24 votes

52% of Americans think their personal data will be breached. They're probably right.

14 comments

  1. [11]
    creesch
    Link
    For most people filling in their email address in on Have I Been Pwned it likely is not a matter of "will be" but "has been". Not from the US but in no particular order here is the sort of data...

    For most people filling in their email address in on Have I Been Pwned it likely is not a matter of "will be" but "has been".

    Not from the US but in no particular order here is the sort of data that is already out there for me:

    • My bank account number
    • My phone number (recruiters have the audacity to call me here and pretend to be shocked when I tell them they can't have gotten hold of my phone number in any legal way).
    • Email address (same story with recruiters as with my phone number)
    • Date of birth
    • Gender
    • Full name
    • Physical address
    • Education level
    • And a bunch more.

    And there could be much more. But it is not as shitty as it is for a large amount of women in the country who participated in national cervical cancer screening.

    If you don't think your data will leak or isn't already out there, then you are sorely mistaken.

    In fact, I strongly believe the percentage of Americans would be much higher in this article if the US had a federal level proper data leak disclosure laws like we have in the EU. I know various states have disclosure laws but afaik they aren't as strict as the GDPR requirements and allow for quite a few cases where companies can decide it isn't a risk for some reason.

    20 votes
    1. [6]
      papasquat
      Link Parent
      I work as an executive in cybersecurity, and I get cold calls from vendors attempting to sell me things all the time. This is fine on my work phone, which I basically always ignore anyway, but I...

      (recruiters have the audacity to call me here and pretend to be shocked when I tell them they can't have gotten hold of my phone number in any legal way).

      I work as an executive in cybersecurity, and I get cold calls from vendors attempting to sell me things all the time. This is fine on my work phone, which I basically always ignore anyway, but I also get frequent calls on my personal phone.

      I've grilled these salespeople multiple times about it. It usually goes something like.

      "Hi, yeah, I'm not interested. I'm just curious, where'd you get this phone number? Its my personal number and I never use it for anything work related.

      "Oh, we got it from your LinkedIn"

      "Its not on my LinkedIn"

      "Oh, well it probably used to be, so it's in our system"

      "Its never been on my linkedin, or any publicly available website for that matter."

      "Oh... Uhh... I'm not sure then"

      "Okay. You should probably look into that. Anyway, never call me again."

      The sheer balls of a company that sells cybersecurity services for a living using leads they purchased from data brokers fed by data breaches will never cease to impress me. You're trying to sell me a product that will stop attackers, while using the fruits of their labor to feed your sales pipeline.

      Truly impressive stuff.

      19 votes
      1. [3]
        creesch
        (edited )
        Link Parent
        Oh yeah, at one time I got a guy mailing me on my personal mail about a work field related thing. Something about a collaboration with my company and all that. The only way they could have put my...

        Oh yeah, at one time I got a guy mailing me on my personal mail about a work field related thing. Something about a collaboration with my company and all that.

        The only way they could have put my work field and my personal mail together is through a data leak. I outright asked them, got a vague answer. So I then replied that the only way they reasonably could have gotten my personal mail and connected it to my work activities was through a data leak. And that as such I had to report this to our national data protection agency as a GDPR violation.

        To which they replied, somewhat peeved, with something along the lines of "If I had known that you would question me about the legality of how I am using your mail address I would not have contacted you". No shit Sherlock, you are using questionable methods and of course you were hoping to get away with it.

        16 votes
        1. DefinitelyNotAFae
          Link Parent
          Absolutely LOL

          ""If I had known that you would question me about the legality of how I am using your mail address I would not have contacted you"*.

          Absolutely LOL

          10 votes
        2. papasquat
          Link Parent
          Hilarious reply. "If I would have known you were going to call the cops on me I would have never broken into your house!"

          Hilarious reply.

          "If I would have known you were going to call the cops on me I would have never broken into your house!"

          5 votes
      2. updawg
        Link Parent
        To be fair, "your information wouldn't be out there if company x had used our product" is a decent marketing pitch, if a bit unethical.

        To be fair, "your information wouldn't be out there if company x had used our product" is a decent marketing pitch, if a bit unethical.

        3 votes
      3. PraiseTheSoup
        Link Parent
        "Impressive" is a word you could and did use, but I think I would go with "disgusting".

        "Impressive" is a word you could and did use, but I think I would go with "disgusting".

        1 vote
    2. tanglisha
      Link Parent
      Folks already seem to have forgotten about the Equifax data breach. There's been a lot going on since then, I guess.

      Folks already seem to have forgotten about the Equifax data breach. There's been a lot going on since then, I guess.

      8 votes
    3. vord
      (edited )
      Link Parent
      How to find the name of the owner of almost any property in America: Pick a random address. Seach 'city, state property tax lookup' After a click or two on the relevant municipality website,you...

      How to find the name of the owner of almost any property in America:

      Pick a random address.
      Seach 'city, state property tax lookup'
      After a click or two on the relevant municipality website,you can now plug in said address.

      Now you probably have the names for the current and past owners, sale history, tax assessment info and more.

      And that's how I found out who my actual landlord was, and not the management company. Then, having a name and address, you can search all the various socials, and for average people who keep their profile public, congratulations, you know their carreer path, their families, etc.

      For $0.26 each, 200 minimum, you can now send a highly detailed fraudulent instructions to a bunch of addresses "get a 50% discount" on your property tax bill by paying early.

      6 votes
    4. [2]
      CptBluebear
      Link Parent
      [...] Goddorie wat een lijst. Was je klant bij Odido ofzo? I've had leaks and probably have plenty of my personal data strewn around, but you've been extra unlucky it seems.

      My bank account number

      My phone number

      [...]

      Physical address

      Education level

      Goddorie wat een lijst. Was je klant bij Odido ofzo?

      I've had leaks and probably have plenty of my personal data strewn around, but you've been extra unlucky it seems.

      1. creesch
        Link Parent
        Yup, though a lot of it was already out there. Or would be with the latest breach of that logistical partner of Bol and half of the companies in the Netherlands. A small selection of all the...

        Goddorie wat een lijst. Was je klant bij Odido ofzo?

        Yup, though a lot of it was already out there. Or would be with the latest breach of that logistical partner of Bol and half of the companies in the Netherlands.

        A small selection of all the breaches I've been involved in

        • 2026: Odido
        • 2024: Trello
        • 2021: Ticketcounter
        • 2020: Gravatar
        • 2019: Deezer
        • 2016: Dailymotion
        • 2016: MoDaCo
        • 2015: Trillian
        • 2015: vBulletin
        • 2013: Adobe
        • 2013: imgur
        • 2012: Drobox
        • 2012: LinkedIn (guess where those recruiters get their info from)
        • 2012: last.fm

        Not all of them contain the same data of course. But much of the information that would have been in the Odido leak would also have been in the Ticketcounter leak for example.

        4 votes
  2. Grenno
    Link
    I think the better statistic was that only 11% disagreed with the statement. With how many site registrations require more and more personal data it has to be a statistical inevitability. And all...

    I think the better statistic was that only 11% disagreed with the statement. With how many site registrations require more and more personal data it has to be a statistical inevitability. And all it takes is a single slip up from 1 company, or subsidiary, or employee and its out there pretty much for good.

    I would highly doubt things are going to get better in the future for your online privacy.

    6 votes
  3. post_below
    Link
    That means at least 48% of Americans don't know their data has already been breached.

    That means at least 48% of Americans don't know their data has already been breached.

    6 votes
  4. Tiraon
    Link
    The article talks about the bubble of the early internet of high quality sites that did not exploit the users popping. The bubble did not pop. It was popped because of profit, because modern...

    The article talks about the bubble of the early internet of high quality sites that did not exploit the users popping.

    The bubble did not pop. It was popped because of profit, because modern business does not understand the concept of enough and of social responsibility and because tech illiteracy is so rampant.

    4 votes