Live data from Hacker News

Capital One Says Breach Hit 100M Individuals in U.S

bloomberg.com

71–80 of 319 posts

Re: Capital One Says Breach Hit 100M Individuals in U.S

#71

> hacked into a cloud-computing company server, federal prosecutors in Seattle said > the cloud-computing company, on whose servers Capital One rented space, wasn’t identified in court papers. Does this feel like it was just an S3 bucket with permissions set incorrectly? I've come across sensitive documents in S3 buckets with a well crafted google search.

Misconfigured WAF - see my comment elsewhere here. Correction: according to the complaint, the defendant is alleged to have assumed an IAM role in the context of Capital One's account whose policy provided access to the S3 bucket in question. So it wasn't that the S3 bucket was public, but rather, that there was some vulnerability she took advantage of by which she obtained indirect credentials to it. (Complaint, pag…

I wonder what data was in the bucket?

Re: Capital One Says Breach Hit 100M Individuals in U.S

#72
I sincerely hope that this is not our government harassing someone because of their gender transition, or because they look weird, etc. The indictment appears to lay out what might appear at first sight to be an iron-clad case against Ms. Thompson, but we haven't heard from her defense yet, and prosecutors love to go after people who don't fit in. I feel that Judges should always consider leniency in these cases, remembering that the DSM-5 has listed gender dysphoria as a serious mental illness since 2013.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#73
post #69

Earlier quoted context omitted.

I would imagine complete credit card applications contain the type of information identity thieves would be willing to pay good money for.

By now everyone's identity data is already widely disseminated, no?

The old joke.. "DDon't worry, the NSA made a backup for you"

But now its more like "Don't worry The 5Eyes have made back for everyone"

Re: Capital One Says Breach Hit 100M Individuals in U.S

#75
post #66
post #61

Earlier quoted context omitted.

How's that a fail?

They should not be letting egress traffic through to a Tor node.

What sort of rule or policy would you put into play to detect that a connection was a TOR node?

Re: Capital One Says Breach Hit 100M Individuals in U.S

#76
post #66
post #61

Earlier quoted context omitted.

How's that a fail?

They should not be letting egress traffic through to a Tor node.

Commenting on you because I can't comment below:

Tor node IPs are published, so you can just block that list.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#77

Earlier quoted context omitted.

Misconfigured WAF - see my comment elsewhere here. Correction: according to the complaint, the defendant is alleged to have assumed an IAM role in the context of Capital One's account whose policy provided access to the S3 bucket in question. So it wasn't that the S3 bucket was public, but rather, that there was some vulnerability she took advantage of by which she obtained indirect credentials to it. (Complaint, pag…

I wonder what data was in the bucket?

> The largest category of data stolen was supplied by consumers and small businesses when they applied for credit cards from 2005 through early 2019, the bank said. It included personal identification data, including names, addresses, phone numbers and dates of birth, and financial data including self-reported income, credit scores and fragments of transaction history.

> About 140,000 Social Security numbers were accessed, as well as 80,000 bank account numbers from credit-card customers, the bank said.

I haven't yet read (all of) the complaint but I presume it goes into even more detail than the article did.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#78
post #43

I guess this is how we all finally get paid for our data. Just continually file for our $125 check as every company that exists is hacked over the next decade.

FYI, getting a $125 check from Equifax is contingent on most of the people that are eligible to get one not actually requesting it. It'll probably be less
Post reply on HN