What should we do when your data is leaked online?

How long should we wait before publishing an article about a data leak?

  • Immediately

    Votes: 86 60.1%
  • Within 24 hours

    Votes: 23 16.1%
  • Within 48 hours

    Votes: 13 9.1%
  • When the company whose clients’ data was leaked approves

    Votes: 17 11.9%
  • Never

    Votes: 4 2.8%

  • Total voters
    143
I think there are two considerations:
1. You cannot publish before you have verified the facts.
2. You should give the company involved the opportunity to respond, but how much time you give them depends on the specifics of the case (and the balance between public and company interests). If it is sensitive data like credit card details, then you publish asap with a note that says you will add comment from the company as soon as you get it. If it is less sensitive information, then you give the company 12 or 24 hours to comment before you publish.
 
Immediately investigate and if data is definitely leaked notify clients as soon as possible so that the client can take measures to protect his/her account
 
In the spirit of preventing zero day attacks where many companies might also be venerable, just let people know instead of letting some company take its time while trying to figure out how to mitigate the breach. You might not have all the facts but I personally would like a little heads up
 
I think MyBB did fine with the level of reporting they had with this story, and I CERTAINLY don't want anything that makes Google search less useful with the forums. Heaven knows it's the only way to find anything on here.

I also think that MagicDude4Eva is getting mighty sassy about the world of responsible disclosure, when he's not shy of blabbing all over the forum after trying for less than 30 minutes to report responsibly. Maybe his views have just evolved significantly over the last three years.

Completely different issue:
Disclosure:
- COJ was informed about the issue already on the 13th August 2013 and did not respond. They also did not action it a week later.
- COJ was also informed about the issue by another person
- Furthermore, Google had information indexed for months before that

Vulnerability:
- It was an OWASP A4 and required to be logged into COJ
- No security credentials were leaked. No data was leaked in bulk and no security credentials/passwords were ever accessed.
- People gained access to other people's invoices (comparable to going through someones postal mail) through their own logins. The exposure was minimal as people gaining access to data were known to COJ.

Mitigation
- COJ could have shut down the website immediately when informed but chose not to
- Although various people on MyBB bulk-downloaded COJ data no obvious damage was done to customers
- COJ should have logs of who accessed what information, so it is very easy to pursue people if they choose to
- Google indexed a large number of COJ data which remained in caches for weeks after MyBB went public and was in Google search several months prior to publication

TL;DR: The COJ incident was responsibly reported and COJ decided to not lift a finger for a good week (nor acknowledge the issue). I have always maintained that a security breach should be responsibly reported so that the affected parties can take ownership and mitigate. FWIW - I have insight into that investigation and what is happening, and you don't.

You have a very naive view in thinking that a vulnerability/breach becomes only "real" when it is reported. Many breaches are never reported to the public (ask anyone working for financial institutions or Sita) and are silently covered up. There have been several cases this year alone where JSE companies paid crypto-locker ransom as well as Btc to have pastes disappear. What do you think happened from 2013 when the C99Shell was installed on the server until now? Many attackers work and harvest data silently for months and years without the target ever knowing.
 
Give the organisation concerned a defined time to plug the hole, if any, and then make sure fa ts are straight .... then publish.
 
Report on the leak as soon as possible to give people who could be affected the best chance of avoiding their data exposed by changing passwords or removing sensitive data or implementing two factor authentication. ✋
 
I'll tell you what you should NOT do. You should not ban the CEO of the company whose data was leaked. :mad:
 
I think that mybb would not be the forum that it is today if in the past it ran to the media with such potentially damaging information of the breached company and to itself. In this day where information gives power to the one who holds it, it is paramount how the use and flow of that potentially damaging or rescuing information is applied. The most affected is the breached company. They need to be informed first.
 
Top
Sign up to the MyBroadband newsletter
X