Live data from Hacker News

Capital One Says Breach Hit 100M Individuals in U.S

bloomberg.com

251–260 of 319 posts

Re: Capital One Says Breach Hit 100M Individuals in U.S

#251

Earlier quoted context omitted.

Looks well qualified to run the coding bootcamp in her prison.

Only facing up to 5 years apparently. I wonder if that will change over time. Considering her hack is worse than what Aaron Swartz hacked (not PII) I cant believe she only gets 5 years.

“Up to” limits on sentencing are different from what people actually get. Swartz supposedly would have got 6 months recommended by the prosecutor. https://mashable.com/2013/01/17/aaron-swartz-prosecutor-orti...

Re: Capital One Says Breach Hit 100M Individuals in U.S

#252
post #247
post #172

Earlier quoted context omitted.

Given that Ms. Thompson is transgender [0], it's likely a lot was stacked against her emotionally. 40% of trans-identifying individuals to attempt suicide [1]. This is a disappointing omission from the reporting and the road that lies ahead for Ms. Thomson in the hands of the federal prison system is surely horrifying. [0] https://twitter.com/0xA3A97B6C/status/1152518528907354112 [1] https://transequality.org/sites/d…

I wonder if it could be an effective legal defense for her, akin to plot of Soderbergh Side Effects (2013). "not guilty by reason of insanity" due to hormonal treatment, there are precedents https://www.charlotteobserver.com/news/local/crime/article64... https://ps.psychiatryonline.org/doi/full/10.1176/appi.ps.53.... https://www.mercurynews.com/2012/08/21/man-acquitted-after-a...

Maybe drs shouldn't prescribe meds in such doses if they have such harmful effects?

Re: Capital One Says Breach Hit 100M Individuals in U.S

#253

Earlier quoted context omitted.

https://gist.github.com/paigeadelethompson Not much is left.

Her gitlab account shows it was updated just few hours ago. How is this possible? https://gitlab.com/netcrave

When you star a project it gets "updated" even if you unstar it. Kinda like Unix's touch command.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#254

Earlier quoted context omitted.

I'd rather see the hammer applied to the companies that allow the data to be stolen.

From what I read in the complaint, it wasn't as blatantly bone headed as other breaches. Seemed to be an IAM permission issue related to AWS WAF. This argument is constantly made on HN and it is analogous to; you left your back door open at your house, and instead of arresting and prosecuting the robber, we are going to arrest you. Sure, I made a mistake and left my back door open, but that doesn't give the robber th…

If I steal capital ones company vehicle and get in a head-on collision, capital ones insurance still pays the damage. I'm still criminally liable for unlawful entry, but C1s insurance covers the damage done by their vehicle. The same precedent needs to apply here. If I broke into a chemical plant and released harmful toxins into the air, the company is still civilly liable. In this case, the data is the toxin.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#255
post #67

Earlier quoted context omitted.

It's a wild ride. Who hacks in via Tor and then posts the data to a GitLab account under their own name?

Could be a frame job, remorse, freakout, or some kind of dissociative or other personality disorder.

A news-source I won't mention, because it's trash, did a full stalk of her on social media, and she seemed to be in an _erratic_ state of mind, but maybe that's just her personality.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#256

If I came across an s3 bucket with my credit application details and I could delete it, I would probably do it and then report to their security team. It’s MY data security they’re being casual with. It occurs to me now that if I did that it would likely be a crime because of the harm to the company. The irony.

> and I could delete it, I would probably do it

In the UK this would definitely open you up to the Computer Misuse act, and I imagine the police would have something to say to you about evidence tampering too.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#257

Earlier quoted context omitted.

Actually looks like she worked for Amazon on S3. So there might have been some insider knowledge. From the complaint below, and googling her name you can find her resume I won't link it here, but here's a screenshot of a snippet: https://i.imgur.com/NezWVKw.png

Looks well qualified to run the coding bootcamp in her prison.

That is a lot of buzzwords.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#258
post #172

Earlier quoted context omitted.

So much evidence of mental illness there (see also Facebook). I hope this person gets help, but given their claim to also be in the country illegally (Tuvalu), who knows. I was ready to think this person was being set up by someone who didn't like her, given how exposed she was to being identified, but the Twitter and FB posts strongly suggest a vulnerable person making poor decisions instead.

Given that Ms. Thompson is transgender [0], it's likely a lot was stacked against her emotionally. 40% of trans-identifying individuals to attempt suicide [1]. This is a disappointing omission from the reporting and the road that lies ahead for Ms. Thomson in the hands of the federal prison system is surely horrifying. [0] https://twitter.com/0xA3A97B6C/status/1152518528907354112 [1] https://transequality.org/sites/d…

Interestingly the Daily Mail had this detail, and I wondered why they felt the need to include it; at first glance it didn't seem at all relevant. My belief is that the small number of trans people I know would rather be judged by their actions in an absolute sense, rather than "well this is kinda excusable because he/she is trans", but maybe I need to re-examine that.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#259
post #152
post #105

Earlier quoted context omitted.

Oh cool I use the same LaTeX template as her for my resume. Mine is blue instead of pink though! https://github.com/posquit0/Awesome-CV

Don’t forget to mention that on your next interview!

ftw

Re: Capital One Says Breach Hit 100M Individuals in U.S

#260

If I came across an s3 bucket with my credit application details and I could delete it, I would probably do it and then report to their security team. It’s MY data security they’re being casual with. It occurs to me now that if I did that it would likely be a crime because of the harm to the company. The irony.

> and I could delete it, I would probably do it In the UK this would definitely open you up to the Computer Misuse act, and I imagine the police would have something to say to you about evidence tampering too.

Having wide open access to customer details with full ability to read/write on the open internet..? That seems like it should be stretching the Computer Misuse too far, but yes, your're right.
Post reply on HN