There is a growing trend where organisations are strictly limiting the amount of information that they disclose in relation to a data breach. Linked is an ongoing example of such a drip feed of PR friendly motherhood statements.

As an ICT professional with 40 years experience, I’m aware that there’s a massive gap between disclosing how something was compromised, versus what data was exfiltrated.

For example, the fact that the linked organisation disclosed that their VoIP phone system was affected points to a significant breach, but there is no disclosure in relation to what personal information was affected.

For example, that particular organisation also has the global headquarters of a different organisation in their building, and has, at least in the past, had common office bearers. Was any data in that organisation affected?

My question is this:

What should be disclosed and what might come as a post mortem after systems have been secured restored?

  • Date that the breach occurred.
  • What parts of the system were accessed.
  • What data was compromised and if any of it is sensitive.
  • If any of this data was encrypted/hashed and what algorithm was used (i.e. I’d be far less worried about having passwords that are bcrypt hashed exposed compared to ones hashed with SHA1 or stored in plain text.)
The Doctor
link
fedilink
520d

Companies are trying to go back to the time when they got popped and told nobody.

Everything. Data breaches/leaks happen all the time. The more these companies have to admit what happened and be shamed and fined the more they will care about security for their customers.

Please don’t reveal my email address in your data breach announcement, sheesh.

i mean, i don’t think anyone has actually considered including the leaked data in the leak announcement. it seems so obvious to just say which fields are leaked that i hadn’t even considered that someone might think to include the data itself.

I responded to a comment that said everything. Everything means everything. We should qualify that it shouldn’t be everything.

There’s literally someone in another comment on this thread saying that they should be able to get the raw data that was leaked from the company on request.

@tsonfeir@lemmy.world
link
fedilink
13
edit-2
20d

deleted by creator

Please no. I don’t want a copy my passport image included in the announcement about the data leak. Its extremely hard to change my passport, and its better if its not on the official announcement, even if it is being traded on the darknet.

They should say what data fields were leaked, but not re-leak the actual raw data to the world on the clearnet.

@tsonfeir@lemmy.world
link
fedilink
3
edit-2
20d

deleted by creator

So you get kyc data on all their other customers? That’s literally a criminal offence in some countries.

Nha they publish metadata describing the leaked data. If you’re a data subject concerned by the incident you then request a copy of yr information which requires proper identification.

Why would they share the data itself….

Why does wikileaks share the data itself? People do these things…

They are active in whistleblowing, not privacy leak management…

Create a post

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

  • 0 users online
  • 57 users / day
  • 383 users / week
  • 1.5K users / month
  • 5.7K users / 6 months
  • 1 subscriber
  • 2.44K Posts
  • 57.3K Comments
  • Modlog