Live data from Hacker News

1k Data Breaches Later, the Disclosure Lag Is Worse

troyhunt.com

71–80 of 133 posts

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#71
So at the risk of sounding incredibly apathetic toward something that I'm sure is probably a massive headache for some people somewhere...

I'm a millennial and I've been told probably hundreds of times by this point in my life that my data has been breached. Not a single one of those times was there a) anything truly actionable for me to do about it[0] or b) a single negative impact to my actual life. In anyway. At all.

People were talking about the Equifax breach a decade ago like identity theft was going to become an absolutely routine part of daily life for +90% of people. That didn't happen, at least not for me.

My point is: I understand that this is a topic that nerd communities like HN are well-aligned on—data collection bad, data breach bad, I get it. But does it actually matter?

Every single one of us have had our data harvested by tech giants every second of every day for absolutely decades and neither I nor a single person I know in real life have ever had any negative consequences, either because of the collection itself or from the inevitable and seemingly continuous breaching of that data. Every single website, from the random indie shoe website I purchased from one time to multiple health insurance companies, have breached my data, over the span of decades, and from all appearances it has had absolutely zero effect that I can actually point to in real actual life.

So I'm becoming a bit of a skeptic on this item of quasi-religious dogma that y'all all seem to recite the same position on. Does the emperor perhaps have no clothes? Do we all just fear "data breaches" because we've been told to fear them by people who sounded smarter than us?

I need y'all to hit me with some scary anecdata about what happened to your hairdresser's cousin's ex-husband's dog—anecdata with no citation that I obviously can't even verify isn't hallucinated by a GPT, but should clearly accept as valid because "ooooh data breach bad"—because without that the propaganda patina on my brain is wearing a little thin.

[0] (I use a password manager to guarantee that I'm not sharing passwords between logins, so really the only thing I could do in response to a data breach disclosure is rotate the password on the breached account. But that only matters if they were storing my password in plaintext right? I certainly can't do anything about my data being out there, and it's too late for closing that account out to prevent anything.)

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#72
post #52
post #19

For years, I've been trying my best to stay low-key when it comes to my personal information on the internet. I don't create new accounts, I never cross-login with my email address, I don't use phones. Certainly not perfect, but a lot of times I'm preferring privacy over convenience. At the same time, my government and society at large is pushing more and more for "digital everything". It's great when it works. But t…

>We need to establish measures of accountability for data holders. Not securing customer data appropriately needs to be persecutable, and the affected parties need to be given a right for compensation. The ultimate entity that could hold businesses accountable is the government but the government itself is careless with citizens' private data. I underwent a government required background check to get a security clear…

> The ultimate entity that could hold businesses accountable is the government but the government itself is careless with citizens' private data.

Let's not forget the largest data breach in US history by Elon Musk and his DOGE kids.

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#73
post #64

Earlier quoted context omitted.

> If done right, it is not incompatible with a system where identities can be reconstructed by the authorities for legal actions. Doing it right is exactly the thing that makes this impossible. If instead you give everyone a unique barcode that every other pseudonym can be tied back to, do you really think that database will never be breached? It would become the prime target for all attackers in the world. Meanwhile…

> Doing it right is exactly the thing that makes this impossible. [...] do you really think that database will never be breached? It would become the prime target for all attackers in the world. Critical data is always better in the hand of a few (trustable) than in the hands of many. That is currently the exact reason why you are using Paypal instead of giving your credit card number to everybody. That is the exact…

I don't use Paypal. My credit cards protect me from fraud. And it rarely happens. In fact it's been well over a decade since I had a fraudulent charge on any of my payment cards. Funny how when there's motivation, protection happens.

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#74
post #52
post #19

For years, I've been trying my best to stay low-key when it comes to my personal information on the internet. I don't create new accounts, I never cross-login with my email address, I don't use phones. Certainly not perfect, but a lot of times I'm preferring privacy over convenience. At the same time, my government and society at large is pushing more and more for "digital everything". It's great when it works. But t…

>We need to establish measures of accountability for data holders. Not securing customer data appropriately needs to be persecutable, and the affected parties need to be given a right for compensation. The ultimate entity that could hold businesses accountable is the government but the government itself is careless with citizens' private data. I underwent a government required background check to get a security clear…

Katherine Archuleta and Donna Seymour aren't writing code or administering online systems. I'm sure their organizations have security policies and standards, why not put the devs and sysadmins in prison if they didn't follow them?

I think that what we're seeing is evidence that humans, in general, are not capable of securely delivering the kinds of online services that they are trying to deliver. It's just too complicated, and while defenses have to be perfect, attacks only have to work occasionally to be worth doing.

Edit: not that we shouldn't expect best efforts, and financial liability for organizational failures. Prison maybe for clear proven negligence or intentional sabotage, but for mistakes? Nobody will write software anymore. When is the last time you wrote even a screenful of code without a mistake?

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#75

So at the risk of sounding incredibly apathetic toward something that I'm sure is probably a massive headache for some people somewhere... I'm a millennial and I've been told probably hundreds of times by this point in my life that my data has been breached. Not a single one of those times was there a) anything truly actionable for me to do about it[0] or b) a single negative impact to my actual life. In anyway. At a…

I feel you're correct, and it's why it's a losing battle. It's a spectrum of consequences. The worst outcomes are serious but rare. For most people the most severe outcome they'll deal with are unauthorized credit card charges, which are an annoyance at worst.

The most severe consequences just aren't common enough to elicit any kind of change, and even when they are the response is about cleaning up the damage instead of fixing the upstream problem (how that fraud was allowed to occur in the first place).

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#76

So at the risk of sounding incredibly apathetic toward something that I'm sure is probably a massive headache for some people somewhere... I'm a millennial and I've been told probably hundreds of times by this point in my life that my data has been breached. Not a single one of those times was there a) anything truly actionable for me to do about it[0] or b) a single negative impact to my actual life. In anyway. At a…

Because nothing bad happened to you, therefore nothing bad happens?

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#77
post #67

Earlier quoted context omitted.

Yes, but note that you have to pay for that, see the pricing here: https://haveibeenpwned.com/Subscription#corePlans For me, with a similar wildcard setup, it became something I wasn't willing to spend money on. I work on the basis that accounts are compromised and if the company is large enough I'll see it in the news. Strong passwords, and a password-database is the best I can manage.

You don't, you can register a whole domain and it'll work.

Can confirm it's free. I tried it based on the GP comment. There are various ways to prove it is your domain: token sent to one of a small number of email addresses like {admin,security,webmaster}@, DNS TXT record, place a small file in the root of the website, etc.

The only extra bits I saw for the other emails on my domain was a plus address I'd used for last.fm which had been leaked. None of the other emails (wife, kid, family, etc) appear in any breach.

I'm slowly moving away from using my own personal domain as it's becoming an ever increasing burden. I'm also concerned that my wife/kid will be left with something they may not have access to, or would stop working at some point, if I suddenly dropped dead.

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#78
post #64

Earlier quoted context omitted.

> Doing it right is exactly the thing that makes this impossible. [...] do you really think that database will never be breached? It would become the prime target for all attackers in the world. Critical data is always better in the hand of a few (trustable) than in the hands of many. That is currently the exact reason why you are using Paypal instead of giving your credit card number to everybody. That is the exact…

I don't use Paypal. My credit cards protect me from fraud. And it rarely happens. In fact it's been well over a decade since I had a fraudulent charge on any of my payment cards. Funny how when there's motivation, protection happens.

> My credit cards protect me from fraud.

Your credit card protect you against nothing. Reimbursement in case of fraud is not fraud protection, it is just bare minimal customer service.

In fact, the first thing your bank will do when your credit card number has been leaked and was used for a fraud... is to replace your credit card.

Because they know that, when the number is in the wild, it will happen again. The system is inherently insecure in case of dataleak.

Visa and Mastercard spent decades and millions constructing systems like "3D secure" supposed to protect again that by enforcing external authentication factors. But since the system is not enforced in every country, it is still a problem today.

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#79
post #12

At this stage just expect that every accounts will get leaked or rooted, it's a matter of when, not if... Use varying email `plus addressing` (john+am2604@foo.com), varying passwords or passkey and 2FA on anything remotely important (use of your identity, not just financials).

Plus addressing (or movable periods in gmail addresses, etc) is increasingly pointless for a whole host of reasons.

It may keep out the bottom x% of spammers/hackers but it doesn't do much for the increasingly sophisticated scams that are appearing.

If the bit before the + ends up in your inbox anyway then it'll just get stripped off and used. Spammers seeing this kind of thing across several breach dumps:

bob+trello@example.com, bob+spotify@example.com, bob+chase@example.com

and will leverage that to target spam at you for other sites, or just email bob@example.com as there's a good chance that'll get through.

Years ago I did a test with my own domain where I created who unique aliases with plus addresses, e.g. steve.smith+iawer@example.com, bob.jones+wpoqe@example.com

It didn't take long for emails to start arriving to steve.smith@example.com and bob.jones@example.com even though that email address had never been used anywhere ever before.

As others have said, you're better off just creating unique emails with `pwgen -s 16` such as wmR5pNhGI8yidU7N@example.com and storing that in your password manager alongside a similarly random password. (Yes, this is roughly what those unique email address services provide.)

Also many services/sites/providers simply assume the username is immutable. $DEITY forbid you might have to change your email address at some point in the future.

Re: 1k Data Breaches Later, the Disclosure Lag Is Worse

#80
post #67

Earlier quoted context omitted.

Yes, but note that you have to pay for that, see the pricing here: https://haveibeenpwned.com/Subscription#corePlans For me, with a similar wildcard setup, it became something I wasn't willing to spend money on. I work on the basis that accounts are compromised and if the company is large enough I'll see it in the news. Strong passwords, and a password-database is the best I can manage.

You don't, you can register a whole domain and it'll work.

I had a domain registered and I got notices for about five email addresses - but after a while I was told I'd had too many localparts appear in breaches and I had to pay to upgrade.

It might have changed again now, but that was the point I deleted my account. The pricing list seems to imply a limit on the local-parts for a domain, though ..

Post reply on HN