[HN Gopher] Lost USB with 460k city residents' personal data found
___________________________________________________________________
Lost USB with 460k city residents' personal data found
Author : Kaibeezy
Score : 249 points
Date : 2022-06-24 10:25 UTC (12 hours ago)
(HTM) web link (www3.nhk.or.jp)
(TXT) w3m dump (www3.nhk.or.jp)
| O__________O wrote:
| For content, Japan is well known for finding & returning lost
| items.
|
| From 2020: "With an inner-city population fast approaching 14
| million people, millions of items go missing here each year. But
| a staggering number of them find their way home. In 2018, over
| 545,000 ID cards were returned to their owners by Tokyo
| Metropolitan Police - 73% of the total number of lost IDs.
| Likewise, 130,000 mobile phones (83%) and 240,000 wallets (65%)
| found their way back. Often these items were returned the same
| day."
|
| Source: https://www.bbc.com/future/article/20200114-why-japan-is-
| so-...
| seanw444 wrote:
| A sign of a mannered people. Now let's try it in New York.
| bragr wrote:
| No it's a sign of the overall culture, not the individual.
| You could do this in New York but it would be so unusual that
| people would think you are scamming them or just look at you
| like you grew a second head.
| picture wrote:
| I think "a sign of a mannered people" refer to the
| collective rather than the individual, but it also takes
| changing the individual to change the collective.
| zzixp wrote:
| Related video:
| https://www.youtube.com/watch?v=jnL7sJYblGY&t=2s
| upupandup wrote:
| It's a testament to Confucianism. Same in Korea, you can
| leave your items unattended, lost items are always returned.
|
| I also wonder if this is more the result of a homogenous
| society. Since everyone is expected to know the rules and the
| cost of going against it is known. ex) ijime culture in japan
| esotericimpl wrote:
| elliottkember wrote:
| I have a link for you!
|
| > A group of 13 research assistants (11 men and 2 women) were
| recruited for a trip around the world. They traveled to 355
| major cities across 40 countries. In each city, they visited
| banks, theaters, hotels, police stations, and other public
| spaces and turned in a "lost wallet," which they claimed to
| have found on the street, to a nearby employee.
|
| https://gizmodo.com/researchers-lost-17-000-wallets-in-
| hundr...
| brentm wrote:
| > The company explained that the employee had drinks after work
| and later fell asleep on the street, but when he woke up he
| realized that he had lost the bag containing the USB.
|
| I respect the honesty but wow, I can't believe any company would
| spell it out that literally.
| Markoff wrote:
| That's what happenes when you are not tied with US political
| corectness BS and can say things as they are, one of the few
| things I liked about China as well, which is similar int his
| aspect, people have no problem to say harsh truth (unless it's
| politics), though on the other hand they often lie about
| irelevant things.
| tomjakubowski wrote:
| Interesting to label vague, indirect phrasing as "political
| correctness" -- US police departments are notorious for this
| when giving accounts of police shootings.
| ziddoap wrote:
| > _can say things as they are, one of the few things I liked
| about China as well,_
|
| What a hearty laugh this gave me early in the morning, thank
| you.
| IncRnd wrote:
| > can say things as they are, one of the few things I liked
| about China as well
|
| Some of the people who live there would disagree with your
| assessment.
| happyopossum wrote:
| > one of the few things I liked about China as well, which is
| similar int his aspect, people have no problem to say harsh
| truth
|
| That explains the daily mass protests I see on TV in Shanghai
| and Beijing about slave labor. Or all the discussion about
| the Tiananmen Square protests. Or all those T-Shirt vendors
| with shirts that have the Tank Guy pic or Free Hong Kong
| slogans.
| samatman wrote:
| Given how Japanese work culture functions, this is not that
| different from an American company saying that an employee went
| to a company happy hour and lost the USB stick in the taxi on
| the way home.
|
| Staggering to a bench and sleeping it off is just, normal. No
| one is going to pick your pocket, so why not?
| 0des wrote:
| > No one is going to pick your pocket
|
| I can't fathom this. I cannot imagine a world in which passed
| out drunk guy doesn't get audited in his sleep.
| SEJeff wrote:
| For all of the "freedom" we have as Americans, there are
| many areas much of the rest of the western world does
| things better. Not getting political, but just factually...
| check out gun violence statistics next.
| IncRnd wrote:
| Check out knife statistics in China. They don't have
| school shootings but mass school knifings.
| fellowniusmonk wrote:
| A cursory google pulled this wikipedia article up (linked
| below), and it makes it seem like mass knifings are
| generally rare and generally less destructive compared to
| north american shootings.
|
| Do you have an article or graph (per capita or absolute)
| of deaths comparing the two countries you could point to
| for more info?
|
| https://en.m.wikipedia.org/wiki/School_attacks_in_China
| thrownblown wrote:
| you have never been to tokyo on friday night/saturday
| morning. business dudes sleeping it off on benches are not
| uncommon at all.
| 0des wrote:
| It's on my list of places to go. For now, all I have is
| PaoloFromTokyo, which is family friendly so there isn't
| much nightlife content. I had no idea there was this
| level of public good will.
| thrownblown wrote:
| that was one of the things that surprised me on an early
| saturday bike ride, also in regards to street crime in
| japan, at least in my experience it is so exceedingly
| rare that most people there are incredibly naive to it.
| 0des wrote:
| What street dangers are there?
| [deleted]
| [deleted]
| armada651 wrote:
| You don't have to fear getting mugged in the streets, but
| you can still get ripped off.
|
| One example are the notoriously expensive bars in
| Roppongi, at night there will be touts in the streets
| trying to convince tourists to join them for a night of
| drinking. They'll then go to the bar that hired those
| touts where, after a night of drinking, the tourists will
| be presented with a bill that's the equivalent of getting
| robbed.
| ethbr0 wrote:
| That was my experience in Japan and Thailand.
|
| The line for "acceptable robbery" was "no physical
| violence" + "someone consensually gives me their money."
|
| Which is still possible (and easily doable if that mark
| is drunk), but is substantially different from American
| (and European?) style physical robbery.
| 0des wrote:
| Just curious, how much are we talking here? Sometimes out
| here the bar tab can get up to 300-400 for 2, especially
| if you order bottle service, since the law states they
| can only sell per drink and not full bottles.
| snlnspc wrote:
| Thousands (USD) for a drink or two, tens of thousands for
| a bottle or two. It's a very well known scam in some
| parts of Tokyo, and similar forms exist in many parts of
| the world.
|
| Long and short, don't let someone on the street talk you
| into going into a bar or tea shop or whatever, and
| especially don't follow them to a second location.
| 0des wrote:
| wow sweet jesus, they get away with that?
| Tijdreiziger wrote:
| In that case, you might also be interested in Tokyo Lens,
| TAKASHii from Japan, That Japanese Man Yuta and Let's ask
| Shogo, all on YouTube. Dogen is also highly recommended.
| limaoscarjuliet wrote:
| Oh yes, drunk businessmen sleeping around JR stations
| because they did not make it for the train to come home for
| the night are treated as holy cows in India. Full respect,
| including Police.
| moomoo11 wrote:
| Japan is awesome. I'm a brown guy and went to Japan and I
| had the mistaken thought that I would feel like an
| outsider.
|
| I couldn't be farther from the reality. Japanese people are
| so kind and welcoming, and their cities and towns are
| beautiful, safe, and clean. Just a simple hello led to some
| amazing conversations, and I felt as if I was living at the
| edge of the future because we talked by passing our phones
| to each other. Google translate enabled us to have real
| time conversations and get to know about each other.
|
| I met an old man who gave me my Japanese name and dropped
| some wisdom. A businessman and I shared our thoughts on
| life and family over a late night off the map hole in the
| wall type of seafood ramen place. Ran into some people at a
| bar who happened to work in the same industry as me and we
| shared stories over beers. When I missed my bus in a remote
| town, a family reopened their restaurant and cooked a meal
| for me.
|
| I was there for only a few weeks, and I wish I could move
| permanently to Japan. If any Japanese company or
| entrepreneur wants to hire me as a software engineer
| manager or as a co-founder, hit me up!
| bravura wrote:
| I am curious for perspectives on this.
|
| My immediate guess, based upon dealing with people not
| Japanese specifically: Japanese culture welcomes
| outsiders who respect the culture. But once you try to
| get deep into the fabric of the community (buy property,
| marry a local, etc.) there is a strong invisible wall of
| which you were not aware.
|
| Most cultures seem to have different ideas of where and
| how boundaries are created to push away outsiders. The
| notoriously cold Germans are _initially_ very cold, but
| once you 're on the inside there is complete trust.
| Meanwhile, the flaky southern California "let's do lunch"
| thing is an endless series of weak onion-like translucent
| boundaries and you never can get to the core of things.
| Groxx wrote:
| Japan is consistently very welcoming of _visitors_. It 's
| a _fantastic_ place to be a tourist - clean, safe,
| welcoming, and top-tier cheap transit in major cities. If
| you 're a permanent resident though, you start grinding
| against the extremely strong culture of conformity, which
| you can never quite achieve simply due to biology.
| noboostforyou wrote:
| Riding the bullet train from Kyoto to Osaka, accidentally
| left my iPhone in the seatback pocket. Didn't realize it
| until way later, but was able to use find my phone to see
| that it was still powered on and had made its way all the
| way to the end of the line. Went to the local train
| station's lost and found, they called the other station
| where the phone had been turned in. They shipped it to
| where we were staying. I can't imagine ever getting my
| iphone back like that in the US.
| envp wrote:
| I lost some clothes, sneakers in a duffel bag on my first
| ride with LIRR from NY Penn. Nothing valuable, but
| certainly essential. Was told off by the on-duty person
| to either show them a picture of the bag & items or get
| new ones lol.
| InCityDreams wrote:
| Nark Rober - 200 wallets. https://youtu.be/jnL7sJYblGY
| Fomite wrote:
| My wife left her Kindle on a United Airlines flight, and
| two days of searching later, they found it and shipped it
| to us.
|
| A friend left an iPad on a flight. That was shipped back
| to him as well, albeit with a dick drawn on the screen in
| sharpie.
| darkwater wrote:
| You usually (there are some exceptions) don't hop off and
| on planes. With trains is the norm, so you simply cannot
| compare the anecdotes.
| robot9000 wrote:
| Maybe in California, but it's a lot less likely in the
| civilized world.
| 0des wrote:
| It's not the civilized world, but here in the south
| you'll wake up with a racoon in your pocket making off
| with your Dentyne Ice and a flock of mosquitos airlifting
| a liter of O-positive.
| Phrenzy wrote:
| That's doesn't sound like a big deal. I don't really care
| for that type of gum and that isn't even close to my
| blood type.
| 2143 wrote:
| > I can't fathom this.
|
| I'm told that in northern Europe you could leave your
| laptops or whatever in semi-public places (like, cafes I
| suppose), and if you come back after a few hours it would
| still be there.
|
| Can northern Europeans confirm or deny this?
| NalNezumi wrote:
| From Sweden, Stockholm, can say a solid NO. my coworker
| lost his backpack (wallet, iPad and Mac) in the
| university computer room (card key required to get in) by
| just leaving it for 5min under summer HPC course. When we
| managed to track the mac down (through cloud & GPS) it
| was 40km away, moving in a car.
|
| You can usually ask someone to keep an eye out while you
| go to the restroom/refill coffee and most people are
| happy to help, but you need your due diligence
| asutekku wrote:
| In Finland, I wouldn't leave my staff for half an hour
| but definitely can leave my stuff if I go to a toilet for
| example.
| juahan wrote:
| Having lived in Norway and Finland, I'd say it would be
| very likely that you would get your items back. And if
| there would be contact details, someone would have most
| likely tried to call you before the few hours would be
| up. Would more or less the same in actual public spaces
| as well.
| toyg wrote:
| Define "Northern Europe". With all due respect, I
| wouldn't test that theory for 10 minutes in Amsterdam,
| Malmo, Gothenburg...
| Cloudef wrote:
| In finland it depends. In Helsinki? Nope. Anywhere else?
| Yeah.
| tannhaeuser wrote:
| Depends on sex.
| flimflamm wrote:
| Depends. Usually yes. Also wallet return rates are high /
| Finland.
| 2143 wrote:
| That's cool.
|
| Where I'm at when people (like, taxi drivers) do bother
| to return lost-and-found wallets, it's newsworthy enough
| to make its way to the newspaper.
|
| That should tell you the status quo here.
| [deleted]
| Tor3 wrote:
| For _hours_? No way. I wouldn 't do that, even if I
| sometimes leave stuff for a few minutes if I'm in a
| cafeteria I know well, plus etc. etc. But not for hours.
| At best your stuff would be taken care of by e.g. the
| cafeteria personnel, if not then with that much time the
| statistics won't be in your favour.
| twawaaay wrote:
| I lived in Sweden for a little bit, traveling around and
| into Norway and I can confirm this, at least partly.
|
| Where it is not true is in large cities. Small cities and
| rural areas are one of the safest places on Earth as long
| as you don't get nibbled by a moose or overrun by ants.
| drdeadringer wrote:
| > audited
|
| I've not before seen this word used to substitute for being
| checked over for being robbed.
| plainnoodles wrote:
| I don't usually actually laugh at HN comments, but when I
| read "audited" in this context, I did. I don't know why,
| but this kind of tongue-in-cheek use of a more
| "sophisticated" word to refer to something mundane like
| robbery is my kind of humor.
| rr888 wrote:
| After spending too much time with External Audit on
| meetings and reports, I'd actually prefer being mugged.
| IncRnd wrote:
| I guess you don't like getting soced.
| baisq wrote:
| Homogenous and wealthy society, basically.
| tux3 wrote:
| They sound a lot more trustworthy to me for owning up to it and
| spelling it out literally. That makes it sound like an isolated
| incident that they're able to recognize as a problem publicly.
|
| When a company does a standard "we take your privacy very
| seriously" non-response right after demonstrating that they do
| not, in fact, take it very seriously, it makes it sound like
| they're not willing to acknowledge the problem at all.
| xbar wrote:
| Agreed.
|
| The transparency of the entire event, end to end, becomes a
| "ho hum, thanks for telling me, i guess" sort of story. Which
| is, I suppose, why it's on HN.
|
| I mean, "guy loses usb with data, finds usb with data" used
| to happen to me twice on Thursday back when usb was a thing.
| It was hardly front page news.
| Aeolun wrote:
| > That makes it sound like an isolated incident that they're
| able to recognize as a problem publicly.
|
| I think it's more that 80% of all company employees can
| symphatize. The situation isn't all that uncommon (falling
| asleep on the street and misplacing your stuff somewhere).
| The fact that this person had a USB stick with the data of
| ~450k people on was.
| astura wrote:
| Seems pretty normal for Japan.
| ugjka wrote:
| Isn't that Japan?
| Aeolun wrote:
| This is peak Japan.
| tester756 wrote:
| What would be the equivalent in dishonest company?
|
| "Nationwide cybersecurity attack performed by state level
| actors using novel techniques"
| plainnoodles wrote:
| Probably just not even saying anything at all, given they
| found the USB shortly after it was lost.
| googlryas wrote:
| Getting drunk after work and passing out on the street, on a
| train, at your office desk, are all actually fairly accepted
| aspects of Japanese "salaryman" work culture.
| seba_dos1 wrote:
| At work we are dealing with a bug which causes USB XHCI
| controller to die and become inaccessible after failed runtime
| resume, and it took me a while to understand how "lost USB" can
| be related to city resident data.
| sydthrowaway wrote:
| Where do you work
| omoikane wrote:
| Last time when something like this happened, it was 2 floppy
| disks[1], so at least they have improved that bit.
|
| [1] "Tokyo police lose 2 floppy disks containing info on public
| housing applicants" -
| https://news.ycombinator.com/item?id=29738298
| coffeeblack wrote:
| People still use external storage media without full disk
| encryption? How?
| shikoba wrote:
| Security, who Cares?
| [deleted]
| glandium wrote:
| The last thing I heard yesterday about this event is that they
| found the employee's bag where he presumably left it when he
| slept. He "just" forgot it there when he woke up...
|
| For all the talk about the USB and the handling of data, I so
| wish it had sparked some conversation about the drinking problem
| in Japan, but nope, not one bit about that. But you'll regularly
| hear how dangerous and evil Marijuana is...
| dvngnt_ wrote:
| if it was cannabis he would have forgotten too lol jk
| rado wrote:
| The data was encrypted and protected with a password, according
| to the city.
|
| - The Japan Times
| sys_64738 wrote:
| What is the intent of admitting this? What happened here is
| utterly appalling and the employee and a few layers of
| management above should be fired and prosecuted. Haven't these
| fools realized the data can be brute forced offline? Are they
| that stupid to not realize lists of passwords are run against
| such data?
| mola wrote:
| So you would've preferred they lied and covered it up?
| jamal-kumar wrote:
| It comes from a culture of honor and taking ultimate
| responsibility for your mistakes in order to preserve this
| honor through honesty and integrity, all the same which led
| to the safe return of the data in the end.
| 0des wrote:
| Good morning Jamal. I've got to admit, I really respect
| that culture of taking ownership of their mistakes. Other
| companies could take a page out of their book and do a
| little good.
| jamal-kumar wrote:
| Yeah, I went to school there when I was a teenager. It
| was an interesting experience to say the least. Much more
| social cohesion in some ways but definitely a LOT more
| bullying than I was used to seeing in North America. I
| got to be friends with the mean gay kids with shaved
| eyebrows and hot girls due to where I ended up doing my
| homestay and it was... wow, those kids were MEAN. Never
| towards me but a few kids in our classes really got the
| brunt of it. They were insulting their families to their
| faces in front of the teacher who just completely ignored
| this happening right in front of him.
|
| It's pretty clear in my travels that there's good and bad
| in pretty much every culture and every country, and that
| you should focus and celebrate the good while being
| highly aware of the flip side of things that might be an
| issue if you are blind to that.
| nonrandomstring wrote:
| > What is the intent of admitting this?
|
| Incident response always ends on "lessons learned" and it's
| rarely productive to hide the facts due to political
| embarrassment. Earliest disclosure also mitigates against
| much bigger liabilities as a consequence of a leak.
|
| > management above should be fired and prosecuted.
|
| And be immediately replaced by management with the same level
| of understanding and responsibility.
|
| > Haven't these fools realized...
|
| No. And this is the key point. The biggest thing by _FAR_ in
| cybersecurity is education. Ordinary people do not have any
| working model of the threat landscape and basic operational
| security because they foolishly, blindly trust technology and
| services providers.
|
| We literally need a second digital literacy revolution. One
| that undoes a lot of the naive and trusting enthusiasm for
| digitalisation that we inculcated in the 80s and 90s.
| Unfortunately that goes against the grain of almost every
| policy that's active out there today.
| badkitty99 wrote:
| lmm wrote:
| No doubt the password was written on a piece of paper next to
| the USB. This is the country that loves to send an encrypted
| attachment and a separate email a minute later with the (weak)
| password as if that achieves anything.
| [deleted]
| kalleboo wrote:
| It was announced ON THE NEWS that "the password was 13
| English characters that had meaning to the staff and policy
| was to change it yearly".
|
| The city name is Amagasaki. Everyone on Twitter is guessing
| the password was "Amagasaki2022"
| chx wrote:
| Unlikely. amagasaki2002 is more likely :P
| [deleted]
| tnzk wrote:
| One of the largest banks in Japan once sent over me a piece
| of paper on which the password I set was written :)
| sva_ wrote:
| I once lost my sim card and wanted to lock it, so I called
| the phone company and they asked me for the first 3
| characters of my password to verify myself.
| smcl wrote:
| So I know what you're thinking but it is at least
| technically possible that they don't store it as
| plaintext - like maybe when you set the password it
| stored a salted hash of the whole thing, plus also a
| special hash of the first 3 chars for emergency recovery
| or locking operations (ie can be used when you show up
| in-person with the photo ID they have on file). So they'd
| enter the characters, and compare the hash and you'd then
| follow password reset process offline.
|
| But ... while it's possible, I think we all know they
| probably just stored it as plaintext :-D
| seoaeu wrote:
| Storing a hash of the first three characters still
| cripples the security. It is trivial to brute force a
| hash when there's only 62^3 possibilities. And once you
| know the first characters, brute forcing the remaining
| ones is exponentially easier
| smcl wrote:
| It absolutely does and you're right it would still be
| stupid (though making 62^3 phone calls or store visits
| might not be feasible). I was trying to say it doesn't
| necessarily mean your password is stored in the clear.
| But honestly I think any time you're prompted like this
| for something that _might_ get implemented via storing a
| password in the clear it probably means it _was_ been
| implemented that way.
| 13of40 wrote:
| > an encrypted attachment and a separate email
|
| It's a useful vector for things like malware because an
| intermediate scanning service can't examine the attachment
| without having both emails. If there's a concern about some
| PII or whatever being intercepted in transit, it should help
| with that too.
| BiteCode_dev wrote:
| We can't expect the general public to be very good at
| security.
|
| I gave up on PGP, and most of my clients and I don't have
| an e2e encrypted chat or password manager service in
| common.
|
| But at least I tell them to use a "burn after reading" post
| on an encrypted pastebin like 0bin.net for the secrets
| thing to send me.
|
| It adds almost no complexity, best case scenario, you
| increase the security against bots since they would need to
| parse the link, visit the paste, trigger the Burn After
| Reading feature, interpret JS, extract the password and use
| it. That's already a pretty specific bot.
|
| Most interceptions, even human, will be detected thanks to
| the burn after reading. And the password is never stored in
| the pastebin db since it's encrypted client side.
|
| Worst case scenario, it's the same than a plain text email.
| Not much to loose.
|
| It's easy to teach. Requires no install, little skill or
| tech, works in most corporate setup.
|
| It's not good security. But it's better than abysmal
| security.
| Symbiote wrote:
| It isn't the general public though. It's staff who should
| be trained to use tools necessary for their job.
| BiteCode_dev wrote:
| I'll let you know on a secret: most staff is composed of
| the general public.
| robobro wrote:
| > The company explained that the employee had drinks after work
| and later fell asleep on the street, but when he woke up he
| realized that he had lost the bag containing the USB.
|
| Oh, Japan...
| Cloudef wrote:
| Ah yes, very common here
| reaperducer wrote:
| If he had gone to sleep in the train station because the trains
| stop running at midnight, and someone returned the wayward USB
| drive to him while he slept, with a little note and a can of
| Premium Boss for when he woke up all hungover, it would be the
| most Japan story of the month.
| 0des wrote:
| Only in Japan can you pass out drunk and wake up with
| presents and a caretaker. Unbelievable.
| Tor3 wrote:
| That reminds me.. someone I know very well managed to sleep
| past the only scheduled stop at a station near his home, and
| it was the last train for the night. But they helpfully made
| an unscheduled stop at the next station, just for him, which
| fortunately still wasn't too far away. Japan, of course.
| Trains in Japan are always on schedule, as in _exactly_ on
| schedule, but they have margins to work with and could do
| that extra stop by just increasing the speed a bit
| afterwards.
| yongjik wrote:
| From what I heard, the original press conference was a doozy:
|
| Reporter: Wasn't the password something insecure like a four-
| digit number?
|
| Officer: No, it's a 13-letter alphanumeric password.
|
| Reporter: But if it was totally random wasn't it hard to use?
|
| Officer: It's a meaningful English word, followed by a meaningful
| four-digit number, so it's quite easy to memorize.
|
| Reporter: By an English word, you mean something like _password_?
|
| Officer: It's not a simple word. It's a word and a number that
| are related to the City of Amagasaki.
|
| Reporter: Do you use a capital letter?
|
| Officer: It's grammatically correct, as only the first letter is
| capital.
|
| For god's sake, if you just lost a USB stick with the whole
| city's personal data, don't spell out how you chose your
| password!!!
| thingification wrote:
| https://en.wikipedia.org/wiki/Amagasaki
|
| "The city was founded on April 1, 1916."
|
| Amagasaki1916
| jonny_eh wrote:
| I just checked, it worked!
| imachine1980_ wrote:
| Joke???
| darkwater wrote:
| April's fools joke, to be precise.
| throwaway23234 wrote:
| City officials have been getting trained hard in not lying to
| the public so much that they probably felt obligated to answer
| these questions.
| sedatk wrote:
| Refusing to answer isn't lying though.
| upupandup wrote:
| i think this sort of demonstrates just how far behind and
| backwards Japan is. It's like the country is stuck in late 90s.
|
| In contrast, Korea seemed like it was on a different timeline
| with the massive digitization and broadband internet movement
| in the early 2000s.
|
| With a dwindling population, Korea seems more flexible/apt at
| dealing with the future. There is also a much larger
| awareness/movement to multiculturalism whereas Japan seems
| unwilling to deal with the looming crisis.
| new299 wrote:
| > i think this sort of demonstrates just how far behind and
| backwards Japan is. It's like the country is stuck in late
| 90s.
|
| I've lived in Japan for the last 10 years, in no way does it
| seem "stuck in late 90s". And this single incident in no way
| demonstrates this.
|
| For some reason it's culturally acceptable to make these
| kinds of comments about Japan in English language forums. But
| I don't really understand why... Japan is no doubt very
| different from other countries in various respects. But it
| doesn't seem helpful to say essentially "we are 30 years
| ahead of Japan".
|
| You could if you wanted say "wow the US/UK are stuck in the
| 1990s" because copper broadband is still common in the US/UK.
| In Japan you often have 4G fiber to the home in rural
| locations, and 10G connections available in some locations...
| it's not a super helpful comment though, because countries
| are complex and you can't point to single issues and make
| general statements about the countries stage of development.
| mutt2016 wrote:
| Also Japan is the world leader in fax technology. Fax. Many
| fax companies are only viable because of the Japanese
| market.
| Fomite wrote:
| Now do checkbooks and the US
| digisign wrote:
| US banking still stuck in the 70s and encourages rent-
| seeking third-parties to fill the gaps.
| jonny_eh wrote:
| Nintendo, one of Japan's largest/most successful companies,
| still doesn't know how to run an online service properly.
| Sony's Playstation is better (but not as good as
| Microsoft's Xbox), but the Playstation online service is
| run in California.
| mttjj wrote:
| And I could name a half-dozen US government -.gov -
| websites that are downright terrible with respect to
| usability and security practices. Since when does
| Nintendo represent all of Japan?
| Nuzzerino wrote:
| Still feels more intelligent then the average doctor visit
| these days in the US. Painting a country with the same brush
| overlooks the fact that some professions aren't sent the best
| and brightest, depending on country.
| notRobot wrote:
| This seems like it's out of My Family And Other Animals - 2022
| edition.
| pacarvalho wrote:
| At least there was a password lol
| TwistedWave wrote:
| Amagasaki2022
| TrainedMonkey wrote:
| "Amagasaki2022" is a 13-letter alphanumeric password with
| meaningful word and four-digit number.
| tyingq wrote:
| It was probably something like legacy/default zipfile utility
| encryption anyway.
| brigandish wrote:
| I see that a lot of people are praising the openness of this
| admission but cynical old me who's lived in Japan a while - a
| culture that (generally) values appearances over truth - notes
| that the article mentions that USB was found. I have to wonder if
| we'd have heard about it if they hadn't.
| johnwalkr wrote:
| It was definitely reported on before it was found.
| brigandish wrote:
| After a re-read of the article I do believe you are right.
| Thanks.
|
| My cynicism will live to fight another day though!
| [deleted]
| TheOnly92 wrote:
| They actually announced the length and the characters
| (letters/numbers) used in the password in yesterday's press
| conference, if you could believe it...
|
| Many people on the internet guessed what the password probably
| was (city name + year).
| zaik wrote:
| Source? Japanese original is fine.
| TheOnly92 wrote:
| Here https://www.sankei.com/article/20220623-YMHUI532OZPTHOXV
| JHHK...
| 960design wrote:
| [deleted]
| [deleted]
| Zenst wrote:
| Only just read the BBC article saying it was lost, which is only
| an hour old so clearly they didn't dig deep into this as the
| found article is three hours old.
|
| Shows news is best sourced from multiple sources for the full
| picture.
|
| https://www.bbc.co.uk/news/world-asia-61921222
| ume wrote:
| I've undertaken information security training in a number of
| Japanese companies. They all had what I thought was a
| disproportionate weighting on the "blind drunk salaryman falls
| asleep on a train and leaves behind a laptop, mobile phone, USB
| stick etc." scenario.
|
| I stand corrected.
|
| Edited for clarity
| iasay wrote:
| That was the usual loss vector when I was in the defence sector
| as well.
| lelandfe wrote:
| https://gizmodo.com/how-apple-lost-the-iphone-4-5520438
|
| It can happen to Americans as well, as evidenced by an Apple
| engineer leaving an iPhone prototype at a bar after his
| birthday.
|
| > _" I underestimated how good German beer is," he typed into
| the next-generation iPhone 4_
| jamal-kumar wrote:
| I always thought they did that "by accident" on purpose kind
| of thing. Like macrumors was always some kind of marketing
| ploy.
| zaptrem wrote:
| Unlikely seeing as they blacklisted Gizmodo for life and
| (afaik) practically busted down the door of one of their
| reporters.
| jamal-kumar wrote:
| I must be thinking of when this happened like at least
| two other times then [1]
|
| [1] https://www.cnet.com/tech/tech-industry/apple-loses-
| another-...
| belter wrote:
| It seems for the UK Ministry of Defense the going rate was 30
| lost per year...
|
| "...More than 120 USB memory sticks, some containing secret
| information, have been lost or stolen from the Ministry of
| Defence since 2004, it was reported earlier this year....Some
| 26 of those disappeared this year == including three which
| contained information classified as "secret", and 19 which
| were "restricted"...."
|
| "UK Ministry of Defense Loses Memory Stick with Military
| Secrets" (2008): https://www.schneier.com/blog/archives/2008/
| 09/uk_ministry_o...
| anonymousiam wrote:
| USB media is now prohibited on any classified system.
| They've even gone as far as disabling the USB storage
| drivers. Even having a USB memory stick in a closed area is
| a big no no.
| 0cVlTeIATBs wrote:
| And so the floppy lives on.
| toyg wrote:
| Big if true. I mean, I don't put anything beyond UK
| authorities these days, but even just buying readers
| would be a struggle.
| toyg wrote:
| I always assumed most of those sticks are simply stolen by
| employees, like pens.
| jrochkind1 wrote:
| So I actually can believe it happens to Americans as much as
| anyone, but that story is a bit different -- the Apple
| employees were testing the devices "in the field", bringing
| them along with you in your daily activities including the
| bar was intentional and part of the assignment.
|
| I don't know why you bring a USB stick with half a million
| people's data with you to the bar. Why is that even leaving
| the office?
|
| I bring this up not to talk about differences between
| Americans and Japanese (boring, I think they are probably
| exagerated), but becuase these are different "threat models".
| You handle the "USB stick with company data" on it "threat"
| by training people... not to just stick sensitive data in
| their pocket as they go about their business? It should be on
| a USB stick for as little time as possible and that USB stick
| should be treated like it's worth a fortune (because it is).
| There's no reason you should be carrying that thing with you
| to the bar in the first place.
|
| The iPhone case... eh, if you ask people to carry a device
| along with them in their daily lives, it's inevitable that
| someone will forget one someplace at some point. Maybe some
| kind of proximity alarm that beeps if you walk away from it?
| galangalalgol wrote:
| I'm with you on asking why that data was even on a
| removable drive. What possible use case is there for that?
| And if there is one, like transferring between airgapped
| networks, it seems you'd encrypt it at least.
| IncRnd wrote:
| The data was planted on the usb by an Evil Maid[1], so
| the salaryman could gain face [2] as an everyman.
|
| [1] https://en.wikipedia.org/wiki/Evil_maid_attack
|
| [2]
| https://en.wikipedia.org/wiki/Face_(sociological_concept)
| BiteCode_dev wrote:
| Also, it is suspected than Apple actually orchestrate those
| "leaks" for free publicity.
| dmd wrote:
| [by whom?]
| BiteCode_dev wrote:
| https://www.google.com/search?hl=en&q=apple%20ochestrate%
| 20l...
| 0des wrote:
| I suspect it, tbh
| samatman wrote:
| Does Apple do controlled leaks? Of course, any company
| which is able to keep secrets in the first place does.
|
| For the iPhone 4? Absolutely not, the only other model
| which changed iPhone as much as the 4 was the X, Steve
| was still alive for the 4 and there is absolutely no way
| he would have approved just leaving it in a bar for hype.
|
| Steve Jobs wanted to be the person who showed that to the
| world. Remember the first MacBook Air? Steve _lived_ for
| that moment.
| jrochkind1 wrote:
| We live in a conspiracist society, any secret plan you
| can imagine has "been suspected", and generally people
| require no particular evidence other than "it would make
| sense to me" (as if there aren't plenty of things that
| would make sense to me that haven't happened!)
|
| But if Apple actually wanted media outlets to cover it,
| having law enforcement seize and search the property of
| the editor that broke the story, and then banning the
| media outlet that broke it from WWDC... doesn't seem like
| the way to encourage anyone to cover it next time there's
| a leak, if you're actually hoping for coverage of
| secretly orchestrated leaks.
| https://www.pcmag.com/archive/gizmodo-banned-from-
| wwdc-25149...
| [deleted]
| smoyer wrote:
| Interesting ... I came here to highlight the quote from the
| affected city:
|
| > The company explained that the employee had drinks after work
| and later fell asleep on the street, but when he woke up he
| realized that he had lost the bag containing the USB.
|
| My premise was going to be that perhaps this isn't the company
| you'd trust with the residents' subsidies but clearly I
| misunderstand the cultural aspect to this story. The other
| thing I didn't get is that the employee who "lost" the bag
| filed a police report for theft. If you're passed-out-drunk,
| how would you even know it was a theft?
| amichal wrote:
| There is something like a 90% return rate on lost wallets in
| Japan. Failure to attempt to return a lost item of value is
| an actual crime... so if the bag was not sitting on the
| street next to him when he woke up and not returned by a kind
| soul it was by Japanese definition stolen
|
| Edit: An eye opening video on how well this works
| https://www3.nhk.or.jp/nhkworld/en/ondemand/video/9999897/
| Aeolun wrote:
| > If you're passed-out-drunk, how would you even know it was
| a theft?
|
| Fall asleep thinking you are carrying bag. Wake up when
| slightly less drunk. No find bag. Freak out. Rush to report
| bag as stolen.
|
| Later go back the all the bars in town (forgot where you
| went), and find the one where you left your bag behind.
| totetsu wrote:
| Yes. They cover this exact situation. If you have work data in
| your bag, don't go drinking, don't put your bag in the coin
| locker, go directly back to the office.
| duxup wrote:
| I had my personal information lost three times at one company
| when someone at HR decided to go out for drinks, left their
| laptop in their car and their laptop was stolen. THREE TIMES.
|
| When I asked why our personal information was stored on a laptop
| I was told that I was being "unhelpful".
|
| Thankfully not long after the company was acquired and they fired
| everyone who wasn't directly making products or customer facing
| or a direct manager of a customer facing or product development
| employee. It was a pretty stark layoff.
|
| I later ran into the new CEO who was super personable and we were
| chatting and I asked about the acquisition. "We wanted the
| products, we wanted the support team and engineers, but we knew
| we didn't want any of the rest, they were not smart people." I
| liked that guy.
| toyg wrote:
| _> someone at HR decided to go out for drinks, left their
| laptop in their car and their laptop was stolen. THREE TIMES._
|
| Call me cynical, but I'd say that sentence translates to
| "someone at HR wanted a new laptop".
___________________________________________________________________
(page generated 2022-06-24 23:00 UTC)