Live data from Hacker News

1k Data Breaches Later, the Disclosure Lag Is Worse

troyhunt.com

21–30 of 133 posts

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#21
post #11

Earlier quoted context omitted.

Depends where they are in the world. I _think_ GDPR would be a good enough business reason, as they set a ticking clock of 72 hours from the breach to notifying individuals who are in the breach. And the fines involved are pretty steep (almost effing vertical for some).

A minor problem with GDPR is enforcement. At least in germany it feels like you need a very dedicated and persistent person to make the case against a company/service (bonus points if they get media attention). Other countries are a bit better but it generally is not very consistent. The enforcement for most small to mid-sized companies is often just not present and resources for relevant agencies are often only relu…

[dead]

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#22
post #13
post #6

Earlier quoted context omitted.

This is a bad idea, for multiple reasons. https://www.troyhunt.com/here-are-all-the-reasons-i-dont-mak...

I don't think he meant "show the actual data," I think he meant "what leaked? My name, address, phone number, email, medical records, payment history, bank account number?" We get a "your private data is now public" email, but knowing exactly what data turns that from a depressing statement on how much corporations value their customers' privacy into something actionable.

Yes, I meant the actual data so you know what leaked. There is a difference between leaking a password 12345678 and leaking a password that was reused on a different site. There is a difference between leaking your actual birthday and leaking 01/01/1900. There is a difference between leaking a fake address, your previous address, and your current address.

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#23
post #12

At this stage just expect that every accounts will get leaked or rooted, it's a matter of when, not if... Use varying email `plus addressing` (john+am2604@foo.com), varying passwords or passkey and 2FA on anything remotely important (use of your identity, not just financials).

Plus addressing doesn't work well unfortunately - lots of poorly written websites will reject it.

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#24
post #19

For years, I've been trying my best to stay low-key when it comes to my personal information on the internet. I don't create new accounts, I never cross-login with my email address, I don't use phones. Certainly not perfect, but a lot of times I'm preferring privacy over convenience. At the same time, my government and society at large is pushing more and more for "digital everything". It's great when it works. But t…

If a business legitimately needs such information to operate, isn't it borderline impossible to 100% prevent it from leaking? If the data is there, it can be compromised either by technical means or non-technical means.

The primary issues in my opinion are (1) businesses collecting and holding on to information they don't need and (2) businesses getting so large that they become prime targets by default.

In a world where pointless data collection was disincentivized and there were many small businesses instead of a few large ones, this problem would be much more localized and addressable. But of course this is a dream within a dream.

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#26
post #6

>why is it still needed? It's not needed. There are already alternatives that could take its place. Some of them are able to actually show you what data leaked instead of leaving you blind of what was actually included in the breach.

This is a bad idea, for multiple reasons. https://www.troyhunt.com/here-are-all-the-reasons-i-dont-mak...

>Most breaches already contain hashed passwords

It could show the hash instead.

>No, it's not ok that these passwords are already out there

So it's better that people have to pay for it instead of getting this information for free?

>Because it's important to say "I don't store passwords in HIBP"

This is a personal choice.

>I'm not your personal lookup service

The idea is that this would be done by the site itself and would not require manual work by the owner.

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#27

there will be more data breaches. Google and Apple are throttling hotfix updates (for app developers) as tons of code pushes to their infra (by vibe coders) is straining their system. The are fixing this by throttling updates to minimum 3 days review period. so good luck fixing the vulnerability or data leaks in your apps.

Dont worry the vibecoders will tire out, they're the same people who were making NFTs and mining bitcoin, they'll move onto the next hot thing soon enough. Its more an archetype, not necessarily the same exact people. They dont commit long term.

This indeed. They are the "type of guy type of guys", always drifting to next big thing®

I wonder whats next, I feel it might be a huge swing of the pendulum next.

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#28
I found I had exactly that issue ~3 months ago. A particular government department had their systems hacked and 1 of my email addresses became public along with 10s of thousands of other users. That in itself was bad enough except that this particular department had known about the breach about 2 months earlier and to make matters worse they had not been aware that the breach had occurred back in June 2025.

I 100% agree with you here. The trouble is, the government which are often the ones to push for major court-issued penalties when corporations stuff up, don't want to be held to the same level of scrutiny and penalty. Go figure

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#29
post #19

For years, I've been trying my best to stay low-key when it comes to my personal information on the internet. I don't create new accounts, I never cross-login with my email address, I don't use phones. Certainly not perfect, but a lot of times I'm preferring privacy over convenience. At the same time, my government and society at large is pushing more and more for "digital everything". It's great when it works. But t…

> . I don't create new accounts, I never cross-login with my email address

I honestly tend to think this is the only viable long term strategy.

Let's face it: In a truly global internet where every single forum or website is hosted in a different country with a different jurisdiction, hoping that every single actor will act responsibly is just delusional.

It is not what we see. It is not happening and it is not going to happen.

Individual need to have right to online privacy.

That's means the right to get proxy email address, proxy phone number, proxy physical address and even proxy identity (first name/family name).

The sooner the governments will accept that, the better.

If done right, it is not incompatible with a system where identities can be reconstructed by the authorities for legal actions.

If nothing is done, scams and blackmails will continue to spread like bushfire and proxies anonymity will happen anyway outside of any control.

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#30
post #19

For years, I've been trying my best to stay low-key when it comes to my personal information on the internet. I don't create new accounts, I never cross-login with my email address, I don't use phones. Certainly not perfect, but a lot of times I'm preferring privacy over convenience. At the same time, my government and society at large is pushing more and more for "digital everything". It's great when it works. But t…

The issue is how easy computers make everything, and how well processes scale with computers. Back in the day to heist data you'd have to physically break in or infiltrate, rummage through files, copy them somehow or just straight up take them. In a briefcase?? How many files can you exfiltrate per day like that?

But on a database it's practically a matter of running a copy command and uploading it or exfiltrating it. And there will always be software vulnerabilities.

Computer processes have no inherent rate limiter to them, and they even allow you to run stuff from a distance.

Post reply on HN