Live data from Hacker News

Black Hat: GDPR privacy law exploited to reveal personal data

bbc.co.uk

11–20 of 239 posts

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#11
post #4

> Mr Pavur says he believes he did not break the law himself while conducting the trial This is a bit odd. I know his partner consented to this, but this doesn't seem like it should be enough to make this not identity fraud. Obviously the research Pavur carried out is extremely valuable and the mid-sized companies failing to follow proper procedure are the real problem here, but it still seems like it would be techni…

Regardless it would then be a bad law since almost all criminal law looks at intent and reasonable expectations of how a citizen should act.

We don’t need to keep replaying the vilification of security researcher game just because it involves the flawed gov systems imposed on technology itself instead of just technology. The end goal is the same, the privacy and security of end users.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#12
post #2

This is pretty appalling, really: "Overall, of the 83 firms known to have held data... 24% supplied personal information without verifying the requester's identity." Want someone else's personal data? No need to "hack into" any systems; just ask for it!

This was actually one of the risks we identified when looking at GDPR for my own businesses last year. Given that in some cases all we have is an online account with minimal personal details, how can we possibly verify their identity to an acceptable standard if someone does send us a GDPR subject access request of any kind? If they have some sort of account with us already and that has associated ID and security che…

Government officials created an untenable law in the name of the technological boogey man?!

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#13
post #2

This is pretty appalling, really: "Overall, of the 83 firms known to have held data... 24% supplied personal information without verifying the requester's identity." Want someone else's personal data? No need to "hack into" any systems; just ask for it!

This was actually one of the risks we identified when looking at GDPR for my own businesses last year. Given that in some cases all we have is an online account with minimal personal details, how can we possibly verify their identity to an acceptable standard if someone does send us a GDPR subject access request of any kind? If they have some sort of account with us already and that has associated ID and security che…

"but what if they don't or they claim to have forgotten their password etc?"

How do you manage this kind of use case in your normal operation? Does it mean that if you cannot reset your password your account is locked forever? If not how is this process less valid to answer a GDPR request?

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#14
post #6
post #5

> "But the kind of mid-sized businesses that knew about GDPR, but maybe didn't have much of a specialised process [to handle requests], failed." I wonder if there is a market for selling GDPR compliance / advising services. Some company that makes sure your doing everything right, and inspects the requests for validity.

There are quite a few firms offering compliance / advisory services, including ones that'll host the data request forms etc. for you. I'm not aware of any willing to take on the liability of verifying identities as part of that, though.

WhireWheel, Onetrust, and a slew of others (https://iapp.org/resources/privacy-industry-index-pii-vendor...) offer a DSAR module/platform to handle this.

they definitely won't be held liable per their contract nor handle the verification for you, but they do provide a system (a ticketing systems really) with a set of workflows that help put an identity verification system in place. It's nothing magic, but it definitely helps the privacy lawyers and DPOs who will end up bothering you with verifying all the data and providing it if needed.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#15
post #8
post #6

Earlier quoted context omitted.

There are quite a few firms offering compliance / advisory services, including ones that'll host the data request forms etc. for you. I'm not aware of any willing to take on the liability of verifying identities as part of that, though.

Do you know of any companies that handle the whole process, similar to how stripe handles the whole purchasing process?

replyed to the wrong comment, see parent comment for my reply :)

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#16
post #8
post #6

Earlier quoted context omitted.

There are quite a few firms offering compliance / advisory services, including ones that'll host the data request forms etc. for you. I'm not aware of any willing to take on the liability of verifying identities as part of that, though.

Do you know of any companies that handle the whole process, similar to how stripe handles the whole purchasing process?

Can you elaborate by what do you mean with "the whole process"? If you have some internal processes that handle the data, then you can't really separate and outsource the "GDPR part" without outsourcing the whole business process that handles the data - e.g. if you ship goods, then handling of adresses can't (IMHO) be separated from the shipping, if you run a website, then the handling of all the related privacy issues can't be separated from running the website.

Furthermore, even if you outsource the whole business process that handles sensitive data, you're still the 'controller' of the data, and you still carry full responsibility for it - you can and should have legal arrangements with the processor to recoup your damages/costs if they screw up, but you're the party that's directly liable, and if the processor can't/won't pay, that's solely your problem.

You can outsource certain parts of GDPR compliance - such as handling the paperwork and managing the customer enquiries properly, but it's hard(impossible?) to separate "the whole process" from the rest of your business.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#17
This is horrible. So right now, in order to get access to data for a certain person, you need to hack your way through a few of the potential services he is using and drive from there.

1. The data might have things like IDs (ie: Crypto exchanges).

2. You can use that data to ask for more data. If you got a copy of his passport, now you can ask for more with this new piece.

3. Looks like some people still store passwords in plain text or don't mind exchanging that over email. This means some of these service might reveal a password to you.

4. With that, you can start hacking into other accounts. You also have loads of knowledge about the person, so you might be able to guess his password.

5. Now you have access to his email, dropbox, banking details and maybe even lock him out.

Right about time: https://en.wikipedia.org/wiki/Cobra_effect

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#18
post #2

This is pretty appalling, really: "Overall, of the 83 firms known to have held data... 24% supplied personal information without verifying the requester's identity." Want someone else's personal data? No need to "hack into" any systems; just ask for it!

This was actually one of the risks we identified when looking at GDPR for my own businesses last year. Given that in some cases all we have is an online account with minimal personal details, how can we possibly verify their identity to an acceptable standard if someone does send us a GDPR subject access request of any kind? If they have some sort of account with us already and that has associated ID and security che…

> we don't have any special knowledge of what official government-issued ID looks like in every country where we have customers, nor the human resources or automated technology to investigate in detail whether any ID that is sent might be faked.

This sounds like one of the risks of doing international business. If you can't follow the laws then don't play.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#19
This is a reflection of the fact that we have no good way for someone to digitally prove their identity. Some countries are getting close-ish - Denmark's NemID system, for example, is used by a lot of financial institutions.

However, there remains no easy way to make ad-hoc verifiable statements like 'I am John Smith and I authorise you to send this data to xyz@example.org'.

Governments, please solve this problem! Essentially: combine NemID with Keybase and build a UI that normal citizens can understand.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#20
post #19

This is a reflection of the fact that we have no good way for someone to digitally prove their identity. Some countries are getting close-ish - Denmark's NemID system, for example, is used by a lot of financial institutions. However, there remains no easy way to make ad-hoc verifiable statements like 'I am John Smith and I authorise you to send this data to xyz@example.org'. Governments, please solve this problem! Es…

> Governments, please solve this problem!

I would prefer governments to solve it with competent Software Engineers in the mix and maybe other professionals from the finances and IT security industries, but never one single large entity.

Post reply on HN