Question that sounds idiotic but is quite serious: how do I make it illegal to lend money to me without confirmation via Keybase? (edit: or some similar cryptographic identity proof) The only reason to keep my name/address/SSN secret is that companies will lend money to a person who has that info, and then try to make me liable for it regardless of whether that person was me. That's a problem, but the solution isn't…
You contribute to campaigns of politicians (aka bribe) and write legislation for them to pass.
Data leak contains 26B records from numerous previous breaches
101–110 of 150 posts
Re: Data leak contains 26B records from numerous previous breaches
#102I feel like the people who calculate that it's more cost effective to deal with the hit from a security breach vs spending money on good security have won. I have gone from feeling outraged to completely numb to these kind of disclosures and have pretty much just assumed that my information will inevitably be leaked somewhere by someone. Does anyone else feel this way? I just keep a close eye on my financial statemen…
I just went through a call with my credit card company. 4 transfers later the only verification I've been asked is the last 4 of my social, my name, and when I was at the "highest level" of security they took the amazing step to... call me back. All because my credit card, which is travel focused, got flagged because I bought a You are not alone. It is an __absolute joke__ that my github account is more secure than a…
Re: Data leak contains 26B records from numerous previous breaches
#103I feel like the people who calculate that it's more cost effective to deal with the hit from a security breach vs spending money on good security have won. I have gone from feeling outraged to completely numb to these kind of disclosures and have pretty much just assumed that my information will inevitably be leaked somewhere by someone. Does anyone else feel this way? I just keep a close eye on my financial statemen…
100% with you. At this point my data has been breached so many times I don't even know what the point of caring is. I don't have privacy anymore. Like you I just have credit monitoring and watch my financial statements and hope for the best. This world sucks.
Re: Data leak contains 26B records from numerous previous breaches
#104Earlier quoted context omitted.
I'll go yet another step further, and say that the main opposition to having a better technical system of government identification is because we're lacking a comprehensive privacy law akin to the GDPR. As it stands if the government started say issuing smart cards for identify verification, then every business would gradually force their customers to identify themselves, for helping the commercial surveillance indus…
There's also a significant constituency that believes any nationwide system of identity is the "mark of the beast" as spoken of in the Bible.
Re: Data leak contains 26B records from numerous previous breaches
#105Earlier quoted context omitted.
The funny thing to me about this title is who brought that term to English in the first place. It came into the vernacular back in 1991 when Saddam Hussein claimed the Kuwait War would become "the mother of all wars". It didn't. It lasted about 24 hours, but the phrase has lasted much longer. It's so weird how language evolves, who has the power to do it, and who doesn't. So for me, the title means that this breach i…
Google Ngram viewer does indicate a sharp rise in use of the phrase starting in 1990: https://books.google.com/ngrams/graph?content=the+mother+of+...
a hyperbole that has been used to refer to something as "great" or "the greatest of its kind", became a popular snowclone template in the 1990s. The phrase entered American popular culture in September 1990 at the outset of the Gulf War, when Saddam Hussein's Revolutionary Command Council warned the U.S.-led Coalition against military action in Kuwait with the statement: "Let everyone understand that this battle is going to become the mother of all battles."[
Re: Data leak contains 26B records from numerous previous breaches
#106I feel like the people who calculate that it's more cost effective to deal with the hit from a security breach vs spending money on good security have won. I have gone from feeling outraged to completely numb to these kind of disclosures and have pretty much just assumed that my information will inevitably be leaked somewhere by someone. Does anyone else feel this way? I just keep a close eye on my financial statemen…
Since the mid 2000s.
I worked very hard trying to figure out how to protect patient data.
To do so requires translucent database techniques.
Which means encrypting all potential PII data at rest at the field level. Exactly like how passwords are stored, extended to all PII.
Which requires globally unique identifiers issued by CAs. Just like RealID.
Nothing will improve until people accept this fundamental technical truth.
Also, on the policy side, PII needs be be changed from an asset to a liability. And ban data hoarding stuff like targeted ads and relevant search.
Re: Data leak contains 26B records from numerous previous breaches
#107Re: Data leak contains 26B records from numerous previous breaches
#108I feel like the people who calculate that it's more cost effective to deal with the hit from a security breach vs spending money on good security have won. I have gone from feeling outraged to completely numb to these kind of disclosures and have pretty much just assumed that my information will inevitably be leaked somewhere by someone. Does anyone else feel this way? I just keep a close eye on my financial statemen…
Re: Data leak contains 26B records from numerous previous breaches
#109Earlier quoted context omitted.
I'm very open to government solutions, but at the same time I'm not sure they have a good track record. Despite that, this service should come from the government because anyone else has misaligned incentives. I specifically would want a privacy and security maximalist approach. What we have right now is completely unacceptable, especially given our current technology level. Though of course, the downside is also tha…
The government is the problem. They issue me a single identification number that can be used anywhere at anytime without any verification or notification that it has been used, and it's next to impossible to get a new one issued. This is madness. A state funded "insurance" system to backstop this mistake is an unworkable hack that seeks to ignore the fundamental problem.
The problem is third parties abused that number for their own purposes.
Imagine if some company somewhere started using phone numbers as identifiers, and criminals started defrauding that company by "stealing" other people's phone numbers. Would you blame the phone company for that? Of course not.
The problem is that banks and anyone else using SSNs need to do more due diligence than checking SSNs, but they don't want to because it would be expensive and add friction to signing up for their "products".
Re: Data leak contains 26B records from numerous previous breaches
#110Question that sounds idiotic but is quite serious: how do I make it illegal to lend money to me without confirmation via Keybase? (edit: or some similar cryptographic identity proof) The only reason to keep my name/address/SSN secret is that companies will lend money to a person who has that info, and then try to make me liable for it regardless of whether that person was me. That's a problem, but the solution isn't…
It's called a credit freeze: https://www.usa.gov/credit-freeze