HN user

throwaway692675

76 karma
Posts0
Comments4
View on HN
No posts found.

It wasn't worth pursuing, partly because it was a part time job. A bit sad, as the company had promised to sponsor him though further study. It was the right decision, as it turned out to be less effort than a court case to get better opportunities with other companies.

It happened as described. Before it happened, I didn't think there were people like that in this world.

To his credit, the family member took it as a life lesson and moved on (probably more than I have given my posting here). These days he deals with companies that value his contributions, and it turns out that his ex-employer's loss is other companies' (significant) gain.

Because it's not worth it. I'm protecting the family member, not the company.

The image of people standing up for the noble whistleblower is far from the truth. Disclosing the company here won't achieve anything apart from garnering a few karma points and generating some short lived outrage at the company.

I'd consider disclosing it to the ICO, and made tentative steps in that direction at the time, but it's not clear that they are interested and whose interests they would protect.

Here's a question that might make this discussion useful: What is people's experience of reporting data breaches to the UK's ICO? In your case, was meaningful action taken by the ICO and was the person doing the reporting protected? .

I'm aware of another batch of leaked passports, from a few years ago.

A family member was booking a school tour, when he noticed the URL of the Travel CRM included an id number. Sure enough, the CRM would return all his details given only the (sequential) id number without a need for credentials: high resolution passport scan, and all the other details provided when booking an overseas trip.

He notified the CRM company, and that email was ignored. He emailed again, proposing disclosure, and the problem was silently fixed with no response.

A few months later he mentioned it to the school, along with the fact that he had followed up and had the vulnerability fixed. The school went straight into panic mode, called him to the principal's office and forced him to write a statement so they could refer him to the Feds. I intervened, explaining that he was the good guy who got the vulnerability fixed, and the problem was the school's, since they had supposedly vetted the CRM for security when choosing a tour company.

All of a sudden from the school's point of view there was no problem and no need to mention it to any of the people whose information had been disclosed, despite my insistence. The people still haven't been notified. The school did acknowledge that the family member had done the right thing and verbally thanked him, but would not put anything in writing.

The people involved in the tour had their details leaked, but there was nothing special about those people in the system, so realistically every person whose details were in that CRM had their details, including passports, leaked. It was a major travel CRM provider, so the number of people in the system would have been 6 or 7 figures.

The kicker is that the family member was employed by a software company that had the school system as a customer. The IT person who was responsible for vetting the travel CRM (and had verbally thanked him) arranged for the school system to phone his employer and deliver an ultimatum: that the family member be sacked or they would risk losing a customer. The family member got the sack.