5 ms·
Incredible how bad the security posture is for companies like this. This should be illegal.
by nynx 4y ago
Incredible how bad the security posture is for companies like this. This should be illegal.
- lbriner 4y agoWhat should be illegal? Not having 2-factor auth? Allowing an account change? SOftware is massively complex and not everything has been defined in a way that there is a "right" way and a "wrong" way to do things. What happens if they setup 2-factor and someone loses their phone? What happens if someone needs to change an email address and can't access their old account because an ISP has gone bust or is refusing to give you access? I agree that things should be much better but until there is a book of "this is the right way to do signup/signin/account reset/ etc. " then most of us are trying to do things the best way we know how to and sometimes bad things happen.
- closewith 4y agoIt should be unlawful to process sensitive personal data without adequate security. It already is in the EU, which is why private credit registers are all but extinct in the bloc now.
- rcMgD2BwE72F 4y agoI wish non-EU developers better knew what the GDPR offers (and requires): https://gdpr-info.eu/issues/privacy-by-design/ https://gdpr-info.eu/issues/privacy-by-design/
- collegeburner 4y agoDefine adequate security. Maybe I want to adopt post quantum crypto but now the law doesn't allow it? Or u2f not totp but the law doesn't allow it? Law can hold back security just as much as improve it. Remember how long it took the feds to get off 3DES? Remember all the leaks of personal data (like all military in US or basically everybody in china)? Govts are shit at security.
- closewith 4y agoIn the case of, say, the GDPR, security requirements aren't prescriptive. You can read Article 32 yourself, but it comes down to being able to "ensure a level of security appropriate to the risk". Whether a company has met that standard is decided by data protection authorities and ultimately the courts. Article 32, GPDR: https://gdpr-info.eu/art-32-gdpr/ https://gdpr-info.eu/art-32-gdpr/
- user3939382 4y ago> Define adequate security SOC2, CSF, FedRAMP?
- enobrev 4y ago> It should be unlawful to process sensitive personal data without adequate security > Define adequate security If there is no means of defining "adequate" when it comes to security of sensitive personal data, then companies should not be allowed to amass and process sensitive personal data. If it's not possible for a company like Experian to exist safely, then it probably shouldn't exist at all.
- lbriner 4y ago> It should be unlawful to process sensitive personal data without adequate security It is but "adequate security" is not defined. That is what I am saying. Would someone without 2FA or this particular account reset process be prosecuted in the EU? Almost certainly not because the Prosecuter cannot currently say, "you didn't follow NIST guidance XYZ requiring it to be done this way". > private credit registers are all but extinct in the bloc now I'm not sure why you think that. In the UK, we have a number of them who are used by organisations. They are bound by the same GDPR regulations as everyone else.
- jaclaz 4y ago>I agree that things should be much better but until there is a book of "this is the right way to do signup/signin/account reset/ etc. " then most of us are trying to do things the best way we know how to and sometimes bad things happen. And when these (hopefully rare) bad things happen (and are documented and reproducible) what do you propose, do nothing and wait some more until that book is published by someone? Or take note of what happened (useful to later publish the "other" book "these are the wrong ways to do signup/signin/account reset/ etc. ") and quickly implement a remedy for the found issue?
- lbriner 4y agoMy argument is that the blanket "enforce it with laws" is meaningless until this document exists. I'm not saying that I don't practice security in my apps or that no-one should, just that the law (right now) is not the right tool to fix this problem.
- AtNightWeCode 4y agoThis is illegal in most western countries...