Live data from Hacker News

1k Data Breaches Later, the Disclosure Lag Is Worse

troyhunt.com

51–60 of 133 posts

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#51
post #19

For years, I've been trying my best to stay low-key when it comes to my personal information on the internet. I don't create new accounts, I never cross-login with my email address, I don't use phones. Certainly not perfect, but a lot of times I'm preferring privacy over convenience. At the same time, my government and society at large is pushing more and more for "digital everything". It's great when it works. But t…

It’s a double whammy in places like India where “digital push” means everything is based on your mobile number with worst of safety and regulation the planet has to offer. Push is 100%, safeguards zero (if not negative).

What makes it even worse is every policy and regulation push is just talk on paper and even it succeeds and comes in effect, it essentially stays at where it was — zero power to the people, zero accountability to others, and negative punishment to the offenders (they are not even considered offenders). There are no legal frameworks like a class action lawsuit either. As in, when you look beyond “paper regulators” (and won’t have to look hard) there is nothing at all, practically speaking.

The thing is you can’t fight it, and you really can’t opt out. Not here. It feels kafkaesque, you don’t even speak up because 90% or more of your compatriots will wonder what the hell you are on about, if you are lucky enough to be not labelled an anti-national.

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#52
post #19

For years, I've been trying my best to stay low-key when it comes to my personal information on the internet. I don't create new accounts, I never cross-login with my email address, I don't use phones. Certainly not perfect, but a lot of times I'm preferring privacy over convenience. At the same time, my government and society at large is pushing more and more for "digital everything". It's great when it works. But t…

>We need to establish measures of accountability for data holders. Not securing customer data appropriately needs to be persecutable, and the affected parties need to be given a right for compensation.

The ultimate entity that could hold businesses accountable is the government but the government itself is careless with citizens' private data.

I underwent a government required background check to get a security clearance and my data was stolen: https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Manag...

My "compensation" for my data being leaked was 1 year of free credit monitoring. But obviously, criminals interested in identity theft will continue their attacks after 1 year.

As far as persecution/prosecution, I suppose Katherine Archuleta, the director of OPM, and the CIO, Donna Seymour ... could have been put in prison as punishment instead of just resigning. I don't think that would change anything. There will still be future scenarios where governments want more collection of private data. Flock cameras, TSA airport scans, internet access age-verification face scans, etc.

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#53
post #34

Earlier quoted context omitted.

I wish that were the case, but because of there being barely any consequences for breaches, it's much more profitable to store everything you can and sell it to the highest bidder. Make it a huge risk to store data, then companies will start treating data like a live hand grenade.

That's exactly what the GDPR tried. If only it was properly enforced

Companies can and do get away with arguing that they have a "lawful basis" to collect whatever data they'd like. It's unfortunate.

IANAL, but the law seems a bit vague to me, and it appears that companies use that vagueness to their advantage. Maybe I'm just not articulating my arguments correctly.

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#54
post #29

Earlier quoted context omitted.

> . I don't create new accounts, I never cross-login with my email address I honestly tend to think this is the only viable long term strategy. Let's face it: In a truly global internet where every single forum or website is hosted in a different country with a different jurisdiction, hoping that every single actor will act responsibly is just delusional. It is not what we see. It is not happening and it is not going…

Is the alternative just accepting that my data is out there? Even if I never used any online service, there are databases out there with my information anyway. Just figure anything online that you aren't securing yourself is compromised. Minimize the effect that has on your life. Identify theft is annoying, but it rarely has severe effects. You will have to go out of your way to be truly anonymous online, and it migh…

> Identify theft is annoying, but it rarely has severe effects.

I disagree. It has already severe effects.

- The fact we are facing so many data leaks made easy for malicious agent to cross and mix data sources and setup much more evolved and convincing scam scheme.

It is now trivial to get name, address, birthday and phone number from a data leak and crossed check that with the login id (email) used for lets say, a financial service and setup a convincing phone scam on that.

Many dubious actors are already doing that. One acquaintance of mine (working in ITsec ironically) got trapped by this exact scheme last week.

- It is trivial to harvest data leaks for online telemarketing, robot calls and any other abusing commercial practices.

- We are heading to a situation where any wierdo or/and stalker with a bit of tech knowhow can rather trivially extract a physical address out of an online profile. That is a giant opened door for harassment and physical insecurity for the most vulnerable of us.

Thats not just "nerd concerns" and the strategy "everything you do online is public" does not work. Many website will request my personal physical address for trivial matters like billing or delivery. That can not under any mean be considered public data.

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#55
post #32
post #24

Earlier quoted context omitted.

If a business legitimately needs such information to operate, isn't it borderline impossible to 100% prevent it from leaking? If the data is there, it can be compromised either by technical means or non-technical means. The primary issues in my opinion are (1) businesses collecting and holding on to information they don't need and (2) businesses getting so large that they become prime targets by default. In a world w…

I'd also add a third issue to this list: data retention. Too many companies I've dealt with have privacy policies that state something to the tune of "we'll hold onto your data for as long as required" without giving much of an explanation as to how long "as required" is.

Which usually means until the financial incentives to remove the data outweigh the incentives to keep the data. Data is more valuable than database storage costs, thus there is no incentive to remove the data. Policies should therefore be in place to punish unnecesary data retention.

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#56
post #53

Earlier quoted context omitted.

That's exactly what the GDPR tried. If only it was properly enforced

Companies can and do get away with arguing that they have a "lawful basis" to collect whatever data they'd like. It's unfortunate. IANAL, but the law seems a bit vague to me, and it appears that companies use that vagueness to their advantage. Maybe I'm just not articulating my arguments correctly.

Even if you have a lawful basis for collecting data, in theory the GDPR is in theory restricting you to only use it for that basis, delete it as soon as you don't need it anymore, have a plan on how to store and handle it, and requires you to follow best practices when doing so. Backups, encryption, regularly testing the technical and organizational measures that protect the data are in theory all mandated. Also, on the topic of this post, notification of data breaches when they occur

But enforcement is just laughable. Even on easy to observe issues like which data is collected

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#57
post #37
post #36

Earlier quoted context omitted.

There is a vast difference between it not being 100% impossible and data holders not doing the absolute basics to keep it safe. I could imagine if, after a data breach, there was a government-run cyber investigative task force that would come into an organization, and be tasked with investigating and fully understanding the nature of the breach. We already have forensic detectives for other crimes, why not this one?…

It doesn't even need to be government-run, we just need the right incentives. I've seen proposals for making some kind of data loss insurance mandatory to compensate victims. The insurance companies would then conduct audits which determine the premiums for the company, and investigate for negligence after a breach. Edit: Thinking more about it, this would probably also be positive for security investigators. If a co…

I've had a similar thought in the past. I was thinking about the feasibility of a law being introduced where each company making over a certain amount of money per year must begin a VDP (and optionally a BBP) so that security flaws can be reported to them easily. This can easily be done by simply opening up security@companydomain and using security.txt (https://securitytxt.org). Reports must receive a response in N days, where N is calculated based on available staff, resource allocation, and revenue of the company. If they don't receive a response after N days, this can be escalated to some government agency which can take action against the company for failing to respond to a report on time.

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#58
post #31

These days I treat other people's data like it's a live hand grenade. Case in point (bit of a shameless plug here :) I'm working on an App called Hockeytastic. It's an ice-hockey stickhandling app that my son's been using for months: the engine is solid but it looked like shit. However, his coach told me to get it on the app stores and sell subs. That meant I needed to clean it up, build a DB, store stuff etc. Anyway…

Why does the app need to store the google/apple Id? Because it stores the data in the cloud, instead of locally for the app to use?

It's for your login and payments. I need to verify that you are authenticated somehow and Google/Apple also handle payments.

You "Login with Apple" or "Login with Google". They manage the login entirely and pass me your id and an access token (assuming you pass their login test). I store that in my DB so that your data from the app can sync (the paid-for app syncs your training data to my backend but I match it only based on the Google/Apple id.)

The alternative is that I build my own auth system and I'd need to store something you can type in the next time, e.g. email/password address etc.

If you have an Android/Apple phone you're already authenticated with them. I just need Google/Apple to say "this guy is cool, let him in" and I then use the id to check if you've paid, sync your training data etc.

On its own, the id is useless! Means nothing and cannot be traced back to a person. I genuinely do not know your name, email, what country you come from, GPS data, CC data. Nothing at all!

I don't want your data.

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#59
post #29
post #19

For years, I've been trying my best to stay low-key when it comes to my personal information on the internet. I don't create new accounts, I never cross-login with my email address, I don't use phones. Certainly not perfect, but a lot of times I'm preferring privacy over convenience. At the same time, my government and society at large is pushing more and more for "digital everything". It's great when it works. But t…

> . I don't create new accounts, I never cross-login with my email address I honestly tend to think this is the only viable long term strategy. Let's face it: In a truly global internet where every single forum or website is hosted in a different country with a different jurisdiction, hoping that every single actor will act responsibly is just delusional. It is not what we see. It is not happening and it is not going…

> If done right, it is not incompatible with a system where identities can be reconstructed by the authorities for legal actions.

Doing it right is exactly the thing that makes this impossible. If instead you give everyone a unique barcode that every other pseudonym can be tied back to, do you really think that database will never be breached? It would become the prime target for all attackers in the world.

Meanwhile reconstructing "identities" is the least valuable thing to doing law enforcement well, because the first thing criminals will do is use someone else's identity, and then tying something to the wrong identity isn't just useless, it's actively counterproductive. The thing you need is not centralized identity but proper investigations that can tie some activity to the person pulling the strings regardless of whose name they're using.

The thing centralized identity does is precisely the opposite -- it leads you to person associated with a name, often the wrong person. You want to get the person offering to do murder for hire to think they have a contract and show up somewhere you can arrest them regardless of whether you know their name, not to convict the person whose identity they stole.

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#60
post #12

At this stage just expect that every accounts will get leaked or rooted, it's a matter of when, not if... Use varying email `plus addressing` (john+am2604@foo.com), varying passwords or passkey and 2FA on anything remotely important (use of your identity, not just financials).

Plus addressing doesn't work well unfortunately - lots of poorly written websites will reject it.

+1 for not giving those websites your email in the first place!
Post reply on HN