How the state helps hackers steal our data

Some might think that security regulation is a necessary pursuit for society. However, in reality, because of the actions of regulators, the exact opposite happens—endless security checks and reports, which are supposed to protect us, actually do the reverse. Companies spend insane amounts of money and a ton of time just to appear secure in the eyes of officials. Consequently, there is neither the energy, the nerves, nor the budget left for actual data protection. The result? Another hack, another leak.

For example, take 23andMe. These cool guys do DNA tests so you can find out that you are 3% Mongol, 5% Swedish, and 92% an ordinary person who simply has nothing to do on a Friday night. You would think they would guard the data like Fort Knox. Yet, the year before last, hackers pulled nearly half of all user data, and now millions of genetic profiles are floating around the internet.

Think this is an exception? No, it’s more of a rule. Take our Sber. You’d expect a major bank, with stricter laws and constant reporting requirements, to be secure. And then—bam—a data leak of 52 million customers. And that’s just from the “Spasibo” loyalty program. Apparently, the customers said “thank you” to the bank, but someone decided that “you’re welcome” meant letting their data scatter across the darknet.

But that’s not all. Remember Yandex.Eda? There was a downright anecdotal case there: they delivered a pizza to someone in the secret apartment of an FSB officer. A data leak from the service revealed the addresses of famous people and security force employees. Thus, the state accidentally stepped on its own tail. It was almost funny, but not for those whose addresses became public.

Why does this happen? Because regulators love checking boxes. They adore paperwork and reports. A hypothetical Vasya from the security department spends 70% of his time on reporting and only 30% on fighting real threats. Then hackers break the defense that no one had time to strengthen while Vasya was trying to figure out how to fill out another form for Roskomnadzor. It becomes a vicious cycle: hacked → fine → even more reports → hacked again.

And the state only adds fuel to the fire. Remember the “Yarovaya Law”? Telecom companies are forced to store giant volumes of data, spending billions of rubles. Now guess who is salivating while looking at these massive data arrays? Exactly—hackers. Because gathering all of this in one place is like putting a huge safe in the middle of the city and hanging a note: “Dear thieves, there are valuables here; we aren’t guarding them because the money went toward buying the safe.”

Of course, the picture is roughly the same in the USA. Medical data leaks there have already become a national sport. So many records were leaked last year that you could give several to every American. The hack of Equifax, the credit history giant, is a “genre classic.” 147 million records fell into the hands of criminals, and the company received a $700 million fine. Imagine how much security could have been improved if that money had been put to work in advance, rather than into paperwork and fines? The moral here is simple: the more a stationary bandit forcibly “protects” our data, the more often that data is lost.

So, what should be done? Probably force companies less to spend their energy on pointless paperwork. Instead of hundreds of mandatory checks, let there be one clear standard: “Protect the data or pay—but not with reports, with money.” And the companies will find the best way themselves. Otherwise, it’s like the joke about the elephant in a china shop: the state stomps around, the dishes break, and the elephant is, of course, to blame. Therefore, it is necessary to stick to simple and clear rules. Regulators come and go anyway, but for some reason, our data remains wandering the network forever!

Voluntarist, Bitarch

Leave a Reply