Live data from Hacker News

Capital One Says Breach Hit 100M Individuals in U.S

bloomberg.com

241–250 of 319 posts

Re: Capital One Says Breach Hit 100M Individuals in U.S

#242

I wonder why data security professionals don't practice compartmentalization. 100 million accounts should not be accessible from one account. It should be like watertight compartments in a ship. Breaching one doesn't sink the ship.

I don’t think they even had a legitimate reason to keep this data around. Surely they aren’t all active accounts and s3 isn’t a place the data likely needs to be long term.

They have to keep the data at least 7 years because of some regulation(s)

Doesn’t excuse what happened, obviously

Re: Capital One Says Breach Hit 100M Individuals in U.S

#244
Instead of focusing on the lady involved, perhaps holding Capital One accountable for their part in the matter may be a better thrust to this thread.

While it might not be okay to instigate such breaches, we might also consider it the actions of a whistleblower. Especially given the unusual way she went sbout disclosing things.

Sure, perhaps there is a little bit of hey look at me about it, but at the bottom of the trough it is actually the corporation that has ultimate responsibility.

I look forward to a statement from Capital One of regret that they allowed the breach to happen and will strive for better standards of security.

And that is actually a message for the entire industry.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#245
post #162

Earlier quoted context omitted.

Actually looks like she worked for Amazon on S3. So there might have been some insider knowledge. From the complaint below, and googling her name you can find her resume I won't link it here, but here's a screenshot of a snippet: https://i.imgur.com/NezWVKw.png

If you put data in the cloud, make sure you encrypt with keys only you have even when they promise all sorts of assurances of oversight and process in addition to “we use AES”.

If you put data in the cloud...

assume it is no longer private.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#246
post #39

Earlier quoted context omitted.

It says she posted on "social media" (Twitter) about it, claiming to have Capital One information, "and that she recognizes that she acted illegally". Nothing about Opsec here. She basically asked them to arrest her. Probably had some of the usual motivations: "look at me I'm clever", "look at this stupid big company with bad security", or maybe used the opportunity for some political thing with banks. Not the sophis…

https://gist.github.com/paigeadelethompson Not much is left.

Her gitlab account shows it was updated just few hours ago. How is this possible?

https://gitlab.com/netcrave

Re: Capital One Says Breach Hit 100M Individuals in U.S

#247
post #172

Earlier quoted context omitted.

So much evidence of mental illness there (see also Facebook). I hope this person gets help, but given their claim to also be in the country illegally (Tuvalu), who knows. I was ready to think this person was being set up by someone who didn't like her, given how exposed she was to being identified, but the Twitter and FB posts strongly suggest a vulnerable person making poor decisions instead.

Given that Ms. Thompson is transgender [0], it's likely a lot was stacked against her emotionally. 40% of trans-identifying individuals to attempt suicide [1]. This is a disappointing omission from the reporting and the road that lies ahead for Ms. Thomson in the hands of the federal prison system is surely horrifying. [0] https://twitter.com/0xA3A97B6C/status/1152518528907354112 [1] https://transequality.org/sites/d…

I wonder if it could be an effective legal defense for her, akin to plot of Soderbergh Side Effects (2013). "not guilty by reason of insanity" due to hormonal treatment, there are precedents

https://www.charlotteobserver.com/news/local/crime/article64...

https://ps.psychiatryonline.org/doi/full/10.1176/appi.ps.53....

https://www.mercurynews.com/2012/08/21/man-acquitted-after-a...

Re: Capital One Says Breach Hit 100M Individuals in U.S

#248
I'm still not clear what I need to do to protect myself from a similar class of misconfiguration mistakes.

"The first command, when executed, obtained security credentials for a role known as *-WAF-Role" says the affadavit.

Was some web app of CapOne coded so the JavaScript app fetched IAM credentials over HTTP so it could do its job by accessing some other S3 bucket?? And thats how Paige or someone she knew found the toehold in? That would be pretty brain dead. Or was it more subtle in terms of pure WAF misconfiguration?

Re: Capital One Says Breach Hit 100M Individuals in U.S

#249
post #86

Earlier quoted context omitted.

It's a wild ride. Who hacks in via Tor and then posts the data to a GitLab account under their own name?

A lot of crime would go unsolved if people just kept their mouths shut. There's a human tendency to need to talk about things you've done, I guess, especially stuff that will get you "street cred".

A lot of crime does indeed go unsolved because of people keeping their mouths shut.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#250

I wonder why data security professionals don't practice compartmentalization. 100 million accounts should not be accessible from one account. It should be like watertight compartments in a ship. Breaching one doesn't sink the ship.

Data security professionals don’t make these decisions, random developers do. And they do what is easiest.

At most large companies, IT sets the policy and developers are required to work within that policy. I've worked at about 10 jobs. The only one where devs could write their own ticket was a startup
Post reply on HN