logoalt Hacker News

sokols • today at 10:33 AM • 2 replies • view on HN

I think that the third parties who have been granted access to the civil registry should be audited on a regular basis for the “best practices” of the day. Similar to the participants of the payment systems like VISA or MC that are regularly audited for PCI standards.


Replies

zweifuss • today at 10:38 AM

A least privilege access redesign seems reasonable too. And abuse monitoring; the leak went on for 21 days undetected.

iLoveOncall • today at 10:36 AM

Or simply make people who choose insecure passwords criminally responsible for the fallout.

➕ show 1 reply