Live data from Hacker News

Revolut confirms customer data breach through fake government requests

techcrunch.com

121–130 of 139 posts

Re: Revolut confirms customer data breach through fake government requests

#121

Earlier quoted context omitted.

What else are you supposed to do? All bank require BYC and will ask you to control your identity. We shouldn’t blame customers for the fintech company mistakes

Some banks, I assume, allow showing the documents in person and without a selfie.

Just showing documents? I never saw a bank that will do this. They always make a copy.

Re: Revolut confirms customer data breach through fake government requests

#122

Storing identification data (like a scanned passport) is not necessary. The question is “did you check the customer identity?” And if the answer is Yes, then you can mark it as such. You don’t need to store these scans at all.

Actually you do have to store those, as proof (but MUST be destroyed after 10 years). This is very typical in AML (Anti Money Laundering) laws.

Good thing there's, at least EU wide, EUDI (EU Digital Identity Wallet) around the corner which legally allows using cryptographic proofs instead of just storing as much data as possible of the user.

This addresses exactly this issue of having to disclose this amount of information solely as proof.

Re: Revolut confirms customer data breach through fake government requests

#124

Earlier quoted context omitted.

My card issuer just gives me a credit when I want to chargeback. They're like, oh you don't want to deal with a real chargeback, just have your money back for free. I would've pressed it since I kinda wanted the company to regret ripping me off, but I already got my money back so it wasn't worth the extra effort.

That's how chargebacks often work. Then they ask the merchant for evidence the charge was legitimate. If convinced, they will retract that initial quick refund.

Real chargebacks claw the money back from the merchant. They don't just provide a credit.

Re: Revolut confirms customer data breach through fake government requests

#125
post #99

Earlier quoted context omitted.

You do not need to compromise anything, you can put any address in the "from" field. Email has no universal verification for sender address.

I would sincerely hope .gov addresses use SPF/DKIM/DMARC. That makes spoofing impossible. In Revolut's case, the sender's email system had been compromised.

And what about the rest of the world?

Re: Revolut confirms customer data breach through fake government requests

#126

Earlier quoted context omitted.

The government did request the data. And since the announcement, it has requested highly sensitive data again, and to keep such data, backed by threats of violent repercussions, that businesses cease to operate or to even exist. That's a dangerous kind of threat to be making, and to act upon. for information that should remain private let alone owned by the bank itself.

> The government did request the data. What's your source? That is not what the news says. Also, you know you can easily impersonate any email? That's a flaw of the email protocol.

I never wrote the government made the specific request that led to the leak. I explain that the government make such requests.

So when a company is requested to hand over sensitive data, they do. For sure when the origin of the request is the government itself (pawned email in this case)

Re: Revolut confirms customer data breach through fake government requests

#127
post #12

How can this happen to a modern fintech... Esp. handling identity verification so poorly? > A Revolut spokesperson confirmed to TechCrunch that a “limited” number of customers were impacted and said the company had contacted those customers directly. Revolut, however, did not disclose the exact number of impacted individuals. It also did not answer whether the incident was limited to a specific market and declined to…

Revolut is built on move-fast-break-things. They make things cheaply, quickly, and it (mostly) works.

But yeah there is always a downside when moving fast, oops

Re: Revolut confirms customer data breach through fake government requests

#128
post #2

Even if the trigger was spoofed, how come there is no secure channel that the govt provides to receive the data? Was this one also compromised?

That may not matter that much, as even if you run a relatively strict policy about where you send the reply, you can still easily get bitten by external mistakes there: Because of the huge number of individually administered departments that might each become authorized recipient of such data, a malicious party only needs to find one suitably dangling DNS delegation to score a "…@attacker-controlled-subdomain.legitim…

I think you missed the point - delivery of sensitive data should involve public key encryption of some sort and it should ideally be done through an application or website that's purpose-built for this.

It should be made impossible for someone at Revolut (and every other org) to deliver this data into the wrong hands by accident.

Re: Revolut confirms customer data breach through fake government requests

#129
post #92

Earlier quoted context omitted.

>The implication that the solution to this is to somehow convince your direct competitors to do inferior in-person KYC for you is the most ridiculous thing. People work with their competitors all the time (see Netfix vs Amazon). Whats ridiculuous is the claim that a scammer would prefer to show up physically at a bank and risk being exposed instead of operating remotely. >leaking a selfie is pretty low down on the li…

No, it’s most certainly patently ridiculous. > Whats ridiculuous is the claim that a scammer would prefer to show up physically at a bank and risk being exposed instead of operating remotely. Of course they wouldn’t prefer to show physically. What does that mean though? Are you saying no scammers showed up physically to banks, therefore banking fraud rates are less? Do you have a source for that? > don't some of them…

>No, it’s most certainly patently ridiculous

Is your argument supposed to be more convincing because you added the word "patently"?

>What does that mean though?

It means that when you find a way to bypass purely online identity verification checks executing fraud at scale is easier than the physical alternative. As you would say, this is patently obvious.

Re: Revolut confirms customer data breach through fake government requests

#130

Earlier quoted context omitted.

Some banks, I assume, allow showing the documents in person and without a selfie.

You assume wrong if you’re taking about old-school banks. They’ll still scan your id and it ends up in the same system

Not necesary, it might be an internal system. And no selfie. For example, in Russia it probably would be illegal to send personal and biometric data abroad. But of course in the West the rules might be different and it is ok to send citizens' data to shady foreign companies.

Also I am surprised people do not see the different between isolated internal "old school" systems built on owned servers located at the bank property and modern vibe-coded microservices in kubernetes in a rented cloud with the widest attack surface possible.

Post reply on HN