Live data from Hacker News

1B identity records exposed in ID verification data leak

aol.com

51–60 of 67 posts

Re: 1B identity records exposed in ID verification data leak

#51

At this point I get about 1-2 emails a year telling me some company has exposed my private data in some way. It’s completely routine. We need a law mandating the company pays at least $1k per exposed record per customer or absolutely nothing will change. The current cost of “here’s a years worth of credit monitoring” doesn’t even amount to a slap on the wrist.

> We need a law mandating the company pays at least $1k per exposed record per customer or absolutely nothing will change.

That won't change a single thing, except for shell-company shenanigans, more frequent bankruptcy proceedings, and the same people coming back trading under a new name and logo. A law sending people to prison may actually change things.

Re: 1B identity records exposed in ID verification data leak

#52

At this point I get about 1-2 emails a year telling me some company has exposed my private data in some way. It’s completely routine. We need a law mandating the company pays at least $1k per exposed record per customer or absolutely nothing will change. The current cost of “here’s a years worth of credit monitoring” doesn’t even amount to a slap on the wrist.

> We need a law mandating the company pays at least $1k per exposed record per customer or absolutely nothing will change. That won't change a single thing, except for shell-company shenanigans, more frequent bankruptcy proceedings, and the same people coming back trading under a new name and logo. A law sending people to prison may actually change things.

All those people have high-priced lawyers that will keep them out of prison. The DBA and the Data Engineer will be the ones who go to jail for "Not ensuring all applicable data security controls were configured, and enabled, to prevent the detection, collection, and modification of any and all data assets within the purview of Company X, all its holdings and subsidiaries."

Re: 1B identity records exposed in ID verification data leak

#54

Earlier quoted context omitted.

> It does apply in the US EU law does not apply to US citizens residing in the US with no ties to the EU.

Correct. It does not apply to US citizens residing anywhere in the world. It does, however, as I said, apply to EU citizens regardless of where in the world they reside. If a company holds data about EU citizens, the GDPR applies to them, regardless of where that company is based. Including the US. Hence the statement "It (GDPR) does apply in the US" is completely correct.

It's written that way, perhaps.

But there's no jurisdictional reality that any of country/union A's rights will protect a person while they are present in country/union B.

In the same way that a US citizen does not have legal protection for free speech when present in, e.g. China, Saudi Arabia, or Germany.

Even if the EU got the text incorporated into the UN Universal Declaration of Human Rights, there are famously many countries who are not signatories (and it would require a locally-implemented actual law to support its recognition).

The EU can arrange post facto penalties for violations of their citizens' rights, to be (potentially) administered in the future, when a responsible entity enters EU jurisdiction, but absolutely not before then without cooperation by treaty with the nation where these foreign-and-not-real "rights" were violated. Which would be a surrender of sovereignty and basically unimaginable.

(No comment on the goodness or successfulness of the GDPR here, just that no part of it is relevant outside of the EU regardless of how the text is composed.)

(And this is all written with awareness that the US somehow manages to selectively enforce their laws extra-jurisdictionally in weak foreign nations. The EU is not the US, and the US is not weak.)

Re: 1B identity records exposed in ID verification data leak

#55

Earlier quoted context omitted.

> We need a law mandating the company pays at least $1k per exposed record per customer or absolutely nothing will change. That won't change a single thing, except for shell-company shenanigans, more frequent bankruptcy proceedings, and the same people coming back trading under a new name and logo. A law sending people to prison may actually change things.

All those people have high-priced lawyers that will keep them out of prison. The DBA and the Data Engineer will be the ones who go to jail for "Not ensuring all applicable data security controls were configured, and enabled, to prevent the detection, collection, and modification of any and all data assets within the purview of Company X, all its holdings and subsidiaries."

force nationalization of the business for egregious cases.

Re: 1B identity records exposed in ID verification data leak

#56

At this point I get about 1-2 emails a year telling me some company has exposed my private data in some way. It’s completely routine. We need a law mandating the company pays at least $1k per exposed record per customer or absolutely nothing will change. The current cost of “here’s a years worth of credit monitoring” doesn’t even amount to a slap on the wrist.

> We need a law mandating the company pays at least $1k per exposed record per customer or absolutely nothing will change. That won't change a single thing, except for shell-company shenanigans, more frequent bankruptcy proceedings, and the same people coming back trading under a new name and logo. A law sending people to prison may actually change things.

"Oh you want to make a little start up to share recipes between friends or whatever? Aww, that's cute. Well, here's the OAuth spec and an incomplete list of footguns. I hope your grasp of elliptic curves is strong. Prison time if you fail."

The absolutely only consequence of laws that criminalise mistakes in handling of PII is to force everyone to externalise auth to the likes of Auth0. And you can bet your ass that if this ever happens, the likes of Auth0 will lobby like hell to never ever repeal or update those laws, being a vast corrupt funnel of business to them.

Congrats, you've created a new Inuit.

Re: 1B identity records exposed in ID verification data leak

#57
post #14

If I was in Vegas, I would bet my life savings that the CXOs of the said ID Verification company's data isn't included in the leak. This is just like that Mc Donald's CEO's video - they never use what they create.

I bet their data is included too, for two reasons: First, identity verification data for KYC is a little bit different from fast food or social media in that it's very difficult to live a normal life without being subject to any KYC checks. (I'm sure someone will chime in that they get paid in bitcoin and buy their groceries with cash.) If you are applying for some financial product or service that requires KYC, and…

I am not debating that they don't need KYC, I'm simply saying they probably use a more secure alternative than their own.

Re: 1B identity records exposed in ID verification data leak

#58
post #26
post #14

If I was in Vegas, I would bet my life savings that the CXOs of the said ID Verification company's data isn't included in the leak. This is just like that Mc Donald's CEO's video - they never use what they create.

Or the tech executives barring their children from using social media.

Absolutely!

Re: 1B identity records exposed in ID verification data leak

#59
post #54

Earlier quoted context omitted.

Correct. It does not apply to US citizens residing anywhere in the world. It does, however, as I said, apply to EU citizens regardless of where in the world they reside. If a company holds data about EU citizens, the GDPR applies to them, regardless of where that company is based. Including the US. Hence the statement "It (GDPR) does apply in the US" is completely correct.

It's written that way, perhaps. But there's no jurisdictional reality that any of country/union A's rights will protect a person while they are present in country/union B. In the same way that a US citizen does not have legal protection for free speech when present in, e.g. China, Saudi Arabia, or Germany. Even if the EU got the text incorporated into the UN Universal Declaration of Human Rights, there are famously m…

Just, that is why I wrote "it's just potentially harder for the EU to enforce meaningful penalties for infractions."

You premise is true in one sense, however, the point remains - the GDPR covers all EU citizens, regardless of where the company is based. For small US companies, sure the EU has very little power to enforce it, but larger companies that derive any revenue from the EU can be, and are, fined by the EU GDPR commissioners.

There is more information here: https://www.gdpradvisor.co.uk/does-gdpr-affect-us-companies or here: https://www.clarip.com/data-privacy/gdpr-united-states/ or here: https://www.usitc.gov/publications/332/executive_briefings/g... or here: https://dataprivacymanager.net/5-biggest-gdpr-fines-so-far-2... (that last one, 16 of the 20 biggest fines were for companies outside the EU)

I can't find the source, but Google's AI in the search results also claims that "EU GDPR fines for U.S. companies are significant, with U.S. firms facing roughly 83% of total GDPR fines, totaling over €4.68 billion by early 2025". That 83% figure seems unreasonably high to me, but it's possibly just a consequence of the size of the fine being based on worldwide revenue and over half of the 20 biggest fines were to Google and Meta.

Re: 1B identity records exposed in ID verification data leak

#60
post #54

Earlier quoted context omitted.

It's written that way, perhaps. But there's no jurisdictional reality that any of country/union A's rights will protect a person while they are present in country/union B. In the same way that a US citizen does not have legal protection for free speech when present in, e.g. China, Saudi Arabia, or Germany. Even if the EU got the text incorporated into the UN Universal Declaration of Human Rights, there are famously m…

Just, that is why I wrote "it's just potentially harder for the EU to enforce meaningful penalties for infractions." You premise is true in one sense, however, the point remains - the GDPR covers all EU citizens, regardless of where the company is based. For small US companies, sure the EU has very little power to enforce it, but larger companies that derive any revenue from the EU can be, and are, fined by the EU GD…

I get it, but the operative point is not "potentially harder", but "literally impossible" to enforce -- unless the corp has some presence in the EU of course.

FWIW, I just checked Wikipedia to sanity-check my memory of our lawyers' guidance. Important differences from our discussion, if my read is correct:

GDPR does not apply to "EU citizens anywhere in the world", it applies to the personal data of "living persons ... inside the EU" or with data processed there.

(So GDPR would apply to a US citizen who is present in the EU, and/or being a user/customer of a vendor that operates in the EU)

From the "Misconceptions" section[0]:

  > ## Misconceptions
  >
  > GDPR applies to anyone processing personal data of EU citizens anywhere in the world
  >
  > In fact, it applies to non-EU established organizations only where they are processing data of data subjects located in the EU (irrespective of their citizenship) and then only when supplying goods or services to them, or monitoring their behaviour.
(So GDPR would not apply to a EU citizen who is present in the US at the time of "processing", whether that's a service or product sale, etc)

This is important to my company. We are US-based, but have EU citizens as customers. For regulatory reasons, we block customer activity from outside the US, and we are not able to comply with GDPR (but we do have to be aware of CCPA[1] which has some similarities).

[0] https://en.wikipedia.org/wiki/General_Data_Protection_Regula...

[1] https://en.wikipedia.org/wiki/California_Consumer_Privacy_Ac...

Post reply on HN