Apparently there was a "blogpost" of a developer showing of their code, where they accidentally leaked access tokens in a piece of commented code: https://archive.ph/mP3bh This is completely unverified though, so take it with a grain of salt.
Binance CEO confirmed this version: https://twitter.com/cz_binance/status/1543905416748359680
Billion-record stolen Chinese database for sale on breach forum
21–30 of 258 posts
Re: Billion-record stolen Chinese database for sale on breach forum
#22Apparently there was a "blogpost" of a developer showing of their code, where they accidentally leaked access tokens in a piece of commented code: https://archive.ph/mP3bh This is completely unverified though, so take it with a grain of salt.
Binance CEO confirmed this version: https://twitter.com/cz_binance/status/1543905416748359680
Re: Billion-record stolen Chinese database for sale on breach forum
#23Quoted post unavailable.
Re: Billion-record stolen Chinese database for sale on breach forum
#24There was an HN post about this a few months ago:
https://news.ycombinator.com/item?id=29654137
Someone posted a comment explaining a little more about Shanghai's special relationship with the CCP/PLA:
>Shanghai is a city with a unique role in the progression of the CCP and its global efforts. Also PLA Unit 61398 is in Pudong, the shanghai district mentioned in the article. Overall there's a lot of CCP/PLA-adjacent tech talent in the area, and of course the local police still ultimately report to the CCP.
Re: Billion-record stolen Chinese database for sale on breach forum
#25What do we do now? It seems the majority of people on the planet now have had some of their data leaked. Or are becoming ever more entangled with government and corporate systems which control and peddle their information as they see fit. Is it ultimately a big nothing burger, or is this some singularity we are passing through?
A lot of data may be made public to equalize, similarly to how real estate property rights or car registries may be public.
Re: Billion-record stolen Chinese database for sale on breach forum
#26Is it 1 billion in long scale or small scale?
Re: Billion-record stolen Chinese database for sale on breach forum
#27In 2018 I saw a local branch office were using Windows XP and an old Internet Explorer. You cannot expect that to be secure. This does not surprise me at all.
Why? Tons of Software was written for XP, and then abandoned without any support. Many of that stuff in the government sector. A lot of online banking clients outright say "only works on XP," and copyright years reads 2006.
This is similar how Android 7+ support was almost nuked in China for nearly a year because Tencent didn't want to port Wechat to newer APIs cuz "nobody uses Android newer than 4.X in China"
Re: Billion-record stolen Chinese database for sale on breach forum
#28Quoted post unavailable.
Governments have been collecting (and poorly securing) this sort of information and more for most of recorded history. It's not to say that I like it, or would work for somewhere like Meta or the like, but plenty of these major data leaks have been from places that used to collect and store physical data bases of this stuff since before most of us were alive. I'm talking calmly about this because people have been scr…
Re: Billion-record stolen Chinese database for sale on breach forum
#29Re: Billion-record stolen Chinese database for sale on breach forum
#30Earlier quoted context omitted.
Binance CEO confirmed this version: https://twitter.com/cz_binance/status/1543905416748359680
Starting today, this will be known as "Shanghai'd credentials" and be reason #1 why we use ephemeral credentials (e.g. AWS STS/SSO) rather than static credentials (e.g. IAM Users)