Live data from Hacker News

9M Australians affected by Optus data breach

optus.com.au

81–90 of 104 posts

Re: 9M Australians affected by Optus data breach

#81

Because of this I finally decided to complain to my (Australian) bank about their max 6 character (alphanumeric) no symbol password policy... And lack of MFA for personal accounts... And continuing to only offer OTP via SMS to authorise transactions. Well, I tried to complain... for you see after going through multiple pages/steps in the UI, when it came time to review and submit, after you press submit you are told…

> max 6 character (alphanumeric) no symbol password policy

You forgot to add case isn't significant. Still, even such small passwords can be secure if managed right. It's been that way for many years, and I don't recall seeing anything about it being broken, so I guess it must be work ok. I doubt the ombudsman would care.

On the other hand, every 10 or 20 logins, after logging in it doesn't display the internet banking home page. Instead it displays the home pages CSS stylesheet. That behaviour has also been there for years. I don't know how you even do that.

Re: 9M Australians affected by Optus data breach

#82

Because of this I finally decided to complain to my (Australian) bank about their max 6 character (alphanumeric) no symbol password policy... And lack of MFA for personal accounts... And continuing to only offer OTP via SMS to authorise transactions. Well, I tried to complain... for you see after going through multiple pages/steps in the UI, when it came time to review and submit, after you press submit you are told…

Password length isn't necessarily cause for concern in this context. See: https://www.troyhunt.com/banks-arbitrary-password-restrictio...

As for MFA, the only Australian bank that seems to do it right is Macquarie (who let you remove SMS 2FA and replace it with a decent authenticator app). A handful will issue physical tokens on request (eg HSBC).

Re: 9M Australians affected by Optus data breach

#83

Earlier quoted context omitted.

Don’t confuse the failings of their consumer-facing systems with the madness behind that facade. The equivalent of what I was describing in terms of a web experience would be having to use a dialup modem to sign up for an account via Netscape Navigator 4. With a login secured using SSL… version 1.0. I wish I was exaggerating, but their systems literally date back to that era and have comparable limitations in terms o…

Hahaha holy shit is GSMIS still running? In all it’s TUI glory? When I left, the mobile division had its customers split between three different systems; GSMIS, Focus and Arbor. The poor customer service reps would have no idea which one any given user was in when the phone rang. The only way to figure it out was to ask the person for their phone number, then type that number into each backend and see which one retur…

Telstra's got something similar going on with their management systems - three platforms and two incomplete migrations in progress for seemingly the last eternity.

Re: 9M Australians affected by Optus data breach

#84

Earlier quoted context omitted.

I hear this often, and as an Aussie techie it's such a shame. Whether or not it's true, it almost certainly means we'll never try. How do we get past this?

Personally, it would take strong legislation preventing any variation of law enforcement having any access to any of the data, even that of convicted criminals, to make me comfortable to provide mine into the system. Perhaps even constitutional change prohibiting it. Currently, home affairs could feasibly access any data in just about anything the government does with barely a sign-off which I’m not comfortable with.…

> Our laws protecting us from the government are way too weak for systems like this to take off.

Indeed. Remember when the police got into the contact tracing apps?

Re: 9M Australians affected by Optus data breach

#85
post #79

Earlier quoted context omitted.

Former customers are also included in the breach, just in case you thought you were safe not being a customer anymore.

I doubt from 2 years ago. They probably said that to cover those who recently left. I guess we'll see. Not sure if they are notifying people or there's any way to check?

Based on one newer article I've seen, leaked data dates back to 2017, so...

No idea how accurate this is just yet though.

They claim to have started notifying people today (Saturday), with customers with most amount of info leaked being prioritised. Supposedly if you've had ID information stolen, you'll know today. Fingers crossed.

Re: 9M Australians affected by Optus data breach

#86
post #79

Earlier quoted context omitted.

I doubt from 2 years ago. They probably said that to cover those who recently left. I guess we'll see. Not sure if they are notifying people or there's any way to check?

Based on one newer article I've seen, leaked data dates back to 2017, so... No idea how accurate this is just yet though. They claim to have started notifying people today (Saturday), with customers with most amount of info leaked being prioritised. Supposedly if you've had ID information stolen, you'll know today. Fingers crossed.

Yep, my details were part of the breach unfortunately. I hate Optus now more than ever.

I left them 2 years ago but they keep my details in a database accessible to the internet? Why? Details leaked are name, email, phone, DOB, home address, drivers license number.

About 4 years ago I emailed them complaining that their marketing team were using my date of birth to send me "birthday deals" on my birthday. Something I never opted in for. I found it creepy because the only reason they knew my DOB was from a sign-up security verification process. So back then they were sharing security details from customer signups to their marketing team for use in promotional material. No respect or care for user's data.

I wonder if a class action can be brought against Optus.

Re: 9M Australians affected by Optus data breach

#88
post #86

Earlier quoted context omitted.

Based on one newer article I've seen, leaked data dates back to 2017, so... No idea how accurate this is just yet though. They claim to have started notifying people today (Saturday), with customers with most amount of info leaked being prioritised. Supposedly if you've had ID information stolen, you'll know today. Fingers crossed.

Yep, my details were part of the breach unfortunately. I hate Optus now more than ever. I left them 2 years ago but they keep my details in a database accessible to the internet? Why? Details leaked are name, email, phone, DOB, home address, drivers license number. About 4 years ago I emailed them complaining that their marketing team were using my date of birth to send me "birthday deals" on my birthday. Something I…

Ah man, I'm sorry to hear that. No emails here yet, but not to say I'm not in the category one down yet (which is only slightly less bad).

I'm starting to worry about the general public's understanding of the ramifications of this. When it first broke, I was pretty upset, and my partner (well educated, and with me long enough to understand some things about breaches) thought my concerns and anger at optus was excessive. It's only after I explained to her in some detail a few scenarios of what could happen with the information, that she asked questions about what we should be doing.

I think we'll be seeing fallout from this for years to come.

Re: 9M Australians affected by Optus data breach

#89

I’ve seen Optus “computer security” in action. I use quotes for a reason. There was a court-enforced order requiring them to apply security updates to their production systems. That was in response to a previous breach. You see, until a judge made them do it… they weren’t patching anything. They would just build systems and walk away . For some software systems they had every major and minor version deployed, like a…

https://twitter.com/Jeremy_Kirk/status/1573652986437726208

Re: 9M Australians affected by Optus data breach

#90

I’ve seen Optus “computer security” in action. I use quotes for a reason. There was a court-enforced order requiring them to apply security updates to their production systems. That was in response to a previous breach. You see, until a judge made them do it… they weren’t patching anything. They would just build systems and walk away . For some software systems they had every major and minor version deployed, like a…

https://twitter.com/Jeremy_Kirk/status/1573652986437726208

from the twitter link ..."The Optus hacker says they accessed an unauthenticated API endpoint. This means they didn't have to login. The person says: "No authenticate needed. That is bad access control. All open to internet for any one to use. The API endpoint was api[dot]http://optus.com.au. Yes, that looks weird, but the hacker says it worked otherwise a DNS error occurred. That API is now offline, so there is no more risk for Optus. It was used in part to let Optus customers access their own data."
Post reply on HN