Live data from Hacker News

Inside the "3 billion people" national public data breach

troyhunt.com

331–340 of 472 posts

Re: Inside the "3 billion people" national public data breach

#331
post #170

From the NPD website: > Please be advised that we will not collect, use, disclose, sell, or share the sensitive personal information or sensitive data of California, Virginia, Colorado, or Connecticut residents as those terms are defined by the CCPA/CPRA, VCDPA, CPA, or CTDPA, respectively.

We need more laws like this, then. Federal ones.

You think this stopped them from aggregation? It didn't...

Re: Inside the "3 billion people" national public data breach

#332

Earlier quoted context omitted.

They could store a hash.

Which would never work because real life data is messy so the hashes would not match. Even something as simple as SSN + DOB runs into loads of potential formatting and data entry issues you'll have to perfectly solve before such a system could work, and even that makes assumptions as to what data will be available from each dataset. Some may be only name and address. Some may include DoB, but the person might have li…

There's a trivial way to not re-add data that was removed: don't do it without user opt-in, whom admittedly you have access to ask at the moment of data collection. If you don't have the ability to ask users to opt in, you probably shouldn't be collecting the data anyway, with very few exceptions like criminal records.

edit for clarity: by criminal records, I mean for the official management of them, not for scraping their content.

Re: Inside the "3 billion people" national public data breach

#333
post #112
post #17

Earlier quoted context omitted.

Could cause you to be listed as deceased in some database sending your life into a Kafka story.

"How do you know he's dead?" "I called him on the phone and he told me!"

Called on the phone - and the person who picked it up said the dude was dead.

Which is how it plays out when someone dies, generally, and the family is there dealing with the aftermath. FYI.

Re: Inside the "3 billion people" national public data breach

#335

Anything the average SSN holder should be doing proactively?

You could freeze your credit, it you wanted to be careful. Realistically though, you should have already been monitoring to check if unexpected things were being done in your name. I’ve presumed that all our SSNs have been out there for years now due to one hack or another, that this hack just makes it indisputable doesn’t change much.

Re: Inside the "3 billion people" national public data breach

#336
post #300
post #42

Earlier quoted context omitted.

I knew someone falsely declared dead (probably a paperwork mixed up around pensions when his ex-spouse died). Without warning, he lost all of his pensions, social security, medicare, etc, along with most financial institutions freezing accounts and canceling credit cards. Many long phone calls, letters, and lawyers eventually resolve most, but that never fully purged the public and private death records so there woul…

You'd think something like that would require a death certificate to actually happen

most places do. though often a poor quality faxed copy is sufficient

Re: Inside the "3 billion people" national public data breach

#337
post #48

Earlier quoted context omitted.

I’ve heard this claim, but they could use some sort of bloom filter pr cryptographic hashing to block profiles that contain previously-removed records. There could also be a shared, trusted opt-out service that accepted information and returned a boolean saying “opt-out” or “opt-in”. Ideally, it’d return “opt-out” in the no-information case.

Hash-based solutions aren't as easy as we might hope. You store a hashed version of my SSN, or my phone number, to represent my opt-out? Someone can just hash every number from 000-00-0000 to 999-99-9999 and figure out mine from that. You hash the entire contents of the profile - name+address+phone+e-mail+DOB+SSN - and the moment a data source provides them with a profile only containing name+address+email - the miss…

> Someone can just hash every number from 000-00-0000 to 999-99-9999 and figure out mine from that.

That's what salts are for, right? It wouldn't be too hard to issue a very large, known, public salt alongside each SSN.

> And of course none of the data brokers have much reason to make opt-outs work well, in the absence of legislation and strict enforcement - it's in their commercial interests to say they "can't stop your data reappearing"

This is the actual reason, IMHO.

Re: Inside the "3 billion people" national public data breach

#338
post #253
post #237

Earlier quoted context omitted.

A collection of facts is not and can not be copyrightable, especially when it was mechanically derived/collected (no human creativity). So, no, it is absolutely not "Equifax's IP".

Only in the US. In the EU and other jurisdictions is does have protection [1]. [1] https://en.wikipedia.org/wiki/Copyright_law_of_the_European_...

So I could copyright my SSN in the EU and sue Equifax et al.?

Re: Inside the "3 billion people" national public data breach

#339
post #96

Earlier quoted context omitted.

Well then you're up against the wall of digital verification. I know there's a fuck load of situations where the banks are 100% screwing the customer to their benefit, but there's a legit conversation about people who give out their passwords, or claim they did, when money gets wiped out. If you meet all the requirements to identify yourself to the bank, at what point does the bank have to say "this is that person, a…

> If you meet all the requirements to identify yourself to the bank, at what point does the bank have to say "this is that person, and that transaction is legal". Our current system is entirely built on ridiculous levels of trust, mostly for convenience / cost saving reasons. I've made payments over the phone with nothing more than the information found on the bottom of every check I've ever sent. I routinely hand my…

> Our current system is entirely built on ridiculous levels of trust, mostly for convenience / cost saving reasons.

Paging patio11: https://www.bitsaboutmoney.com/archive/optimal-amount-of-fra...

Re: Inside the "3 billion people" national public data breach

#340
post #41

Earlier quoted context omitted.

> It's hard to make collection, aggregation, and sharing of facts illegal. Sure, but the US has a precedent in HIPAA. Not saying it's copy-paste, but... maybe it should be. I would prefer the law be more restrictive than less, because I don't believe this is true: > law is justifiably looking for a scalpel treatment here to address the specific problem without putting the quest to understand reality on the wrong side…

As someone who helps care for elderly relatives with widely-dispersed out-of-state families, I can point to HIPAA as an excellent example of why crafting this kind of law is difficult. I think we are going to discover, once people do the research, that HIPAA has done net harm by delaying flow of information for critical-care patients resulting in lack of patient compliance, confusion, and treatment error. Yes, there…

> HIPAA has done net harm by delaying flow of information for critical-care patients resulting in lack of patient compliance, confusion, and treatment error.

You won't find any disagreement from me that HIPAA is very complicated. However there's a certain level of whining and foot dragging that happens in the industry that we should take with a massive grain of salt. There's so many HIPAA compliant and still convenient ways these days to have patient communications, but the industry doesn't want to invest and doesn't care about patience experience enough, and then go "sorry, HIPAA :-(((" every time.

With GDPR, after Schrems II happened and it became clearer that the EU-US Privacy Shield was no longer a valid workaround, I personally observed companies (including the one I was in) suddenly moving mountains to complete migration projects and privacy upgrades in just a few months that the industry previously deemed was technically unfeasible or impossible, cost prohibitive, business destroying, etc. And they still remained massively profitable and growing. If they had just done the right thing early on it wouldn't have been on such a tight deadline either.

That was the final straw for me in terms of being very firmly convinced that we should be telling companies to shut up and comply a lot more because they will never do the right thing on their own even if it wasn't /that/ hard. Another approach here is to start holding them liable for the personal costs of data breaches etc and let the incentives take care of themselves. In fact, why not a bit of both?

Post reply on HN