Crooks threaten to leak 3B personal records 'stolen from background check firm'
theregister.com
theregister.com
> If you are a California, Virginia, Colorado, Connecticut, or Utah resident, you have the right to request that we delete personal information that we collect about you, subject to certain exceptions.
I think it's time to require this on a national level. This is getting ridiculous.
Does anyone else feel like we are slipping into a Dark Mirror episode? I fear that nothing will be sacred soon.
Here's an example: https://news.ycombinator.com/item?id=17154971
Specifically, the EU's teasing out an effective definition of consent is paramount, otherwise the only thing a US privacy law would mean is a few more paragraphs in the bullshit legalese "terms" that nobody reads. Frankly I think Congress should just import the text of the GDPR wholesale and let the courts sort it out. I doubt the outcome could be any worse than what surveillance industry lobbyists end up doing to domestically crafted legislation.
Utah is a small state, the EU dictates how a free market should work across 27 different nations with a variety of laws, 88 pages doesn't seem much to cover for that.
I think the companies collecting personal information assume they have more entitlement to it they they actually do, and are on the wrong side of the law - especially when breaches like this result in real damage. I'd like to see a few really harsh class action lawsuits bite them in the ass and leave behind bad enough scars that other firms begin to see personal data as a liability not as asset.
Opt-in by default.
And then if I want me some spam, I'll ask for it.
How would you have known to opt out from your data being retained? Were you aware of this site before reading this article? I know I wasn't.
That way, there's no financial incentive to make it hard to claim damages, and people won't need to bother filling out a form every few weeks to claim the cash.
They would just fold the company and start another? Most data brokers do not have 3 trillion dollars.
I already pay taxes; why not have the government do their job and protect my digital information and fine the companies and their executives so they learn to care about it. The government allows the corporate barrier to be pierced if employee salaries are not paid.
Stuffed down the memory hole. Before Reagan board members were liable for unpaid non exempt wages. If a company went bankrupt owing hourly workers back wages the bankruptcy court could liquidate the boards assets.
Regs are rarely ever meant to actually favor the average citizen over the corporation. Just look how quickly the consumer protection agency was killed.
But... you had to supply a credit card to enroll.
And... after six/twelve months they'd automatically roll you over to their highest tier plan, and start billing you.
It might as well have been a promo scheme.
Unfortunately, companies are incentivized to treat personal data like something to be aggressively gathered and hoarded instead... but not necessarily like something to be guarded against leakage.
All that information is essentially semi-public these days for nearly all US citizens. How is this still allowed for KYC purposes?
KYC in an environment where all the data points are openly available looks very different.
I get that we can determine if it was a human being with some acceptable level of accuracy, but what actually matters is that it's the right human being. How does a liveness check solve the problem of these numbers that are used as passwords being de facto public information?
Fingerprints and iris scan in person?
Government issued smart card?
Accepting fraud as a cost of business?
Or just no service to person you don't personally know?
For the first three decades of their existence social security cards expressly said they were "not for identification". All the way through 2011 the first three digits of an SSN were a geographical code and the other six were assigned in a predictable sequence, which means that for any SSN from before 2011 there's an entirely deterministic inc() and dec() function that can be used to derive new, valid social security numbers. This also means that any typo most likely ends up pointing at another valid SSN (no check digit).
My credit card has better security characteristics than the card that they used to identify me in order to sign me up for the card in the first place. That's absurd.
Instead you've got governments requiring a mere copy of the document as proof, because fuck logic.
Or in the case of the U.S. such a document may very well not exist, because I'm pretty sure SSNs aren't remotely designed to be checked for authenticity.
I haven't been on the verifier side of this, but I did have a neighbor participate in a passport verification system for a new remote hire job, as the verifier.
According to him, there was some basic information listed about how to verify it was an authentic US passport.
It'll be curious if we see a move to more forgery-resistant documentation being used for KYC (e.g. passport, RealID DL, etc), coupled with in-person verification (even if something like lawyer-drops-by or go-to-notary).
You're good, perhaps! The rest are opted-in for a data leak.
If society appropriately disincentivized data collection, we could even get to where companies don't see customer data as an asset instead more as a liability.
Which means going to a different layer / structural solution maybe. How does the value of data go to zero?
I might end up paying extra because my insurance company decided I didn't fall into their 'lowest risk' bucket because my background check came back as "we have never heard of this gal" because I once used a data privacy protecting service or they can't find my facebook/linkedin/twitter.
There is easily a 10x difference in insurance prices between "known good customer" and "probably fraudulent customer" - and that difference is the difference between being able to own your own house (with mortgage to begin with) and renting for life.
Most people would value owning their own home over having some computer system using their data to select one ad over another.
If people were routinely getting gauged like this for trying to opt out of something, there would be a pretty huge story in that and I doubt it would go unreported.
Rinse. Repeat for loans a half percent to a full percent higher than my credit score should otherwise get me.
Sounds like a pretty awful way to live. Honestly I'm shocked to hear such a conformist and timid opinion uttered in a forum called Hacker News.
Even if you play the 'actually this is a VC connected corporate forum' what sort of entrepreneur lives by this sort of preemptive self censoring?
Why would them using false identities be any different? Why is it MY problem that someone else stole from a bank? If they wear a mask with my face on it during a physical robbery, does that mean I'm liable?
Sounds like capitalism is functioning as intended...