Earlier quoted context omitted.
One of my coworkers generates a fake middle name for every service they sign up with. According to him, this serves as a unique identifier allowing them to determine when a service is selling their data to a third party (or data is being leaked).
Fastmail has subdomain addressing, so if your email is jondoe@example.com, you can use hn@jondoe.example.com to sign up for HN. That way you'll know for sure who leaks your data, and nobody's going to strip it away like some services would strip away plus addressing (as in, johndoe+hn@example.com).
Personal and social information of 1.2B people discovered in data leak
171–180 of 440 posts
Re: Personal and social information of 1.2B people discovered in data leak
#172Yet another Elasticsearch server wide open. This is going to make the flurry of open mongodb servers look trivial.
They're everywhere. Just ask Shodan.
Security standards at any company have always been low, but now it's easy even for a layman to find leaked data.
Re: Personal and social information of 1.2B people discovered in data leak
#173Yet another Elasticsearch server wide open. This is going to make the flurry of open mongodb servers look trivial.
I believe Elasticsearch doesn't allow restricting access by requiring login unless you pay for the enterprise version, which is just straight up stupid.
But I still wonder why that isn't part of the open source version, and why it isn't turned on by default....
Re: Personal and social information of 1.2B people discovered in data leak
#174Re: Personal and social information of 1.2B people discovered in data leak
#175Re: Personal and social information of 1.2B people discovered in data leak
#176Re: Personal and social information of 1.2B people discovered in data leak
#177In retrospect, it would have been interesting to have a bunch of accounts each containing a unique "map trap", at all of the larger services. Then years later, when the aggregator/broker guys get hacked/sold/leaked, you'd have some picture of the genealogy involved.
The problem is that you often can’t find access to the actual “password” used in the breach. Does anyone know where I can see if it was an actual password or just some made up thing?
Re: Personal and social information of 1.2B people discovered in data leak
#178Isn't it exactly what GDPR came to prevent? Are there no Europeans among this group?
Re: Personal and social information of 1.2B people discovered in data leak
#179I found a vulnerability in linkedIn a few years back that allowed anyone to access a private profile (because client side validation was enough for them I guess..?) They didn't take my report seriously (still not completely patched) and I feel like that told me all I needed to know about their security practices.
linkedin is a computer virus
Re: Personal and social information of 1.2B people discovered in data leak
#180People data labs's data is pretty accurate. Here is mine: https://api.peopledatalabs.com/v4/person?api_key=9c6a1382204... You can try it for yourself by changing the email. All of the information is public, so I don't mind. They are basically doing data integration.