|
|
|
|
|
by ctippett
542 days ago
|
|
I once worked for a firm that had access to credit card transaction data and came across almost this exact scenario. Kindergarten transactions one day, escort payments on another. It was — and still is — creepy. An average Joe like me shouldn't be able to pry into someone's private life like that. |
|
Instead they should think from the perspective of an evil person. E.g. "how can I proactively use whatever data that I can get to hurt someone."
For example, at a previous job I went to my managers and pointed out that every developer working on our system had access to our user's names and their involvement with racial justice programs our client was running. By guessing someone's ethnicity from their name, a bad actor could target minorities involved in racial justice. The response I got was not to fix the security issue; instead it was horror that I would ever conceive of such a scheme.