8 ms·
Those on HN are considered extremely tech-savvy and security aware and yet we are still concerned about our accounts getting compromised like this. What can a r
by galaxytachyon 1y ago
Those on HN are considered extremely tech-savvy and security aware and yet we are still concerned about our accounts getting compromised like this. What can a random user like our moms or siblings do? They won't even notice these kind of attack.
It is such a pathetic state of affair where massive leaks like these are expected. I contend this is a result of lax regulation and lack of consequences. In healthcare, patient data are locked down so hard even people who need to work with them have problems getting to them. It is because of regulations. Everything is traceable, recorded, and maintained to the strictest standards possible. It costs a huge amount of money but as a result, we don't see many serious breaches.
Compared it to fintech and regular tech services, these guys make fuckton of profits and yet suffer almost no regulations. What a joke.
- exiguus 1y agoMaybe they can't. But actually, you can install them a password manager and let them generate random password. Setup with them 2fa (FreeOTP or something). And change with them every password when you are at home for chrismas. Also, when they now found themself on have i been powned, they have a bigger problem, because they have likely malware on the phone or computer.
- jsnell 1y agoWhat regulation are you proposing? Forcing all computers to be locked down so hard that users can't install malware?
- 6510 1y agoWe would have to go outside to find dopamine. It wouldn't be safe. People would die. edit: I remember thinking in the 90's that it was weird as hell that the operating system sits in the same folder tree as the users documents, applications live there too! What a concept? Like keeping your socks in the same drawer as your bills and plumbing tools. Spare tire in the kitchen. Lawn mower under the bed.
- galaxytachyon 1y agoMaybe we can start with heavy penalties for whoever responsible for these breaches? The users are irresponsible, but at the higher levels, the company can afford to tighten access and guard their data better. Would these companies leak their own business critical documents? No. So why can't they be forced to treat sensitive customer's data the same way?
- jsnell 1y agoThis is not data leaked by businesses. The businesses were also not breached. The data was stolen from the users' computers, by malware installed by the users themselves.
- throw10920 1y ago> In healthcare, patient data are locked down so hard even people who need to work with them have problems getting to them. It is because of regulations. Everything is traceable, recorded, and maintained to the strictest standards possible. It costs a huge amount of money but as a result, we don't see many serious breaches. ...and one of the side-effects is that it contributes to the insane price of healthcare. Effective regulation, like security, is about finding the sweet spot between security and efficiency. It's extremely easy to turn off your brain and say that nobody has access to the data (which makes it perfectly secure/private) - but obviously that's an insane approach. It's hard, but extremely important, to actually maximize the security-efficiency product. PII should not have the regulations that are currently applied to healthcare/PHI - it'd massively increase the costs (both financial, and worker/individual productivity) of doing everything. It needs a better regulation model that is designed to maximize the security-efficiency product. Most likely, the best model is one that focuses more on outcomes (huge penalties for leaking PII, along with a few things like chain of custody for user data (which I don't think that even HIPAA does) - not to exclude regulation of process of course) than processes (HIPAA describing in excruciating and unnecessary detail all of the ways that you have to process PHI - which include RESTRICTING THE WAYS THAT I CAN MANAGE MY OWN HEALTH DATA).
- galaxytachyon 1y agoThe cost of healthcare is unlikely due to data management cost. That is almost an absurd comment. The cost to develop a drug is in the billions. Manufacturing costs are in the tens to hundreds of millions. Locking down some server and implement better security would be a drop in a bucket. And even if it was more expensive, the biggest pharma megacorps are a fraction of the size of the like of tech megacorps. If the chumps down the street can do it as a side job, why can't the big boys whose entire business is supposedly about data and software can't do better?
- throw10920 1y ago> The cost of healthcare is unlikely due to data management cost. That is almost an absurd comment. I did not state that it was solely due to that. Please read my comment carefully: > ...and one of the side-effects is that it contributes to the insane price of healthcare. Meanwhile, this is a crazy red herring: > The cost to develop a drug is in the billions. Manufacturing costs are in the tens to hundreds of millions. The cost for smaller practices and procedures that have nothing to do with drugs or manufacturing has skyrocketed. It's not very hard to understand that the primary cost of regulation is on smaller businesses and practices. Regulation imposes a disproportionate cost on smaller organizations, leading to consolidation. This is a bad thing. The results of regulation can be a net benefit if you reduce those costs while maximizing the positive effects. This should be incredibly obvious. Moreover, this is a rather uninformed claim: > Locking down some server and implement better security would be a drop in a bucket. That's not how HIPPA works. HIPPA prescribes that you have to use certain HIPPA-compliant services and technologies. That's not a cost burden - that's a compliance burden. It's not enough for your systems to be secure - they have to be HIPPA-compliant, which is so insanely difficult for small practices to do in-house that it forces all of them to use large, expensive, complex medical platforms, and pushes many others to consolidate with larger hospitals in order to amortize the overhead of managing these systems. And guess what? Consolidation in markets without extremely strict anti-monopoly enforcement leads to higher prices and worse products and services. Yes, the cost of actually running the servers is very low. But that's almost never the primary cost of regulation - that's straight-up factually false. The primary cost of regulation is the overhead of compliance. That's why any sane person strives to maximize the security-efficiency product, or the analog in whatever area you're trying to regulate. There's literally no excuse for not trying to do this, or for defending the idea that we shouldn't take efficiency into account when designing regulation, except malice. > If the chumps down the street can do it as a side job Yes, and as is incredibly obvious to everyone, healthcare is orders of magnitude more expensive than services provided by those tech megacorps. This is evidence (even if weak), that bad regulation makes things more expensive, not less. > why can't the big boys whose entire business is supposedly about data and software can't do better? You clearly did not read my whole comment. I'm not arguing that regulation isn't necessary. I'm pointing out the fact that you have to optimize the security-efficiency product, and NOT do what HIPPA does, which is maximize security at the cost of a very high amount of efficiency to the point where it infringes on patient rights. The only absurd comment here is the one that did not actually read what it was responding to, and is mostly composed of red herrings, claims that don't line up with reality, and logical fallacies.
- tialaramex 1y ago> What can a random user like our moms or siblings do? Security Keys. Your mother and siblings have seen keys before right? They can understand the metaphor and use it. Several of the accounts listed, such as Google and Facebook allow Security Keys. Bad guys can't steal the credentials out of Security Keys the way they'd steal say passwords or a TOTP code, they would need to physically obtain access to the keys, your mother and siblings almost certainly don't face adversaries who'll break into their homes or hold them at gunpoint, just ordinary online automated attacks.
- ghusto 1y agoLegit question from someone who both wants their mum to stop getting hacked, and is not sure Security Keys are a good idea: What happens when they lose their phone? My limited understanding is that the key is on their phone (let's say it's a Google key, on an Android phone). When their phone gets lost, stolen, or breaks, are they screwed? This worries me because the chances of the phone being lost is high.
- jgerrish 1y agoSafety deposit box with backup recovery codes. That puts a lot of burden on users though. Maybe start a pilot automated service run by Google or Microsoft or whoever where backup codes are securely sent to local credit unions and it's all almost transparent to the user. They just need to either pick up the code at the credit union and put it in their safety deposit box or approve that last step. I'm not upset at all about banking working with private entities or any of the past with banks. I'm mostly upset because some of these ideas are good, you know? Maybe not this, but some. For a short while longer.
- deleted 1y ago[deleted]
- gabeio 1y agoSecurity Keys are an independent device. I believe you are thinking of Passkeys which can live on the phone or in a password manager like 1Password. If you do go with a security key it’s typically recommended to have at least 2 so that if one dies or is lost both have the same level of access. So long as you add them both/all to every account you need to access.
- charcircuit 1y agoBiometric authentication / passkeys / other forms of authentication which are not phishable and are backed by a random key. Then proper OS security is needed to protect authentication tokens from being stolen by malware.
- dogmatism 1y agowait what? CHS lost millions of records, was fined a few million (out of profit of 1.2 billion) UCLA similar. Bunch of others I don't think even got fined like Ascension recently lost all data in a ransomware attack It's useful going after a rogue employee, but on an org level it's security theater
- const_cast 1y ago> What can a random user like our moms or siblings do? Install a password manager. It's the perfect piece of software. It's not only so much more secure, but it's just a more pleasant experience in every single way. It's very rare that the secure option is more convenient.