Comment by sokols
12 hours ago
I think that the third parties who have been granted access to the civil registry should be audited on a regular basis for the “best practices” of the day. Similar to the participants of the payment systems like VISA or MC that are regularly audited for PCI standards.
A least privilege access redesign seems reasonable too. And abuse monitoring; the leak went on for 21 days undetected.
Or simply make people who choose insecure passwords criminally responsible for the fallout.
and make the people who didn't put any sort of limits on how many records can be downloaded before there has to be a check on what is going on or any of the other stupid security holes that were found, make them criminally responsible as well. At some point you can be sure you'll be imprisoning someone for making a typing mistake (accidentally commented out some code) or a logic mistake (I should have said IS NOT, but instead I said IS) or just being tired.