4 ms·
My understanding is that attack was through a third party that had access to Latitude’s network for legitimate business purposes. Counter terrorism legislation
by guidedlight 4y ago
My understanding is that attack was through a third party that had access to Latitude’s network for legitimate business purposes.
Counter terrorism legislation requires than financial services companies store customer identification.
The issue was not adequately restricting the third party communications into Latitude’s network.
- EdwardDiego 4y agoMy PII was compromised. I've never had a Gem Visa card, but I have had hire purchases 10 - 15 years ago with Harvey Norman, who some time ago shifted from in-house credit to using Latitude, and obviously uploaded their entire customer DB. > Counter terrorism legislation requires than financial services companies store customer identification. I was very much not their customer. The third party was https://dxc.com https://dxc.com
- anenefan 4y agoIf there's a chink in the security, it's just a matter of time ... as such, there's a question that's not really being asked, does x or any third party need all the details. Sometimes they do because which ever company had found a cheap service to do all the account processing or some other task. But more often I don't think third parties don't need full access to the master database via web access ... if they do then surely the customer needs to be informed who the company's partner is, and what that company's policy is to guarding any personal data loss/ misuse / retention. From what I see lately (and there has been some massive data loss here in Australia in just the last year) there's a very care free lax attitude with a few shrugs after data is lost - with the hope naughty hackers can be blamed.