Live data from Hacker News

1k Data Breaches Later, the Disclosure Lag Is Worse

troyhunt.com

101–110 of 133 posts

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#101

there will be more data breaches. Google and Apple are throttling hotfix updates (for app developers) as tons of code pushes to their infra (by vibe coders) is straining their system. The are fixing this by throttling updates to minimum 3 days review period. so good luck fixing the vulnerability or data leaks in your apps.

Dont worry the vibecoders will tire out, they're the same people who were making NFTs and mining bitcoin, they'll move onto the next hot thing soon enough. Its more an archetype, not necessarily the same exact people. They dont commit long term.

>Dont worry the vibecoders will tire out

This seems to rhyme with "Don't worry, the spammers will tire out"

Narrator: "The spammers in fact, did not tire out"

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#102
post #13

Earlier quoted context omitted.

I don't think he meant "show the actual data," I think he meant "what leaked? My name, address, phone number, email, medical records, payment history, bank account number?" We get a "your private data is now public" email, but knowing exactly what data turns that from a depressing statement on how much corporations value their customers' privacy into something actionable.

Yes, I meant the actual data so you know what leaked. There is a difference between leaking a password 12345678 and leaking a password that was reused on a different site. There is a difference between leaking your actual birthday and leaking 01/01/1900. There is a difference between leaking a fake address, your previous address, and your current address.

Then feel free to browse the onion and buy data that you may be included in.

There seems to be some amount of entitlement by people in this thread to get information from a third party about what a first party to them lost.

The first party that lost your data should be the one that shows you exactly what was compromised.

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#103

So at the risk of sounding incredibly apathetic toward something that I'm sure is probably a massive headache for some people somewhere... I'm a millennial and I've been told probably hundreds of times by this point in my life that my data has been breached. Not a single one of those times was there a) anything truly actionable for me to do about it[0] or b) a single negative impact to my actual life. In anyway. At a…

My anecdote story about this is as someone with all of their credit frozen and generally best practices for password security (password manager, no reuse, offline only vault for important things) I ended up getting caught up in a ghost student loan scam. More info/background here https://www.equifax.com/business/blog/-/insight/article/ghos...

I failed to realize that I needed to secure a studentaid .gov account someone was able to open in my name with data breach information.

Thankfully my credit was frozen so I didn’t need to untangle an actual loan, but it would have been a huge legal mess otherwise.

I guess my fear is what account am I going to miss securing next that leads to a giant life ruining problem? If I didn’t setup credit freezes someone else could have with the info in the breaches. I didn’t even think to secure a studentaid account I didn’t know existed. In theory having those credit bureau accounts frozen should be enough, but anyone with enough information on you can likely recover them regardless.

To me the whole experience really drives home how much of a joke the security on a lot of this is. Anyone who seriously sets their eyes on you can just totally ruin your life if they’re dedicated enough.

Though most people doing this its much more effective to take advantage of people who don’t know any better. Credit not frozen, loan accounts not made or secured, etc. Pwning 20 people doing nothing will always be better ROI than trying to PWN one person with their stuff in order. Until you piss the wrong person or they think you’re worth the effort.

I guess I can see how you can view it as not your problem. But there are only so many grandmas to scam. The whole problem space to me metaphorically is everyone’s door is wide open, grandmas is just a straight shot to get in. Mine? Well I have some ball bearings, calipers, and a moat but the doors still open. It’s not like someone is going to rob my open house instead of grandma. I only have to dodge all the traps when I leave and come back but that’s whatever.

The whole thing is absurd. We have doors and locks and better ways to do this and instead we just live like this?

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#104
post #92

Earlier quoted context omitted.

Katherine Archuleta and Donna Seymour aren't writing code or administering online systems. I'm sure their organizations have security policies and standards, why not put the devs and sysadmins in prison if they didn't follow them? I think that what we're seeing is evidence that humans, in general, are not capable of securely delivering the kinds of online services that they are trying to deliver. It's just too compli…

>why not put the devs and sysadmins in prison if they didn't follow them So we should start treating them like licensed engineers... Actually I agree with this.

When the Minneapolis bridge collapsed there were no criminal charges involved. HN has this obsession with "licensed engineers" as if it completely prevents catastrophe and holds people to the highest standards. It's just a dog and pony show.

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#105
post #92

Earlier quoted context omitted.

>why not put the devs and sysadmins in prison if they didn't follow them So we should start treating them like licensed engineers... Actually I agree with this.

When the Minneapolis bridge collapsed there were no criminal charges involved. HN has this obsession with "licensed engineers" as if it completely prevents catastrophe and holds people to the highest standards. It's just a dog and pony show.

I mean, 40 years is a bit longer than the garbage we're making lasts.

And software holds people to exactly zero standards and it shows.

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#106
post #48
post #11

Earlier quoted context omitted.

A minor problem with GDPR is enforcement. At least in germany it feels like you need a very dedicated and persistent person to make the case against a company/service (bonus points if they get media attention). Other countries are a bit better but it generally is not very consistent. The enforcement for most small to mid-sized companies is often just not present and resources for relevant agencies are often only relu…

At least there is the very dedicated and persistent https://noyb.eu :)

NOYB has been ghosting me since January, and EFF since September.

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#107
post #86
post #19

For years, I've been trying my best to stay low-key when it comes to my personal information on the internet. I don't create new accounts, I never cross-login with my email address, I don't use phones. Certainly not perfect, but a lot of times I'm preferring privacy over convenience. At the same time, my government and society at large is pushing more and more for "digital everything". It's great when it works. But t…

We need to attach actual monetary amounts to PII. If a company loses the data they owe you that money. The money is increased based on how and if they disclosed the leak. Lying about a leak should be a criminal offense. This would would allow engineers to better be able to prioritize security, which typically gets ignored or put low in priority.

I think we should exempt this from double-jeopardy: the fines are considered purely-punitive, and are in addition to any civil or criminal penalty issued by the courts. This will help ensure that organisations can't just price data breaches in to "move fast and break things" and have no further liability, and that people who've experienced damages much greater than the standard fine don't lose their chance to get suitable compensation.

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#108
post #3

Is there ANY business motivation for any corporation to open such information up sooner than later?

Depends where they are in the world. I _think_ GDPR would be a good enough business reason, as they set a ticking clock of 72 hours from the breach to notifying individuals who are in the breach. And the fines involved are pretty steep (almost effing vertical for some).

And if they don't disclose, nothing happens anyway. Maybe a five figure "cost of doing business" slap on the wrist fine, not considering the amount of users affected. Enforcement is extremely selectiveand bureaucrats essentially operate on "if company in FAANG, take action, else do nothing" programming.

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#109

So at the risk of sounding incredibly apathetic toward something that I'm sure is probably a massive headache for some people somewhere... I'm a millennial and I've been told probably hundreds of times by this point in my life that my data has been breached. Not a single one of those times was there a) anything truly actionable for me to do about it[0] or b) a single negative impact to my actual life. In anyway. At a…

> a single negative impact to my actual life. In anyway. At all.

This is missing the broader perspective of identity becoming less reliable, and that results is millions of paper cuts in everyday life.

The reason you need to scan your face with your phone to access a government site or your bank is hugely because asking people personal questions or a password has become useless.

There is an argument that the old security models wouldn't have survived for long either way, but if we see it as an arms race, racing at a slower pace is still better than running like there's no tomorrow towards the bitter end.

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#110

So at the risk of sounding incredibly apathetic toward something that I'm sure is probably a massive headache for some people somewhere... I'm a millennial and I've been told probably hundreds of times by this point in my life that my data has been breached. Not a single one of those times was there a) anything truly actionable for me to do about it[0] or b) a single negative impact to my actual life. In anyway. At a…

I don’t know the leak, but I had someone take out multiple credit cards by phones on loan with my Social Security card. I had to freeze my credit score on all the providers (which I think is ridiculous that I have to like. Tell another company that I didn’t even sign up for to pause the account that they created for me)

And then go to each company and bag them to except that this was a fraudulent situation and not me. If they didn’t accept my request, then I would basically be out of luck, owing them the money.

These data leaks are great opportunities for doxing. You can look up all the people that have died from swatters.

Post reply on HN