At this stage just expect that every accounts will get leaked or rooted, it's a matter of when, not if... Use varying email `plus addressing` (john+am2604@foo.com), varying passwords or passkey and 2FA on anything remotely important (use of your identity, not just financials).
The + trick is useless to protect you, obviously. Instead, use a a service like simplelogin to create unique emails for every place you sign in.
1k Data Breaches Later, the Disclosure Lag Is Worse
61–70 of 133 posts
Re: 1k Data Breaches Later, the Disclosure Lag Is Worse
#62For years, I've been trying my best to stay low-key when it comes to my personal information on the internet. I don't create new accounts, I never cross-login with my email address, I don't use phones. Certainly not perfect, but a lot of times I'm preferring privacy over convenience. At the same time, my government and society at large is pushing more and more for "digital everything". It's great when it works. But t…
Re: 1k Data Breaches Later, the Disclosure Lag Is Worse
#63That's the only sensible approach. It's the one that I use, but then, I care about the users of my software, and I don't make any money from their PII.
Re: 1k Data Breaches Later, the Disclosure Lag Is Worse
#64Earlier quoted context omitted.
> . I don't create new accounts, I never cross-login with my email address I honestly tend to think this is the only viable long term strategy. Let's face it: In a truly global internet where every single forum or website is hosted in a different country with a different jurisdiction, hoping that every single actor will act responsibly is just delusional. It is not what we see. It is not happening and it is not going…
> If done right, it is not incompatible with a system where identities can be reconstructed by the authorities for legal actions. Doing it right is exactly the thing that makes this impossible. If instead you give everyone a unique barcode that every other pseudonym can be tied back to, do you really think that database will never be breached? It would become the prime target for all attackers in the world. Meanwhile…
Critical data is always better in the hand of a few (trustable) than in the hands of many.
That is currently the exact reason why you are using Paypal instead of giving your credit card number to everybody.
That is the exact reason why you are using a password manager.
A lot about security is about who you trust, and for how long.
Re: 1k Data Breaches Later, the Disclosure Lag Is Worse
#65I have a custom domain for my emails with catch all. When I create an account somewhere I just use @my-domain.com Can I find out if any of my emails are in leaks with a service somewhere?
That's literally what Have I Been Pwned is for. https://haveibeenpwned.com/
https://haveibeenpwned.com/Subscription#corePlans
For me, with a similar wildcard setup, it became something I wasn't willing to spend money on. I work on the basis that accounts are compromised and if the company is large enough I'll see it in the news. Strong passwords, and a password-database is the best I can manage.
Re: 1k Data Breaches Later, the Disclosure Lag Is Worse
#66Earlier quoted context omitted.
It doesn't even need to be government-run, we just need the right incentives. I've seen proposals for making some kind of data loss insurance mandatory to compensate victims. The insurance companies would then conduct audits which determine the premiums for the company, and investigate for negligence after a breach. Edit: Thinking more about it, this would probably also be positive for security investigators. If a co…
I've had a similar thought in the past. I was thinking about the feasibility of a law being introduced where each company making over a certain amount of money per year must begin a VDP (and optionally a BBP) so that security flaws can be reported to them easily. This can easily be done by simply opening up security@companydomain and using security.txt ( https://securitytxt.org ). Reports must receive a response in N…
Re: 1k Data Breaches Later, the Disclosure Lag Is Worse
#67Earlier quoted context omitted.
That's literally what Have I Been Pwned is for. https://haveibeenpwned.com/
Yes, but note that you have to pay for that, see the pricing here: https://haveibeenpwned.com/Subscription#corePlans For me, with a similar wildcard setup, it became something I wasn't willing to spend money on. I work on the basis that accounts are compromised and if the company is large enough I'll see it in the news. Strong passwords, and a password-database is the best I can manage.
Re: 1k Data Breaches Later, the Disclosure Lag Is Worse
#68Earlier quoted context omitted.
The + trick is useless to protect you, obviously. Instead, use a a service like simplelogin to create unique emails for every place you sign in.
Correct, but you get to see who leaked you.
Re: 1k Data Breaches Later, the Disclosure Lag Is Worse
#69Earlier quoted context omitted.
Is the alternative just accepting that my data is out there? Even if I never used any online service, there are databases out there with my information anyway. Just figure anything online that you aren't securing yourself is compromised. Minimize the effect that has on your life. Identify theft is annoying, but it rarely has severe effects. You will have to go out of your way to be truly anonymous online, and it migh…
> Identify theft is annoying, but it rarely has severe effects. I disagree. It has already severe effects. - The fact we are facing so many data leaks made easy for malicious agent to cross and mix data sources and setup much more evolved and convincing scam scheme. It is now trivial to get name, address, birthday and phone number from a data leak and crossed check that with the login id (email) used for lets say, a…
Some will even require it for no actual reason at all.
Do I need to give my living address when I buy a sandwich? Then why would I need to when buying an online service?
Similarly, fast foods nearly all have these automated kiosques. They don’t need any info. So why do they require an email address when ordering to the table through the app, while in the restaurant?
They don’t need them. They just demand them because they can and everyone online is used to giving them without a second thought.
I can’t wait for personal data to become digital radioactive waste.
Re: 1k Data Breaches Later, the Disclosure Lag Is Worse
#70At this stage just expect that every accounts will get leaked or rooted, it's a matter of when, not if... Use varying email `plus addressing` (john+am2604@foo.com), varying passwords or passkey and 2FA on anything remotely important (use of your identity, not just financials).
Ever since I don't trust online services.