Australia gov wants telco Optus to pay for new passports for data breach victims
rnz.co.nz
rnz.co.nz
I dislike this intensely. All kinds of random places are keeping hi-res scans of documents that are perfect for identity theft and fraud. I've tried suggesting that looking at the passport should be sufficient to verify my identity -- they don't need to make a copy of it -- but I've had no luck.
Has anyone had success at pushing back on this? Are there laws in any country that say that you can't take photocopies or scans of customers' passports?
Also, high-resolution scans of passports are not a new thing. They were already pretty common in the late 2000s. The biggest change from then is that hotel employees are now more likely to be comfortable with electronic documents than paper copies.
Unfortunately there's a disconnect here for what it's used for.
If that page is treated as public information, then information on it can't also be used for the 100 Points of ID that public and private organisations want.
The document number on my passport is enough to get a credit card with a high limit in my name, sent to an address that's never before been connected with my identity. Maybe some more conservative banks will want the address to match.
That information is precisely what was leaked by Optus.
A house booked and paid through booking.com wanted me to email them a copy of my passport. I said no, but they could see it in person when I arrived. When they arrived they wanted to take a photo of it. I said no, then, too.
They were really quite unhappy about that, and claimed they've had people stay on fraudulent cards before, and this was the only way to protect themselves.
Employers doing things like SOC2 are also wanting to go through third party background-check services. All of those also want things like selfies and scans of passports. They all claim the same "We delete it after the check is complete" thing, too, which I don't believe.
If you accept perfect security is impossible (everyone should) then anybody creating data retention laws (ie: the government) really has to also assume some level of responsibility for the risk that the data is going to leak.
That said, yes: government legislators and regulators have been zealously telling private companies to hoover up sensitive PII for years. Here's ACMA's rules for customer auth for telcos: https://www.acma.gov.au/customer-identity-authentication-rul...
There are efforts underway to enable complying with these rules _without_ hoovering up data, but they are not progressing nearly as fast as they need to.
It kind of does. If Optus hires worlds most competent security person, the first comment on this subject would be "there is no commercial or technical upside to storing this data, and massive risks if it leaks. We should delete it immediately".
If the government swoops in and bans them from fixing the problem, it is a bit weird for the government to also penalise them for not fixing the problem. Optus is legally barred from putting an engineering solution in place to remove this risk.
Literally the only two outcomes here for Optus are:
Option 1 - wasted storage fees.
Option 2 - international scandal.
They aren't allowed to pick any other option. It isn't fair to get angry at them for a rather predictable outcome of spreading PII around. Sure with hindsight they could have done a better job of sticking to the first outcome, but seriously if they had the choice it would have been option 3 - take money, ask no questions. Maybe store a credit card number, maybe just use Paypal like a normal merchant.
Anyway, point being, this is demanding Optus be good at something they never signed up for, don't want to be good at. It really sits with the government to decide how the data should be stored and to taxpayers to stump up the money to store it. Optus shouldn't be lumped with this sort of silly responsibility. They don't want it, don't need it and apparently aren't good at dealing with it.
Define quickly, what does the rule say? Is a day not fast enough?
> Anyway, point being, this is demanding Optus be good at something they never signed up for, don't want to be good at.
They already should be good at protecting data. This is making them protect somewhat more important data than they otherwise would, but it's not demanding any new skills.
And we need to put other companies with terrible security on notice. I think the only way big companies will move is by making their executive team sweat money.
Thats how it works everywhere else in the economy - if your negligence causes harm, you're liable. Serve bad food in a restaurant? Sued. Sell sporting equipment which causes injury? Sued. Misrepresent yourself? Sued, and potential criminal charges. Medical malpractice? Sued. But somehow, if your sloppy software causes harm thats ok? What rubbish. Security malpractice should bear the same punishment as everything else.
Maybe the price of paid software will go up. Thats fine. Maybe there aren't enough qualified security engineers. Also, fine.
If you don't have the expertise to manufacture a safe car, we've decided you can't enter the car business at all. Likewise, if you don't have the technical skill to keep my data secure, you have no business storing my data at all.
When you really think about it, that is a VERY scary thing.
Quite literally it goes:
"If I do this illegal thing myself, I'll get in lots of legal trouble."
"If I form a company and do the illegal thing, I'm safe."
I think the limited liability is for debts to creditors and shareholders, rather than limited liability against criminal or other behaviour.
Maybe I’m wrong, but as I understand it, Australian law treats a corporation as a person and the directors are answerable if the corporation breaks the law.
The real problem (as I see it) is that a company the size of Optus can afford to defend their behaviour for so long that enforcement itself becomes a burden. The closer you get to the CEO and board, the more they will spend shareholders money defending themselves.
Actions without proportional consequences were never going to lead to anywhere but destruction. Folk psychology told us that was likely (however much virtual-economists feigned ignorance). Empirical reality has confirmed it.
In cases where there is intentional wrongdoing, existing laws already make complicit people liable both to civil action by people harmed, plus criminal or civil penalty provisions by ASIC (or the ACCC, depending on the industry and conduct). As a plaintiff, you typically join them to increase your potential pool of recoverable assets for your clients.
The same is true if there are breaches of the Australian Consumer Law, and the person has a particular level of knowledge that is below intention.
In cases of pure negligence, like this, if the negligence rises to a criminal standard, then criminal laws and penalties already apply. How and when this works has been a topic for over 50 years, since Tesco v Nattrass in the UK.
In other words, there are already very significant legal mechanisms in place, and by and large they work - and not all of them involve having executives personally liable. In any event, many already do, and this has been worked out carefully over a long period.
This breach happened through a non-production system. Shock. Surprise.
There's no such thing as non-production/production systems imho, as long as it exists, it's a system requiring security checks and protections.
From a security point of view I agree - certainly my current employer makes no distinction and a vulnerability is a vulnerability no matter where it is.
Strongly disagree. If it's an isolated copy of your production system with fake credentials, fake data, etc, there's no associated risk. We explicitly turn off various security checks in our nonprod environment because it makes it easier to poke around and debug issues. That would never fly in prod, for obvious reasons.
If that’s truly the case, and they’re fake data, I’d generally agree. That isn’t what’s happened with Optus and I dare say with many other orgs where nonprod is generally interchangeable with less secure
Anyway, a key point is not to have a network design that's like a Poland where people can just drive across it with little effort. That goes for developers and hackers. It should be organizationally hard for a developer to request to connect a test application to a production system. Change control should automatically put that as a ticket for review and the network team should also be cagey about doing it. It was a big oversight.
The mixing of personal data back into a insecure test system is also a bit iffy. If you think about classification for government secrets, sometimes a large volume of low level data will attract a high protection. Because it's loss represents significant harm.
Optus should have seen it's database of client secrets as a top secret asset and guarded it as such. The release of this information is having profound impacts on many governments, and government systems as well as the individuals (50% of Australia almost).
I think we are still too accepting of non technically literate CEO's. They don't have to know how to solve all the issues but they should know to be very very curious about their IT systems. And this is a telco!
Imagine you're a project manager at a telco, and you are given a project to make a network link from a capital city to a nearby town. You hire some contractors to dig up the dirt, lay down the fibre, put the dirt back in, and then you are done. The project is finished! The budget is spent, and then there is no more money, and nothing to spend it on anyway.
Fibre does not need security patches. Fibre does not need monthly updates. You can simply forget about it, because it doesn't have an end-of-support date. Copper will eventually corrode away and need replacing, but we're talking timescales on the order of 40, 60, 80 years or more, not 4-8 years like in the software world.
Those project managers get promoted, eventually to senior management. The whole budget starts revolving around this short-term, "done and dusted" type projects. Nobody at any senior layer of management develops an expectation of anything else. You deploy things, then you move on to the next project! MOVE. ON.
The same people manage IT and software, but this is a relatively new thing. Certainly a new scale to these organisations. I've been in telco "data centres" 20 years ago, and they were... cute. Just a big office room with maybe two dozen racks in them, the majority of which were optical switching gear.
Now? Telcos might have thousands of virtual machines running tens of thousands of distinct pieces of software. Software deployed in projects run by the same project managers that were used to laying fibre and walking away.
This kind of breach is the consequence of this corporate culture. It's not just the CEO, it's also the COO, the CFO, the CIO, and all the way down to all but the last tier of random befuddled contractors wondering why they're not allowed to touch anything that's not actively being built new.
Don't think for a second that any of the other major telcos are any different or better.
Also security is not one dimensional. A system's required level of confidentiality might be very different from its required level of availability. Being explicit about this might be better than trying to lump different requirements into a "production" label.
The usual way around this is via a class action, and there are already at least 2 being prepared that I know of. They will run and probably settle at some point. The main thing to be policed is to avoid the funders and solicitors taking too much of the proceeds, although that process is already in hand due to recent abuses.
Not to diminish Optus' responsibility here but I think the Australian government should carry some of the blame for imposing this requirement.
I had activated a pre-paid Optus service (in a store, using my drivers' licence as ID) but let it lapse a year ago, and allegedly my licence number was not in the breach.
I never used the Optus number and I have moved since then. So maybe impact is minimal. But I'm still angry.
No. Or perhaps yes, but only in part. Our laws need to be updated to make corporate malfeasance in general an existential threat to executives and board members, as individuals. Ordinary Aussies end up in jail for unpaid parking fines. Centrelink 'customers' (ugh) get robodebted, often into depression, sometimes to death. The "law" rules us plebs with a rod of iron, and wields it with abandon. Heads of industry get away with pretty much anything. If they want to skirt a law, all they have to do is shove fines on balance sheets. Those fines can be in the millions or billions; they're just another business expense.
Suits in jail would change the so-called 'incentives' (myopic concept though that is) dramatically. "More suits in jail" should be the catchcry of the next few generations. Every T shirt. Every graffito. Every pop song.
Of course to really fix this stuff we have to go after 'investors' and eliminate the absurdity of limited liability ("gamble on destroying the world and risk only your stake!"), but that ideology is now so culturally rigidified it would require a collapse of 'civilisation' to eliminate. That may well be coming of course.
Honestly I trust my data with Optus way more than a company that can't build a secure MyGov app where my tax and health info are stored.
Imagine a car company which sold cheap cars that injured people. "If we fine them for their actions, the executive team will just raise prices or fire employees!". Yeah - maybe don't sell a car thats so cheap that it causes accidents.
Certainly it would be much more effective than the system we have now - where their negligence seems to have had no negative consequences for the company.
But if you're suggesting there should be personal liability for CEOs as a result of data breaches like this, then I think I could be convinced.
"Nobody wants to be the CEO at the helm when a successful company was ruined"
Are successful people really concerned about pride? I always thought it was money and I'm not being sarcastic. I tried to find some data to back this up but couldn't. However as an anecdotal example Henry Ford II was the CEO/chairman/president from 1945 to 1980. This includes the period where the Ford Pinto (70-80) existed and received huge amounts of negative press. It's also when imports were started to take a major toll on American car manufactures (late 70s) The only reason he retired was the mandatory retirement age at Ford.
To fix this I think we need to ignore punishments for now and focus on prevention. A government agency, funded by fees, should do yearly audits on companies that have more than X users or some other variable to confirm compliance.
And yes, Boeing has this but they were too chummy with the regulators and this and that. Even though it's not perfect it's a first step. We can fix the problems similar to what came about in the aerospace industry later.
Fortunately we're able (in South Australia) to get our drivers licenses changed over free of change if impacted, which I'll do but now that's something else I need to get around to doing... I wonder how many of these costs will be forwarded on to Optus on behalf of the goverment
edit: hn is rate limiting me but like, any phone number? you need id even for a prepaid one? and why do they need to keep this on file?
https://www.sa.gov.au/topics/driving-and-transport/licences/...
This means using a Drivers License / Proof of Age card is functionaly equivilant.
There's a bunch of places where they've got some sort of ID requirement that only accepts either a licence or passport.
There's a really big assumption in this country that you must have a driver's license, and if you don't well then difficulties arise.
This is the SA version since GP is from South Australia, all other states have the same thing too https://www.police.sa.gov.au/services-and-events/100-point-i...
If the Australian Government actually goes through with its threat to make Optus pay millions to cover the cost of the damage its lax security has caused then the idea may catch on elsewhere.
It seems to me that at the risk of going bankrupt over a breach of its customers' privacy a company would want to divest itself of as much information about its customers as was possible.
Wouldn't it be great if that were to happen.
+1 super hope equifax finally has to own up to their damages on society (on many levels, including beyond data breaches)
I mean I hope the Government goes after that Service NSW Data Breach too. Would be cool to see huge fines put to them. Would I get some of my tax back for that?
People should 100% sue, but that the Gov says anything is laughable.
"We are outraged.".. "Didn't you have a breach last year?".. "I said we are outraged. Don't look over there. Look over here."
Likewise, but I won't hold my breath whilst waiting.
You can then select the businesses you would like to forget about you and Mine will send pre-written emails on your behalf and monitor for replies.
The experience has been enlightening. This is what I've found after sending 50ish requests:
- A small number of businesses already have a process in place to deal with such requests and action immediately without further correspondence
- Others ask that you fill in a form (pdf or web) to start the process
- A large number won't get back to you for around a week or two and eventual responses appear to be written by a person
- A small number tell you the can delete some data but not all. e.g. Compare the Market. In the past I've used compare the market to purchase insurance products, that sale is linked to my personal details and so they can not delete. I'm not sure why this is the case. Maybe there are compliance reasons but it is a little worrying that these middle-men companies that live on commission either can't or won't erase my data.
The big one that's been mentioned in other HN threads on this is Car Rental companies. I made it a priority to deal with them first. They have all manner of sensitive information and their size, tenure and CX don't instill me with confidence.
Why waste 100 hours of my own time, minimum, going through my hundreds of thousands of emails adhoc to find examples like receipts from 10 years ago from an obscure ecommerce site?
"Optus is not aware of any security events which would warrant revisiting the security obligations imposed on regulated entities,” the telco’s submission stated."
Despite concerns that data retention could create a ‘honey pot’ for hackers, telcos already had in place security measures to protect customer data they already retained for commercial purposes, the department argued.
“Given this, it did not follow that the proposed data retention scheme presented an unmanageable level of risk to customer privacy,” its submission stated. “The evidence to date supports that the existing data security arrangement have been effective.”
https://www.computerworld.com/article/3458462/data-retention...> Data retention: Government gave Optus ‘exemption’ from encrypting metadata
> Editor, Computerworld | 17 JULY 2019 6:46 AEST
> Optus says that it would have struggled to comply with its legislative obligations without a decision by the government that exempted it from a requirement to encrypt all metadata collect as part of Australia’s data retention regime.
The government 100% has some responsibility in this. I can’t express how much this pisses me off, and I’m not even an Optus customer. The OAIC, it turns out, is a farce.
I wonder if this is actually intended to be an "ask", or if this is polite language for "we will legally compel them to".
>Passport numbers are among the personal details accessed in what the federal government has described as a "basic hack".
>Optus says the data breach was due to a "sophisticated" operation.
It would be good to know more details of the hack itself.
These are all really good questions.
Knew a guy who used to work for Optus, he said their business SIP service was constantly getting hacked and their strategy for dealing with it was just to eat the losses and give out account credit like water, because their infrastructure was so outdated and poorly designed that it was functionally impossible to secure.
Honestly, Ausgov should rip Optus to shreds for this... not only for the data breach specifically, but also as a critical infrastructure operator they should be held to a far far higher standard than an ordinary business.
Companies should only collect data that they really need. One way to encourage this behavior is to punish them when a breach happens based on the amount of data they collect.
A data breach on a service that only has an email address on it matters a lot less to me than one that has my name, phone, address or picture of my id.
Collecting and keeping this data is a regulatory requirement for Optus.
The problems with this breach have their roots in how identity is proven and verified in Australia. Far too much relies on possession of a physical document.
Here are the ID requirements for their major competitor, Telstra: https://www.telstra.com.au/support/account-payment/id-check-...
These are legislated: https://www.legislation.gov.au/Details/F2022L00548
That doesn’t stop these companies just going for the big ID though, and for postpaid they are offering credit and will definitely require 100 points of ID.
The ACMA determination is pretty hard to parse unfortunately.
https://www.comparitech.com/blog/vpn-privacy/sim-card-regist...
US Senate tried to pass a similar law back in 2010. Bill sponsors were Chuck Schumer and John Cornyn, in case you ever see those names on your ballot.
Then they detained an innocent person for the longest time without charge in recent history, including solitary for 23 hours per day, and not letting him access legal advice or contact his family, because terrorism.
Not much but there's this article from the ABC (Australian Public Service broadcaster) https://www.abc.net.au/news/2022-09-23/optus-rejects-claim-h...
QUOTE STARTS
"[They] wanted to make integrating systems easier, to satisfy two-factor authentication regulations from the industry watchdog, the Australian Communications and Media Authority (ACMA)."
The process allegedly involved opening up the Optus customer identity database to other systems via what's known as an Application Programming Interface, with the assumption that the API would only be used by authorised company systems.
QUOTE ENDS
Also this one https://www.theregister.com/2022/09/23/cyberattack_optus/ although it's six days old.
This is a summary of the statements made by Optus https://whirlpool.net.au/wiki/optus_sept_2022_breach .
There's been some chatter on Twitter that at some point an Optus flack characterised the attack as "sophisticated" because the attackers "used Postman" so that's obviously caused a few laughs https://twitter.com/search?q=optus+postman+until%3A2022-10-0... .
It sounds like a convenient caveat to an agreement to pay ransom to the hackers, and I wouldn't put it past a big company here in Australia to pull that kind of PR trick.
We live in the Lucky Country after all, I doubt we'll ever know the truth.
ASD and ASIO have despised Singtel since they bought out C&W in the late 90's and want them out of the country. This whole media fiasco is a blessing for everyone. Might be able to finally cancel their carrier licence.
In Israel you use your ID number, if a citizen, or passport number if not, in tons of transactions (as a citizen it somehow flows to your yearly taxes, not sure exactly), even stuff as mundane as getting gas needs an ID number.
If passport numbers are meant to be secret I suspect a lot of people are in for a rude surprise.
Yeah, 2.x% sounds like a small percentage of the ~10M records.
It's still 2.x million people's records.
Also the 2 million number was what I had heard in the news, seems the number is actually 3.8 million records having a document number, according to this screenshot[1]
[1] https://www.abc.net.au/news/2022-09-27/optus-data-breach-cyb...
Post-paid generally is a lot stricter e.g. most telcos want 100 points of ID with at least one primary document such as driver's license or passport [2]. Not sure if that's a legislative requirement though, or just good business practice.
[1] https://www.acma.gov.au/acmas-rules-id-checks-prepaid-mobile...
[2] https://www.telstra.com.au/support/account-payment/id-check-...
They won't let you open a post-paid account if you've got a history of non-payment.
So about 1-2%.
All sims need personal data - otherwise overseas could be a loophole to get a ghost sim.
Do all countries require a ton of personal info to get a sim?
Why do we accept it as a given that the government must know who owns a phone? Is this necessary?
Can telcos do sufficient KYC without?
(Edited)
What more could they possibly do?
This is probably the end for Singtel in retail telecommunications in Australia, and I don't know who would buy their network now that TPG and Vodafone have merged. They may just convert it to a much smaller wholesale only operation.
When the data companies want on you becomes a liability in case of data breaches, one of 2 things will happen:
1. They'll drastically improve their security
2. They'll stop asking for a lot of data just because they think they might use it later or because they want to sell it to others.