Data is a Toxic Asset
schneier.com
schneier.com
This seems to me the wrong way to solve the problem. The crazy thing about credit cards, social security numbers, and bank account numbers is that these numbers are supposed to be kept secret and private, and yet you need to constantly give them out to people. Everyone you write a check to gets your bank account number, every place you buy from gets a credit card number. This is insane.
The right way to solve this is that Visa and Master Card need to develop a standard to make super easy to generate a unique payment number everytime you make an online purchase. Then that should be built in as a browser extension or component. So I browse to a site, click to pay with my Visa card, and Visa automatically generates a unique code for that site and fills it in on the form.
Also it is insane that someone can steal my identity by simply knowing my social security card. The right way to solve this would be to have an indentity provider that has a short 10 second video of myself on file. Then, when I want to sign up for a credit card or bank account, I take a 10 second video of myself using my cell phone, granting approval to open the account. A staffer at the credit card company then compares the video with the video on file with the identity provider, and verifies that it matches. The identify provider also sends a message to an email address or mobile number on file, so that I am alerted that someone is opening an account in my name. Using these two simple safe guards, identity theft would be much, much harder. A video recording of a person is very hard to fake, much harder to fake than a signature.
A final key innovation would be if email providers would make it super-easy to generate aliases per site. I do this myself manually with fastmail, but if there was a simple browser extension that would automatically create an alias and fill in a form, that would be great, because I could have a unique address that all funnels into one place, for everything I sign up to.
What should those of us without smartphones do? Not to mention that this seems trivial, if not easier to break. I can find the target on Facebook and use a faceswap program to generate a video that looks good enough so that the $9.50/hr worker spending all day comparing faces, who doesn't quite care enough, accepts the video.
Ok, I know US citizens are not automatically given ID cards, so if everybody takes the SSN you give them at face value, I get that.
I don't understand the bank account especially. Like I have some automatically deducted monthly payments, but I remember I needed to specifically authorize the receiving account to be able to ask for the money with my bank.
With cards,the standards are starting to get there, i.e: I can enable with my bank that every time I use the card for internet payment, I need to confirm my identity with code they send me in sms. As far as I know, I could ask for different second factor of authentification, I know my dad has standard rsa token.
Unfortunately I had problem using this with some foreign site (I think it was Amazon?), so I had to disable it. I live in Czech Republic.
For SSN, if you have good credit, you a SSN and a name is basically all that's needed to open a new account connected to your general credit record. If the account was opened in your name without your consent, it's a lot of work to get it disassociated from you.
For bank account numbers, most payments are processed through the 'automated clearing house', which is fancy check clearing. In the old days, maybe your bank would look at the check presented and return it without payment if they could tell it wasn't legitimate / your signature wasn't right. With an electronic withdrawl, there's not really any information provided to them to check anything.
It's a constant pain that there isn't a common standard scripting language for finances so I can automate this stuff sensibly.
You could still retrieve some identifying information through their API, but if you keep your account credentials somewhere separate from your database it's less likely for an attacker to get both.
So at the end of the day there is a lot of things which make data toxic easily avoidable, and it takes people at the company willing to invest in making the data "non-toxic" and to some extent non-useful to people outside the company.
It's beyond this. MOST email address forms won't accept a '+'. I had to change the extension character to '_' on my server because it's the only non-alphabetic character that everybody seems to accept.
That said, many banks - including in the US - can already generate single-use virtual CC numbers.
Blur[0] from Abine has this in their premium version. I have used it, and overall it worked well, but I had some password syncing issues and stopped using it.
A final key innovation would be if email providers would make it super-easy to generate aliases per site. I do this myself manually with fastmail, but if there was a simple browser extension that would automatically create an alias and fill in a form, that would be great, because I could have a unique address that all funnels into one place, for everything I sign up to.
Something like this can be done on FastMail using a catchall alias[1], but it requires a custom domain, and the domain could be used to link all the accounts to you.
I'm experimenting with it, but what happens when I forget a password and the email I used to sign up for it? A password manager is an option for that, but they have their own problems.
Edit: FastMail also has subdomain addressing[2]. I believe it works with all of the FastMail provided domains.
[0] https://www.abine.com/index.html [1] https://www.fastmail.com/help/receive/alias-catchall.html [2] https://www.fastmail.com/help/receive/addressing.html
It's infuriating there's any chance for fraud at all when it seems like a solveable problem in 2015
Of course, then i go to the US and any random hobo on the street can charge me with just the card number and a scribble. The problem isn't that credit card companies don't know how to get rid of card fraud, it's that their customers like the convenience too much and won't let them do it.
The same thing for identity theft. In my country opening a bank account or getting a loan requires an id card, which is government issued and contains a digital certificate protected by a personal pin. Unless someone steals that card and knows your pin, they can't steal your identity.
These are easily solved problems. The reason they're not solved in the US is because the people won't allow them to be, or at least banks and government perceive it as such.
There was a mechanism from the 1990s to do online payments without giving the merchant a reusable secret identifier.
https://en.wikipedia.org/wiki/Secure_Electronic_Transaction
It's too bad that something like that didn't become widespread sooner, because it could have drastically cut down on credit card fraud.
So something like, a public key with a private key that only you own? ;)
Android Pay, that succeeded Google Wallet, uses such tokens.
I thought Google Wallet was available in many platforms, e.g. even in my browser which may or may not run Android.
So many regulatory bodies and laws requiring companies to keep all kinds of data for all kinds of reasons for a wide variety of periods, so that simply having a policy to "store all the things" is way, way simpler to implement than to carefully study and adhere to each individual rule.
Nothing really new here, even before cheap storage and ubiquitous computers, companies kept boxes and boxes of all the paperwork ever, just in case some audit may require them to dig it up. Only physical limitations sometimes caused them to throw away stuff labeled "a decade ago", and today there simply is more data and zero incentive to destroy it.
https://www.gov.uk/guidance/register-and-use-the-vat-mini-on...
For example, while banks are required to keep tons of data for legal reason, the ones I've worked with have procedures where, for example, tellers are required to shred everything and send it for incineration. Then, the digital copies, once they can only be required if theres legal compulsion going on (ie after x number of years), are transfered by batch jobs which encrypt everything with a key generated by a CA that is offline most of the time, to a tape library which is only online for batch writes and can only be brought online manually by physically going into the data center. Then, after a little more time, but still within legally required reporting periods, the tapes are moved into a warehouse which very much resembles a bank vault.
And as soon as theres a reason that the data isnt mandatorily kept, the tapes are destroyed.
Honestly the security around those tapes is higher than bricks of cash, and they're destroyed even more readily.
Out of 100 average web developers only a handful take security into account during design and fewer still think and work through what's necessary to keep anything safe at all.
It's no wonder that popping servers is so trivial and even high value targets with dedicated security teams and constant proactive threat response get pw0nd daily.
This is certainly one of the reasons I've become more aware recently of the amount of data certain companies have on me. Data breaches have the potential to be catastrophic and very few people are looking out for my best interests.
You want security, then hire a security expert to oversee the development and ensure security. Pay him or her 60,000-70,000 to ensure that. Otherwise forget about it, not going to happen. Your developer is already too busy as he or she is.
?por que no los dos? I agree that the stack is crazy-huge these days, and shifting too much to solidly learn everything. We should still expect devs to try and integrate security through the entire thing though
Just like we do QA you need security reviews that follow QA, a security team needs to review the code for just that security. Some of it can be automated, other stuff needs to be carefully studied. You can expect to add 20-30% to the final cost to account for something like this.
https://www.owasp.org/index.php/Top_10_2013-Top_10 and that's only Web security.
I think stating things like "don't trust user input" risks things like https://kivikakk.ee/cryptography/2016/02/20/breaking-homegro... happening.
Security is hard, programming is hard, we should all get better at both.
Your data is over the place, in many hands. While it should be protected, it should also be much harder to use it to pretend to be you.
You should be able to set up 0 or 1 or 2 step authentication for trivial purchases, 3 step for larger purchases or accessing credit, or even 4 step authentication for things like buying a car or house.
Some steps could be approval require or denial required. Its enough to be able to deny the purchase of a latte, but you might want to always have to approve spending thousands of dollars.
And we need to be able to set up new kinds of authentication steps, like fingerprints or the approval of one or more trusted relatives for an older person or child. Or even use a notary public. And you might have to use more of these if you are from home.
And none of this should be manditory, but there should be sensible defaults that individuals can change. AFTER being well authenticated, of course :-)
If we raise the difficulty level of stealing MOST people's identity, this will largely solve this problem, especially for those most wanting to solve it.
That's not some shocking new thing. Forums and other such sites have been letting people sign up with no more than an email address and password for years. And the payment stuff on these sites and services could easily go through PayPal or some other third party provider (who's likely got a much more secure system setup than you).
But no, a lot of sites and companies and services seem to be all 'let's store everything about everyone, and then wonder why it causes a meltdown when the site gets hacked and said data leaked all over the internet'.
He's wrong that there is evidence more data isn't better. While there are indications of this for advertising, it is definitely not the case for financial data.
And the other subtlety is that lots of low quality data is indeed useless, but small sums of high value data can do a lot. That high value data is what people are looking to steal. Having a little bit of user financial traction data, for example, is incredibly powerful. Much more so than, say, cross-website shared cookies or Amazon referral patterns.
And there is a whole class of data that has value proportional to the total sum of it you possess. A good example of that is surveillance data. Ubiquitous video coverage of an environment is much more useful (to both machines and humans) than partial coverage.
That way when there's a breach, it's impractical for the attackers to exfiltrate the complete dataset because the target probably represents a non-trivial percentage of the world's storage capacity.
The attackers can filter the data, but surely someone's going to notice ten thousand machines whirring away at odd MapReduce queries.
The rest of the data is not that valuable in comparison.
I'm not sure what that is exactly, but it sounds really sensitive. :)
In all seriousness, while the release of banking and identity information is certainly bad, I'd argue the contents of private communications or browsing/search history are potentially far more damaging for a lot of people. In order to include that in your hypothetical, it'd require either a lot of filtering or the 6TB number would balloon quite a bit.
I was poking fun at "security" questions.
These bits of data are gatekeepers, if I have your aol account password, I get all of those for free.
(So I think we're in agreement, my SSN isn't controversial to my friends, employer, family, news, etc, but most people have probably had conversations or searches that could look really bad)