Live data from Hacker News

Capital One Says Breach Hit 100M Individuals in U.S

bloomberg.com

81–90 of 319 posts

Re: Capital One Says Breach Hit 100M Individuals in U.S

#81
post #66

Earlier quoted context omitted.

They should not be letting egress traffic through to a Tor node.

Commenting on you because I can't comment below: Tor node IPs are published, so you can just block that list.

You can reply to deep-nested posts by clicking into their permalink.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#84
post #16

Earlier quoted context omitted.

Well, the main cloud Capital One uses is Amazon as far as I know. If you think about the attack vectors here, it was most definitely the virtual server that got attacked. If it was the cloud provider (Amazon), there are a lot of safeguards that these banks use to make sure that any data that touches the shared server persistent storage is encrypted. And when I say safeguards, I mean automation to make sure that this…

"there are a lot of safeguards that these banks use to make sure that any data that touches the shared server persistent storage is encrypted. And when I say safeguards, I mean automation to make sure that this sort of scenario shouldn't ever happen." ROTFLMAO....you have clearly never worked for a bank, no offense mate. Capital left this shit in plain text on an S3 bucket, I guarantee you

If you took ten seconds to look at the posted source note above, you would see Cloud Custodian has a policy to enforce bucket encryption.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#86

I downloaded the indictment (edit: complaint, not indictment) from PACER: https://www.dropbox.com/s/z7u5rxcdajuvw6t/19718675504.pdf?dl...

It's a wild ride. Who hacks in via Tor and then posts the data to a GitLab account under their own name?

A lot of crime would go unsolved if people just kept their mouths shut. There's a human tendency to need to talk about things you've done, I guess, especially stuff that will get you "street cred".

Re: Capital One Says Breach Hit 100M Individuals in U.S

#88
post #66

Earlier quoted context omitted.

They should not be letting egress traffic through to a Tor node.

What sort of rule or policy would you put into play to detect that a connection was a TOR node?

Tor node IPs are published, so you can just block that list. There's probably a way to detect them too, but I don't think an exit node can be secret.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#89

> hacked into a cloud-computing company server, federal prosecutors in Seattle said > the cloud-computing company, on whose servers Capital One rented space, wasn’t identified in court papers. Does this feel like it was just an S3 bucket with permissions set incorrectly? I've come across sensitive documents in S3 buckets with a well crafted google search.

Actually looks like she worked for Amazon on S3. So there might have been some insider knowledge. From the complaint below, and googling her name you can find her resume

I won't link it here, but here's a screenshot of a snippet: https://i.imgur.com/NezWVKw.png

Post reply on HN