Live data from Hacker News

Personal and social information of 1.2B people discovered in data leak

dataviper.io

371–380 of 440 posts

Re: Personal and social information of 1.2B people discovered in data leak

#371

Earlier quoted context omitted.

My gmail is my first initial followed by my last name. There are other people on this planet with same first initial and last name, some of whom seem to think that must be their email too, because I keep on getting emails where they used it to sign up for things.

I had a lady send me a zip file that contained a VPN client, certificate and a word document with usernames and passwords to the VPN and a number of industrial control systems at the factory she was a manager of. She sent it religiously, every 90 days.

Do you have any clue who she thought you were?

Re: Personal and social information of 1.2B people discovered in data leak

#372

Earlier quoted context omitted.

I had a lady send me a zip file that contained a VPN client, certificate and a word document with usernames and passwords to the VPN and a number of industrial control systems at the factory she was a manager of. She sent it religiously, every 90 days.

Do you have any clue who she thought you were?

Oh yes, she was emailing a copy of her stuff to “herself”.

Re: Personal and social information of 1.2B people discovered in data leak

#373

It should be illegal for any company to store my private information like this. The 'anonymous' sharing of my information is easily de-anonymized. Sites asking for your phone number for "security purposes" are a joke. You just have to accept that absolutely everything you've done online is public information. If it isn't now, it is being stored and future tools / databases will make what is either difficult to access…

What private information? If you give a random website your email address or phone number, it's not private anymore and you're the one who released the secret. Unless they promised to keep it private in a legally binding way, in which case, your wish is already true.

Re: Personal and social information of 1.2B people discovered in data leak

#374
post #334
post #275

Earlier quoted context omitted.

Software should be secure by default. Don't blame the user. mySQL in comparison wont even let you install without setting a root password. And it only listen on localhost/unix-socket by default. Then you need to explicitly add another user if you want to allow it to login from a non local ip. I don't think it's even possible - to both set a blank root password and allow it to login from a public IP. So you really thi…

This is ridiculous. Software should be built in the best method of delivering maximum value to its users. A trade-off for usability can be made for certain cases like ease-of-use for new software. Redis was part of this a while ago http://antirez.com/news/96 . Engineers should know their tools before using them. It's a huge part of our jobs. You could introduce a ton of other vulnerabilities in software: XSS, SQL inj…

It's not always engineers that use them.

Sometimes software managers have the sudden need to show statistics and other things.

Yeah, that was fun...

Re: Personal and social information of 1.2B people discovered in data leak

#375
post #321

Earlier quoted context omitted.

I get bank statements, job offers, party invitations, and lately a bunch of lets say very questionable email verifications from euro 'dating' sites- I've identified the guy in the UK but its too much (and getting embarrassing now) to keep forwarding his stuff to him. Downside of getting in early on popular email services.

> but its too much (and getting embarrassing now) to keep forwarding his stuff to him What amazes me is when I get misaddressed email, and I reply to say its misaddressed (and I'm not talking about automated services, I'm talking about obviously manually sent stuff), and my reply just gets ignored and the misaddressed email just keeps on coming.

That's the most surreal, when you try to fix it and the behavior never changes.

Re: Personal and social information of 1.2B people discovered in data leak

#376

Earlier quoted context omitted.

Hash collisions most likely.

Have heard this so many times about Gmail... How have they not resolved this?

I think it's like EC2 instance IDs. When they first came up with it, they never thought there would be literally billions of unique email addresses/EC2 instances eventually.

Re: Personal and social information of 1.2B people discovered in data leak

#377

Earlier quoted context omitted.

Do you have any clue who she thought you were?

Oh yes, she was emailing a copy of her stuff to “herself”.

Seriously?

How the hell could she think that your email address was hers? I mean, wouldn't she notice that she never got the messages?

Re: Personal and social information of 1.2B people discovered in data leak

#378
Cyber alarmists would call a telephone directory: 'A verified threat incident'. Yet these are the same companies selling OSINT data. These alarmist groups need to put down the buzzwords, step off from their white horse and take a look at the hypocrite in the mirror.

If you use social networks, you don't have a reasonable expectation of privacy. You've published your data publicly. If you want to keep this information private, then don't publish it on the Internet.

From: http://www.dmlp.org/legal-guide/publication-private-facts

>2. Private Fact: The fact or facts disclosed must be private, and not generally known.

Re: Personal and social information of 1.2B people discovered in data leak

#379

Earlier quoted context omitted.

Oh yes, she was emailing a copy of her stuff to “herself”.

Seriously? How the hell could she think that your email address was hers? I mean, wouldn't she notice that she never got the messages?

Totally serious. There are about a dozen people who regularly do this. One guy has missed 4-5 job interviews.

Re: Personal and social information of 1.2B people discovered in data leak

#380

Earlier quoted context omitted.

Seriously? How the hell could she think that your email address was hers? I mean, wouldn't she notice that she never got the messages?

Totally serious. There are about a dozen people who regularly do this. One guy has missed 4-5 job interviews.

So is it typos? Like one letter off?

I can imagine someone mistyping an address, and then reusing the "to" link.

Post reply on HN