Live data from Hacker News

French government agency confirms breach as hacker offers to sell data

bleepingcomputer.com

51–60 of 168 posts

Re: French government agency confirms breach as hacker offers to sell data

#51
post #10

> the data stolen in the breach could include full names, dates and places of birth, mailing and email addresses, and phone numbers on an undisclosed number of citizens Nothing really new here sadly, this information about me have leaked half a dozen of times in the past 2-3 years or so. These things will never change if the only penalty the company/agency gets is "send a message to your users saying you are sorry an…

Not disagreeing with you, but:

> These things will never change if the only penalty the company/agency gets is

I do not think penalties can prevent these situations. Perhaps they may be less frequent; perhaps people would get more compensation, but ultimately I do not think these can be prevented. The first consideration is why the data has to be stored in the first place. Naturally one can say "the government needs to know who is a citizen and who is not", and I can understand this rationale to some extent, but even then I wonder whether this has to be correct. Perhaps we could have a global society without any requirement to be an identifiable citizen per se. Things such as mandatory age verification-sniffing to never become an issue, because it is not needed and not possible and nobody would have an addiction-need to sniff for that data (we know Meta and co want that data, this is why their lobbyists run rampage via the "but but but somebody protect the children" lie).

Re: French government agency confirms breach as hacker offers to sell data

#52
post #10

> the data stolen in the breach could include full names, dates and places of birth, mailing and email addresses, and phone numbers on an undisclosed number of citizens Nothing really new here sadly, this information about me have leaked half a dozen of times in the past 2-3 years or so. These things will never change if the only penalty the company/agency gets is "send a message to your users saying you are sorry an…

GDPR has solid fines for data breaches, but this doesn't work for government agencies. Just someone else's money going from one government pocket to another. What they need is an automatic firing of the head of the government agency that suffered a breach. No question asked.

Re: French government agency confirms breach as hacker offers to sell data

#53

It seems to me we must move away from worrying about ransomware, data breach, data protection as that ship has already sailed and everyone's PII has already been stolen. We should think of how to verify people's identities online (for things like government benefits etc). I have heard of the Dutch and the Japanese using national digital identity systems although I am unclear how they work. India is doing biometrics.…

> We should think of how to verify people's identities online

France already has that, in multiple ways.

There is the France Connect SSO, which is kind of a federated SSO. You need at least one account which is physically proven (it could be with the Post Office which send you a letter with a code to confirm your address and idenntity / ask you to physically come to a post office for an ID inspection; the tax authority where there are also multiple physical verification hoops, the social security system, same), and can use that via the SSO to authenticate to all government services.

Separately, there is an app proposed that scans your physical ID's NFC chip with your biomettrics, compares that to a selfie you take, and uses that identity to authenticate you to stuff.

Re: French government agency confirms breach as hacker offers to sell data

#54

Earlier quoted context omitted.

Wait, you don’t even get a month of free credit monitoring?

I'm not sure about France, but here in Argentina all this info is assumed to be public. If you want a credit at a bank or shop, they ask for a physical copy of the national ID [1], probably a photocopy too, an electricity or water bill and perhaps other paperwork that is hard to get (verified phone number???). [1] Do you want my number? It's inside this list: for i in range(1E9): print (i)

[deleted]

Re: French government agency confirms breach as hacker offers to sell data

#55
post #31

Earlier quoted context omitted.

Wait, you don’t even get a month of free credit monitoring?

My full name, phone number, and address were leaked by TAP Air Portugal about five years ago, along with the details of my parents who were on the same booking. Since then, my dad has been targeted by those types of scams where a fraudster impersonates me to ask for money. I never received a notification from TAP; I only found out a year later through my Google One security feature. I certainly didn't get an apology—…

I do use an email alias everywhere. But I don't believe you can do the same with phone numbers. I tried using my twilio rented number and there is a way systems use to figure out if that is a real number for a person or a VoIP one. Though it is sometimes successful in use for signups and hence spam reduction.

Re: French government agency confirms breach as hacker offers to sell data

#57
post #2

Great, now scammers can steal my identity directly from the government. I hope they release a tool to check if I'm impacted or at least email me about it.

Why would those pieces of data (DOB, full name, address) ever be sufficient for identity theft? If that's sufficient to achieve anything then those systems are built on top of hopes and dreams.

It's good enough for health insurance fraud.

Edit: does someone not realize that many (all?) the doctors and hospitals use to verify you is your name and date of birth (in the U.S. - although I suppose that's why since this breach happened elsewhere)?

Re: French government agency confirms breach as hacker offers to sell data

#58

It seems to me we must move away from worrying about ransomware, data breach, data protection as that ship has already sailed and everyone's PII has already been stolen. We should think of how to verify people's identities online (for things like government benefits etc). I have heard of the Dutch and the Japanese using national digital identity systems although I am unclear how they work. India is doing biometrics.…

I can make a new password, hard to get a new eyeball.

Re: French government agency confirms breach as hacker offers to sell data

#59
post #55
post #31

Earlier quoted context omitted.

My full name, phone number, and address were leaked by TAP Air Portugal about five years ago, along with the details of my parents who were on the same booking. Since then, my dad has been targeted by those types of scams where a fraudster impersonates me to ask for money. I never received a notification from TAP; I only found out a year later through my Google One security feature. I certainly didn't get an apology—…

I do use an email alias everywhere. But I don't believe you can do the same with phone numbers. I tried using my twilio rented number and there is a way systems use to figure out if that is a real number for a person or a VoIP one. Though it is sometimes successful in use for signups and hence spam reduction.

Could set up 6 digit long extensions and only ever issue a few hundred of them in total.

Guess wrong 3x and goodbye.

Can also set some/most/all to go to voicemail so they can get in touch with you, but not really.

Or blackhole the invalid extensions to /dev/null voicemail but then you run the risk of legit misdials and you never get some important message.

The real vs “fake” number issue could be worked around by having your cell phone provider forward all calls to your VoIP number. It’s baked into gsm, don’t need a phone after initial setup: https://www.geckobeach.com/cellular/secrets/gsmcodes.php

Re: French government agency confirms breach as hacker offers to sell data

#60
post #2

Great, now scammers can steal my identity directly from the government. I hope they release a tool to check if I'm impacted or at least email me about it.

Why would those pieces of data (DOB, full name, address) ever be sufficient for identity theft? If that's sufficient to achieve anything then those systems are built on top of hopes and dreams.

Because the world is run by people who don't know anything, but have to pretend they know everything, so they can't ask those of us who have some idea about how IT security works.
Post reply on HN