Live data from Hacker News

Delta Dental says data breach exposed info of 7M people

bleepingcomputer.com

91–100 of 152 posts

Re: Delta Dental says data breach exposed info of 7M people

#91

> who had their names, financial account numbers, and credit/debit card numbers, including security codes, exposed. Delta Dental should be rightly and truly f'd for that one. Storing security codes at all is totally forbidden by PCI rules. Delta Dental should have their ability to process credit cards completely revoked for this egregious breach.

Why they are doing their own payments processing is beyond me. Is it just too expensive to use someone like Stripe?

I used to work at a medium-sized non-tech company (We never stored CVVs or any of that insane nonsense though. Our systems only ever saw CC info in transit but they were never stored on-site.

God I miss that company. Working with smart people is great.

Re: Delta Dental says data breach exposed info of 7M people

#93
post #65

If you've been putting it off, a friendly reminder to freeze your account at the credit card agencies. Make sure you do all 3! Here's details from NerdWallet: https://www.nerdwallet.com/article/finance/how-to-freeze-cre...

Good tip! It's awful what this entails: 1) Creating accounts with the major credit reporters, presumably subject to hacks or social engineering 2) Accounts that require answering an easily guessed "secret question" 3) Password "rules" that restrict both the length and special characters of your password 4) After all that, creating the account results in a "Congratulation!" NOT FROZEN account. You have to go through a…

Yeah... it's a complete PITA. I also had the 'we can't freeze right now' and it took a few days of verification and eventually having to call them to get it all sorted.

My reasoning is it's better to do this before a bad person has your account rather than during.

Re: Delta Dental says data breach exposed info of 7M people

#94
we need to flip the conversation on this.

journalists don't seem to grok the fact that breaches are totally the fault of the breached site. sure, the attackers are bad people, but that's a different crime.

we need something close to a death sentence for sites that allow themselves to be breached. mandatory $10k per exposed SSN, $10 per exposed email, that sort of thing.

what would be the result? only good: sites should not be storing this data themselves. the real conversation-flip is that we need to put people in charge of their own data, and make it radioactive for data-users (like Delta Dental) to store it. this kind of data should only live in facilities that are solely run for the purpose, and which provide the data-subject with full control. who pays? not really that hard - some combination of the data-subject, data-users (transaction fees), perhaps just a governmental single payer (since we're talking tiny cost).

imagine if you could look at your data (you can't today!) and could explicitly share out bits to particular data-users. all your records (dental, tax, CC, banking).

Re: Delta Dental says data breach exposed info of 7M people

#96

> who had their names, financial account numbers, and credit/debit card numbers, including security codes, exposed. Delta Dental should be rightly and truly f'd for that one. Storing security codes at all is totally forbidden by PCI rules. Delta Dental should have their ability to process credit cards completely revoked for this egregious breach.

I use delta dental. What does this mean? Why would they store my CC info when I’m paying directly to my dentist and delta dental is also paying the dentist?

How does my CC info get transferred to the insurer? There’s no such transaction afaik.

Re: Delta Dental says data breach exposed info of 7M people

#97

Earlier quoted context omitted.

> A customer asked for a screen to be able to see CC numbers for their own customers I'd be curious what reason they had.

In 2002? Probably something now-crazy like “how else will I process returns?” It is not directly related, but as a hopefully funny semi-related anecdote, the federal government stopped states from putting social security numbers on drivers licenses in 2004. Renewals frequency depends on the state, but it is typically in the 4-8 year range, so plausibly until 2012 people were going around showing their SSN to anybody…

SSNs shouldn’t have to be kept any more secret than your name. The fact that somehow they started being used as passwords is the insane thing.

Re: Delta Dental says data breach exposed info of 7M people

#98

Earlier quoted context omitted.

In 2002? Probably something now-crazy like “how else will I process returns?” It is not directly related, but as a hopefully funny semi-related anecdote, the federal government stopped states from putting social security numbers on drivers licenses in 2004. Renewals frequency depends on the state, but it is typically in the 4-8 year range, so plausibly until 2012 people were going around showing their SSN to anybody…

At one time it was routine to have your SSN and Drivers License # printed on your checks. And in 1988 my student ID number as university was my SSN.

But 1988 is officially The Past, ask any millennial, my self image can’t deal with the fact that our anecdotes objectively belong side-by-side.

Re: Delta Dental says data breach exposed info of 7M people

#99
post #30

They knew about the breach June 1, confirmed June 6, but the information is only made public after almost five months, November 27? (After a "second, more lengthy investigation".) This is better than nothing, but it seems absurd.

It is absurd, and it violates the mandatory timely notification laws which are in place in many states, including Washington. Umpqua bank was also affected by MoveIt by way of one of their fintech vendors (FIS), they didn't even bother to notify my state's AG, as required by law, nor did they provide timely or accurate notifications. Maybe companies feel a diffusion of responsibility when there are so many others aff…

They feel a diffusion of responsibility because they are never held responsible for it.

Re: Delta Dental says data breach exposed info of 7M people

#100
post #93

Earlier quoted context omitted.

Good tip! It's awful what this entails: 1) Creating accounts with the major credit reporters, presumably subject to hacks or social engineering 2) Accounts that require answering an easily guessed "secret question" 3) Password "rules" that restrict both the length and special characters of your password 4) After all that, creating the account results in a "Congratulation!" NOT FROZEN account. You have to go through a…

Yeah... it's a complete PITA. I also had the 'we can't freeze right now' and it took a few days of verification and eventually having to call them to get it all sorted. My reasoning is it's better to do this before a bad person has your account rather than during.

Why are you doing so much work to save some third party money when they get defrauded?
Post reply on HN