3 ms·
It hasn’t gone far enough; not by a looooong shot. Billions of compromising documents, photos and personal details are now sitting around on the servers of a h
by charlesism 7y ago
It hasn’t gone far enough; not by a looooong shot.
Billions of compromising documents, photos and personal details are now sitting around on the servers of a half dozen for-profit companies.
Only Equifax has given us a taste of what is in store.
Is the world prepared for the day when a trillion Gmail messages leak? Billions of personal camera-roll photos? Trillions of search history entries?
We needs to start taking these issues seriously.
- aww_dang 7y agoSure take it seriously, but don't trivialize the issue with alarmism. A few decades ago more information (Full name, phone number and home address) was available in phone directories. These were commonly distributed to every home with phone service. Today we have security-expert-journalists calling the equivalent of a phone book a "verified threat incident". I'd wager that gmail data is already available to the intelligence services of the five-eyes countries. What does taking it seriously mean in this case? Not using Facebook? Acknowledging that data posted publicly is, wait for it... public? To top it off the bread and butter of this blog is affiliate links to VPN providers. Another centralization of data for those seeking privacy. Not only is this contradictory, but it preys on the ignorance of the audience. When companies sell this same data to employers it is called OSINT. When someone finds this data through Shodan and it is hosted in Vietnam they call it cyber-crime. Many times the OSINT groups are the same ones making the accusations.
- 0134340 7y agoI hear this analogy used sometimes but modern data isn't equivalent to phone book data. You had the option to be unlisted and it was respected. You also didn't have your name and address tied to so much personal data in one place. And do we know this data was public? I don't use FB but I know you have options to control who can see what you post, whether it's public or private. Sure, if you're the HN crowd and assume every database is penetrable, this may not be a "threat incident" but when you're Grandma Jones who assumes that when she ticks the "private" box on her posts that it'll be private. If you care about infosec but are still ignorant of just how incompetent these companies can be then this breach is a "verified threat incident" and there's no reason to be alarmist here because someone mentioned that it happened.