Top storiesNew ZealandPoliticsBusinessEntertainmentSportsWorld

Measures loom to tell people if their data is hacked

Thursday, 14 December 2017

Most data breaches are swept under the rug by companies and if they are found out it isn't until personal information has long been copied and pasted off of the site or platform. Most people don't know their info has been breached and to prove it

Companies often don't notify customers if their information has been breached, so Australian web expert Troy Hunt has taken on the job instead.

Hunt has created a free service – haveibeenpwned.com – that lets people see if their email has been found in a specific data breach, and what kind of personal information was leaked.

He regularly gets sent links to webpages where people have attached folders of hundreds, even thousands of individual data breaches, some with hundreds of millions of emails and passwords.

Companies either don
Companies either don't know they've been hacked, or don't want to tell their customers, so Australian web expert Troy Hunt is doing it for them.

When testifying in a United States Congressional Hearing last week about the impact of data breaches, Hunt compared the 'personal stash' people have of data collected from data breaches to a baseball card collection.

**READ MORE:

A lot of people collect and redistribute hacked data, which is how Troy comes across it.
A lot of people collect and redistribute hacked data, which is how Troy comes across it.

Embarrassed companies hit by ransomware pay up, and keep it quiet

Privacy Commissioner John Edwards talking about the Privacy Act.

Kiwis hit by Uber hack, no sign yet the data's been used

More LinkedIn members' information leaked after 2012 security breach**

'There is a culture of sharing data breaches and there are multiple drivers for this; in some cases we see data breaches monetised` so we see it being sold …

'Other times, and this is the one that still blows me away, we see a lot of people simply collecting and redistributing this data,' Hunt said.

Cesar Koene a photographerdiscovered his email and password had been sold online as part of the LinkedIn data breach.
Cesar Koene a photographerdiscovered his email and password had been sold online as part of the LinkedIn data breach.

He recalled seeing 167 million email addresses and 117 million passwords from LinkedIn's 2012 breach being sold online for 5 bitcoins, which at the time would have been several thousand dollars.

LinkedIn has never clarified how many users were affected by the breach, but reported affected users had to do a mandatory password reset.

Last year emails and passwords leaked in a 2012 security breach on LinkedIn were sold for 5 bitcoins online.
Last year emails and passwords leaked in a 2012 security breach on LinkedIn were sold for 5 bitcoins online.
Troy Hunt founder of haveibeenpwned.com speaks to US Congress about data breaches.

When Wellington photographer Cesar Koene used Hunt's website, he found out that his account and password had been one of those leaked in the 2012 LinkedIn breach.

'I never knew … I'm a bit shocked actually because you think it's secure but it's not really,' Koene said.

With no legal requirement requiring companies to tell users if their information has been hacked, those with compromised information are left vulnerable, especially if the password that hackers made public is one the victims use for other things.

Hunt said he knows from combing through thousands of data breaches that passwords being repeated is a widespread issue.

'The stuff we use to authenticate ourselves is becoming useless because so much data that we consider constrained to the head of an individual that uses it, like their mother's maiden name is now all over the web.'

Privacy Commissioner John Edwards says the case for fining companies that don
Privacy Commissioner John Edwards says the case for fining companies that don't report data breaches is compelling.

Hunt has seen data theft lead to payday loans taken out under someone's stolen identity, fraudulent tax returns filed, and 'SIM card hijacking' – getting control of someone's mobile phone.

'It's a mess at the moment.'

Hunt said sometimes companies are not even aware of breaches that have left personal information floating around the web.

He recently identified a 2014 data breach from image sharing website Imgur.

'They didn't know they had a data breach until someone sent it to me and I got in touch with them and said, 'I have millions of records of your data'.'

The Law Commission first proposed making mandatory breach reporting part of the new Privacy Bill, which is currently being drafted by the Parliamentary Counsel and the Ministry of Justice.

Privacy Commissioner John Edwards said without mandatory breach reporting, 'we don't have any information about how many data breaches there have been, and how many get reported, and how many get swept under the rug.'  

'All we know is what people chose to tell us and what we learn from the big international incidents like Ashley Madison like the LinkeIn like the Uber breach.'

Edwards hoped changes to the Privacy Act would require companies that have been breached to pay a larger fine, and compel companies to prove they have changed vulnerable security systems after a breach.

He recommended that Parliament adopt fines of up to $1 million for corporations that do not report breaches into the Privacy Act.

'At the moment there is no fine … but I think the case for fines is compelling.'

The European Union plans to pass a law in May of next year called General Data Protection Regulation (GDPR).

As it stands, the law will have the power to fine up to 4 per cent of global revenue, which for companies like Amazon, Google, Apple and Facebook could be billions of dollars.

Global research firm Gartner predicts massive spending increases on security services over the next year. 

Worldwide spending is expected to reach $86.4 billion by the end of this year, up 7 per cent on last year. 

Gartner's latest forecast predicted spending would grow to $96.3b in 2018. 

Research director Ruggero Contu said companies spending money on security is a reaction to high profile cyberattacks like WannaCry and NotPetya and the Equifax breach.