• Our new ticketing site is now live! Using either this or the original site (both powered by TrainSplit) helps support the running of the forum with every ticket purchase! Find out more and ask any questions/give us feedback in this thread!

LNER customer data loss

Status
Not open for further replies.

enginedin

Member
Joined
15 Dec 2020
Messages
473
Location
UK
Doesn’t look to be a formatted mailshot email, it looks like it’s been sent individually.
it's not difficult to send emails which are basically an (e)mail-merge - e.g. Outlook has it built in, so you can compose an email and send it to everyone in a database / spreadsheet. I doubt each email was really sent individually
 
Sponsor Post - registered members do not see these adverts; click here to register, or click here to log in
R

RailUK Forums

duffield

Established Member
Joined
31 Jul 2013
Messages
3,268
Location
East Midlands
Which it's worth noting is some of the most intrusive data gathering that commercial companies undertake.
At least in my case, Tesco get zero extra information about my buying habits from me having a Clubcard - because I have everything delivered, so they already know exactly what I buy.
 

DynamicSpirit

Established Member
Joined
12 Apr 2012
Messages
9,211
Location
SE London
It's about time these companies were fined £x for every piece of customer data they allow to be compromised - it's the only way they'll learn.

That would be on the logic that, if, say, someone breaks into your house, or mugs you in the street, you should be fined for 'allowing' the crime against you to happen, right?

Or we could remember that the bad guys here are the people who quite deliberately break into company systems in order to steal data - and they are the ones who need to be tracked down and put in prison. The organisations whose systems get hacked into aren't the criminals - they are victims of the crime.

Now I shoud qualify that: If a company has actually been negligent in the way they stored the data, or has not acted appropriately in response to the data being stolen (for example, failing to quickly notifying customers), then there's a good case for fining them for that. But it makes no sense to fine them merely for being victims of a crime.

== Doublepost prevention - post automatically merged: ==

Companies need to improve their systems, take a dual key approach to more functions, and use outsourcing only if there is no other option. One of my previous bosses once said to me: you only outsource if you don't care. I think he had a point.

Improving systems comes at a cost - it's not free! That ultimately impacts the prices you pay for - in the case of LNER, your tickets, or in the case of any other company, whatever you're buying from them. It's not possible to get absolute 100% guaranteed security: At some point you have to balance how much security you want vs. the cost of having that security.

Ditto outsourcing - companies typically outsource because that means they can get the service provided more cheaply than they could have done it themselves (probably because the company they are outsourcing to specialises in that particular service and therefore already has all the required expertise). You can stop lots of outsourcing, but that will probably mean more expensive products and less efficient security as each company has to pay for its own specialist staff.
 
Last edited:

DarloRich

Veteran Member
Joined
12 Oct 2010
Messages
32,887
Location
Fenny Stratford
What data has actually been lost here? I am sure that scammers and criminals in Craplakistan are able to use data that I travelled from York to London for nefarious purposes!

Obviously, OBVIOUSLY, a data breach is bad but the head loss here is out of all proportion to what has actually been lost. I bet there are much worse breaches involving intimate personal data that you know nothing about.
 
Last edited:

Halwynd

Member
Joined
11 Sep 2021
Messages
555
Location
North West
That would be on the logic that, if, say, someone breaks into your house, or mugs you in the street, you should be fined for 'allowing' the crime against you to happen, right?

Or we could remember that the bad guys here are the people who quite deliberately break into company systems in order to steal data - and they are the ones who need to be tracked down and put in prison. The organisations whose systems get hacked into aren't the criminals - they are victims of the crime.

Now I shoud qualify that: If a company has actually been negligent in the way they stored the data, or has not acted appropriately in response to the data being stolen (for example, failing to quickly notifying customers), then there's a good case for fining them for that. But it makes no sense to fine them merely for being victims of a crime.

== Doublepost prevention - post automatically merged: ==



Improving systems comes at a cost - it's not free! That ultimately impacts the prices you pay for - in the case of LNER, your tickets, or in the case of any other company, whatever you're buying from them. It's not possible to get absolute 100% guaranteed security: At some point you have to balance how much security you want vs. the cost of having that security.

Ditto outsourcing - companies typically outsource because that means they can get the service provided more cheaply than they could have done it themselves (probably because the company they are outsourcing to specialises in that particular service and therefore already has all the required expertise). You can stop lots of outsourcing, but that will probably mean more expensive products and less efficient security as each company has to pay for its own specialist staff.

It's only like breaking into your house if you keep the data of 300,000 customers in your bedroom...

The 'bad guys' don't always 'break into company systems' - in recent breach examples, such as M&S, they just rang up and asked for the keys to the front door - and were given them.

Improving systems does come at a cost - but the M&S breach cost them £300m in lost profit alone, Jaguar Land Rover are currently shut down and unable to manufacture or trade, with reports that smaller businesses in the supply chain might actually go bust. Penny wise, pound foolish.
 

duffield

Established Member
Joined
31 Jul 2013
Messages
3,268
Location
East Midlands
Any company whose systems are breached due to lack of multi-factor authentication should be fined. There's no excuse these days for any internal company system to be accessible just with an id and password.

All companies should be using at least two factor authentication by now and be moving to the gold standard, three factor authentication, which as per previous posts is "something you are, something you have and something you know", i.e. biometric (fingerprint etc.) + authentication device (smartcard, USB security token etc.) + PIN.

These measures were expensive and uncommon a few years ago, now they are cheap and readily available to any business and there is no excuse for not using them, since they completely block certain categories of social engineering - an employee can hand over their userid and password when a bogus "help desk" contacts them, but they can't hand over their fingerprint or physical token. These measures also make various categories of malware (like keyloggers) useless again since that only gets one out of the three things you need for access.

Also any company which is lax about applying security patches should be fined; it's a basic requirement for doing business and skimping on this is gross negligence. A company whose systems are taken over due to an exploit which was (for example) patched six months ago is not a company fit to be entrusted with other people's data.

Only companies which follow best practice in these sort of areas should be exempt from being fined in the event of a breach.

It's all very well to say "blame and punish the criminals, these companies are just victims" but in the real world many of the criminals are untraceable, and of those who are traceable most of them are beyond the reach of our law enforcement systems. With virtually every company being under constant attack they owe a duty of care to those whose data they hold and there is no excuse for penny-pinching and incompetence in this area.
 

takno

Verified Rep - Traksy
Joined
9 Jul 2016
Messages
6,574
Any company whose systems are breached due to lack of multi-factor authentication should be fined. There's no excuse these days for any internal company system to be accessible just with an id and password.

All companies should be using at least two factor authentication by now and be moving to the gold standard, three factor authentication, which as per previous posts is "something you are, something you have and something you know", i.e. biometric (fingerprint etc.) + authentication device (smartcard, USB security token etc.) + PIN.

These measures were expensive and uncommon a few years ago, now they are cheap and readily available to any business and there is no excuse for not using them, since they completely block certain categories of social engineering - an employee can hand over their userid and password when a bogus "help desk" contacts them, but they can't hand over their fingerprint or physical token. These measures also make various categories of malware (like keyloggers) useless again since that only gets one out of the three things you need for access.

Also any company which is lax about applying security patches should be fined; it's a basic requirement for doing business and skimping on this is gross negligence. A company whose systems are taken over due to an exploit which was (for example) patched six months ago is not a company fit to be entrusted with other people's data.

Only companies which follow best practice in these sort of areas should be exempt from being fined in the event of a breach.

It's all very well to say "blame and punish the criminals, these companies are just victims" but in the real world many of the criminals are untraceable, and of those who are traceable most of them are beyond the reach of our law enforcement systems. With virtually every company being under constant attack they owe a duty of care to those whose data they hold and there is no excuse for penny-pinching and incompetence in this area.
That's an extensive manifesto of things virtually no companies do, which focuses huge expense on a couple of areas. The problems with it are the false sense of security it gives, and the way it uses up the entire budget and leads to skimping in other areas

You could easily do all this and still end up hiring a wrong-un, whether from North Korea or just down the road. Or you could fall victim to one of the many zero-day vulnerabilities that exist. Or you could end up with all the people able to do the patching locked out of the system, or just generally unable to do normal business because you've invented a security regime that your normal employees struggle to comply with. Or this could happen to one of your suppliers, or their suppliers.

Furthermore, you aren't even starting to mitigate against software supply chain attacks which "modern best practice" development have left wide open, and aren't addressed at all by anything you suggest.

There's a lot of real problems here, but absolutely none of them are helped by arbitrary legal requirements for unusual tech and unworkable processes, or posturing fines.
 

duffield

Established Member
Joined
31 Jul 2013
Messages
3,268
Location
East Midlands
That's an extensive manifesto of things virtually no companies do, which focuses huge expense on a couple of areas. The problems with it are the false sense of security it gives, and the way it uses up the entire budget and leads to skimping in other areas

You could easily do all this and still end up hiring a wrong-un, whether from North Korea or just down the road. Or you could fall victim to one of the many zero-day vulnerabilities that exist. Or you could end up with all the people able to do the patching locked out of the system, or just generally unable to do normal business because you've invented a security regime that your normal employees struggle to comply with. Or this could happen to one of your suppliers, or their suppliers.

Furthermore, you aren't even starting to mitigate against software supply chain attacks which "modern best practice" development have left wide open, and aren't addressed at all by anything you suggest.

There's a lot of real problems here, but absolutely none of them are helped by arbitrary legal requirements for unusual tech and unworkable processes, or posturing fines.
I'm sorry but I don't in any way regard fingerprint authentication or security tokens as either unusual or unworkable these days. They're standard in many industries and companies; many laptops come with fingerprint readers, and tokens like Yubikeys are cheap and common; support for fingerprints, tokens and other methods is baked into Windows, although it seems to be limited to fingerprint+PIN or token+PIN rather than all three.

Before I retired recently, every system I had access to required a token (USB or smartcard) for login and selected other functions. That was five years ago and we had been using those methods for at least a decade, longer for some systems.

I know these things are not a panacea, but these days it simply should not be possible for an employee to "hand over" their credentials to some convincing scammer. Yet this still happens.

Also I'm not arguing for specific, arbitrary legal requirements; what I'm getting at is that the factors I've mentioned are examples of what should be taken into account when deciding whether to issue a fine. Zero day exploit? Probably not your fault. Employee handed over the admin credentials to your critical system to a scammer on the phone? Probably your fault, should not be possible.
 

takno

Verified Rep - Traksy
Joined
9 Jul 2016
Messages
6,574
I'm sorry but I don't in any way regard fingerprint authentication or security tokens as either unusual or unworkable these days. They're standard in many industries and companies; many laptops come with fingerprint readers, and tokens like Yubikeys are cheap and common; support for fingerprints, tokens and other methods is baked into Windows, although it seems to be limited to fingerprint+PIN or token+PIN rather than all three.

Before I retired recently, every system I had access to required a token (USB or smartcard) for login and selected other functions. That was five years ago and we had been using those methods for at least a decade, longer for some systems.

I know these things are not a panacea, but these days it simply should not be possible for an employee to "hand over" their credentials to some convincing scammer. Yet this still happens.

Also I'm not arguing for specific, arbitrary legal requirements; what I'm getting at is that the factors I've mentioned are examples of what should be taken into account when deciding whether to issue a fine. Zero day exploit? Probably not your fault. Employee handed over the admin credentials to your critical system to a scammer on the phone? Probably your fault, should not be possible.
USB/Smartcard is still just 2-factor. In general you social-engineer these by phoning the helpdesk and saying you lost the key/card and getting the second factor reset. Biometrics are actually still largely 2-factor as well, just with a device which requires a biometric to release the code - again you can social-engineer by claiming to have lost the device.
 

Taunton

Veteran Member
Joined
1 Aug 2013
Messages
12,218
It's about time these companies were fined £x for every piece of customer data they allow to be compromised - it's the only way they'll learn.
Rather victim blaming. Like if your house has been burgled, instead of looking for the perpetrator the police fine YOU instead.

Before long whoever the fines go to will start setting budgets for this windfall ...
 

35B

Established Member
Joined
19 Dec 2011
Messages
5,362
I'm sorry but I don't in any way regard fingerprint authentication or security tokens as either unusual or unworkable these days. They're standard in many industries and companies; many laptops come with fingerprint readers, and tokens like Yubikeys are cheap and common; support for fingerprints, tokens and other methods is baked into Windows, although it seems to be limited to fingerprint+PIN or token+PIN rather than all three.

Before I retired recently, every system I had access to required a token (USB or smartcard) for login and selected other functions. That was five years ago and we had been using those methods for at least a decade, longer for some systems.

I know these things are not a panacea, but these days it simply should not be possible for an employee to "hand over" their credentials to some convincing scammer. Yet this still happens.

Also I'm not arguing for specific, arbitrary legal requirements; what I'm getting at is that the factors I've mentioned are examples of what should be taken into account when deciding whether to issue a fine. Zero day exploit? Probably not your fault. Employee handed over the admin credentials to your critical system to a scammer on the phone? Probably your fault, should not be possible.
They aren’t necessarily especially difficult. But if you codify a particular technology in law, you make it harder to move on when technology advances.

The other point is that these are commercial IT systems, used to serve a commercial purpose. I’ve had to contact a Helpdesk for a forgotten password; it’s time consuming and frustrating, and prevents me doing my job. The security policy needs to balance absolute protection against practicality.

There’s a further point that is lost in your pursuit of punitive measures. In these cases, businesses lose large sums. The staff (including those whose job it is to manage security) lose large amounts of their lives to fixing the problem - I’ve seen the hollow eyes and heard the exhaustion that result.

To a person, they are trying to do a good job, and fix the damage caused by the criminals who’ve caused the problem. Firing blame around doesn’t help fix the problem, and may well make it harder to fix as people refuse to say what happened.
 
Joined
16 Aug 2017
Messages
455
Many people also swear by password managers
I think this is the only way to go, really, if you have more than a few passwords because they should all be different and nobody can remember enough words! Then you can put all the effort into remembering a strong password for the password manager, with a second factor. Another benefit of a password manager is that it will put up a fight if you are trying to use your credentials on a different web address or app.

And to keep it on-topic, I see the Rail Data Marketplace has many unnecessary rules about what they'll accept in a password (min / max / capitals / these special characters / but not those special characters), and any site that has a maximum password length is an immediate red flag. In passwords, length is better than complexity.
 
Joined
14 Jun 2022
Messages
45
Location
Yorkshire
What data has actually been lost here? I am sure that scammers and criminals in Craplakistan are able to use data that I travelled from York to London for nefarious purposes!

Obviously, OBVIOUSLY, a data breach is bad but the head loss here is out of all proportion to what has actually been lost. I bet there are much worse breaches involving intimate personal data that you know nothing about.
According to the email I received, my name my email address, origin and destination from one journey I made and the fact that I used a two together railcard. Journey was in 2024, checked my account. Was March 2024
 

sprunt

Established Member
Joined
22 Jul 2017
Messages
1,624
Rather victim blaming. Like if your house has been burgled, instead of looking for the perpetrator the police fine YOU instead.

It's more like if you told people that they could store their valuables safely in your house then you didn't bother locking the door. The fines are not for being a victim of a crime, they are for letting down the people whose data they are supposed to be looking after safely.
 

Bletchleyite

Veteran Member
Joined
20 Oct 2014
Messages
112,941
Location
"Marston Vale mafia"
It's more like if you told people that they could store their valuables safely in your house then you didn't bother locking the door. The fines are not for being a victim of a crime, they are for letting down the people whose data they are supposed to be looking after safely.

Or perhaps comparable to an airport failing to provide the correct security, resulting in a serious incident. Not only the perpetrators would be hauled over the coals, but also the airport. There shouldn't be crime, but as there is there are duties to mitigate against it to keep people safe - not just physical but also their data.
 

35B

Established Member
Joined
19 Dec 2011
Messages
5,362
It's more like if you told people that they could store their valuables safely in your house then you didn't bother locking the door. The fines are not for being a victim of a crime, they are for letting down the people whose data they are supposed to be looking after safely.
Which is fine, so long as you acknowledge a) that the breached supplier will suffer commercially and b) that there still needs to be a question of fault - being breached is not evidence of fault in itself.
 

DynamicSpirit

Established Member
Joined
12 Apr 2012
Messages
9,211
Location
SE London
It's more like if you told people that they could store their valuables safely in your house then you didn't bother locking the door. The fines are not for being a victim of a crime, they are for letting down the people whose data they are supposed to be looking after safely.

Well that depends. Sure, if it's roughly like your example then it would be reasonable to be fined for not looking after the people's valuables safely. But what if you did lock the door but the thieves gained access by breaking in the windows? Or If you locked the door, boarded up the windows, but the thieves gained access by battering down the door...? And so on. At some point you'd surely say that you took all reasonable proportionate security precautions and it wouldn't be at all fair for you to be fined or to be blamed.

The thing is, most of us would have a fair sense of that things we can do to mitigate the risk of someone physically breaking into your house, but very few of us have a comparable understanding of good practices when it comes to digital security. Probably most of us know some things (the need to use strongish passwords, to be sceptical of someone phoning out of the blue claiming to be from Microsoft, not to open unknown links in emails, and such like), but beyond that it's a specialist skill. I mean, I'm a professional software engineer so I probably know more than most people about digital security, but even I am in no position to judge whether or not a company is following good best practices (unless that company makes a really rookie mistake). And with that lack of knowledge comes the temptation to assume any successful hack must mean the organization that fell victim must be at fault. But it's not the case at all. Absolute 100% security is just not possible - and you can't assume that just because a company has been hacked, that means the company is at serious fault.
 

duffield

Established Member
Joined
31 Jul 2013
Messages
3,268
Location
East Midlands
Well that depends. Sure, if it's roughly like your example then it would be reasonable to be fined for not looking after the people's valuables safely. But what if you did lock the door but the thieves gained access by breaking in the windows? Or If you locked the door, boarded up the windows, but the thieves gained access by battering down the door...? And so on. At some point you'd surely say that you took all reasonable proportionate security precautions and it wouldn't be at all fair for you to be fined or to be blamed.

The thing is, most of us would have a fair sense of that things we can do to mitigate the risk of someone physically breaking into your house, but very few of us have a comparable understanding of good practices when it comes to digital security. Probably most of us know some things (the need to use strongish passwords, to be sceptical of someone phoning out of the blue claiming to be from Microsoft, not to open unknown links in emails, and such like), but beyond that it's a specialist skill. I mean, I'm a professional software engineer so I probably know more than most people about digital security, but even I am in no position to judge whether or not a company is following good best practices (unless that company makes a really rookie mistake). And with that lack of knowledge comes the temptation to assume any successful hack must mean the organization that fell victim must be at fault. But it's not the case at all. Absolute 100% security is just not possible - and you can't assume that just because a company has been hacked, that means the company is at serious fault.
But frequently when we do find out, the cause is someone's credentials being simply socially engineered or similar, and if those credentials involved a separate physical token or biometric, that method would be literally impossible without the additional and much more difficult and time consuming step of also obtaining the token or spoofing the biometrics. If a company has not taken those measures they are clearly negligent.
 

35B

Established Member
Joined
19 Dec 2011
Messages
5,362
But frequently when we do find out, the cause is someone's credentials being simply socially engineered or similar, and if those credentials involved a separate physical token or biometric, that method would be literally impossible without the additional and much more difficult and time consuming step of also obtaining the token or spoofing the biometrics. If a company has not taken those measures they are clearly negligent.
A false logic, as there are still potential holes that can be exploited - just consider the lost token scenario to think about how it might be possible to get past that.
 

DynamicSpirit

Established Member
Joined
12 Apr 2012
Messages
9,211
Location
SE London
But frequently when we do find out, the cause is someone's credentials being simply socially engineered or similar, and if those credentials involved a separate physical token or biometric, that method would be literally impossible without the additional and much more difficult and time consuming step of also obtaining the token or spoofing the biometrics. If a company has not taken those measures they are clearly negligent.

To use a very obvious counter-example, Railforums doesn't require a separate physical token or biometric for us to login (Although the site does offer the option of 2-step verification for those who wish it). So the logic of your comment would be that railforums is clearly negligent! Do you really believe that?

To be clear, I don't believe that at all: Railforums uses passwords - which (provided properly implemented) is a perfectly appropriate level of security for a non-profit-making group of volunteers providing a free service where you just couldn't justify the expense of buying in additional security - and I doubt most people would be interested in the extra hassle of doing 2-step verification just to login to read comments on a public forum. FWIW I volunteer for a similar enthusiast group for which people need to login to a website, and I'm pretty sure if we were required to use biometrics, we'd simply end up having to close down because of not being able to afford the expense. You can't just assume that any organization that only uses passwords is 'clearly negligent' - it's going to be very dependant on the context/nature of the services/etc.

Of course if it's a large company that has much more resources and is dealing with much more sensitive data - the most obvious example being a bank - then you would expect far greater security. But then, for something like a bank, most people are willing to put up with it being somewhat harder to login because they realise the dangers of their account being hacked are so huge.
 

duffield

Established Member
Joined
31 Jul 2013
Messages
3,268
Location
East Midlands
To use a very obvious counter-example, Railforums doesn't require a separate physical token or biometric for us to login (Although the site does offer the option of 2-step verification for those who wish it). So the logic of your comment would be that railforums is clearly negligent! Do you really believe that?

...
I hoped it was obvious I was talking about internal company systems, not trivial (not wishing to be insulting!) public forums. The sort of systems that give you access to customer data. The consequences on one individual having their UK rail forums account taken over are essentially zero.

== Doublepost prevention - post automatically merged: ==

A false logic, as there are still potential holes that can be exploited - just consider the lost token scenario to think about how it might be possible to get past that.
Really? Essentially you're saying because a security measure is not 100% effective it is worthless.

As far as a lost token is concerned, I can only speak for my former workplace, but if I lost my token the procedure was to order a replacement via the helpdesk - and it would be delivered by courier only to my registered base location to be personally signed for by me. So I don't see how that would help an attacker.

To emphasize: Social engineering to get simple id/password credentials on the phone or via email is a low hurdle. Performing that step and also obtaining a token or spoofing a biometric is, while not totally impossible, a very much higher hurdle. I really don't see why so many people seem to be disputing this. Companies that take security seriously (such as the one I worked for until recently) have been doing this for many years. More and more services are requiring 2FA rather than having it as an option. Are they all stupidly wasting their money?
 
Last edited:

enginedin

Member
Joined
15 Dec 2020
Messages
473
Location
UK
Performing that step and also obtaining a token or spoofing a biometric is, while not totally impossible, a very much higher hurdle.
I don't think anyone is disputing that. But there are plenty of criminals who are willing to put a _lot_ of effort into overcoming those hurdles - that doesn't mean those companies are negligent if a criminal is successful, which is what you're suggesting.

Another analogy would the Hatton Garden robbery - I'd think almost everyone would agree that the security protocols in place were suitable, but preventing people going to the effort that the robbers did wouldn't be something that the industry / insurance companies would require. Maybe you do think that the Deposit company was negligent though, for not being able to prevent it? (that's not that mean to be provocative, just a genuine understanding of where you sit along the risk / prevention spectrum)
 

duffield

Established Member
Joined
31 Jul 2013
Messages
3,268
Location
East Midlands
I don't think anyone is disputing that. But there are plenty of criminals who are willing to put a _lot_ of effort into overcoming those hurdles - that doesn't mean those companies are negligent if a criminal is successful, which is what you're suggesting.
...
I'm not suggesting that at all. If they put these sort of high hurdles in the way and the criminals still overcome them, then they are *not* negligent. I thought that was clear. If they fail to protect their internal systems with these measures and as a result get penetrated via simple credential extraction, *then* they are negligent.
 

sprunt

Established Member
Joined
22 Jul 2017
Messages
1,624
Well that depends. Sure, if it's roughly like your example then it would be reasonable to be fined for not looking after the people's valuables safely. But what if you did lock the door but the thieves gained access by breaking in the windows? Or If you locked the door, boarded up the windows, but the thieves gained access by battering down the door...? And so on. At some point you'd surely say that you took all reasonable proportionate security precautions and it wouldn't be at all fair for you to be fined or to be blamed.

No, in circumstances that are completely different from those I described, the assignment of blame might also be completely different. I would have thought this was obvious.

The thing is, most of us would have a fair sense of that things we can do to mitigate the risk of someone physically breaking into your house, but very few of us have a comparable understanding of good practices when it comes to digital security. Probably most of us know some things (the need to use strongish passwords, to be sceptical of someone phoning out of the blue claiming to be from Microsoft, not to open unknown links in emails, and such like), but beyond that it's a specialist skill. I mean, I'm a professional software engineer so I probably know more than most people about digital security, but even I am in no position to judge whether or not a company is following good best practices (unless that company makes a really rookie mistake).

Then I'm sure you'd agree you shouldn't be running a data centre or performing the due diligence regarding which data centre your customers' personal data is stored in.

and you can't assume that just because a company has been hacked, that means the company is at serious fault.

I don't believe I've done so. There have been examples provided in this thread of cases where the blame and penalties were assigned to the third party data hosting company rather than the organisation whose clients' data was leaked when it was appropriate to do so, so I'm not sure why people are getting so upset about the regime. Nobody is saying that LNER were definitely at fault here, only that they should face appropriate consequences if they were.
 

takno

Verified Rep - Traksy
Joined
9 Jul 2016
Messages
6,574
I hoped it was obvious I was talking about internal company systems, not trivial (not wishing to be insulting!) public forums. The sort of systems that give you access to customer data. The consequences on one individual having their UK rail forums account taken over are essentially zero.

== Doublepost prevention - post automatically merged: ==


Really? Essentially you're saying because a security measure is not 100% effective it is worthless.

As far as a lost token is concerned, I can only speak for my former workplace, but if I lost my token the procedure was to order a replacement via the helpdesk - and it would be delivered by courier only to my registered base location to be personally signed for by me. So I don't see how that would help an attacker.

To emphasize: Social engineering to get simple id/password credentials on the phone or via email is a low hurdle. Performing that step and also obtaining a token or spoofing a biometric is, while not totally impossible, a very much higher hurdle. I really don't see why so many people seem to be disputing this. Companies that take security seriously (such as the one I worked for until recently) have been doing this for many years. More and more services are requiring 2FA rather than having it as an option. Are they all stupidly wasting their money?
The problem is that you have clearly worked for an employer who has highly critical data or systems, where it's worth the cost of putting in some seriously expensive technology and processes to meet a specific anticipated threat.

The people arguing with you are, as far as I can see, mostly seasoned tech industry professionals who have worked in different fields. The problem is that what you suggest would add potentially hundreds of millions of annual cost to an operator like LNER, for extremely questionable benefit.

In addition to having to issue probably all of their technical and operational, and a good proportion of their customer-facing staff with biometric tokens, they would have to contend with those staff being unable to work for protracted periods whenever they lost their token.

Perhaps more importantly they would be unable to use customer service, hosting, email or analysis suppliers who didnt have these standards in place as well. The cost of this would be astronomisk.

Even if we believed for a second that users would regard the increase in ticket prices to pay for this as worthwhile, there are still any number of backdoors you aren't guarding, and frankly the systems will likely still be breached.
 

35B

Established Member
Joined
19 Dec 2011
Messages
5,362
Really? Essentially you're saying because a security measure is not 100% effective it is worthless.

As far as a lost token is concerned, I can only speak for my former workplace, but if I lost my token the procedure was to order a replacement via the helpdesk - and it would be delivered by courier only to my registered base location to be personally signed for by me. So I don't see how that would help an attacker.

To emphasize: Social engineering to get simple id/password credentials on the phone or via email is a low hurdle. Performing that step and also obtaining a token or spoofing a biometric is, while not totally impossible, a very much higher hurdle. I really don't see why so many people seem to be disputing this. Companies that take security seriously (such as the one I worked for until recently) have been doing this for many years. More and more services are requiring 2FA rather than having it as an option. Are they all stupidly wasting their money?
I’m not saying it’s worthless, but that it’s not a panacea, and therefore its absence is not proof of negligence.

The Maginot Line was an effective line of defence, but still bypassed.
 

duffield

Established Member
Joined
31 Jul 2013
Messages
3,268
Location
East Midlands
I’m not saying it’s worthless, but that it’s not a panacea, and therefore its absence is not proof of negligence.

...
I think we're just going to have to disagree on that.

Locking your front door is absolutely not a panacea either, but if you fail to do so and a thief walks in, your insurance company will deem you negligent.

As far as I'm concerned not using at least 2FA of some kind for your internal company systems is the equivalent of failing to lock your front door.
 

Taunton

Veteran Member
Joined
1 Aug 2013
Messages
12,218
It's more like if you told people that they could store their valuables safely in your house then you didn't bother locking the door. The fines are not for being a victim of a crime, they are for letting down the people whose data they are supposed to be looking after safely.
I think the Data Protection Registrar (apparently now called the Information Commissioner) would have more credibility if they actually used their resources to identify and try to block those who perpetrate these raids. instead they take the easy (and lucrative) way out by fining substantially the victim organisations, fines big enough to come to the attention of the press so it looks like they are doing their job. I presume someone at the Treasury has set them a budget for how much to recover each year in fines.
 

sprunt

Established Member
Joined
22 Jul 2017
Messages
1,624
I think the Data Protection Registrar (apparently now called the Information Commissioner) would have more credibility if they actually used their resources to identify and try to block those who perpetrate these raids.

That seems more like the job of the police.

instead they take the easy (and lucrative) way out by fining substantially the victim organisations

If the organisations have not taken the steps they are legally required to take to safeguard their customers' data they are not the victims.
 
Status
Not open for further replies.

Top