logoalt Hacker News

aiiotnoodle • today at 9:29 AM • 20 replies • view on HN

I'm seriously at a point where I'm opposed to talking to my doctor because the information may be digitally recorded and leaked, going on a flight because my passport may be used to aqquire a loan by cybercriminals, comparing car insurance because my phone will be called by robocallers selling me things or verifying my ID with websites because it might be used to associate my information with whatever else I do online.

I don't think, for a vast majority of cases, these companies I'm forced to interact with can be trusted with my data and it's having a real world negative impact. Even with the best intentions the information is somehow valuable to steal and I'm baffled how it's not secure.

There should be some consequences for companies asking for things like SSN/National Insurance numbers on job adverts or retaining drivers licence photos after test driving a car, they just don't need the data anymore.


Replies

suslik • today at 10:07 AM

I am at a point where I simply stopped worrying and began to love the bomb. I did my best, I really did - degoogled before it was trendy, dropped all social media, built a homelab for complete data ownership, set up matrix messaging with family, and so on - but it feels like a wasted effort at this point.

All my data is out there, one way or another, and a dedicated cybercriminal - or worse, a government entity - can obtain or exfiltrate it without issues. I know it, they know it, everyone knows it.

The only thing I can change now is my reaction to this fact, and although the idea of off grid autarky is tempting, I am not there yet. I just don't want to stop living - flying abroad, going to doctors - I just accept that privacy in the current state of human condition is impossible, and move on with my life.

➕ show 11 replies
archon • today at 1:28 PM

> I'm seriously at a point where I'm opposed to talking to my doctor because the information may be digitally recorded and leaked

And then add on that fact that my doctor recently started using some kind of AI voice transcription app that listened to our entire conversation. Except that it hallucinated details I absolutely did not say, which are now in that doctor's records and I'm sure will be taken at face value in the future.

It's maddening.

➕ show 1 reply
strideashort • today at 9:53 AM

I recently needed a lawyer on something that involved lots of highly sensitive PI.

Sending my file over to lawyers in a semi-safe way has proved impossible.

And in any case, i received an answer with lots of PI over a plain email…

Absolutely maddening

➕ show 1 reply
coryrc • today at 4:59 PM

I have another solution. I look normal online when filling out information. I use Facebook, whatever.

But whenever possible, I lie. Different name, birthdate, every question about "favorite pet"? A lie. "They" have tons of data on me, but more and more is wrong. Let it leak.

➕ show 2 replies
talon8635 • today at 8:55 PM

I was at that point in 2015, at which point my social was already leaked in a major breach, and after which it was leaked two more times in other breaches.

msdz • today at 10:51 AM

> There should be some consequences for companies […] retaining drivers licence photos after test driving a car, they just don't need the data anymore.

I know it’s modern American tech tradition to make fun of the GDPR, but this is genuinely one of the things it stipulates: You’ll get at least a slap on the wrist, or potentially much worse, if you needlessly keep data around longer than necessary to do the task you had collected it for in the first place.

➕ show 2 replies
faidit • today at 3:08 PM

We need HIPAA for businesses. We tried letting them regulate themselves and it didn't work. Businesses need to be forced to compete on the quality of their products/services and not rewarded for reselling customer data to spammers and criminals

amelius • today at 9:34 AM

I mean why does every hotel need to make a copy of my passport?

➕ show 3 replies
tokioyoyo • today at 9:45 AM

I said it before as well, but it’s because nothing “publicly really bad” happened despite the leaks and stolen information over the past decades. After Equifax breach, everyone got tired, because company survived, and whatever identity theft happens from time to time gets swept under the rug. It didn’t impact most people’s lives, despite leaking half of the US’s SSNs and etc. Then fatigue kicked in, and with subsequent leaks everything just mellowed down, so nobody cares.

I’ve switched to operate with the idea that my information has already been leaked at some point. I should be generally ready to fix the problems if/when identity theft happens, rather than inconveniencing myself and figuring out the third party trust situation.

NooneAtAll3 • today at 8:15 PM

> or retaining drivers licence photos after test driving a car,

mind that there was a breach recently where all the data was being leaked *the moment it was collected*

so simply controlling retention is not enough. The very fact of data being taken is already a vulnerable part

TacticalCoder • today at 11:06 AM

In France the french IRS leaked infos about the wealth of its citizens and evil thieves cross-checked it with leaks of people who ordered hardware wallet for cryptocurrencies and families are getting kidnapped and tortured. In a recent case three family members have been beaten over two days so that... 40 000 EUR could be stolen.

That's the world we live in.

"Police and thieves", collaborating one way or another (leaking data collected by big brother and then having big brother being very soft on crime is one way to collaborate with evil people), "to scare the nation with their guns and ammunition" (as in the reggae song).

As much as I don't like the cryptocurrency ecosystem, I don't think facilitating and encouraging kidnapping and torture is the way to go.

Shame on the french government.

Two sides of the same coin.

➕ show 1 reply
crabbone • today at 6:46 PM

Last month I had to lodge a complaint with Lycamobile because they arbitrary cancelled my plan, essentially, pocketing some 50 Euro. Trying to follow their very elaborate support extensions maze, I ended up in some Indian customer support center that proved to be completely useless when it comes to solving issues caused by the service provider itself.

However, next week, I started getting calls from other Lycamobile numbers, where it sounded like the same Indian guy, but now he presented himself as a police officer who wanted to arrest my bank account :)

The moral of the story: if you have a phone number, it's been already sold to some shady call center in South-East Asia and it's just a matter of time before they will try to scam you or use your phone for some nefarious purpose. I don't think Lycamobile is unique in how bad their system is and how much they want to extract every last penny from you buy outsourcing every service to foreign companies with zero responsibility and questionable work ethics.

mdp2021 • today at 10:15 AM

> where I'm opposed to talking to my doctor because the information may be digitally recorded and leaked

Let me say "Hi mate, +1". State doctors? There are territories in which a pharmacological prescription is shared DB only now (where previously they could be on paper - a secret between you, the pen, the paper, the pharmacist and the gods). Private entities? Good luck finding one that does not require a privacy waiver as a condition for the visit. Searching for a medical dock (a dock for a doc), calling them to ask? "This is a recorded message. If you proceed with the call then you agree..." (Hang-up click).

chrisjj • today at 11:40 AM

> I'm baffled how it's not secure.

Our civilisation needs to face up to the fact the reason is simply: its stored on a connected computer.

➕ show 1 reply
c-fe • today at 12:37 PM

> they just don't need the data anymore.

Thats the wording of GDPR.. that you should delete data after you dont need it anymore for the original purpose..

Unfortunately, it seems noone is enforcing it enough.

KPGv2 • today at 1:38 PM

> my passport may be used to aqquire a loan by cybercriminals

In the US, you can freeze your credit, making this impossible (even for yourself).

Hamuko • today at 9:58 AM

I’m never going to a therapist after one company leaked all of the patient data / therapy notes for 33k patients.

➕ show 1 reply
ratg13 • today at 9:58 AM

This is just a general American complaint that has merit on its own, but has nothing to do with the article and is just derailing any discussion about the article itself and driving the conversation to your own personal concerns about something completely separate.

In this case, the EU does have consequences for data breaches where proper protocols are not followed.

Additionally, this is not private information .. most anyone can look this information up. ID numbers are not confidential information like SSNs are treated in the US.. they are just a number to tell person A from person B. You give this number to everyone without thinking about it because it's how every company you interact with identifies you.

In this case a rogue company, or compromised company, used their access to contact the central database to download everyone's information.

In my country we essentially use the same system, except for we still allow companies to download the whole database if they want to instead of making individual queries.

In this case the access to their system was unauthorized, and under GDPR data breaches have to be reported within 72 hours. Companies can't make the decision on their own that it's not a big deal.

Zealotux • today at 11:11 AM

[dead]

heresie-dabord • today at 10:41 AM

> I don't think [...] these companies [...] can be trusted with my data

Abusing privacy is the lucrative norm. The laws won't help you and the government is busy with its corporate agenda.

➕ show 1 reply