Live data from Hacker News

French government agency confirms breach as hacker offers to sell data

bleepingcomputer.com

151–160 of 168 posts

Re: French government agency confirms breach as hacker offers to sell data

#151
post #78

Earlier quoted context omitted.

Or maybe the government should not require companies to KYC you for every little stupid thing or action you do in this world. What happened to requiring only the information that's actually required? Why do I need to be KYCd in the systems when buying banana, ordering delivery, etc. Because of the inevitable breaches and leaks - KYC is the illicit activity. The selling point of KYC was preventing fraud and money laun…

> Or maybe the government should not require companies to KYC you for every little stupid thing Actually.... Say what you like about the French today, but one good thing they have is an electronic service[1] where you can generate single-use KYC ID: - That only discloses minimum information required - For a specific recipient organisation - For a specific duration - For a specific use-case by that organisation More c…

Wish entities who handle Aadhar in India be required to accept the one-time Virtual Aadhar. Its a quick online and SMS-only process. Seems everybody forces you to hand over your permanent Aadhar, including the ID verification partner for Paypal.

Re: French government agency confirms breach as hacker offers to sell data

#152
post #78
post #10

> the data stolen in the breach could include full names, dates and places of birth, mailing and email addresses, and phone numbers on an undisclosed number of citizens Nothing really new here sadly, this information about me have leaked half a dozen of times in the past 2-3 years or so. These things will never change if the only penalty the company/agency gets is "send a message to your users saying you are sorry an…

Or maybe the government should not require companies to KYC you for every little stupid thing or action you do in this world. What happened to requiring only the information that's actually required? Why do I need to be KYCd in the systems when buying banana, ordering delivery, etc. Because of the inevitable breaches and leaks - KYC is the illicit activity. The selling point of KYC was preventing fraud and money laun…

I’m not versed in the French system specifics, but know a bit about the Belgian itsme. It’s up to the companies to specify which scopes and data bits they want. The better government agencies only ask for your ID number and proof that you’re you. Corporate users tend to ask for absolutely everything in your profile.

Re: French government agency confirms breach as hacker offers to sell data

#153
post #78
post #10

> the data stolen in the breach could include full names, dates and places of birth, mailing and email addresses, and phone numbers on an undisclosed number of citizens Nothing really new here sadly, this information about me have leaked half a dozen of times in the past 2-3 years or so. These things will never change if the only penalty the company/agency gets is "send a message to your users saying you are sorry an…

Or maybe the government should not require companies to KYC you for every little stupid thing or action you do in this world. What happened to requiring only the information that's actually required? Why do I need to be KYCd in the systems when buying banana, ordering delivery, etc. Because of the inevitable breaches and leaks - KYC is the illicit activity. The selling point of KYC was preventing fraud and money laun…

[dead]

Re: French government agency confirms breach as hacker offers to sell data

#154

Earlier quoted context omitted.

Penalties don't work for government agencies. Taxpayers would pay for it and it doesn't act as an incentive. The way to fix it is to empower one government agency to do aggressive pentesting against every other agency, hospitals, banks, infrastructure, and big corporations, with salaries matching the private sector. Impose a legally-enforced deadline to fix any issues, with a fine (for private actors) or demotion of…

I agree with the premise that SSII audits are useless, but your solution sounds like bandaid on a cancer. The real solution solution is stop this surveillance machine madness! I understand that identity is required for property deeds and bank accounts for tax reasons and that should 100% not be online. But for the rest, it should be entirely outlawed to collect personal information beyond what's necessary for the ser…

Er? social security covers more than just healthcare and the issue with on-line data in context of healthcare is patients' history, which i) is sensitive and ii) needs to be shared among health care providers.

Re: French government agency confirms breach as hacker offers to sell data

#155
In 2015/2016, the president (Hollande), and its prime minister (Valls) did install a document which is "law", about technical directives for the gov and its agencies/dependencies. This document was probably written by big tech themselves. No following prime minister and even the new president (macron), did fix this obvious big tech ("whatng cartel") trojan horse.

They were probably screwed as f... or they had/have some interests somewhere ($$$).

In the last decade, all web sites were broken to be replaced by web apps ($$$), creating a hard dependency on the massively huge and complex "whatng cartel" web engines and their related massively complex c++ compilers. It is very hard to believe to anything else than corruption, really hard.

This document, which is law, which only the president and prime minister have power on, must be modified to make the difference between web sites and web apps and to mandate a web site for core and critical online services of gov and dependencies. Aka, restore noscript/basic (x)html interoperability, or "small" and technically reasonable web engines (to foster real-life alternatives from citizen, local company, etc, initiatives). All of such online services had a working web site (no app) before this document sold the gov and its dependencies to big tech (here the "whatng cartel").

No gov authorities (competition/anti-trust, justice, etc), not even the parliaments can do anything here, only the president and the prime minister.

Hardly believable, and I found out only a month ago, in spite of consulting lawyers, being part of related user groups with legal experts, etc, for 10 years. I could not understand what was going on, all this money and 'loss of strategic control' channelled in those 'companies'.

Re: French government agency confirms breach as hacker offers to sell data

#156

Earlier quoted context omitted.

Biometrics are the only credential you can't roll after compromise.

kind of but others are hard as well... most people don't change their name, date of birth or even email address when they are leaked.

These aren't really "credentials" in that they're not secret the way your iris/retina pattern, fingerprint pattern, password, pin, secret key, or security token are.

Your name, DoB, and email address are identifiers, yes, but aren't really authenticators - they're more like a username, not a password.

Re: French government agency confirms breach as hacker offers to sell data

#157
post #52

Earlier quoted context omitted.

GDPR has solid fines for data breaches, but this doesn't work for government agencies. Just someone else's money going from one government pocket to another. What they need is an automatic firing of the head of the government agency that suffered a breach. No question asked.

It's not just one head though. It's 3 different right-wing administrations (Sarkozy, Hollande, Macron) wanting to make everything digital, fighting against the unions, fighting against the users, and fighting against any common-sense administrator so they can destroy public services, close down local government service branches (La Poste, sécurité sociale, etc). It was always an entire fuck up. There was no way it wa…

> It's 3 different right-wing administrations (Sarkozy, Hollande, Macron)

So now socialists are right wing? Who isn’t then? Kim Jong Un maybe?

Re: French government agency confirms breach as hacker offers to sell data

#158

Earlier quoted context omitted.

The attacker will then simply use the decryption key to decrypt it.

Then the headline would be French goverment loses encryption keys ..

Access to the server gives you access to the encryption keys, unless the server is just storing end-to-end encrypted material for someone else and doesn't do anything with the data.

Re: French government agency confirms breach as hacker offers to sell data

#159
post #65

Earlier quoted context omitted.

Wait, you don’t even get a month of free credit monitoring?

The credit system is not the same in Europe, first of all there is no such thing as credit rating and what not. People don't have credit card like the one in US and Canada. The vast majority use a debit card.

the credit rating system in Europe is quite different from the one in the United States and varies significantly from country to country.

but credit ratings are definitely a thing, they're just not FICO scores.

Equafax is still a thing in the UK and Spain, etc.

Re: French government agency confirms breach as hacker offers to sell data

#160
post #157

Earlier quoted context omitted.

It's not just one head though. It's 3 different right-wing administrations (Sarkozy, Hollande, Macron) wanting to make everything digital, fighting against the unions, fighting against the users, and fighting against any common-sense administrator so they can destroy public services, close down local government service branches (La Poste, sécurité sociale, etc). It was always an entire fuck up. There was no way it wa…

> It's 3 different right-wing administrations (Sarkozy, Hollande, Macron) So now socialists are right wing? Who isn’t then? Kim Jong Un maybe?

[deleted]
Post reply on HN