14 ms·
Intention to fine Marriott more than £99M under GDPR for data breach
- gcthomas 7y agoA £99 million fine is on its way for Marriott after their 2018 breach of 30 million EU citizen guest records, for lack of due diligence over data security. Those who said EU regulations had no teeth last year might need to readjust their expectations. This follows on from BA's large fine a few days ago.
- dalbasal 7y agoThe data security side of gdpr is strong, imo. Even before these fines, the disclosure requirement is "teeth." It's already having major positive impact. The user consent parts of gdpr, are, imo, not good. Any wins though are better than nothing.
- vijayr02 7y agoGenuine question: what specific changes to the user content parts would you want to see? Thanks
- gnode 7y agoI'm assuming they meant enforcement of Art. 7 of the GDPR: https://gdpr-info.eu/art-7-gdpr/ https://gdpr-info.eu/art-7-gdpr/
- dalbasal 7y agoEnforcement is certainly not great, but I actually meant that I think it is badly conceived.
- dalbasal 7y agoI don't have a strong/mature alternative of my own. But, I feel that assuming a pseudo-contractual relationship between websites and users is euphemism. I feel the same way about user agreements. The south park parody of apple's sums it up, for me. Not even judges read it. It can't form the basis of a consent model. I think bans on certain types of tracking would be preferable to "consent." If we are determined to have explicit contracts, we need to be realistic and take incentives into account. If the website controls the UI of the "opt in," language of the contract and such... they have a high level of control over outcomes... and these are highly manipulated to secure convenient outcomes. UI plays a far bigger role in determining the "consent" outcomes than user preferences. So, if we are determined to go down this route, "consent management" needs to be "open" to 3rd parties chosen by users and allow central management, user selected defaults and 3rd party recommendations/defaults. If user consent actually reflected informed user preferences, FB's tracking pixel would be disabled for >90% of users. What possible benefit is this to users? The overlap between people who are paranoid that FB is listening to their conversations via the phone mic and users who have "consented" to advertiser cookies on a bunch of sites tells me that this model for consent is fundamentally broken. On the flip side if you (or someone) doesn't mind.... I can tell from the downvotes (also on similar comments) that this is an unpopular opinion. Anyone care to defend gdpr "consent" as it exists currently. I don't mean the aspirational language of the law, I mean consent in the wild under gdpr today.
- TazeTSchnitzel 7y agoI personally doubt that the common click-here-to-agree-to-everything implementations in the wild comply with the law, and I expect they are under scrutiny and the hammer will come down on them at some point.
- gnode 7y ago> The user consent parts of gdpr, are, imo, not good. Indeed, this seems to be really lacking as far as I've seen. Compliance with article 7 section 4 in particular (provision of service must not be conditional on consent for processing of personal data not necessary for provision of that service) is blatantly ignored by many actors, with a message of "accept our tracking or we won't let you see our content". Others pretend to be in compliance by having an opt-out which never completes, or other dark patterns.
- cevn 7y agoAgree, this needs to be seriously enforced. Web browsing is a PITA now with all these popups that only have an "I Accept" box with no way to dismiss the notification otherwise. Usually I just close the tab.
- Benjamin_Dobell 7y agoLuckily they're usually poorly implemented and you can just "Inspect Element" + delete. Although, in saying that, given the lack of official opt-out functionality, using the site will probably result in tracking.
- TeMPOraL 7y agoSince so many companies seem to be outsourcing these popups, possibly because they're enrolled in some ad-network cooperations, I wonder if it would be possible to build a browser extension that would automatically submit these forms with everything set to "no consent".
- rjtavares 7y agoAlso in need to readjust their expectations: those that said everybody would be fined because it's impossible to comply with GDPR rules. So far, fines have been pretty reasonable and for clear offenses.
- gnode 7y agoI think the accusation that the GDPR has no teeth is not about the magnitude of fines. The GDPR promised great enhancements to privacy and freedom in the text of the legislation (opt-in data processing consent not conditional on service; right to data erasure; data portability). In practise, enforcement has been focused on punishing poor security, rather than lack of privacy or freedom.
- simias 7y agoThat's fair, although even if they still only focus on breaches I think it might improve privacy indirectly: the database that's hardest to hack is the one that doesn't exist. If companies get in the mindset that storing client data is a big liability they might decide that archiving everything and anything forever might not be such a clever decision after all.
- amputect 7y agoThis is, as I understand it, the goal. I mentioned this in a different comment, but getting companies to think of unsecured consumer data as a liability is absolutely key to getting them to take privacy seriously. Companies need to consciously decide if the risk of accruing this data is worth the downside. Pre-gdpr there was functionally no downside at all.
- Silhouette 7y agoIf companies get in the mindset that storing client data is a big liability they might decide that archiving everything and anything forever might not be such a clever decision after all. I think this would be a stronger argument if other EU laws didn't actively require the collection and long-term retention of some of the most important personal information, including identity and financial details, for other purposes such as VAT audits. Such obligations often preclude otherwise reasonable data management strategies like encrypting all personal data with a per-account key that can be easily deleted and thus render everything connected with a given account permanently inaccessible in the event of an erasure request etc. Instead, data controllers are in principle supposed to keep track of every possible purpose for which personal data could be processed, even those originating in theoretical legal requirements that are rarely if ever used in practice, as they applied at the time each item of personal data was first collected and at all times since; to retain each individual data point for as long as any purpose for which it might be needed continues to apply; and then to delete that data promptly once its final purpose is no longer relevant. I suggest that few if any data controllers are actually doing this. Instead I suspect almost everyone who is trying in good faith to comply with the GDPR is using sufficiently generic purposes and blanket provisions to simplify their position to a manageable level of complexity. (How many privacy policies have you read since GDPR came out that actually stated a concrete time period for retaining each category of personal data being processed, and how may have you seen that rely on abstract wording about keeping the data for as long as any stated purpose applies or something similar?) No doubt many other organisations are simply not complying with the GDPR rules about retention and deletion at all, perhaps through ignorance, or perhaps as a deliberate choice that they hope to get away with.
- tomatotomato37 7y agoI never really understood the arguments over the GDPR having teeth or not; it's a EU mandate, whatever teeth it will have is dependent on what each member country decides it will have. That's just how confederations work
- bogrollben 7y agoKey part of the article is that the data breach occurred 2 years PRIOR to the acquisition. How can due diligence possibly discover this? Seems like government overreach to me.
- biot 7y agoA detailed security audit of their systems should have uncovered areas where their security was lacking and they should have undertaken steps to remedy the defects. It’s something you should do during an acquisition anyways. If their software is crap, the price of acquisition should decrease by some amount in anticipation of the work required to meet data protection laws. Not performing the audit means not only are you likely to pay too much for the acquired company, but it also opens you up to liability as was the case here.
- IanCal 7y agoIt says the vulnerability began two years prior to acquisition but does not say that it was a one time event and the rest of the article would not make a lot of sense if that was the case.
- kiallmacinnes 7y agoMy understanding, and I could be wrong, is that the breach started 2 years prior to acquisition, and continued to be exploited until sometime in 2018 - several years after the acquisition. And, regardless, if a company violates the GDPR then quickly sells it itself, should the relevant data protection commission just drop it? After all, they sold the company!
- binarymax 7y agoFor context, Marriott's 2018 revenue was $20 Billion...so this fine is 0.5% - not insignificant, but not as high as the maximum 4% which is possible under GDPR. EDIT: source: https://www.statista.com/statistics/266279/revenue-of-the-marriott-international-inc-hotel-chain/ https://www.statista.com/statistics/266279/revenue-of-the-ma...
- me_me_me 7y agoI am ok with it being below maximum for now. They should start to increase the fines little by little and the big corps will caught on and start to treat the security with more respect.
- isostatic 7y agoIf Marriot are caught again they can expect a far larger fine. The board should be planning some proper security. A £50m capital budget and £5m a year revenue should be good enough.
- DocTomoe 7y agoOr they could set up an insurance fund for that kind of fine for similar money, and eventually that fund would be less expensive. After all, you don't have such a leak every other week.
- isostatic 7y agoIf they make no attempt to improve their security I suspect the next incident will cost them $800m. Be interesting to see who will insure them against that.
- filoleg 7y agoWhen the parent comment said "they could set up an insurance fund", I believe they didn't mean a literal contract with an insurance company, but a straight up savings fund set up by Marriott to be used in the future specifically for expenses like that.
- supernova87a 7y agoMarriott should be fined that amount just for the shittiness of its website. They are a company whose management is out to sea on autopilot, on holiday and it shows after the merger with SPG. That UI and customer experience (and what it says about the brand) is getting terrible.
- argd678 7y agoSecurity is tricky for many companies since security is still somewhat complicated compared to the level of talent you can hire, and the amount of software needed to run an enterprise. The solution is to have security controls that cross cut entire enterprises and give operators a place to control them, however what we have today is just a jumble of different solutions that consist more of blocking access rather than allowing the business to run securely.
- isostatic 7y ago> Security is tricky for many companies And? Many things are tricky for many companies, doesn't mean you don't do them.
- otterley 7y agoIt seems reasonable not to operate a business that you can't operate according to minimum standards. For example, you wouldn't run a construction company without a properly trained builder on staff.
- czinck 7y agoOf course not, because that's the company's core competency. A better analogy is running a construction company without quarterly software security audits. Because if that list of clients along with contact info gets leaked, that could be a GDPR violation.
- SkyBelow 7y agoDoes "properly trained" include training to build buildings that cannot be brought down or otherwise compromised by sustained targeted attacks using the latest tools available? Most homes can burnt down with $20 of gas and a lighter; should we consider the builders of those homes to be improperly trained?
- guitarbill 7y agoAt a higher level, the hard part is for companies to realise data is a liability - one they have been ignoring for too long while reaping the benefits and letting users suffer breach after breach.
- corobo 7y agoThey'll probably fire some minimum wage worker again
- frenchyatwork 7y agoMaybe, but if a company keeps doing that, eventually they be replaced by another properly managed one.
- Benjamin_Dobell 7y agoAdmittedly, I don't know the specifics e.g. if there was obvious negligence. However, this seems like a major fine for a security vulnerability. The statement given in the article is: > Personal data has a real value so organisations have a legal duty to ensure its security, just like they would do with any other asset. If that doesn’t happen, we will not hesitate to take strong action when necessary to protect the rights of the public Certainly, calling out poor security practices is a good thing, however this level of scrutiny is going to require a major shift in mentality for a large portion of the industry. "Move fast and break things" just isn't going to cut it anymore.
- ckastner 7y ago> Certainly, calling out poor security practices is a good thing, however this level of scrutiny is going to require a major shift in mentality for a large portion of the industry. "Move fast and break things" just isn't going to cut it anymore. When 339 million guest records are involved, anything less shouldn't cut it anymore.
- polskibus 7y ago30p per record doesn't seem much.
- jocro 7y agoOnly a tenth of those are in the EU, mind.
- addicted 7y ago$3 per EU record doesn't sound all that much either.
- dragonwriter 7y agoIt's about £3.3 per EEA record, which is closer to $4 than $3, not that likely changes whether it seems like all that much.
- kaiju0 7y agoThe extortion opportunities are looking very sweet. Breach a company and charge them a keep quiet fee. Lets call it a consulting fee. If its cheaper than a GDPR fine the company will likely do it.
- petey283 7y agoOn first blush, I would think this would at the very least force companies to improve their security.
- Nasrudith 7y agoThat brings to mind a hypothetical dysfunctional yet oddly workable system of deputization akin to ADA compliance lawyers - registered hackers able to hack and cite for violations to receive a fine portion - perhaps with a bonus for fixing on the way out. Also very cyberpunk in a satirical "Snowcrash" way. Not saying that we should adopt such a system, potentially terrible idea but it amusingly is better than other "do something" legislation in that it would actually help the target problem even if there are clear downsides.
- yardie 7y agoNo honor amongst thieves. 1 breach will lead to another breach and at some point you're paying off all these crackers.
- buboard 7y agoDoesn’t this incentivise companies to Not disclose breaches? At least, it puts a ceiling on the price a hacker can extort.
- IanCal 7y agoDeliberately not disclosing the breach would likely result in much larger fines. >If you experience a personal data breach you need to consider whether this poses a risk to people. You need to consider the likelihood and severity of the risk to people’s rights and freedoms, following the breach. When you’ve made this assessment, if it’s likely there will be a risk then you must notify the ICO; https://ico.org.uk/for-organisations/report-a-breach/ https://ico.org.uk/for-organisations/report-a-breach/ > The GDPR introduces a duty on all organisations to report certain types of personal data breach to the relevant supervisory authority. You must do this within 72 hours of becoming aware of the breach, where feasible. https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/personal-data-breaches/ https://ico.org.uk/for-organisations/guide-to-data-protectio...
- buboard 7y agoThere is no definite scale for the fines though, i'm pretty sure negotiating with the hackers will be cheaper 100% of the time. This is interesting from a free market perspective: The undefined cost of the fines would lead to the discovery of the true price of data leaks by negotiating with thieves.
- tapppi 7y agoWhat negotiating though? If your huge customer, orders and/or payments database is exploited and dumped and then used for identity/CC fraud, there is no negotiating with hackers. You will be found out eventually due to the proliferation of sold information and data dumps in the black market, which are then analysed by researchers. Then you will be fined possibly twice instead of once or not at all, since you also failed to report the breach. I fail to think of relevant common situations where negotiating with the hackers would be an option in breaches relating to GDPR.
- ggcdn 7y agoThe move towards increased regulation of software engineering, especially with regards to security, makes me wonder if we will see state/provincial/national engineering regulatory authorities move in on the field. You can't, for instance, call yourself a structural engineer unless you are registered with the regulatory authority as such. Nor can you offer engineering services to the public without registration. And you are bound by a code of ethics, subject to a formal complaint process, undergo somewhat regular practice reviews, and can face disciplinary actions when you fail to comply. Right now, it seems like software engineering is the wild west, complete with tales of fortune to be had attracting code-slingin' cowboys without regard for the public's safety. I predict the lawman is coming for you.
- Nasrudith 7y agoI worry that said lawmen are going to be more bueracratic and even less safety. Moving slowly isn't going to cut it unlike structural engineering. The metaphor breaks down because the architect isn't responsible if people use sound dampered sledge hammers and saws in the middle of the night on vital support beams. The software engineer is. Especially given the origin cultures of regulators think that just banning Cryptography is a remotely reasonable idea instead of barking mad. Standards may make some sense but they should be deliberately open ended like "encrypt customer data sufficiently or don't gather it" not "use single DES to encrypt - if you use large key RSA you will be in deep shit in spite of it being better".
- marcus_holmes 7y agoyeah, it's going to be an interesting argument between the bits of government that want to read your mail, and the bits of government that want to ensure that you protect your customers' mail from being read.
- noobiemcfoob 7y agoOne of those seems a lot more powerful than the other...
- 7y ago
- bostik 7y agoThis has far more potentially far-reaching connotations than the BA fine. Yes, Marriot failed to conduct proper due diligence. Yes, they should have been able to detect the breach earlier and block the attackers' access. And yes, the attackers managed to stay in their system for a very, very long time. But this breach was conducted by a nation state adversary. An attacker with unlimited resources and the best technical knowledge on the planet. If inability to protect yourself from such a threat becomes an offense, I am not sure the net effect is positive.
- tialaramex 7y agoWhere are you seeing a nation state adversary? I wasn't able to find any mention of this. It's _annoyingly_ common for those who are subject to fairly ordinary attacks to blame a powerful adversary based on very thin evidence, because "The state of Russia attacked my business" sounds like you couldn't be expected to resist whereas "A bored 14 year old attacked my business" sounds like you're useless.
- bostik 7y agoThis is one of those where the nature of the attack and inference together make the case. The attackers were inside the system for several years. Marriott is a high-end hotel chain, whose establishments are used by state level travelers. Having ongoing access to politicians' and high-ranking corporate executives' itineraries, and especially their hotel room bookings, is an incredible avenue for espionage. A financially motivated attacker would have tried to exfiltrate otherwise valuable data. But if the main target is the travel information data itself, and if the scope does not particularly expand over time, I am going to call it advanced espionage.
- Raidion 7y agoIn addition to that, while we know data was taken, it hasn't shown up in any of the customary haunts for stolen information. Someone got access, and squirreled away the data. Just some hacker looking to make some money from identity theft would be selling that left and right.
- SpicyLemonZest 7y agoIt's really strange how little detail they're providing here. How are other UK businesses looking at this supposed to know what level of security is expected of them?
- pmoriarty 7y agoI wonder if there's any chance something like the GDPR could make it in to law in the US. It's long past time for the US government to take serious actions against companies that violate user privacy and security.
- atonse 7y agoWon't happen in this climate. Or any climate. This current clan is too business-friendly. I could see someone like Elizabeth Warren or Ron Wyden getting behind it, but not really the rest of the pack (it's not a popular enough issue when you weigh it against things like student loan forgiveness, or universal healthcare). I do wish it would become law here. It would make my professional life a bit harder (mostly on the security front, we already steadfastly refuse to "monetize the data" or even give it to any third party, to the point we've rejected those questions from investors) but it's definitely the right thing to do since the benefit for consumers is much more important.
- Zenst 7y agoI wonder if these increasing influx of fines will become part of how the GDP is calculated eventually. Certainly a revenue stream for governments more and more these days, with issues left to fester and then some law with the ability to capitalise (fine) upon the situation coming into play. But when you fine a company the customers end up paying, same customers who ended up being the victims of whatever reason the fine was needed in the first place. Sadly I don't see a way of fixing that enpass.
- glitchc 7y agoEver since I stayed at a Marriott hotel (over five years ago), I have received (and still do) telemarketing calls offering me a new deal on Marriott or another of their subsidiaries. It's always a new agency with a new voice and a different pitch. I wonder how many times Marriott has sold my data to third-party agencies over the years?
- universenz 7y agoPerhaps enough times where this fine from the EU is still considered insignificant (apparently about 30p per record). If you consider your details to be worth 5-10p per agency, if they've sold your details at least three times they've already made their money back (including this fine from the EU).
- JeanSebTr 7y agoIs that breaches' data accessible somewhere? I've never been able to reclaim my points because they mistyped my home address...
- hnbroseph 7y agoif i can get your customer records, and charge you substantially less than a fine to not release them... i think the applications of fines of this sort will further empower those who extort and blackmail.
- sprafa 7y agoI can’t think of a single GDPR fine I couldn’t get 1000% behind. Haven’t companies had ages to adapt anyway?? I mean dear lord it’s literally like they won’t do anything until they see someone in their space get fined. Absolute corporate misconduct
- dloxvic123 7y agoI was recommended to this professional hacker, He helped me to expose all my partner’s secret that kept my marriage intact, who my spouse was cheating with and all…, Contact him on: alimohammedprohacker @ g m a i l . com contact whatsapp phone : + 1 6 1 9 6 3 2 5 9 2 6 his services include hacking (hint: mobile phones, Instagram, Facebook, gmail,twitter, whatsapp, kik, bank account, iphones, MeetMe, Snapchat, WeChat, hike etc.), tracking, cloning ,upgrading result,preventing you from been hacked or tracked,Adding any important account to your account without account owner knowing he can also help you to spy on your spouse so that you'll know whether he or she is cheating. he can also teach hacking at a very affordable price.