this post was submitted on 22 Jan 2024
575 points (97.8% liked)

Technology

57472 readers
3626 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
 

I just got the email from haveibeenpwned. F Trello.

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 10 points 7 months ago (1 children)

I agree that data security is important, even if it is only email addresses, where many are probably findable in the web anyway. Maybe, the link with the username has some value, but I’d bet only little. In my opinion, harsh penalties are more needed in privacy invasive (in my opinion malware) like google, meta, Amazon etc. are spreading.

[–] [email protected] 8 points 7 months ago (2 children)

The problem is that this data can be combined with other data. An email address by itself isn't particularly important but when it's matched up with names, physical addresses, DoB, SSN, other PII and the network of other services with matching data it becomes very serious.

It's never just this breach, it's every other breach as well. Every breach makes every preceeding breach more effective and more valuable.

[–] [email protected] 1 points 7 months ago (1 children)

Except this contains none of that

[–] [email protected] 1 points 7 months ago (1 children)

Other breaches do.

If two breaches have an overlap, e.g. they both contain email address, then they can be joined into a more complete set.

[–] [email protected] 0 points 7 months ago

Yeah, I don't think there is much that would be gleamed by combining with this dataset

[–] [email protected] 0 points 7 months ago (1 children)

Of course, but where are names, physical addresses, DoB, SSN, etc in this dataset? It’s just mail and username

[–] [email protected] 1 points 7 months ago

Other breaches do.

If two breaches have an overlap, e.g. they both contain email address, then they can be joined into a more complete set.