Live data from Hacker News

Covid Test Data Breach: 1.3M Patient Records Exposed Online

vpnmentor.com

71–80 of 143 posts

Re: Covid Test Data Breach: 1.3M Patient Records Exposed Online

#71

Earlier quoted context omitted.

How many temperature readers now log the information to the cloud?

Doesn't matter if there's no way to tie it back to the individual; that is, the information on whose temperature is never available to the reader.

That depends on how many people work in the particular area with the particular reader, and what their general patterns of arrival to work are, and what their general patterns of body temperature are.

Re: Covid Test Data Breach: 1.3M Patient Records Exposed Online

#72

I feel frequent data leaks, credit card number leaks, difficulty in un-subscribing or stopping payments after subscribing, etc... makes me appreciate and want to use consolidated sign in / subscription management / payment management options almost exclusively.

Until there's a breach of the SSO providers, like the Okta incident.

Okta, Lastpass, Jumpcloud, Authy, Auth0..

the list of hacked SSO providers gets longer by the day.

Re: Covid Test Data Breach: 1.3M Patient Records Exposed Online

#73
post #10

I feel frequent data leaks, credit card number leaks, difficulty in un-subscribing or stopping payments after subscribing, etc... makes me appreciate and want to use consolidated sign in / subscription management / payment management options almost exclusively.

It's a bit like keeping money... You can stash it under your mattress, hoping you'll never suffer a burglary; or you can give it to a bank, and let them spend money on security and insurance. This said, banks have specific fiduciary responsibilities and the above-mentioned insurance, which compensate for the big target they're painting on their own backs; whereas most tech services, even massive ones, tend to hide be…

>and increased risk of identity fraud that we endure.

The problem is even worse than that. The whole framing of the issue of identity theft as a thing that happens to a person rather than a bank is problematic. That the bank issued credit in my name to someone other than me really should be entirely their problem, not one that probably messes up my life for years.

Re: Covid Test Data Breach: 1.3M Patient Records Exposed Online

#74

Earlier quoted context omitted.

Until there's a breach of the SSO providers, like the Okta incident.

Okta, Lastpass, Jumpcloud, Authy, Auth0.. the list of hacked SSO providers gets longer by the day.

DIY or die

Re: Covid Test Data Breach: 1.3M Patient Records Exposed Online

#75
post #22

Earlier quoted context omitted.

Apple can be hacked like anyone else.

Shared passwords place you at risk if any of serval services are hacked. Password managers provide similar convenience with a smaller attack surface. I’ve defaulted to picking random passwords for most services which I don’t bother to remember instead using password resets. But it’s inconvenient.

Yeah, I just randomize mine and keep all of that local. It's a bit strange seeing people doing the same, but over the wire though.

Re: Covid Test Data Breach: 1.3M Patient Records Exposed Online

#76

Earlier quoted context omitted.

Doesn't matter if there's no way to tie it back to the individual; that is, the information on whose temperature is never available to the reader.

That depends on how many people work in the particular area with the particular reader, and what their general patterns of arrival to work are, and what their general patterns of body temperature are.

From an absolute "can this be correlated?" perspective, sure. From a "is this data easily mine-able" or "if someone gets this data, will I care?" perspective, not so much.

Re: Covid Test Data Breach: 1.3M Patient Records Exposed Online

#77
post #63

Earlier quoted context omitted.

Generally, the use of the word 'coerced' involves threat of force, which approximately zero employers invoked. When you use it to describe conditions of employment, you're conflating violence with company policy. Most people at this point are going to infer that you have some kind of problem with the pandemic response, whether they agree with you or not. So, that's likely the dogwhistle being referred to here. Meanwh…

>Generally, the use of the word 'coerced' involves threat of force, which approximately zero employers invoked Yes. Forcing someone to choose between losing their job or undergoing unusual and routine mandatory, invasive medical procedures, which can lead to consequences like those mentioned in the above article, constitutes coercion.

That's not the commonly-accepted interpretation of coercion. Under this definition, "forcing" someone to choose between losing their job and doing the work they were hired to do also constitutes coercion. Losing your job because you declined to comply with company policy does not constitute violence. Insisting that your modified definition is the correct one does not advance the discourse in a productive manner.

Re: Covid Test Data Breach: 1.3M Patient Records Exposed Online

#78

Earlier quoted context omitted.

difficult isn't the word as opposed to "hilarious", "waste of energy", "deaf ears", "lack of focus on what can be controlled"

I like to think the Dutch don't fall for conspiracies' as much. But there was that whole 'Tulip mania' thing that happened.

tongue in cheek reference but based in a flawed but pervasive understanding of that event

government modification of derivatives contracts, war right beyond the border (affecting delivery of supply), total gaps in price discovery possibly due to plague... this is probably one of the worst examples of anything irrational, despite being the poster child

Re: Covid Test Data Breach: 1.3M Patient Records Exposed Online

#79

During the height of COVID, I was exploring the API design of the top-selling COVID tests on Amazon. Several had wildly unsecured APIs—sequential patient IDs but the results endpoint assumed knowing the “secret” patient ID counted as auth. Or just completely open GraphQL implementations, no different than a password-less db… For anyone considering DIYing a diagnostics program, don’t. But I’m biased (I’m the founder o…

The fact that at-home tests had an API of any sort was already a major screwup IMO.

Re: Covid Test Data Breach: 1.3M Patient Records Exposed Online

#80

During the height of COVID, I was exploring the API design of the top-selling COVID tests on Amazon. Several had wildly unsecured APIs—sequential patient IDs but the results endpoint assumed knowing the “secret” patient ID counted as auth. Or just completely open GraphQL implementations, no different than a password-less db… For anyone considering DIYing a diagnostics program, don’t. But I’m biased (I’m the founder o…

I was working for the NL government on COVID stuff and the only thing I can say is that it's a shame I'm under NDA. It changed my view of the tech industry and I feel silly for calling colleagues in the past out for what I consider inadequate practices. As all were far above the mean.

I am surprised there isn’t some law in NL that would allow you to expose it either to the public or maybe at least to MPs and not be bound by NDA.
Post reply on HN