Nothing really new here sadly, this information about me have leaked half a dozen of times in the past 2-3 years or so. These things will never change if the only penalty the company/agency gets is "send a message to your users saying you are sorry and that it won’t happen again".
Because of the inevitable breaches and leaks - KYC is the illicit activity. The selling point of KYC was preventing fraud and money laundering. It doesn't actually do that. Search for "largest money laundering settlements" and you will find 5 banks and one crypto scam.
The way to fix it is to empower one government agency to do aggressive pentesting against every other agency, hospitals, banks, infrastructure, and big corporations, with salaries matching the private sector. Impose a legally-enforced deadline to fix any issues, with a fine (for private actors) or demotion of the guy in charge of infosec (for state agencies).
Forget compliance checklists, KPMG "audits" and all that crap, just have government-sponsored hackers trying to get into everything like an attacker would.
France seems to have had a ton of government hacks in the past year at various levels, so it's sorely needed.
I feel like if we're going to make progress in preventing wholesale data breaches it will be through architectural innovations that attack the problem of why a trove of concentrated data needs to exist. Even if the government needs to be a central authority, are there ways to house the data that limit the blast radius?
I'm sure there are innumerable arguments why this can't help, but when the mainstream alternative is despair and helplessness, progress will be made in the margins.
So, you want the French government to fine the French government so the French government uses French taxpayer money to pay the French government for the French government's mistake?
What is the penalty for the government?
> These things will never change if the only penalty the company/agency gets is
I do not think penalties can prevent these situations. Perhaps they may be less frequent; perhaps people would get more compensation, but ultimately I do not think these can be prevented. The first consideration is why the data has to be stored in the first place. Naturally one can say "the government needs to know who is a citizen and who is not", and I can understand this rationale to some extent, but even then I wonder whether this has to be correct. Perhaps we could have a global society without any requirement to be an identifiable citizen per se. Things such as mandatory age verification-sniffing to never become an issue, because it is not needed and not possible and nobody would have an addiction-need to sniff for that data (we know Meta and co want that data, this is why their lobbyists run rampage via the "but but but somebody protect the children" lie).
Facts at Equifax
Ironically it changes nothing for me as that same data had already been leaked by the French government agency that handles unemployment benefits a couple years ago. Silly me had not bothered deleting that account even after it was no longer necessary due to finding a new job.
This problem has long been solved with federated IdPs and MFA - something you own like OTP device/physical token besides something you know like SSN/tax id/password.
Most governments prefer biometrics of course because citizen privacy is the opposite of what they want.
If you want to build a society on information, then you cannot forget the most important group.
Like they didn't have access to it anyway.
They were probably screwed as f... or they had/have some interests somewhere ($$$).
In the last decade, all web sites were broken to be replaced by web apps ($$$), creating a hard dependency on the massively huge and complex "whatng cartel" web engines and their related massively complex c++ compilers. It is very hard to believe to anything else than corruption, really hard.
This document, which is law, which only the president and prime minister have power on, must be modified to make the difference between web sites and web apps and to mandate a web site for core and critical online services of gov and dependencies. Aka, restore noscript/basic (x)html interoperability, or "small" and technically reasonable web engines (to foster real-life alternatives from citizen, local company, etc, initiatives). All of such online services had a working web site (no app) before this document sold the gov and its dependencies to big tech (here the "whatng cartel").
No gov authorities (competition/anti-trust, justice, etc), not even the parliaments can do anything here, only the president and the prime minister.
Hardly believable, and I found out only a month ago, in spite of consulting lawyers, being part of related user groups with legal experts, etc, for 10 years. I could not understand what was going on, all this money and 'loss of strategic control' channelled in those 'companies'.
It also ensured democratic participation by all of the people employed there making sure that processes are followed and making sure no one is cheating.
We all knew that systems like this would get breached. It’s not a matter of, “if,” but, “when.” If we’re going to continue down this route because of convenience or surveillance and authoritarianism or whatever; people designing these systems need to thinking: When this system is breached…. And they should make sure there’s a good story for protecting people and the system from these sorts of events.
There will be zero risks to you of course, because their software is magically perfect, unlike any other software created in the history of mankind.
It's the age of the leak and the sooner we accept, no matter our efforts, we live in a security free world and design around that - the better
This is a major reason as to why I am so strongly against all this verification shit governments keep trying to push, the best way to keep data secure is not to have it in the first place, therefore my personal data should not leave my device except in the strictest of circumstances for things like my name/DOB/address/SSN.
They hack the taxes and the heath insurance system and yhay have everything about us.
What a shitty world because of these idiots
„Small, not harmful leak of non important data, few records only”
Or are they magically exempt?
Google selling data? So far no one came to blackmail me for certain dispositions, while the other does as they want, IRS, foreign governments, social security whatever.
Google can be sued while the other gives itself a pass.
Who is the baddie?
In Germany the administration put massive duties on IT providers and added punitive damage as a looming consequence.
Fast forward and the government with its “Ha, we are so digital!” and “Europe is better than US in CS!” suddenly has to swallow some brutal medicine I guess.
I stick to my guns: Silicon Valley and especially Google is art regarding code and CS evolution. Same for FAANG etc.
EU is hubris to say the least.
Every time someone says “Let’s build our own Google/Cloud/…” a penguin dies.
E Invoice will be a brutal boomerang, XRechnung the greatest backdoor of all times.
Your data, time to shift everything into the EU.