Live data from Hacker News

French government agency confirms breach as hacker offers to sell data

bleepingcomputer.com

71–80 of 168 posts

Re: French government agency confirms breach as hacker offers to sell data

#71
post #31

Earlier quoted context omitted.

Wait, you don’t even get a month of free credit monitoring?

My full name, phone number, and address were leaked by TAP Air Portugal about five years ago, along with the details of my parents who were on the same booking. Since then, my dad has been targeted by those types of scams where a fraudster impersonates me to ask for money. I never received a notification from TAP; I only found out a year later through my Google One security feature. I certainly didn't get an apology—…

> I never received a notification from TAP

They have been reporting millions in profits despite rising costs. What you propose would further elevate costs. Shareholders don’t want that.

Re: French government agency confirms breach as hacker offers to sell data

#72
post #34

Earlier quoted context omitted.

I'm dissatisfied about the TAP leak as well! I was affected, and like you, didn't even receive a notification - nevermind compensation for having leaked my personal data to the dark web enabling all sorts of shenanigans that make my personal life difficult.

About 2 million portuguese there. Basically all active portuguese adults that have enough financial conditions to travel by airplane. It was a fantastic leak, based from an excel file asked by a marketing department which forgot it inside a shared folder on the hacked (private) server. There was far more info there than just that, also included the details of employees and more interesting if they were on medical lea…

It’s scams all the way down.

Re: French government agency confirms breach as hacker offers to sell data

#73
post #10

> the data stolen in the breach could include full names, dates and places of birth, mailing and email addresses, and phone numbers on an undisclosed number of citizens Nothing really new here sadly, this information about me have leaked half a dozen of times in the past 2-3 years or so. These things will never change if the only penalty the company/agency gets is "send a message to your users saying you are sorry an…

Penalties don't work for government agencies. Taxpayers would pay for it and it doesn't act as an incentive. The way to fix it is to empower one government agency to do aggressive pentesting against every other agency, hospitals, banks, infrastructure, and big corporations, with salaries matching the private sector. Impose a legally-enforced deadline to fix any issues, with a fine (for private actors) or demotion of…

> Penalties don't work for government agencies. Taxpayers would pay for it and it doesn't act as an incentive.

This is the same as the rogue police problem in the US. What needs to happen is a shift to personal liability for those responsible.

Re: French government agency confirms breach as hacker offers to sell data

#74
post #10

> the data stolen in the breach could include full names, dates and places of birth, mailing and email addresses, and phone numbers on an undisclosed number of citizens Nothing really new here sadly, this information about me have leaked half a dozen of times in the past 2-3 years or so. These things will never change if the only penalty the company/agency gets is "send a message to your users saying you are sorry an…

Seeing another one of these breaches had me returning to look at local-first software. https://lofi.so

I feel like if we're going to make progress in preventing wholesale data breaches it will be through architectural innovations that attack the problem of why a trove of concentrated data needs to exist. Even if the government needs to be a central authority, are there ways to house the data that limit the blast radius?

I'm sure there are innumerable arguments why this can't help, but when the mainstream alternative is despair and helplessness, progress will be made in the margins.

Re: French government agency confirms breach as hacker offers to sell data

#75
post #31

Earlier quoted context omitted.

Wait, you don’t even get a month of free credit monitoring?

My full name, phone number, and address were leaked by TAP Air Portugal about five years ago, along with the details of my parents who were on the same booking. Since then, my dad has been targeted by those types of scams where a fraudster impersonates me to ask for money. I never received a notification from TAP; I only found out a year later through my Google One security feature. I certainly didn't get an apology—…

The world of today is so weird sometimes.

When I was a kid most adults' full name, phone number, and address were available for free in the phone book.

Re: French government agency confirms breach as hacker offers to sell data

#76

Earlier quoted context omitted.

Wait, you don’t even get a month of free credit monitoring?

I'm not sure about France, but here in Argentina all this info is assumed to be public. If you want a credit at a bank or shop, they ask for a physical copy of the national ID [1], probably a photocopy too, an electricity or water bill and perhaps other paperwork that is hard to get (verified phone number???). [1] Do you want my number? It's inside this list: for i in range(1E9): print (i)

> in Argentina all this info is assumed to be public

Same here. You can probably can find my address and phone numbers fairly easily from my name by a number of methods. That doesn't mean it isn't bad when an organisation spews out, or allows to be sucked out, huge numbers of people's data. With a leak like this it is practical to try scam everyone the list, searching for each person's details individually, and having to enumerate those people in the first place⁰, would mean no such attack would scale in a way to make it worthwhile bothering¹.

--------

[0] This seems strange when you first think it, but: the most important thing being on such a list says about you, is that you are a real existing person, whose identity could be exploited somehow. That fact is what makes any other information valuable.

[1] except for high-worth targets, which is why spear-phishing is a thing

Re: French government agency confirms breach as hacker offers to sell data

#77
post #18

Earlier quoted context omitted.

Biometrics is just something else to get leaked, terrible idea because it's even more sensitive (can be used to track you through cameras for example, like used in the Iran war). This problem has long been solved with federated IdPs and MFA - something you own like OTP device/physical token besides something you know like SSN/tax id/password. Most governments prefer biometrics of course because citizen privacy is the…

Biometrics are the only credential you can't roll after compromise.

It depends what the biometrics are. There have been successful hand transplants, so new finger prints are possible, but completely impractical.

https://en.wikipedia.org/wiki/Hand_transplantation

Re: French government agency confirms breach as hacker offers to sell data

#78
post #10

> the data stolen in the breach could include full names, dates and places of birth, mailing and email addresses, and phone numbers on an undisclosed number of citizens Nothing really new here sadly, this information about me have leaked half a dozen of times in the past 2-3 years or so. These things will never change if the only penalty the company/agency gets is "send a message to your users saying you are sorry an…

Or maybe the government should not require companies to KYC you for every little stupid thing or action you do in this world. What happened to requiring only the information that's actually required? Why do I need to be KYCd in the systems when buying banana, ordering delivery, etc.

Because of the inevitable breaches and leaks - KYC is the illicit activity. The selling point of KYC was preventing fraud and money laundering. It doesn't actually do that. Search for "largest money laundering settlements" and you will find 5 banks and one crypto scam.

Re: French government agency confirms breach as hacker offers to sell data

#79
post #30
post #8

Earlier quoted context omitted.

Yes, but unelected bureaucrats only impose fines on the private sector.

what would be the point of the government fining itself though? Now that I'm thinking of it, it would create the need for an extra gaggle of bureaucrats to oversee the process,so I suppose someone might see a point to it ...

You may think you're funny or something, but boy do I have news for you.

There absolutely are fines for French administrations. And, knowing the French tax system, they've probably found a way to levy VAT and some other taxes on top of those fines.

Re: French government agency confirms breach as hacker offers to sell data

#80
post #70
post #10

> the data stolen in the breach could include full names, dates and places of birth, mailing and email addresses, and phone numbers on an undisclosed number of citizens Nothing really new here sadly, this information about me have leaked half a dozen of times in the past 2-3 years or so. These things will never change if the only penalty the company/agency gets is "send a message to your users saying you are sorry an…

The problem though is when its from a gov agency it validates previous breach data making it more valuable.

Depends. According to DOGE, voter registration databases have people listed as 150 years old or deceased people receiving monthly government checks. Obviously a different govt than TFA, but govt databases are no less prone to inaccurate data. They are still run/managed by humans regardless of the govt in question
Post reply on HN