Live data from Hacker News

New ‘Meow’ attack has deleted almost 4k unsecured databases

bleepingcomputer.com

181–190 of 544 posts

Re: New ‘Meow’ attack has deleted almost 4k unsecured databases

#181

Earlier quoted context omitted.

Better off? The idea that victims deserve to be victimized because they didn't take enough care is trotted out every time a security issue comes up on HN.

These aren't victims; they were harmed through their own gross negligence or the gross negligence of the developer they employed.

They aren't victims? If you forget to lock your car door and it is stolen or something inside it is stolen are you also not a victim by your logic?

Re: New ‘Meow’ attack has deleted almost 4k unsecured databases

#182
post #129

Earlier quoted context omitted.

Better off? The idea that victims deserve to be victimized because they didn't take enough care is trotted out every time a security issue comes up on HN.

Thr victims are the unaware customers who's data has been stolen because the company wasn't providing security. If a business left the store open with the customers credit cards details on display. Anyone passing by can go in and copy that info. Someone sees this and burns the exposed records. Perhaps they helped the victim. Remember no one burned the store down or the table holding the records. They burned only the…

You don't know who was the storage vendor and who's data was being deleted and you have no idea what that data represents or what the consequences are of having to restore it.

You are making several unfounded assumptions.

Re: New ‘Meow’ attack has deleted almost 4k unsecured databases

#183

Earlier quoted context omitted.

Yeah. I don't care if some big business loses their Elasticsearch data and their site stops working until they get it secured and re-hydrated with data from their relational database. Good, they learned a lesson. But I would feel bad if someone's small business had to shut down or lose a bunch of money because they lost all their customer data. I'd feel bad if someone lost all the data they'd been using for a persona…

> But I would feel bad if someone's small business had to shut down or lose a bunch of money because they lost all their customer data. Don't. When businesses of any size cut corners and provide services they aren't qualified to provide, it gives them an advantage compared to businesses that try to do it properly. They make more money or charge less and can often out compete competent owners. They'll also be the firs…

Said small businesses might have no idea their data wasn’t secure. That would be on whoever developed their technology, not necessarily the business. Not all small businesses with customer or sales data is a technology company.

Re: New ‘Meow’ attack has deleted almost 4k unsecured databases

#185

Earlier quoted context omitted.

You should configure a timeout.

Good tree^H^H^H^Hgraph traversal algorithms have a history stack specifically to detect and deal with loops.

1) If it‘s a tree, it ain‘t got no loops 2) The stack isn‘t to deal with loops, the „visited“ flag at each edge is there for that. The stack (for DFS, BFS would be a queue) is there to keep track of which nodes have been visited such that you can construct a path from the starting node to the one you‘re looking for.

Obviously there are variants to this, depending on what you‘re actually trying to achieve with it. My point is that a stack would be a very inefficient way to deal with loops.

Re: New ‘Meow’ attack has deleted almost 4k unsecured databases

#186
post #31

Earlier quoted context omitted.

What I don't get about Shodan: Why aren't all unsecured databases found instantly (at the moment Shodan went online), but recurring attacks/dumps like this one that rely on it? Do they update their crawl data in waves?

One real limitation is getting data out of Shodan. Having done a few different projects that involve large-scale use of Shodan results (e.g. several hundred thousand records), this kind of thing usually ends up costing $300 for either export credits or a service plan. Sure, $300 isn't really that much to cause millions in damage, but I think it's a big factor in why we don't often see Shodan used for huge-scale malfe…

We're actually getting rid of export credits because it's caused confusion over the years. We now just have query credits to download data/ do searches, and scan credits for users that want to request on-demand scans. We announced this change in the most recent Shodan Update newsletter. You can already use our new website (https://beta.shodan.io) to download data using your query credits.

Export credits were the first way I tried to monetize Shodan and it became a legacy system that lots of companies used so I was hesitant to get rid of it until something better was in place.

I'll also add that the API was purposely not designed for downloading lots of search results. The API is designed for security operations center (SOC) use cases. Companies that need large-scale, bulk access to our data would need to check out our enterprise platform (https://enterprise.shodan.io).

Re: New ‘Meow’ attack has deleted almost 4k unsecured databases

#187
post #146

Earlier quoted context omitted.

What happens when mom & pop are storing your name and credit card # in plain text and then your identity gets stolen and credit ruined? Should we still be "charitable" to them and their d-bag nephew?

Your credit card number being stolen is a problem for your bank, not a problem for you. You can't steal someone's identity with a credit card number. The concern in this case is when there is some social problem with being in Mom & Pop Inc's customer database. There are probably some people that buy some things that they don't want other people to know about. When the database gets hacked and you are linked to being…

It's a problem for the vendors, not the banks. They get hit with chargebacks for fraud that's no fault of their own, hurting the whole ecosystem of vendors and their customers.

https://www.thestreet.com/personal-finance/credit-cards/cred...

Re: New ‘Meow’ attack has deleted almost 4k unsecured databases

#189
post #134

Earlier quoted context omitted.

Maybe. However, if this was my diary or photoalbum, bank statements, medical reports or anything of that sort I’d rather have them destroyed than knowing that they may have been copied... The lesson is not for the people, it’s for the companies that take shortcuts to save money. It for the MBA’s that think things don’t have to be properly engineered.

So you are rationalizing a crime because it teaches companies a lesson? That is a crazy rejection of the rule of law. Would you be comfortable in applying that logic to all crimes?

I'm not gp, but let's take a step back for a sec.

(I've mostly lived in the northeastern US)

I live in a small (~20k population) rural technically-city (but... it's a town) where crime is not much of an issue; my car sits unlocked in my driveway and I seldom lock my house -- when I do, it's almost always when I'm at home (alone) -- it's about a feeling of security, not any real risk of a break-in. I've lived this way in this town for many years and have never experienced a robbery. I think it's pretty low risk, not irresponsible.

I've also lived in a larger city. There, I absolutely locked my doors. And I've traveled to tourist-y locations known for pickpockets, and kept an even closer watch on my belongings.

The internet is two orders of magnitude larger than the world's largest city and policing it is exceptionally difficult, since it spans national borders. There will be crime.

I wish this weren't the case. I much prefer living in a safe place where I don't have to worry about locking my doors when I go out. But when crime is common, it's negligent not to protect against it.

Re: New ‘Meow’ attack has deleted almost 4k unsecured databases

#190

Why must some people insist on being assholes?

> Why must some people insist on being assholes? The ones leaving giant databases unsecured? At least they are being taught an important lesson.

My blame scale for breaches, most to least:

1) the cultural and economic forces driving everything online way before that’s anything like a good idea,

2) companies storing more than they need to,

3) the people who left it unsecured (bigco, tech startups, and anything very sensitive),

4) the people stealing data,

5) the people who left it unsecured (Smaller shops that’ve been made to feel they must be online),

[large gap]

20) someone who simply deletes all the insecure data (assuming they didn’t also steal all of it)

Post reply on HN