What I'm Telling US Congress about Data Breaches
troyhunt.com
troyhunt.com
Let's talk about how the ubiquitous use of SSN and credit reports puts a massively unfair burden on every US citizen.
Right now, it's all on me. I need to safeguard everything related to my government-issued nine digit ID that I never asked for - yet is somehow accepted as my financial identity, well beyond its intended scope.
If I fail to do so, or if I fail to aggressively identify fraudulent use of it by monitoring reports from 3-4 different agencies, it's on me. It's my credit that's screwed.
It's hard to emphasize enough how unreasonable that is. This isn't a house or other peace of real property that's in my control - it's 4 bytes of data that is assigned to me, but that I fundamentally have no control over.
In spite of that, I am accountable for any and all uses of that data. It's hours of my life each time a breach occurs - more if it's actually misused. The assumption of 'bad credit risk unless and until you convince the reporting agencies that fraud has happened' is a fundamentally flawed one.
I can't opt out. I can only keep spending my time and money to play the game - because it's the only one in town.
My identity wasn't stolen! You gave a loan/credit card/whatever to someone and didn't verify who they were. How is your organization not doing the proper work a "theft" of my identity? I'm not involved and I don't want to be!
Example: Someone opens a bank account using your information. That's fraud. Someone lied to the bank, and the bank believed them. That's the bank's problem. But by pointing at you and saying "Your identity was stolen" (using the term "stolen" to make it seem like this is similar to the theft of a physical object), it suddenly seems like it's your problem.
I agree that it's misleading, but have to concede that whoever first came up with that term must have been an expert in framing and spin. There are few words that so effectively distort the discussion as "identity theft".
But it is the bank, it should be! When a bank is robbed, its clients aren't the victims. The bank is. The clients aren't giving money to the bank for nothing in return; what they get in return is assurance of safety and availability (otherwise, that would be a loan, not a deposit). Spinning the failure to deliver on that obligation as the client's problem is indeed great PR work.
Via https://en.wiktionary.org/wiki/fraud: The crime of stealing or otherwise illegally obtaining money by use of deception tactics.
Legally speaking
> Fraud must be proved by showing that the defendant's actions involved five separate elements:
> (1) a false statement of a material fact ["I am John Doe"],
> (2) knowledge on the part of the defendant that the statement is untrue [they are not John Doe],
> (3) intent on the part of the defendant to deceive the alleged victim [they want money],
> (4) justifiable reliance by the alleged victim on the statement [bank credit approves access based on identity], and
> (5) injury to the alleged victim as a result [bank loses customer money].
[1]previous HN comment - https://news.ycombinator.com/item?id=15657887
I'd like to see a startup or non-profit that automates libel civil lawsuits against the reporting agencies. At least then maybe we'd get some responsibility from them.
But if some economy of scale could be provided in filing these lawsuits, like those boilerplate will in a box products, then the business of credit reporting in its current form may be made non-viable.
I'll have a stab at coining the new word.
The concept is referring to attempted or successful deceit of the bank. Let's take the Latin word for deceit, fraudem, and modernize it so it won't sound so quaint. I think that "fraud" would do.
Impersonation.
What's worse is when government agencies themselves use it, knowing full well the number of recent data breaches. I recently went to the DMV in Colorado to obtain a driver's license (since I moved here from another state). They turned me away because I didn't have my physical social security card with me. I did have my U.S. Passport, which has far more security than a blue card with a number printed on the front of it. And sadly the Colorado DMVs will continue using SSN to identify people, even after hearing about the Equifax breach.
Honestly, a social security card may as well be a post-it-note with the number written in crayon or finger paint.
Usually, you get loans from your bank - and since you have a preexisting relationship and secure authentication methods, you generally can do it remotely. However, establishing your identity to a new organization usually requires a visit in person and verifying official ID; the lenders who don't require this (e.g. various companies offering small payday loans) have a much higher rate of fraud and thus charge high interest rates to cover those risks. A popular measure that I've seen used is that they require you to wire them 1 cent from the account to which they'll pay out the loan, which can remotely show that you most likely own that account.
>Knowledge-based authentication (KBA) is predicated on the assumption that an individual holds certain knowledge that can be used to prove their identity. It’s assumed that this knowledge is either private or not broadly known thus if the individual can correctly relay it then, with a high degree of confidence, they can prove their identity. KBA is typically dependent on either static or dynamic “secrets” with the former being the immutable data attributes mentioned earlier (date of birth, mother’s maiden name, etc.) and the latter being mutable such as a password.
In France, private credit bureaus don't exist. It's up to banks to track these things.
The country seems to work fine.
> The country seems to work fine.
I hope you realize the joy you have brought to many people's day by writing this.
I would pay a large sum of money to see all of the replies that will go unwritten.
Is the same type of credit with the same interest rates available just as easily in France as in the US?
Banks will usually not give you an account and shops won't give you credit if your rating is bad. For example, you are so late to pay your bills that the creditor has involved collection agencies or the courts to get their money.
Landlords will more often than not demand a document from the Schufa (supplied at your own expense) to consider you eligible for renting a flat or a house.
edit: grammar
Not just landlords, employers do Schufa checks too, same for phone/mobile contracts, cable TV, and for what its worth even power/gas companies. The latter is really bad because it locks poor people into the highly expensive "Grundversorgung" tarriff (regulated, the local utility MUST offer it) by the local utility, thus taking away even more of their money.
https://news.ycombinator.com/item?id=15751344
Some of the replies really touch upon what can go wrong with government regulation.
That said, I do really want something done about this:
> An attitude of “data maximisation” is causing services to request extensive personal information well beyond the scope of what is needed to provide that service
Stop collecting information which is not required. Most of this information ends up in some form of advertisers/advertisement in guise of creating "more engagement with users".
And FFS, at least outlaw the required arbitration BS for data breaches. Let the bond or insurer pay out when it happens, then jack up their prices on the breached company until they cry.
The Government is more guilty than any business on collecting, hoarding, and making public all kinds of personal information about you.
If the government wants to curb data breaches it needs to start cleaning its own house. 90% of "public data" should not be public at all
The downside is that the most critical components of information which tie to identity itself, are the ones that businesses most commonly need to hold to verify identity. More challenging is that without a way to modify identity data (i.e. change your SSN), the insurable risk is huge because it needs to include a discounted cost of identity monitoring forever, and the cost of the individual losses that someone might encounter for the loss of that data. Then of course, if a person's identity is compromised more than once, how do you discount the responsibility across multiple careless parties?
IMO it all comes down to never using immutable information (Name, DOB, etc) to firmly define identity online. That information should be for display purposes only. At the backend, we need an identity that is tolerant of change, and can easily be updated if it is ever lost. In reality this will probably mean that instead of an ID, we have ID probability, which would include photos, addresses, ID numbers, Credit card account access, and companies that needed to verify it would be able to evaluate how certain they were the identity was real, and to insure against mishandling of the individual components of information.
If it gets expensive enough, maybe banks and CC companies and such will finally get off their asses and fix the whole "identity theft" issue. That's a feature, not a bug.
I think the US is too allergic to anything with even a whiff of "secure national ID" for us to let the government fix it, so this is the next best (or, better, depending on your perspective) option. I frankly don't care how we do it, but it's really stupid this is still a thing people have to worry about, and making it cheaper for the banks to fix it than not to fix it seems like the most politically viable solution.
Hell, maybe they could even use a distributed ledger to do it and bring in the credit reporting agencies too.
You mean the government that spent 26 years printing "NOT FOR IDENTIFICATION" on the bottom of every social security card.
This is the elephant in the room I don't see anyone addressing, but be warned, we can see the effect caving to this model had on the journalism industry. If tech doesn't free itself from this, it will likely have similar consequences.
Of course, identity theft is a mortal wound and is hard to ignore. Casual mometization of every private action is death by 1000 cuts.
The benefits of insurers getting involved is that they can de facto mandate these kinds of security audits and practices by making insurance policies unaffordable without them. And, unlike government regulation, the requirements from insurers can evolve rapidly over time in a way that's difficult for laws to evolve. Insurers will hire security experts to advise on best practices and each have their own ideas of what security means. If a business finds a single security practice onerous, they can shop for an insurer that doesn't require it.
from https://www.troyhunt.com/im-testifying-in-front-of-congress-...:
"Troy, to your point "Data breaches can take years to discover," I think it's helpful to put in layman's terms that breaches are closer to making photocopies where there are now two people in possession rather than a theft where the owner is deprived of access. How do you detect that a document has been photocopied?"
In the final (this link):
"However, unlike a physical commodity, the trading of data breaches replicates the asset as each party retains their original version, just like making a perfectly reproduced photocopy."
:)
To expand on my point and
> We Often Don’t Know Until Years Later
You notice someone's stolen physical property from you, because you are deprived of it.
You don't notice someone's stolen digital property from you, because now there are more copies of it.
(maybe "stolen" and "property" aren't the correct terms to use for digital assets?)
Stolen is rarely the right word (that is, it's possible to steal digital assets, notably if also stealing the physical medium on which they are stored, but usually the term is used in only a loosely figurative sense), but “property” is often correct; there are all kinds of nonphysical property that share important features with physical property, and there are equally important distinctions within classes of tangible property as between tangible and intangible property.
Indeed. See, for example, https://www.stallman.org/articles/ft-response.html
He does specifically go out of his way to say, in bold and isolated text, Do keep in mind that the context here is the impact on identity verification in "a post-breach world".
I don't believe it's nearly as black-and-white as you would make it out to be. There is a middle ground where our industry has a responsibility to not only "give the facts", but also provide guidance, especially when explicitly asked for.
There isn't a damn thing wrong with being cynical. Cynicism (at whatever level) is a very valid philosophy and no one should have to apologize for having it.
http://richardbayan.typepad.com/the_cynics_sanctuary/cynicis...
Some people think motive and human nature should be viewed with rose colored glasses. Many people urging others to hold this viewpoint stand to gain by advocating it. But not me. I expected.
Back to the original off topic point. Don't apologize for being cynical. It's a mental model that is quite often accurate.
<edit because I really have to get this off my chest as it's so annoying>
Here's what I think. I think you have observed a pattern of hearings that appeared to be little more than political grandstanding. And maybe you haven't ever observed a hearing that was anything different, as in, designed to get to the bottom of something and produce results. If the above is true you understandably expect a continuation of the same pattern. Yet you feel the need to apologize for this perfectly intelligent and rational expectation. Why? Possibly because you have been conditioned against being "negative" and led to believe that cynicism is somehow evil? Well I just have to say... Fuck That! You are right from what I can see.
I'm of the opinion that the US is irretrievably lost in the hole of plutocracy / oligarchy. Recall during the election Donald Trump bragging he can buy politicians [1].
I'm finding "hero politicians" to be less and less common, and dare they raise their head, the establishment usually does everything in their power to mow the lawn. See - Bernie Sanders, alongside a couple other rare US Federal politicans, an actual good egg that appears to not be bought and paid for by corporate lobbyists.
There's lots of people trying to paint in black in white how obvious it is you can pay a politician to pass laws to protect you - we can go on for hours about Big Telecom minging about in local jurisdictions to prevent new providers, Big Oil essentially preventing a nuclear revolution in the USA, etc, but this site[2] paints a pretty clear picture in my opinion: Given that a corporation is expected to generate profit on dollars spent, why would BlueCross BlueShield and UnitedHealthcare be dumping money onto politicians? What reason could there possibly be other than to protect their profits?
I dunno man, other people are better than espousing the problem of money in politics than me, I just am cynical as hell after seeing time and time again obviously anti-WeThePeople votes bought for mere thousands.
So, to answer your question, in my un-professional opinion, the reason these hearings are good is they can inform the media and general public. They can get something on the record. We still reference hearings from decades ago - and can use that to apply pressure. "Senator, weren't you in x hearing, why then did you not do anything about y?" It can also inform the select few Hero politicians who can actually do good work for us with this new information - they're busy as fuck and this is one hell of a way to get data to them.
Ancillaries include giving new ammunition to Word Wars - various politicians can use buzzlines from the hearing to further their own goal, which might help us, might not, god only knows.
So my opinion, I'm glad these happen, but I think afterwards it'd be cool if people like Troy Hunt used their position to drum up donations to buy a couple of the politicians in the hearing, or at the very least throw more money at Twitter so that the Comcast and BroadBandForAmerica lobbyist propaganda promoted tweets can be buried under pro-WeThePeople material.
[1](https://www.washingtonpost.com/politics/trump-bragged-that-h...)
[2](https://www.opensecrets.org/lobby/issuesum.php?id=HCR&year=2...)
Troy is doing what he can to make a difference. We shouldn't have unrealistic expectations of what this can accomplish. But we should applaud the effort.
We can force companies and governments to change their approach to security. But we need to start talking about these issues outside of HN. We need to get organized. We need to force change in our own companies.
My end-game though is to become Really Goddamned Rich and start swinging my big cash dick around. I'm kind of curious why folks like Musk don't do that more often. Gates did it once and nearly irradiated an entire species of virus (polio).
EDIT: Btw, this is a great tool for pestering all your reps at once: https://democracy.io/#!/
Much better examples would be "Gender" and "telephone number".
I completely agree with the notion that data maximization (or aggregation of meta data associated with a unique ID) are the roots of many evils and risks.
Verifying if someone is legally an adult doesn't require you to know the exact age and definitely not the birthday, simply "yes" would be sufficient.
I am not saying that this is a reason that everyone uses for asking these questions obliquely. I am simply sharing a situation for which I was explicitly told that was the reasoning behind asking the question in that way.
This presentation involves a lot of complex terminology from the get go. This keeps it from engaging people's logical brains, and means that you are too easy to ignore. Our first pass at analyzing people is to figure out whether they can be safely ignored. This response is well before rational thought, and the part of our brain that decides it is unable to handle complex language. It doesn't matter how right you are, you are literally not heard.
You can't fix the document. But you'll be talking in person to lawmakers. You can address the challenge there.
Don't open with something like, Data breaches occur via a variety of different “vectors” including malicious activity by attackers exploiting vulnerabilities, misconfiguration on behalf of system owners and software products intentionally exposing data by design.
Open with something like, Anyone can steal your identity. Your wife's as well. My site shows you some of the security breaches that criminals can use to pretend to be you. Nobody knows how many more are out there.
Make it simple and straightforward. Make the threat personal. This requires their full attention to figure out what you are saying. That makes their logical brains connect.
Good luck. You have an important message and I really hope that they hear you.
On a second note, will this be the historic first time anyone says the word "Pwned" before congress?
Identity Fraud is not normally carried out using just 1 breach, so it is several breaches combined that give a criminal what they need to commit full Identity fraud.
Credit Card Fraud can almost never be traced back to a single breach.
Are you holding the company that collected the data, or the company that the data was stolen from liable, often times these are not the same entities.
I can probably come up with about 1000 other things to bring up in relation to "let the companies be liable for their own data breaches."
What would be even better is to move the lack of reporting of a breach to the criminal branch of the law.
And HIBP is an example of this attitude because it collects data dumps and then (at least) collects and retains user-submitted email addresses and a record of presence/absence of such "live" email addresses in the data dumps. This is beyond the scope of what is needed to provide the service, namely, copies of the data dumps available for download. The user need not share their search terms with any third party, such as HIBP. A means to search these dumps locally (offline) without sharing the searches with third parties such as HIBP exists. "Online tools" are vectors for gathering the sort of data that is later the subject of "data breaches". Offline tools do not suffer from this problem.
"6. Data breaches are redistributed extensively. There's an active trading scene exchanging data both for monetary gain and simply as a hobby; people collect (and thus replicate) breaches."
HIBP is collecting and thus replicating data breaches for "monetary gain" or "simply as a hobby"? Or is it something else?
As above, HIBP does not provide users with the data dumps they need to check them locally (offline) without submitting contributing more data to third parties in the process (e.g., working email addresses, associated search terms, associated originating IPs, etc.).
Further, users are not provided with transparency into what HIBP is doing i.e., what it is storing and how and where it is stored. Users cannot evaluate the security practices of HIBP as yet another online repository of sensitive user data that by virtue of its existence could be a target.
In summary, what he is not telling US Congress is that 1. "online services" or so-called "online tools", HIBP being one, are a major part of the problem and 2. there are alternative solutions, i.e., offline service and offline tools, and what HIBP provides is an excellent example of where an online service is unnecessary and is collecting large amounts of user data, unnecessarily.
Addendum: "What I'm telling you" is that I believe the problem is data collection. Any "solution" which collects data, and in this case data it is not supposed to have (e.g., a data breach), then collects more data (e.g., metadata) from users and finally asks users to trust the "new collector" is not a solution, IMO. Especially where the new collector shares no technical details about his operation (e.g. storage of user data). This practice ignores simple, obvious solutions to the problem of data collection, such as performance of tasks offline which if performed online would likely lead to the collection of user data. It reinforces the mindset that perpetuates the problem: that data collection and trusting third parties is always necessary.
you're telling us that you'd rather that HIBP act as a clearing house for credentials and user information as a result of a data breach rather than exposing a single bit of information per user ("have i been pwned?")
I, at least, completely disagree with you, regardless of Troy's motives or any "monetary gain" he receives through HIBP. Troy has been incredibly transparent, and in fact talks about this very issue on his blog https://www.troyhunt.com/here-are-all-the-reasons-i-dont-mak...