Live data from Hacker News

French government agency confirms breach as hacker offers to sell data

bleepingcomputer.com

101–110 of 168 posts

Re: French government agency confirms breach as hacker offers to sell data

#101
There’s something to be said about old school bureaucratic institutions: it made breaches like this significantly more difficult to pull off and far less valuable as a result.

It also ensured democratic participation by all of the people employed there making sure that processes are followed and making sure no one is cheating.

We all knew that systems like this would get breached. It’s not a matter of, “if,” but, “when.” If we’re going to continue down this route because of convenience or surveillance and authoritarianism or whatever; people designing these systems need to thinking: When this system is breached…. And they should make sure there’s a good story for protecting people and the system from these sorts of events.

Re: French government agency confirms breach as hacker offers to sell data

#102

This shit should be stored encrypted not in plaintext.

The attacker will then simply use the decryption key to decrypt it.

Then the headline would be French goverment loses encryption keys ..

Re: French government agency confirms breach as hacker offers to sell data

#105

It seems to me we must move away from worrying about ransomware, data breach, data protection as that ship has already sailed and everyone's PII has already been stolen. We should think of how to verify people's identities online (for things like government benefits etc). I have heard of the Dutch and the Japanese using national digital identity systems although I am unclear how they work. India is doing biometrics.…

[dead]

Re: French government agency confirms breach as hacker offers to sell data

#106
post #65

Earlier quoted context omitted.

Wait, you don’t even get a month of free credit monitoring?

The credit system is not the same in Europe, first of all there is no such thing as credit rating and what not. People don't have credit card like the one in US and Canada. The vast majority use a debit card.

We do very much have credit rating in Germany, might be very different than the one in the US, don’t know theirs.

Re: French government agency confirms breach as hacker offers to sell data

#107

Earlier quoted context omitted.

Biometrics are the only credential you can't roll after compromise.

It depends what the biometrics are. There have been successful hand transplants, so new finger prints are possible, but completely impractical. https://en.wikipedia.org/wiki/Hand_transplantation

Thinking about it, I probably wouldn't remember to change my fingerprints to the new ones with all the services I use, I'd probably have to carry my "legacy fingerprints" wherever I go for some time to avoid a lockout.

Re: French government agency confirms breach as hacker offers to sell data

#108
post #10

> the data stolen in the breach could include full names, dates and places of birth, mailing and email addresses, and phone numbers on an undisclosed number of citizens Nothing really new here sadly, this information about me have leaked half a dozen of times in the past 2-3 years or so. These things will never change if the only penalty the company/agency gets is "send a message to your users saying you are sorry an…

Wait, you don’t even get a month of free credit monitoring?

Heh, for real, it's maddening how often this is the "solution" to any breach. It's especially lovely when it comes from multiple companies at the same time, that may or may not have leaked your SSN.

Re: French government agency confirms breach as hacker offers to sell data

#110
post #75
post #31

Earlier quoted context omitted.

My full name, phone number, and address were leaked by TAP Air Portugal about five years ago, along with the details of my parents who were on the same booking. Since then, my dad has been targeted by those types of scams where a fraudster impersonates me to ask for money. I never received a notification from TAP; I only found out a year later through my Google One security feature. I certainly didn't get an apology—…

The world of today is so weird sometimes. When I was a kid most adults' full name, phone number, and address were available for free in the phone book.

If the scam success rate is 0.1%, and it takes days to comb a phone book and put together a list of potential relationships and takes a human 10 minutes per phone call, the economics of scamming works out a lot less profitable than importing a data leak and emailing or robocalling everyone in the list.
Post reply on HN