Live data from Hacker News

Capital One Says Breach Hit 100M Individuals in U.S

bloomberg.com

131–140 of 319 posts

Re: Capital One Says Breach Hit 100M Individuals in U.S

#131
post #102

I sincerely hope that this is not our government harassing someone because of their gender transition, or because they look weird, etc. The indictment appears to lay out what might appear at first sight to be an iron-clad case against Ms. Thompson, but we haven't heard from her defense yet, and prosecutors love to go after people who don't fit in. I feel that Judges should always consider leniency in these cases, rem…

Uh, I don't see anything in the article that indicates she is transgender.

See the Twitter account mentioned above. Keep scrolling back to around July 20th.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#132
> She is charged with a single count of computer fraud and faces a maximum penalty of five years in prison and a $250,000 fine. Her lawyer declined to comment.

We need to start putting the hammer down on these people; maximum five years, meaning she/he will probably do one year. The US needs to start making examples and these people and increase penalties.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#134

Earlier quoted context omitted.

Actually looks like she worked for Amazon on S3. So there might have been some insider knowledge. From the complaint below, and googling her name you can find her resume I won't link it here, but here's a screenshot of a snippet: https://i.imgur.com/NezWVKw.png

Looks like she only worked there until 2016? Or is that just a resume from 3 years ago?

> Looks like she only worked there until 2016? Or is that just a resume from 3 years ago?

The last commit in the Git repository where her resume is located shows this:

    commit 44e40140ab1ccdd47d8b56a8a78fc532d5b3386d
    (HEAD -> master, origin/master, origin/HEAD)
    Author: Paige Thompson 
    Date:   Thu Jan 10 14:38:02 2019 -0800
    
        update linkedin address
    
    diff --git a/cv.pdf b/cv.pdf
    index bf26140..add1ea9 100644
    Binary files a/cv.pdf and b/cv.pdf differ
If we assume this is the only repository she has, then the resume seems to be up to date.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#136

Earlier quoted context omitted.

If you took ten seconds to look at the posted source note above, you would see Cloud Custodian has a policy to enforce bucket encryption.

Bucket encryption doesn't protect against anything except someone getting access to the hard drives underlying S3 and somehow recovering data. If you've somehow left access to a bucket open the odds are that you also have it configured to let anyone with access to the bucket decrypt the files. AWS calls this server side encryption, where S3 automatically encrypts and decrypts files for you. You can also do client sid…

I am well aware how S3 works, I just mean you can use custodian to enforce SSE on the bucket as well as KMS based encryption, so the original commenter is just being a troll was the point I was getting at.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#137
post #62
post #24

Dear "Seattle Woman": while you're in there, please dump Capital One's junk mail database, and set their address label printer on fire. Sincerely, another Seattle resident with a mailbox.

https://www.optoutprescreen.com/ should handle most of that. Yes, its legit [0]. [0] https://www.consumer.ftc.gov/articles/0148-prescreened-credi...

Sorry not going to hand my SSN over to some random website to opt out from junk mail.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#140

> She is charged with a single count of computer fraud and faces a maximum penalty of five years in prison and a $250,000 fine. Her lawyer declined to comment. We need to start putting the hammer down on these people; maximum five years, meaning she/he will probably do one year. The US needs to start making examples and these people and increase penalties.

They will likely come up with more as the investigation progresses. Capital One only contacted the FBI like 10 days ago. This was enough to pick her up on and get things rolling.
Post reply on HN