Live data from Hacker News

StockX was hacked, exposing millions of customers’ data

techcrunch.com

71–80 of 108 posts

Re: StockX was hacked, exposing millions of customers’ data

#71

Earlier quoted context omitted.

The store's. I put the hat on while I continued shopping. I had every intention of buying the hat, but apparently the paper fell out. The employee came to me fist-clenched, with a fighting tone. I'm sure you're skeptical and think there's two sides to every story, but I don't want to expand too much on the story for privacy and retaliatory concerns. I invite you to come to SoHo, NYC and visit a few stores if you have…

I've lived in NYC all my life and am familiar with the scene. Did they ask you nicely (initially) to pick it up? What was the tone of your response? These are two missing clues on how this might have gotten started.

> Did they ask you nicely (initially) to pick it up?

Nope. It was "Are you going to buy that?" and other rhetorical heckling questions. I said "yes" and didn't give them the attention they want. Eventually, looks over to my girlfriend, turned back to me, and commands me "go pick that up". If they simply asked "did you drop that?" I would have immediately said "oh, sorry, I didn't see that" and done so.

Re: StockX was hacked, exposing millions of customers’ data

#72
post #10

Earlier quoted context omitted.

Given that data, doesn't their attempt to call this "system updates" constitute a violation of California's data breach notification laws? https://oag.ca.gov/privacy/databreach/reporting

Oh man this is an interesting grey area. If the data was “encrypted” then they aren’t required to notify unless the encryption key is reasonably believed to have been acquired by the hacker. I don’t know anything about MD5 or what makes it vulnerable but if StockX has no reason to believe the hacker acquired the key they could certainly make the argument they had no notice obligation. Reading the statute (and assumin…

MD5 is not an encryption algorithm. There is no key!

Re: StockX was hacked, exposing millions of customers’ data

#73

Earlier quoted context omitted.

Oh man this is an interesting grey area. If the data was “encrypted” then they aren’t required to notify unless the encryption key is reasonably believed to have been acquired by the hacker. I don’t know anything about MD5 or what makes it vulnerable but if StockX has no reason to believe the hacker acquired the key they could certainly make the argument they had no notice obligation. Reading the statute (and assumin…

The non-password data was not encrypted, so is definitely a breach of California law.

Ahh well then it’s definitely not grey. And serves me right for scanning the comments here and not actually reading the article.

Re: StockX was hacked, exposing millions of customers’ data

#74

Earlier quoted context omitted.

I've lived in NYC all my life and am familiar with the scene. Did they ask you nicely (initially) to pick it up? What was the tone of your response? These are two missing clues on how this might have gotten started.

> Did they ask you nicely (initially) to pick it up? Nope. It was "Are you going to buy that?" and other rhetorical heckling questions. I said "yes" and didn't give them the attention they want. Eventually, looks over to my girlfriend, turned back to me, and commands me "go pick that up". If they simply asked "did you drop that?" I would have immediately said "oh, sorry, I didn't see that" and done so.

I see. Typical territorial domineering of an immature ego.

Re: StockX was hacked, exposing millions of customers’ data

#75
post #63
post #45

Earlier quoted context omitted.

I used to work closely with Quicken Loans and other FoCs and can attest that this behavior is commonplace. There is this strange culture within the Family of Companies where non-tech leaders think that tenured Quicken engineers and tech people are these sort of super-geniuses. Many years back I was a part of a company in the Quicken led start-up space. We were often "encouraged" to meet with Quicken or FatHead senior…

While I don't agree with the way he spoke, was C# one of the de facto or explicit in-house languages of the company, and Ruby was not? If so, he may have been referring to the fact that the company already had many libraries in C# that you could use. Plus, if C# was one of their areas of expertise, it's typically best to use that as opposed to a new, unfamiliar language unless you're explicitly testing out a new appr…

>While I don't agree with the way he spoke, was C# one of the de facto or explicit in-house languages of the company, and Ruby was not? If so, he may have been referring to the fact that the company already had many libraries in C# that you could use. Plus, if C# was one of their areas of expertise, it's typically best to use that as opposed to a new, unfamiliar language unless you're explicitly testing out a new approach.

[...]

>I don't think RoR is trash, but if you were starting a large program that would be used across multiple departments whose in-house language was C#, it was probably the right call to suggest switching to C#.

According to the parent comment, he was working at a startup that was in the "Quicken led start-up space". My interpretation is that Quicken was acting like an incubator, and he isn't working in quicken, and so the engineering teams are separate. Therefore I don't think organizational inertia applies here.

Re: StockX was hacked, exposing millions of customers’ data

#76

Earlier quoted context omitted.

> Did they ask you nicely (initially) to pick it up? Nope. It was "Are you going to buy that?" and other rhetorical heckling questions. I said "yes" and didn't give them the attention they want. Eventually, looks over to my girlfriend, turned back to me, and commands me "go pick that up". If they simply asked "did you drop that?" I would have immediately said "oh, sorry, I didn't see that" and done so.

I see. Typical territorial domineering of an immature ego.

In every other sane retail environment, this should have never happened at all, regardless of how rude the customer is, unless they're being racist or intentionally degrading or belittling the staff.

Re: StockX was hacked, exposing millions of customers’ data

#77
post #58

Earlier quoted context omitted.

https://www.quickenloans.com/about/partner-company

Huh, that’s a bit of a random collection of stuff.

Rock Ventures, http://www.rockventures.com/ , was founded by Quicken Loans billionaire Dan Gilbert.

Re: StockX was hacked, exposing millions of customers’ data

#78

Earlier quoted context omitted.

That would be a civil case prosecuted by the other companies, not a criminal case.

It should be criminal.

Good luck proving that a "reasonable person" shouldn't have done it. Most people on HN probably do, but I wouldn't be surprised if everyone coming out of a 3 month coding bootcamp only knew to hash passwords and nothing else. The other comments in this thread seems to suggest that the company is filled with bootcamp programmers.

Re: StockX was hacked, exposing millions of customers’ data

#79
post #18
post #2

> The stolen data contained names, email addresses, scrambled password (believed to be hashed with the MD5 algorithm and salted), and other profile information — such as shoe size and trading currency. The data also included the user’s device type, such as Android or iPhone, and the software version. The serious tone of this article made me double check if this was April 1st when I read this paragraph. The stolen dat…

Author might be a young intern writer.

My bad. He isn't. I suppose this was a 'strictly news' piece. Separate analysis coming soon.

Re: StockX was hacked, exposing millions of customers’ data

#80
post #78

Earlier quoted context omitted.

It should be criminal.

Good luck proving that a "reasonable person" shouldn't have done it. Most people on HN probably do, but I wouldn't be surprised if everyone coming out of a 3 month coding bootcamp only knew to hash passwords and nothing else. The other comments in this thread seems to suggest that the company is filled with bootcamp programmers.

As a government body actually publishes advice on this, NIST [0], it may well be possible to argue for what is reasonable in a court of law.

[0] https://csrc.nist.gov/projects/hash-functions/nist-policy-on...

Post reply on HN