Earlier quoted context omitted.
It's for your login and payments. I need to verify that you are authenticated somehow and Google/Apple also handle payments. You "Login with Apple" or "Login with Google". They manage the login entirely and pass me your id and an access token (assuming you pass their login test). I store that in my DB so that your data from the app can sync (the paid-for app syncs your training data to my backend but I match it only…
If I'm using an app I'm very skeptical of "Login with Google" because I have no way to verify that you're only getting a random identifier and not my email address. I prefer to sign up with a proxy email address.
1k Data Breaches Later, the Disclosure Lag Is Worse
91–100 of 133 posts
Re: 1k Data Breaches Later, the Disclosure Lag Is Worse
#92Earlier quoted context omitted.
>We need to establish measures of accountability for data holders. Not securing customer data appropriately needs to be persecutable, and the affected parties need to be given a right for compensation. The ultimate entity that could hold businesses accountable is the government but the government itself is careless with citizens' private data. I underwent a government required background check to get a security clear…
Katherine Archuleta and Donna Seymour aren't writing code or administering online systems. I'm sure their organizations have security policies and standards, why not put the devs and sysadmins in prison if they didn't follow them? I think that what we're seeing is evidence that humans, in general, are not capable of securely delivering the kinds of online services that they are trying to deliver. It's just too compli…
So we should start treating them like licensed engineers... Actually I agree with this.
Re: 1k Data Breaches Later, the Disclosure Lag Is Worse
#93So at the risk of sounding incredibly apathetic toward something that I'm sure is probably a massive headache for some people somewhere... I'm a millennial and I've been told probably hundreds of times by this point in my life that my data has been breached. Not a single one of those times was there a) anything truly actionable for me to do about it[0] or b) a single negative impact to my actual life. In anyway. At a…
I feel you're correct, and it's why it's a losing battle. It's a spectrum of consequences. The worst outcomes are serious but rare. For most people the most severe outcome they'll deal with are unauthorized credit card charges, which are an annoyance at worst. The most severe consequences just aren't common enough to elicit any kind of change, and even when they are the response is about cleaning up the damage instea…
One time there was a leak from a university database and as a result there were a few news articles over the years about people that had their identity stolen likely due to that leak. It's not just credit card charges. They have had loans taken in their names, stuff bought on store credit or something (nowadays that's not so easy), stuff stolen from library in their name...
They had to deal with the fallout for years, always fearing that there's a new letter waiting at home regarding some unpaid expense or from debt enforcement agency that they have to contact and try to make it go away. It shouldn't be too hard if you have an open case with the police but it's not always that easy.
Also, if the leaked data is sensitive (e.g. private conversations, records about mental health etc.), you can face extortion or the data may get published.
One other thing that I know of personally is that victims of harassment very much don't like to have their contact info leaked to the harasser.
Re: 1k Data Breaches Later, the Disclosure Lag Is Worse
#94Earlier quoted context omitted.
>We need to establish measures of accountability for data holders. Not securing customer data appropriately needs to be persecutable, and the affected parties need to be given a right for compensation. The ultimate entity that could hold businesses accountable is the government but the government itself is careless with citizens' private data. I underwent a government required background check to get a security clear…
Katherine Archuleta and Donna Seymour aren't writing code or administering online systems. I'm sure their organizations have security policies and standards, why not put the devs and sysadmins in prison if they didn't follow them? I think that what we're seeing is evidence that humans, in general, are not capable of securely delivering the kinds of online services that they are trying to deliver. It's just too compli…
And the side benefit is that we could summarily execute one every once in a while for failing to write secure code.
Re: 1k Data Breaches Later, the Disclosure Lag Is Worse
#95Earlier quoted context omitted.
Is the alternative just accepting that my data is out there? Even if I never used any online service, there are databases out there with my information anyway. Just figure anything online that you aren't securing yourself is compromised. Minimize the effect that has on your life. Identify theft is annoying, but it rarely has severe effects. You will have to go out of your way to be truly anonymous online, and it migh…
> Identify theft is annoying, but it rarely has severe effects. I disagree. It has already severe effects. - The fact we are facing so many data leaks made easy for malicious agent to cross and mix data sources and setup much more evolved and convincing scam scheme. It is now trivial to get name, address, birthday and phone number from a data leak and crossed check that with the login id (email) used for lets say, a…
None of these things have historically been considered private information. There's zero reason that knowledge of any or all of this should be considered adequate or even relevant to proving identity.
Re: 1k Data Breaches Later, the Disclosure Lag Is Worse
#96So at the risk of sounding incredibly apathetic toward something that I'm sure is probably a massive headache for some people somewhere... I'm a millennial and I've been told probably hundreds of times by this point in my life that my data has been breached. Not a single one of those times was there a) anything truly actionable for me to do about it[0] or b) a single negative impact to my actual life. In anyway. At a…
From a personal example, about ten years ago, my tax return was rejected by the IRS. It turned out someone stole my identity which had been leaked/ breached multiple times. At that time it was trivial to file the paperwork and get the tax return sent to someone else.
Re: 1k Data Breaches Later, the Disclosure Lag Is Worse
#97Earlier quoted context omitted.
Because nothing bad happened to you, therefore nothing bad happens?
I see your reductio ad absurdum and counter you with its exact inverse: Because something bad has happened at some point to someone somewhere, you personally must take precautions against it happening to you? Do you intend to modify your behavior, spending habits, or thought patterns to reduce the risk of catching mad cow disease? Oh, no? So you're saying mad cow disease doesn't exist? But mad cow disease has a docum…
Well, yes, in the sense I vote for rational politicians rather than raving single issue lunatics.
The problem here is you latch on to the most absurd example, where the actual farmers raising cattle are the ones expected to avoid mad cow disease because there is an actual cost to them (slaughtering their entire herd). The analogy here would be businesses having to protect their customers data or suffer consequences, which they generally don't.
Now, if you're a deer hunter the responsibility now returns to you. If you shoot some janky ass deer and eat it you might find your brain full of holes in a decade. Again, the analogy here would be using some sketch ass card reader, or hell, using an ATM in a part of town where you get mugged.
Re: 1k Data Breaches Later, the Disclosure Lag Is Worse
#98So at the risk of sounding incredibly apathetic toward something that I'm sure is probably a massive headache for some people somewhere... I'm a millennial and I've been told probably hundreds of times by this point in my life that my data has been breached. Not a single one of those times was there a) anything truly actionable for me to do about it[0] or b) a single negative impact to my actual life. In anyway. At a…
Probably not, because most of us are boring. Most of us don't have stalkers. Most of us don't have government clearances. Most of us aren't politically adjacent, significant, or know someone who is. Most of us are not wealthy. Most of us will not be a target by the relatively small pool of humans who could actually do anything with that data.
I might have a few chains where I do connect to someone important (degrees of connection to Kevin Bacon), but that isn't directly useful here.
The point is it's still private information and it must be protected, if only out of common sense or respect for your fellow humans. We don't need damages to defend this point.
Re: 1k Data Breaches Later, the Disclosure Lag Is Worse
#99Earlier quoted context omitted.
I see your reductio ad absurdum and counter you with its exact inverse: Because something bad has happened at some point to someone somewhere, you personally must take precautions against it happening to you? Do you intend to modify your behavior, spending habits, or thought patterns to reduce the risk of catching mad cow disease? Oh, no? So you're saying mad cow disease doesn't exist? But mad cow disease has a docum…
> you personally must take precautions against it happening to you? Well, yes, in the sense I vote for rational politicians rather than raving single issue lunatics. The problem here is you latch on to the most absurd example, where the actual farmers raising cattle are the ones expected to avoid mad cow disease because there is an actual cost to them (slaughtering their entire herd). The analogy here would be busine…
Re: 1k Data Breaches Later, the Disclosure Lag Is Worse
#100So at the risk of sounding incredibly apathetic toward something that I'm sure is probably a massive headache for some people somewhere... I'm a millennial and I've been told probably hundreds of times by this point in my life that my data has been breached. Not a single one of those times was there a) anything truly actionable for me to do about it[0] or b) a single negative impact to my actual life. In anyway. At a…
My wife has had someone rent an apartment in Oakland and open bank accounts with her name and social. Other than getting the bank accounts cancelled, and locking credit, there's nothing to do. The apartment management said they weren't able to evict based on stolen identity; and Oakland PD did nothing. Reporting identity theft to the FTC like they want you to do is a joke.
Unfortunately, the Oakland address has been showing up in KYC questionaires so it's probably in some minor credit bureau file as true.
Thankfully AMEX called her to notify when the fraudster tried to open a new AMEX with the wrong address.
There's no accountability for the people that collect this data and allow it to be copied. There's no accountability for those who use it for fraud. There's no accountability when credit bureaux distribute inaccurate data. It's a big mess.
Thankfully, most of the haveibeenpwned breaches I'm involved in are like name and email which big deal. But when at&t allowed their records to be copied, someone tried to open a bank of america account with my info. At&t didn't really need my ssn, but they required it as a condition of service, so they had data people wanted.