Ticketmaster: We're not liable for credit card badness because the hack straddled GDPR day
- Reference: 1606305546
- News link: https://www.theregister.co.uk/2020/11/25/ticketmaster_gdpr_fine_chicanery/
- Source link:
The firm was [1]fined earlier this month after UK data regulator, the Information Commissioner's Office, ruled it had broken data protection laws by failing to properly secure its network.
Yet Ticketmaster is insisting that it is not liable to a customer for the compromise of its network, attempting to exploit an apparent legal loophole to squeeze out of Reg reader Richard's fight for compensation.
When it fined Ticketmaster, the ICO said: "The total duration of the personal data breach was between February 2018 and 23 June 2018… however, the dates under consideration for the purposes of this penalty notice were from 25 May 2018 to 23 June 2018."
Those dates are significant: while the ICO made clear findings that Ticketmaster's infrastructure was compromised in February, its fine only covered the period from May, when higher penalties under the EU's General Data Protection Regulation (GDPR) were available – and now Ticketmaster seemingly wants to use that to avoid admitting liability for its systems becoming compromised in the first place.
Our reader Richard travelled to the US in February 2018. Both his debit and credit cards had been cancelled by his bank, which had spotted an attempt to fraudulently use them on Ticketmaster. This was long before the ticket resale site got its act together and removed a compromised Javascript-powered chatbot from its payments page. Having struggled to find alternate sources of money while Stateside, Richard demanded compensation from Ticketmaster.
In a letter seen by The Register , Ticketmaster's lawyers told Richard:
We are writing to inform you that the ICO has finished its investigation, and published its findings in November 2020. The ICO made no findings about any contraventions by our client of its duties over the period during which you transacted with our client using your account associated with [email address removed]. Accordingly, our client's concluded position is that it has no liability to you arising from the Data Security Incident and, for that reason, it considers your inquiry closed and will not be providing compensation.
This came as a surprise to Richard, who showed us their letter. He wasn't best pleased and said he had contacted the ICO.
We did the same thing. An ICO spokesperson told The Register : "The £1.25m fine issued to Ticketmaster was in relation to infringements of the GDPR which only came into force on 25 May 2018. Whilst the fine therefore could only relate to infringements from 25 May 2018, prior to that date Ticketmaster would still have had to comply with the Data Protection Act 1998."
Ticketmaster has been asked to comment on Richard's claim.
Spoiling the ship for a ha'porth of tar
Ticketmaster could have plugged the breach for approximately 0.03 per cent of the eventual fine sum, according to crowdsourced infosec firm HackerOne. Security engineer Laurie Mercer told us: "The cost of the actual vulnerability itself, the bounty is often a lot lower than the monetary penalty that the ICO put out there."
He added: "Critical vulnerabilities like SQL injection might attract a bounty of €3,000 to €4,000. And of course the impact if that was exploited by a malicious actor, it would have led to something else going wrong."
While Ticketmaster was pwned by Magecart thanks to chatbot vendor Inbenta's Javascript chatbot being compromised, the principle remains similar. Don't allow unauthenticated JS on payment pages, and especially do not use Javascript from third parties whom you aren't monitoring. (Inbenta maintains that it knew the risks and would have told Ticketmaster to remove the chatbot from payment pages had it known.)
Even if Ticketmaster decided not to set up a full bug bounty scheme, a responsible disclosure email inbox checked once a day by an IT bod would be better than nothing, Mercer added. ®
Get our [2]Tech Resources
[1] https://www.theregister.com/2020/11/13/ticketmaster_fined_1_25m_magecart_breach/
[2] https://whitepapers.theregister.com/
Re: Ticket master
Upvoted. I still cannot work out exactly why we need companies like this - if an artist or group want to sell tickets, do it through whatever venue they are using. Ticketmaster don't really seem to do anything useful except vastly increase the cost of already over-priced tickets.
Re: Ticket master
I still cannot work out exactly why we need companies like this
Because nature always maintains an on average zero sum balance. The extremes may swing very large, good guys, bad guys, and then it averages to no guys again.
See, all quite normal.
Re: Ticket master
Agree,
I went to see Alice cooper last year in Leeds and it is impossible to get tickets direct from Leeds. You have to go through an agency! Total Madness.
Re: Ticket master
Completely agree however bands/artists are signed to labels and labels have deals with the major ticket selling websites. Also venues will sign deals with ticket sellers for exclusivity. Then you have radio/tv only promoting the artists labels want them to. All these people take a cut and there is no way they will allow people to move easily outside these constraints. That's why music is so shit these days (and no it's not because I'm older there are a few that break through every now and again but they are very far and few between these days)
Re: Ticket master
Your description is great, the word Music, can be replaced with Politicians, Medical treatments, and a slew of products. Many large industries around these things only cater to business partners that promote each others skimming, and blocking other 'products" getting to people to keep the markets cornered. To benefit a few people and not society. But,,, most companies are in business only to make money, not help people. It's how we can afford lunch,,,
Re: Ticket master
Ticketmaster exists for the same reason Amazon & ebay do. People's own web stores, shipping, and customer service are usually totally crap.
I'm not saying Ticketmaster/Amazon/ebay aren't totally crap, but they manage to get the job done on average, so people use them.
Re: Ticket master
I still cannot work out exactly why we need companies like this
Please don't shoot the messenger, but economies of scale. Ticketmaster et al scale and facilitate the sale of tickets in a way no venue or band could possibly come close to. From an events perspective the savings (profits) are massive when they outsource the sale to such specialists.
There are some artists and events fighting back, hopefully more will recognise the excess being creamed and tighten the conditions on sales.
Re: Ticket master
+ PR people, insurers and bankers.
That email may refer to events prior to their getting caught out, but the tone and content make it perfectly clear what they currently think of their customers.
3rd party Javascript
Blocking that is what noscript is good for. Has the beneficial side effect of blocking facebook, etc.
Unfortunately: some web sites just do not work when I block 3rd party JS - so I usually just go elsewhere. I'll allow JS from a payment processor that I recognise, but rarely much else. When will web developers recognise that they are losing their customers business, or are people like me rare enough for them to not worry ?
Re: 3rd party Javascript
You are very much the minority, so they don't care.
Re: 3rd party Javascript
I'm on the same boat.
If the website requires third party JS to make business, then bye!
Re: 3rd party Javascript
#MeToo
Too much JS used for things that it should not be used for.
Way too many pages are just blank if JS disabled - fucktards! I piss offstaright away when taht happens: Basic content sghould always render irrespective of JS - use JS for a few bells % whistles if you must, but as much as possible core functionality should not rely on JS (not always possible e.g. depending on implementation may need JS for purchasing)
"prior to that date Ticketmaster would still have had to comply with the Data Protection Act 1998".
So what were the penalties available under DPA 1998? Perhaps that should be the direction of travel now, with the ICO support or is there a date limitation?.
The ICO can't prosecute for one offence twice. So they've chosen to prosecute under the newer legislation which allows for much, much higher fines. This is a "good thing" (tm).
The reader's compensation issue is not affected by this: Ticketmaster are just using red-herring / bogosity tactics to try and put him off. What is clear is: Ticketmaster committed an offence and as a result the reader was subject to cost and inconvenience that he wants compensation for. It's irrelevant that the conviction for the offence came much later after the cost and inconvenience was incurred.
This is not unusual in law: think of cases like industrial diseases where the disease diagnosis comes years after the events, and the relevant industry and safety legislation could have changed two or three times.
Small Claims Court
I'd take them to the small claims court.
Chances are they won't even turn up to contest it. It's a small cost with no risk other than you don't get said compensation.
I've had recourse to use them once and it was a fairly streamlined, easy, process.
Re: Small Claims Court
Indeed, Their lawyers can take any line they like, a magistrate may well conclude that the ICO fine was for breach of GDPR rules only, any 3rd party claims are separate cases to answer.
Re: Small Claims Court
Streamlined small claims procedures, yes. But results depends on the company involved. I used the process against a well known big (well it was big at the time) travel company. After 2 years of dragging their feet, they then tried to object to the interest charge (8%) that the court was allowed to add over the time taken to settle. After that they still would not pay up, so I paid the extra fee for the bailiffs to be sent in. Net result was they ended up paying out over twice as much as I was originally claiming. Adds a new dimension to any claim to be "customer focused".
Re: Small Claims Court
" I paid the extra fee for the bailiffs to be sent in. Net result was they ended up paying out over twice as much as I was originally claiming. "
Yes, but if only one in ten claims take the effort to pass to the Bailiffs then overall the company wins. We need more claim and shame, and more "The Sheriffs are Coming" and "Don't Pay We'll Take It Away"
Re: Small Claims Court
And add in a complaint under the Consumer Protection from Unfair Trading 2008 (specifically, misleading statements intended to impact upon a customer's behaviour)..?
Re: Small Claims Court
I second this. Small Claims Court is fantastic. And if that doesn't work, yes, sending in the bailiffs tends to focus their mind beautifully... as RBS once found out when bailiffs walked into a local branch and started confiscating stuff.
Read *that* story here: [1]https://www.standard.co.uk/news/customer-sends-bailiffs-in-to-seize-banks-computers-7197321.html
[1] https://www.standard.co.uk/news/customer-sends-bailiffs-in-to-seize-banks-computers-7197321.html
Re: Small Claims Court
That's reminded me of when I went into RBS to pay in a cheque in 2009 and got asked if I wanted to have a word with someone about managing my finances.
The response of "You've just lost over £20Bn! Why should I listen to you?" didn't go down too well.
Doesn't matter a fetid dingo's kidneys
" Ticketmaster seemingly wants to use that to avoid admitting liability for its systems becoming compromised in the first place "
The fact that the breach persisted for a month after the GDPR had come into force is the deciding factor. How and when it came about is entirely secondary.
Re: Doesn't matter a fetid dingo's kidneys
Have an upvote just for the fetid dingo's kidneys
Just try
reporting fraud to any financial services organisation. Very few actually have a link on their web site to report fraud. Most want your account number (so if the fraud is that an account has been fraudulently set up in your name you can be a bit stuck). The 'Contact us' link usually has sections for what product you already have or want, and not all of them have a section marked 'other'. If you telephone them you have to wait for all of the menu options to expire before you actually talk to a human being, if you can get that far without giving them an account number or applying for one of their 'products'.
The next time you do internet banking or anything where fraud could be involved, just have a quick look for the 'Report suspected fraud' link on the front page. Oh and most of the phone lines are not available at the weekend, so if you only find out on Saturday morning that someone has stolen £36000 from your pension fund and £40000 from your building society account, you have to wait until the following Monday morning to tell them.
and R-E-L-A-X
Deep breath
I shall remain C-A-L-M
CC cancelled
Couldn't he call his CC company and have them re-activate it and just left the clearly fraudulent Ticketmaster charge blocked? Sounds like "his" particular issue is with the CC company. (I'm reading this story as 2 parts, the problem he had, and the overall Ticketmaster response)
Re: CC cancelled
No as one of my cards was suspended via this and I was out shopping. I could at least purchase what I needed. I rang the bank to ask why my recent card was not working and they told me that they had stopped it and a new card was on its way. I said that I was not aware blah blah blah and could they reactivate ? They said that once it is deactivated it is dead and no way to reactivate. New card *has* to be issued
Just checked wtih my misses who works for a bank and she concurs
Re: CC cancelled
I assume the Credit Card companies still issue blacklists of cards to other organisations to stop small value fraud. Back in the day online transactions over a certain value made an "online" authorisation, those under the value only checked a local "cancelled" list. Technology has moved on, but I'm betting there is still a place for the blacklist and once your card is on it, it isn't coming off.
Ticket master
Up there with loan sharks, advertising execs, patent trolls and lawyers