Chat app fined for plaintext passwords under GDPR
theregister.co.uk
theregister.co.uk
Anyone bashing the GDPR for being too hostile towards startups and smaller businesses should read this. Looks like the fine was almost a bit too low in this case...
Then you get the problem of (hypothetically) “Yeah, BMW compromised everyone’s information ... but we took into account how much our country/state depends on them and gave a slap on the wrist.”
Like the VW case.
Edit: or does the EU allow third parties to sue over too-low fines? That would be a surprise.
It's not a slippery slope.
See I can do it too.
That's not even a statement. Slippery slope to what end? By refusing to spell it out you can claim any interpretation that results in absurdity is a strawman.
"It's a slippery slope" is literally a bullshit statement. It's vague enough to express disapproval without really presenting any argument other than "just don't" yet it has the appearance of sophistication.
Either make an argument or just say you disapprove. Being vaguely ominous doesn't add anything to the conversation.
Here, I'll give you a start: "I think leaving such a wide range to a board's decision is dangerous because...".
You make it seem like that's supposed to be assuring? Essentially, small companies and startups are left to the whims of bunch of bureaucrats.
The fact that they have to make the fine "almost a bit too low" just shows you what a terrible thing GDPR is.
Fixed that for you. There's a way for small companies to avoid this - take your user's data security at least slightly seriously
... and they might even have to comply to other laws, too. god forbid. why can't they just make a quick buck without anyone bothering them? ...
Law shouldn't be applied based on the opinion of some bureaucrats. That's how you get a tiny fine for a big multinational because "they are responsible for too many jobs" or the classical one "their lobby pay me well enough" while the tiny startup get a too big for them fine because, who cares.
Can't we both agree that this fine is WAY too small? Can we both agree that this fine would be WAY too big if it was for a tiny website with a few hundred users?
The idea behind GDPR is amazing, I agree with the concept. What I disagree with is the execution and that fine is the proof that it's pretty badly done.
You also have absolutely no way of knowing if all countries will attempt to be benevolent data overlords, as Germany appears to have been in this case. My guess is that had this been an American company, the gloves would have come off. There are 28 unique countries subject to GDPR, and each will have their own interpretations and enforcement policies. The only thing that any smaller company knows for sure about GDPR is that they may be fined up to 20M EUR, regardless of their ability to pay. Other than that, both its requirements and its enforcement are entirely up in the air.
In this case, storing passwords in plain text is equivalent to building cars with defective breaks. Definitely something the government should punish.
https://en.wikipedia.org/wiki/General_Data_Protection_Regula...
This strikes me as hyperbole. Storing passwords in plaintext is a serious security issue, to the point of gross negligence - but the potential harm isn't even in the same ballpark. If your password is compromised and you have poor security practices, you could lose access to online services and perhaps even suffer significant financial loss. If your brakes fail you stand a good chance of death or serious injury.
Car makers might have a bigger responsibility, but the amount of negligence is the same IMO. Many people recycle passwords, so having a company storing yours in plain text has the potential to ruin someone's life.
If you sell 10,000 pieces of 15 dollar items for 20 dollars, your turnover is 200,000 dollars but your profit is 50,000 dollars because the cost of your investment was 1 50,000 dollars.
4% of the turnover would be 8000, which is suddenly 16% of your profits in this case. Oops.
Then you have to take into account that this is your global turnover. Your one branch in Germany made a mistake and suddenly the whole worldwide company has to pay.
Microsofts turnover last year was a 100B roughly. That could end up being a 4 billion dollar fine. 20 million dollars is peanuts compared to what it could be in the worst case. Hundreds of companies could take a 20m fine and not go bankrupt but a 4% global turnover fine will kill almost any company.
The company broke the law in a way that could have potentially harmed* individuals (passwords are critical secrets, many users do not have more than one, and so could lose their entire identity and maybe several years worth of funds. Sure, you can say that is the fault of the user, but there is the assumption of security here that was given by the company and not fulfilled).
If you rent a deposit box at a bank, with the assumption of safety, and it turns out they leave all the doors unlocked, don't hire guards, and someone came in and stole everyone's things and took them to the market, then closure of the bank is absolutely deserved.
Conversely, if a prison gives the assumption of security, but doesn't hire guards, or bother locking cells, and all the inmates walk out and some people are killed, does the prison deserve to go bankrupt?
These examples are exaggerated, yes, but roughly similar in circumstance. Hopefully enough to show that, yes, there are circumstances in which we want the government to have that hold over companies.
Now, do we want governments to have restraint? Sure. But it seems clear to me that they very openly are acting in restraint in this case. 20k EUR is a pittance to what was potentially lost by the people involved in the breach.
* - (Indeed, in America and a few other countries with weak to non-existent social welfare nets, loss of identity and money is likely to lead to homelessness and eventual death for the person, if they do not have family to rely on).
OK, but I don't think any government action to close the bank would be necessary in that case.
So how does giving the government a say help?
In the case of things covered by GDPR the value is opaque and intangible, and only valuable to certain people. Letting 'the free hand of the market, driven by the layman who doesn't understand this, is not effective.
If you want proof, well, it's in the pudding.
Edit: also, if banks wheew getting knocked over as much as sites and apps, the government would intervene
Most recent cases that come to mind are Bitcoin thefts. "The government shouldn't do anything to regulate or even look in the general direction of Bitcoin". Oh, the exchange left your pockets empty? "The Police and the government should do something!"
Companies aren't scared of consumers because as a mass they have no idea what's good for them or how to protect themselves. Without a watchdog we'd all just be open for abuse with no leverage to stop it. Companies are far more motivated and capable to abuse you than you are to defend yourself.
I have so little sympathy for this position that despite generally having been pro-GDPR I no longer can support it if it is going to be used to encourage users to do something fundamentally stupid :/. The reality is that if we are going to make users think using one password is somehow ok then we need to be using authentication protocols that don't involve sending that password to a server in the first place: this is 2018, and challenge response takes like an hour to implement; the idea that sending a critical password to someone in the hope that they immediately hash it and store it is something that is somehow protected is insane.
What we need to be doing is spending our time either on a massive education campaign or on technological solutions (like challenge response passwords, which HTTP never added even while every other old protocol was carefully adapting to get this right), not entrenching the position that users should be allowed to do the thing that will never ever ever be secure by putting up laws that somehow make it look sane.
The point here isn't "shame on the users": the point here is "shame on developers and lawmakers for working against users by encouraging them to do this horribly insecure thing rather than doing something sane". Seriously: how about we instead make a law (with a GDRP-like lead up of multiple years to "get ready for it") which says that "handling passwords at all isn't legal, even in transit (whether on a third-party SSL termination service or on your own servers)", and lets see how many mere hours it suddenly takes the Chrome/Firefox teams to come up with a real solution to this problem?
Passwords will never die. also by outlawing them either you force everyone to re-register to every site they want to visit or give all the power to single-sign-on services like facebook and google.
The fact that users do insecure things—and that real-world systems need to be designed to deal with that fact—is orthogonal to the idea that we should be making things more secure as well. Yes – security is broken and we need to fix it. The way to do that is emphatically not to pretend that it's already fixed.
I mean, seriously: why would the law make it so illegal to allow passwords to be dumped, with technical people coming out saying "these passwords might protect something really important as the user is using the same password on more than one thing", if that wasn't at all how you were supposed to use passwords?
Imagine if the opposite were the case: if banks were not liable for any money lost by a user if it could be shown that the user was using their banking password for any other service. That would be a very different conceptualization of the risks and how passwords work, and frankly "fits reality" better than what people seem to want out of this situation (which is the exact opposite of that) :(.
If you don't want to claim that the issue is "already fixed" by "a bunch of websites that know what they are doing hash passwords and hopefully never have code bugs or people tapping their web servers or employees who can modify the code or debug logs that dump POST requests accessible to anyone or any other number of ways this password could be leaked because you sent it to this company's web server (which quite often might have used some SSL termination from some third party and so who knows how many people have access to your password!)", we might come up with actual solutions (or maybe spend the effort to educate users, as right now I don't know anyone who really tries).
I believe in some places this is the case.
If you get hacked or use 123456 as password it is not the bank fault. If a service get hacked and the attacker discover your bank password it is not the service fault if they did their due diligence in securing your data.
most people use the built in password manager anyway
Are you advocating government not be able to influence businesses to comply with the law at all?
GDPR is actually a very well thought through piece of legislation and I've implemented compliant systems: best rule of thumb I heard - treat peoples personal information as if it is credit card data and you will comply in a fairly straight forward way.
Yet so many business use third parties to avoid to deal with storing credit card data....
The IP is considered a PII too.
You mean two years to comply before it went into effect. + over 10 years of similar local laws.
"right under their noses" my ass
To be clear, I'm not arguing for no control at all. However, fines should not be so egregious that it ends up being up to bureaucrats to decide whether a company lives or dies. This will easily lead to selective enforcement and corruption.
I think we've seen enough of how this theory works in practice (or how it doesn't) to be able to say that there is absolutely no good reason to rely on it.
2. In many businesses, the actual customers are not the end-users, whose data is leaked (all the nice free services you're getting over this invisible thing called internet), they are the merchandise business is selling to somebody else (ads, etc.).
3. There are two ways of coping with this:
3.1 darwinian, where stupid users who choose to hand their data to dumb businesses all jump off the cliff holding hands
3.2 paternalistic, where we elect somebody competent to make choices for the rest of the community, which would prevent people's poor judgment to both hand data to insecure businesses and for businesses to be insecure in the first place.
4. We tried darwinian one since the day 1 in many fields. Reverting it comes at cost (antibiotics would be one good example to think of).
How does that work in a case like Equifax?
1. Knuddels is largely targeting minors
2. its customers are other companies not its users
3. in the real world there are externalities (like the network effect)
Even on breach could result in real damage to an individual, but that risk increases as more of that individuals data can be collated.
It is only after publicly known exploit that small customer can know about issue.
Frankly, yes.
Turn this statement around. Would you say that no matter what it does, no matter how many crimes are committed or citizens harmed, a business should be able to carry on without interference? That companies should be superior to people - entirely above the law?
(It's not a very big harm in this case, but I don't see anyone arguing that e.g. companies should be able to dump unlimited amounts of toxic waste into rivers any more)
Sure, because before the GDPR businesses needed to follow no laws and never would have been closed by the government by not following laws and regulations.
"The government" have the ability to remove the freedom of people who have erred. In some backwards countries the government even has the ability to execute people.
I would say "no", but you have to understand that's coming from the perspective of an anarchist.
Rationally, this power pales in comparison to the others that governments already possess. If a state wants a business to fail, it will fail. GDPR has zero impact whatsoever on that.
It's not the government, it's the judiciary. The business can go to court to appeal any fines with the final court being outside the country.
There is a fundamental difference between America and Europe, in that Americans distrust their government but trust corporations and the free market. Europe is the exact opposite.
You can agree or disagree our world view, but that doesn’t change the fact that in average, more than 70% of Europeans trust the EU to have their best interests in mind, mich higher for GDPR.
I don’t think it’s really start-up hostile either. I think there is a huge potential for disruption for privacy centric companies.
I don't think that's true; that's a common European misinterpretation. I think, in general, Americans trust their government less than they trust corporations, but they are generally distrustful of any entity that wields or appears to wield significant power over them. Exceptions are made for entities that "agree" with a particular person (and these exceptions are not entirely rational).
GDPR is nothing new in this respect.
Right. But that won't work.
We set the fines at say, 20% of the business.
So a 'mom and pop' firm breaks it, gets reported. Ok, now they're out say, 20,000 EUR (scale to whatever is appropriate in your country for a small company).
Then a big business breaks it for maybe, gets reported. Ok, now they're out $35.57bn.
These might indeed be acceptable amounts. Now imagine that for example, instead of having a fair number of people affected, it is just two people. Or three people. And perhaps in this instance the people involved were only marginally affected by it, perhaps at worst they would have lost a couple of hundred $currency.
Technically speaking, the companies still broke the law, but suddenly perhaps the punishment does not quite fit the crime!
Universally large fines would threaten small businesses while reasonably charging large businesses. Universally small fines would potentially be reasonable for small businesses, but would be negligible for large businesses.
Why shouldn't it be tailored to the company's size/viability?
Businesses that break the law, yes!
Do you really not want your government to be able to fine or even shut down repeat offenders?
Still stupid, but at least the had good intentions, just bad execution.
[0] https://www.golem.de/news/datenleck-warum-knuddels-seine-pas... (in german)
Is there any way to do that in a secure manner? Because a hash says nothing about the length of a password (and you certainly don't want to store the length, which would make the attack space much smaller)... so if passwords are anywhere, say, from 8-64 characters, then for each chat message you'd need to hash every possible consecutive string of characters for every possible window size separately, which if the hash is even remotely computationally intensive could possibly turn into too much -- especially if being done on the server instead of the client (in order not to expose the hash and salt).
Is this just something it's not possible to protect against?
But is storing a plaintext password, even on the client, good practice? E.g. in a browser that uses a cookie with something like a session ID to make sure you're logged-in... is storing a plaintext password in localStorage considered a valid security practice? I would have assumed not, although it's certainly not close to as bad as storing it on the server...
Rather than scan for password being contained in the message, something more reasonable to try would be to check if the whole message is the password since you can just plug that into the normal password hasher and run just one slower hash op
(My password was reset by something/someone, as it contained a '*'; when trying to set it anew, 'star' was a forbidden character...)
It makes you wonder that if there's a team that isn't as rigorous elsewhere (or a team on which pressure has been applied to accidentally leave in some such 'mistakes') what kind of SQL injection possibilities exist.
1. They tried to prevent SQL injection attacks by stopping the page from loading instead of properly escaping data.
2. They failed to actually check if parameters had the forbidden characters they were looking for (they checked the URL, instead of the parameters after they were parsed so all it took was URL encoding an apostrophe)
3. They stored credit card details that they should have never recorded in the first place (including CVV code) rather than just storing the transaction ID from Authorize.net
4. They never bothered to archive old order data even though their ecommerce site didn't even have a customer login and they had absolutely no use for old orders after they were complete.
If you spot that kind of incompetence on something inconsequential from a small team, dollars to donuts they're making the same kind of mistakes with far more serious code. And due to the Dunning-Kruger effect, they're probably too incompetent to realize that they shouldn't be touching anything related to i.e. payment processing or authentication.
The (most visible) part that isn't fit for purpose are all the things which gdpr solves by referring to a pseudo-contract between customer and website... permissions.
The premise, that a user/reader of a website has a contractual relationship with the website... this is madness. An average user's permissions on Google or BBC does not represent their privacy preferences. They don't understand the implications and expecting them to is silly.
That whole part of the legislation is doomed to (a) fail to benefit users and (b) cause freedom problems. Freedom as in free market and also freedom as in freedom and open platform.
It could) should be replaced with new rules governing online advertising platforms. Most privacy issues gdpr addresses begin here anyway.
Note that no online advertising platforms were involved, the data subjects were not exactly technically literate (most are retirees) and GDPR helped them greatly to protect their privacy.
The nice thing about GDPR is that all non-essential data collection needs to be opt-in, so if someone doesn't understand the implications of a choice presented to them, they can simply refuse to agree without negative consequences. How many people accidentally opt-in to being tracked for advertising when they have to individually allow each advertiser to do so?
Part pf the GDPR is a requirement that such things are spelled out explicitly in clear language.
They are wrong.
Usernames can be whatever the user likes, unless there is a good reason for them to give their actual name. In which case, there is a good reason for them to give their actual name. And then the business has a responsibility to store the user's actual name securely, etc. This is good.
There is no good reason for anyone to store passwords in plain text. Fining people who do this is good.