Data leak contains 26B records from numerous previous breaches
cybernews.com
cybernews.com
I have gone from feeling outraged to completely numb to these kind of disclosures and have pretty much just assumed that my information will inevitably be leaked somewhere by someone.
Does anyone else feel this way? I just keep a close eye on my financial statements and hope for the best.
And what's annoying is that more and more things now also require phone numbers (like, seriously, in the past an email address was enough but today the simplest thing you want to signup for uses some third party booking platform (which means yet one more party that gets to leak your data) that wants your phone number; even a railway company can't manage its own login anymore. In the mid 2000's I would have thought phone numbers would die and internet would become the new way to communicate but nope, they suddenly became more important instead)
That’s about it.
Since that hasn't happened yet, I try to avoid handing my data over when I can.
The IT and software industries would really change. Perhaps for the better, but perhaps not.
The idea that someone can lose all your data and then pay for two years of identity monitoring is absurd. The people with the data can see that and can just wait two years to sell it. Social security numbers don’t reset after two years.
If you lose data, you pay a data breach tax forever. Over time, your competitors will be able to run with lower margins if they stay secure. As companies die out, the remaining breaches ones are responsible to keep footing the bill.
2. https://github.com/sertoID/
3. https://www.hyperledger.org/projects/hyperledger-indy
The government does not want to incentivize that.
Mention of attorneys general and social security numbers in OP's posting put me in a US mindset.
It was a successful tactic used by banks and credit bureaus to shed their responsibility of proper verification when opening lines of credit or other accounts.
Or it can require ATM, which is not frictionless.
Businesses already ask for phone numbers anyway. Can it become worse?
Pseudonyms don't work for the topic under discussion, issuing credit. And for the general case, since credit issuers would be able to require you to do a non-psuedonym identification, then any other entity can require this as well, unless there were a privacy law.
(no idea what you mean by "ATM")
Because businesses want spammable addresses. That's why they won't ask for properly designed digital identification.
By ATM I mean you use ATM with your card to authenticate yourself. You can't use a smart card with thin air, can you?
I can walk into a shop with a handful of cash, buy an item, and leave without anyone knowing who I was. That should be true of any good or service, including banking, that does not require additional data for direct practical reasons related to the provision of the service, e.g. cleaners need to know where you live. "Prevention of fraud/laundering/terrorism/whatever" is not such a reason.
This is further complicated by US bank accounts including an intrinsic bit of credit from writing checks and other ACH debits.
Banks have notaries of the public. After you have established a relationship with a bank, the notary may have enough evidence to authenticate you for others. If you have continued to use the bank in an anonymous manner, then you should not be authenticated to others.
TWO years?
I have had my data pwn3d a couple of times. One was six months', the other was one year, and Experian used that as leverage to unendingly nag me to buy into them.
I do think we should also push back against surveillance capitalism. This has been a disaster. Such data breaches are a result of this system (and clearly it isn't even unique to the western world). I think any government has the power to hold these companies accountable in at least some form or another. Big dogs like US, China, and Germany should be leaders, but clearly they aren't as this stuff keeps happening.
They issue me a single identification number that can be used anywhere at anytime without any verification or notification that it has been used, and it's next to impossible to get a new one issued.
This is madness. A state funded "insurance" system to backstop this mistake is an unworkable hack that seeks to ignore the fundamental problem.
The problem is third parties abused that number for their own purposes.
Imagine if some company somewhere started using phone numbers as identifiers, and criminals started defrauding that company by "stealing" other people's phone numbers. Would you blame the phone company for that? Of course not.
The problem is that banks and anyone else using SSNs need to do more due diligence than checking SSNs, but they don't want to because it would be expensive and add friction to signing up for their "products".
It goes on.. third parties weren't the worst and they didn't start it and some are required by law.
Imagine if Credit Card companies were as blatantly incompetent and as reckless as the government? The reason they aren't is because they hold most of the liability at all times, and there's a lot of good laws that set them up for huge damages if the make a mistake. The reason the government doesn't care is because no one holds them accountable.
If you have an interest bearing account, you need to provide an SSN, and even though the regulation has since been changed, you needed it for any account for 30 years or so. Anyways, if my SSN suddenly starts being used 12 states away from where it has been the last few decades, _nobody_ notices. The government is the only agency that could and they just don't.
The burden of authentication is not on the entity who issued a simple ID number, it is on those who go on to use it as if it is a secret.
I think your trust in credit card companies is misplaced. The only thing that holds them back is consumer protection laws, and they fight those however they can. Jack up rates, check. Grant credit at a sales point of presence with a minimum wage sales clerk doing identification, check. Sell or trade your payment history, check.
In some moral systems, lending money to make money itself is outright wrong. If you maintain a balance on your credit card for day to day expenses, any financial advisor will tell you to stop that.
> It’s time for attorney generals
Attorneys generalThey are attorneys, so that is the word to pluralize. What type of attorney are they? General
You thank.
LIST OF GENERAL ATTORNEYS FTW!
(SEE HOW EVEN THE ACRONYM AT THE END OF THE SENTENCE FITS INTO COBOL SYNTAX, BEING IN UPPERCASE?)
COMPILE IN A FLASH, DEBUG AT LEISURE.
AND DON'T FORGET YOUR COBOL PERIODS.
Cybersecurity is a sham, a bolt on industry extracting rent out of the mobile internet junkies we've become.
We want to have an endless stream of entertainment and trivia so bad we've actually built homes with locks that connect to the internet. You'd think a networked lock defeats its purpose.
It's impossible to keep a secret on the internet. You can't secure military technology, bank secrets, crypto tokens or prevent piracy.
Computers were designed to be open by default.
General purpose computing mannufactured across the planet with everybody having a hand in the supply chain has become the betrayal system.
Security follows the traditional Mafia protection scheme racket.
- Some Romanian hacker leaks data from your web server and sells it.
- You pay developers to close the vuln.
- You pay cybersecurity a protection fee to prevent it happening again.
- It happens again.
Developing a real technology that can give secure control back to the owner-operator goes against good business incentives. You can't farm users and share the wealth on a truly secure computing model.
No consequences at all. It’s no surprise that patching the holes costs them more.
It’s also that all these massive companies are absolutely allergic to any change. Unless legal gets wind of it everything can stay exposed if it means the status quo is maintained.
You are not alone. It is an __absolute joke__ that my github account is more secure than any banking service I use. How is it that the only 2FA they offer is text message? A method that's been known to be terrible for over a decade now. Where are my OTPs? They give me apps on my phone, why not push verification there? (Vanguard recently started doing this) Why can't I set up hardware keys or public private keypairs? Sure, I get that you still got to service grandma and grandpa, but at least give me something. In today's day and age the two most important services I have are email and banking. The former is impossible to resolve when shit hits the fan and the latter doesn't even implement basic security.
Something is very wrong, and I'm not sure it is even about money (unless short term vs long term). Dinky little websites implement better security than most baking services. Clearly the banks could reduce their spending on fraud detection and resolution if they added some basic security.
I will note that I had a Capital One account that used the card as a 2FA into the phone app. Was neat, other than Capital One was a whole shitshow on its own.
I'm also very surprised at how much spam gets through services like Gmail and Twitter which could be easily detected by Naive Bayes filters. Something is very wrong.
The interesting part is that if I have to do a 2FA SMS challenge, I am required to re-enter my password. At this point the password checking becomes case sensitive.
This doesn't work on my chase.com account.
The banks' understanding of security is so poor that they push people to use voice or fingerprint authentication. My wife constantly fights Wells Fargo about it every time she calls them because they want to helpfully sign her up for their voiceprint service so she doesn't have to use her PIN anymore. She used to work in a retail cellphone store so has heard tons of horror stories of people signing up for the same and then getting their voice deepfaked by a telemarketer to access their accounts.
The OPM data breach was bad. So much data on there about the individuals and a few degrees of association away from them. Every security question and answer are there.
I had 4 data breaches last year and one so far this year I just posted about today that I have no idea how they got my information (0). Mail was stolen by a petty theft and identity theft ring which called to try to get more out of me a couple years ago.
Freezing your credit is the best course of action. I don’t really worry about it much anymore.
Same ideas as with bicycles. Thieves now have sufficiently advanced tools that people stop buying the kind locks that could possibly stop them, and instead just assume that left unattended in the outside, their bike will be stolen eventually, and deal with it. For example by not having nice bikes, or by not biking unless there is a safe place for that bike.
So yeah, leaks will happen. Unless maybe you get a combination of well designed and enforced security standards, harsh penalties for cybercrime, and international collaboration.
Who will lobby for it because /you/ don’t count? Too poor to matter to law makers.
They do win, unfortunately because they're right. Why spend much on designing security when the inevitable breach costs nothing other than bad press for a few days and then all is forgotten.
The only possible solution is to have significant fines for every data item breached.
Ideally I'd ratchet up the fines for each occurrence. First breach should hurt the company financially a bit but not be too disruptive, offering a learning opportunity.
Subsequent breaches the fines go up, by the fifth breach or so the fines would wipe away the company entirely, since they clearly didn't learn.
Anything short of something like this, companies will never care and leak all your data to the wind every year.
Like 3 check chess, but in Delaware.
Well-funded attackers and competing nations are already attacking these companies, so adding their competitors to the mix doesn't change a lot.
I think part of the problem is that hacker movies make people think hacking is inevitable. Like you can’t actually protect your site and your data from the average punk on roller skates, so why bother? But that’s not true at all. Gmail has - as far as we know - never been breached by anything short of a nation state attacker. And I’m sure a lot of people have tried. You just need to actually care about security and follow best practices (like doing audits / red team and keep up to date with security patches). But most companies only seem interested in properly investing in security if it’s an existential threat.
Since the mid 2000s.
I worked very hard trying to figure out how to protect patient data.
To do so requires translucent database techniques.
Which means encrypting all potential PII data at rest at the field level. Exactly like how passwords are stored, extended to all PII.
Which requires globally unique identifiers issued by CAs. Just like RealID.
Nothing will improve until people accept this fundamental technical truth.
Also, on the policy side, PII needs be be changed from an asset to a liability. And ban data hoarding stuff like targeted ads and relevant search.
Then Comcast/Xfinity, same thing. I have 2 options for internet, now, it seems. Comcast or now starlink.
Point is, you can plunk your information into relative bare-minimum of sketchiness -- and you'll still be screwed over.
Fast forward to 2021, apple released hide-my-email which I use practically everywhere which forwards to a burner email just in case. Every site gets a unique email, password, two-factor. I’ll never have 0 risk but this limits my exposure so much it lets me sleep at night. I only provide real information if absolutely required by law.
catch-all email domains just work, thou it's a bit of a hassle to configure the sending address depending on the mua (ios mail grr)
and it's not like it wasn't forseeable 20/40/60 years ago. thou the question remains what would be the alternative?
what really bugs me is the fact that it essentially puts all the 'nothing to hide, have my data' folks in the right because, yea, why bother.
So for me, the title means that this breach is only of importance to the people who want it to be. Everyone else will simply ignore it after 24 hours, just like the first Kuwait War.
https://books.google.com/ngrams/graph?content=the+mother+of+...
a hyperbole that has been used to refer to something as "great" or "the greatest of its kind", became a popular snowclone template in the 1990s. The phrase entered American popular culture in September 1990 at the outset of the Gulf War, when Saddam Hussein's Revolutionary Command Council warned the U.S.-led Coalition against military action in Kuwait with the statement: "Let everyone understand that this battle is going to become the mother of all battles."[
https://en.wikipedia.org/wiki/The_Mother_of_All_Demos#Origin...
(Also you wrote the same message twice.)
Whether or not that is a generally viable or desirable suggestion is a different question, but it is possible as demonstrated by Signal, Apple, etc.
Most things aren't going to work with that model. Can Amazon ship you products without knowing what you ordered? Can you send and receive email on multiple devices without the provider having your email? Can you join public chat groups? Can you view your lab results without the lab having them?
And don't say "the lab can encrypt and send them to you". Your encryption key must be known to the lab, so they can provision a new device for you, in case you lose your phone.
Even the vaunted "WhatsApp and Signal" could actually read all your messages if they wanted to - they have your encryption key after all, all they need to do is deploy a version of their application that copies your messages to them.
So no, it's not actually possible.
Well the whole point of not implicitly trusting third parties would be to remove Amazon from the equation altogether and instead be P2P with the shipper with just a protocol between us. If we need a third party, we can find another peer for that based on the intersection of our trust graphs. It doesn't have to be a global conglomerate with an IT department that we all have to trust implicitly. It could be Jimbob from down the road, who we both trust explicitly--this gets rid of high-value targets altogether.
Particl marketplace is pretty much this (no affiliation, I just like the idea).
Sure, I suppose there's still the possibility that the individual shipper was compromised, but like... Why? It's not exactly a juicy target. There would be no reason to really have a large database of addresses lying around. Print label, ship item, once receipt is acknowledged, delete address.
Nothing you said addressed the uselessness of encryption for this task.
PS. I hope you are aware that Amazon also sells things themselves, they are not just a shipper? And that even if Amazon sells for a 3rd party, you handle returns, etc, via Amazon? So even your singular example demonstrates exactly what I said: this idea would not work.
As for returns and such, that's what the explicitly trusted third party is for: Jimbob. He can meditate disputes because both parties trust him in that domain (or they trust someone who...) Maybe that limits the scope somewhat, but global scale is overrated. Transitive trust ought to get you plenty far.
As for encryption, Jimbob need not know either address to fulfill his role. Encryption is for hiding such things from him (and from the operator of any nodes that are needed to for the protocol to function).
As for not having a design ready for every one of your examples. You've got me there. My point is merely that the space of solutions to these problems which do not require implicit trust of somebody's IT department is larger than you presume, and largely unexplored.
Like, maybe we need to assume everyone's records are leaked somewhere all the time?
I'm not sure what that means in practice but I e.g., am not sure that "identity theft" should be a scary thing if the other side of the system is working optimally.
For that, the US needs to follow what virtually all EU member states have done, and provide every citizen with a government-issued ID card with NFC that can be used to authenticate against a website (e.g. a bank), and browsers would need to agree on a web standard allowing interfacing with such cards (there is Web NFC but it's by far not enough).
The problem is, this is politically untenable in the US for a bunch of reasons - the right wing complains about "big government" and fears a "nanny state" that tracks everyone and everything, and the left wing complains because ID cards cost money and would exclude people without proper documentation.
Additionally, passports don't store your residential address and people don't necessarily want the government to know said address, which means they are useless to banks as a factor proving "person X lives at address Y".
The only reason to keep my name/address/SSN secret is that companies will lend money to a person who has that info, and then try to make me liable for it regardless of whether that person was me. That's a problem, but the solution isn't for me to keep my identity secret, it's for companies to stop doing that.
I should be able to march into some government office, prove my identity to their satisfaction, and give them a private key. Then, if Wells Fargo lends money to someone who can't prove ownership of that key, that's Wells Fargo's problem. Keybase does this fairly well, and is essentially abandonware since the founders were (if I remember right) acquihired by Signal. So, can we just nationalize it or build something similar, declare it to be SSNv2, and move on with our lives?
For all intents and purposes, Keybase was abandoned the moment the team was acquired by Zoom.
It's called a credit freeze: https://www.usa.gov/credit-freeze
- https://usa.experian.com/mfe/regulatory/security-freeze
- https://my.equifax.com/membercenter/#/freeze
- https://service.transunion.com/dss/freezeStatus.page
Ignore anything about “locking” your credit, because this made up term is not the one that has been defined by Congress. “Freezing” your credit is the real action, and it also must be free of charge. The direct links are useful, because the CRAs definitely want to mislead you into purchasing unnecessary services.
Does it really hurt them? Does even the reputation produce any hit on them?
https://www.science.org/content/article/how-many-ants-live-e...
https://en.wikipedia.org/wiki/Orders_of_magnitude_(numbers)
Humans: 8,000,000,000
Trees: 3,000,000,000,000
Ants: 20,000,000,000,000,000More than 3 per person.
In a way, it's miraculous if one's identity HASN'T been used in nefarious ways without their knowledge, yet.
Cries in Canadian. As far as I am aware there is no way up here to have more than one virtual card. Please correct me if I'm wrong.
https://cybernews.com/security/billions-passwords-credential...
The other is just a way for malwarebytes to get some clicks and contains very little information.