Live data from Hacker News

9M Australians affected by Optus data breach

optus.com.au

31–40 of 104 posts

Re: 9M Australians affected by Optus data breach

#31
post #10

A mobile company that wants so much of their users ID info. Is it really necessary for them to get all that user info?

This doesn't even seem to include the traffic retention data that must be kept in Australia. That's an accident waiting to happen.

Re: 9M Australians affected by Optus data breach

#34
post #22

Today is a one-off national public holiday in Australia to mourn the loss of the Queen. I'd be curious to know when this attack started and whether it coincided with the public holiday by chance or by choice.

I don't know when it actually occurred, but usually this sort of announcement comes long after the incident. The announcement occurring on a holiday afternoon seems a little convenient.

That said, Optus knows they don't get in any real trouble for this sort of thing so they can only benefit from appearing to respond rapidly and transparently. (Which is a better PR move than being proactive)

Re: 9M Australians affected by Optus data breach

#35
It's long past time for countries to embrace the digital id the way Estonia (and a few others) have.

For comparison, visit https://www.telia.ee/en and you're prompted for your smart card or associated Smart ID (which is mobile app you can bootstrap from your smart card).

No more need to do a 100 point check (and then hold that information indefinitely), it's been done.

Even if you don't like the Estonian system it's high time to get serious about digital identity and stop pretending that knowing your DoB etc (or social security number in US) is a secure mechanism of proving identity.

Aside: Highly recommend Estonia's e-residency program. Great place to run a company. Future focused.

Re: 9M Australians affected by Optus data breach

#36

I’ve seen Optus “computer security” in action. I use quotes for a reason. There was a court-enforced order requiring them to apply security updates to their production systems. That was in response to a previous breach. You see, until a judge made them do it… they weren’t patching anything. They would just build systems and walk away . For some software systems they had every major and minor version deployed, like a…

maybe the same or a different determination that was levelled against them? https://web.archive.org/web/20170218203327/https://www.oaic....

the 100,000’s of open management ports is pretty lol

Re: 9M Australians affected by Optus data breach

#37
post #10

A mobile company that wants so much of their users ID info. Is it really necessary for them to get all that user info?

Probably not. As others have said, some of it is more or less legally required. What I don't understand is why they need to (or should be allowed to) retain that data in perpetuity.

Re: 9M Australians affected by Optus data breach

#39

> Information which may have been exposed includes customers’ names, dates of birth, phone numbers, email addresses, and, for a subset of customers, addresses, ID document numbers such as driver's licence or passport numbers Okay so this was half the country. I cant honestly understand how anyone thinks KYC laws make sense if anyone can make a bank account as anyone else, and it all looks like legitimate money or the…

> driver's licence or passport numbers

They are required to verify that information.

They shouldn't have been storing that though.

Should only have existed for the period of the verification request on signup - a single form post.

Re: 9M Australians affected by Optus data breach

#40

How could Dan Andrews let this happen? /s

Ironically #Gladys is currently trending on twitter due to a similar question from people.

Nah this is why:

https://www.optus.com.au/about/media-centre/media-releases/2...

> Optus appoints Gladys Berejiklian to its Executive Team in a new role as Managing Director, Enterprise, Business and Institutional

Post reply on HN