Live data from Hacker News

Capital One Says Breach Hit 100M Individuals in U.S

bloomberg.com

141–150 of 319 posts

Re: Capital One Says Breach Hit 100M Individuals in U.S

#141

> She is charged with a single count of computer fraud and faces a maximum penalty of five years in prison and a $250,000 fine. Her lawyer declined to comment. We need to start putting the hammer down on these people; maximum five years, meaning she/he will probably do one year. The US needs to start making examples and these people and increase penalties.

I'd rather see the hammer applied to the companies that allow the data to be stolen.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#143

Well, on the bright side it's a woman in IT. If only she were being recognized for something good, not bad.

Looks like transexual to me. https://heavy.com/news/2019/07/paige-adele-thompson/

Yes, if you google the phone number from the resume, this profile will come up in the search results. The person in the photo seems to match: https://www.tsdating.com/members/murkurgurl

Re: Capital One Says Breach Hit 100M Individuals in U.S

#144

Earlier quoted context omitted.

Actually looks like she worked for Amazon on S3. So there might have been some insider knowledge. From the complaint below, and googling her name you can find her resume I won't link it here, but here's a screenshot of a snippet: https://i.imgur.com/NezWVKw.png

Are Git and SVN really considered IDEs?

Not to anyone even remotely in the industry.

I think the minimum to be considered an IDE, you need to be able to edit, possibly compile depending on the language, and run/debug from within the same tool. By last loose definition, I've joked my most used "IDE" would be bash. I can edit with vim, compile/link with make/gcc/ld, and debug using gdb or run my bins directly.

I mean it's an integrated development environment in that I can access all of my tools from one centralized location, the bash shell, but certainly not integrated in the sense that I have a GUI that hides the nuances of commands of various tools behind menus and friendlier non-command-line names and making it appear that the half dozen or so tools are a single entity.

I also use Visual Studio for Windows development and I've been switching between VS Code and PyCharm for Python development.

But are git and svn an IDE? No. They are both merely source control management systems.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#145

I wonder why data security professionals don't practice compartmentalization. 100 million accounts should not be accessible from one account. It should be like watertight compartments in a ship. Breaching one doesn't sink the ship.

I worked at a tech company, three times my personal data was put at risk because someone at HR left their laptop in their car during a night on the town.

I asked if my personal data was stored in files downloaded to the laptop, they said yes.

When I asked why my data needed to be downloaded to the laptop and not limited to just online access they stopped responding.

This of course was the same company who mailed me my co-workers salary in spreadsheet form, twice because my name was similar to another manager.

Why that was necessary was beyond me too.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#146
post #58

How is this person's information wiped off the Internet? I literally cannot find anything related to her. Is it just me?

her twitter account's still active. https://twitter.com/0xA3A97B6C. Also, someone posted other accounts, but that's dead for some reason. https://news.ycombinator.com/item?id=20561258

Re: Capital One Says Breach Hit 100M Individuals in U.S

#147
post #99

Earlier quoted context omitted.

Sounds less like intrusion and more like accidental exposure by Capital One.

It sounds like an internal threat to me (she was an employee at Amazon).

Not at the time of the hack. Insider access was not used.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#148
post #102

Earlier quoted context omitted.

Uh, I don't see anything in the article that indicates she is transgender.

See the Twitter account mentioned above. Keep scrolling back to around July 20th.

sdinsn is commenting on the (startling) omission of the journalist who wrote the particular article here and not on my post. The information is already reported widely elsewhere.

In fact, I'm very surprised that my post highlighting the bullying actions of prosecutors against transgender people was flagged. This is a very real issue, as anyone with any experience of the criminal justice system is aware.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#149

I downloaded the indictment (edit: complaint, not indictment) from PACER: https://www.dropbox.com/s/z7u5rxcdajuvw6t/19718675504.pdf?dl...

Good lord. -Paige left code used in the "attack" on her GitHub. -Paige left text files with unencrypted data there, too. -Paige openly posted about it in an open (!!!) Slack channel and publicly named her VPN service of choice, which of course, matched access logs AND GitHub server logs. (Also tor, which the FBI agent was able to confirm and add yet another data point) -Paige said "I have a leak proof IPredator route…

[deleted]

Re: Capital One Says Breach Hit 100M Individuals in U.S

#150
post #43

I guess this is how we all finally get paid for our data. Just continually file for our $125 check as every company that exists is hacked over the next decade.

Our society should give up expecting these things to stay private, secure, secret etc and figure out how to do financial things another way.
Post reply on HN