Does this passwordless future still involve getting a cookie in your browser that can be stolen and used from an attackers machine? If so, we still have a problem to fix.
Suing a journalist is not a good look. I wonder what other vendors out there will take up some market share from them after this nonsense is over. Hopefully this in the end this turns into a net positive for Krebs.
Maybe I missed it but did they cover logging all keystrokes entered by users over the bastion? (In the case where you need to log into it first vs merely doing port forwarding)
When I looked mine up I could see just about every job I’ve ever had. It also showed who pulled this report over the past 24 months. I see that my credit card companies pulled it, a background check company that my current job used, and also some random “TEST Batch Account” whatever that is.
SSN + DOB and you can find out how much money I made on my w2 for many years of my life. Nice.
I am debating on doing a ccpa delete on this data. I wonder if future employers will give me a hard time when negotiating pay if they can’t verify my salary this way? Also, will I have to delete it every time that an employer sends them this data? Awesome.