this post was submitted on 24 Jan 2024
124 points (97.7% liked)

Privacy

1272 readers
69 users here now

Icon base by Lorc under CC BY 3.0 with modifications to add a gradient

founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 1 points 10 months ago (2 children)

But its not a breach, its accounts being compromised. Yes you can't trust them but its their own fault still. And you can't make it too hard to get the data because otherwise your idiot of a user cant access it either.

They should definitely force 2FA however.

[–] [email protected] 6 points 10 months ago (1 children)

IBM defines "Data Breach" as:

any security incident in which unauthorized parties gain access to sensitive data or confidential information, including personal data (Social Security numbers, bank account numbers, healthcare data) or corporate data (customer data records, intellectual property, financial information).

Despite the fact the attackers used real passwords to log in they are still an 'unauthorized party' because they are not the intended party.

It's also legally the case that using a password to access data you know you are not supposed to access still counts as 'hacking'

[–] [email protected] 1 points 10 months ago (1 children)

Well, the authorisation is the password, so from their side it was in fact not a breach because they just got a normal login with the correct authorisation(password).

[–] [email protected] 3 points 10 months ago

The front door unlocked because the burglar found a copy of the key outside.

This wasn't a burglary, though. His key was legitimate.

[–] [email protected] 1 points 10 months ago