Live data from Hacker News

Personal and social information of 1.2B people discovered in data leak

dataviper.io

171–180 of 440 posts

Re: Personal and social information of 1.2B people discovered in data leak

#171

Earlier quoted context omitted.

One of my coworkers generates a fake middle name for every service they sign up with. According to him, this serves as a unique identifier allowing them to determine when a service is selling their data to a third party (or data is being leaked).

Fastmail has subdomain addressing, so if your email is jondoe@example.com, you can use hn@jondoe.example.com to sign up for HN. That way you'll know for sure who leaks your data, and nobody's going to strip it away like some services would strip away plus addressing (as in, johndoe+hn@example.com).

I have excellent results with a subdomain. Even though PDL probably has a lot of data on me, they have (not yet?) been able to glue it to my primary mail address. That one only has my name, gender, github, country and name of my employer. They can't seem to map the remainder to anything else.

Re: Personal and social information of 1.2B people discovered in data leak

#172
post #4

Yet another Elasticsearch server wide open. This is going to make the flurry of open mongodb servers look trivial.

They're everywhere. Just ask Shodan.

Since I learned about Shodan, I'm convinced that the (subjectively) increase in reported data breaches is just due to an increasing amount of people looking through Shodan results, and doesn't have anything to do with any trends in security.

Security standards at any company have always been low, but now it's easy even for a layman to find leaked data.

Re: Personal and social information of 1.2B people discovered in data leak

#173
post #4

Yet another Elasticsearch server wide open. This is going to make the flurry of open mongodb servers look trivial.

I believe Elasticsearch doesn't allow restricting access by requiring login unless you pay for the enterprise version, which is just straight up stupid.

The basic license is free now, so you can get basic authentication.

But I still wonder why that isn't part of the open source version, and why it isn't turned on by default....

Re: Personal and social information of 1.2B people discovered in data leak

#177
post #6

In retrospect, it would have been interesting to have a bunch of accounts each containing a unique "map trap", at all of the larger services. Then years later, when the aggregator/broker guys get hacked/sold/leaked, you'd have some picture of the genealogy involved.

The problem is that you often can’t find access to the actual “password” used in the breach. Does anyone know where I can see if it was an actual password or just some made up thing?

I was suggesting something different. Specifically open an account on every service as a tracking canary, say with the same email to help them tie them all together. But on each one, vary something slightly like phone. Then years later, when looking at a leaked aggregator entry, all the phones on the record should tell you all the places they bought/stole data from.

Re: Personal and social information of 1.2B people discovered in data leak

#179
post #88

I found a vulnerability in linkedIn a few years back that allowed anyone to access a private profile (because client side validation was enough for them I guess..?) They didn't take my report seriously (still not completely patched) and I feel like that told me all I needed to know about their security practices.

linkedin is a computer virus

No it is not.

Re: Personal and social information of 1.2B people discovered in data leak

#180

People data labs's data is pretty accurate. Here is mine: https://api.peopledatalabs.com/v4/person?api_key=9c6a1382204... You can try it for yourself by changing the email. All of the information is public, so I don't mind. They are basically doing data integration.

Wow.. I checked with an email address I use for disposable purposes. The only thing they had on it was a blank LinkedIn profile -- meaning that LinkedIn cancer has trawled some pretty questionable sites, harvesting email addresses as placeholders for their accounts. WTF.
Post reply on HN