I feel like the people who calculate that it's more cost effective to deal with the hit from a security breach vs spending money on good security have won. I have gone from feeling outraged to completely numb to these kind of disclosures and have pretty much just assumed that my information will inevitably be leaked somewhere by someone. Does anyone else feel this way? I just keep a close eye on my financial statemen…
Data leak contains 26B records from numerous previous breaches
81–90 of 150 posts
Re: Data leak contains 26B records from numerous previous breaches
#82Earlier quoted context omitted.
I'm very open to government solutions, but at the same time I'm not sure they have a good track record. Despite that, this service should come from the government because anyone else has misaligned incentives. I specifically would want a privacy and security maximalist approach. What we have right now is completely unacceptable, especially given our current technology level. Though of course, the downside is also tha…
The service doesn’t need to come from the government. A marketplace of services of which I can choose my own provider would work.
Re: Data leak contains 26B records from numerous previous breaches
#83Earlier quoted context omitted.
I'm unclear how encrypting the data would help. The same breach that gives access to the data, can also decrypt it. (Also you wrote the same message twice.)
I think you misunderstand their suggestion. If you only gave service providers access to encrypted data (i.e. End-to-end encryption), then neither the service provider nor the leaker would be able to decrypt. Whether or not that is a generally viable or desirable suggestion is a different question, but it is possible as demonstrated by Signal, Apple, etc.
Most things aren't going to work with that model. Can Amazon ship you products without knowing what you ordered? Can you send and receive email on multiple devices without the provider having your email? Can you join public chat groups? Can you view your lab results without the lab having them?
And don't say "the lab can encrypt and send them to you". Your encryption key must be known to the lab, so they can provision a new device for you, in case you lose your phone.
Even the vaunted "WhatsApp and Signal" could actually read all your messages if they wanted to - they have your encryption key after all, all they need to do is deploy a version of their application that copies your messages to them.
So no, it's not actually possible.
Re: Data leak contains 26B records from numerous previous breaches
#84Earlier quoted context omitted.
I would go one step further, saying that proper verification is prone to fraud because of failure in government (in the US; not sure about other countries). It still baffles me that identification typically comes down to two things: social security card and driver's license, and both are managed by agencies whose primary objective is not identification. IMHO, it's time for a single agency at either the fed or state l…
I'll go yet another step further, and say that the main opposition to having a better technical system of government identification is because we're lacking a comprehensive privacy law akin to the GDPR. As it stands if the government started say issuing smart cards for identify verification, then every business would gradually force their customers to identify themselves, for helping the commercial surveillance indus…
Re: Data leak contains 26B records from numerous previous breaches
#85Question that sounds idiotic but is quite serious: how do I make it illegal to lend money to me without confirmation via Keybase? (edit: or some similar cryptographic identity proof) The only reason to keep my name/address/SSN secret is that companies will lend money to a person who has that info, and then try to make me liable for it regardless of whether that person was me. That's a problem, but the solution isn't…
Speaking of Keybase, is it still supported? I just launched mine after a multi-week hiatus, and I'm getting an error: "x509: certificate signed by unknown authority" Hmmm.
For all intents and purposes, Keybase was abandoned the moment the team was acquired by Zoom.
Re: Data leak contains 26B records from numerous previous breaches
#86I feel like the people who calculate that it's more cost effective to deal with the hit from a security breach vs spending money on good security have won. I have gone from feeling outraged to completely numb to these kind of disclosures and have pretty much just assumed that my information will inevitably be leaked somewhere by someone. Does anyone else feel this way? I just keep a close eye on my financial statemen…
I just went through a call with my credit card company. 4 transfers later the only verification I've been asked is the last 4 of my social, my name, and when I was at the "highest level" of security they took the amazing step to... call me back. All because my credit card, which is travel focused, got flagged because I bought a You are not alone. It is an __absolute joke__ that my github account is more secure than a…
The banks' understanding of security is so poor that they push people to use voice or fingerprint authentication. My wife constantly fights Wells Fargo about it every time she calls them because they want to helpfully sign her up for their voiceprint service so she doesn't have to use her PIN anymore. She used to work in a retail cellphone store so has heard tons of horror stories of people signing up for the same and then getting their voice deepfaked by a telemarketer to access their accounts.
Re: Data leak contains 26B records from numerous previous breaches
#87I feel like the people who calculate that it's more cost effective to deal with the hit from a security breach vs spending money on good security have won. I have gone from feeling outraged to completely numb to these kind of disclosures and have pretty much just assumed that my information will inevitably be leaked somewhere by someone. Does anyone else feel this way? I just keep a close eye on my financial statemen…
I just went through a call with my credit card company. 4 transfers later the only verification I've been asked is the last 4 of my social, my name, and when I was at the "highest level" of security they took the amazing step to... call me back. All because my credit card, which is travel focused, got flagged because I bought a You are not alone. It is an __absolute joke__ that my github account is more secure than a…
Re: Data leak contains 26B records from numerous previous breaches
#88Earlier quoted context omitted.
I just went through a call with my credit card company. 4 transfers later the only verification I've been asked is the last 4 of my social, my name, and when I was at the "highest level" of security they took the amazing step to... call me back. All because my credit card, which is travel focused, got flagged because I bought a You are not alone. It is an __absolute joke__ that my github account is more secure than a…
USAA actually does push passcodes using their app. The banks' understanding of security is so poor that they push people to use voice or fingerprint authentication. My wife constantly fights Wells Fargo about it every time she calls them because they want to helpfully sign her up for their voiceprint service so she doesn't have to use her PIN anymore. She used to work in a retail cellphone store so has heard tons of…
Re: Data leak contains 26B records from numerous previous breaches
#89Earlier quoted context omitted.
I just went through a call with my credit card company. 4 transfers later the only verification I've been asked is the last 4 of my social, my name, and when I was at the "highest level" of security they took the amazing step to... call me back. All because my credit card, which is travel focused, got flagged because I bought a You are not alone. It is an __absolute joke__ that my github account is more secure than a…
I can log into chase.com with my password in any case. Banking security is an absolute joke. The interesting part is that if I have to do a 2FA SMS challenge, I am required to re-enter my password. At this point the password checking becomes case sensitive.
This doesn't work on my chase.com account.
Re: Data leak contains 26B records from numerous previous breaches
#90Earlier quoted context omitted.
It should all be free, like getting credit reports is now. We need a robust and accessible way to manage our data personas, assuming that all of the supposed secrets are in fact public data.
As a reminder for any US Citizens, there is an official path to getting this from each of the main three for free[1] is the approved method verified by FTC [2]. 1. https://annualcreditreport.com 2. https://consumer.ftc.gov/articles/free-credit-reports