Live data from Hacker News

Capital One Says Breach Hit 100M Individuals in U.S

bloomberg.com

201–210 of 319 posts

Re: Capital One Says Breach Hit 100M Individuals in U.S

#201

Earlier quoted context omitted.

Yeah, there's only $31M allocated for those payouts :/

So less than 5% of the settlement goes to people affected? Yes, that seems reasonable...

Right? Also just FYI I pulled that number from

https://www.theverge.com/2019/7/26/8932398/equifax-settlemen...

Re: Capital One Says Breach Hit 100M Individuals in U.S

#202

> hacked into a cloud-computing company server, federal prosecutors in Seattle said > the cloud-computing company, on whose servers Capital One rented space, wasn’t identified in court papers. Does this feel like it was just an S3 bucket with permissions set incorrectly? I've come across sensitive documents in S3 buckets with a well crafted google search.

Actually looks like she worked for Amazon on S3. So there might have been some insider knowledge. From the complaint below, and googling her name you can find her resume I won't link it here, but here's a screenshot of a snippet: https://i.imgur.com/NezWVKw.png

[deleted]

Re: Capital One Says Breach Hit 100M Individuals in U.S

#203
post #91

I don't trust in the U.S. justice system to handle every crime and person as it should but for us, context is important: This person's Twitter is 0xA3A97B6C, y'all can go there and get a better picture of the situation.

So much evidence of mental illness there (see also Facebook). I hope this person gets help, but given their claim to also be in the country illegally (Tuvalu), who knows. I was ready to think this person was being set up by someone who didn't like her, given how exposed she was to being identified, but the Twitter and FB posts strongly suggest a vulnerable person making poor decisions instead.

>Erratic finally got arrested?

>Jesus christ, how many times did she come back into Discord rooms she was banned from under new names, just to brag about how she "snuck in," like within two weeks, and of course getting banned again. Being a desperate attention whore is bad opsec.

>I guess she's finally getting all that attention she's been begging for.

>She pulled the same shit with our tiny IRC network nobody on earth could possibly give a shit about. I don't know how a person can be this insane. Relentless stalking of individual users, histrionic rants, literally attempting to dox randos and flooding the server with spambots, you fucking name it.

Sounds like personality disorder.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#204
post #198

Earlier quoted context omitted.

Good lord. -Paige left code used in the "attack" on her GitHub. -Paige left text files with unencrypted data there, too. -Paige openly posted about it in an open (!!!) Slack channel and publicly named her VPN service of choice, which of course, matched access logs AND GitHub server logs. (Also tor, which the FBI agent was able to confirm and add yet another data point) -Paige said "I have a leak proof IPredator route…

I hope the reality is that criminals are really dumb and not that we only catch the really dumb ones.

Heh, not even close. I know several individuals who should be in prison for their cyber crimes. But the fact is, not only have they never been caught, the victims probably don’t even know that anything happened.

There is such a lack of talent out there right now in the cybersecurity industry that it’s very easy for criminals to slip around undetected. You’d have to be a total idiot to get caught, or catch the attention of someone really motivated to catch someone.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#205
post #39

Earlier quoted context omitted.

It says she posted on "social media" (Twitter) about it, claiming to have Capital One information, "and that she recognizes that she acted illegally". Nothing about Opsec here. She basically asked them to arrest her. Probably had some of the usual motivations: "look at me I'm clever", "look at this stupid big company with bad security", or maybe used the opportunity for some political thing with banks. Not the sophis…

https://gist.github.com/paigeadelethompson Not much is left.

In https://gist.github.com/paigeadelethompson/620192d8c4b344d24...

Interesting note that she comments that they skipped 3 for the fan values. Seemingly an oversight for the fact that these fan values of 1,2,4 indicate that it is probably a bitfield with each bit indicating a fan speed.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#206

> hacked into a cloud-computing company server, federal prosecutors in Seattle said > the cloud-computing company, on whose servers Capital One rented space, wasn’t identified in court papers. Does this feel like it was just an S3 bucket with permissions set incorrectly? I've come across sensitive documents in S3 buckets with a well crafted google search.

There are more details on dailymail article:

https://www.dailymail.co.uk/news/article-7299511/Ex-Seattle-...

Re: Capital One Says Breach Hit 100M Individuals in U.S

#207
post #120

Earlier quoted context omitted.

Metadata, yes. But not content. So they can see you have 200 c5.9xlarges running in 3 AZs in 3 subnets in one VPC, for example. But they can't see what you have on the volumes attached to those instances, what processes are running, etc.

I've had AWS support tell me exactly what processes are running on my instance. They do seem to have some visibility beyond metadata.

Seems vanishingly unlikely, unless you're using a service (SSM Inventory or similar) that would reflect what you have running/installed.

I'm at AWS and we have basically zero insight into these things.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#209

I was there when C1 negotiated that deal with Amazon and they swore it couldn't happen but of course, we all know that's false.

Miss the LevelMoney folks... Yeah AWS can’t protect you against a misconfigured environment

AWS roles and access are incredibly complex to configure and audit though. Needlessly so.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#210
post #197

Earlier quoted context omitted.

Actually looks like she worked for Amazon on S3. So there might have been some insider knowledge. From the complaint below, and googling her name you can find her resume I won't link it here, but here's a screenshot of a snippet: https://i.imgur.com/NezWVKw.png

I know that reading the actual linked content on HN is verboten, but the Bloomberg story says "Thompson was previously an Amazon Web Services employee. She last worked at Amazon in 2016, spokesman Grant Milne said. The breach described by Capitol One didn’t require insider knowledge, he said."

The parts about Amazon was added later after the article was originally published. Maybe they read HN and found her Gitlab account like was posted below before this was published. Most of those news sites back referral link lists.
Post reply on HN