Welcome to Incremental Social! Learn more about this project here!
Check out lemmyverse to find more communities to join from here!

arrl.org

Clbull , to Privacy in How much should an organisation reveal about a data breach?
  • Date that the breach occurred.
  • What parts of the system were accessed.
  • What data was compromised and if any of it is sensitive.
  • If any of this data was encrypted/hashed and what algorithm was used (i.e. I'd be far less worried about having passwords that are bcrypt hashed exposed compared to ones hashed with SHA1 or stored in plain text.)
drwho , to Privacy in How much should an organisation reveal about a data breach?
@drwho@beehaw.org avatar

Companies are trying to go back to the time when they got popped and told nobody.

sic_semper_tyrannis , to Privacy in How much should an organisation reveal about a data breach?

Everything. Data breaches/leaks happen all the time. The more these companies have to admit what happened and be shamed and fined the more they will care about security for their customers.

delirious_owl ,
@delirious_owl@discuss.online avatar

Please don't reveal my email address in your data breach announcement, sheesh.

thedirtyknapkin ,

i mean, i don't think anyone has actually considered including the leaked data in the leak announcement. it seems so obvious to just say which fields are leaked that i hadn't even considered that someone might think to include the data itself.

delirious_owl ,
@delirious_owl@discuss.online avatar

I responded to a comment that said everything. Everything means everything. We should qualify that it shouldn't be everything.

There's literally someone in another comment on this thread saying that they should be able to get the raw data that was leaked from the company on request.

tsonfeir , to Privacy in How much should an organisation reveal about a data breach?
@tsonfeir@lemmy.world avatar

Every little detail. Including access to the raw data that was leaked (that pertains to the individual). The steps taken to correct the action if possible. The source of the attack, including raw access logs if possible.

Basically, let me decide how fucked I am, how it happened, and who now has my data.

delirious_owl ,
@delirious_owl@discuss.online avatar

Please no. I don't want a copy my passport image included in the announcement about the data leak. Its extremely hard to change my passport, and its better if its not on the official announcement, even if it is being traded on the darknet.

They should say what data fields were leaked, but not re-leak the actual raw data to the world on the clearnet.

tsonfeir ,
@tsonfeir@lemmy.world avatar

I didn’t mean they would publish the information to the internet in an insecure way. But I should, if i CHOOSE, get a copy of the leaked data. You don’t have to ask for it.

delirious_owl ,
@delirious_owl@discuss.online avatar

So you get kyc data on all their other customers? That's literally a criminal offence in some countries.

a4ng3l ,

Nha they publish metadata describing the leaked data. If you’re a data subject concerned by the incident you then request a copy of yr information which requires proper identification.

Why would they share the data itself….

delirious_owl ,
@delirious_owl@discuss.online avatar

Why does wikileaks share the data itself? People do these things..

a4ng3l ,

They are active in whistleblowing, not privacy leak management…

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • incremental_games
  • meta
  • All magazines