Live data from Hacker News

Show HN: Breach Insider – Detect a data breach using realistic pseudo-users

breachinsider.com

1–10 of 45 posts

Re: Show HN: Breach Insider – Detect a data breach using realistic pseudo-users

#3
post #2

Well, that is actually a clever service.

Clever for sure. But I wonder how they can identify the leaked account even if they actively scan web / deep web. I mean it's not because Carlos Sanchez is for sale somewhere that it's my "insider".

Re: Show HN: Breach Insider – Detect a data breach using realistic pseudo-users

#5
post #2

Well, that is actually a clever service.

Clever for sure. But I wonder how they can identify the leaked account even if they actively scan web / deep web. I mean it's not because Carlos Sanchez is for sale somewhere that it's my "insider".

Creator here – There are a few ways we can detect a breach/leak using our Insiders.

1. The unique email address assigned to the Insider is contacted. We gather forensic evidence of the email along with any attachments. Useful to identify specific attacks against your users too.

2. An optional real mobile number assigned to your Insider is contacted. Again, we store all of the details, including the original SMS details or even call recordings.

3. Your Insider shows up on the Internet or dark web somewhere - we check a number of common sources for dumps, such as Pastebin for any references to the Insider. We currently keep a copy of the contents of the paste, as the original details could be removed at any time. However, we are working on better captures (full page screenshots, entire copy of the DOM etc.)

We are working a few more detection methods too, which we shall reveal soon...

Re: Show HN: Breach Insider – Detect a data breach using realistic pseudo-users

#6
post #2

Well, that is actually a clever service.

Clever for sure. But I wonder how they can identify the leaked account even if they actively scan web / deep web. I mean it's not because Carlos Sanchez is for sale somewhere that it's my "insider".

The match would be if there's a Carlos Sanchez combined with a specific email or phone number.

Re: Show HN: Breach Insider – Detect a data breach using realistic pseudo-users

#7

Earlier quoted context omitted.

Clever for sure. But I wonder how they can identify the leaked account even if they actively scan web / deep web. I mean it's not because Carlos Sanchez is for sale somewhere that it's my "insider".

Creator here – There are a few ways we can detect a breach/leak using our Insiders. 1. The unique email address assigned to the Insider is contacted. We gather forensic evidence of the email along with any attachments. Useful to identify specific attacks against your users too. 2. An optional real mobile number assigned to your Insider is contacted. Again, we store all of the details, including the original SMS detai…

It sounds great. Thank you for the explanation.

Re: Show HN: Breach Insider – Detect a data breach using realistic pseudo-users

#8

Earlier quoted context omitted.

Clever for sure. But I wonder how they can identify the leaked account even if they actively scan web / deep web. I mean it's not because Carlos Sanchez is for sale somewhere that it's my "insider".

The match would be if there's a Carlos Sanchez combined with a specific email or phone number.

I see. Thanks.

Re: Show HN: Breach Insider – Detect a data breach using realistic pseudo-users

#10
There's value here in detection of a breach that's already been monetized, but this isn't in the kill chain; it's long-after, so it appears reactive-only.

Why should a non-massive company implement this rather than boosting and refining centralized logging and monitoring which can, if done right, provide far more immediate (even real time) notification of a breach? Your Wells Fargos of the world might do it because they can spare the change, and in your position I'd target the whales for initial revenue, certainly, but why should any mid-sized SaaS firm do it?

Not asking cynically. I want you to sell me on it.

Post reply on HN