Live data from Hacker News

Knuddels: Chat platform must pay after hacker attack fine

tellerreport.com

21–30 of 125 posts

Re: Knuddels: Chat platform must pay after hacker attack fine

#22
post #15

"Knuddels is safer than ever." Corporate speak is just so funny. The bar for "safer than ever" is pretty low when your dev team hasn't heard of password hashing.

Well, you can work your way up with ever increasing levels of safety by adding first MD5, then moving to SHA-1, then adding a salt, and eventually something sensible like bcrypt. That's four more press releases right there :-)

Re: Knuddels: Chat platform must pay after hacker attack fine

#24
post #11

Attack, succeed and blackmail could become a business. "If you don't pay me X we'll report you under GDPR and you'll have to pay much more."

They’d have to report it themselves. This is a worse value proposition than regular blackmail, where you take an existing violation, which the target already knows is illegal and has already shown willingness to conceal from authorities (or is not illegal at all, but e.g. just embarrassing), and threaten leaking it. In the proposed scheme, the mere reception of the threat itself creates a new situation for the receiver which must be reported. Paying off the blackmailer puts you in a worse spot than before. Not so with “ordinary”, Hollywood movie blackmail.

Re: Knuddels: Chat platform must pay after hacker attack fine

#25
post #16
post #7

Full list of 5000+ websites that store their passwords in plain text: https://github.com/plaintextoffenders/plaintextoffenders/blo...

I've looked at many of those Tumblr posts; most of them show that the website sends you a welcome email with your password in plain text, which is bad practice, but doesn't prove that the password is stored in plain text in the database.

But which proves that access to the website codebase will grant you access to those passwords.

Re: Knuddels: Chat platform must pay after hacker attack fine

#26
post #11

Attack, succeed and blackmail could become a business. "If you don't pay me X we'll report you under GDPR and you'll have to pay much more."

"If you don’t pay me X we’ll report you under criminal law and you’ll have to pay much more." "If you don’t pay me X we’ll report you under environmental protection law and you’ll have to pay much more." "If you don’t pay me X we’ll report you under labour regulations law and you’ll have to pay much more." How would GDPR be special?

In the extreme large fines.

Re: Knuddels: Chat platform must pay after hacker attack fine

#27
post #19

Earlier quoted context omitted.

Someone should send a friendly email to each of those offenders, linking the ruling. It's also fair to say that the next few years will be a busy time for the government agencies tasked with GDRP enforcement. (Assuming they do it properly, which falls within the responsibility of the relevant country)

They should, though assuming a bloated org structure and process, fixing it now is probably more expensive than the €20000 fine.

Note that the actual cost to Knuddels is much higher, because you also have to include the cost of implementing proper security measures. The Data Protection Officer's statement (https://www.baden-wuerttemberg.datenschutz.de/lfdi-baden-wue..., in German) states that the total cost to Knuddels is a six figure sum.

Re: Knuddels: Chat platform must pay after hacker attack fine

#28
post #3

This is actually a cool idea - paying idiot tax

In my experience, this is mostly what the GDPR is. There is no excuse for storing plaintext passwords in 2014+ and 20k is a fair fine for a mid-size company.

€20k doesn't seem much to me. Cheaper than taking on a security consultant.

Not that you need a security consultant to know passwords shouldn't be stored (at all, nevermind plaintext).

If they're doing that then they're likely being sloppy elsewhere, and by only paying €20k across the last n years they might have saved a €million.

If your company is in the same boat probably worth not bothering to get any security issues addressed. Why address security, just pay the much smaller fine if you ever get caught ...

I couldn't find Knuddels annual profit but they appear to have a dozen staff, which suggests to me the fine is too small.

Re: Knuddels: Chat platform must pay after hacker attack fine

#29
post #11

Attack, succeed and blackmail could become a business. "If you don't pay me X we'll report you under GDPR and you'll have to pay much more."

If he blackmailer can figure out, others can. Takes away the leverage.

Best strategy: Ignore the blackmailer and improve the security of your system and take privacy serious. (Doing such a cleanup also helps to reduce fines, thus also reduces leverage of blackmailer)

Re: Knuddels: Chat platform must pay after hacker attack fine

#30

Earlier quoted context omitted.

"If you don’t pay me X we’ll report you under criminal law and you’ll have to pay much more." "If you don’t pay me X we’ll report you under environmental protection law and you’ll have to pay much more." "If you don’t pay me X we’ll report you under labour regulations law and you’ll have to pay much more." How would GDPR be special?

In the extreme large fines.

They paid a 20.000€ fine. How is that extremely large?
Post reply on HN