Live data from Hacker News

Inside the "3 billion people" national public data breach

troyhunt.com

251–260 of 472 posts

Re: Inside the "3 billion people" national public data breach

#251
post #197

Earlier quoted context omitted.

That seems entirely like an implementation detail that doesn't have anything to do with the smart card interface itself. It's not like it's rocket science to have the reader application detail what the request is used for, and encoding it in the request/response, verified when used, so that it can't be used for anything but the approved purpose.

Why do you trust the reader though? It could display one thing and send another. Although I guess this also happens with payment card terminals. Who's to say the €3 displayed is not charged as €300...

This is a solved problem.

If the ID is on your phone, you can make it so that the transaction details have to be digitally signed by the person authorizing them in order to be valid. Then, if 3€ shows up on your phone, that's what you're authorizing, not 300€.

Re: Inside the "3 billion people" national public data breach

#252
post #35

Earlier quoted context omitted.

my understanding is that there's a bit of a catch-22 with data removal - if you request that a data broker remove ALL of your information, it's impossible for them to keep you from reappearing in their sources later on because that would require them to retain your information (so they can filter you out if you appear again).

Sorry, I value my legal rights over the viability of the data broker industry. If they can’t figure out a way for lawfully not collecting my data, they should not collect data period.

I mean, if we’re not allowed to know that we’re not allowed to surveil the shit out of you, it seems like something we can’t worry about

Re: Inside the "3 billion people" national public data breach

#253
post #237
post #107

Earlier quoted context omitted.

Private information on people is Equifax's IP.

A collection of facts is not and can not be copyrightable, especially when it was mechanically derived/collected (no human creativity). So, no, it is absolutely not "Equifax's IP".

Only in the US. In the EU and other jurisdictions is does have protection [1].

[1] https://en.wikipedia.org/wiki/Copyright_law_of_the_European_...

Re: Inside the "3 billion people" national public data breach

#255
post #48
post #35

Earlier quoted context omitted.

my understanding is that there's a bit of a catch-22 with data removal - if you request that a data broker remove ALL of your information, it's impossible for them to keep you from reappearing in their sources later on because that would require them to retain your information (so they can filter you out if you appear again).

I’ve heard this claim, but they could use some sort of bloom filter pr cryptographic hashing to block profiles that contain previously-removed records. There could also be a shared, trusted opt-out service that accepted information and returned a boolean saying “opt-out” or “opt-in”. Ideally, it’d return “opt-out” in the no-information case.

So for a perfect match they'd need to have some sort of unique identifier that's present in the first set of data you ask them to remove, as well as being present in any subsequent "acquisitions" or "scrapes" of your data.

If these devs that scrape/dump/collate all this info are anything like the ones I've seen, and they're functioning in countries like the US and UK whereby you don't have individual identifiers that are pretty unique, then I'd say the chance of them being able to get such a "unique" key on you to remove you perpetually, is next to impossible. And if it's even close to being "hard", they'll not even bother. Doubley-so if this service/people/data is anything like the credit-score companies, which are notoriously bad at data de duplication and sanitation.

Likewise, if you want them to do some sort of removal using things other than a unique identifier, then you have to have some sort of function that determines closeness between the two records. From what I've heard, places like Interpol, countries' border-control and police agencies usually use name, surname and dob as a combination to match. Amazingly unique and unchanging combination, that one! /s

Re: Inside the "3 billion people" national public data breach

#256

For years I've said the entire SSN database just needs to be published alongside legislation strictly assigning liability to any company who defrauded as a result of using the SSN as a "secret". That would fix the problem with SSN's and "identity theft" quickly. Part 1 has been accomplished. Let's get part 2 going! Aside: It amazes me how the American public has allowed defrauded companies to assign the company's los…

Ever since the Equifax breach I’ve been a proponent of a new national ID program to replace the SSN, that can be designed for what the SSN has become and tolerant to these never ending data breaches.

Maybe this will give a second chance at a conversation around that, but I’m not too hopeful.

Re: Inside the "3 billion people" national public data breach

#257

> The problem with verifying breaches sourced from data aggregators is that nobody willingly - knowingly - provides their data to them This is a bit of a tangent but I feel like if we can prove this statement then these data aggregators should be made illegal. How can you consent to something that you don’t know you’re consenting to? Likewise why do these entities have the right to collect detailed personal informati…

I have been using a different site@mydomain email address for every service I've used for the past 15 years. I can point to exactly which site breach furnished my email address to the aggregators.

Care to call out some bad actors so others know to avoid business with them?

I recently started using unique emails for everything I sign up for. Thankfully I haven’t seen anything yet, but I have little hope it will stay that way.

Re: Inside the "3 billion people" national public data breach

#258
post #238

Earlier quoted context omitted.

I think most of those right wingers are against illegal immigration. There's a big distinction here. I think very few of those so-called right-wingers are -say- against doctors immigrating to one's country if there's a doctor shortage. As long as immigration is all done using legal means. And with proper checks and balances. I'm a right winger (but not born and raised in the UK). And I am very much against illegal im…

There were just a series of mass race riots by right-wingers across the UK, in which they went around smashing up shops owned by immigrants and beating up people who don't look white. This isn't about illegal immigration. It's about racism.

conveniently emitting the fact that this is a reaction to immigrants going around randomly attacking birtish people. If you aren't already consider workong for MSM.

Re: Inside the "3 billion people" national public data breach

#260
post #77

For non-Americans (and Americans) that don't quite understand what SSN is and why it's a problem, CGP Grey [1] has a great (and short) video about the history and why it's not technically an identifier, but has become one. [1] https://www.youtube.com/watch?v=Erp8IAUouus

Not only an identifier, many places use it as a secret.

Plenty of places also use mother's maiden name as a password/secret too.
Post reply on HN