Breach affecting 1M was caught only after hacker maxed out target’s storage
arstechnica.com
arstechnica.com
The problem with most of these hacks isn't usually so much that the hacked system itself has lots of valuable data, but that the data from the hacked system can be used to hack into other systems that do have valuable data. Just like we tell people to only use a different password per-site, we need the option to essentially give only tokenized versions of our data to third parties. We've started somewhat with tokenization in place of credit card numbers, but we should be able to do this in many more areas.
There are obvious difficulties here regarding how we'd handle certain fields (e.g. how do I calculate your shipping if I don't know your exact zip code), but these should still be solvable problems.
The alternative of believing that every rinky dink (or non-rinky dink) site out there will be able to keep your data secure is laughable.
Forget calculating shipping; how do you ship me my product at all without me giving you my address?
(A quick napkin sketch would be that I wouldn't, I'd give you a USPS reference number, which you could use to calculate shipping costs as well as actually mail me a thing; only the USPS would be able to link the reference number to my physical location. There's almost certainly problems with this idea, which is why it's a napkin sketch.)
Main difference of course being that you want the ability to generate a unique "PO Box" per merchant.
Of course, there is a 3rd party (the post office in this case) that would need to know the mappings between real address and "reference number", but even in the case the post office got hacked at least they would only get your old mappings. Any new purchases would use new reference numbers.
Along with some form of digital cash analogue (i'm not sure existing crypto is it), we'd be getting close to restoring some privacy in online transactions.
These breaches are the personal fault of many of the people who frequent this site. As the FTC says - the first step here should have been not warehousing data they didn't need for their business purposes. Which is the mandate of GDPR as well.
I've seen many smart developers accidentally log a request in an API that also happens to show the login credentials.
https://krebsonsecurity.com/2019/03/facebook-stored-hundreds...
https://www.theverge.com/2019/3/21/18275837/facebook-plain-t...
https://arstechnica.com/information-technology/2019/03/faceb...
https://www.wired.com/story/facebook-passwords-plaintext-cha...
storing these in plain text violates PCI-DSS
"... stored consumers’ personal information, including consumers’ SSNs, payment card information (including full or partial credit card and debit card numbers, CVVs, and expiration dates), bank account information (including account and routing numbers), and authentication credentials such as user IDs and passwords, in clear, readable text on InfoTrax’s network."
I hacked into a server. I wanted to take a copy of everything so I made a tar of / to wget it to computer later. Only that the disk was at >50% usage so I filled it by making the tar file. Everything stopped to work with 0 bytes left of disk space (I wasn't root) so I kinda bricked the machine. I had to walk away in shame.
So I rebooted, and tried it again. Same result.
Eventually I figured it out.
No, you'd have walked away in shame if you had walked away in handcuffs. Don't do stupid stuff. Imnsho you got lucky that disk filled up before you could notch up a(nother?) crime.
Do something more useful with your time and skills.