Live data from Hacker News

9M Australians affected by Optus data breach

optus.com.au

71–80 of 104 posts

Re: 9M Australians affected by Optus data breach

#71
Because of this I finally decided to complain to my (Australian) bank about their max 6 character (alphanumeric) no symbol password policy... And lack of MFA for personal accounts... And continuing to only offer OTP via SMS to authorise transactions.

Well, I tried to complain... for you see after going through multiple pages/steps in the UI, when it came time to review and submit, after you press submit you are told that they can't receive complaints online at this time.

So I wrote in the web feedback form instead. At least that went through. As will, I hope, my screenshots of the process to the ombudsman.

In nearly all these microservice components, the UI has an outdated copyright year in the footer. 2016 in the feedback app, 2017 in a preference update component. The year sits right underneath a lock symbol and some text telling you how secure they are.

This tells me a number of things. Either no one has smoke-tested that component for 6 years, or picked up that the year was off, or it has been picked up and left in backlog because of other priorities leaving me to ask what else could be in the aged backlog, but really telling me they don't have the resources to do or to take software or UX seriously.

Re: 9M Australians affected by Optus data breach

#72
I want to point out that Optus also offers a Digital Identity verification solution via Mastercards DI infrastructure. I am currently implementing Mastercards DI solution somewhere...

The way that is implemented SHOULD be mostly unhackable, with everything server side being encrypted and inaccessible without user action and communication with MCs backend.

Still, this is not a good look for trust. Should we now go to Australian customers and say "and now you authenticate via the Optus app, it's super secure" while they immediately think of this hack?

https://www.optus.com.au/customer-extras/mastercard-id

Re: 9M Australians affected by Optus data breach

#73

Earlier quoted context omitted.

I'm an Australian living in Sweden who loves BankID but I don't trust the Aus Govt to provide a similar service.

I hear this often, and as an Aussie techie it's such a shame. Whether or not it's true, it almost certainly means we'll never try. How do we get past this?

> Whether or not it's true,

Australia could not even design a proper national broadband network.

Re: 9M Australians affected by Optus data breach

#74
post #37
post #10

A mobile company that wants so much of their users ID info. Is it really necessary for them to get all that user info?

Probably not. As others have said, some of it is more or less legally required. What I don't understand is why they need to (or should be allowed to) retain that data in perpetuity.

> What I don't understand is why they need to (or should be allowed to) retain that data in perpetuity.

Probably because there is no law saying you need to delete the data in X days.

Re: 9M Australians affected by Optus data breach

#76

Earlier quoted context omitted.

I'm an Australian living in Sweden who loves BankID but I don't trust the Aus Govt to provide a similar service.

I hear this often, and as an Aussie techie it's such a shame. Whether or not it's true, it almost certainly means we'll never try. How do we get past this?

I mean the incompetence is only a tiny part of why I feel this way - with how much they improperly use the data they already have on us I'd rather not let them record every login I perform etc.

Re: 9M Australians affected by Optus data breach

#77

Earlier quoted context omitted.

You can tell how broken their tech is when you try and use the website. Half the pages just fail to load. I don't mean time out, I mean, they think they are finished loading but most of the page is missing.

Don’t confuse the failings of their consumer-facing systems with the madness behind that facade. The equivalent of what I was describing in terms of a web experience would be having to use a dialup modem to sign up for an account via Netscape Navigator 4. With a login secured using SSL… version 1.0. I wish I was exaggerating, but their systems literally date back to that era and have comparable limitations in terms o…

Hahaha holy shit is GSMIS still running? In all it’s TUI glory?

When I left, the mobile division had its customers split between three different systems; GSMIS, Focus and Arbor. The poor customer service reps would have no idea which one any given user was in when the phone rang. The only way to figure it out was to ask the person for their phone number, then type that number into each backend and see which one returned a result.

Re: 9M Australians affected by Optus data breach

#78
post #9

FYI optics is Australia's second largest telecommunications provider. This would be the worst known databreach in Australian history. It is interesting that compared to identity theft announcements from many US corporations they are direct, apologize and state the authorities they are working with. I imagine there's less fear of the legal consequences of not having a tight response as the culture isn't as litigious.

The recent update to Cyber Security legislation in Australia specifically states that any major breach must be reported to the Australian Cyber Security Centre within 24 hours of becoming aware of it. "MAJOR" being subjective, but this easily qualifies. There are significant penalties for not disclosing within this time period, which is why I think we are seeing this reported before Optus has a clearer plan of how to…

Thank for that extra info on the obligatory reporting. Good for consumers to know now. I feel like this report could take months to come out in the US.

Re: 9M Australians affected by Optus data breach

#79
post #47

Glad I dumped them 2 years ago. I hated their imposed "non direct debit fee" if you elected to pay manually instead of direct debit. I hated their mandatory text messages that couldn't be blocked, such as upcoming bill reminders. Spam my email as much as you want, but stay out of my text messages!

Former customers are also included in the breach, just in case you thought you were safe not being a customer anymore.

I doubt from 2 years ago. They probably said that to cover those who recently left. I guess we'll see. Not sure if they are notifying people or there's any way to check?

Re: 9M Australians affected by Optus data breach

#80

I’ve seen Optus “computer security” in action. I use quotes for a reason. There was a court-enforced order requiring them to apply security updates to their production systems. That was in response to a previous breach. You see, until a judge made them do it… they weren’t patching anything. They would just build systems and walk away . For some software systems they had every major and minor version deployed, like a…

> Non-production on the same network was not to be touched.

Unsurprisingly, you're were absolutely correct.

"An early investigation suggests hackers were able to breach Optus through a test network"

'Human error' emerges as factor in Optus hack affecting millions of Australians https://www.abc.net.au/news/2022-09-23/optus-hack-likely-res...

Post reply on HN