Knuddels: Chat platform must pay after hacker attack fine
tellerreport.com
tellerreport.com
Regardless, even if you disagree with the scope of the law (which I do but not the intent of course), it is a very welcoming sign to see some actual enforcement happening. An under/subjectively enforced law of this size is much worse than a reasonably enforced one.
Hash passwords, not encrypt.
An encryption is reversible, a hash result isn't.
Ugh. A credit card company...really?
"8.4 Render all passwords unreadable during transmission and storage on all system components using strong cryptography"
It's also fair to say that the next few years will be a busy time for the government agencies tasked with GDRP enforcement.
(Assuming they do it properly, which falls within the responsibility of the relevant country)
Also, the ruling mentioned a reduced fine for cooperation and quick remediation. This probably wouldn't play out so well with a bloated structure and process, as you mentioned.
What you do is have one single function create the user, pick a random password, set it in the database (which in my case uses a perfectly sensible hash) and send the user email. The cleartext password in the mail comes from the function's local string variable, not from the database.
Whether doing this is a good idea is another question. IMO it usually isn't. But this kind of mail does not prove cleartext access.
Of course, you may have a system that forces a password reset on login. That won't help the users who have never logged in. Those accounts are freely available to a hacker.
Plaintext passwords anywhere are a really bad idea.
The recipients' servers store the message with the password, of course, but they also store the other messages the same user has received from the same server, which in my case contain the same information as what could be accessed with the password. So the password offers very little additional value to an attacker, compared to just reading the mail.
Well, the way I read the parent is that you can request a previously set password to be sent to your e-mail.
If someone has access to your codebase you've got bigger problems than plaintext passwords anyway.
Not necessarily. The simple solution is client-side hashing. You could combine that with challenge-response to only reveal the password hash to the server once.
You're joking, right? The context of the discussion is when your database is already leaked. Then the chance is that your e-mail database is leaked, too. You may leak code, too. It doesn't necessarily mean someone can execute arbitrary code on your server though, yet.
Corporate speak is just so funny. The bar for "safer than ever" is pretty low when your dev team hasn't heard of password hashing.
https://www.archynety.com/tech/why-knuddels-saved-his-passwo...
Which sounds odd. You could just hash/compare filter words.
I'm guessing similar issues too, like "no salt" or "same salt for all passwords".
Note the quoted reason from Knuddles is different from what others are saying the reason is: "so users can not filter their own password via our platform via a filter"
Edit: Apparently, the posted articles on this are misquoting things. Here's the original company response: https://forum.knuddels.de/ubbthreads.php?ubb=showflat&Number...
It does appear they were screening all chat text for the user's password after all.
https://forum.knuddels.de/ubbthreads.php?ubb=showflat&Number...
Not that you need a security consultant to know passwords shouldn't be stored (at all, nevermind plaintext).
If they're doing that then they're likely being sloppy elsewhere, and by only paying €20k across the last n years they might have saved a €million.
If your company is in the same boat probably worth not bothering to get any security issues addressed. Why address security, just pay the much smaller fine if you ever get caught ...
I couldn't find Knuddels annual profit but they appear to have a dozen staff, which suggests to me the fine is too small.
More cooperative still would be doing the changes before you're caught.
If you could skip your tax bill for a few years, but get a much smaller fine if you cooperated when caught then you'd be silly to actually pay.
In short, in terms of pour encourage les autres this fails badly IMO.
If you do the work ahead of time, you pay the cost of doing the work. If you wait for the fine, you pay the cost of doing the work plus the fine. It doesn't take a lot of fine to make doing the work to begin with worth it -- basically just accounting for chance of getting away with it and time value of money, which goes down as the government gets better at catching more people quicker, as should be their primary goal for something like this.
That means those with poor security regimes may "win" because the costs of poor PII hygiene are externalised.
It would certainly be nice to imagine all the 2 million UK corporations are addressing PII security rather than hiding and hoping not to get a fine ...
If the regulators catch someone breaking a rule like this, the consequence should obviously involve an audit that looks for other violations and requires them to fix those too.
But even if it didn't, your conclusion wouldn't follow, because they would still have no incentive to fix the other problems unless they expected to get caught for not fixing them. But if they did expect to get caught then the numerous predicted small fines would be a sufficient deterrent.
> It would certainly be nice to imagine all the 2 million UK corporations are addressing PII security rather than hiding and hoping not to get a fine
It's the hiding and hoping not to get a fine that's the reason large fines don't work. Higher penalties can't deter someone who doesn't expect to be caught.
What works is smaller penalties with vigorous enforcement.
The analysis is similar to a parking fine, if the fine is €1 but parking is €2 per hour then people will chance it.
If the fine is having your car towed and €200 then people will be damned sure not to go even a minute over their paid time.
But if you make it a $200 fine with a one in a thousand chance of getting caught, then it's profitable, because then many people rationally take the risk and become a source of citation revenue. But the violation rate is higher, so if that was your goal, it fails -- unless you're still doing vigorous enforcement, in which case high fines are once again unnecessary.
But most places don't do dumb stuff like this because they've smartly chosen to be dumb. It's just thoughtlessness, just focusing on the wrong things. And one of those wrong things is "saving" money by being too cheap.
If a cheapskate client asked me to store passwords in plaintext on the theory they could save a few days of dev work, I'd love to be able to say, "Sorry, that's such a bad idea it's illegal. Fines start at €20k and go up." Their cheapness meter would swing into the red and they'd leave me alone.
If they company had actually chosen to be broadly negligent, it's clear the regulator could have imposed a much bigger fine, so I think your case is covered too.
True, if there is no punishment and a threat is teethless nobody acts on it (that's why the big GDPR outcry also came only this year after the two year introductory phase)
However if you have too high fines what happens s that companies try everything to hide the fault and lie to avoid the fines. Here a company complied to all things, improved security (which according to the data privacy agency let to six digit costs (while a question is how you measure this) - see other comments) and therefore got a low punishment.
The punishment also has another effect: It makes it clear that fines are being collected. If it were higher the Knuddels company would go to court and we'd have an example case only in two or more years.
The goal is to improve data safety. That goal was achieved.
Some examples of economic crime would be: not implementing security, tax fraud, overweight freight trucks; speeding to make a delivery on time (whilst on the clock).
The first kind of crime is generally made by people who 'know they are wrong, but they feel like they don't have other options' or people who 'know they are wrong, but don't give a f*ck about that'. Especially that first type of person won't respond to more punishment.
The second kind of crime is much more calculated. Here, the response to harsher punishment would be a lot better. This is generally why the fines on overweight trucks are so high. It is actually required in order to make the calculation unacceptable for driving overweight.
On the comparison with overweight trucks: I doubt anybody builds an insecure system to gain an economical benefit, not using state-of-the-art technology is a mistake/stupidity/carelessness/.... "See how much money we earned from saving CPU time of bcrypt!" nobody said.
I can't recall ever hearing of a company coming forward to declare they broke the law and so should pay a fine.
Could anyone give us a couple of high profile examples?
Do you have any support for your assertion that punitive fines don't stimulate regulatory compliance but small fines do?
"Das Unternehmen hatte sich am 08. September 2018 mit einer Datenpannenmeldung an den LfDI gewandt [...] Gegenüber dem LfDI legte das Unternehmen in vorbildlicher Weise sowohl Datenverarbeitungs- und Unternehmensstrukturen als auch eigene Versäumnisse offen." ("The company contacted the data protection agency on September 8th 2018[...] In exemplary manner they gave access to company and data management processes and highlighted their on omissions") https://www.baden-wuerttemberg.datenschutz.de/wp-content/upl...
The relationship is the opposite of the one you're describing.
The problem with personal crimes is that everyone has a different utility function. If you could steal a million dollars at risk of a month in jail, many people would take the risk. Fewer at six months in jail. Fewer still at a year. Fewer still at five years. So you need as high a penalty as you can get without violating proportionality (or reaching the point of diminishing returns, once nearly everyone who can be is deterred).
There are some people who aren't even deterred by the death penalty, e.g. because they'd rather have the money needed to save their kid's life even if it costs them their own, but that's pretty rare. Most of the people who aren't deterred by even large penalties are simply the people who don't expect to be caught, or don't realize they were violating of the law to begin with.
By contrast, for economic crimes, nearly everyone's utility function is the same. If you can save $2000 by taking a 50% risk of having to pay the $2000 anyway plus a $1500 fine, it's profitable. If you can save $2000 by taking a 50% risk of paying the $2000 anyway plus a $2500 fine, it isn't. A $3000 fine provides no additional deterrence, and anything more is just a money grab. Even the $1500 fine may be higher than strictly necessary, because getting fined at all results in a PR hit that independently provides a non-zero deterrence value.
That isn't to say that a small fine won't leave a large number of violators, but they're no longer the people overtly doing the calculations. They're the people who assign negligible probability to getting caught, or who don't even realize they're violating the law. No amount of higher penalties will deter them, the only thing that works against that group is vigorous enforcement -- which works fine (better even) with modest penalties, because all you really need to do to get those groups into compliance is to tap them on the shoulder and explain how they're not.
It really isn't. The cost of a $2000 for a poor person is huge, the cost for a richer person - whilst significant - is not debilitating. If you've 10% chance of getting caught then a rich person can afford it, getting caught really doesn't hurt so much.
That's why progressive justice systems use means tested fines for things like speeding.
I'm going to guess you're relatively wealthy, your analysis seems entirely wrong to me.
What you get with small fines is people will pay, even if they didn't deserve the fine, because of the cost of time/effort to challenge it.
If a company can save €100k for multiple years, the only downside being that if they're the 1:10000 that are caught they'll have a €20k fine, the financial analysis - morals aside - says don't pay, unless the €20k would sink you.
Which is irrelevant for economic issues because both values are in the same units. An hour may be worth more than $500 for a rich person and not a poor person, but $3500 is more than $2000 for everybody.
> That's why progressive justice systems use means tested fines for things like speeding.
Then the super rich will hire a chauffeur to do their speeding for them, or fly in a helicopter, so all you're doing is creating a differential between the low and middle income people. But then either the fine is oppressively high for middle income people or is an inadequate deterrent for lower income people.
Because dollars have a declining marginal utility when you get more, but the relationship isn't linear. Someone who makes $60,000 may have effectively the same disposable income as someone who makes $30,000 (i.e. both near zero) because the first person has higher costs (housing/transportation/other cost of living) needed to live in the area where the higher paying job exists. You also end up penalizing the person who has "double the income" because they have three kids to support and have to work two jobs. Means tested fines are a populist farce.
> What you get with small fines is people will pay, even if they didn't deserve the fine, because of the cost of time/effort to challenge it.
This is not a deterrence issue, and can be solved by returning to the person the true entire cost of the resources and time taken to successfully challenge a false claim against them.
> If a company can save €100k for multiple years, the only downside being that if they're the 1:10000 that are caught they'll have a €20k fine, the financial analysis - morals aside - says don't pay, unless the €20k would sink you.
If the €20k would sink you then surely the €100k/year would, so the amount of the fine in that case is irrelevant. The real problem in your scenario is the 1:10000 chance of getting caught. If you could clear €100k/year for ten years with a 1:10000 chance of getting caught, the fine would have to be ~€10B, which would obviously annihilate any entity for which €100k/year was a meaningful amount of money to be worth skimping to begin with. Which means that no amount exists that could act as an adequate deterrent for a small organization and that probability of getting caught. Any amount over their total enterprise value couldn't actually be paid and therefore doesn't act as a deterrent.
What you need is to improve the chances that they'll be caught. In which case you don't need such a large fine.
On the other hand they seem to have at least as many open positions. This is either a sign of strong growth or a sign of inability to offer competitive pay. For a struggling pre-Facebook social web relic, it's easy to guess which one it is.
edit: title has been changed, nevermind
There are no input fields, no requests sent with personal information at all etc.
Everything that's questionable already comes over HTTPS on their site though, like Facebook content etc.
"If you don’t pay me X we’ll report you under environmental protection law and you’ll have to pay much more."
"If you don’t pay me X we’ll report you under labour regulations law and you’ll have to pay much more."
How would GDPR be special?
The proportion of businesses who are unintentionally violating it is unusually high.
Best strategy: Ignore the blackmailer and improve the security of your system and take privacy serious. (Doing such a cleanup also helps to reduce fines, thus also reduces leverage of blackmailer)
They were doing this so they could filter out the passwords from chats (i.e. to make it so users can't give out their passwords to other users). Not saying this justifies it, but it's interesting.
Also, you probably can't just try hashing each word, since there could be whitespace and punctuation in the password text, so I think you'd have to hash all possible substrings of each message to be able to reliably catch passwords.
Obviously, though, they shouldn't have been storing them in plaintext.
For every message typed, compute a running XOR of each sequence of L bytes (2 XOR’s per character, so as good as free). Whenever it equals X (about once every 64 letters or so, because typical text doesn’t use all bits in each byte equally), compute the salted hash of the last L characters, and compare with H.
Unicode and Unicode normalization will complicate that, but I think it should be fast enough for a chat.
You probably can also improve on that factor 32 by storing multiple XOR-like (but slightly more computationally expensive) hashes and computing multiple running totals.
Given that this is to protect users from falling for scammers who claim they need their password to help them, you may be able to run it on the user’s machine.
I fear, however, that a scammer will just ask them to type their password with a space inserted, spell it in the NATO spelling alphabet, or whatever. If you fall for a scammer, that won’t stop you from giving them your password.
In the suggested case, storing the length of the password alone massively reduces the search space, and storing the XOR (of the plaintext with the hash, I think you're suggesting?) negates the value of using a hashing algorithm suitable for passwords, since the point is that checking if a password matches a hash is an expensive operation.
Also, the premise is faulty, because as soon as users figure out they can't type their password in the chat, they'll just describe it in words or split it into two pieces etc.
It could however in general have a problematic side-effect if the password is a common word that could be guessed from surrounding context when censored that way. Something I'd find a lot more likely here than passwords with spaces.