Live data from Hacker News

Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

abc.net.au

101–110 of 169 posts

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#101
Paypal are terrible and should be closed down.

I had a paypal account. They demanded copies of my govt. ID. I refused and said close the account. I only ever used it to make payment to web shops using my credit card.

Paypal refused repeatedly to simply close the account given their change in terms of service to which I do NOT agree.

Will someone hack into paypal? Absolutely they will and it will have happened multiple times since this debacle. Will someone hacking paypal then use this account which should not exist to do something that causes a problem for me?

Paypal are responsible for this. This is 100% paypal's problem. Paypal should be on the wrong end of the most expensive litigation seen in this are from which they do not survive.

Paypal's actions in this area are quite deliberate and they know and understand the consequences to people.

Paypal are foul.

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#102
post #85

The tl;dr is that the victim was Australian and the court proceedings were heard in the US. Unless they're put before a court in Australia she's under no obligation to pay. Knowing a bit about Australian society it would not go down well if they tried. I would've used the money she spent on a US IP lawyer to sue Medibank for negligently allowing her personal information to be hacked and sold on the dark web. At the v…

She’s under no obligation to pay but I do wonder if she ever decides to take a trip to the US if she will be escorted away from the airport under police escort on landing. That’s a big worry if I was in her shoes.

The next big data breach in Australia will be from the wave or realestate rental “startups”, it’s only a matter of time.

The sites are badly designed which doesn’t give much faith in security. Also the largest being a Murdoch subsidiary which I guess the data conveniently has huge money value for ad targeting…

The online rental application companies collect (require) more data than any paper rental application form, credit card/bank/mortgage application, or visa application. It’s also unregulated! They’ve positioned themselves so a large number of rental applications have to go through them to apply. The amount of detailed sensitive pii data they hold has to be huge. It’s a treasure trove for any hacker and an easier target than a bank or insurance company.

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#103
To give context to people who may have not heard; there has been a MASSIVE amount of high profile data breaches in the Australia in the past 12 months with zero consequences for the businesses involved.

In a 6 month period I had; - My private health insurance data leaked (AHM/Medibank) - including claim history, medicare number, password, username, email, phone - My old phone account (Optus) - including my phone number, my current passport number(!!!), current address, phone. - My old credit card account (Latitude finance) - including my current passport, driver license, my income history and bank statements that was provided to get the credit card originally, address, phone, email

The ONLY thing that any of these businesses have done is pay for a replacement passport and a 12 month credit watch. Optus wasn't even a 'breech', they had an API exposed with the all the data!

How is someone meant to protect themselves from this? It is pure negligence. Until governments legislate that the punishment for exposing personal data is more expensive than the work and infrastructure required to keep it secure this will continue to happen.

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#105
post #4

Situations like these keep bringing me back to the idea that important actions should require an actual, in person, human notary seal. Contract signings, online court service, title changes, etc should not be valid without an offline record examiner who affirms under threat of perjury that the parties involved are who they claim (or are claimed to be).

Some countries/jurisdictions do exactly that, and trust me, it's a massive pain in the ass. Would you really want to visit a notary just to set up an eBay account? Because that's what you're proposing. The existing system isn't foolproof but, by and large, it works perfectly well. If the transactions in TFA truly were fraudulent, no court is going to hold her liable. The bigger problem here is a US court being happy…

>Would you really want to visit a notary just to set up an eBay account?

Yes.

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#106
post #94
post #42

Earlier quoted context omitted.

It’s entirely possible to do this digitally and have it working seamlessly. In Denmark we have a thing called “MitID” (MyID) which is basically a government login and which you can use to sign and also login to all kinds of things that need to confirm your identity (e.g. Phone subscription, taxes, 3DS verification for Credit Card transactions, etc). It’s essentially 2FA, works by the site sending a confirmation to an…

And then...your govt login is stolen and you are back to square one with "identity theft". National ID systems are such nonsense it is appalling there are people stupid enough to think this is a Good Thing. Easy is NOT always better. The best things in life are definitely not free.

The bar to stealing it is way different now though.

You would have to steal a username + phone + PIN code for phone + PIN code for MitID app.

If that happens, then it would also be trivial to unlink the app from that phone.

At no point in time would you be unaware of the theft here.

Contrast this to what happens in the US often: your personal info is leaked from the plethora of places it’s kept. Someone can now in perpetuity exploit your identity, or at the very least for a long time until you find out randomly.

Which system sounds better to you? I sure know that I’d prefer the first one.

I’d welcome any actual arguments against it, but you’ve not really presented any at all so far.

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#107

Earlier quoted context omitted.

Yes thank you. This is my "actually it's GNU + Linux" tic, please fellow Americans (and I would be interested in learning if this problem exists in other countries) do not accept the framing that a bank giving a loan to someone they thought was you is _your problem_! It's their problem! We should not be normalizing this phrase or practice.

> I would be interested in learning if this problem exists in other countries In Norway you can voluntarily register as not wanting to allow credit assessments to be performed on you. This in turn can help a bit because it results in most attempts at making loans in your name not being possible. https://www.datatilsynet.no/regelverk-og-verktoy/sporsmal-sv... There are four companies in Norway that do credit assessmen…

You can do this in America. It’s called a credit freeze. A problem is credit freezes can also be fraudulently lifted, but serve as a decent barrier for most run of the mill mass frauds. They’re virtually unknown and require you to independent contact each individual credit bureaus to both freeze then unfreeze.

https://consumer.ftc.gov/articles/what-know-about-credit-fre...

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#108

Earlier quoted context omitted.

Ex parte just means it’s an emergency and you need the court to move fast

No, ex parte means not requiring a party that would normally be required. It is _also_ used in emergencies because the process of pleadings, answers, and replies would be too slow, so you are asking the court to temporarily ignore the rule that the other party respond before the court issues some sort of order or response.

You still have to argue your way out of notice.

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#109

Earlier quoted context omitted.

> I would be interested in learning if this problem exists in other countries In Norway you can voluntarily register as not wanting to allow credit assessments to be performed on you. This in turn can help a bit because it results in most attempts at making loans in your name not being possible. https://www.datatilsynet.no/regelverk-og-verktoy/sporsmal-sv... There are four companies in Norway that do credit assessmen…

You can do this in America. It’s called a credit freeze. A problem is credit freezes can also be fraudulently lifted, but serve as a decent barrier for most run of the mill mass frauds. They’re virtually unknown and require you to independent contact each individual credit bureaus to both freeze then unfreeze. https://consumer.ftc.gov/articles/what-know-about-credit-fre...

> They’re virtually unknown...

I (and millions of other people) learned how to do a credit freeze after having our personal info leaked in the Equifax data breach of 2017:

https://en.wikipedia.org/wiki/2017_Equifax_data_breach

Having that credit freeze saved me from at least two attempted frauds since then - I was notified by two credit card issuers that credit card applications in my name that I had never made were rejected because my credit file was frozen.

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#110

"Identity Theft" shouldn't even be a thing. Someone falsifies documents and takes out a loan or something that should not have been approved. That's bank fraud and should be an issue entirely between the fraudster and the lender/bank. Somehow banks have re-named it from "bank fraud" to "identity theft," deftly shifting responsibility onto some unrelated third party, who now has to deal with it. "Your identity was sto…

This is a spot on. Now how do we make force a change on the legal framework to make this mind shift happen?
Post reply on HN