120M American Households Exposed In 'Massive' ConsumerView Database Leak
forbes.com
forbes.com
Maybe the solution is a data tax. You pay a set amount every year for every piece of personal data you have. If you buy personal data from another company, you still have to pay the tax for the data you acquired.
If you have a breach of data, your tax goes up for a period of 10 years.
In addition, every piece of personal data needs to have provenance which must be tracked. There must be a way to track from when a consumer input the data all the way through. Fraud in regards to this provenance is punishable by jail time. If you have data that does not have provenance, the company will be severely fined and people will go to jail. In the event of any data breach, not only will the company that had the breach be taxed extra, all companies that provided the data to the company (which is in the provenance information for the data) that had the breach will also be punished with increased data taxes.
EDIT:
In addition, maybe require annual personal data reports. The reports should contain
Amount of personal data.
Amount of personal data last year.
Data breaches.
Amount of personal data acquired directly from consumers.
Amount of personal data purchased and from whom at what prices.
Amount of personal data sold and to whom for what price.
This will be a filing to a government agency every year on penalty of perjury and be signed by all the board members and the c-suite. This will be publicly made available by the government. That way people can see what is happening with their data, and who is profiting off their data.
The financial math has to clearly be on the side of it being more profitable to practice proactive security.
Why not just liability for lost data? Companies could then choose to hold the risk themselves or field it out to insurers.
It would be nice to require insurance or a bond to hold personal data so a company can't just disappear when data is lost.
This is exactly what I mean when I say that, if you want to see real corruption, just take a look at regular small businesses around you.
If this is possible without insurance then it’s possible with, and every insurance company will mandate the structure to limit payouts. Mandating insurance simple entrenches the insurers. Why, for instance, would you want to require Apple purchase insurance against its users’ data?
Side note: beneficial ownership [1] and affiliate definitions [2] are useful for such cases.
[1] https://www.investopedia.com/terms/b/beneficialowner.asp
[2] http://rule144opinion.blogspot.com/2014/02/rule-144-are-you-...
You can't limit insurance payouts this way, because the entity has to carry the insurance. You only limit the exposure of the larger entity after the assets of the liable entity, including any insurance coverage, are exhausted. But the more the mandatory insurance level is, the less likely spinning off to protect the parent is to ever be valuable, and it never protects the insurer, so they won't mandate it.
Of course, that's all irrelevant unless there's a significant change in how the law treats data security.
Risks (all kinds, not just technical) can be accepted, ignored, transferred and mitigated so it is important to have this option.
Its still not a great option for anyone involved as it is hard to price and last I checked had pretty low ceiling on payouts.
What would the actuarial standards be for something like that?
In Europe, especially with the upcoming GDPR laws, data is seen as a liability by many companies.
Data being a liability just means that companies need to think twice before storing it - if the data is sufficiently valuable, companies will still store it, but they have to manage it properly and mitigate risks since penalties are harsh.
Storing data "just because you can" will no longer be worth it, and rightly so, given the risk.
Also have the fine scale exponentially by data items.... data set of 100 people with 2 items (name and email = $400 total or ($2x$2=$4 per user x 100 users)).
Data set with 1 million users and 10 fields per user would be $1B and $1,024 paid to each person...
Then make companies bond their liability - with recourse against anyone up the chain of title if the data was purchased...
Perhaps a bit draconian...
Observations I make are mine, if I observe you it's my observation.
I can tell stories about my observations, but if I make public statements about you that are false, that's a tort.
Your security clearance report stolen by the Chineese from the US government OPM database[1]. This could be a real problem for you. Information anyone can get by paying for it? This would not be a problem if credit fraud and credit reports were not such a big problem.
[1] https://www.nytimes.com/2015/06/05/us/breach-in-a-federal-co...
Coincidentally, we don't have the same types of mass identity theft issues that USA has.
I was specifically giving an example of why your observations don't automatically mean you have ownership today. I'm personally in favour of laws that ensure such observations are more explicitly owned by the observee in corporate scenarios.
Credit reporting and debt is a dumpster fire that needs to be rebuilt from scratch.
We need a new system where knowing the right pieces of information does not allow you to buy a car in someone else's name.
Identity is information. Ownership as a coherent social process is contingent on shared information.
You do know it is impossible thwart all data breaches right? You can have the most sophisticated security system created and Zero-day attacks are still bound to occur. Data breaches occur without the companies themselves even knowing they took place... Geniuses are on the offensive side, if they want in, they will get in. No company in the right mind would agree to pay a tax when the inevitable happens. Just my 0.02
As RcouF1uZ4gsC's proposal contains measures to be taken when it happens, I strongly suspect that he does, in fact, know that.
> Zero-day attacks are still bound to occur... Geniuses are on the offensive side.
Most of the breaches have required neither of these. The goal is to improve the practice of security to the point where the only successful attacks would require both.
> No company in the right mind would agree to pay a tax when the inevitable happens.
You have a very unconventional idea of how companies generally operate.
His proposals imply that he does not in fact realize that zero-day attacks occur. Negligence is one thing, but having state of the art security systems and still being punished for a breach is another thing. A state sponsored group with enough time and money can repeatedly infiltrate a system. A tax certainly wont solve the problem
If your business is such that a tax penalty on a breach would make you no longer able to afford to do business, then you have two options: 1) don't store the data in the first place - your risk no goes to 0 2) scrap your business plan as the cost of holding the data given the impossibility of preventing every breach is greater than the economic value it would generate
Today you don't have to really think about what the cost of losing the data is because your portion of it is 0. That's stupid. It's like every startup deciding to include a new type of coffee machine that includes a small nuclear reactor - sure, we can't prevent all possible disaster scenarios, but the marketing people and data people REALLY LIKE having this type of coffee available, and the government isn't giving us any reason NOT to have it, so why not?!
So if a tax either makes you put money aside to account for the risk, or shuts down a bunch of frivolous examples of personal data collection, it's solved a huge part of the problem.
False. No system, no breach. No data stored, no possibility to lose it. Accept the liability for having the data or don't have it.
When he started there, as bottom level IT support, he had access to everything. Admin passwords, doctor's passwords, he could write prescriptions and put a doctor's name on it. He could order anything and everything, and send it anywhere. He could read your medical files, if you were a patient there at any time. There were no restrictions, only some logging.
The place is only >>this week<< securing the network, because the last security guy quit and a new guy started.
I don't know what it's like in the US, but where he is there should be regular audits and criminal negligence charges for this kind of thing.
I know, networks change everything. But inside a secure facility its often (always) the case that personal integrity (and maybe some audits) is used to ensure correctness most of the time.
Somebody working in a hospital could steal prescriptions off of patient's tables, could lift wallets and purses, heck could even take a knife and attack people. But instead of hobbling everybody and locking everything up, we instead trust folks. And take action when somebody un-trustworthy violates that.
First, "impossible" is taking the argument to the extreme. Second, the insecure network OP described is negligence. Perhaps they were even reckless. That's not a new concept.
The solution: lawsuits. The laws need to be relaxed where if a company leaks data, we are entitled to damages. Just like if someone assaults you on the street you are entitled to damages.
The most famous case is McDonald's. When their hot coffee scalded a woman, she was awarded damages. Suddenly, everyone food serving establishment too care to make sure the temperature was right, printed warning labels, and told customers to be careful...it's hot.
Pretty sure if some of these companies get stiffed with huge fines, everyone will take notice and clean up their act.
> Summary This whole post is about giving control of data back to the rightful owners and minimising the impact on them when a breach occurs. This is equal parts a fundamentally simple objective to achieve and one that is enormously difficult. It's simple not to request that someone provides their date of birth to a cat forum; neither the site nor the user themselves lose anything by not collecting this data. Yet it remains a difficult objective because not only do so many services continue to view our data as an asset, they never expect to be the victim of a data breach which then turns that data into a liability.
[1] https://www.troyhunt.com/fixing-data-breaches-part-2-data-ow...
What an excellent insight. You changed my conception of the problem. Thanks!
This gets complicated when the interactions themselves are complex and indirect. I'm looking at some general notion of complexity, in terms of scale, structure, and depth, but one general notion I'm working toward is that of intermediation -- the distance, think of it as a depth in nodes -- between the observer and observed. The shallower that depth, the simpler the interaction, the less intermediated the relationship.
Node complexity also matters. Jumping through dumb pipes is one thing, passing through complex relays another. The children's game of "telephone" exemplifies this -- contrast that to simply passing a note down the chain. The note (written on paper) is physically transported. The verbal message is passed from one person to the next.
(We're ... starting to see bits of this emerge as our comms networks become more complicated, and powerful in processing capabilities.)
Back to value/liability: any given opportunity or action has some positive potential and some negative one. We tend to pursue actions with a high probability of success, and where negative consequences are either rare, or, and this is problematic: vaguely defined or difficult to articulate. That is, there's a risk, but you don't know how big that risk is. And in cases it's huge: tetraethyl lead, asbestos, tobacco, CFCs, fossil hydrocarbons.
But it takes years or decades to establish the risk. And there's a strong motivation to denying it or suppressing the message.
Data falls into that class of goods (or bads).
I hear things about how the data is the 'real' product, and how it's mostly used just to train algorithms that are then used to sell ads. More data, better training algos, better ad targeting, more money spent.
But that data can be remarkably easy to spoof and goof with. Garbage in = garbage out. That would be a liability to the algos, the real weak links.
So, I think that a tax is not the best idea.
Rather, the data needs to be made into 'garbage'. Yes, an obfuscation race will ensue, but there is always more trash than gold, more noise than signal.
If we really want to change the game, we need to have easy to use apps that will throw a minute amount of static on the instagram photos, that will put just a bit of background on the phone calls, and that will throw a small bit of random words into the emails.
Yes, PGP does this already, but we all know PGP is not easy to use (by design?).
We don't need 'total' security and safety, just a bit of fuzz will screw with the algos enough (thus the start of the obfuscation race/war)
[0] https://www.schneier.com/blog/archives/2016/03/data_is_a_tox...
Either it's private, and then NOBODY has it (i.e. stored on local machines, paper or just memorized), or it's not private, and then it's publicly accessible on a website, or it's confidential and then it's either service-specific data that is deleted as soon as possible (e.g. web searches) or given along with a physically signed contract containing an NDA and penalties for failure to keep secret.
The best way to achieve this is to require, by law, companies to publish on the web anything they learn from customers that is either not strictly part of their interaction with the service or has been stored for more than a month.
This will result in companies no longer asking for things that customers don't want to be public, and deleting interaction data unless the customer wants it kept and published.
Also it will result in a reduction of Google/Facebook/etc.'s monopoly powers since they will have a reduced monopoly on customer data.
We could start by repealing that nonsense.
Can we change this to link to the Forbes article referenced in the linked one? It goes into substantially more detail, including reconciling the researcher's claim with Experian's. https://www.forbes.com/sites/thomasbrewster/2017/12/19/120m-...
edit: didn't even notice the substantially more click-baity headline "Every single American household" vs. "120 million American households".
The Forbes article says that the US is one of the few countries that does not have laws requiring the protection of such information. But let me ask: what would a new law change about this particular incident?
Unless the law specifically requires that someone go to jail, then the law will make no difference. The owner of the data didn't mean to expose it all. It just happened.
We already know that when companies flout the laws, no person goes to jail. The company pays a fine and everyone continues doing what they were doing. The punishment is irrelevant. With this kind of repercussions, Laws are ineffective.
1. This isn't an announcement that our details have been leaked, so much as a reminder that our details are now and will perpetually be leaked, in one form or another by an externalized party.
2. Databases mapping all American households exist.
And they can be pretty comprehensive. Short anecdote but the last time I moved, and before I had updated any address information on my accounts/ID, the first piece of non-forwarded mail I received addressed to me was a credit card offer from AMEX. I still have absolutely no clue how they knew where exactly to send it to me.
That said the cynic in me won't allow the positive optimist within me to win this one. While I do believe there to be many wonderful postal workers I am going to assume that corporate greed is winning out over the kindness and caring of the human heart in this specific situation :(
Compared to Equifax, this is nothing. Why? Because this data can't be used for identity theft, and it's been widely available in downloadable, fully portable form for 2 decades.
My understanding is the information was readily available to businesses from other sources. It just popped up on people's radar because Lotus was such a high profile company at the time.
If you want to be mad, be mad about that, not the fact that somebody applied a publicly readable bucket policy to some data they paid tens of thousands of dollars for.
Well said.
It has more detailed information about the dataset.
The only “data” any organization should receive is an encrypted blob that is constructed using the key of the person who owns the data and the key of the entity that was directly given the data. Furthermore, the encoded blob should have a date of encoding and a duration of validity. In other words: “I, John Q. Public, authorize You, DataLosingMegaCorp, Inc., to receive This Blob, which is valid for 6 months or until either party revokes the key”.
Other public systems in society should be upgraded to require additional layers of security. Want to send commercial snail mail to my home address? Great: please provide the postal service with a one-time authorization code that you received from me (after all, you are using an address given to you by me and not bought from somebody else, right?).
Another nice feature would be for data to include bank deposit info for the data owner and bank withdrawl info for the data-receiving entity, where EVERY SINGLE TIME your data is decrypted you receive a cash deposit from the data-receiving entity. And make it sting, a lot: I want it to cost real dollars to use data (and of course, I can still revoke my key at any time if you still manage to do something stupid with my data).
1. Credit applicants, who release all-or-none of their credit report information, and can see it at any point in time. Means it needs to be stored encrypted with their public key.
2. Creditors, who can add, edit, and remove information from someone's credit report. Presumably this adds a way to verify that the addition/edit/deletion is from them and not some other party (sign with private key).
3. Other creditors, who can - with approval - view an applicant's credit report and know it is complete and up-to-date.
4. Arbitrator, who resolves disputes and deletes or corrects inaccurate information from reports.
And presumably you'd want some sort of additional safety mechanism to prevent dissemination of the unencrypted result? Like, if you gave an organization an unlock code, maybe it's possible to arrange things such that that organization's private key is able to create legit-looking data, so nobody else could trust third-party sharing of credit report data?
And if the interaction does also belong to them, why don't I get access to their data?
I use S3 and I have noticed that by default it's locked down and secure and in order for it to be open you have to open it for the public. Maybe AWS could improve the way it can secure the S3 buckets by making it easier to whitelist access by IPs or some variant to this. Although I personally find it fairly straight forward to use in the projects I work on but it appears it may be difficult and my developers just open it up to the public so their apps can easily access it.
I would like to see more sense of responsibility from AWS for these leaks rather than blaming the users.
It’s bad usability.
Maybe we can start holding companies accountable?
This isn't someone hacked into their system. This is just being negligent.
Also what I don't understand is do AWS storage buckets have directory listing enabled by default? How can a third party guess the URL, unless it is something obvious like /backup.csv.
How is it okay that this information is even available from Experian in the first place?
I don't think anyone opted in to this. And I don't think there is any obvious way to opt out.
And Experian is not just some data tracking company watching your behavior on a website; they're supposed to be protecting our credit system. Do they obtain some of this information through special privileges because they're a pseudo-official credit score agency? If so, is this grounds for a class action lawsuit?
(As others have argued, this data is legally available through Experian, it just normally isn't free. https://www.experian.com/assets/dataselect/brochures/consume...)
"Blue Sky Boomers," "Significant Singles," "Pastoral Pride" (subgroups: "True Grit Americans," "Countrified Pragmatics," "Rural Southern Bliss," "Touch of Tradition").
At least that's how I originally imagined this Internet thing to play out as, too bad it took the exact opposite direction.
Not to go all Godwin but when the parent mentioned "something really bad and really large scale" my mind immediately went to the holocaust and other genocides. Can you imagine a totalitarian regime having access to this type of tracking data? It's pretty chilling.
My initial thought was "good luck with that", but maybe, in an ironic sort of way, these breaches are going to force that to happen.
"You say someone opened a credit card in my name, and you want me to pay for what they charged? What data did they use to open the account? Um, yeah, have you heard about the Experian breach? So you know that the entire internet has that data about me? Yeah, good luck collecting, suckers."
If that holds up in court (at not too great expense for the party being sued to pay the debt that isn't theirs), then financial institutions (all of them) are going to learn very quickly not to rely on that information for anything.
They don't have to collect, they just ruin your credit and make your life difficult. That's what they do now.
There are options that have been tried, they're just difficult for USA to adopt because of reasons mostly tied to the weirdness of identity and IDs in USA.
that should align some incentives and get you a good way along. It will incentivise proper security measures, and help quench the thirst for data in the first place.
This is their white paper: http://web.media.mit.edu/~guyzys/data/ZNP15.pdf
Forgetting for a moment the fact that with even a few data points on someone it is getting easier and easier to cross reference other data sources and de-anonymize almost anything - but address and phone numbers are so directly and easily tied to real people this seems like a massive oversight in current regulations on "personal identifying information".
Where goes this data? Who will use this information?
They'll probably stop doing it after they kick down the door of a day-care in a rich neighborhood and only find hot glue guns and those beads you fuse with an iron.
¯\_(ツ)_/¯
LEAK-DISCUSS-FORGET-SUFFER-REPEAT?
This is hard to believe. S3 bucket names are unique. I can't make a bucket named `bucket`; I'd have to call it `dashkb-bucket` or something (a common convention is to prefix with your company's domain)... anyway...
The point is: for the bucket to be named `bucket` Alteryx must have had one of the very first AWS accounts, and from there isn't it reasonable to assume this bucket has been exposed for many years?
It is saying that the data was in a thing that Amazon Web Services provides, which AWS calls a "bucket".
Most people who are not web developers don’t even know Amazon Web Services is a thing, much less the cute names of any of their services.