If you’re required to handle this kind of sensitive information — for any purpose, but I would say this is even more true for anything tied to anything of a sexual nature or anything tied to health — you should take every precaution that that information is secure, encrypted when possible, and that your systems are regularly audited for vulnerabilities.
If the onus of properly protecting sensitive data — whether you’re legally required to hold it or not — is too much or too expensive, you shouldn’t be in that type of business. Period.
And to counter that, the victims are porn actors/actresses, so the perpetrators probably won't face consequences for it.
I'd like to /s this comment, but I'm not sure I can.
The law of having to hold the identification of the models is pretty much the only law you need to uphold. These sites are created from shills of shells.
You have one company, from there you then have two or three other companies which create white label brands utilising one of the shell companies.
So the brand “bangshelia” would be registered with a shell company “adult dating world”. This brand would then be bought by a shill and branded as “purple dating” but registered by a company called “dating purple”.
You would then affiliate with “adult dating tonight” where they would provide the data for your brand.
To get anywhere near close to chasing the company, you need to launch a lawsuit against the active site, (the company registered to) and then the company behind that and from that the company providing the database. Which all costs money.
As my CEO did, you pack up shop on one of those brands and rebrand yourself. Claim your not associated to the previous company by registering another director.
There are no resources available to attempt to make anything secure. The website of the company I used to work for kept all passwords in plain text in a database that was accessible online publicly for other affiliates to borrow to create their own “brand”.
It’s shill of shells. The CEO makes one company, another “investor” buys a brand of the original company and registers it in their name and then sells that on.
That's pretty much a good rule of thumb for, well, everything.
(Sure, there are exceptions. But, there's a reason AWS not only doesn't enable public access to buckets by default, but actually by default has superceding policies in place which block setting normal policies to allow public access; it's almost always the wrong choice.)
> If you’re required to handle this kind of sensitive information ... you should take every precaution that that information is secure, encrypted when possible, and that your systems are regularly audited for vulnerabilities.
None of that solves the problem, though.
You can protect an S3 bucket, but anyone who wants it simply checks it periodically.
Then one day someone is working with the data and changes the permissions to get access, and before they know it, it's downloaded in minutes. It just takes one attacker to get lucky and catch it before your audits do.
And S3 is not unusual, it's just an Internet service like any other, they all have this problem. Even if you have your own data center on a private network, it's only private until someone needs to transmit something and opens a route.
It's ultimately a human problem, there's no magic that can prevent it.
> If the onus ... you shouldn’t be in that type of business. Period.
Ending an unjustified opinion with "period" highlights the fact that you didn't justify the opinion. And it sounds fatuous.
[1] https://en.wikipedia.org/wiki/Child_Protection_and_Obscenity...
Considering that getting it wrong is a federal felony, the incentive set by the law is clear even if, arguably, unintended.
I don’t think you’re wrong, but I would argue that if getting it wrong is a felony, not properly protecting the data should be a felony as well. I realize it isn’t, but incidents like this showcase just how poorly the laws around this type of thing are written. If you can’t properly protect the data, you shouldn’t be in this type of business.
Of course, in this case, this is a site registered in Andorra. So who even know what those laws required in the first place.
What I will say is that just as computers are a force-multipler for getting important stuff done, they are also a force-multiplier for causing harm. As the old saying goes: “to er is human, to really foul up requires a computer”.
This leak did not endanger just one or two people, which would be bad enough, but 4000. Even if the remedy is limited to a fine sufficient for each affected person to change their names and address, it is still a more serious harm than almost anything normal intuition will help with because of how many were involved.
I wish that being in the sex industry was socially neutral for men and women and that nobody would be assaulted or insulted for it. I don’t know why that isn’t the case already, but I do recognise that it isn’t — and given that it isn’t, this leak is still extremely likely to result in someone getting hurt.
It probably should be; I suspect that it's not because making involvement in porn risky for adult participants (and thereby discouraging it), while not the central focus of the law, isn't actually undesirable to lawmakers.
> Of course, in this case, this is a site registered in Andorra. So who even know what those laws required in the first place.
My understanding is that the US applies it's rules to anything of an adult nature sold into or among the US states, regardless of origin, though in practice applying it to foreign entities with little US exposure is difficult; but certainly it wouldn't be the only law that applies, to the extent it might apply.
The law should allow for schemes that prove a performer is legal, identified, etc., but that don't keep individual private details. Even if the site was completely compromised, all the attackers would gain is a single bit of data on each performer. The data would be worthless for personal identification
Store all the identifying data they need to hold onto for compliance purposes plus the user ID in offline storage.
Just like banking regulations that seems stupid, they come from real abuses and a solution to it at the time. I doubt laws signed in 1988 had internet scale and access in mind, nor could they predict it.
This makes me physically sick.
Also, because of face recognition there really is zero anonymity at this point. It would be very misleading to represent to someone otherwise.
Also, there is a very big difference between citing facial recognition tech (which while rapidly becoming more common, is still something that requires a degree of skill to use and has a real cost to using) as a reason for “zero anonymity” and having public records with direct ties to nude photos and videos leaked. It’s even more misleading to represent that these have the same risk profile.
[1]: https://lawofsex.wordpress.com/2014/03/25/keeping-your-recor...
More like the state should not need it at all. Why support even more surveillance?
Age verification and privacy aren't mutually exclusive. The law can be amended in a way to remain effective without exposing people to such risks.
Back when the law was designed data breaches and being able to find everything online wasn't a thing so it wasn't a problem anyone thought of. Now it's time to fix the law to address the new risks.