Intention to fine Marriott more than £99M under GDPR for data breach
ico.org.uk
ico.org.uk
> Personal data has a real value so organisations have a legal duty to ensure its security, just like they would do with any other asset. If that doesn’t happen, we will not hesitate to take strong action when necessary to protect the rights of the public
Certainly, calling out poor security practices is a good thing, however this level of scrutiny is going to require a major shift in mentality for a large portion of the industry. "Move fast and break things" just isn't going to cut it anymore.
When 339 million guest records are involved, anything less shouldn't cut it anymore.
The monetary value of a particular person of interest's guest record may be more than that, but those people are few and far between.
If you disagree, please let me know who I can get in touch with, who will pay me $4/guest record. I'll quit my day job, and set up camp outside a hotel lobby, recording guests and license plates.
A few people have done some very interesting things. For them, those numbers are substantially higher than zero.
You haven't disproven my point. The quantifiable, median damage is zero. This is relevant, because this sub-thread tries to quantify the harm by taking the fine, divides it by the number of records, produces $3, and posits that the leak has done more than that amount of harm. Because, obviously, if any harm comes, the harm is over three dollars.
Well, yes. It is. If you can measure the harm, of course it's more than three dollars.
For most people, though, the harm is immeasurable. Pointing out that the median harm is zero exposes the absurdity of the original argument.
There's also a problem we haven't brought up in this thread, which is that the main damage from privacy invasion is not to people individually, but to human society as a whole. Increasing the price of doing anything particularly interesting can condemn an entire society to domination by mediocrity.
I'm saying we have no idea, and we're not going to get there, by doing arithmetic. But, if you ask me, I do believe (based on nothing more then a worthless napkin calculation) that it's more likely to be between $0.3 and $3, than it is to be between $3 and $30. Remember, the recipient of this data is incredibly unlikely to cause maximum possible worst-case damage to even the interesting people on the list. Most likely, they just want to steal credit card numbers.
> There's also a problem we haven't brought up in this thread, which is that the main damage from privacy invasion is not to people individually, but to human society as a whole. Increasing the price of doing anything particularly interesting can condemn an entire society to domination by mediocrity.
The nice thing about the GDPR is that even if it doesn't address the damage of a particular leak, it's a swift kick in the ass of the IT departments other companies, who are really keen to not end up on the receiving end of the next fine.
Move fast and break things all you want if you have such an amazing safety net. But at that point you’re not breaking anything, you’re just letting the real world fill in the gaps in your test suite with an insignificant impact.
Still, not good enough if you’re dealing with money, medical stuff, vehicles, etc. You’re getting into life or death territory there.
That motivational quote should never have made it out into corporate communication. It was embraced by everyone[1] because it seemed edgy and hey that company is successful in spite of itself.
That should never have been embraced by anyone especially outside specific contexts.
[1]Just about everyone embraced it because it was a kind of punk attitude in the face of stodgy enterprise development schedules. Everyone wanted to seem cool, so they went whole hog.
But even in the US, medical equipment breaks down. Just not at near as high a rate.
I made medical imaging software for diagnosis and analysis. We would get a regulatory proctology exam every release. These guys would find arithmetic errors in papers referenced to support algorithms used in the software, and ask us about them. (Incidentally, that's where I learned never to trust "peer reviewed" papers or dissertations in computer science. Always check it, in detail, yourself. CS guys have to be some of the worst mathematicians I've seen during my time in scientific research.)
But yeah, the FDA were that anal in our case. If they were not that anal for you, I'm not sure why that is? Maybe the radiation? We were putting out software that potentially dealt with, essentially, irradiating humans. Software that controlled radioactive devices. Etc. No one wants the equivalent of a dirty bomb going off in some small town somewhere. So I don't blame the FDA for the whole "every i dotted, every t crossed" treatment. It was actually reassuring. At least in our case.
>that company is successful in spite of itself
That's a pretty strong opinion. Some would argue that FB is successful because of stuff like that.
A bit of a sidenote, but after all, I remember how badly Zuck was clowned everywhere (including by FB shareholders and people here on HN) immediately after the purchase of Instagram and WhatsApp. People were saying that FB is dying and Zuck is trying to buy companies that are hyped but irrelevant to the core business out of desperation. These days, it is a pretty universal sentiment that those acquisitions were some of the smartest purchase decisions he could have made at the time.
Most of HN didn't have some insider information which Facebook did. This information was acquired by surreptitious data logging of a VPN "security" app [0]. This is the same app which was controversially packaged as a "research" app and then forced to take down from the App store [1].
[0] https://www.wsj.com/articles/facebooks-onavo-gives-social-me...
[1] https://www.theverge.com/2018/8/22/17771298/facebook-onavo-p...
I think it's 10,000% more likely to be due to so much post-2008 ZIRP money floating around, so why give a shit about quality or consequences? As long as advertising and copyright industries are able to establish themselves as the fundamental arbiters of all content, anything else that happens to us or the companies are broken eggs for the proverbial omelet.
The people embracing MFaBT exhibit nothing resembling "punk attitude."
Good.
> It is believed the vulnerability began when the systems of the Starwood hotels group were compromised in 2014. Marriott subsequently acquired Starwood in 2016
Starwood was well beyond the "move fast and break things" phase of companies. Many companies aren't, and if you're trying to say all startups have to comply with GDPR on day 1, you are wrong.
> U.S. based businesses may actually be exempt based upon some interpretation of Article 3.2(a):
This is a very different situation from your original statements based on size and maturity of a company - but I'll concede that the EU reach clearly only applies to EU interests .
https://www.internetlegalattorney.com/are-there-gdpr-exempti...
It's not a blanket immunity, but it's not universal as you say.
Yes, it's probably a drafting defect, but I think one would be very brave indeed to try to rely on it, especially given that establishing an art 30 record is, practically speaking, a prerequisite for being in a position to comply with the rest of GDPR.
Unfortunately, this is a good demonstration of two criticisms made of the GDPR right from the start: the costs of creating new paperwork in the approved format even if it makes no material difference to any actual data processing, and ambiguity about what is required or permitted even in quite fundamental respects.
This motivation is asinine. Record leaks don't do anything to harm the original records and it's not like Marriott's secret sauce is a list of customer records. Companies don't protect assets from things that don't cause the assets harm.
Personal data does not have value to the company in that regard. It's a liability more than an asset.
Hopefully that will stop them hoarding personal data.
GDRP is working as intended :)
Yes, the cutting edge can cut both ways. But alas is kinda needed in IT security. So easy for a security update to come out, yet the process in some companies rightly dictates that it is tested so that the update does not break anything else. So you get a delay. So even then, that small window could see that security issue exploited and the powers that be will see you didn't apply the update instantly and you're lambasted - even for following best practices and going by the book of testing. After all, any update could have an impact upon the applications and infrastructure in ways above and beyond the issue the update is addressing. We have all encountered such issues as well.
So the phrase "move fast and break things" has a younger brother now "move slow and be broken".
Be nice if the powers that be (Governments) proactively audited companies IT security proactively instead of being event driven - after the horse has always bolted. I would love to see companies fined for security issues before such security issues are exploited and abused. After all, the customer always pays. Until that happens, the same mentalities in how security is treated as a priority will carry on playing out. But the other old IT saying of "if it works, don't touch it" whilst true, equally is the source of so many security issues that it just can not carry on being leaned upon.
Move fast and break things used to be the way that bridges were designed (i.e., build it, test it, see if it breaks, improve it if it does). I don't think anyone would tolerate that as a way to conduct other fields of engineering anymore.
That's the point. "A major shift in mentality for a large portion of the industry" is basically GDPR's success criteria.
Those who said EU regulations had no teeth last year might need to readjust their expectations. This follows on from BA's large fine a few days ago.
The user consent parts of gdpr, are, imo, not good. Any wins though are better than nothing.
But, I feel that assuming a pseudo-contractual relationship between websites and users is euphemism. I feel the same way about user agreements. The south park parody of apple's sums it up, for me.
Not even judges read it. It can't form the basis of a consent model. I think bans on certain types of tracking would be preferable to "consent."
If we are determined to have explicit contracts, we need to be realistic and take incentives into account. If the website controls the UI of the "opt in," language of the contract and such... they have a high level of control over outcomes... and these are highly manipulated to secure convenient outcomes. UI plays a far bigger role in determining the "consent" outcomes than user preferences.
So, if we are determined to go down this route, "consent management" needs to be "open" to 3rd parties chosen by users and allow central management, user selected defaults and 3rd party recommendations/defaults.
If user consent actually reflected informed user preferences, FB's tracking pixel would be disabled for >90% of users. What possible benefit is this to users?
The overlap between people who are paranoid that FB is listening to their conversations via the phone mic and users who have "consented" to advertiser cookies on a bunch of sites tells me that this model for consent is fundamentally broken.
On the flip side if you (or someone) doesn't mind....
I can tell from the downvotes (also on similar comments) that this is an unpopular opinion. Anyone care to defend gdpr "consent" as it exists currently. I don't mean the aspirational language of the law, I mean consent in the wild under gdpr today.
Indeed, this seems to be really lacking as far as I've seen.
Compliance with article 7 section 4 in particular (provision of service must not be conditional on consent for processing of personal data not necessary for provision of that service) is blatantly ignored by many actors, with a message of "accept our tracking or we won't let you see our content". Others pretend to be in compliance by having an opt-out which never completes, or other dark patterns.
Although, in saying that, given the lack of official opt-out functionality, using the site will probably result in tracking.
I wonder: what can we (as a community) do to change this? Can we:
- make applications to the information commissioner about the most egregious breaches - create enough nuisance value that these entities need to acknowledge and address this issue
I'm sure there are enough privacy minded individuals on HN that if we all agreed on a concerted plan of action we could make an impact?
In fairness, that's because it's a legislative over-reach that the EU wants to enforce extra-territorially, but a lot of businesses outside the EU's jurisdiction have declined to undermine their entire business model because a foreign government decided they should.
It is reasonable to say that people should have a choice about things like being tracked, and that such tracking may only be used with the subject's informed consent. This protects the privacy of those who value it by default.
However, IMHO it is not reasonable to say that organisations that fundamentally rely on such data processing to be financially viable must then continue to provide service to users who choose not to participate. That's an entirely one-sided deal, and it's logically unsustainable to require businesses to operate on that basis. You'd never tell a bricks and mortar grocery store that if someone came in but didn't have any money with them then the store still had to let them take a chocolate bar and eat it, and I don't see the effects of the GDPR in this respect as any better than that.
I'm not convinced this is true. Television, billboards, and print newspapers demonstrate that advertising can still exist and support a business model without invading the privacy of users. I'm also not convinced that user-targeted advertising is significantly more effective in practise than contextual advertising.
Maybe if we were faced with some severe and immediate threat to public health and the business were a manufacturer of essential medication, there might be some overriding public interest justification for adopting that sort of position in law, but I think it would need to be a crisis of that sort of level to justify such direct intervention. I don't think the situation we're talking about here is anywhere close to justifying it on similar grounds.
Nor do I see any obvious evidence that forcing the matter through regulatory action will motivate a shift to more desirable funding models for the affected businesses. First some good alternative models would have to be identified, and if we'd done that already, we probably wouldn't be having this conversation at all.
The advertising industry has been subject to regulation for a long time, especially in European countries. There is precedent for regulating the quantity and quality of advertising, banning classes of adverts (e.g. tobacco), and the use of personal data for direct marketing (telemarketing). Ultimately they have the option of providing their services within the bounds of the law, or not providing them at all. I don't see why web advertising should be exceptionally unregulated.
The GDPR does not prohibit advertising, and as a website operator you would be within your rights to block access to adblocker users. Advertising without the use of personal data is demonstrably successful (TV; radio; cinema; magazines; sponsorship). Personal targeting of adverts may improve revenue, but so would allowing tobacco advertising, increasing the length of advert breaks on TV, or numerous other regulated practises.
So far, fines have been pretty reasonable and for clear offenses.
I think this would be a stronger argument if other EU laws didn't actively require the collection and long-term retention of some of the most important personal information, including identity and financial details, for other purposes such as VAT audits. Such obligations often preclude otherwise reasonable data management strategies like encrypting all personal data with a per-account key that can be easily deleted and thus render everything connected with a given account permanently inaccessible in the event of an erasure request etc.
Instead, data controllers are in principle supposed to keep track of every possible purpose for which personal data could be processed, even those originating in theoretical legal requirements that are rarely if ever used in practice, as they applied at the time each item of personal data was first collected and at all times since; to retain each individual data point for as long as any purpose for which it might be needed continues to apply; and then to delete that data promptly once its final purpose is no longer relevant.
I suggest that few if any data controllers are actually doing this. Instead I suspect almost everyone who is trying in good faith to comply with the GDPR is using sufficiently generic purposes and blanket provisions to simplify their position to a manageable level of complexity. (How many privacy policies have you read since GDPR came out that actually stated a concrete time period for retaining each category of personal data being processed, and how may have you seen that rely on abstract wording about keeping the data for as long as any stated purpose applies or something similar?) No doubt many other organisations are simply not complying with the GDPR rules about retention and deletion at all, perhaps through ignorance, or perhaps as a deliberate choice that they hope to get away with.
I see this violated so often with full-screen popups requiring you disable adblock or exit private mode. The EU really needs to fine these companies into oblivion, I should not have to create an account just to look and see if they have a disabled tracking toggle (and they usually don't, so the only way to prevent tracking is private mode/adblock).
Sounds like teeth to me.
(1) https://www.gdprtoday.org/gdpr-in-numbers-4/ (2) https://www.reuters.com/article/us-google-privacy-france/fra... (3) https://blogs.dlapiper.com/privacymatters/
Hopefully the rate of enforcement will further increase and compliance attitudes will improve.
Indeed. Are the following two statements true or false?
1. Major data hoarders, including online giants like Facebook and Google and traditional data brokers like credit reference agencies, are still hoovering up huge amounts of personal data and processing it in ways that some or all of the data subjects don't understand and to which they can't therefore have given their informed consent (assuming they are aware of any processing and have given any consent at all).
2. Governments and organisations with ties to governments are still hoovering up huge amounts of personal data allegedly for purposes involving security with little meaningful oversight and little need to demonstrate effectiveness or proportionality.
Until statements like these are false, data protection and privacy law isn't really protecting people from the biggest threats anyway, and the main positive effect of the GDPR is just to give the regulators the ability to impose fines for things that were mostly prohibited anyway but now on a scale that is significant to large businesses. That in itself is probably no bad thing, but if that's all it achieves then it's far from clear that it's been worth the huge implementation costs and the uncertainty it has brought even to honest organisations.
That's not true in the slightest. One bank (ING) in The Netherlands implemented an opt-out for analyzing customers data. Quite a bit of outrage. PR spokeperson said: "all is fine, this is all good, we follow the GDPR".
Local privacy authority sent a general letter informing that such behaviour is very likely not according to the GDPR. ING quickly backtracked. Other banks said they'd obviously comply with GDPR.
No fine was given.. it was not needed. I don't particularly care if companies are fined. I do care that they take my privacy into account. The latter is what (slowly) is happening.
You can't, for instance, call yourself a structural engineer unless you are registered with the regulatory authority as such. Nor can you offer engineering services to the public without registration. And you are bound by a code of ethics, subject to a formal complaint process, undergo somewhat regular practice reviews, and can face disciplinary actions when you fail to comply.
Right now, it seems like software engineering is the wild west, complete with tales of fortune to be had attracting code-slingin' cowboys without regard for the public's safety. I predict the lawman is coming for you.
Especially given the origin cultures of regulators think that just banning Cryptography is a remotely reasonable idea instead of barking mad.
Standards may make some sense but they should be deliberately open ended like "encrypt customer data sufficiently or don't gather it" not "use single DES to encrypt - if you use large key RSA you will be in deep shit in spite of it being better".
Yes, Marriot failed to conduct proper due diligence. Yes, they should have been able to detect the breach earlier and block the attackers' access. And yes, the attackers managed to stay in their system for a very, very long time.
But this breach was conducted by a nation state adversary. An attacker with unlimited resources and the best technical knowledge on the planet. If inability to protect yourself from such a threat becomes an offense, I am not sure the net effect is positive.
It's _annoyingly_ common for those who are subject to fairly ordinary attacks to blame a powerful adversary based on very thin evidence, because "The state of Russia attacked my business" sounds like you couldn't be expected to resist whereas "A bored 14 year old attacked my business" sounds like you're useless.
The attackers were inside the system for several years. Marriott is a high-end hotel chain, whose establishments are used by state level travelers. Having ongoing access to politicians' and high-ranking corporate executives' itineraries, and especially their hotel room bookings, is an incredible avenue for espionage.
A financially motivated attacker would have tried to exfiltrate otherwise valuable data. But if the main target is the travel information data itself, and if the scope does not particularly expand over time, I am going to call it advanced espionage.
It's not the inability to protect yourself that's the offence, it's not doing the right thing in the event of a breach that's the offence.
The solution is to have security controls that cross cut entire enterprises and give operators a place to control them, however what we have today is just a jumble of different solutions that consist more of blocking access rather than allowing the business to run securely.
And? Many things are tricky for many companies, doesn't mean you don't do them.
Still we see databases with no password made accessible on the internet, maybe it is time that you don't employ someone that has no training at all, or offer a training program, say if your developer needs to use TodaysCoolDb then have him trained on how to use it instead of him copy pasting the hello world from a webpage.
The amount of money you invest in your data security should be proportional to the data you collect, so collecting less will help you or investing more into security training and auditing your own systems.
> Security is tricky for many companies ... The solution is to have security controls that cross cut entire enterprises and give operators a place to control them
This is definitely an area worth tackling, and one where multiple companies are recently growing. That's not the only issue though.
Security has many levels and the landscape is historically filled with opaque practices and prices. That does not entice people to go forward with security audits or solutions.
We've seen improvements on tooling with SAST but active security is largely pattern-based WAF or at the network level. This has poor signal/noise ratio and can't protect against more advanced attacks that target above the network layer (including HTTP).
Recent developments target more knowledge of the application and the business logic itself. Facebook itself for example has internal tools to detect data leaks. Being inside the application is much more useful because they don't just see data flying by but have knowledge of context and call sites, which allows to register malicious calls on the spot, protect just in time (even against zero days because you hinge on behaviour), and show the exact line of code (including the call stack) where the vulnerability lies, allowing to surface and fix it, or even virtual patch the vulnerability live.
> however what we have today is just a jumble of different solutions that consist more of blocking access rather than allowing the business to run securely.
The goal of ASMs is precisely to solve that: those tools are kind of APMs like New Relic or Datadog, only geared towards security. Big names like Facebook or Google have their own internal tools, but a couple of independent solutions have emerged already, and I think that having those companies around is going to be a shift that will benefit everyone's security in the long run, due to their accessibility and ease of use compared to previously existing solutions.
(We have a culture of transparency, faith in our product and our vision, and are hell-bent on improving for security for everyone because it’s desperately needed, so no, I’m not afraid to name competitors)
Feel free to ask me anything here, on our Intercom support channel, or via email of you’re so inclined!
https://www.contrastsecurity.com/
At least, it puts a ceiling on the price a hacker can extort.
>If you experience a personal data breach you need to consider whether this poses a risk to people. You need to consider the likelihood and severity of the risk to people’s rights and freedoms, following the breach. When you’ve made this assessment, if it’s likely there will be a risk then you must notify the ICO;
https://ico.org.uk/for-organisations/report-a-breach/
> The GDPR introduces a duty on all organisations to report certain types of personal data breach to the relevant supervisory authority. You must do this within 72 hours of becoming aware of the breach, where feasible.
https://ico.org.uk/for-organisations/guide-to-data-protectio...
I fail to think of relevant common situations where negotiating with the hackers would be an option in breaches relating to GDPR.
This will not be true if any paid-off breach is ever discovered as then you'll have paid the hackers and the fine, which will be larger because you've deliberately kept it from the ICO/similar.
The lack of discovery/disclosure also covered an acquisition, companies not disclosing breaches during acquisitions is something I bet the SEC would be interested in.
EDIT: source: https://www.statista.com/statistics/266279/revenue-of-the-ma...
The board should be planning some proper security. A £50m capital budget and £5m a year revenue should be good enough.
After all, you don't have such a leak every other week.
Will have to be a big fund.
This fine is half a week's revenue, so losing 330m records is deemed not as serious as going 75 in a 70.
Endangering Lives of others for no damn reason other than wanting to be home 3 seconds earlier > Loosing customer records
Bollocks. If 75 was so dangerous then 70 is also dangerous.
For an example, just look at the recent US corp. tax cut. One time bonus to employees and then repurchase of company stock to boost the share price and in turn boost executive level rewards.
If this is under the 2% then it's 25% of the max for that tier.
In either case explaining 99 million quid to the board isn't a conversation you'd want to have.
What's your source for that? Marriott International only reported $5.2B in 2018[1].
But when you fine a company the customers end up paying, same customers who ended up being the victims of whatever reason the fine was needed in the first place. Sadly I don't see a way of fixing that enpass.
Not saying that we should adopt such a system, potentially terrible idea but it amusingly is better than other "do something" legislation in that it would actually help the target problem even if there are clear downsides.
i think the applications of fines of this sort will further empower those who extort and blackmail.
I could see someone like Elizabeth Warren or Ron Wyden getting behind it, but not really the rest of the pack (it's not a popular enough issue when you weigh it against things like student loan forgiveness, or universal healthcare).
I do wish it would become law here. It would make my professional life a bit harder (mostly on the security front, we already steadfastly refuse to "monetize the data" or even give it to any third party, to the point we've rejected those questions from investors) but it's definitely the right thing to do since the benefit for consumers is much more important.
And, regardless, if a company violates the GDPR then quickly sells it itself, should the relevant data protection commission just drop it? After all, they sold the company!