Covid Test Data Breach: 1.3M Patient Records Exposed Online
vpnmentor.com
vpnmentor.com
For anyone considering DIYing a diagnostics program, don’t. But I’m biased (I’m the founder of a YC-backed diagnostics as a service co: https://spotdx.com)
Only during the process you get exposure to a lot of other things (and a lot of that is not government).
My original post is referring to other things outside of the Ministry.. My role was deep and broad so I got to see a lot.
-> ""The exposed certificates and other documents were all marked with the name and logo of Coronalab.eu. Although the website appears to be offline, Coronalab is owned by Microbe & Lab, an ISO-certified laboratory based in Amsterdam, Netherlands. According to the NL Times, “CoronaLab is one of the two largest commercial test providers in the Netherlands”.""
the list of hacked SSO providers gets longer by the day.
This said, banks have specific fiduciary responsibilities and the above-mentioned insurance, which compensate for the big target they're painting on their own backs; whereas most tech services, even massive ones, tend to hide behind service agreements boiling down to "eh, if it happens it happens, nothing we can do, sucks to be you". Unless they're in healthcare, they're barely required to disclose whether they've been breached, let alone compensate us for the loss of privacy and increased risk of identity fraud that we endure.
Maybe it's time for the legislator to define "personal data providers" a bit more rigorously.
The problem is even worse than that. The whole framing of the issue of identity theft as a thing that happens to a person rather than a bank is problematic. That the bank issued credit in my name to someone other than me really should be entirely their problem, not one that probably messes up my life for years.
The one thing making a copy is supposed to achieve is prove that someone saw the original. But what's important is not what was on it, but who saw it, where and when and whether it was valid. This doesn't require knowing what exactly is on the document, and a mere copy achieves none of these.
What grinds my gears is idiots in the Dutch government who should know better and decided to write into law that a copy or transcript is sufficient proof. So now everyone is storing lots of sensitive information to prove something the information does not show.
It's silly. AT&T wanted it from me to add a phone on a business account that was shipping to our physical address, which has not ever changed since the account was opened. eBay wanted it (and my SSN! and my wife's!) despite our account being a business account registered with an EIN and connected to a business bank account. Instagram/Facebook/Meta/whatever wanted it to reactivate a dormant account that talked to a still-valid email address to which I had access.
Me neither. But they normalized this behavior when moving to mobile apps for netbanks by requiring people to photograph their IDs and take selfies for KYC.
After all this KYC stuff, photographing personal documents became normal and then many other big tech companies started requiring this stuff. I think even Facebook started asking people to send pictures of IDs to verify accounts. I know phone companies in EU started doing this.
I still refuse doing it for all these trivial services and it has a real cost in that it prevents me from using several services. At some point I will probably have to do it.
In my country, we recently had a real estate agency who got hacked and had all their KYC stuff exposed and sold for ID theft. It is a huge mess. The company then reached out to all the persons that were affected by mail telling them that this happened and that they should contact them immediately. So I contacted them. First step when contacting them was them requiring to prove my identity by sending photo of my personal ID again. Yeah, fool me once....
Ironic about the first step in resolving KYC ID leakage being acquiring more KYC ID images...
https://www.justice.gov/usao-ma/pr/ebay-inc-pay-3-million-co...
Ideally, the people we pay to represent us in government would actually represent our interests and that'd be how we deal with things like this.
if authorities stop demanding that everyone takes copies of personal IDs
They're actually considering the opposite for social media.If some company does not want to unsub me, I just turn off that virtual card.
I’ve defaulted to picking random passwords for most services which I don’t bother to remember instead using password resets. But it’s inconvenient.
Additionally, connecting devices to the internet directly or indirectly should have the same sorts of responsibilities.
Banks have this dialed in, it's called a "personal guarantee"
You lose our money, you're personally bankrupt
Pretty well aligns the incentives
Find something comparable for data, no question the problem will improve
I'm in the industry and even I don't have an actionable course to take.
Breach is not the word I would use here.
Insurance might decide to not cover you for not having a minimum level of control in place, but you are still a victim of burglary.
I'm making no judgement on whether that approach was a net positive or negative here, but the writing was on the wall from day 1 with regards to data security.