Greetings, I discovered that spam messages are being sent from my account. It is necessary to find out from which device this happened to try to determine how the attackers got the password from my account. Can I get information about the facts of access to my profile?To which I received the answer:
Support Agent:As you can see, there was no concrete answer to my question, but the followers made friendly recommendations. Well, I had to write again:
Hello User.
We noticed signs of hacking in your profile. The tools with which the hacking was carried out are unknown to us.
')
As we can see, you have already changed the password from your Personal Account, and at the same time we recommend changing the password from email as well.
After logging in to your profile, check if your name, phone number and city are correctly specified in the Settings section (https: //www.service.ru/profile/settings).
How to protect your profile from hacking, you can read here: (https: //support.service.ru/articles / ...)
Good mood and successful transactions on the Service.
Thank you for the answer, and maybe ah-pi addresses or some logs can be seen? I wonder if this could be a zombie of one of my devices?And here I get the traditional rejection:
Support agentHow our state defines the term personal data you can read in the Federal Law, or in these posts: What does the Federal Law No. 152 On Personal Data give an ordinary person?
User, we do not disclose details so that this information cannot be used to the detriment of the service and users.
Hope for your understanding.
In many respectable services, the transfer of such information is permissible and is in the public access.Of course, no one gave it to me "right there" and the employee gives a fulfilled answer:
In addition, I ask for information about the attacker, so who turns out to use this information to the detriment?
You withhold the information that the user requests from you, his personal, because it is "my" account on your service. In this context, I am not a third party and I have every right to demand this information from you based on your own rules. Just like you require data from your users.
Thank you, I hope for understanding.
Support agentAll right, here I am already sitting in warm pants, in a warm chair.
Hello User.
This information is private. We can provide it only at the official request of the authorized state bodies.
How the Service processes and protects user data can be found in Section No. 4 of the terms of use of the Service and policies in the area of processing and security of data of users of the Service: (https: // support.service.ru/articles / ...) and (https: / /www.service.ru/safety/personal/company).
We also comply with the requirements of the federal law “On Personal Data” dated July 27, 2006. You can ask for a detailed explanation of the law to experts in the field of law. Service support service does not advise on legal issues.
We wish you a warm autumn!
Greetings, Agent Support.Here the personal assistant of the "raging" user comes into the business:
This information is closed to me only if I decide this way or I will be restricted access in accordance with the law.
Familiarize yourself with the rights of the subject of personal data.
Federal Law of July 27, 2006 No. 152 FZ. Article 14. The right of the subject of personal data to access his personal data.
- I have the right to request any information related to my personal data.
- You are violating my user rights.
- You collect technical information about my devices, analyze it and make money on it.
I, in turn, use your service, consider working for you. The benefits to me for the years of operation you have brought as little as possible in such services.
If you provide me the information in an uncomfortable or unorganized form for me, I will request a complete download of the information for analysis.
If you plan to refuse me again, provide proof.
If you are not involved in legal issues, refer to those who are engaged.
Thank you for the warm autumn.
Support agentA few hours later he gives the following:
Good day.
My name is Daniel, I am a claim handling specialist.
In your situation, I check the information in addition. According to the result of the check, I will definitely return to you with the answer.
Support agentAnd then I went to discover the laws and waste my time, and “spoil my eyes”:
Hello.
Thank you for waiting: it took time to familiarize yourself with the situation.
The security of your credentials has a high priority for us - all communications with the Service are carried out via secure communication channels.
At the same time, we also need user assistance - we always advise:
1) do not tell anyone your password (even to us);
2) a strong password includes letters, numbers, its length is at least 8 characters - so it will be difficult for outsiders to guess, I recommend changing the password every 2-3 months.
3) regularly check all devices from which you access the Internet for viruses;
4) do not follow suspicious links. If you still went to the site, where they require to enter your username and password, immediately close the tab.
For the protection of your rights, you can contact the regulatory authorities, for our part, we are ready to assist in resolving this issue. However, to provide such information, we need legal grounds. This can be a request from law enforcement / judicial officials, or from your lawyer.
We have a procedure when, upon official request (not only law enforcement / judicial authorities, but also your lawyer) can send it, we provide this or that information.
To obtain such information, they need to send to our address an official request on the letterhead of the organization stamped and signed by an authorized person, as well as contact information of the contractor, which can be contacted in case of additional questions, and the fax number of the organization (sending an answer to the request by email mail is not provided). If this is a letter from your representative, he should additionally provide a scanned copy of the lawyer's certificate.
A scanned copy of the request must be sent by e-mail compliance@service.ru, the original request - by mail of Russia to the legal department of OOO Service addressed to the Head of the department for working with requests Head S.Z. to the address: 123456, Moscow, Ulitsa St., 1
I believe that in the future you will not encounter such situations. If you need help with the Service, please contact us, we are always open to dialogue.
Thanks for the detailed answer.At the moment I am confidently following the path described by the hardworking comrade in this article: Mechanism of the exercise of their legal rights by the owners of personal data
I understand your interest in protecting clients, as well as I see a reluctance to distribute information that is private to ordinary users. I can assume that you are not interested in this, instead of protecting my rights, you usurp them. What could be the risk, is it a regular user or a well-known blogger, will he consider information in search of a violation of his rights, or is he just defending his interest?
I will tell you the reason why I am so interested in resolving this issue. In my entire history of using passwords (just believe that I am very careful about security), there has not yet been a single hacking or password leak (at least fixed). Your system does not have a notification about the entrance from a new device; there is no open log for the client, as it is done on some systems. Therefore, it is important for me to find out information about this incident, it is desirable that it be complete and unchanged (Part 5, Art. 13.11 of the Administrative Code of the RF).
To protect my rights, the law does not require contacting regulatory authorities. If you need legal grounds, here they are:
Federal Law of July 27, 2006 No. 152 FZ. Article 14. The right of the subject of personal data to access his personal data.
The personal data subject has the right to require the operator to clarify his personal data, as well as to take measures provided for by law to protect his rights.
Information is provided to the subject of personal data by the operator upon request. The request must contain the number of the main document certifying the identity of the subject of personal data: Passport Issued by TP № of the Department of the Federal Migration Service of Russia for the region; information confirming the participation of the subject of personal data in relations with the operator: the user number is, then, as you see, I use your website, and according to your rules, this means my agreement with the user agreement. After the conclusion of additional agreements, I will attach a digital signature, because this is enough to send you a request in digital form.
My rights are protected by law. If you break the law, then you should be responsible for violation of the law on personal data. I do not have to resort to the help of a lawyer, because I am not at all interested in your procedure. Leave the bureaucracy with you.
It is better for you to fulfill my request, since Article 5.39 of the Administrative Code of the RF has already been assigned to you.
Keep in mind that you should be careful about our correspondence. Time goes by, if you wait three weeks and there is no reaction, you will fall under the operator’s failure to provide the personal data with information about the processing of his personal data Part 4 of Art. 13.11 of the Administrative Code.
I hope for your faith that I will not have to face a similar situation this time.
I'm waiting for your decision. Thank.
ps I sympathize with you as an employee of the company, if you go about me it will not benefit your career, but the farther we go, the higher the rates. It’s just more interesting, right?
Source: https://habr.com/ru/post/429482/
All Articles