Live data from Hacker News

Gigabytes of user data from hack of Patreon donations site dumped online

arstechnica.com

91–100 of 151 posts

Re: Gigabytes of user data from hack of Patreon donations site dumped online

#91

Earlier quoted context omitted.

How do you distinguish someone who was lax with their security from someone who actually takes it seriously and still got hacked?

You can't :) There is a huge Market for Lemons ( https://en.wikipedia.org/wiki/The_Market_for_Lemons ) style scenario in IT systems with relation to security. Everyone will say "we take security seriously", but there's no way for ordinary consumers (or indeed most companies) to determine what the company meant by their statement, and to evaluate the relative security of the systems of two companies. This could actual…

Maybe the answer is some sort of audit and certifiaction

Re: Gigabytes of user data from hack of Patreon donations site dumped online

#93
post #82

That's pretty devastating to anybody who gave up their data to support things they enjoy. I would really like to see services getting hit with massive fines so they actually "take security very seriously" before they get owned. It's far too late to care about it now, there's a lot of compromising data in that leak.

I'm not sure how compromising the data is... if you're referring to the display of what people support, that's public information. For instance here's my user profile. https://www.patreon.com/user?u=632496&pat=1 you can find it with one targeted google search

You can make that page private in the settings, which I have.

Re: Gigabytes of user data from hack of Patreon donations site dumped online

#94
post #90

All the data breaches lately have demonstrated the need for some kind of professional engineering license to ensure compliance with best practices. Even if your app is meaningless in and of itself, a data breach can reveal Personally Identifying Information or credentials for other sites and accounts. There's too much of a "code cowboy" mentality out there right now. As a community we've become very feature-driven an…

If we are going to put collective political effort into stemming the tide of data leaks and hacks, I would much rather put it into finding and punishing the people who steal the data than the people who are trying to create a productive service and get hacked through less than perfect security.

Re: Gigabytes of user data from hack of Patreon donations site dumped online

#95

Apparently they were compromised via a publicly exposed Werkzeug debugger: http://labs.detectify.com/post/130332638391/how-patreon-got-...

There's almost no hack needed here, as the article says, they basically opened up remote code execution to anyone. That's shockingly bad.

Re: Gigabytes of user data from hack of Patreon donations site dumped online

#96
I was somewhat surprised to find my email on the list, since I don't have a Patreon account.

It seems that when Subbable was acquired by Patreon, they got the user information, and possibly password database, too. I can't log in to Patreon with my Subbable password, but my email address is definitely in the breach.

Makes me glad I use a password manager.

It's also a sobering reminder of the permanence of user data. You have to trust the competence of not only the service you use now, but any company that owns that service down the road. (Not that Subbable was necessarily more secure than Patreon.)

Re: Gigabytes of user data from hack of Patreon donations site dumped online

#97

Apparently they were compromised via a publicly exposed Werkzeug debugger: http://labs.detectify.com/post/130332638391/how-patreon-got-...

There's almost no hack needed here, as the article says, they basically opened up remote code execution to anyone. That's shockingly bad.

Makes me wonder what can be done to prevent this from happening without making it a terrible experience from a user point of view. Maybe the solution would be to store a password for the debugger and ask for it on first usage.

Re: Gigabytes of user data from hack of Patreon donations site dumped online

#98
post #80

Earlier quoted context omitted.

I don't think they're particularly informed if they aren't aware of password managers.

I'm aware, I just can't be bothered. Every time I create an account I ask myself "do I care if this gets compromised?". If the answer is no, then it gets a standard password.

As long as you understand that when that site gets compromised, all other sites where you use your standard password get compromised for you as well. Collectively, all those sites getting compromised for you may be enough of a reason to consider password managers.

Re: Gigabytes of user data from hack of Patreon donations site dumped online

#99
post #94
post #90

All the data breaches lately have demonstrated the need for some kind of professional engineering license to ensure compliance with best practices. Even if your app is meaningless in and of itself, a data breach can reveal Personally Identifying Information or credentials for other sites and accounts. There's too much of a "code cowboy" mentality out there right now. As a community we've become very feature-driven an…

If we are going to put collective political effort into stemming the tide of data leaks and hacks, I would much rather put it into finding and punishing the people who steal the data than the people who are trying to create a productive service and get hacked through less than perfect security.

That's pushing on a string, man. You will never be able to effectively track down and punish every bored Russian teenager.

As Schneier puts it - security is a process. The process doesn't have to be perfect, but there needs to be one. If your process is drastically substandard, someone need to be liable for that. The need for a standards group and a single point of liability follow logically from that, just as it does with other engineered systems. Under HIPAA an individual must be designated a "security officer", and that role should extend to other systems that store Personally Identifying Information as well.

I think the real point of disagreement with many people is about the significance of a data breach. In my opinion (and the standards of the EU) anything that leaks Personally Identifying Information is significant. It doesn't matter if it's leaking from an app that sends fart noises to your friends, only that it can be tied to you or your other accounts. If you really need to be storing PII then there needs to be a requirement to do it securely (meaning in accordance with secure best-practices). Otherwise, again, nobody does it until it's too late.

A good read: https://www.schneier.com/essays/archives/2000/04/the_process...

Re: Gigabytes of user data from hack of Patreon donations site dumped online

#100
Wow, I avoided Patreon because I didn't trust that all the music being hosted was following proper licensing and compensation rules (e.g. looked like >50% of songs were covers), so this is kind of a double shock to me about how they ran their operation.

Believe it or not, this re-inforces my commitment to SoundCloud, which isn't monetized (yet), thereby keeping listeners' financial information off the table for the present.

Post reply on HN