JPMorgan Says Data Breach Affected 76M Households
bloomberg.com
bloomberg.com
I could see that.
Or am I just off in my understanding of fraud protection?
[1] https://www.schneier.com/blog/archives/2009/08/small_busines...
That kind of information is nearly public (not that it's OK but it seems a lot less damaging).
If more was, it would be good know.
User contact information – name, address, phone number and email
address – and internal JPMorgan Chase information relating to
such users have been compromised.
I have multiple personal and business accounts at Chase, and they collect a shitload of other "internal information", way beyond name, address, phone and email.Ostensibly for KYC [2] they try to collect personal information about the other members of my company, non-public information about my company's revenues and customers, my work and professional history, business plans and projections, my kids' college plans, real estate holdings, interests in other businesses, etc., etc., etc.
They're very pushy about gathering this information, claiming it's for regulatory compliance. I'm sure it's mostly for their own attempts to hawk their lame financial products.
So that category of "information relating to such users" could be ginormous.
[1] http://investor.shareholder.com/jpmorganchase/secfiling.cfm?...
Only have a couple of recurring bills with the card and don't generally use it at stores, so I'm pretty confident that it was due to the breach at Chase. My biggest concern is someone using the other information they stole to open accounts under my name.
If stealing card/account information was their goal, there are a lot easier ways to do it. Any time you use your card at a non-official ATM, put it down to pay at a restaurant or even not shredding any mail with account information, you're putting yourself at risk. Heck, account information can be social engineered out of people quite easily as well - your particular usage habits could have nothing to do with it.
Extending that logic, it means the NSA is an even more worthwhile target for attackers, because they have far more private financial data about individuals in the USA and people abroad. But you can bet that when (not if) a breach of the NSA happens, it will never be reported to the public.
The only solution here is to do away with these centralized stores of all our private and financial information, so the incentive for these attacks no longer exist. There's no amount of technological hardening that will prevent a determined attacker (state sponsored or otherwise) to give up, when the reward for a successful attack is so high. Until then, reports of massive data breaches are going to be more and more common.
A security breach of the NSA has happened (obviously referring to Edward Snowden). It wasn't just user data either, but thousands confidential documents about nearly everything the NSA was doing.
Given the simplicity of his attack, and the fact he would of gone by undetected had he not disclosed those documents to media sources, it seems probable that important data has been stolen from the NSA in the past.
I dropped Linode after they showed me multiple times I couldn't trust them with my data or my money. People still recommend them, trust them, and even try to convince people to come back because the breech of trust wasn't that bad. Even in the tech world where people should know the impact and should care, no one really does.
There is some bad PR on the day of announcement a for a short time after, but people soon forget and the stock price is barely affected if at all, so those up top don't feel it in the slightest.
Especially if you have been through it before, the apparatus for handling fraud, reversing it, and cleaning things up is so tight that it's hardly even distressing anymore. The biggest annoyance would be updating any recurring payments from that card.
Which got me thinking: How much of my bank fees are spent on fraud prevention and clean up? How much cheaper could credit card processing and banking in general be if banks didn't need to spend BILLIONS of dollars in infrastructure, procedures, and automation to make these fraud cases go so smoothly?
The way the credit card system works is we all send the keys to our accounts in plain text, and then store it in plain text.
Rather than come up with a more secure means of payment, the credit card companies force every customer to check every monthly bill on every credit card to make sure none of it was fraudulent, and somehow this is more "convenient" than using a secure method for payment.
Related:
“Vandalism By Design”
http://www.icanbarelydraw.com/comic/2570
http://www.icanbarelydraw.com/comic/2574
http://www.icanbarelydraw.com/comic/2674
“Should We Accept Dollars?”
http://www.icanbarelydraw.com/comic/2565
One thing which jumped out at me from this story but was not mentioned in others was that the attacks had been traced back to servers in a Russian data center. I wonder if and how we can distinguish between:
- Criminal hackers exploiting lax or less capable Russian law enforcement, or
- Criminal hackers operating with the studious indifference or tacit acceptance by Russian law enforcement, or
- State-sponsored espionage expressing a retaliatory or threatening posture in response to western sanctions against Russia.
It's very hard (as a consumer) to gauge whether the main problem here is corporate negligence, very well-supported attacks, or excess organizational size and complexity...or some combination of these 3 factors.
[0] - I think I saw something implying this in official statements, though I can't find any good source that would confirm it right now; however the idea was discussed in media.
Often it seems to me that two ways of avoiding trouble are to avoid commodity solutions that can be automatically exploited (e.g., Wordpress, Drupal, Joomla, common plug-ins, etc) and staying under the radar.
If you're big or holding especially valuable data, you'll be targeted.
The market will quickly sort things out if it has the appropriate information. People can then decide what privacy is valuable for themselves.
This is already the case. The information comes from JPM's (mandatory) SEC filings. I forget the time frame but stuff like this (information that could reasonably be expected to have a material impact on the stock price) has to be reported within a pretty narrow window of becoming known to management, like 72 hours or so.
The market will quickly sort things out if it has the appropriate information.
By all appearances the opposite is true. I mean, where do you move your business to? I have no idea which is the most secure bank, only which ones have so far discovered and reported breaches. Neither Target nor Home Depot seem to have been punished very severely by the market if their stock prices are anything to go by.
No, we do not have any kind of transparency.
The second issue (where do I go?) can't be worked out at all until we have some idea of "where do I really not want to be?"
Would you not agree that a data breach brought on by a disgruntled employee selling records is materially different than the same data breach caused by failure to patch systems? I don't care about the investigation (where did you get any implication I think investigations should be public); I care about the results.
>>Would you not agree that a data breach brought on by a disgruntled employee selling records is materially different than the same data breach caused by failure to patch systems?
Directly contradicts this one:
>>I don't care about the investigation (where did you get any implication I think investigations should be public); I care about the results.
The result is that people's credit card information got stolen. The investigation and the details -- i.e. whether it was an internal or external breach -- are not relevant to me as the customer.
Of course there is going to be some level of sanitization, but today we get no information beyond "we lost a bunch of data" (oh, look, they told us names, address, email, "and other information used to categorize customers", whatever that means).
If you decide it's not relevant to you, brilliant. Don't pay attention to it. It is relevant to me, because I don't have any other way to decide who I should trust with my information security. A company losing hundreds of credit cards a day to hundreds of different hacks is much less secure in my mind than a company that loses 70M names and addresses (as far as I know, the Chase hack did not expose credit cards; mine was not replaced). The former goes unreported; the latter gets splashed all over the news.
The cost is borne somewhere (likely in the % fee credit cards charge merchants), but individual users have no incentive to care about it.
>This is already the case.
Err, no it isn't.
>I mean, where do you move your business to? I have no idea which is the most secure bank,
Couldn't agree more with that bit.
Do 'responsive firewalls' exist, that would close a hacked connection just because of the size of the data that is flowing out?
[I have often thought a firewall would be a good golang project]
Some already are, sorta. I made a single purchase at Target with a debit card during the period of their breech and my bank automatically sent me a new card with new numbers. It wasn't auto-activated, but once I did activate it, the old card and numbers went into the ether.
Not that it helps a bit if they are hacking banks however.
There was a complete lack of encryption at key points.
The chip is not part of the equation for online transactions. So if everything but the chip is stolen, the bad guys are going to use the card online.
Check out http://krebsonsecurity.com/2014/05/the-target-breach-by-the-..., particularly his "by the numbers" section:
0 – The number of customer cards that Chip-and-PIN-enabled terminals would have been able to stop the bad guys from stealing had Target put the technology in place prior to the breach (without end-to-end encryption of card data, the card numbers and expiration dates can still be stolen and used in online transactions).
With regards to online use, I'll say I'm not familiar with how Chip and Pin really works, but presumably they have some guard for online use, right? Or is that just wide open still?
How would having a having the Chip and Pin have prevented the data from being stolen? It does not. The "Chip and Pin" argument is brought up each time this sort of retail breach happens, like a reflex.
It seems that this is not that same type of system or am I mistaken in some way? Seems to me that it would have helped; my account number/card number/exp. date are useless on their own.
1 million – 3 million – The estimated number of cards stolen from Target that were successfully sold on the black market and used for fraud before issuing banks got around to canceling the rest (based on interviews with three different banks, which found that between 3-7 percent of all cards they were told by Visa/MasterCard were compromised actually ended up experiencing fraud).
So clearly they were able to use the cards.
Saying "76m records lost" is ok for headlines but like air traffic investigation we want to improve the whole system.
When the US government agrees to let Internet stakeholders make the Internet really secure, and not "secure to the point we can still break that security", then we should see some progress.
2. Even after discovering and fixing the bug rolling it out takes
So, no, there always be breaches. The best you can hope for as the data magnitude grows perhaps a bit more effort will be on protecting it so that it doesn't shoot through the roof.
Encryption, when it applies to systems that need unassisted access to data in a database, is hugely overrated.
Do you think that the goodwill from the first statement would save them $10 million? My bet is that a bank actually being able to say that a breach was a non issue because they had actually taken all possible measures to protect your data with them because they actually might care about their customers just a tiny bit would easily drive them in a positive direction both in the short term and the long term.
[1]: https://iafcu.org
And if you're contracting you'd better make sure you have indemnity insurance yourself: it's something software engineers who start freelancing often (always?) overlook. But you can bet that if - for example - some security breach was pinpointed to code that you had written as a freelancer that your client will come after you.