Live data from Hacker News

Capital One Says Breach Hit 100M Individuals in U.S

bloomberg.com

181–190 of 319 posts

Re: Capital One Says Breach Hit 100M Individuals in U.S

#181
post #22

Earlier quoted context omitted.

Who cares if it has your data in it or not. Just report it to authorities and the guy who runs haveibeenpwned. Plus what are you going to do with credit card applications anyway? Sell them to a marketing company with some phony story? Or the 'sell them on the darknet to fraudsters in Russia' angle? Unless you're already involved in some dirty business already this isn't very valuable.

I would imagine complete credit card applications contain the type of information identity thieves would be willing to pay good money for.

I think the point is: unless the hacker is already aware of how to sell PII of this nature and how to move "good money" then a hack like this is for naught.

Reading the mistakes made in the hack itself makes me wonder if black markets and money laundering are a skill they posses.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#182

Earlier quoted context omitted.

I took down the mailbox at my house and now use my business address for all my mail, because bulk junk mail doesn't get delivered to business addresses. Targeted credit offers do still get delivered, unfortunately. But the amount of junk mail in general is about 10% of what it was. Works well, though I do often get accused of being a Unibomber type when I tell people they can't send mail to my house address because I…

> I took down the mailbox at my house Serious question... is this legal?

Why would it be illegal to not have a mailbox?

It's your property. Do whatever you please.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#183
post #91

I don't trust in the U.S. justice system to handle every crime and person as it should but for us, context is important: This person's Twitter is 0xA3A97B6C, y'all can go there and get a better picture of the situation.

So much evidence of mental illness there (see also Facebook). I hope this person gets help, but given their claim to also be in the country illegally (Tuvalu), who knows. I was ready to think this person was being set up by someone who didn't like her, given how exposed she was to being identified, but the Twitter and FB posts strongly suggest a vulnerable person making poor decisions instead.

The Tuvalu thing was obviously a joke.

But yes, those tweets do show that this person is clearly experiencing a mental health crisis.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#185
post #67

Earlier quoted context omitted.

It's a wild ride. Who hacks in via Tor and then posts the data to a GitLab account under their own name?

Could be a frame job, remorse, freakout, or some kind of dissociative or other personality disorder.

Or simply the age old quest to become (in)famous.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#186
post #182

Earlier quoted context omitted.

> I took down the mailbox at my house Serious question... is this legal?

Why would it be illegal to not have a mailbox? It's your property. Do whatever you please.

Mailboxes live in this weird property-right limbo (that I don’t know really anything about) where the homeowner buys it but it is “property of” the US Postal Service. I found this[1] Supreme Court case that sort of touches on how the property rights work.

[1] https://supreme.justia.com/cases/federal/us/453/114/

Re: Capital One Says Breach Hit 100M Individuals in U.S

#187

Apparently she used "erratic" as a pseudonym. After reading through some of the complaint, it seems quite fitting.

Quite possibly self-aware of their own ups and downs.

But that can get you in trouble when you're playing with fire.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#189
post #69

Earlier quoted context omitted.

I would imagine complete credit card applications contain the type of information identity thieves would be willing to pay good money for.

By now everyone's identity data is already widely disseminated, no?

I operate under the assumption my name, address, email, social media profiles, social security number, place of birth, and mother's maiden name are all easily available in the wild. I've bought one of those online background checks before, at the very least I can be confident the info on that report is available to anyone.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#190

Earlier quoted context omitted.

Are there AWS experts who can do some sort of quick audit or "sanity check" of an environment's configurations? AWS almost makes it too easy for someone who only sort of knows what they're doing (like me) to get things up and running.

There are many different automated systems for checking for misconfigurations in your AWS organization. Capital One even developed a very popular one (Cloud Custodian). Like most automated configuration checkers or monitoring systems they rely on being configured by experts because at their default settings they are mainly a source of annoying alerts that end up auto-filed to email folders you never look in because t…

[deleted]
Post reply on HN