Live data from Hacker News

Hacking into an insurance company by exploiting their premium calculator

eaton-works.com

91–100 of 113 posts

Re: Hacking into an insurance company by exploiting their premium calculator

#92
post #78

Earlier quoted context omitted.

The Peter Principle…people get promoted into incompetence.

We put peter there. He's doing the job we put him there to do.

The Peter Principle says people get promoted until they can’t do the job. If you aren’t being promoted to a higher position people wonder about you…

I see your point, did you know it’s a book?

Dang

Harvard Business Review: https://hbr.org/2014/12/overcoming-the-peter-principle

Re: Hacking into an insurance company by exploiting their premium calculator

#93
They could have set up a rule (within the Outlook logic) to automatically delete any received (and possibly sent) emails, but they didn't.

This takes "don't call us, we'll call you" to the next level: running a vast chunk of your business from the noreply@ account!

Re: Hacking into an insurance company by exploiting their premium calculator

#94

Earlier quoted context omitted.

There is a huge missing niche for trusted intermediaries of identity information. We’ve been working on this at https://cerebrum.com in a different niche (background checks), but this comment just triggered a slew of ideas…

Lol 0/10 marketing push. Btw, schedule is spelt with a c after the s.

Thanks for the feedback on the site!

This isn’t a marketing push so much as an observation. Some company will fill this niche at some point. There is no reason to disclose your SSN to a car dealership if you can share a shielded, verifiable record of your credit history to them.

You can look through my comment history — I am not here to sell a product.

Re: Hacking into an insurance company by exploiting their premium calculator

#95
post #33

Earlier quoted context omitted.

I think nowadays the blur feature just makes it look blurry, but it's not the actual original text being blurred.

How are we to know if someone didn't just use an affine transform? This is another place where ignorance could result in security leaks.

Yeah I'm not fucking around with that. Solid block of black removes the guesses. (Caveats for layered documents like PDFs).

Re: Hacking into an insurance company by exploiting their premium calculator

#97

Earlier quoted context omitted.

> This is what you get, ladies and gentlemen, without unions and labour right. Are you speaking of the EU? The US has at-will employment and most software developers are not unionized.

Is it legal to have a 90 day salary clawback (not a signing bonus clawback, just salary clawback for quitting) in the US?

[deleted]

Re: Hacking into an insurance company by exploiting their premium calculator

#98

Earlier quoted context omitted.

How are we to know if someone didn't just use an affine transform? This is another place where ignorance could result in security leaks.

Yeah I'm not fucking around with that. Solid block of black removes the guesses. (Caveats for layered documents like PDFs).

I like to convert to transparent png, cut the area I need removed, use background color (eg black) to indicate that something was removed, and export to jpg.

Re: Hacking into an insurance company by exploiting their premium calculator

#99
post #84

Earlier quoted context omitted.

https://www.enforcementtracker.com/ Here's a long list of them

Not really. That links to a list of all enforcement actions. If you search for "technical" you get "organisational and technical measures", and most are organisational rather than technical. If you search by the word "hack" which seems to be the seems to be the usual terminology used there for vulnerabilities being exploited. There are 18 of these of 2182 entries. Not even one per EU country since 2018. Given how com…

The search function isn't that good, "Insufficient technical and organisational measures to ensure information security" are basically all data leaks.

Here's a few famous ones, most of which are of course a few years old since government agencies tend to move slow but more recent ones will get what's coming for them.

https://www.theguardian.com/technology/2022/nov/28/meta-fine...

https://ico.org.uk/media/action-weve-taken/mpns/2618524/marr...

https://en.wikipedia.org/wiki/British_Airways_data_breach#Co...

https://www.bbc.com/news/technology-54931873

Re: Hacking into an insurance company by exploiting their premium calculator

#100
post #77

The security blunders are obviously horrible, but MAYBE explained by inexperienced developers tasked with something way beyond their understanding. But how on earth did anyone approve storing confidential customer documents in an email account? This seems to indicate there's nobody in charge that understands anything about how to run this business. And if it's a subsidiary or outsourcing partner, it also shows that n…

I saw a fairly large estate agency system that bcc’d every outgoing email from their system to a shared account everybody then synced to Outlook. It was part audit log, part debugging tool, part database backup. They changed when they realised employees were taking all their customers’ details to new jobs.

The most salient element of this story is that it is business trade secretes (such as customer lists) that motivate enterprises far more than customer privacy.

A friend who's taken Visa's data confidentiality training several times notes that customer data is secondary to Visa's own marketing campaign details.

Post reply on HN