Robinhood says millions of customer names, email addresses taken in data breach
techcrunch.com
techcrunch.com
Now I get an email from them that not only did they not do what I asked, they did indeed serve my data to criminals.
Is there some legal mechanism to compel companies to delete your data rather than this "soft-delete" garbage? Registering an account with a new website these days feels more and more like a stain one will never be able to wash away.
If that is not the case then yes its super annoying how hard it is to actually remove your data from websites.
So ... we're basically screwed with Robinhood.
Email Address Validation is not "yep, that looks like an email address", it's "let's send a confirmation email and have them click on a link".
Please do NOT trust users when it comes to email addresses!
Mint used to send me somebody else's statements. I don't understand how companies in sober industries can be this reckless.
Then there are the peripherals - global db backups with x expiration date, random documents on various cloud providers, etc.
In short, I 100% agree that you should keep your main email (at the very least) off of anything possible.
You could take a copy of the original e-mail and a copy of the notice and send them, with a cover letter, to your state securities regulator [1]. If you want to turn up the heat, submit a complaint to FINRA [2]. If you want to be peskier, and live in California, submit a CCPA complaint [3].
[1] https://www.nasaa.org/contact-your-regulator/
[2] https://www.finra.org/investors/need-help/file-a-complaint
[3] https://oag.ca.gov/contact/consumer-complaint-against-busine...
Yeah, GDPR and California's equivalent thing. Hacker News seems to really dislike it for some reason though.
I guess if you're building a business you don't see it from that perspective, just another hurdle stopping you from moving fast and leaking things
Brokerages are required by law to retain a great deal of records about all of their clients and to keep it for a minimum of at least 5 years. You don't get to just tell a broker that you used to engage in tightly monitored financial transactions that you want all your info deleted as if you were dealing with some kind of social network.
Yes. GDPR (and other legislations basing themselves on this). The US has CCPA if you're in california for example.
Unfortunately, and this applies more or less worldwide, you can't count on this for anything financial. Expect financial institutions to have to legally keep your data for 7-10 years (sometimes even 20). This is one of those cases where soft delete might be the best they can do for you.
[1] If you have a service like Gmail or a service that supports wildcards you just do `name+[blahblah]@` or `name.[blahblahblah]@` to make the email specific to the service you are signing up for. So like `bluetidepro+robinhood@` and then if there is a breach you block all emails that go to that, and change your acct to be say `bluetidepro+rh@` or whatever new one so only legit emails go to the new one.
My understanding is that the use case for these hacks is typically not email spam.
One of my (non-wildcarded) emails has been included in many hacked email breaches, and I've yet to notice any associated spam.
The people who use the + trick are exactly the set of people who would never read spam email, and they're also likely to use the "report spam" feature and lower the deliverability of the rest of their spam.
you can also add extra periods in your name: so something like na.me.blah@gmail... will aso work.
Perhaps it is time to actually train customer service techs?
Get one smart dude to call in pretending to be a customer to "pen test".
Do that once a month, would take maybe an hour or two of the dude's time.
You'll offset the cost of training, and help with employee turnover at the SAME TIME! :D
/s in case it's necessary.
I was surprised to learn how poorly phone reps are paid. Even in America.
I work in healthcare, and when COVID hit, almost everyone in the company had to man the phones. We were all e-mailed PDFs from the customer service contractor with instructions about how to use the soft phone system on our computers.
Since it was a standard new hire packet, the contractor accidentally left in all of the other workplace policies. Some of which were terrible. For example, the phone reps were only allowed two bathroom breaks each day, and they could total no more than 11 minutes.
And this was an American company, with call centers in supposedly "liberal" western states.
Checkmate liberals
Robinhood reminded me of Theranos in that they are ran as tech companies that don't take the usual responsibilities of their respective industries seriously. And their outages make me think they don't take their tech seriously either.
Poor: "I'm rich!"
Robinhood: narrows eyes - "You're what?"
Edit: Oh, this is markdown, isn't it?
I thought the SEC would step in after the blatant fraud that they perpetrated on the behalf of their real customers during the GME debacle.
Now I find out they leaked my name and email after I deleted my account? Is there a class action being formed?
Don’t mean to pile on but this is not a hard problem to solve; it might cost money, require training etc. It’s scary that this could happen to a supposedly financial institution.