4 ms·
And whilst its impossible to police effectively the datasets on various forums, it seems KPMG and Troy Hunt are just not aware of the fact that GDPR exists. htt
by jfdhu 7y ago
And whilst its impossible to police effectively the datasets on various forums, it seems KPMG and Troy Hunt are just not aware of the fact that GDPR exists. https://en.wikipedia.org/wiki/General_Data_Protection_Regulation https://en.wikipedia.org/wiki/General_Data_Protection_Regula...
Its quite interesting putting in various peoples email addresses to see what sites they are linked to. Maybe once he has made some money out of it, a GDPR claim and financial settlement can be made as he's made no steps to control the data privacy of Europeans.
- paublyrne 7y agoDoes this really fall foul of GDPR? I would have guessed that once your data is in the wild, there is nothing in GDPR that applies. GDPR puts certain responsibilities on groups you give your data to treat that data in certain ways in terms of who it is shared with, which would not seem to apply to someone offering a lookup of an in the wild dataset. I'm curious if my naive understanding of this is wrong.
- addicted 7y agoI’m not sure how GDPR applies to HIBP. GDPR is all about data that is shared by the user. But HIBP is about data that hasn’t been shared by a user, but rather, is available publicly. It’s a grey area at the very least.
- DanBC 7y ago> GDPR is all about data that is shared by the user. No it isn't. It covers my data no matter how you got it, with a few exceptions. EDIT: Please feel free to point to the legislation showing that GDPR only applies to data supplied by the subject.
- cameronbrown 7y agoYou're not wrong, but purely from a practical standpoint, your data is out there and without a service like this to hold these companies to account, they could cover things up/downplay the situation/be too incompetent to know they've leaked data. An operation like this levels the playing field and lets us collectively hold companies to their responsibilities.
- jfdhu 7y agohttps://en.wikipedia.org/wiki/General_Data_Protection_Regulation#Scope https://en.wikipedia.org/wiki/General_Data_Protection_Regula... "The regulation applies if the data controller (an organisation that collects data from EU residents), or processor (an organisation that processes data on behalf of a data controller like cloud service providers), or the data subject (person) is based in the EU. Under certain circumstances,[2] the regulation also applies to organisations based outside the EU if they collect or process personal data of individuals located inside the EU. The regulation does not apply to the processing of data by a person for a "purely personal or household activity and thus with no connection to a professional or commercial activity." (Recital 18) " The EU laws apply to people and entities outside of the EU, he is not immune from these EU laws because he is affecting the lives of every European who has an email address in this website.
- M2Ys4U 7y ago>GDPR is all about data that is shared by the user. Wrong, wrong, wrong. GDPR covers the processing of any data about an identified or identifiable individual.
- samwillis 7y agoIt’s a very easy fix, confirm ownership of the email address before exposing the results.
- _underfl0w_ 7y ago...if the password for said email address is already visible on the same page (assuming negligent password reuse) what kind of verification could you hope for?
- AshleyGrant 7y agoHave you actually used HIBP?
- jfdhu 7y agoOnly if in possession of the email address or domain name. Where an email address or domain name has been taken over by someone else, then sending the results to the email address instead of currently showing it on the webpage doesnt solve the problem. This data set is ripe for blackmailers, intelligence services and any company looking for intelligence on rival businesses.
- OskarS 7y agoPresumably it's partly questions like these that make Troy Hunt eager to find people with money and lawyers to help him host this thing.
- DanBC 7y ago> Maybe once he has made some money out of it, a GDPR claim and financial settlement Do you think GDPR fines go to the person, and not the regulator?
- M2Ys4U 7y agoPeople can sue (Article 79) and claim compensation for actual damages suffered (Article 82) due to a violation of the GDPR. Administrative fines levied by a supervisory authority generally don't go to people who have had their personal data processed illegally, though.
- dumpsterdiver 7y agoThey would just get hit back with tariffs, no problem. If I were European I wouldn't want to be playing money games with America.
- deleted 7y ago[deleted]
- deleted 7y ago[deleted]
- dumpsterdiver 7y agoIt looks like he's based in Australia, so Europeans wouldn't have to worry too much about having tariffs rained down upon them in retribution. I say go for it.
- deleted 7y ago[deleted]
- jameshart 7y agoYes, you're right, I'm sure that the guy who is at the forefront of campaigning about personal data protection, has been running this service for years, has advised governments on privacy breach regulation, and has contracts to help european governments monitor their domains for breaches, has no idea whatsoever about the most prominent personal data regulation regime in the world. Oh wait: https://www.troyhunt.com/free-course-the-gdpr-attack-plan/ https://www.troyhunt.com/free-course-the-gdpr-attack-plan/ https://www.troyhunt.com/new-pluralsight-course-the-state-of-gdpr-common-questions-and-misperceptions/ https://www.troyhunt.com/new-pluralsight-course-the-state-of... https://twitter.com/troyhunt/status/1017679101698572295 https://twitter.com/troyhunt/status/1017679101698572295
- jfdhu 7y agoAuthorities now handling it, out of my hands. I dont want my details appearing on that website so anyone who knows me can put my email addresses (past and present) to see what hacked sites or databases its appeared on.
- slips 7y agoThat's the whole point. You can see the data that criminals are using and seeing. Don't blame the guy telling you about it.
- deleted 7y ago[deleted]
- deleted 7y ago[deleted]