back
151 comments
> the data stolen in the breach could include full names, dates and places of birth, mailing and email addresses, and phone numbers on an undisclosed number of citizens

Nothing really new here sadly, this information about me have leaked half a dozen of times in the past 2-3 years or so. These things will never change if the only penalty the company/agency gets is "send a message to your users saying you are sorry and that it won’t happen again".

Or maybe the government should not require companies to KYC you for every little stupid thing or action you do in this world. What happened to requiring only the information that's actually required? Why do I need to be KYCd in the systems when buying banana, ordering delivery, etc.

Because of the inevitable breaches and leaks - KYC is the illicit activity. The selling point of KYC was preventing fraud and money laundering. It doesn't actually do that. Search for "largest money laundering settlements" and you will find 5 banks and one crypto scam.

Penalties don't work for government agencies. Taxpayers would pay for it and it doesn't act as an incentive.

The way to fix it is to empower one government agency to do aggressive pentesting against every other agency, hospitals, banks, infrastructure, and big corporations, with salaries matching the private sector. Impose a legally-enforced deadline to fix any issues, with a fine (for private actors) or demotion of the guy in charge of infosec (for state agencies).

Forget compliance checklists, KPMG "audits" and all that crap, just have government-sponsored hackers trying to get into everything like an attacker would.

France seems to have had a ton of government hacks in the past year at various levels, so it's sorely needed.

Hey now, don’t forget the offer of “free credit monitoring for a year” - I feel like at this point I’ve gotten so many of those that if I signed up for them all, I’d have my personal info in twice as many probably-hackable locations as I do already.
Seeing another one of these breaches had me returning to look at local-first software. https://lofi.so

I feel like if we're going to make progress in preventing wholesale data breaches it will be through architectural innovations that attack the problem of why a trove of concentrated data needs to exist. Even if the government needs to be a central authority, are there ways to house the data that limit the blast radius?

I'm sure there are innumerable arguments why this can't help, but when the mainstream alternative is despair and helplessness, progress will be made in the margins.

Wait, you don’t even get a month of free credit monitoring?
These things will never change if the only penalty the company/agency gets is "send a message to your users saying you are sorry and that it won’t happen again".

So, you want the French government to fine the French government so the French government uses French taxpayer money to pay the French government for the French government's mistake?

With everyone doing online “identity” verifications, all these details and more are already available to data brokers. Persona.. I mean Palantir even has a short video of you from your “liveness check” to go with the scan of your ID.
The problem though is when its from a gov agency it validates previous breach data making it more valuable.
And 12 months of credit monitoring to go with the 2346823 months of credit monitoring they already have.
Yeah we are all walking with online targets in our real life. Technology has failed us spectacularly
> if the only penalty the company/agency gets

What is the penalty for the government?

Not disagreeing with you, but:

> These things will never change if the only penalty the company/agency gets is

I do not think penalties can prevent these situations. Perhaps they may be less frequent; perhaps people would get more compensation, but ultimately I do not think these can be prevented. The first consideration is why the data has to be stored in the first place. Naturally one can say "the government needs to know who is a citizen and who is not", and I can understand this rationale to some extent, but even then I wonder whether this has to be correct. Perhaps we could have a global society without any requirement to be an identifiable citizen per se. Things such as mandatory age verification-sniffing to never become an issue, because it is not needed and not possible and nobody would have an addiction-need to sniff for that data (we know Meta and co want that data, this is why their lobbyists run rampage via the "but but but somebody protect the children" lie).

GDPR has solid fines for data breaches, but this doesn't work for government agencies. Just someone else's money going from one government pocket to another. What they need is an automatic firing of the head of the government agency that suffered a breach. No question asked.
> Nothing really new here sadly

Facts at Equifax

I received the email telling me I am impacted today.

Ironically it changes nothing for me as that same data had already been leaked by the French government agency that handles unemployment benefits a couple years ago. Silly me had not bothered deleting that account even after it was no longer necessary due to finding a new job.

A copy of it would be nice for record purpose (so Anthropic and OpenAI can have it in their dataset :))
Is it from ANTS? I haven't gotten anything yet.
And they're still pushing through with the idea of centralized IDs for the internet creating massive honeypots for hacker groups and AI companies all over the world. Meanwhile it's a breach every other month all over.
It seems to me we must move away from worrying about ransomware, data breach, data protection as that ship has already sailed and everyone's PII has already been stolen. We should think of how to verify people's identities online (for things like government benefits etc). I have heard of the Dutch and the Japanese using national digital identity systems although I am unclear how they work. India is doing biometrics. I am curious what the US will eventually land on.
Biometrics is just something else to get leaked, terrible idea because it's even more sensitive (can be used to track you through cameras for example, like used in the Iran war).

This problem has long been solved with federated IdPs and MFA - something you own like OTP device/physical token besides something you know like SSN/tax id/password.

Most governments prefer biometrics of course because citizen privacy is the opposite of what they want.

Based on how things are, I feel like the US solution is just going to end up with me requiring a retinal scan to buy pants from Target online and then that scan will end up on the dark web along with my voice print and a scan of a my driver's license.
If governments are treating my personal data as if it is worth nothing, then I'm not going to treat copyrighted works as if they are worth something.

If you want to build a society on information, then you cannot forget the most important group.

I find it especially ironic that they would leak all my data, given the fact that they would ask of me to forward them every piece of id imaginable whenever I needed to forge or amend a new one (when adding a mention on my driver's license for instance).

Like they didn't have access to it anyway.

In 2015/2016, the president (Hollande), and its prime minister (Valls) did install a document which is "law", about technical directives for the gov and its agencies/dependencies. This document was probably written by big tech themselves. No following prime minister and even the new president (macron), did fix this obvious big tech ("whatng cartel") trojan horse.

They were probably screwed as f... or they had/have some interests somewhere ($$$).

In the last decade, all web sites were broken to be replaced by web apps ($$$), creating a hard dependency on the massively huge and complex "whatng cartel" web engines and their related massively complex c++ compilers. It is very hard to believe to anything else than corruption, really hard.

This document, which is law, which only the president and prime minister have power on, must be modified to make the difference between web sites and web apps and to mandate a web site for core and critical online services of gov and dependencies. Aka, restore noscript/basic (x)html interoperability, or "small" and technically reasonable web engines (to foster real-life alternatives from citizen, local company, etc, initiatives). All of such online services had a working web site (no app) before this document sold the gov and its dependencies to big tech (here the "whatng cartel").

No gov authorities (competition/anti-trust, justice, etc), not even the parliaments can do anything here, only the president and the prime minister.

Hardly believable, and I found out only a month ago, in spite of consulting lawyers, being part of related user groups with legal experts, etc, for 10 years. I could not understand what was going on, all this money and 'loss of strategic control' channelled in those 'companies'.

19 millions de Français! Et moi, et moi, et moi.
There’s something to be said about old school bureaucratic institutions: it made breaches like this significantly more difficult to pull off and far less valuable as a result.

It also ensured democratic participation by all of the people employed there making sure that processes are followed and making sure no one is cheating.

We all knew that systems like this would get breached. It’s not a matter of, “if,” but, “when.” If we’re going to continue down this route because of convenience or surveillance and authoritarianism or whatever; people designing these systems need to thinking: When this system is breached…. And they should make sure there’s a good story for protecting people and the system from these sorts of events.

It’s kind of interesting that this happens so shortly after they proudly announced how easily they would’ve able to migrate all systems from Microsoft and US firms. Maybe next year will be the year of the Linux desktop
Important to remember: this is the competency level of basically all governments who are currently proposing you be required to identify yourself using their proprietary identity systems anytime you visit a website to "save the children."

There will be zero risks to you of course, because their software is magically perfect, unlike any other software created in the history of mankind.

Would it be possible to spread so much noise that data like this becomes useless? Could an LLM be used to help here?
A possible outcome of AI-assisted hacking is that companies, governments, and people become more resistant to using software, and software adoption actually declines.
C’est la vie.
Governments may just be incompetent. Still, the lobbyists will never give up for mandatory age verification in the future.
We are going to leak everything from our sexual health records to our HR files

It's the age of the leak and the sooner we accept, no matter our efforts, we live in a security free world and design around that - the better

What all these breaches tell me is that personal data should not be required, and especially not stored unless absolutely necessary. I cannot verify how my data is treated once it leaves my device, so how can I possibly trust it will be treated properly and not leaked?

This is a major reason as to why I am so strongly against all this verification shit governments keep trying to push, the best way to keep data secure is not to have it in the first place, therefore my personal data should not leave my device except in the strictest of circumstances for things like my name/DOB/address/SSN.

It's nothing special. Our data goes away on a regular basis.

They hack the taxes and the heath insurance system and yhay have everything about us.

What a shitty world because of these idiots

- There was no leak - Here is sample data we stole

„Small, not harmful leak of non important data, few records only”

I wonder: Do all these government ID databases etc contain the IDs of the politicians and other people in "power" that pushed for all this shit?

Or are they magically exempt?

This shit should be stored encrypted not in plaintext.
Use Mythos!
Yet another example why NO ONE should trust age verification laws or companies like Anthropic forcing you to verify identity with shady companies like Persona (https://news.ycombinator.com/item?id=47872608). Whatever info you give up, it’ll be exposed one day.
Great, now scammers can steal my identity directly from the government. I hope they release a tool to check if I'm impacted or at least email me about it.
I trust Google more than any government with my data. One needs security to survive the other couldn’t care less.

Google selling data? So far no one came to blackmail me for certain dispositions, while the other does as they want, IRS, foreign governments, social security whatever.

Google can be sued while the other gives itself a pass.

Who is the baddie?

In Germany the administration put massive duties on IT providers and added punitive damage as a looming consequence.

Fast forward and the government with its “Ha, we are so digital!” and “Europe is better than US in CS!” suddenly has to swallow some brutal medicine I guess.

I stick to my guns: Silicon Valley and especially Google is art regarding code and CS evolution. Same for FAANG etc.

EU is hubris to say the least.

Every time someone says “Let’s build our own Google/Cloud/…” a penguin dies.

E Invoice will be a brutal boomerang, XRechnung the greatest backdoor of all times.

Your data, time to shift everything into the EU.