Live data from Hacker News

9M Australians affected by Optus data breach

optus.com.au

21–30 of 104 posts

Re: 9M Australians affected by Optus data breach

#21
post #10

A mobile company that wants so much of their users ID info. Is it really necessary for them to get all that user info?

Good question. I think the idea is you can’t have a burner phone. Well you can…for example use a foreign sim card of a less fussy telco. But in general this makes it harder to have a burner. Once we get to a point where telcos are not needed to make calls (that amazon wifi mesh for example) maybe we can do away with this need for ID anyway because it is futile.

Calls yes, but making calls is not what’s regulated in Australia. The ACMA regulates the assignment of Numbers in Australia, so make calls to your hearts content but if you want to be addressable by a e164 or IP number, prepare your documents.

Re: 9M Australians affected by Optus data breach

#23
> Information which may have been exposed includes customers’ names, dates of birth, phone numbers, email addresses, and, for a subset of customers, addresses, ID document numbers such as driver's licence or passport numbers

Okay so this was half the country.

I cant honestly understand how anyone thinks KYC laws make sense if anyone can make a bank account as anyone else, and it all looks like legitimate money or the human is getting framed while the criminal just rotates IDs.

Re: 9M Australians affected by Optus data breach

#24

> Information which may have been exposed includes customers’ names, dates of birth, phone numbers, email addresses, and, for a subset of customers, addresses, ID document numbers such as driver's licence or passport numbers. Payment detail and account passwords have not been compromised. Geez, ID document numbers is such a big thing. Now hackers can basically call most institution and impersonate victims. this is qu…

It shows why we need to rapidly embrace the idea that knowledge of an ID document number and its associated personal details is insufficient proof of identity.

Re: 9M Australians affected by Optus data breach

#25

> Information which may have been exposed includes customers’ names, dates of birth, phone numbers, email addresses, and, for a subset of customers, addresses, ID document numbers such as driver's licence or passport numbers Okay so this was half the country. I cant honestly understand how anyone thinks KYC laws make sense if anyone can make a bank account as anyone else, and it all looks like legitimate money or the…

You can't make an account with the number or a scan of an ID document (at least here in the EU, but i doubt it'd be much different down under). The real thing is required, or in the case of neobanks, multiple photos at specific angles + selfie from their app.

Re: 9M Australians affected by Optus data breach

#26

I’ve seen Optus “computer security” in action. I use quotes for a reason. There was a court-enforced order requiring them to apply security updates to their production systems. That was in response to a previous breach. You see, until a judge made them do it… they weren’t patching anything. They would just build systems and walk away . For some software systems they had every major and minor version deployed, like a…

I tried to sign up for Optus in around 2007? They had this contract system you agreed to over the phone . I spent ages saying “yes” in different ways because it couldn’t pick up my kiwi accent. Eventually I managed to agree and got the worst internet experience ever. Moved to TPG after the contract finished.

Re: 9M Australians affected by Optus data breach

#27

Earlier quoted context omitted.

Good question. I think the idea is you can’t have a burner phone. Well you can…for example use a foreign sim card of a less fussy telco. But in general this makes it harder to have a burner. Once we get to a point where telcos are not needed to make calls (that amazon wifi mesh for example) maybe we can do away with this need for ID anyway because it is futile.

Calls yes, but making calls is not what’s regulated in Australia. The ACMA regulates the assignment of Numbers in Australia, so make calls to your hearts content but if you want to be addressable by a e164 or IP number, prepare your documents.

My point is in rural locations not at home you need a phone number to connect to 5G (or lesser G) for the data to make a non phone call.

Re: 9M Australians affected by Optus data breach

#28

I’ve seen Optus “computer security” in action. I use quotes for a reason. There was a court-enforced order requiring them to apply security updates to their production systems. That was in response to a previous breach. You see, until a judge made them do it… they weren’t patching anything. They would just build systems and walk away . For some software systems they had every major and minor version deployed, like a…

You can tell how broken their tech is when you try and use the website. Half the pages just fail to load. I don't mean time out, I mean, they think they are finished loading but most of the page is missing.

Don’t confuse the failings of their consumer-facing systems with the madness behind that facade.

The equivalent of what I was describing in terms of a web experience would be having to use a dialup modem to sign up for an account via Netscape Navigator 4. With a login secured using SSL… version 1.0.

I wish I was exaggerating, but their systems literally date back to that era and have comparable limitations in terms of supported network protocols.

Re: 9M Australians affected by Optus data breach

#30
post #25

> Information which may have been exposed includes customers’ names, dates of birth, phone numbers, email addresses, and, for a subset of customers, addresses, ID document numbers such as driver's licence or passport numbers Okay so this was half the country. I cant honestly understand how anyone thinks KYC laws make sense if anyone can make a bank account as anyone else, and it all looks like legitimate money or the…

You can't make an account with the number or a scan of an ID document (at least here in the EU, but i doubt it'd be much different down under). The real thing is required, or in the case of neobanks, multiple photos at specific angles + selfie from their app.

all it takes is a single institution that subverts that.

regarding angles and selfies, most of those just require you to go through the motions not for it to be accurate or withstand [human] scrutiny.

Post reply on HN