816
classic opsec mistake (discuss.tchncs.de)

cross-posted from: https://discuss.tchncs.de/post/10692187

so, the company was Vastaamo. was because it got bankrupt after the breach, and GDPR violations.

the "hacker"(or rather cracker) was extradited from France to Finland.
you can read about how terrible the company's security was here: https://tietosuoja.fi/en/-/administrative-fine-imposed-on-psychotherapy-centre-vastaamo-for-data-protection-violations

or watch mental outlaw's video on the matter, or the Wikipedia article on the breach.

now there are several things that shouldn't have happened (e.g.: don't do these things on your main OS, have root access disabled, etc.), but I'll leave that to you experts.

you are viewing a single comment's thread
view the rest of the comments
[-] baseless_discourse@mander.xyz 93 points 1 year ago* (last edited 1 year ago)

While in the U.S., your mental health data are just on the market, waiting to be brought.

https://www.ftc.gov/business-guidance/blog/2023/03/ftc-says-online-counseling-service-betterhelp-pushed-people-handing-over-health-information-broke

In the good case, there will be a class action law suit, and every victim will get approximately 2 dollars back for all their health data sold; but only after giving more sensitive information to the company that distributes these two dollars.

https://www.morrisbart.com/faqs/how-is-money-divided-in-a-class-action-lawsuit/

What a fun time to be alive.

[-] randoot@lemmy.world 25 points 1 year ago

What the fuck, I had no idea about betterhelp being so scummy.

[-] chiliedogg@lemmy.world 55 points 1 year ago

I firmly believe any service that advertises that much on YouTube and podcasts is evil.

I'm waiting to hear about Hello Fresh's child trafficking ring or whatever they're up to.

[-] EvilLootbox@lemmy.world 20 points 1 year ago

Hello Fresh is notorious for being an abusive employer who LOVES union busting!

https://www.theguardian.com/us-news/2021/nov/11/hellofresh-employees-union-claims-abuse

[-] Agent641@lemmy.world 14 points 1 year ago

pulls off loose sticker from box

'Hello Flesh'

Its made of people!

[-] WhiskyTangoFoxtrot@lemmy.world 13 points 1 year ago

Yeah. Turns out, Raid: Shadow Legends is just about the least scummy thing being advertised on YouTube.

[-] AMDIsOurLord@lemmy.ml 13 points 1 year ago

Raid Shadow Legends is connected to an Israeli gambling company

Anything that advertises heavily is most likely to be a piece of shit

[-] IntentionallyAnon@lemm.ee 8 points 1 year ago

I find Nord’s sponsor scripts misleading at the best and lies at the worst but the service for what it is is pretty good. Still would recommend Mullvad

[-] anivia@lemmy.ml 6 points 1 year ago

but the service for what it is is pretty good

I disagree. Most people wouldn't need it at all, and for most people that would actually need it it's useless due to not supporting port forwarding

[-] IntentionallyAnon@lemm.ee 1 points 1 year ago* (last edited 1 year ago)

Mainly so someone doesn’t get my ip and know my city and sometimes I sail the high seas

I know ip is useless. I just don’t want someone to get my city and send an investigator

I fully agree with your point. I feel like sponsor scripts should say these points. 1: if somebody sends you an ip tracker link Nord won’t leak your IP 2. if you want to watch georestricted content 3. If you are on someone else’s network and you don’t want them peeping your websites. 4. 🏴‍☠️

[-] anivia@lemmy.ml 1 points 1 year ago

and sometimes I sail the high seas

Yeah, but it's useless for that. If you pirate from Usenet or one click hosters you don't need a VPN, and if you use torrents or other peer to peer protocols you need port forwarding, which NordVPN doesn't support

[-] IntentionallyAnon@lemm.ee 2 points 1 year ago

It works for me and the ISP hasn’t caught on

this post was submitted on 11 Feb 2024
816 points (98.2% liked)

linuxmemes

22622 readers
2040 users here now

Hint: :q!


Sister communities:


Community rules (click to expand)

1. Follow the site-wide rules

2. Be civil
  • Understand the difference between a joke and an insult.
  • Do not harrass or attack users for any reason. This includes using blanket terms, like "every user of thing".
  • Don't get baited into back-and-forth insults. We are not animals.
  • Leave remarks of "peasantry" to the PCMR community. If you dislike an OS/service/application, attack the thing you dislike, not the individuals who use it. Some people may not have a choice.
  • Bigotry will not be tolerated.
  • These rules are somewhat loosened when the subject is a public figure. Still, do not attack their person or incite harrassment.
  • 3. Post Linux-related content
  • Including Unix and BSD.
  • Non-Linux content is acceptable as long as it makes a reference to Linux. For example, the poorly made mockery of sudo in Windows.
  • No porn. Even if you watch it on a Linux machine.
  • 4. No recent reposts
  • Everybody uses Arch btw, can't quit Vim, <loves/tolerates/hates> systemd, and wants to interject for a moment. You can stop now.
  • 5. 🇬🇧 Language/язык/Sprache
  • This is primarily an English-speaking community. 🇬🇧🇦🇺🇺🇸
  • Comments written in other languages are allowed.
  • The substance of a post should be comprehensible for people who only speak English.
  • Titles and post bodies written in other languages will be allowed, but only as long as the above rule is observed.
  •  

    Please report posts and comments that break these rules!


    Important: never execute code or follow advice that you don't understand or can't verify, especially here. The word of the day is credibility. This is a meme community -- even the most helpful comments might just be shitposts that can damage your system. Be aware, be smart, don't remove France.

    founded 2 years ago
    MODERATORS