What should we do when your data is leaked online?

How long should we wait before publishing an article about a data leak?

  • Immediately

    Votes: 86 60.1%
  • Within 24 hours

    Votes: 23 16.1%
  • Within 48 hours

    Votes: 13 9.1%
  • When the company whose clients’ data was leaked approves

    Votes: 17 11.9%
  • Never

    Votes: 4 2.8%

  • Total voters
    143
Would a personal message (SMS, Whatsapp, email, etc) directly to the customer not be quicker than an article on mybb, IT News, Techcentral, etc?

It's pretty clear from the thread that plenty of people who read the article didn't receive the emails so when it comes to urgent dissemination the more methods the merrier, no?
 
But rpm's question is a difficult one to give a clear answer on as there is so many factors involved. If said company takes 2 weeks to fix, should they list before then or wait till the fix? We all heard stories of companies ignoring exploits when brought to their attention and then there's people like Microsoft that takes months before they do a fix.

My personal opinion is to engage impacted company, give them time to review and asses how long it will take to correct. Come to an agreement on when the story will be published. I would go as far and say publish when he emails go out about password resets. Coordinate the comms so the public is aware what happened and assist in affected company in communicating how to resolve the issue.

It's a impromptu partnership and everyone will be glad of the outcome.

And if a company doesn't want to play ball...feck them and watch them burn

:evil:

Data leaks and zero day exploits are not the same thing and should be treated differently.
 
Did all of their customers who were impacted receive their email message in a timely fashion?
We are looking at the future, not the past... I did not mention email messages exclusively. My preference would be an SMS to the contact number I gave them when applying for the service.

And this is what needs to be set up by all ISPs with all their customers. If there is a crisis regarding your account, what is your preferred means of contact?
 
How would MyBB respond if your data were leaked? What would you do, as a profit-orientated business hosting with Hetzner, with thousands of user credential data, if a hacker got in and published your client list? Would you have a defacto policy where you publish within 24 hours no matter the situation or repercussions of doing so? Or would you treat each case on its merits and use some integrity to make a call on the correct disclosure timing?

Also, should you be allowing yourselves to become the ransom arms of malicious hackers?
 
How would you measure this?

I suppose you could start by going through the thread?

Or by asking CW if any of their users called up this morning asking why they cannot access their account?

Anyway, my point was the more methods employed the better, that's all.
 
I suppose you could start by going through the thread?

Or by asking CW if any of their users called up this morning asking why they cannot access their account?

Anyway, my point was the more methods employed the better, that's all.

*nods*

I like MickeyD's idea of an emergency contact method.
 
And this is what needs to be set up by all ISPs with all their customers. If there is a crisis regarding your account, what is your preferred means of contact?

Shotgun - any and all means possible, including a phone call.
 
How would MyBB respond if your data were leaked? What would you do, as a profit-orientated business hosting with Hetzner, with thousands of user credential data, if a hacker got in and published your client list? Would you have a defacto policy where you publish within 24 hours no matter the situation or repercussions of doing so? Or would you treat each case on its merits and use some integrity to make a call on the correct disclosure timing?

Also, should you be allowing yourselves to become the ransom arms of malicious hackers?

Are 24 hours not enough? That's 3 working days when working overtime.
 
The question for us is: How do we best serve the public interest.

If the data is immediately available for criminals to abuse, how long should we wait before we publish an article?

And: What if the company involved is not responding to our communication? Or what if they do not let their users know about the leak within a reasonable time frame?

In the case of CW it was an easy process. They asked for 48 hours before we publish, and they acted quickly to inform their users. But we have no control over this process. What if a company is slow, or unresponsive?
 
Are 24 hours not enough? That's 3 working days when working overtime.

Why are 24hours needed? Do companies not have a pan of action already formulated to deal with these sort of things?

"Expect the best, plan for the worst, and prepare to be surprised…"
 
Why are 24hours needed? Do companies not have a pan of action already formulated to deal with these sort of things?

"Expect the best, plan for the worst, and prepare to be surprised…"

I'd guess most don't expect this kind of thing to happen so they are unprepared. 24 hours helps them plug the holes before the media makes it public. Look I'd prefer immediately publishing but that could do more harm.
 
My 2c...

I think there is a very big difference in reporting on an event which is newsworthy and of public interest and the dissemination of the information which was leaked. Once the information is available online it is in the public domain and a news website cannot possibly get involved in the mitigation of the risk or damage caused by such publication.

As much as it may be noble to give reasonable opportunity to the party who's data was leaked to take the necessary action to address the issue it must also be noted that in many occasions the first time an affected customer becomes aware of such a leak is not from the company hacked but from the media - this allows the customer to personally mitigate the risk to themselves (sometimes hours or days before official press releases). Also, companies who are victims of leaks (if they notify their customers at all) generally downplay the seriousness or consequential risk to their customers (focusing on what was not leaked vs what was leaked or blaming third parties etc).
 
If MyBroadband is alerted to an online data leak, where sensitive data of South Africans is available online, how long should we wait until we publish an article about it?

Perhaps the very fist step is to inform the involved parties without the intent to publish first?

How would you feel if I come along and give you x-hours to respond and then BHAM mother ****er, I publish it and see how it goes from there.

Nothing learnt, you think?
 
Many posts have been deleted. This really reflects badly on yourself rpm.

Sort this feud out ffs.
 
Top
Sign up to the MyBroadband newsletter
X