hhmx.de

Dave Rahardja

Föderation EN Fr 12.07.2024 21:36:34

How to not leak customer data:

- Don’t collect them

JacobRPG+ 🫘

Föderation EN Sa 13.07.2024 01:19:07

@drahardja πŸ’― I've been saying that in addition to holding business and governments accountable for data leaks, we must implement regulations that prevent collecting information not necessary to get the job done. I realize, even this is an idealistic dream, but it's what we should work towards.

PhilipKing

Föderation EN Sa 13.07.2024 11:54:57

@jaykass @drahardja What country are you in? Many countries already have that restriction and rules like not storing payment details (the payment processor issues a token valid only for the originator) The problem is that the sort of information you need for a service (email, payment and possibly physical address) is exactly the sort of information that hackers want.

PhilipKing

Föderation EN Sa 13.07.2024 16:19:42

@jaykass @drahardja I thought some states had quite tough data protection laws ?

JacobRPG+ 🫘

Föderation EN Sa 13.07.2024 16:22:40

@PhilipKing @drahardja possibly. But it sure seems like there is a lot of unnecessary information still collected. Though you have a great point that much of the core data to do business is exactly what hackers find valuable.

Misuse Case

Föderation EN So 14.07.2024 21:38:41

@jaykass @drahardja The U.S. government has this as an internal standard and requirement (data minimization). The private sector doesn’t really.

Peter Bindels

Föderation EN So 14.07.2024 22:14:12

@MisuseCase @jaykass @drahardja As long as the benefit for overgathering outweighs the penalty, companies will keep overgathering. We need companies that breach data to be held actually responsible - liquidated if need be - so other companies learn not to leak data.

Misuse Case

Föderation EN So 14.07.2024 22:19:37

@dascandy @jaykass @drahardja IMO we need to outlaw ad tracking and data brokering, those things make data monetizable.

Beans_please

Föderation EN Sa 13.07.2024 01:50:32

@drahardja but what if you invent, at astronomical expense, a perfect cyber Fort Knox which no one can break into because an employee clicked a link saying "FREE CANDY" which then directed them to a website where they put in their login details and MFA code?

Galbinus Caeli 🌯

Föderation EN Sa 13.07.2024 19:12:57

@beans_please @drahardja Let's not just blame foolish employees. Remember that there are organizations out there who will hold a million dollars in one hand and hold a gun to your child's head with the other while they "request" access to the data.

webhat

Föderation EN Sa 13.07.2024 03:04:13

@drahardja thank you for your TED Talk

sortius

Föderation EN Sa 13.07.2024 03:08:07

@drahardja easier said than done. It's legislated for some industries to collect information, and, in Australia, they must keep it for a certain amount of years πŸ˜–

The data retention legislation has already been blamed for the sheer amount of data stolen

Dave Rahardja

Föderation EN Sa 13.07.2024 03:23:55

@sortius Right. The fact that governments have given the responsibility of surveillance to telcos is a *huge* problem.

sortius

Föderation EN Sa 13.07.2024 03:28:55

@drahardja far far worse than they want to let on. I'm guessing a lot of breaches would be much less impactful if there was less emphasis on collecting and retaining information, and more on revokable trust systems between citizens and companies

Hunterrules

Föderation EN Sa 13.07.2024 04:20:31

@drahardja don't hold data if you can't secure it

Lot⁴⁹

Föderation EN Sa 13.07.2024 10:22:59

@drahardja That's no fun. Also less profitable.

mcSlibinas

Föderation EN Sa 13.07.2024 12:26:31

@drahardja impossible level of wisdom πŸ˜‰

m0xEE

Föderation EN Sa 13.07.2024 13:19:58

@drahardja
So easy!
Yet, this seems unthinkable to absolute most companies, they will offer you everything in the arsenal: from OTPs to having to set a new password after having logged in from a different IP address once β€”Β and no, of course your can't use your old one the one that is complex and yet you remember it well.
But not forcing you to enter your real name and other such things seems completely out of the question.

Orm Alephwyr ΘΔ

Föderation EN Sa 13.07.2024 13:21:08

@drahardja Literally illegal in half the world now.

artemis iris :therian:

Föderation · So 14.07.2024 09:59:28

Nitpick

Cal Alaera

Föderation EN So 14.07.2024 16:51:45

Vern McCandlish

Föderation EN So 14.07.2024 16:57:37

@drahardja So like "Zero Trust" but for customer data collection, so "Zero Data"

Richard W. Woodley RNKD BLTS    πŸ‡¨πŸ‡¦πŸŒΉπŸš΄‍β™‚οΈπŸ“· πŸ—ΊοΈ

Föderation EN So 14.07.2024 17:21:36

@drahardja
I do not recall which but I did notice a few online retailers give you the option to NOT have your credit card information kept for future use. That should be the normal default everywhere.

Retailers should not need your credit card information at all.

the5thc.blogspot.com/2022/04/h

πŸ‡©πŸ‡ͺ くら Woomy :disconnecting:

Föderation · So 14.07.2024 17:31:12

@drahardja@sfba.social b-b-b-but how do we send out personalized intimate ads otherwise?

Sweet Home Alaberta  πŸ‡¨πŸ‡¦ πŸ‡ΊπŸ‡¦ 🏳️‍🌈 🏳️‍⚧️ πŸ‡²πŸ‡½

Föderation EN So 14.07.2024 18:04:39

@drahardja
While waiting on hold for the bank, I heard that I could ask them to not use voice recognition. She was incredulous, but we got there. Now I have to answer ID questions, but the hackers have less opportunity to get my voice now.

Peter Bindels

Föderation EN So 14.07.2024 22:07:28

@drahardja Have you tried publishing any app on any app store? Half the questions are unanswerable if you don't.

Doug Baker

Föderation EN Mo 15.07.2024 17:21:45

@drahardja You do business with some company online: why do they need your information, say, 5 years later? Should be a law: "dump info after 3 years' of no further business..."

Kat

Föderation EN Mo 15.07.2024 17:24:50

@drahardja Cashier at Counter- Can I get your phone number?
Me- Nah.
*her perplexed look*

Aaron :apple_inc: :isles:

Föderation EN Mo 15.07.2024 19:35:28

@katmckatniss @drahardja Cashiers here: β€œCan I get your email address?”
Me: β€œI don’t have one”

Extinction Studies

Föderation EN Mo 15.07.2024 18:12:27

@drahardja There are companies who literally have no value other than the data they're collecting. Those companies, if liquidated, would sell their data to the highest bidder and the problem would persist. We need to make holding data toxic, or data extremely short lived. Like it should self destruct after 48 hours. And any company caught selling data should have its assets frozen. Money, credit, real estate, crypto. Forfeit.

Darwin Woodka

Föderation EN Di 16.07.2024 02:05:26

@aka_quant_noir @drahardja

We all need to own our own data, and they should pay us for using it.

Extinction Studies

Föderation EN Di 16.07.2024 02:44:08

@darwinwoodka @drahardja

They should pay a fine for holding it. Something comparable to what they're asking copyright violators to pay, per item of PHI.