backups of essentially their entire consumer credit DB, unencrypted, via UPS. UPS truck got robbed at gunpoint, only one package stolen... EDIT: Transunion -> Experian

Could you please share some online references or sources for this? "It was never made public" - do you mean to imply that this is otherwise unverifiable

Might be this - https://www.nytimes.com/2005/06/07/business/personal-data-fo...

First result for "experian ups truck stolen"

Re: Delta Dental says data breach exposed info of 7M people

#123

> who had their names, financial account numbers, and credit/debit card numbers, including security codes, exposed. Delta Dental should be rightly and truly f'd for that one. Storing security codes at all is totally forbidden by PCI rules. Delta Dental should have their ability to process credit cards completely revoked for this egregious breach.

That would just force the company to form back up with the same people under a new name. Unless individuals can be held responsible, there's nothing we can do about it.

Re: Delta Dental says data breach exposed info of 7M people

#126

> who had their names, financial account numbers, and credit/debit card numbers, including security codes, exposed. Delta Dental should be rightly and truly f'd for that one. Storing security codes at all is totally forbidden by PCI rules. Delta Dental should have their ability to process credit cards completely revoked for this egregious breach.

That's a good point. The best way to not leak a secret is to not have the secret in the first place. I don't know anything of PCI rules but I would imagine there is a way to implement the feature "store this credit card information for future purchases" without storing the raw credit card information.

[deleted]

Re: Delta Dental says data breach exposed info of 7M people

#127

Surely the data breaches we hear about are the tip of the iceberg? Just think of what needs to happen after a hack for you to hear about it: - someone at the company needs to be aware it has happened. - they need to accurately identify what was accessed. - they need to disclose that this has happened. - it needs to be visible enough that it gets picked up and talked about. Each step of that funnel must have some drop…

And finding out shouldn't be like pulling teeth.

Delta should leave the teeth pulling to the dentists.

Re: Delta Dental says data breach exposed info of 7M people

#128

Earlier quoted context omitted.

But 1988 is officially The Past, ask any millennial, my self image can’t deal with the fact that our anecdotes objectively belong side-by-side.

At the risk of instantly drying into dust by suggesting that 2002 is also The Past, but my SSN was also my student ID then.

In 2002 my school (Kent State) was in the process of phasing out SSNs as student numbers. I was working as a student IT employee in one of the departments and spent quite a bit of time updating systems to remove the use of SSNs.

Re: Delta Dental says data breach exposed info of 7M people

#129
post #74

Earlier quoted context omitted.

Are acute and not universal dental operations like a root canal, crown, abscess op not adverse events for which there can be risk pooling?

They are, and that is not what Delta “insurance” covers.

I’m not sure why you say this. Maybe I don’t understand what you mean.

I have Delta Dental through my employer’s benefits and it covers all the types of operations that I’d expect: preventive, endodontic, periodontic, orthodontic, prosthodontic, etc.

If I need a root canal, it’s covered by Delta Dental (up to a point, given the deductible). If I chip a tooth, and get an inlay or onlay, that is covered. Is this not insurance? Why not?

Re: Delta Dental says data breach exposed info of 7M people

#130

> who had their names, financial account numbers, and credit/debit card numbers, including security codes, exposed. Delta Dental should be rightly and truly f'd for that one. Storing security codes at all is totally forbidden by PCI rules. Delta Dental should have their ability to process credit cards completely revoked for this egregious breach.

> Storing security codes at all is totally forbidden by PCI rules. It's kind of silly though. They are no more "secret" than your credit card number itself or expiration date. Once you give it out once or hand your credit card to literally anyone, it's out. Now instead of acquiring N numbers, the hacker needs to acquire N+3 (or N+4) numbers. Our payment system needs something like: struct { string credit_card_number;…

I agree with you. When the secret is always collected side-by-side with the number it seems little comfort that only one part is “supposed to be stored”.
Post reply on HN