RE: https://infosec.exchange/@SecurityWriter/116305873092655616

if people stopped giving all these corporations their age or id/kyc info and just canceled their subscriptions or accounts for 4 months we'd see how fast they stop asking once those next quarter results show up.

governments would wake up pretty fast with less VAT, GST, and Tax revenue, too. you give them an inch and they will take a mile. cut that inch and cut their source of revenue, and they will all fall in line.

that is the only solution to all these stupid laws.

the only time you should hand over your ID like a passport or stuff like that is when you absolutely need to. for example like crossing international borders, opening or operating a bank account or applying for a driver's license. those are all valid cases and highly regulated.

but this for profit corporation will just use your data to target you for profit. they even sold mobile phone numbers used for 2FA to advertisers. can you really trust them now with this nonsense?

Sweden’s Digital ID System Hacked, Public’s Data Sold on Dark Web

Frank Bergman Sweden’s sweeping national digital ID system has been hacked, with the public’s sensitive data already being sold on the dark web...

@twit_terrorist @nixCraft Click bait.

"CGI also stated that the attackers accessed an older version of the source code and insisted there was “currently no indication of any impact on customers’ production environments, production data, or operational services. Information to the contrary is not accurate.”

The Swedish Tax Agency echoed that position.

“We take all incidents seriously, but we don’t see anything that affects us right now,” IT Director Peder Sjölander said."

@txtx @twit_terrorist @nixCraft

> However, cybersecurity experts warn that exposure of source code, even from test environments, can provide attackers with a roadmap to exploit live systems, including authentication flows and security architecture.

This always bugged me.. just as we say open-source is better for security due to the many eyes, shouldn't we say open architecture is better for the same reason?

Yeah, while your arch is closed it is more likely crappy, but that would change fast.

@txtx @twit_terrorist @nixCraft

I imagine if sufficiently many arch were open, this would fly. It might be a problem for you to be the first one to open up your arch. It could be an invitation for bad actors (or those with incentive to keep security bad) to prove your idea wrong.