4 ms·
Only slightly related, but back when GDPR was first enacted I mentioned that it would inadvertently open up some vulnerabilities and that it should have been re
by tdrp 6y ago
Only slightly related, but back when GDPR was first enacted I mentioned that it would inadvertently open up some vulnerabilities and that it should have been reviewed by white hat security researchers.
- "Download all my data" was mandated by GDPR (article 20)
- Right to delete, right to access made it so that there is up to a ten million dollar fine if you refuse it, so you are more prone to social engineering attacks. Meaning if some user requests access or deletion, (e.g. having forgotten their password or username) you might not be 100% sure that it's him but arguing with him or asking too personal a verification proof can get you in hot water and you'd rather not get dragged into a fight with the European committee.
- While our users could initially create an account without e-mails and be relatively anonymous, a couple of "right to access" requests from "users who have forgotten their username" means you are basically forced to require e-mail, thereby carrying even more PII unnecessarily.
It probably wouldn't have slowed the hackers down much here though.
- Semaphor 6y agoWhere does it say you have to follow through with data or erasure of users who can’t prove they are who they say they are? Both of those seem like the opposite of what you are supposed to do. I just checked the first result, and even the ICO [0] says > [Your full name and address and any other details such as account number to help identify you] [0] https://ico.org.uk/your-data-matters/your-right-to-get-your-data-deleted/ https://ico.org.uk/your-data-matters/your-right-to-get-your-...