Live data from Hacker News

Capital One Says Breach Hit 100M Individuals in U.S

bloomberg.com

61–70 of 319 posts

Re: Capital One Says Breach Hit 100M Individuals in U.S

#62
post #24

Dear "Seattle Woman": while you're in there, please dump Capital One's junk mail database, and set their address label printer on fire. Sincerely, another Seattle resident with a mailbox.

https://www.optoutprescreen.com/ should handle most of that. Yes, its legit [0].

[0] https://www.consumer.ftc.gov/articles/0148-prescreened-credi...

Re: Capital One Says Breach Hit 100M Individuals in U.S

#63
post #61

"According to Capital One, its logs show a number of connections or attempted connections to Capital One’s server from TOR exit nodes" Now there's a fail.

How's that a fail?

You probably want your corp firewall to block/deflect connections from TOR exit node IPs.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#64

I downloaded the indictment (edit: complaint, not indictment) from PACER: https://www.dropbox.com/s/z7u5rxcdajuvw6t/19718675504.pdf?dl...

Intersting. She ran three commands - the first downloaded IAM credentials and the second then listed buckets using those credentials.

I'm curious about what the first command could have been

Also this all unfurled after a report to their security line from someone monitoring gists - that public feed as well as text dump sites have always been a good source of new vulnerabilities

Re: Capital One Says Breach Hit 100M Individuals in U.S

#65
"I sincerely apologize for the understandable worry this incident must be causing those affected." - CEO

He worded it carefully. He's not apologizing for the actual and potential harm of the breach so as to not take responsibility for it. Not a real, sincere, apology, but just a legally defensive move.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#66
post #61

"According to Capital One, its logs show a number of connections or attempted connections to Capital One’s server from TOR exit nodes" Now there's a fail.

How's that a fail?

They should not be letting egress traffic through to a Tor node.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#67

I downloaded the indictment (edit: complaint, not indictment) from PACER: https://www.dropbox.com/s/z7u5rxcdajuvw6t/19718675504.pdf?dl...

It's a wild ride. Who hacks in via Tor and then posts the data to a GitLab account under their own name?

Could be a frame job, remorse, freakout, or some kind of dissociative or other personality disorder.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#68
post #35

Generally it's not a good idea to sabotage your employer's clients, but I wonder how many engineers across the Big 3 US cloud providers have the know-how to exploit holes in how Forture 500 companies use their platforms.

This is a legitimate risk.

At a minimum, AWS Support has near complete read access to AWS accounts in connection with support cases.

It would be interesting to hear from an AWS employee how access to customer information is controlled.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#69
post #22

Earlier quoted context omitted.

Who cares if it has your data in it or not. Just report it to authorities and the guy who runs haveibeenpwned. Plus what are you going to do with credit card applications anyway? Sell them to a marketing company with some phony story? Or the 'sell them on the darknet to fraudsters in Russia' angle? Unless you're already involved in some dirty business already this isn't very valuable.

I would imagine complete credit card applications contain the type of information identity thieves would be willing to pay good money for.

By now everyone's identity data is already widely disseminated, no?

Re: Capital One Says Breach Hit 100M Individuals in U.S

#70

> hacked into a cloud-computing company server, federal prosecutors in Seattle said > the cloud-computing company, on whose servers Capital One rented space, wasn’t identified in court papers. Does this feel like it was just an S3 bucket with permissions set incorrectly? I've come across sensitive documents in S3 buckets with a well crafted google search.

Per the complaint, it doesn't sound like the bucket was exposed to the world. Rather, security credentials were "obtained": > Capital One determined that the first command, when executed, obtained security credentials for an account named XXXX-WAF-Role, that in turn, enabled access to certain of Capital One's folders at the Cloud Computing Company. Unsure how one would obtain credentials for an IAM Role, but the abov…

I recall a newbie dev at our company some years back accidentally posted creds in code to github. I have talked about this here before - but - we had paid for 200 repos.. problem was he made a new repo, which became 201 - which since we had only paid for 200, github auto makes the next one public. Bots slurp these and hunt...

They used those creds to launch like 1700 gpu machines across the globe for a bitcoin mining network...

The culprit was from germany...

We got it cleared and AWS forgave all the charges.

Post reply on HN