1. OCAU Merchandise is available! Check out our 20th Anniversary Mugs, Classic Logo Shirts and much more! Discussion in this thread.
    Dismiss Notice

Consolidated Major Australian Data Breaches Thread

Discussion in 'Networking, Telephony & Internet' started by ipv6ready, Sep 23, 2022.

  1. bcann

    bcann Member

    Joined:
    Feb 26, 2006
    Messages:
    6,523
    Location:
    NSW
    Yeah, sorry, but if you want to take it out on someone, take it out on all the nefarious folk out there who want to rob you of your hard earned money. We (the people giving you this lecture) are the people who have the mop and bucket and are being made to clean up other peoples mess, normally well and truly AFTER telling said people in power to just do it, who then ignored this and hence the mop and bucket.
     
  2. supasaiyan

    supasaiyan Member

    Joined:
    Nov 17, 2006
    Messages:
    6,393
    Location:
    3000
    I find it annoying that some MFA requires their own MFA app
     
    Elmf, bcann and MUTMAN like this.
  3. MUTMAN

    MUTMAN Member

    Joined:
    Jun 27, 2001
    Messages:
    19,065
    Location:
    4558
    or that the only options are email/sms
    just let me use a time based mfa app ffs
     
  4. fnp

    fnp Member

    Joined:
    Apr 20, 2004
    Messages:
    5,311
    Location:
    Wait Awhile
    I'm annoyed that innane systems like to fill out my timesheet are secured like Fort Knox, yet important things like the bank or MyGov still persist with (optional) SMS-only 2FA.
     
    MUTMAN and supasaiyan like this.
  5. caspian

    caspian Member

    Joined:
    Mar 11, 2002
    Messages:
    13,258
    Location:
    Melbourne
    if your timesheet is breached it costs your employer money. if your banking or MyGov details are breached, it costs you money.
     
  6. TheWedgie

    TheWedgie Insert Custom Title Here

    Joined:
    Jun 16, 2002
    Messages:
    3,410
    Unless it's with Frontier Software...
     
  7. cvidler

    cvidler Member

    Joined:
    Jun 29, 2001
    Messages:
    20,426
    Location:
    Canberra
    used to have a HR/payroll system that was all proud that they encrypted your payslip PDF with your account password. They were rather confused when I asked why are they keeping account passwords in cleartext so that they may use them in their PDF system?

    thankfully and somewhat surprisingly after complaining up my CoC said HR system contract was tore up after only a few months. so we do somewhat take security seriously enough.

    the fact all our PII is thrown around various outsourced/cloud HR systems every other year doesn't flag any concerns though. and they wonder why I won't fill out any address details in the systems, only bit I can opt out of filling in.
     
  8. looktall

    looktall Working Class Doughnut

    Joined:
    Sep 17, 2001
    Messages:
    27,924
    https://www.abc.net.au/news/2025-04...passwords-stolen-by-malware-hackers/105196976
     
    sammy_b0i likes this.
  9. JSmithDTV

    JSmithDTV Member

    Joined:
    Jun 13, 2018
    Messages:
    13,435
    Location:
    Algol, Perseus
  10. Dass Booty

    Dass Booty Member

    Joined:
    Aug 11, 2001
    Messages:
    1,868
    Location:
    Logan, Queensland
  11. Sphinx

    Sphinx Member

    Joined:
    Sep 16, 2001
    Messages:
    11,579
    Location:
    Brisbane
  12. th3_hawk

    th3_hawk Member

    Joined:
    Jun 4, 2005
    Messages:
    2,879
    Location:
    Kilsyth 3137
    I got all six correct... although the reasons they provided were not the reasons I chose the one I did... Apparently I can sense a scam site :p

    But really, no one is checking that every word on a page is spelt correctly or that the information listed is "up to date" and this is why it works and catches people out. I read recently about how scammers work in teams, one contacting your real bank and one contacting you so they can pass through real questions from the bank, including requests to authenticate things, which of course people do since those are legit requests through legit channels. Scary stuff.

    My CC was compromised (again) last month and while I caught it early and it was all sorted, the moment it was cancelled/put on hold by me through the app (I was on hold waiting for the bank at the time) I missed a call from a number which left a message claiming to be the bank. I think that was something like the above scam where they would have tried to do dodgy things. In my case, the replacement card was compromised BEFORE it even arrived or was activated!! Apparently the scammers must have added it to a digital wallet which gets automatically updated when a new card gets issued unless the bank resets the tokens. Apparently the standard process is to only kill tokens for things that get disputed, that way your digital token with the phone company still works and doesn't need updating... although who the fuck knows which institutions might auto update vs which ones do I need to call??

    In any case, the process was smooth enough and another replacement was sorted and it's fine for now, but if history tells me anything it will happen again in the next 24 months. I'm still begging for an Australian bank to provide an account which can generate single use numbers.
     
    Dass Booty and JSmithDTV like this.
  13. bcann

    bcann Member

    Joined:
    Feb 26, 2006
    Messages:
    6,523
    Location:
    NSW
    Why not Google pay/apple pay, they use single use numbers/token.... its the whole reason i use them directly...
     
  14. th3_hawk

    th3_hawk Member

    Joined:
    Jun 4, 2005
    Messages:
    2,879
    Location:
    Kilsyth 3137
    I do that everywhere I can as well as paying through PayPal, but plenty of merchants don't offer an integration for Apple/Google Pay. Or is there some way to use one of them at random merchants because I choose to?
     
  15. supasaiyan

    supasaiyan Member

    Joined:
    Nov 17, 2006
    Messages:
    6,393
    Location:
    3000
    another data breach

    https://www.websiteplanet.com/news/infostealer-breach-report/
     
  16. caspian

    caspian Member

    Joined:
    Mar 11, 2002
    Messages:
    13,258
    Location:
    Melbourne
    I believe Commbank already do so, but only for business accounts. this is the first I have seen for consumer grade. https://www.bankwest.com.au/virtual-cards
     
    Sphinx likes this.
  17. supasaiyan

    supasaiyan Member

    Joined:
    Nov 17, 2006
    Messages:
    6,393
    Location:
    3000
  18. bcann

    bcann Member

    Joined:
    Feb 26, 2006
    Messages:
    6,523
    Location:
    NSW
    Not at this moment, but in the coming years i've been reading stories about "Numberless" credit cards, and i've seen one or two banks talk about releasing a consumer version, but as to how that connects to "Randomjoescrap.com.au" being able to process that payment, isn't fully developed yet. I suspect it'll work like some kind of "Passkeys" type thing where you scan a QR code to do the payment. That'll be the next way sites get hacked for payment details, replace said vendor payment QR code with "dodgysite.com" payment details... yes it'll only work once as it'll be tokenised, but how many people will notice until its too late anyway?
     
  19. cvidler

    cvidler Member

    Joined:
    Jun 29, 2001
    Messages:
    20,426
    Location:
    Canberra

    it'll probably end up more like Visa and Mastercard will set up their own PayPal equivalents. Where your account deets are kept centrally, and all randomjoescrap.com.au gets is, yeah bcann sent you $50, it's on the way. there's nothing to hack* from the vendor sites. and MC/Visa etc. have much more invested in being secure than Joe who hasn't updated the myeshop plugin on his site since whenever it was first put together.

    not a stretch as Visa/MC already do all the middleman work for a CC transaction, they just then take over the front end as well.


    * in terms of payment deets, they'll still of course poorly collect and store your name, and addresses.
     
    bcann likes this.
  20. Hater

    Hater Member

    Joined:
    Nov 19, 2012
    Messages:
    6,224
    Location:
    Canberra
    bankwest and commbank = same

    so i guess they're using bankwest as a trial before taking it to commbank customers
     

Share This Page

Advertisement: