Live data from Hacker News

Covid Test Data Breach: 1.3M Patient Records Exposed Online

vpnmentor.com

101–110 of 143 posts

Re: Covid Test Data Breach: 1.3M Patient Records Exposed Online

#101
post #98

It seems that anyone entrusted with private information will eventually be breached. I think that there should be legislation - strong legislation - that protects our society's individuals and their information. Make it an uncomfortable and costly responsibility to collect information, store it temporarily and long-term. Additionally, connecting devices to the internet directly or indirectly should have the same sort…

That's what we have in the EU.

Re: Covid Test Data Breach: 1.3M Patient Records Exposed Online

#102
post #100

We should have well defined mechanisms for sunsetting and destroying data.

As Charlie Munger said "Show me the incentive I'll show you the outcome"

Banks have this dialed in, it's called a "personal guarantee"

You lose our money, you're personally bankrupt

Pretty well aligns the incentives

Find something comparable for data, no question the problem will improve

Re: Covid Test Data Breach: 1.3M Patient Records Exposed Online

#103
post #44
post #32

Earlier quoted context omitted.

The “instant” tests that can be done without a lab are not anywhere near as accurate as lab tests.

Lab test require visiting place where you meet infected people.

I had several and was never in close proximity to anyone other then the staff.

Re: Covid Test Data Breach: 1.3M Patient Records Exposed Online

#104

I feel frequent data leaks, credit card number leaks, difficulty in un-subscribing or stopping payments after subscribing, etc... makes me appreciate and want to use consolidated sign in / subscription management / payment management options almost exclusively.

That doesn't do much to protect you against a website storing government mandated passport information. The only protection there would be if authorities stop demanding that everyone takes copies of personal IDs.

Is my passport information really that precious? It doesn’t contain much that isn’t on my birth certificate, apart from my ugly mug. And quite literally anyone can get an officially certified copy of my birth certificate, because that’s a matter of public record.

Re: Covid Test Data Breach: 1.3M Patient Records Exposed Online

#105
post #77

Earlier quoted context omitted.

>Generally, the use of the word 'coerced' involves threat of force, which approximately zero employers invoked Yes. Forcing someone to choose between losing their job or undergoing unusual and routine mandatory, invasive medical procedures, which can lead to consequences like those mentioned in the above article, constitutes coercion.

That's not the commonly-accepted interpretation of coercion. Under this definition, "forcing" someone to choose between losing their job and doing the work they were hired to do also constitutes coercion. Losing your job because you declined to comply with company policy does not constitute violence. Insisting that your modified definition is the correct one does not advance the discourse in a productive manner.

I don't know if you are being willfully obtuse but coercion doesn't have to be physical. Feel free to consult any dictionary.

Re: Covid Test Data Breach: 1.3M Patient Records Exposed Online

#106
post #79

During the height of COVID, I was exploring the API design of the top-selling COVID tests on Amazon. Several had wildly unsecured APIs—sequential patient IDs but the results endpoint assumed knowing the “secret” patient ID counted as auth. Or just completely open GraphQL implementations, no different than a password-less db… For anyone considering DIYing a diagnostics program, don’t. But I’m biased (I’m the founder o…

The fact that at-home tests had an API of any sort was already a major screwup IMO.

It's not necessarily a problem, you just have to be sensible about security practices. To be clear, at-home tests mean you collect the sample at home and then mail them in, not the test is run at home. (disclaimer, I work at Spot)

Re: Covid Test Data Breach: 1.3M Patient Records Exposed Online

#107
post #10

I feel frequent data leaks, credit card number leaks, difficulty in un-subscribing or stopping payments after subscribing, etc... makes me appreciate and want to use consolidated sign in / subscription management / payment management options almost exclusively.

It's a bit like keeping money... You can stash it under your mattress, hoping you'll never suffer a burglary; or you can give it to a bank, and let them spend money on security and insurance. This said, banks have specific fiduciary responsibilities and the above-mentioned insurance, which compensate for the big target they're painting on their own backs; whereas most tech services, even massive ones, tend to hide be…

The bigger difference between a mattress and a bank is that a mattress can't create new money or operate on a fractional reserve system.

Re: Covid Test Data Breach: 1.3M Patient Records Exposed Online

#108
post #92

Earlier quoted context omitted.

Banks KYC practices normalized this.

I have no problem showing ID to my local bank though. They at most photocopy it and put it in a paper file, which maybe goes into Docstar or something. I don't trust $big_tech_site to actually a) do a good job securing it and b) not just sell the information to someone anyway. It's silly. AT&T wanted it from me to add a phone on a business account that was shipping to our physical address, which has not ever changed…

Definitely say no.

Re: Covid Test Data Breach: 1.3M Patient Records Exposed Online

#109

Earlier quoted context omitted.

I have no problem showing ID to my local bank though. They at most photocopy it and put it in a paper file, which maybe goes into Docstar or something. I don't trust $big_tech_site to actually a) do a good job securing it and b) not just sell the information to someone anyway. It's silly. AT&T wanted it from me to add a phone on a business account that was shipping to our physical address, which has not ever changed…

Definitely say no.

I do when I can. For AT&T I was able to just go to the store and do it. For eBay, we had to acquiesce as they were holding sales payouts hostage.

Re: Covid Test Data Breach: 1.3M Patient Records Exposed Online

#110

Earlier quoted context omitted.

Definitely say no.

I do when I can. For AT&T I was able to just go to the store and do it. For eBay, we had to acquiesce as they were holding sales payouts hostage.

They won’t protect it. Is small claims court an option?
Post reply on HN