Live data from Hacker News

PayPal says personal data may be compromised for 1.6M TIO users

foxbusiness.com

11–20 of 44 posts

Re: PayPal says personal data may be compromised for 1.6M TIO users

#11
post #5

Isn't it time we criminalize any kind of data leaks by a company? This has to be seriously discussed now. That is the only way we can make these companies keep data security at the top of their priority list. I know it is a subsidiary of paypal, not paypal itself, but that is irrelevant.

FTFY: That is the only way we can make sure companies will avoid disclosing breaches for sure and to have them pursue a burnt-and-salted-earth-approach towards anyone who might turn up evidence of a breach.

Perhaps if the penalty is based on days since exposure--immediately revealing the breach gets you a minimal fine, but waiting six weeks is enough to cause a major fine (or add to sentences for fraudulent trading related to the incident), and years is even bigger?

Re: PayPal says personal data may be compromised for 1.6M TIO users

#12
post #5

Isn't it time we criminalize any kind of data leaks by a company? This has to be seriously discussed now. That is the only way we can make these companies keep data security at the top of their priority list. I know it is a subsidiary of paypal, not paypal itself, but that is irrelevant.

FTFY: That is the only way we can make sure companies will avoid disclosing breaches for sure and to have them pursue a burnt-and-salted-earth-approach towards anyone who might turn up evidence of a breach.

Pretty much becomes “blame the messenger” in a hurry. That and these comments quickly become “why didn’t they just do it the ‘right’ way...as if such a thing existed. With security there is no right way, just many known wrong ways.

I got into a discussion once about how to properly handle passwords (cause somebody has to do it). There is no right answer, just lots and lots of wrong ones. Don’t encrypt, hash. But not that hash, use another...and not any of those over there; and sure as shit don’t write one yourself. Use an off-the-shelf hash...just not any that you have access to now. Not that one either, we don’t recognize the author by name...and not the other one because we don’t like the owner of the company (who is not a developer).

TL:DR, if you write code that needed security...eventually you are fucked.

Re: PayPal says personal data may be compromised for 1.6M TIO users

#14

Aside: a downside of Know-Your-Customer laws (and anything else that requires your to upload personal data to web services) is now that data can be compromised as well. Maybe there should be less such requirements.

Or requirements to not keep data unless for a legitimate business purpose.

Re: PayPal says personal data may be compromised for 1.6M TIO users

#15
This is ridiculous. Does anyone have any insight into how these security breaches keep happening? Is it rampant carelessness on the part of the companies, some new technology that's opening a significant number of new exploits, or is it an escalation on the efforts/persistence of hackers?

Re: PayPal says personal data may be compromised for 1.6M TIO users

#18

> PayPal will offer affected TIO consumers free credit-monitoring services through Experian Plc, the spokesman said. What's the point anymore? This has happened so many times this year I've got more credit monitoring than I could ever need . Now I just need them to actually redo the "identity" system into something I can actually use with peace of mind.

Absolutely. Such a remedy is completely inadequate as compensation for the damage done to those whose personal information has been compromised.

Re: PayPal says personal data may be compromised for 1.6M TIO users

#19
post #8

Earlier quoted context omitted.

The victim is not the company. It is the users - people like you and me. Let me say it again - companies are NOT the victims.

Companies have a reasonable obligation to protect our data, so I'm with you if they were negligent in prevention, detection, mitigation, or revelation. If they took reasonable measures to prevent, and were forthcoming if compromised anyway, and took measures to minimize damage to users, there's no reason to blame them.

It's OUR data, and WE as individuals are the ones who have to clean up the mess after aggregators spill it.

Perfect security is impossible, but let's not forget 1) who is harmed, or 2) who is getting rich and who will in a worst case will cut their losses, go bankrupt, then start another company with the accumulated weath.

Re: PayPal says personal data may be compromised for 1.6M TIO users

#20
post #19

Earlier quoted context omitted.

Companies have a reasonable obligation to protect our data, so I'm with you if they were negligent in prevention, detection, mitigation, or revelation. If they took reasonable measures to prevent, and were forthcoming if compromised anyway, and took measures to minimize damage to users, there's no reason to blame them.

It's OUR data, and WE as individuals are the ones who have to clean up the mess after aggregators spill it. Perfect security is impossible, but let's not forget 1) who is harmed, or 2) who is getting rich and who will in a worst case will cut their losses, go bankrupt, then start another company with the accumulated weath.

It's not YOUR data. It belongs to the COMPANY. If I draw a sketch of you sitting on a subway, sorry, but you don't own the sketch.
Post reply on HN