Live data from Hacker News

Billion-record stolen Chinese database for sale on breach forum

theregister.com

21–30 of 258 posts

Re: Billion-record stolen Chinese database for sale on breach forum

#21
post #19
post #16

Apparently there was a "blogpost" of a developer showing of their code, where they accidentally leaked access tokens in a piece of commented code: https://archive.ph/mP3bh This is completely unverified though, so take it with a grain of salt.

Binance CEO confirmed this version: https://twitter.com/cz_binance/status/1543905416748359680

Starting today, this will be known as "Shanghai'd credentials" and be reason #1 why we use ephemeral credentials (e.g. AWS STS/SSO) rather than static credentials (e.g. IAM Users)

Re: Billion-record stolen Chinese database for sale on breach forum

#22
post #19
post #16

Apparently there was a "blogpost" of a developer showing of their code, where they accidentally leaked access tokens in a piece of commented code: https://archive.ph/mP3bh This is completely unverified though, so take it with a grain of salt.

Binance CEO confirmed this version: https://twitter.com/cz_binance/status/1543905416748359680

This is less a confirmation but more of a "piggybacking".

Re: Billion-record stolen Chinese database for sale on breach forum

#24
The Shanghai police has a unique role in China and abroad. For example the Shanghai police is tasked with spreading pro-CCP propaganda globally on platforms like twitter and Facebook.

There was an HN post about this a few months ago:

https://news.ycombinator.com/item?id=29654137

Someone posted a comment explaining a little more about Shanghai's special relationship with the CCP/PLA:

>Shanghai is a city with a unique role in the progression of the CCP and its global efforts. Also PLA Unit 61398 is in Pudong, the shanghai district mentioned in the article. Overall there's a lot of CCP/PLA-adjacent tech talent in the area, and of course the local police still ultimately report to the CCP.

https://news.ycombinator.com/item?id=29656017

Re: Billion-record stolen Chinese database for sale on breach forum

#25
post #9
post #3

What do we do now? It seems the majority of people on the planet now have had some of their data leaked. Or are becoming ever more entangled with government and corporate systems which control and peddle their information as they see fit. Is it ultimately a big nothing burger, or is this some singularity we are passing through?

A lot of data may be made public to equalize, similarly to how real estate property rights or car registries may be public.

I would counter that, although it could, some groups will be able to evade it, effectively maintaining their advantage/power. Effectively averaging out the position of middle and lower classes, and lowering their chances of moving up the social ladder?

Re: Billion-record stolen Chinese database for sale on breach forum

#27

In 2018 I saw a local branch office were using Windows XP and an old Internet Explorer. You cannot expect that to be secure. This does not surprise me at all.

Surprise, it's 2022, and XP is still a de-facto standard Windows version, with hacked Win7 slowly gaining.

Why? Tons of Software was written for XP, and then abandoned without any support. Many of that stuff in the government sector. A lot of online banking clients outright say "only works on XP," and copyright years reads 2006.

This is similar how Android 7+ support was almost nuked in China for nearly a year because Tencent didn't want to port Wechat to newer APIs cuz "nobody uses Android newer than 4.X in China"

Re: Billion-record stolen Chinese database for sale on breach forum

#28
post #20

Quoted post unavailable.

Governments have been collecting (and poorly securing) this sort of information and more for most of recorded history. It's not to say that I like it, or would work for somewhere like Meta or the like, but plenty of these major data leaks have been from places that used to collect and store physical data bases of this stuff since before most of us were alive. I'm talking calmly about this because people have been scr…

[flagged]

Re: Billion-record stolen Chinese database for sale on breach forum

#30
post #19

Earlier quoted context omitted.

Binance CEO confirmed this version: https://twitter.com/cz_binance/status/1543905416748359680

Starting today, this will be known as "Shanghai'd credentials" and be reason #1 why we use ephemeral credentials (e.g. AWS STS/SSO) rather than static credentials (e.g. IAM Users)

I never heard about "ephemeral credentials" before your post. I have some Googling to do!
Post reply on HN