Live data from Hacker News

9M Australians affected by Optus data breach

optus.com.au

11–20 of 104 posts

Re: 9M Australians affected by Optus data breach

#12
This is bad. Australia isn't know for it's strong privacy laws anyway, but with the kind of data that's now available out there, ID theft is going to be a huge risk for almost half the country. Even if Optus gets sued, how the hell are people supposed to protect themselves?

Re: 9M Australians affected by Optus data breach

#13
I’ve seen Optus “computer security” in action. I use quotes for a reason.

There was a court-enforced order requiring them to apply security updates to their production systems. That was in response to a previous breach.

You see, until a judge made them do it… they weren’t patching anything. They would just build systems and walk away. For some software systems they had every major and minor version deployed, like a museum of software history.

They had operating system versions in production that were in my university text books… in the late 1990s.

Their interpretation of the court order was to update only production systems. Non-production on the same network was not to be touched.

And by “update” they meant simply running the system update tool, which does precisely nothing on software that has passed its end-of-extended-support before some of the IT staff on the payroll were born.

They also fired their entire IT staff recently and replaced them with a low-cost Indian outsourcer.

Most of the above is a matter of public record. I wish I could tell you all about things that are still under NDA.

Re: 9M Australians affected by Optus data breach

#15
post #10

A mobile company that wants so much of their users ID info. Is it really necessary for them to get all that user info?

Good question. I think the idea is you can’t have a burner phone. Well you can…for example use a foreign sim card of a less fussy telco. But in general this makes it harder to have a burner. Once we get to a point where telcos are not needed to make calls (that amazon wifi mesh for example) maybe we can do away with this need for ID anyway because it is futile.

Re: 9M Australians affected by Optus data breach

#18
post #10

A mobile company that wants so much of their users ID info. Is it really necessary for them to get all that user info?

Yes it's legally required for them to properly verify your identity both for credit reasons (on a postpaid plan) and simply to identify who owns what phone number s

Re: 9M Australians affected by Optus data breach

#19
post #10

A mobile company that wants so much of their users ID info. Is it really necessary for them to get all that user info?

Yes. You need to provide legal id to get a phone number in Australia. This is handled by the phone companies themselves. But this is probably a good reason to not let them do it themselves.

Re: 9M Australians affected by Optus data breach

#20

I’ve seen Optus “computer security” in action. I use quotes for a reason. There was a court-enforced order requiring them to apply security updates to their production systems. That was in response to a previous breach. You see, until a judge made them do it… they weren’t patching anything. They would just build systems and walk away . For some software systems they had every major and minor version deployed, like a…

You can tell how broken their tech is when you try and use the website. Half the pages just fail to load. I don't mean time out, I mean, they think they are finished loading but most of the page is missing.
Post reply on HN