Liberty SMS - Unauthorized access to IT infrastructure

No, but there is common sense like storing your data encrypted at rest.

Sucks for the people that use Liberty that they trusted their data to a bunch of monkeys.

Whatwhat makes you think data was not stored encrypted at rest? And let's hear your definition of encrypted at rest - I'm interested to hear what you feel is good enough.
 
Can you elaborate for context - who is we? If you feel there's more to this story then please share.

As above, clearly you have inside info.

I must have missed those. Can you quote / link?

NDA's I'm afraid.
And the article was in yesterday's Sunday Times
 
NDA's I'm afraid.
I'm sure you can elaborate without disclosing sensitive information. Are you a current vendor? Were you hired by them to perform security risk assessment/s? No need for company name.
And the article was in yesterday's Sunday Times
OK, so iffy at best.
...actually here it is:

NEGbEsv.png
 
Last edited:
How about these companies start with the basics and have client correspondence only viewable via browser, and only accessable with a physical OTP generator keyring.
 
I'm sure you can elaborate without disclosing sensitive information. Are you a current vendor? Were you hired by them to perform security risk assessment/s? No need for company name.
OK, so iffy at best.

Banks and a large diamond mining company.
System upgrades, and vulnerability testing. Think " Why do we have to remove the CD writers and disable usb functionality on the staff computers"

And while the ST is definitely not a bastion of solid reporting, they directly quoted.
So either it's true, or a retraction is on the cards, and then I'll eat humble pie.
 
Banks and a large diamond mining company.
System upgrades, and vulnerability testing. Think " Why do we have to remove the CD writers and disable usb functionality on the staff computers"

And while the ST is definitely not a bastion of solid reporting, they directly quoted.
So either it's true, or a retraction is on the cards, and then I'll eat humble pie.
So not Liberty?
I've posted the article above... looking for this though:

petec said:
and read their initial denial, and sound bite of it could never happen to us
 
Whatwhat makes you think data was not stored encrypted at rest? And let's hear your definition of encrypted at rest - I'm interested to hear what you feel is good enough.

The term is pretty self explanatory. As for being compliant to things like POPI and GDPR there are whitepapers written by software and hardware vendors on how to meet or exceed the requirements.
 
The term is pretty self explanatory.
Actually it's not. There are different ways to store data at rest, I'm curious about what you would find acceptable. Besides, what makes you think this is a data storage issue in the first place?

As for being compliant to things like POPI and GDPR there are whitepapers written by software and hardware vendors on how to meet or exceed the requirements.
And you're calling Liberty out on a specific point? If so, please be specific.
 
Sources said they were engaging with the hackers before this went live.
No doubt. I imagine that's usually the order of things in these situations. Again, all I was asking for was something more than "I heard through a colleague or friend".

Also, back to one of the other questions I had...
So you do not have first hand experience with Liberty or work for a company with first hand experience of Liberty's systems? We can make this painless, I'm trying to establish whether you're speculating or have first hand experience. So far it seems like everyone is speculating.
 
Last edited:
Now before I get flamed for "You don't know what went down at Liberty", well if you read yesterday's newspaper article, and read their initial denial, and sound bite of it could never happen to us, then I have no qualms about painting them with the same brush on security issues that have been plaguing large networks for so many years.

I am not sure I read a denial in the ST article.
Did you listen to the press conference last night from Liberty?
Kudo's to Liberty for making the hack public and in the open. This to me is anything than a denial but owning up.
 
Actually it's not. There are different ways to store data at rest, I'm curious about what you would find acceptable. Besides, what makes you think this is a data storage issue in the first place?

And you're calling Liberty out on a specific point? If so, please be specific.

"Notify the supervisory authority of a data breach within 72 hours of becoming aware of the breach (Article 33), and under certain circumstances, notify every data subject whose data was breached as well (Article 34). A breach notification is not required to the
supervisory authority if the breach is "unlikely to result in a risk to the rights and freedoms of natural persons," nor to data subjects if the breach won't result in a "high risk" to their rights and freedoms. For example, if the breached data was encrypted with a sufficiently strong encryption mechanism, data breach notifications are not required."

I suggest you contact Liberty and ask them for comment.
 
I am not sure I read a denial in the ST article.
Did you listen to the press conference last night from Liberty?
Kudo's to Liberty for making the hack public and in the open. This to me is anything than a denial but owning up.

GDPR requires them to do that if they didn't put enough security in place. This is not them being open and public, this is them coming short on securing your data.
 
"Notify the supervisory authority of a data breach within 72 hours of becoming aware of the breach (Article 33), and under certain circumstances, notify every data subject whose data was breached as well (Article 34). A breach notification is not required to the
supervisory authority if the breach is "unlikely to result in a risk to the rights and freedoms of natural persons," nor to data subjects if the breach won't result in a "high risk" to their rights and freedoms. For example, if the breached data was encrypted with a sufficiently strong encryption mechanism, data breach notifications are not required."

I suggest you contact Liberty and ask them for comment.

And you're suggesting they didn't do that? From where I stand, it's exactly what they did.
Back to the other question, what makes you think this is a data storage issue in the first place?
 
GDPR requires them to do that if they didn't put enough security in place. This is not them being open and public, this is them coming short on securing your data.

Again, pure speculation - you keep on about encryption of data at rest when that has nothing to do with the issue. You're speculating based on the blanks. Some of us are trying to get facts.
 
And you're suggesting they didn't do that? From where I stand, it's exactly what they did.
Back to the other question, what makes you think this is a data storage issue in the first place?

Please point me to where they confirm all their stuff is encrypted as per regulatory requirements.
 
Please point me to where they confirm all their stuff is encrypted as per regulatory requirements.

Why would lack of statement prove the contrary? Why would that be brought up when this may not even be a data at rest issue? Come on guys, it's not that hard. I'm not saying this is or isn't whatever, I'm saying there's no indication that this is an encryption of data at rest issue. Encryption of data at rest is not a magic bullet to solve every vulnerability.
 
Last edited:
GDPR requires them to do that if they didn't put enough security in place. This is not them being open and public, this is them coming short on securing your data.

It’s more the other way around.

What the GDPR means is that «*if the stolen data is encrypted sufficiently making it an assumption that the hackers won’t be able to decipher it, there’s no need for a notification”.

It doesn’t mean that there wasn’t enough security in place.
 
Top
Sign up to the MyBroadband newsletter
X