Live data from Hacker News

French government agency confirms breach as hacker offers to sell data

bleepingcomputer.com

131–140 of 168 posts

Re: French government agency confirms breach as hacker offers to sell data

#131
post #41

If governments are treating my personal data as if it is worth nothing, then I'm not going to treat copyrighted works as if they are worth something. If you want to build a society on information, then you cannot forget the most important group.

Let us know how it works out. It's great in theory to stick to your principles but taking on the government in that way is almost certainly a losing battle. There are better ways to bring about change.

Not sure the French of all people need lectures on bringing about change and taking on the government.

Re: French government agency confirms breach as hacker offers to sell data

#132
post #78

Earlier quoted context omitted.

Or maybe the government should not require companies to KYC you for every little stupid thing or action you do in this world. What happened to requiring only the information that's actually required? Why do I need to be KYCd in the systems when buying banana, ordering delivery, etc. Because of the inevitable breaches and leaks - KYC is the illicit activity. The selling point of KYC was preventing fraud and money laun…

> Or maybe the government should not require companies to KYC you for every little stupid thing Actually.... Say what you like about the French today, but one good thing they have is an electronic service[1] where you can generate single-use KYC ID: - That only discloses minimum information required - For a specific recipient organisation - For a specific duration - For a specific use-case by that organisation More c…

[dead]

Re: French government agency confirms breach as hacker offers to sell data

#133
post #10

> the data stolen in the breach could include full names, dates and places of birth, mailing and email addresses, and phone numbers on an undisclosed number of citizens Nothing really new here sadly, this information about me have leaked half a dozen of times in the past 2-3 years or so. These things will never change if the only penalty the company/agency gets is "send a message to your users saying you are sorry an…

And 12 months of credit monitoring to go with the 2346823 months of credit monitoring they already have.

Re: French government agency confirms breach as hacker offers to sell data

#134
post #10

> the data stolen in the breach could include full names, dates and places of birth, mailing and email addresses, and phone numbers on an undisclosed number of citizens Nothing really new here sadly, this information about me have leaked half a dozen of times in the past 2-3 years or so. These things will never change if the only penalty the company/agency gets is "send a message to your users saying you are sorry an…

These things will never change if the only penalty the company/agency gets is "send a message to your users saying you are sorry and that it won’t happen again". So, you want the French government to fine the French government so the French government uses French taxpayer money to pay the French government for the French government's mistake?

You could just jail the CEO or who was responsible for the security at that agency / company.

Re: French government agency confirms breach as hacker offers to sell data

#135
post #73

Earlier quoted context omitted.

> Penalties don't work for government agencies. Taxpayers would pay for it and it doesn't act as an incentive. This is the same as the rogue police problem in the US. What needs to happen is a shift to personal liability for those responsible.

Personal liability? Are you also against no blame culture that is prevalent in the tech world?

If it’s related to compliance? Yeah I think that’s a pretty dangerous culture to have. Compliance requirements need owners who will ensure standards are met. If they don’t do their jobs, then they should face the consequences for the harm they allow.

Re: French government agency confirms breach as hacker offers to sell data

#136
post #10

> the data stolen in the breach could include full names, dates and places of birth, mailing and email addresses, and phone numbers on an undisclosed number of citizens Nothing really new here sadly, this information about me have leaked half a dozen of times in the past 2-3 years or so. These things will never change if the only penalty the company/agency gets is "send a message to your users saying you are sorry an…

Penalties don't work for government agencies. Taxpayers would pay for it and it doesn't act as an incentive. The way to fix it is to empower one government agency to do aggressive pentesting against every other agency, hospitals, banks, infrastructure, and big corporations, with salaries matching the private sector. Impose a legally-enforced deadline to fix any issues, with a fine (for private actors) or demotion of…

I agree with the premise that SSII audits are useless, but your solution sounds like bandaid on a cancer. The real solution solution is stop this surveillance machine madness!

I understand that identity is required for property deeds and bank accounts for tax reasons and that should 100% not be online. But for the rest, it should be entirely outlawed to collect personal information beyond what's necessary for the service, including for government agencies.

Make healthcare (really) free => no social security database to hack. Give me back humans in offices for taxes and drivers licences => no ANTS database to hack. etc.

Re: French government agency confirms breach as hacker offers to sell data

#137
post #97

Earlier quoted context omitted.

Penalties don't work for government agencies. Taxpayers would pay for it and it doesn't act as an incentive. The way to fix it is to empower one government agency to do aggressive pentesting against every other agency, hospitals, banks, infrastructure, and big corporations, with salaries matching the private sector. Impose a legally-enforced deadline to fix any issues, with a fine (for private actors) or demotion of…

You don't seem to realize the difference between those 2. > The way to fix it is to empower one government agency to do aggressive pentesting against every other agency, hospitals, banks, infrastructure, and big corporations, with salaries matching the private sector. Impose ... And now you've got private people empowered to attack specific government officials. In fact, that's their job. Btw: you forgot to specify "…

> this needs a very un-French form of government to get it to work

I'm usually not one to defend french culture, but i believe your interpretation is wrong. What went wrong in this case is the americanization of the french administration: make everything complex, remove all local government branches and workers who can help you, remove every sensical administrator from their position, ignore all the privacy laws that were passed after Vichy and the nazi/IBM databases, "just make all the NUMÉRISATION".

The french government didn't have a proper national ID system until the nazi administration (Vichy) who invented the CNI and the Ausweis. There was strong sentiment against this well into the 70s and the Loi Informatique et Libertés, and it's only the more recent startup generation that started undoing all our ancestors hard fought battles against data collections/centralization.

Re: French government agency confirms breach as hacker offers to sell data

#138
post #52
post #10

> the data stolen in the breach could include full names, dates and places of birth, mailing and email addresses, and phone numbers on an undisclosed number of citizens Nothing really new here sadly, this information about me have leaked half a dozen of times in the past 2-3 years or so. These things will never change if the only penalty the company/agency gets is "send a message to your users saying you are sorry an…

GDPR has solid fines for data breaches, but this doesn't work for government agencies. Just someone else's money going from one government pocket to another. What they need is an automatic firing of the head of the government agency that suffered a breach. No question asked.

[deleted]

Re: French government agency confirms breach as hacker offers to sell data

#139
post #18

It seems to me we must move away from worrying about ransomware, data breach, data protection as that ship has already sailed and everyone's PII has already been stolen. We should think of how to verify people's identities online (for things like government benefits etc). I have heard of the Dutch and the Japanese using national digital identity systems although I am unclear how they work. India is doing biometrics.…

Biometrics is just something else to get leaked, terrible idea because it's even more sensitive (can be used to track you through cameras for example, like used in the Iran war). This problem has long been solved with federated IdPs and MFA - something you own like OTP device/physical token besides something you know like SSN/tax id/password. Most governments prefer biometrics of course because citizen privacy is the…

> something you know like SSN/tax id/password

How can you equal an SSN/Tax id with a password? The SSN/Tax id is more or less public knowledge while a password is not.

Re: French government agency confirms breach as hacker offers to sell data

#140
post #52
post #10

> the data stolen in the breach could include full names, dates and places of birth, mailing and email addresses, and phone numbers on an undisclosed number of citizens Nothing really new here sadly, this information about me have leaked half a dozen of times in the past 2-3 years or so. These things will never change if the only penalty the company/agency gets is "send a message to your users saying you are sorry an…

GDPR has solid fines for data breaches, but this doesn't work for government agencies. Just someone else's money going from one government pocket to another. What they need is an automatic firing of the head of the government agency that suffered a breach. No question asked.

It's not just one head though. It's 3 different right-wing administrations (Sarkozy, Hollande, Macron) wanting to make everything digital, fighting against the unions, fighting against the users, and fighting against any common-sense administrator so they can destroy public services, close down local government service branches (La Poste, sécurité sociale, etc).

It was always an entire fuck up. There was no way it was anything else than an entire fuck up. The "highest level of security" (ANTS) leak is just the cherry on the top. Time to get the guillotine out of the garage i guess?

Post reply on HN