HomeSecurityPrivacy Watchdogs: Ashley Madison's security was 'unacceptable'

Privacy Watchdogs: Ashley Madison's security was 'unacceptable'

ashley-madison7-security

The online security of the notorious cheating website, Ashley Madison, had “unacceptable deficiencies.”

This fact should have been obvious to every user, who had a name, e-mail and banking details that leaked onto the internet in mid-2015. This was also concluded by the Privacy Commissioner of Australia and Canada from a study that was carried out, the results of which were published on Wednesday.

The problems of the site, which belongs to the company Avid Life Media (ALM), started in July 2015, when a hacking group called “The Impact Team” threatened to leak users' personal data unless the company shuts down two of its dating sites, Established Men and Ashley Madison. Shortly after, up to 36 million Ashley Madison user accounts were leaked.

The privacy protection commissioners of both countries launched their joint investigation in August 2015, focusing on the security guarantees of ALM, which has now been renamed to Ruby Corp. Particular concern was raised by four questionable practices: the retention of personal data after a user had deleted their account, the company's policy of charging for what it called «full deletion»», the failure to verify email addresses, and the lack of transparency regarding how it handled user data.

The report found that ALM failed to implement a «clear risk management process» and had failed to properly train staff regarding privacy obligations.

«The company continues to make significant, ongoing investments in everything related to privacy and security», said the CEO of Ruby Corp, Rob Segal. Now it offers free account deletion for users, among other changes.

Let's hope that the updated security releases are sufficient, because Ashley Madison is now trying to win back its customers. According to Mark Gregory, a private security expert and lecturer at RMIT University in Melbourne, the report highlights the need for the implementation of laws regarding data breaches in Australia. In his view, these laws will force companies to improve their security systems.

Australian companies have a history regarding online leakage of customers' personal data. In 2015, Kmart and David Jones suffered data breaches, among others.

In 2015, the government released a change to the data breach notification bill, but its progress through parliament has stalled. Gregory said that the government is betraying consumers by not passing the legislation. «The lack of mandatory legislation for data breaches, the lack of penalties for non‑compliance with reasonable privacy protection requirements, will continue to lead to such problems.»

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS