Live data from Hacker News

1k Data Breaches Later, the Disclosure Lag Is Worse

troyhunt.com

11–20 of 133 posts

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#11
post #3

Is there ANY business motivation for any corporation to open such information up sooner than later?

Depends where they are in the world. I _think_ GDPR would be a good enough business reason, as they set a ticking clock of 72 hours from the breach to notifying individuals who are in the breach. And the fines involved are pretty steep (almost effing vertical for some).

A minor problem with GDPR is enforcement.

At least in germany it feels like you need a very dedicated and persistent person to make the case against a company/service (bonus points if they get media attention). Other countries are a bit better but it generally is not very consistent.

The enforcement for most small to mid-sized companies is often just not present and resources for relevant agencies are often only reluctantly allocated. Ime, in government institutions it is generally not very respected as it "impedes progress".

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#12
At this stage just expect that every accounts will get leaked or rooted, it's a matter of when, not if...

Use varying email `plus addressing` (john+am2604@foo.com), varying passwords or passkey and 2FA on anything remotely important (use of your identity, not just financials).

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#13
post #6

>why is it still needed? It's not needed. There are already alternatives that could take its place. Some of them are able to actually show you what data leaked instead of leaving you blind of what was actually included in the breach.

This is a bad idea, for multiple reasons. https://www.troyhunt.com/here-are-all-the-reasons-i-dont-mak...

I don't think he meant "show the actual data," I think he meant "what leaked? My name, address, phone number, email, medical records, payment history, bank account number?"

We get a "your private data is now public" email, but knowing exactly what data turns that from a depressing statement on how much corporations value their customers' privacy into something actionable.

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#14
post #10

there will be more data breaches. Google and Apple are throttling hotfix updates (for app developers) as tons of code pushes to their infra (by vibe coders) is straining their system. The are fixing this by throttling updates to minimum 3 days review period. so good luck fixing the vulnerability or data leaks in your apps.

I am not sure I get the connection between AI code holding up review processes and data breaches.

The post made a pretty clear claim, I thought: the volume of apps being sent through is so extreme that they can't keep up with their review process.

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#16
post #13
post #6

Earlier quoted context omitted.

This is a bad idea, for multiple reasons. https://www.troyhunt.com/here-are-all-the-reasons-i-dont-mak...

I don't think he meant "show the actual data," I think he meant "what leaked? My name, address, phone number, email, medical records, payment history, bank account number?" We get a "your private data is now public" email, but knowing exactly what data turns that from a depressing statement on how much corporations value their customers' privacy into something actionable.

This information is shown on the site of the breach, as example: https://haveibeenpwned.com/Breach/BakerDistributing

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#17
post #12

At this stage just expect that every accounts will get leaked or rooted, it's a matter of when, not if... Use varying email `plus addressing` (john+am2604@foo.com), varying passwords or passkey and 2FA on anything remotely important (use of your identity, not just financials).

The + trick is useless to protect you, obviously. Instead, use a a service like simplelogin to create unique emails for every place you sign in.

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#18
post #12

At this stage just expect that every accounts will get leaked or rooted, it's a matter of when, not if... Use varying email `plus addressing` (john+am2604@foo.com), varying passwords or passkey and 2FA on anything remotely important (use of your identity, not just financials).

I recommend people use proper email aliasing, not plus addressing. Duckduckgo makes a free one that's can integrate into Bitwarden, if you have iCloud+ Apple's($0.99/month) hide my email is good. Addy.io and SimpleLogin are the best and allow PGP encryption to prevent another party having access to your emails, but they are paid for full features.

> Organizations like the IAB require that advertisers normalize email addresses so that they can be correlated and tracked, regardless of users' privacy wishes.

https://www.privacyguides.org/en/email-aliasing/#over-plus-a...

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#19
For years, I've been trying my best to stay low-key when it comes to my personal information on the internet. I don't create new accounts, I never cross-login with my email address, I don't use phones. Certainly not perfect, but a lot of times I'm preferring privacy over convenience.

At the same time, my government and society at large is pushing more and more for "digital everything". It's great when it works. But to me, every new service translates to a new opportunity for my data to be leaked.

I think one reason why we're still seeing so many breaches is that security is hard and thus expensive - and on the other hand, other than customer push-back, companies or other providers have pretty much nothing to worry about when their data gets extorted. To me, this is impossible. When I give my private data to them, I'm giving them something very valuable. If being careless with that value basically has no consequences, the incentives to care are low.

We need to establish measures of accountability for data holders. Not securing customer data appropriately needs to be persecutable, and the affected parties need to be given a right for compensation. Of course, that's not going to happen. It would be difficult to implement in practice, if at all possible. But as long as there is no monetary incentive for data holders to be as careful as possible, the laxness is going to continue.

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#20

there will be more data breaches. Google and Apple are throttling hotfix updates (for app developers) as tons of code pushes to their infra (by vibe coders) is straining their system. The are fixing this by throttling updates to minimum 3 days review period. so good luck fixing the vulnerability or data leaks in your apps.

Dont worry the vibecoders will tire out, they're the same people who were making NFTs and mining bitcoin, they'll move onto the next hot thing soon enough. Its more an archetype, not necessarily the same exact people. They dont commit long term.
Post reply on HN