Live data from Hacker News

Vietnam Airlines Data Breach

haveibeenpwned.com

21–30 of 39 posts

Re: Vietnam Airlines Data Breach

#21
post #8

Earlier quoted context omitted.

https://security.stackexchange.com/a/95070 https://en.wikipedia.org/wiki/Phishing#Spear_phishing

As I mentioned, the real issue is around considering of this data as a secret.

Just to clarify to the downvoters: I meant "Secret" as in password, not as in "private data". It is a private data, but it shouldn't be used as a secret to pass some security check.

Re: Vietnam Airlines Data Breach

#22

I've never been able to unsubscribe from their shitty emails - which I never subscribed to. I only signed up for a flight. And now, my data is open-source ಠ_ಠ

I think technically the CAN-SPAM act applies to an international company with any US customers, but in practice no company primarily in another country cares about that US law.

Maybe if the US was willing to perform an air strike on each business that violated CAN-SPAM we'd get some real compliance.

Re: Vietnam Airlines Data Breach

#23
post #3

Trying to understand what's the real damage here. Dates of birth, Email addresses, Loyalty program details, Names, Phone numbers - how is one going to use this data to cause a loss the data owner? If any security check depends on this data by considering it as a secret, then I guess it's the fault of that security check.

>> If any security check depends on this data by considering it as a secret, then I guess it's the fault of that security check.

That is very small solace when you're the victim, regardless of the failures of others. "But you shouldn't be using that data as validation!" is not the first response when say, you find out someone's opened a credit card in your name with a $20K balance. Or your friends & family get phished (especially with the help of AI) because they know so much about you it had to be you.

Re: Vietnam Airlines Data Breach

#24
post #17

Testing some emails in haveibeenpwned i realized something terrible about these leaks. In isolation, ok, you have just your personal data like birthdate, name, phone number leaked just based on an email. But now that there was so many leaks, just taking a single email, you can easily map an important part of the profile of a person. Give me an email, I now have: - All identification details, sometimes scanned id docu…

Makes me feel OK about my strategy to use a different email for every sign up

if you run your own domain and have a wildcard for email this is a very good strategy. I also never provide my real birthdate for (almost) anything. The vast majority DO NOT NEED IT, and the rare case where it might be required (still doubt it, but maybe age of majority or consent, or a waiver) I use Jan 1st of the real year. This has caused problems (ex: doesn't match your id) but on the balance seems to be positive.

Re: Vietnam Airlines Data Breach

#25
post #5

at this point one should just assume all their data is already public once they entered it to any platform...

Given how willing basically every major company is to sell your data to make money this is basically already the case and has been for years.

And when governments try to plug up some of the loopholes when it comes to privacy and data sharing, every major company finds some new gap to exploit or just does it illegally without telling anybody until they get found out and pay the fine.

Re: Vietnam Airlines Data Breach

#26
post #2

Haven't heard a word from Vietnam Airlines - my whole family are members. Interesting to see how a Vietnamese organisation handles this type of incident.

Does the Vietnamese government have any interest in cases like this? Or are things pretty laissez-faire over there despite the nominal socialism?

Really not sure - my partner is Vietnamese (dual citizenship) but we don't live there. We flew Vietnamese Airlines for 4 flights in the last month (2 international). I'd like to think we'd receive an email about this in any case - so far only an email from HIBP.

Re: Vietnam Airlines Data Breach

#27

Testing some emails in haveibeenpwned i realized something terrible about these leaks. In isolation, ok, you have just your personal data like birthdate, name, phone number leaked just based on an email. But now that there was so many leaks, just taking a single email, you can easily map an important part of the profile of a person. Give me an email, I now have: - All identification details, sometimes scanned id docu…

[deleted]

Re: Vietnam Airlines Data Breach

#28
post #10
post #3

Trying to understand what's the real damage here. Dates of birth, Email addresses, Loyalty program details, Names, Phone numbers - how is one going to use this data to cause a loss the data owner? If any security check depends on this data by considering it as a secret, then I guess it's the fault of that security check.

It's inherently a loss of privacy that anyone (given that the dataset is now public) can correlate > Dates of birth, Email addresses, Loyalty program details, Names, Phone numbers

Another way to look at it is what's the real damage considering the breach right under Vietnam airlines already leaked that.

Re: Vietnam Airlines Data Breach

#29
post #17

Earlier quoted context omitted.

Makes me feel OK about my strategy to use a different email for every sign up

if you run your own domain and have a wildcard for email this is a very good strategy. I also never provide my real birthdate for (almost) anything. The vast majority DO NOT NEED IT, and the rare case where it might be required (still doubt it, but maybe age of majority or consent, or a waiver) I use Jan 1st of the real year. This has caused problems (ex: doesn't match your id) but on the balance seems to be positive…

Even without your own email hosting, Gmail kind of lets you do this by appending +whatever to your address before @gmail.com. Obviously this can be trivially detected and stripped but I suppose it is better than nothing. Multiple real Email addresses are definitely a best practice.

Re: Vietnam Airlines Data Breach

#30
post #3

Trying to understand what's the real damage here. Dates of birth, Email addresses, Loyalty program details, Names, Phone numbers - how is one going to use this data to cause a loss the data owner? If any security check depends on this data by considering it as a secret, then I guess it's the fault of that security check.

I’ve seen folks get their frequent flyer miles siphoned off. This would be perfect for a phishing attack intended to do that.
Post reply on HN