Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You could argue that the government agency is at fault. 1 for their breach, 2 more importantly: for mandating that personal information get handed over without an official court order which would have involved a far more stringent process with multiple parties involved.
 help



My understanding of the situation is that no government agency actually requested data at all, just that someone impersonated a government email address and this was enough for Revolut to reply with the requested data.

The government did request the data. And since the announcement, it has requested highly sensitive data again, and to keep such data, backed by threats of violent repercussions, that businesses cease to operate or to even exist.

That's a dangerous kind of threat to be making, and to act upon. for information that should remain private let alone owned by the bank itself.


> The government did request the data.

What's your source?

That is not what the news says.

Also, you know you can easily impersonate any email? That's a flaw of the email protocol.


I never wrote the government made the specific request that led to the leak. I explain that the government make such requests.

So when a company is requested to hand over sensitive data, they do. For sure when the origin of the request is the government itself (pawned email in this case)


From the PR statement, it's unclear if a gov. agency was hacked or it was a phishing attempt, from my point of view. Both cases are still not enough, even for a greasy spoon.

If the Revolut know the agency was hacked it surely would be in their interest to say so (unless the agency hold them at "gunpoint")



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: