Earlier quoted context omitted.
I think you misunderstand their suggestion. If you only gave service providers access to encrypted data (i.e. End-to-end encryption), then neither the service provider nor the leaker would be able to decrypt. Whether or not that is a generally viable or desirable suggestion is a different question, but it is possible as demonstrated by Signal, Apple, etc.
There's only a limited number of things that can be done that way. Basically point-to-point messaging. Most things aren't going to work with that model. Can Amazon ship you products without knowing what you ordered? Can you send and receive email on multiple devices without the provider having your email? Can you join public chat groups? Can you view your lab results without the lab having them? And don't say "the la…
Data leak contains 26B records from numerous previous breaches
111–120 of 150 posts
Re: Data leak contains 26B records from numerous previous breaches
#112Earlier quoted context omitted.
I think you misunderstand their suggestion. If you only gave service providers access to encrypted data (i.e. End-to-end encryption), then neither the service provider nor the leaker would be able to decrypt. Whether or not that is a generally viable or desirable suggestion is a different question, but it is possible as demonstrated by Signal, Apple, etc.
There's only a limited number of things that can be done that way. Basically point-to-point messaging. Most things aren't going to work with that model. Can Amazon ship you products without knowing what you ordered? Can you send and receive email on multiple devices without the provider having your email? Can you join public chat groups? Can you view your lab results without the lab having them? And don't say "the la…
Well the whole point of not implicitly trusting third parties would be to remove Amazon from the equation altogether and instead be P2P with the shipper with just a protocol between us. If we need a third party, we can find another peer for that based on the intersection of our trust graphs. It doesn't have to be a global conglomerate with an IT department that we all have to trust implicitly. It could be Jimbob from down the road, who we both trust explicitly--this gets rid of high-value targets altogether.
Particl marketplace is pretty much this (no affiliation, I just like the idea).
Sure, I suppose there's still the possibility that the individual shipper was compromised, but like... Why? It's not exactly a juicy target. There would be no reason to really have a large database of addresses lying around. Print label, ship item, once receipt is acknowledged, delete address.
Re: Data leak contains 26B records from numerous previous breaches
#113Re: Data leak contains 26B records from numerous previous breaches
#114I feel like the people who calculate that it's more cost effective to deal with the hit from a security breach vs spending money on good security have won. I have gone from feeling outraged to completely numb to these kind of disclosures and have pretty much just assumed that my information will inevitably be leaked somewhere by someone. Does anyone else feel this way? I just keep a close eye on my financial statemen…
Fast forward to 2021, apple released hide-my-email which I use practically everywhere which forwards to a burner email just in case. Every site gets a unique email, password, two-factor. I’ll never have 0 risk but this limits my exposure so much it lets me sleep at night. I only provide real information if absolutely required by law.
Re: Data leak contains 26B records from numerous previous breaches
#115I feel like the people who calculate that it's more cost effective to deal with the hit from a security breach vs spending money on good security have won. I have gone from feeling outraged to completely numb to these kind of disclosures and have pretty much just assumed that my information will inevitably be leaked somewhere by someone. Does anyone else feel this way? I just keep a close eye on my financial statemen…
Probably about 10-12 years ago I almost exclusively used +emails so I could determine with pretty high confidence who had breaches and failed to disclose OR identify companies that had sold my data without disclosure. One of the most recent examples was Robinhood Holdings. +emails only got me so far as 50% of sites don’t properly support the RFC5233 subaddressing standard and it ended up being a massive pain when a s…
Re: Data leak contains 26B records from numerous previous breaches
#116I feel like the people who calculate that it's more cost effective to deal with the hit from a security breach vs spending money on good security have won. I have gone from feeling outraged to completely numb to these kind of disclosures and have pretty much just assumed that my information will inevitably be leaked somewhere by someone. Does anyone else feel this way? I just keep a close eye on my financial statemen…
Probably about 10-12 years ago I almost exclusively used +emails so I could determine with pretty high confidence who had breaches and failed to disclose OR identify companies that had sold my data without disclosure. One of the most recent examples was Robinhood Holdings. +emails only got me so far as 50% of sites don’t properly support the RFC5233 subaddressing standard and it ended up being a massive pain when a s…
Re: Data leak contains 26B records from numerous previous breaches
#117I feel like the people who calculate that it's more cost effective to deal with the hit from a security breach vs spending money on good security have won. I have gone from feeling outraged to completely numb to these kind of disclosures and have pretty much just assumed that my information will inevitably be leaked somewhere by someone. Does anyone else feel this way? I just keep a close eye on my financial statemen…
Re: Data leak contains 26B records from numerous previous breaches
#118Earlier quoted context omitted.
It’s time for attorney generals to hold permanent identity monitoring pots and funds. The idea that someone can lose all your data and then pay for two years of identity monitoring is absurd. The people with the data can see that and can just wait two years to sell it. Social security numbers don’t reset after two years. If you lose data, you pay a data breach tax forever. Over time, your competitors will be able to…
It also incentivizes holding as little personal data as possible and increases the probability of coordinated adoption of systems[1][2][3][4][5] of identification/verification that minimize collateral damage. 1. https://sovrin.org/ 2. https://github.com/sertoID/ 3. https://www.hyperledger.org/projects/hyperledger-indy 4. https://identity.foundation/ion/ 5. https://www.civic.com/
The government does not want to incentivize that.
Re: Data leak contains 26B records from numerous previous breaches
#119How is this the mother of all beaches when it is the child of several smaller breaches?
Re: Data leak contains 26B records from numerous previous breaches
#120Question that sounds idiotic but is quite serious: how do I make it illegal to lend money to me without confirmation via Keybase? (edit: or some similar cryptographic identity proof) The only reason to keep my name/address/SSN secret is that companies will lend money to a person who has that info, and then try to make me liable for it regardless of whether that person was me. That's a problem, but the solution isn't…
Minus all the complicated implementation details, this is possible. It's called a credit freeze: https://www.usa.gov/credit-freeze
- https://usa.experian.com/mfe/regulatory/security-freeze
- https://my.equifax.com/membercenter/#/freeze
- https://service.transunion.com/dss/freezeStatus.page
Ignore anything about “locking” your credit, because this made up term is not the one that has been defined by Congress. “Freezing” your credit is the real action, and it also must be free of charge. The direct links are useful, because the CRAs definitely want to mislead you into purchasing unnecessary services.