Live data from Hacker News

Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

abc.net.au

131–140 of 169 posts

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#131

Earlier quoted context omitted.

> I would be interested in learning if this problem exists in other countries In Norway you can voluntarily register as not wanting to allow credit assessments to be performed on you. This in turn can help a bit because it results in most attempts at making loans in your name not being possible. https://www.datatilsynet.no/regelverk-og-verktoy/sporsmal-sv... There are four companies in Norway that do credit assessmen…

You can do this in America. It’s called a credit freeze. A problem is credit freezes can also be fraudulently lifted, but serve as a decent barrier for most run of the mill mass frauds. They’re virtually unknown and require you to independent contact each individual credit bureaus to both freeze then unfreeze. https://consumer.ftc.gov/articles/what-know-about-credit-fre...

I wish I wrote down the un-freeze PIN codes or stored them in Bitwarden when I did this six years ago.

I'm dreading trying to recall the PINs I used when the time comes to un-freeze them.

Still glad I did it, though. However burdensome the PIN recovery process will be, I'm sure it's less stress than dealing with fraud.

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#132

"Identity Theft" shouldn't even be a thing. Someone falsifies documents and takes out a loan or something that should not have been approved. That's bank fraud and should be an issue entirely between the fraudster and the lender/bank. Somehow banks have re-named it from "bank fraud" to "identity theft," deftly shifting responsibility onto some unrelated third party, who now has to deal with it. "Your identity was sto…

I thought I was depositing a billon dollars with the real bank, turns out it was fake. The bank now owes me a billion dollars.

This works for me.

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#133
post #103

To give context to people who may have not heard; there has been a MASSIVE amount of high profile data breaches in the Australia in the past 12 months with zero consequences for the businesses involved. In a 6 month period I had; - My private health insurance data leaked (AHM/Medibank) - including claim history, medicare number, password, username, email, phone - My old phone account (Optus) - including my phone numb…

> Until governments legislate that the punishment for exposing personal data is more expensive

The EU did. Everyone, for some inexplicable reason hates it; and not the casual hate one spews when it rains or traffic is bad but a deep visceral hatred normally reserved for war criminals or kiddie fiddlers.

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#134
post #130

"Identity Theft" shouldn't even be a thing. Someone falsifies documents and takes out a loan or something that should not have been approved. That's bank fraud and should be an issue entirely between the fraudster and the lender/bank. Somehow banks have re-named it from "bank fraud" to "identity theft," deftly shifting responsibility onto some unrelated third party, who now has to deal with it. "Your identity was sto…

You’re right, both morally and legally. My friend a government law professor told me that in the EU you could probably even construct a pretty solid case arguing this. The argument would be that If there is not a single slip of evidence tying you physically to the money Except your PII Then the banks anti-money laundering should have catched it. That gets their attention right away since the fines in that cases are p…

I’m not sure what the exact rules and regulations are, but at least in Germany you should be well protected. The German Wikipedia entry [0] is a bit confusing, as it both has damages (I checked the primary source, no further information) but also a section how it will not be your issue as the other party was defrauded, so I can only guess it’s people who simply paid (fraudulent online shop orders or fraudulent withdrawals) without fighting back.

[0]: https://de.wikipedia.org/wiki/Identit%C3%A4tsdiebstahl

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#135
post #4

Situations like these keep bringing me back to the idea that important actions should require an actual, in person, human notary seal. Contract signings, online court service, title changes, etc should not be valid without an offline record examiner who affirms under threat of perjury that the parties involved are who they claim (or are claimed to be).

Some countries/jurisdictions do exactly that, and trust me, it's a massive pain in the ass. Would you really want to visit a notary just to set up an eBay account? Because that's what you're proposing. The existing system isn't foolproof but, by and large, it works perfectly well. If the transactions in TFA truly were fraudulent, no court is going to hold her liable. The bigger problem here is a US court being happy…

> Would you really want to visit a notary just to set up an eBay account?

You're saying like it's bad. It's not. In fact, it's wonderful.

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#136
post #127

Earlier quoted context omitted.

Interesting. This should be adopted by the EU. (I know Norway is not a member state but this makes good sense and that's why I would love to see the EU to adopt it.)

I disagree with this system, banks can instead require the exact same Auth process they'd use to unblock your "no credit" request when they want to start a new credit for anyone. Why would there be more checks to "remove block" than to "start credit"? I can think of one reason that's good for the banks. The "locked" state should be the default, whatever extra checks they need to do to a person that has it "frozen", t…

In Sweden all banks require me to sign off credit requests through BankID as well, so the check can be performed but I need to ultimately sign it.

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#137

Earlier quoted context omitted.

> very common Are there statistics on this somewhere?

ALPRs are everywhere these days. "Very common" is probably understatement in this situation.

Then some statistics shouldn’t be hard to find.

I can’t find anything stating this is “very common”. I guess as a rough metric for “very common” let’s say on a similar level to heart attacks. Quite rare still but common enough that you could be justified in calling it very common.

So 850,000 cases per year.

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#138
post #79

Earlier quoted context omitted.

Isn't that basically conspiracy theory logic? ie. "This thing is totally true! Evidence? That doesn't exist because The Powers That Be are suppressing it!"

No, you’re just uninformed and eager to trust power. Asking for cop stats as prerequisite to critique is a pledge to their supremacy

Does the alternative exist - being uninformed and eager to criticize power? How are we meant to differentiate the two?

I think one way is to note that this post was about being inaccurately charged with a felony - not about cops. The request for stats was not “cop stats” but identity fraud based felony and as a result arrest at routine traffic stop.

If a cop sees you have multiple felonies in another state, it’s quite literally their job to arrest you. Do you suggest they see someone charged with multiple felonies and just say have a good day?

No, the post was about being charged inaccurately due to identity theft. Perhaps you are overly eager to criticize police and became uninformed with reading the comment thread.

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#140
post #4

Situations like these keep bringing me back to the idea that important actions should require an actual, in person, human notary seal. Contract signings, online court service, title changes, etc should not be valid without an offline record examiner who affirms under threat of perjury that the parties involved are who they claim (or are claimed to be).

Some countries/jurisdictions do exactly that, and trust me, it's a massive pain in the ass. Would you really want to visit a notary just to set up an eBay account? Because that's what you're proposing. The existing system isn't foolproof but, by and large, it works perfectly well. If the transactions in TFA truly were fraudulent, no court is going to hold her liable. The bigger problem here is a US court being happy…

> Would you really want to visit a notary just to set up an eBay account? Because that's what you're proposing.

I do, if the service involves hard identity/finance. Maybe where I'm from is odd, but you can't go into a neighborhood without tripping over a notary, there are mobile notaries, notaries in every white collar office etc. Not too inconvenient for a one time (per major action) event.

Post reply on HN