Live data from Hacker News

9M Australians affected by Optus data breach

optus.com.au

51–60 of 104 posts

Re: 9M Australians affected by Optus data breach

#51
post #49
post #24

Earlier quoted context omitted.

It shows why we need to rapidly embrace the idea that knowledge of an ID document number and its associated personal details is insufficient proof of identity.

this brings up a very important question - how does one verify one's identity with a business? Esp. online, without having to meet in person at some sort of branch/store?

Some kind of identity provider, like https://www.mygovid.gov.au/ or https://www.digitalid.com/personal

Yes it’s pushing the problem somewhere else, but at least I’m not giving copies of my ID to every little shit of a business.

Re: 9M Australians affected by Optus data breach

#52
In Australia, due to counter terror laws, you can't get a phone sim without providing verifiable government ID. So the consequence of that is that they phone companies have a really large amount of sensitive information. This information loss should be treated like a workplace death. Or a toxic spill. things will only change when a CEO goes to jail for this sort of obvious negligence. It may be harsh, but until there's real consequences, nothing will change.

Re: 9M Australians affected by Optus data breach

#53
post #35

It's long past time for countries to embrace the digital id the way Estonia (and a few others) have. For comparison, visit https://www.telia.ee/en and you're prompted for your smart card or associated Smart ID (which is mobile app you can bootstrap from your smart card). No more need to do a 100 point check (and then hold that information indefinitely), it's been done. Even if you don't like the Estonian system it's…

I'm an Australian living in Sweden who loves BankID but I don't trust the Aus Govt to provide a similar service.

I hear this often, and as an Aussie techie it's such a shame. Whether or not it's true, it almost certainly means we'll never try. How do we get past this?

Re: 9M Australians affected by Optus data breach

#54

> Information which may have been exposed includes customers’ names, dates of birth, phone numbers, email addresses, and, for a subset of customers, addresses, ID document numbers such as driver's licence or passport numbers. Payment detail and account passwords have not been compromised. Geez, ID document numbers is such a big thing. Now hackers can basically call most institution and impersonate victims. this is qu…

Why the hell were they storing it? just delete it after marking the account as verified.

Re: 9M Australians affected by Optus data breach

#55
> Optus notifies customers of cyberattack compromising customer information

- the notification being finding a link to their quietly released press release on HN this afternoon? Thanks Optus!

- cyberattack is the word to use to encourage speculation that a nation-state was behind the breach, that there was no way to defend against this and to avoid saying "data breach"

- here "customer information" means current and former Optus customers' personal information

Re: 9M Australians affected by Optus data breach

#56
post #52

In Australia, due to counter terror laws, you can't get a phone sim without providing verifiable government ID. So the consequence of that is that they phone companies have a really large amount of sensitive information. This information loss should be treated like a workplace death. Or a toxic spill. things will only change when a CEO goes to jail for this sort of obvious negligence. It may be harsh, but until there…

Optus CEO Kelly Bayer Rosmarin did an interview with ABC today, and said "some of the customer information is information you would find on Facebook or LinkedIn such as name, date of birth, phone number and email address".

Umm...no. Most people do NOT publicise that information to the public.

Agreed. Until a CEO goes to jail for something like this, it'll continue to become a "pay the fine and move on" situation.

Re: 9M Australians affected by Optus data breach

#57
post #34
post #22

Today is a one-off national public holiday in Australia to mourn the loss of the Queen. I'd be curious to know when this attack started and whether it coincided with the public holiday by chance or by choice.

I don't know when it actually occurred, but usually this sort of announcement comes long after the incident. The announcement occurring on a holiday afternoon seems a little convenient. That said, Optus knows they don't get in any real trouble for this sort of thing so they can only benefit from appearing to respond rapidly and transparently. (Which is a better PR move than being proactive)

New laws make it mandatory to report this major type of breach in Australia to the Australian Cyber Security Centre within 24 hours. They had no choice, or risk having the full weight of the government come at them for trying to cover it up.

Re: 9M Australians affected by Optus data breach

#58
post #40

Earlier quoted context omitted.

Ironically #Gladys is currently trending on twitter due to a similar question from people.

Nah this is why: https://www.optus.com.au/about/media-centre/media-releases/2... > Optus appoints Gladys Berejiklian to its Executive Team in a new role as Managing Director, Enterprise, Business and Institutional

“Optus has set its vision to become Australia’s most loved everyday brand with lasting customer relationships by redefining what customers should expect from their communication provider through our relentless pursuit of best-in-class service, greater innovation, better value and connectivity for all Australians.”

Thsts... amusing.

Re: 9M Australians affected by Optus data breach

#59
post #12

This is bad. Australia isn't know for it's strong privacy laws anyway, but with the kind of data that's now available out there, ID theft is going to be a huge risk for almost half the country. Even if Optus gets sued, how the hell are people supposed to protect themselves?

To protect themselves, I suspect services like "credit monitoring and alerting" services will see increased subscribers in coming months.

I'm in no way affiliated, but an example is https://www.equifax.com.au/lp/protect-your-identity

AUD$15 per month to tell you if your details are leaked or used to create an account in your name.

Re: 9M Australians affected by Optus data breach

#60
post #54

> Information which may have been exposed includes customers’ names, dates of birth, phone numbers, email addresses, and, for a subset of customers, addresses, ID document numbers such as driver's licence or passport numbers. Payment detail and account passwords have not been compromised. Geez, ID document numbers is such a big thing. Now hackers can basically call most institution and impersonate victims. this is qu…

Why the hell were they storing it? just delete it after marking the account as verified.

Even if it needs to be verified afterwards, the numbers could be bcrypted with high enough iteration count to make them impossible to brute force but easy to verify every few years if necessary... Say 10sec per id?
Post reply on HN