It seems that anyone entrusted with private information will eventually be breached. I think that there should be legislation - strong legislation - that protects our society's individuals and their information. Make it an uncomfortable and costly responsibility to collect information, store it temporarily and long-term. Additionally, connecting devices to the internet directly or indirectly should have the same sort…
Covid Test Data Breach: 1.3M Patient Records Exposed Online
101–110 of 143 posts
Re: Covid Test Data Breach: 1.3M Patient Records Exposed Online
#102We should have well defined mechanisms for sunsetting and destroying data.
Banks have this dialed in, it's called a "personal guarantee"
You lose our money, you're personally bankrupt
Pretty well aligns the incentives
Find something comparable for data, no question the problem will improve
Re: Covid Test Data Breach: 1.3M Patient Records Exposed Online
#103Re: Covid Test Data Breach: 1.3M Patient Records Exposed Online
#104I feel frequent data leaks, credit card number leaks, difficulty in un-subscribing or stopping payments after subscribing, etc... makes me appreciate and want to use consolidated sign in / subscription management / payment management options almost exclusively.
That doesn't do much to protect you against a website storing government mandated passport information. The only protection there would be if authorities stop demanding that everyone takes copies of personal IDs.
Re: Covid Test Data Breach: 1.3M Patient Records Exposed Online
#105Earlier quoted context omitted.
>Generally, the use of the word 'coerced' involves threat of force, which approximately zero employers invoked Yes. Forcing someone to choose between losing their job or undergoing unusual and routine mandatory, invasive medical procedures, which can lead to consequences like those mentioned in the above article, constitutes coercion.
That's not the commonly-accepted interpretation of coercion. Under this definition, "forcing" someone to choose between losing their job and doing the work they were hired to do also constitutes coercion. Losing your job because you declined to comply with company policy does not constitute violence. Insisting that your modified definition is the correct one does not advance the discourse in a productive manner.
Re: Covid Test Data Breach: 1.3M Patient Records Exposed Online
#106During the height of COVID, I was exploring the API design of the top-selling COVID tests on Amazon. Several had wildly unsecured APIs—sequential patient IDs but the results endpoint assumed knowing the “secret” patient ID counted as auth. Or just completely open GraphQL implementations, no different than a password-less db… For anyone considering DIYing a diagnostics program, don’t. But I’m biased (I’m the founder o…
The fact that at-home tests had an API of any sort was already a major screwup IMO.
Re: Covid Test Data Breach: 1.3M Patient Records Exposed Online
#107I feel frequent data leaks, credit card number leaks, difficulty in un-subscribing or stopping payments after subscribing, etc... makes me appreciate and want to use consolidated sign in / subscription management / payment management options almost exclusively.
It's a bit like keeping money... You can stash it under your mattress, hoping you'll never suffer a burglary; or you can give it to a bank, and let them spend money on security and insurance. This said, banks have specific fiduciary responsibilities and the above-mentioned insurance, which compensate for the big target they're painting on their own backs; whereas most tech services, even massive ones, tend to hide be…
Re: Covid Test Data Breach: 1.3M Patient Records Exposed Online
#108Earlier quoted context omitted.
Banks KYC practices normalized this.
I have no problem showing ID to my local bank though. They at most photocopy it and put it in a paper file, which maybe goes into Docstar or something. I don't trust $big_tech_site to actually a) do a good job securing it and b) not just sell the information to someone anyway. It's silly. AT&T wanted it from me to add a phone on a business account that was shipping to our physical address, which has not ever changed…
Re: Covid Test Data Breach: 1.3M Patient Records Exposed Online
#109Earlier quoted context omitted.
I have no problem showing ID to my local bank though. They at most photocopy it and put it in a paper file, which maybe goes into Docstar or something. I don't trust $big_tech_site to actually a) do a good job securing it and b) not just sell the information to someone anyway. It's silly. AT&T wanted it from me to add a phone on a business account that was shipping to our physical address, which has not ever changed…
Definitely say no.