MoviePass database exposes 161M records
scmagazine.com
scmagazine.com
Thousands or millions of records are breached due to X (usually egregious negligence, sometimes not), the company makes an apology full of mental gymnastics, blame game, and bold lies ("Your privacy is our number one concern, we're sorry we are only pretending to care now."), a few days later the heat is off because another company let loose a few million other records. Repeat.
I feel like I need to be re-sensitized. This is a major problem - and I just can't seem to muster up any care for it anymore.
However, there are many other goals of phishing: Pivoting through another person/company to reach another target, IP theft, espionage, corporate sabotage, impersonation, etc.
[0] https://www.armyupress.army.mil/Journals/NCO-Journal/Archive...
I don't think we're really meant as a species for this constant stream of depressing information we can't act upon, it's not good for us. Apathy seems like the only natural response to this barrage of stressors.
I agree banks need to improve security standards (along with just about every other major and minor company). But banks being more secure doesn't get to the root of the issue any more than just forgetting about it (after all, it's generally not the bank having their innards on display). There is no silver bullet.
Your idea might cut down on identity theft - I'm not sure. But it doesn't speak to the root issue. (Not to say it isn't worth pursuing, just that it doesn't do anything if I shared a password between my email, bank, and MoviePass)
If we are claiming that it is too difficult for people especially poor people to get a current state photo ID ( which is why we do not want to mandate it for voting ) what are we going to do with 20-30% of the US population that won't have a key?
[1] https://archive.nytimes.com/www.nytimes.com/external/readwri...
Perhaps the paranoia is a bit overblown, and is implicitly allowed to satisfy notions that financial market performance is somehow the highest priority or literally reflective of efficiency.
Remember, scores of people are convinced Sky Wizards are literal things. I’ve seen no reason to believe common held beliefs in economics are anything less than qualification without well reasoned checking.
My priorities in life are not a rich person’s financial portfolio. And we can see how they treat each other when these breaches happen. They don’t care and pat each other on the back coughEquifaxcough.
Why should we take such a serious posture if the rich owners don’t?
I don't know how someone getting access to my medical records or locking me out of my email account is related to financial market performance.
>Remember, scores of people are convinced Sky Wizards are literal things.
We know, for a fact, that data is being breached and ending up in the hands of the wrong people. How are you honestly making a comparison to "Sky Wizards"?
Why should we take such a serious posture if the rich owners don’t?
Because it's my f'in data.
You and some other engineers on this forum can conjure all the concepts you want about how to fix it, and the perceived value in doing so, on here in these forums and nothing will come of it. Because by and large the system doesn’t give a shit.
You’re “f’in” data is being bought and sold to bad actors without you even knowing it. And you agreed to that by using these services.
Like you said in another post, the genie is out of the bottle.
The value of securing an inherently insecure society is stupid.
You’re thinking about this like an engineer only and you’re losing and have been for years. There’s no engineering solution to these problems at the technical or social level.
We’ve been fighting fraud since society began. Good luck. I’m sure a hardcore software engineer will figure it out
I have no right to complain if the service I sign up to tells me they are selling my data to 3rd parties. I certainly have a right to complain if the service I sign up to tells me my data is private, then through their negligence someone lays their DB bare.
>The value of securing an inherently insecure society is stupid.
A real live nihilist. Better give up on everything that's broken, eh?
>There’s no engineering solution to these problems at the technical or social level.
No technical engineering solutions to a technical issue, that's a hot take I haven't heard. As for social, luckily we are able to communicate with other humans and work together on different aspects of a problem. Or I guess some people just shit on others, claim everything is insolvable, and ride their high horse into the sunset.
>Good luck. I’m sure a hardcore software engineer will figure it out
Thanks, friend.
Like I’ve nailed you as a self aggrandizing tech bro who thinks he’s smarter and more aware than anyone else and can tackle a problem there’s no social will to tackle in earnest.
Good luck.
Not saying those things are no longer problems, but they weren’t seen as ones until they suddenly became ones.
Like toxic waste, data always finds a way to escape its container. Data wants to be free - just not in the way we originally hoped.
Just like those early fridge manufacturers, we don’t yet know what the long-term effects of releasing so much data into the atmosphere are going to be.
The next 50 years are going to be bumpy as we find out.
[0] Fun fact: the inventor of leaded petrol also invented CFCs. He probably did more damage to the environment than anyone else ever, living or dead. https://en.m.wikipedia.org/wiki/Thomas_Midgley_Jr.
If somebody’s ssn or sexual preferences got leaked and They had their identity stolen, or lost a job, and the rich ceo doesn’t care, you are suggesting that they shouldn’t take it seriously until the damage is proven?
The issue is that there are no punishments for the leaks, not that they are harmless
My poor mom on the other hand doesn't necessarily know what that entails, and what steps she should take.
"Oh, you've got the correct address and the last 4 digits of a social" is no longer acceptable as proof that someone is who they say they are. Something else needs to be in place. Whatever that is, the burden should be on the banks, etc. to develop that and explain to your mom what it is and how it works.
I have no interest however, in further increasing the amount of online shopping accounts I maintain, because that means I have to keep tabs on the shenanigans of even more, highly technically incompetent, companies to know if I've been compromised.
Additionally, I don't understand why companies continue to roll their own payment processing rather than paying a service that knows how to do it. I guess it seems easy...
There are various "financial hammers" these types of breaches will induce, depending on the network (Visa, MasterCard, etc.). Plus, processors (the banks) will put the liability onto Merchants which are shown to have violated thier ToS. Storing PAN's in clear text (or at all in some cases) is certain to trigger one or both of these ramifications.
Fully outsourced payment solutions are a good fit for some business models but not for others.
One thing I would add is that PCI DSS is also applicable for ISO's as well VAR's which operate payment processing gateways.
Whether or not they could theoretically provide a more secure service has no bearing on the monopoly argument because the moment that we accept companies completely destroying fundamental tenets of capitalism (i.e. not controlling a market) because they can do it better is the moment that capitalism truly begins to die. Amazon shouldn't have the power to control the ecommerce market regardless of their security, and the fact that there are people out there willing to make this trade-off kinda scares me.
It's also not that hard to replace a credit card since the industry has been regulated to cooperate with consumers on fraudulent claims. As another user mentioned, password managers help here too.
0: https://krebsonsecurity.com/2019/03/facebook-stored-hundreds...
But why not just assume that your data has already been compromised? It has.
What could you even do with that information? How do you respond when you find out that your data has been leaked?
You’re barking up the wrong tree trying to engineer a solution before society changes laws that would hold the power brokers accountable.
Push aside your keyboard and get out there advocating for legal accountability.
At the same time, those of us around today have been leaked. I’ve been in tech since the 80s, data tapes went missing all the time. One breach in the 90s resulted in tapes showing up in Russia.
Change the laws. Cause there is no stopping it from a tech perspective.
You’re not needing re-sensitizing. You’re needing to think of the problem outside the context of technical solutions.
I said I'm apathetic because this happens too much, and that it is a problem. Where you assumed all the other stuff about me, I'm not sure.
They're putting in systematic regulations to ensure that data isn't arbitrarily kept, it must be secure and the regulations have teeth. It's really well thought out - minimize the number of companies that have your data, minimize the data they have, minimize how long they can hold it for and hold them repsonsible for keeping it safe.
Yet, when these regulations were actually bought in, you can see especially on this forum, that people were incredibly sceptical. So whilst you might think that we need to be sensitive to private personal data, it seems like people disagree when it comes to actually implementing that.
There is very little the GDPR would have done to prevent this.
The data was legitimatly collected from customers. It was leaked because of badly configured server or firewall. The company is no longer in business so no fines (or minimal fines) would be paid.
My theory is that the lack of punishment is intentional for just such a purpose, in a collusion between government and industry to milk all of us for free data about every aspect of our lives, from the past into the future. They're just going to take it.
You see, people won't demand privacy protections enshrined in law if they simply don't give a shit anymore. Companies don't incur liability, people get some free "credit monitoring" service that should be provided by default.
None of this does anything about the leaked data being used to market to you, manipulate your votes, or worse. Then, at the end of the day Facebook et al doesn't have to worry about their contributory privacy violations at all. If you don't want your private messages sold (rented) to every spammer on Earth, what are you gonna do about it? What's the business case for caring on their part?
General rule of thumb for spam email is 0.1% conv rate, so if you blasted this leak list then you'd have 150K sign ups.
There is an entire data broker industry that relies on selling lead/contact information, so if anything there is a value savings on the hack. I've seen high quality contact (and assoc. company) data sell anywhere from $3 to $120.
At this point, I'd join a social network that matched me with all of the people around the world that also used the same "clever, obscure" passwords.
edit: still doesn't solve the issues with the other personal identity problems that comes with all of this... I just want an anonymous payment method. Is that so hard? I don't want any business to ever know who I am.
I would be wary of any service which requires this level of access to your finances. If the offering is determined worth it, at least set up a separate account with your bank which is not "linked" to any others and transfer into it as needed via standard banking mechanisms.
How would a company be held accountable for losing data? Fining them? Paying out to users?
You prove gross negligence, they pay a fine. They prove that they were doing everything reasonably in their power, they don't pay a fine.
Storing PAN's in clear text is a violation of many, if not all, payment networks, be it done by a Merchant or any intermediary. The citation I will show below is MasterCard specific, but should not be considered restricted to that network.
> It's not their fault if they lost a database to a 0day or if they were otherwise doing everything reasonably correctly.
Actually, it very well can be. And, in this case, it almost certainly is the Merchant's liability (fault) due to not adhering to security standards. For reference regarding same, see the MasterCard "Security Rules and Procedures" document's "Chapter 10 Account Data Protection Standards and Programs"[0].
0 - https://www.mastercard.us/content/dam/mccom/en-us/documents/...
...Yes? With the caveat of an investigation and a ruling of negligence... by someone.
Alternatively, create a situation where companies are responsible in perpetuity for damages related to identity theft if a victim's credentials are lost. If company X loses my SSN and then someone opens up a fake account in my name, they are automatically responsible for any costs I incur and I don't have to prove attribution.
The purpose should be to heavily, heavily disincentivize any storage of basic data or PII unless absolutely necessary.
China tired of US putting pressure on Huawei? Bam, start targeting American companies and totally financially ruin them using their own privacy laws/fines against them!
Disgruntled suicidal employee has a grudge? Take down the whole company on your way out with that backdoor time bomb you planted and let the $1.6B fine do the rest!
You may argue that you can't just buy absence of security bugs with money and a different culture, but there are plenty of formal verification tools out there, and they are not all toys. True, verified code is expensive compared to writing "normal" software, which is developed using the same best practices" that lead to a data breach being announced seemingly every other day. But it is quite cost-competitive with "high assurance" software (i.e. software developed when people face real consequences for the existence of bugs) and the techniques have been used to secure a number of nontrivial real systems by now. I have absolutely no doubt (as someone who's in the field) that we would see a huge boost to the state of the art in that field if there were actual money in it, especially considering how much of the current difficulty with using formal verification comes down to the lack of user-friendly tooling.
But, to reiterate, my larger argument isn't really about formal verification; I'm mostly bringing it up to refute the argument that the existence of bugs is something totally outside of any company's control. Ultimately companies are currently choosing not to pay to make their code secure, and it's not hard to see why given the current legal climate of "there are no consequences whatsoever." Ideally, the first step towards fixing this would be for the software development community at large to acknowledge that it is, actually, a choice, but frankly I don't see things happening that way. If a move towards not just safer, but genuinely bug-free (or at least, bug-free outside of hitherto undiscovered exotic side channels) software is going to happen at all, it'll be because a large government drags its country's unwilling programmers and CEOs in that direction.
I can dream.
I like the OWASP content. Google Gruyere is also really nice for xss imho
Pretty big difference to what the headline implies
>161 million records was left unsecured and _exposed credit card and customer card information on at least 60,000 of the ticket service’s customers_.
> Over 59,000 data breach notifications have been reported across the European Economic Area by public and private organizations since the GDPR came into force on 25th May 2018, according to DLA Piper's GDPR Data Breach survey.
Sounds like they really solved this issue!