Dow Jones’ watchlist of 2.4M high-risk clients has leaked
techcrunch.com
techcrunch.com
Information from public sources - no liability? No DJ customer details - no loss of business? Bob Diachenko discovered it - so no dumps floating around? 3rd responsible - remains unnamed, no brand damage? Free sample included in the high traffic TC article
It probably was not intentional, but could Dow Jones have benefited from this press overall?
AWS can not know what is your true intention.
The consequences of those questions could be quite serious.
We could find intel out about political candidates.
OTOH I guess this is relevant information and so they should be allowed to have it under GDPR rules? I'm obviously not a lawyer although my work, like most programmers' is affected by GDPR, PCI and whatnot.
http://lexindicium.com/2018/03/19/data-mining-and-gdpr-compl...
https://ec.europa.eu/info/law/law-topic/data-protection/refo...
Right to:
information about the processing of your personal data;
obtain access to the personal data held about you;
ask for incorrect, inaccurate or incomplete personal data to be corrected;
request that personal data be erased when it’s no longer needed or if processing it is unlawful;
object to the processing of your personal data for marketing purposes or on grounds relating to your particular situation;
request the restriction of the processing of your personal data in specific cases;
receive your personal data in a machine-readable format and send it to another controller (‘data portability’);
request that decisions based on automated processing concerning you or significantly affecting you and based on your personal data are made by natural persons, not only by computers. You also have the right in this case to express your point of view and to contest the decision.
In particular, the clauses about access to personal data and to have decisions being made by a natural person seem relevant here.
Not just punishing the small percentage who get 'caught' while doing nothing to actually help the problem - ala the drug war. And for everyone who thinks it's just big evil companies who get punished, one of the first GDPR fines was $4k against an Austrian small business owner whose video surveillance around his building was deemed too broad it violated peoples privacy.
I'm not declaring GDPR a failure by any means but all policy must be judged on a long-term full-picture basis. Not simply on "good intentions" of the bill + a few high visibility wins early on, then moving on as if the world is a better place.
GDPR tells you what you can't do and what the penalty is for being caught in violation, just like a speeding law tells you what speed you can't exceed and what the penalty is for being caught.
I think that is the catch?
1. To prevent cruel and unusual punishment.
2. To set expectations about the seriousness of the infraction in the eyes of the law.
I am not a lawyer or a legal scholar, so I'm sure there are more reasons.
Because while the rulemaker believes that there is a range of potentially reasonable judgments based on particular circumstances, they do not believe that range is unbounded.
> The only reason I can think of is to protect large corporations.
The fixed minimum upper limit of $20 million is actually probably to prevent (or limit the effect of) large corporations using smaller subsidiaries and fancy accounting for GDPR-risky activities, rather than the upper limit protecting large corps.
When a store says “Everything up to 50% off”, that doesn't mean everything is half price.
The threat of the gigantic fine is what gets people into compliance to prevent this from happening.
Lots, possibly even the majority of companies in Europe beefed up their IT security procedures because of this, and I wouldn't be surprised if almost everyone that sits at a keyboard in Europe didn't get called into a meeting to talk about how important it is for them to keep their customer's data private and ways to do that.
Without something like this in place, companies can just not even care about users data.. because 'oops, we did nothing to protect it' is still a valid excuse.
On the other hand, they also don't provide internet services to people.
>The data is all collected from public sources, such as news articles and government filings.
It's exactly the same as Wikipedia; yet nobody calls Wikipedia a "sensitive database."
I mean "So?" from a privacy standpoint, from a business standpoint it's an issue for Dow Jones.
Mostly the sensitivity is in controlling write access rather than read though.
You could probably build most of it with Google.
Secondly, people are placed on these watchlists with no burden of proof or right to recourse.
Thirdly, if you appear on these lists, which can be quite fuzzy, you can find that your banks accounts are frozen, with no explanation. Banks are now very risk adverse meaning that they are more than happy to alienate a few customers if it means avoiding the risk of massive fines.
This is totally on amazon for not having vpc-enabled elasticsearch clusters for way too long, AND, not providing an upgrade mechanism to move an existing internet-accessible cluster to a vpc. I was mindblown when I first utilized elasticsearch service and was sure that there would be data leaks for only having public net.
When I learned the ropes of ES, configuring the endpoint was one of the first things that came up in a large number of docs and posts. In this case, I also wonder if the person doing it even realized it would be a problem since the database was based on "Publicly Available data". "Sure, turn CORS on, let's roll."
Thankfully this leak was of public data combined into a proprietary reporting tool, rather than something more sinister that would cause greater harm.