Live data from Hacker News

1k Data Breaches Later, the Disclosure Lag Is Worse

troyhunt.com

121–130 of 133 posts

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#121
A problem of incentives. How can we fix it?

Advertising tied to liquidated damages.

1. Any company handling PII must prominently advertise a amount of money per user they must pay in cash in the event of a data breach. This is a mandatory minimum payment and does not preclude subsequent lawsuits on specific damages.

2. Any claim of security or privacy must prominently advertise that amount earlier and in larger text than any other statement: “We provide 25 cents of security.”

3. In the event of data breach, your first notification must inform all affected partys and you immediately become tentatively liable for your data breach amount. Any affected party not notified in the initial disclosure receives 3x damages in the event their data was lost.

4. You may disclose to partys that you now know they are not affected. In the event that their data was lost they will receive 3x damages.

5. In the event of a data breach, you must issue your first notification within 1-7 days of when you discover it or are informed of it. Failure to do so constitutes a first notification to 0 partys, so you become liable for 3x damages to all users.

6. A data breach of any vendor you supplied PII to constitutes a breach.

1 and 2 align marketing with capability. 3 and 4 prevent underreporting. 5 prevents late reporting. 6 prevents diffusion of responsibility or the creation of scapegoat entitys and incentivizes only using vendors who properly track data provenance so their lawyers can tell your lawyers your users are unaffected.

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#122
post #101

Earlier quoted context omitted.

Dont worry the vibecoders will tire out, they're the same people who were making NFTs and mining bitcoin, they'll move onto the next hot thing soon enough. Its more an archetype, not necessarily the same exact people. They dont commit long term.

>Dont worry the vibecoders will tire out This seems to rhyme with "Don't worry, the spammers will tire out" Narrator: "The spammers in fact, did not tire out"

The hilarious part is that spam actually makes money, while slop does not. There's no reason to tire out if it's profitable, right?

Meanwhile.. have you ever paid for a vibe-coded anything? Why would you, when you (along with everyone else) can slop the same thing together in a weekend with a $20 CC subscription?

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#123

I have a custom domain for my emails with catch all. When I create an account somewhere I just use @my-domain.com Can I find out if any of my emails are in leaks with a service somewhere?

While others pointed out that Have I Been Pwned is (kind of) for this specific purpose, there is a limit of like 10 email addresses. Beyond that, you will have to have a paid subscription. You'll still get "alerts" without the subscription, but have no way of seeing which email addresses have made it into a leak somewhere. And the pricing cliff was pretty steep if I recall correctly.

Minimum ~$50 / year for 1 domain and up to 25 breached email addresses. https://haveibeenpwned.com/Subscription

I'm just one guy, but I have a lot of project domains. If I wanted to monitor 5 domains, it would cost me $443 / year.

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#124
post #3

Is there ANY business motivation for any corporation to open such information up sooner than later?

Depends where they are in the world. I _think_ GDPR would be a good enough business reason, as they set a ticking clock of 72 hours from the breach to notifying individuals who are in the breach. And the fines involved are pretty steep (almost effing vertical for some).

> as they set a ticking clock of 72 hours from the breach to notifying individuals who are in the breach

It doesn't, that 72 hours is for notifying the DPA (Article 33). There is no strict timeline for data subject notification (Article 34), just that it must be done "without undue delay".

And the time limits start running when controller becomes aware of the breach (be it minutes or years after the actual breach). If processor is breached the time limits only start running once they notify the controller. Time limit to notify controller is "without undue delay" (33(2)). I don't think there is a lot of case law around what that exactly means.

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#125
post #78

Earlier quoted context omitted.

I don't use Paypal. My credit cards protect me from fraud. And it rarely happens. In fact it's been well over a decade since I had a fraudulent charge on any of my payment cards. Funny how when there's motivation, protection happens.

> My credit cards protect me from fraud. Your credit card protect you against nothing. Reimbursement in case of fraud is not fraud protection, it is just bare minimal customer service. In fact, the first thing your bank will do when your credit card number has been leaked and was used for a fraud... is to replace your credit card. Because they know that, when the number is in the wild, it will happen again. The syste…

I'm not trying to be snarky, but it sounds like you have never had to implement an online payment system directly using a merchant account. If you've only used something like Stripe, there's a lot of requirements and compliance that the card companies do that has been abstracted away.

Visa & Mastercard have pretty singularly forced online payments to the level of security they are currently at. PCI compliance is pretty much solely driven by the card companies. If your payment details leak then yes, they want to issue you a new card. Half of that is making the customer feel better, but the other half is that the secrets need to be rotated since they've been exposed. SSH keys aren't vulnerable if generated properly, but if you expose the private key then the key needs rotated.

If you actually follow PCI compliance standards, there is no way to leak a customer's full payment details that I'm aware of. You could still leak other PII, but card # and CVC are something you can't access even with admin privileges on your recurring billing app.

So the card companies do quite a lot to protect against fraud and make people comfortable using their cards for online purchases. They just do this by requiring merchants to follow specific minimum practices. I'm not trying to glaze them, there is more they could do; and they do this to protect their bottom line. But fraud charges cost them a lot of money, and their interests align with consumers in this case to prevent fraud as much as they can.

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#126
post #64

Earlier quoted context omitted.

> If done right, it is not incompatible with a system where identities can be reconstructed by the authorities for legal actions. Doing it right is exactly the thing that makes this impossible. If instead you give everyone a unique barcode that every other pseudonym can be tied back to, do you really think that database will never be breached? It would become the prime target for all attackers in the world. Meanwhile…

> Doing it right is exactly the thing that makes this impossible. [...] do you really think that database will never be breached? It would become the prime target for all attackers in the world. Critical data is always better in the hand of a few (trustable) than in the hands of many. That is currently the exact reason why you are using Paypal instead of giving your credit card number to everybody. That is the exact…

> Critical data is always better in the hand of a few (trustable) than in the hands of many.

Centralizing identity so that your ID number becomes "crucial data" is worse than not doing this so that the "crucial data" doesn't exist. This is the natural conclusion of your own logic -- having it in the hands of zero entities is better than having it in the hands of one.

Case in point:

> That is currently the exact reason why you are using Paypal instead of giving your credit card number to everybody.

The reason this is happening is that credit cards use the card number as a secret, which is insane.

Imagine a payment system that works like this: The merchant gives the client a request for payment, which is only the amount of the bill and the deposit routing number of the merchant -- specifically a number that can only be used to make deposits, not withdrawals. The buyer's device, using a standard protocol, then tells the buyer's bank to transfer that amount of money to the merchant. The buyer's device receives a random UUID for the transaction from their own bank and provides the UUID to the merchant.

First, notice that this would be extremely decentralized. All you need is for each financial institution to use its own prefix in its routing numbers and then the centralization is strictly to prevent different financial institutions from using the same routing prefix as one another and publish the entirely non-secret mapping from routing prefixes to depository institutions.

Second, notice that the merchant receives no information about the buyer. All they get is a random UUID that allows them to confirm with their own financial institution that the bill was paid and there is now money in their account, and even their financial institution only knows the UUID and which financial institution transferred the money to them, not which individual.

If the only thing the intermediary could discover is which bank you use and absolutely nothing that could allow them to steal your money, who needs Paypal? The fact that it doesn't work like that is the scam.

Post reply on HN