Nearly 60,000 Data Breaches Reported Since the Launch of GDPR
amatas.com
amatas.com
As a nice side effect you see who lost your data to the spammers, based on the email adress and you can block whole email addresses from getting stuff
I had the bitcoin porn spammers use that address (with what was probably a valid password).
After the linkedin breach I moved to a password manager so I'm mostly immune these days.
Back at the beginning of the 2000's, I use to get hundreds of spams. So I decided to use an alias of a special mail on my own domain name for each new site I register to.
I used alias for not having to configure a new account on my mail client.
And then it's super easy to shame whoever sold your email.
Best anecdote I have ? An antivirus / antispam brand. I registered as reseller with an alias.
Less than a week later, I started receiving unsolicited mail on the alias.
I asked them why it happened, but never received anything more convincing than "Mmmm, don't know, let me check".
Of course I explained them I won't be buying their product anymore for my clients, and destroyed the alias.
If you don't run your own mail server, Fastmail offer it (and have a nice fallback for the occasions where a badly coded site doesn't accept email addresses in the form of username+blah@domain.tld ...I'm looking at you microsoft!): https://www.fastmail.com/help/receive/addressing.html
Do you include browser extensions or some mechanism for filling in the credentials that doesn’t require me to open up the app itself?
An iOS companion that could somehow use the Continuity features of iOS/macOS to do an offline sync between the two would also be a killer feature.
I don't currently include browser extensions, you still have to open the app and search, then CMD+C for the password, and CMD+B for the email or username.
I may do browser extensions, but I'm always wary of browser extensions these days
Privacy and security shouldn’t be hard or expensive to embed in applications.
We believe the trend towards “ephemeral data” that has a TTL/Policy follow it in the real world is the right approach.
We have some amazing products coming soon and we are hiring persons who want to be part of this mission.
They are referring to breach as in breach of rules. These are not security vulnerabilities, these are GDRP complaints that may or may not be real, but have been reported by people.
> Austria has issued its first fine for GDPR violation, sanctioning the owner of a retail establishment with EUR 4,800, Digital Freshfields report. The reason is that the entrepreneur has placed a surveillance camera which not only captures too much of the sidewalk in front of the establishment, but it was not properly marked as conducting video surveillance.
For example, I know of a financial institution that reported a breach because they sent an account statement to the wrong address.
(Edit: well, certain breaches are entirely clear, of course. It's the breaches at the lower boundary that are in question.)
We can be reasonably certain the regulators won't want to be bothered with every account statement misdelivery but they haven't specifically told us. Self-reporting this is low risk and demonstrates an effort at complying with the regulation. It also has the added "benefit" (from the corporation's perspective) of demonstrating to the regulator how onerous and unreasonable the compliance obligations will be for their office if they don't make an effort to set "reasonable" compliance and reporting standards (again, from the corporation's perspective).
But the contractor who "misplaced" the flashdrive of customer data? Well we haven't been told that's a breach because we don't know that it's "lost." It certainly feels like something a regulator would care about more than a misdelivered account statement but they haven't specifically told us they care about this scenario yet. That's a risky thing to self-report because there will probably be consequences and we have no idea what the consequences are because it hasn't come up for anyone else yet either. In that case it's low(er) risk not to report it and hang our hat on the ambiguity of the new regulation in the very unlikely event the regulator even gets wind of the breach. The strategy is to ask for forgiveness for our ignorance of the scope rather than clarification.
It's not right, but that's how it works.
Source: Corporate attorney/Former Chief Info Security Officer at an investment bank. I quit over their handling of a particularly egregious PII breach.
Did we expect 60K? Does that mean we should expect a reduction in the future because companies are taking the right actions? Should we expect to see a reduction in identity thefts? How does the EU know the law works?
One of the big issues pre-GDPR is that companies weren't always forthcoming about their data breaches, so the scale of the issue was unknown.
This meant that people looking at either solutions or at necessary regulations/legislation were acting in the dark.
I suspect people in the EU would know more or less immediately if they still receive targeted ads, and didn't opt-in to anything
First, if you consider the sample size and timeline large enough, you can weigh what the goals were to what has actually happened (be sure to include the societal costs of the legislation in your calculation).
Second, you can look at the success or failure of previous attempts (e.g. data protection directive) and the reasons for success or failure. Are we repeating history, for better or worse, concerning government oversight of the internet and enforcement? Did we improve on the successes by adding more (larger scope, bigger fines, more legislation, etc) or did we exacerbate the failures?
While the questions are subjective and therefore not amenable to an objective large-scale determination, they help me arrive at a conclusion personally.
Even if that were the only effect of GDPR, I think we could already chalk it up as a huge win, but it won't be. The recent news about German anti-trust regulators using very GDPR-like language to forbid Facebook data gathering/correlating, but with the additional teeth of anti-trust, is also a good sign.
I also saw that less than 100 fines were levied, so for now a rate of 600:1 breaches:fines.
What you'll get a fine for is:
- Not reporting a major databreach promptly when you become aware of it
- Not responding well or taking proper steps to notify affected people
- Not taking basic precautions to safeguard data
- Being warned and then disregarding guidance (what it seems Facebook has done)
1. GDPR… who cares? Give me a break, sick of that shit.
2. OK, let's do the bare minimum to comply.
3. Hey, you, IT guy! You know where we're storing all the data, right? Good. Put that in a document somewhere. DPIA: done.
4. Oh shit, someone's laptop got stolen / email account got breached. What sensitive data was actually there? Who's affected? What now?
Disclosure: we built SW for automated AI discovery and analytics of personal data, PII Tools. It's used by auditors, and I can say the most severe problems come from unexpected places (file shares, archives, email attachments…), not your "front-facing central DB" that's typically top of everyone's mind.
As to your ...: backups, old hardware that is discarded, lost USB sticks that had data on them they shouldn't have had in the first place, test systems, developer laptops with data on them they should not have.