Ticketmaster confirms data breach with a SEC filing
stackdiary.com
stackdiary.com
Now that’s interesting. Anyone know how they’re related?
The original article was pulled, strangely with no explanation as to why. and to make it even more confusing, Snowflake’s press release is pretty heavy with corporate speak making it difficult to tell if they’re outright denying it happened or if they’re dangling keys trying to buy themselves time.
it’s worth going to the discussion.
Had that happen a few times with my +company@gmail filters that went on to reveal the trail of acquisition breadcrumbs.
If they find it too complicated to keep our data safe then they shouldnt store it and make billions annually trading in our information.
i don’t think it’s unreasonable to expect them to take responsibility for their own actions. either they’re responsible enough to collect our data and use it or they’re not.
Ticketmaster introduces new 'data protection fee' to all ticket purchases.
“Ticketmaster Hacker Demands $500K Ransom (Plus $300K Ransom Processing Fee, $220K Ransom Handling Fee)”
Whole (joke) article is hilarious.
And the DoJ is suing Ticketmaster for being an abusive monopoly as we speak, so.....
[1] Actually, we've known this as far back as Adam Smith! He talked a fair bit of shit about monopolies in The Wealth of Nations. His "invisible hand," after all, was competition, which monopolies by definition don't have.
Remember this every time someone talks shit about capitalism and points to corrupt and abusive American monopolies as evidence of why it's a failed system. America's government only really started leaning into its modern love for monopolies from the Reagan administration onward - in defiance of centuries of evidence that it was a bad idea.
You could argue that they shouldn't be housing this data with Snowflake but then you could say the same about a service like Amazon S3.
At what point is a company able to rely on a third-party vs being expected to run it in-house?
It makes me sad that the initial reaction is gleeful & mean-spirited towards the targets, when if you've ever been involved in something like this you'd hope it would be empathy for what a lot of Snowflake and TM employees are working on this weekend, and anger towards the hackers. It's like people forget that because it's data and the targets are big companies these criminals aren't stealing from real people and making the world a worse place.
I jokingly called then that Ticketmaster got breached. Crazy to see this being actually true.
I need the wretched app to go to a QR code-only concert. Would love to take up a stallman-esque stand against this, but the bands I love aren't getting any younger and neither am I.
Need to show my digital ticket to the steward. Only to find the app has again signed out, spend ages fumbling with my phone and password manager to sign in, while standing in the rain outside of the venue.
Not the seamless experience they promise!
That's easy to program and is very common in apps that produce scannable QR codes that they don't want duplicated, that will only work for the next e.g. 60 seconds.
Any animation that could reliably be picked up by a scanning camera would necessarily be quite visible to the user. Just think of how QR codes often don't even work until you increase your phone's brightness, and they're as high-contrast as you can get...
Too bad nothing will improve because of this.
https://www.theverge.com/2024/5/31/24168984/ticketmaster-san...
[0] https://www.linkedin.com/pulse/nightmare-letter-subject-acce...
- US: https://privacyportal.onetrust.com/webform/ba6f9c5b-dda5-43b...
- Non-US countries: https://privacyportal.onetrust.com/webform/ba6f9c5b-dda5-43b...
[1] https://privacy.ticketmaster.com/en/privacy-policy#your-choi...
https://www.cyberdaily.au/security/10632-hackers-claim-ticke...
And they've been trying for years to get away from all that legacy on to a more mainstream platform. (And for all I know that legacy system is still running today.) But this breach clearly has nothing to do with all that, since it involved a breach of the Snowflake cloud database. So either the legacy system's replacement, or some supporting system.
Side note: Terry Davis was one of the developers of Ticketmaster's OS, before he wrote TempleOS, although they created their OS years before he was hired. He credited working on Ticketmaster's OS as part of his inspiration for writing his own
Ah, All is well then. It has no material impact on your business.
So, the 600'000'000 affected customers can kindly go and fuck themselves?
They have a legal duty to report hacks and report if it will have any affect on their business. And this is what they are doing here. Being outraged because a company does what they are legally obliged to do just makes you angry for no reason.
They'll address the hack to customers no doubt, in a separate email/communication.
At no point did they say the 600M people "can kindly go and fuck themselves" and contorting things to try and get there will just make you angry. If you want to blindly feel anger, you're welcome to, but the company did what they should here.
With nary a word this was fully implied way before they even started collecting customer data.
Companies can have this attitude regardlless of whether there is any data at all.
That is exactly what they said. Verbatim. That's how my brain received it, anyway.
I think the view I’m most sympathetic too is that customer information should be viewed and reported on as a toxic asset/liability to discourage gathering of personal information in the first place.
It's TicketMaster, that's their business model. No need to say it again in this message to the SEC.
- no expected damage for the leak
- no cost for any remediation
- no cost for any legal issue
- no expected cost to ensure it does not happen again
If you believe that they should be impacted then it's kind of a Fuck you.They are not the ones making the law but it certainly looks like they will plainly use the fact that they can continue business as usual with almost no impact.
They cared more about there shareholders than users.
A bit of contrition is required. Not a nice to have. Not contextual. Required.
They are mostly just acknowledging that the general public has "breach fatigue". Nobody cares anymore. It's just another 12 months of free monitoring on top of the others you already have. So now you just freeze your credit until you need a loan, unfreeze it, put it back.