Live data from Hacker News

Black Hat: GDPR privacy law exploited to reveal personal data

bbc.co.uk

131–140 of 239 posts

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#131
post #96

Earlier quoted context omitted.

> BankID is horrible. The rest of your post does not back up this claim IMO. > It's coupled to your phone's OS, so as it becomes even more mandatory you're stuck carrying around an iOS or Android device, even if your primary phone is something like a Librem 5. At least here in Norway you can get a standalone hardware 2-factor key. > It also doesn't support anyway to delegate access, either to people ("my partner shou…

> At least here in Norway you can get a standalone hardware 2-factor key. You can get the key embedded on a smartcard, but it's still coupled to their proprietary driver (which only works on Windows or macOS, of course). It's also a separate API and not as widely supported as Mobile BankID.

Ugh, my Austrian bank is currently trying to force me into using a system like this. The "standard" way is via an Android or iOS app, the "alternative" is via a smartcard reader thing that seems to work with Windows only.

They claim that this is mandatory due to some EU regulation, but they conveniently forget to say what regulation that is supposed to be.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#132
post #38

Earlier quoted context omitted.

And yet other laws require the collection and retention of sensitive user data, in particular any service that allows for transmission of large amounts of money (crypto exchanges were a good example).

That is well covered within GDPR scope. Retaining data to fulfill legal obligations is allowed. One common related example is invoice data.

But then "just don't keep the data" is not an effective response to these attacks of requesting someone else's data.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#133
post #17

This is horrible. So right now, in order to get access to data for a certain person, you need to hack your way through a few of the potential services he is using and drive from there. 1. The data might have things like IDs (ie: Crypto exchanges). 2. You can use that data to ask for more data. If you got a copy of his passport, now you can ask for more with this new piece. 3. Looks like some people still store passwo…

Interesting that you consistently refer to the target as "he" as if women weren't a major target of this kind of campaign.

Please stop seeing *isms everywhere. It's equally possible that he isn't a native speaker.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#134

Earlier quoted context omitted.

Remember that a GDPR request is going to typically come electronically. You won't have a physical item to examine for all its anti-counterfeiting features - you're probably going to have a photograph from a mobile phone to look at.

To me it sounds a bit dubious that you can both have a valid reason for keeping personal information about someone and not have a valid way of verifying that you are actually communicating with them. What sort of agreement can you enter with someone if you don't know who they are?

What sort of agreement can you enter with someone if you don't know who they are?

Have you ever walked into a shop, bought some chocolate with cash, and walked out?

There you go, legally binding contract of sale, yet the seller has no idea who the buyer was.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#135
post #91

Earlier quoted context omitted.

I doubt that a black-hat attacker is going to file a lawsuit to obtain someone else's personal information.

But what if the request is genuine?

Then the user will be authenticated by the court, and you will have to make your case that without the court's intervention, you could not be certain of the requester's identity.

This isn't black and white. It is legally ok to question the validity of GDPR data subject requests.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#136

Earlier quoted context omitted.

> It's a different API. Most services specifically require Mobile BankID these days. Desktop (regular) BankID won't work there. I'm not sure which point you're referring to with the mention of differing API. Mobile BankID is the same API as regular BankID (but services can choose which they accept); as for other Swedish e-ID services, there are aggregator services. Re: most, really? There are some that don't accept n…

> but services can choose which they accept And therein lies the problem. > Re: most, really? There are some that don't accept non-mobile BankID, but it is uncommon in my experience. You already refuted this yourself in https://news.ycombinator.com/item?id=20656033 . > I don't think it's unreasonable for services to want to know who they're dealing with. In real life, if someone else shows my ID at postnord, they hav…

It would likely be very problematic for the security model as it is crucial that you only sign your own requests that you understand what they do. I guess you can technically sign someone else's request made with your identification number today as most service don't use QR codes for presence verification. In general I am also not sure that further expanding, and blurring the line, of what you can do with BankID is a good idea. If anything I would like more limits.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#137
post #21

Earlier quoted context omitted.

Sweden's BankID is quite good too.

BankID is horrible. It's coupled to your phone's OS, so as it becomes even more mandatory you're stuck carrying around an iOS or Android device, even if your primary phone is something like a Librem 5. It also doesn't support anyway to delegate access, either to people ("my partner should have access to this bank account") or computers ("I want to back up my incoming govt. messages automatically").

Not to mention that all providers of Mobile Bank ID (which, as you mentioned, is by far the most widely supported one) are private companies, mostly banks, which have no duty to take you on as a customer.

If you for whatever reason can't or won't get an account with a Swedish bank, you're effectively cut out from large parts of online services.

I really think the government needs to realize they should provide ID issuance digitally to ensure that no one is left out.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#138
post #90
post #17

This is horrible. So right now, in order to get access to data for a certain person, you need to hack your way through a few of the potential services he is using and drive from there. 1. The data might have things like IDs (ie: Crypto exchanges). 2. You can use that data to ask for more data. If you got a copy of his passport, now you can ask for more with this new piece. 3. Looks like some people still store passwo…

This is not a problem with GDPR. This is a problem with organizations (companies and governments) treating publicly data as private keys.

That is true. But it is the current state of the world and GDPR enables people to more effectively weaponize that.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#139

Earlier quoted context omitted.

One of the major goals of GDPR is to discourage firms from retaining personal data in the first place. It did not used to cost them anything so they kept it regardless of its use. Now that there are big risks to keeping it these firms have to think twice about it. This "cobra effect" is one more reason NOT to retain personal information in the first place.

I'll let you in on a secret. For government institutions which in general have huge amounts of information about you and are notoriously bad at security. They don't even get fined with the GDPR. The worst that can happen to them is bad press. So the institution that has all the healthcare data of all German citizens can not get fined under the GDPR. Same with any other KdöR https://de.wikipedia.org/wiki/K%C3%B6rpersc…

We had a mayor fined for sending out election mails to a list of subscribers to list intended for other purposes. Not exactly "big government agency" but it still counts.

The downvotes are probably because you failed to cite the laws that exempt government agencies from the GDPR.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#140

Earlier quoted context omitted.

I wouldn't agree that the medium sized companies tried to comply with the GDPR and failed. Yes, they tried to comply with that particular request but the failures suggest that they didn't even try to be GDPR compliant in the first place - if they had done so, then they would have had assigned a data protection officer who would have long ago asked themselves the question "what do we do in case of a personal informati…

I’m very skeptical of the idea that, if they didn’t account for this particular attack vector, that must mean nobody thought about GDPR at all. If someone came to me to write a DSR plan, I’d be thinking about how to reliably enumerate all the places we might have personal data, not how to verify that people aren’t impostors. (Does your DSR plan also have to prevent spearphishing your DBAs?)

It's not about an attack vector (which may be uncommon or unexpected) but about a basic process for handling information requests. If you're a data controller, there are a few duties you must satisfy, and handling these requests is a mandatory part.

If you're not prepared (whatever that means in your organization) to receive and answer information requests from customers, then you're not prepared to meed GDPR requirements.

If a company had a reasonable process for identity verification in place, and that process was circumvented by an attacker, then I (and most likely the regulator) would consider that as trying and failing, which is generally not punishable but mandates improvements. However, if the company didn't have any process in place (which seems to be the case in many of these examples) and "just happened" to fail, then I (and, again, most likely the regulator) would consider that as negligence, because they had an explicit duty to "use all reasonable measures to verify the identity of a data subject who requests access, in particular in the context of online services and online identifiers" and did not. The question essentially comes down to "were the measure they used reasonable?"; if you spend a little time thinking about it beforehand you generally get to something reasonable, but if a random employee tries to wing it when the first request comes, then it's plausible that the result will not be reasonable.

And, regarding "Does your DSR plan also have to prevent spearphishing your DBAs?" the answer is not clearly negative - GDPR does require you to take reasonable means to ensure data security, and that could involve taking some steps to both reduce the risk of spearphishing DBAs and steps to ensure that DBAs don't get unlimited unlogged unsupervised access to private data; in any case if a breach occurs by spearphishing your DBAs, you'd need to demonstrate to the regulator that you did take reasonable measures and this wasn't because of pure negligence.

Post reply on HN