Live data from Hacker News

Capital One Says Breach Hit 100M Individuals in U.S

bloomberg.com

211–220 of 319 posts

Re: Capital One Says Breach Hit 100M Individuals in U.S

#213
post #28

> hacked into a cloud-computing company server, federal prosecutors in Seattle said > the cloud-computing company, on whose servers Capital One rented space, wasn’t identified in court papers. Does this feel like it was just an S3 bucket with permissions set incorrectly? I've come across sensitive documents in S3 buckets with a well crafted google search.

The court filing directly says "s3", so yeah, it's Amazon.

Good thing they didn't mention it by name ;)

Re: Capital One Says Breach Hit 100M Individuals in U.S

#214
post #184

What was Slack's role in all of this? They appear to have turned over historical images and chat logs, not just for the person indicted, but even others in the same channel. Did the FBI ask nicely or was there actually some formal process?

Some of the conversation occurred on her Slack server, which as of an hour or two ago was still completely open/public via an invite linked shared on Meetup.

The entire server chat log is a few Google searches away.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#215

Earlier quoted context omitted.

I would imagine complete credit card applications contain the type of information identity thieves would be willing to pay good money for.

I think the point is: unless the hacker is already aware of how to sell PII of this nature and how to move "good money" then a hack like this is for naught. Reading the mistakes made in the hack itself makes me wonder if black markets and money laundering are a skill they posses.

I think you could just sign up on one of the onion drug/fraud markets for ~$500 vendor deposit and put up a listing for those profiles at like $5-10 a pop.

If you were lazy you could just hit up an existing vendor and ask them to sell your data in batches.

I’m not saying this would be a good idea, but it certainly wouldn’t be very difficult.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#216

Earlier quoted context omitted.

Miss the LevelMoney folks... Yeah AWS can’t protect you against a misconfigured environment

Are there AWS experts who can do some sort of quick audit or "sanity check" of an environment's configurations? AWS almost makes it too easy for someone who only sort of knows what they're doing (like me) to get things up and running.

Basically, no. AWS is flexible enough to let you set it up in any complicated way you want, meaning it gives you plenty of rope to hang yourself with. It's arguably much easier to audit a random Linux box for security than an AWS account.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#217

Earlier quoted context omitted.

Actually looks like she worked for Amazon on S3. So there might have been some insider knowledge. From the complaint below, and googling her name you can find her resume I won't link it here, but here's a screenshot of a snippet: https://i.imgur.com/NezWVKw.png

Unlikely. S3 was publicly rebuilt in the wake of the 2017 S3pocalypse.

What does this refer to?

Re: Capital One Says Breach Hit 100M Individuals in U.S

#218
This spooked me. I thought I recognized the name, and then I remembered she had recently contacted me out of the blue on meetup.com to ask if I was interested in doing some urban exploration. I said yes, but we never got around to picking a day. Now I'm kind of glad we didn't!

Re: Capital One Says Breach Hit 100M Individuals in U.S

#220

If I came across an s3 bucket with my credit application details and I could delete it, I would probably do it and then report to their security team. It’s MY data security they’re being casual with. It occurs to me now that if I did that it would likely be a crime because of the harm to the company. The irony.

Whats funny to me about this statement is it would propose an interesting legal question in the EU due to GDPR. You certainly do have your right to delete it there.... Despite it being unconventional.
Post reply on HN