Facial recognition company Clearview’s client list stolen by “intruder”
thedailybeast.com
thedailybeast.com
"Security is Clearview's top priority," he said in a statement provided to The Daily Beast. "Unfortunately, data breaches are part of life in the 21st century. Our servers were never accessed. We patched the flaw, and continue to work to strengthen our security."
Servers never accessed? Then how was the client list stolen? Was a paper copy stolen from a filing cabinet? I find this posture somewhat arrogant and dismissive. Also, the article is light on technical details- does anyone have info on what flaw was exploited and patched?
I was at a large web dev company where an employee put in his two week notice, then was able to access several of the companies servers and exfiltrate nearly every app or web site they had built in the last two years.
Rumor had it he was using the code to start a dev company on his own and this was the "seed" code that would help him get up and running much faster. AFAIK nothing ever happened to him legally.
Dumbass didn't realize that all SSL traffic was being MITM'd. I never sent any sensitive over personal email from work, being well aware of the practices (also helps to have friends in compliance).
The trick is to use a piece of software that doesn't use your system's certs but has it's own built in, like run Linux in a VM and use that browser. That way, you'll see the MitM attack.
Did Clearview get a picture of the 'intruder'?
>The firm drew national attention when The New York Times ran a front-page story about its work with law-enforcement agencies. The Times reported that the company scraped 3 billion images from the internet, including from Facebook, YouTube, and Venmo. That process violated Facebook’s terms of service, according to the paper. It also created a resource that drew the attention of hundreds of law-enforcement agencies, including the FBI and the Department of Homeland Security, according to that report. In a follow-up story, the Times reported that law-enforcement officials have used the tools to identify children who are victims of sexual abuse. One anonymous Canadian law-enforcement official told the paper that Clearview was “the biggest breakthrough in the last decade” for investigations of those crimes.
They are not. Just don't collect the data in the first place.
I find it hard to justify that companies should not collect any data.. It should just be the minimum required. Such as GDPR attempts.
It's so frustrating that there is no recourse usually. Organising class action suits just takes too long to co-ordinate in a timely fasion that would point a larger spotlight on security.
Clearly...