Earlier quoted context omitted.
In history what have databases of people and state actor interests usually led to if any events are similar?
IIRC when Nazi Germany invaded Denmark in 1940, one of the first things the SS did was to send representatives to the local churches. In Denmark, every child was (I’m not sure if they still are actually?) registered at birth by the local parish in so called “church books”. With these “databases” in hand, the SS had a neat list of all names, and the approximate location of peoples homes. Those lists were used to ident…
Billion-record stolen Chinese database for sale on breach forum
31–40 of 258 posts
Re: Billion-record stolen Chinese database for sale on breach forum
#32Earlier quoted context omitted.
In history what have databases of people and state actor interests usually led to if any events are similar?
IIRC when Nazi Germany invaded Denmark in 1940, one of the first things the SS did was to send representatives to the local churches. In Denmark, every child was (I’m not sure if they still are actually?) registered at birth by the local parish in so called “church books”. With these “databases” in hand, the SS had a neat list of all names, and the approximate location of peoples homes. Those lists were used to ident…
"Machine-tabulated census data greatly expanded the estimated number of Jews in Germany by identifying individuals with only one or a few Jewish ancestors. Previous estimates of 400,000 to 600,000 were abandoned for a new estimate of 2 million Jews."
[0]: https://en.wikipedia.org/wiki/IBM_and_the_Holocaust
Re: Billion-record stolen Chinese database for sale on breach forum
#33The Shanghai police has a unique role in China and abroad. For example the Shanghai police is tasked with spreading pro-CCP propaganda globally on platforms like twitter and Facebook. There was an HN post about this a few months ago: https://news.ycombinator.com/item?id=29654137 Someone posted a comment explaining a little more about Shanghai's special relationship with the CCP/PLA: >Shanghai is a city with a unique…
Re: Billion-record stolen Chinese database for sale on breach forum
#34Apparently there was a "blogpost" of a developer showing of their code, where they accidentally leaked access tokens in a piece of commented code: https://archive.ph/mP3bh This is completely unverified though, so take it with a grain of salt.
I can't count the amount of SO questions I've had to edit from others posting live API Keys for everything from custom services to AWS.
Re: Billion-record stolen Chinese database for sale on breach forum
#35What do we do now? It seems the majority of people on the planet now have had some of their data leaked. Or are becoming ever more entangled with government and corporate systems which control and peddle their information as they see fit. Is it ultimately a big nothing burger, or is this some singularity we are passing through?
It is both. It is huge, I'd say it's absolutely the latter. but I can't think of a single thing anyone can do about any of it at this point, which also makes it the former.
Re: Billion-record stolen Chinese database for sale on breach forum
#36Earlier quoted context omitted.
In history what have databases of people and state actor interests usually led to if any events are similar?
IIRC when Nazi Germany invaded Denmark in 1940, one of the first things the SS did was to send representatives to the local churches. In Denmark, every child was (I’m not sure if they still are actually?) registered at birth by the local parish in so called “church books”. With these “databases” in hand, the SS had a neat list of all names, and the approximate location of peoples homes. Those lists were used to ident…
Re: Billion-record stolen Chinese database for sale on breach forum
#37Earlier quoted context omitted.
Starting today, this will be known as "Shanghai'd credentials" and be reason #1 why we use ephemeral credentials (e.g. AWS STS/SSO) rather than static credentials (e.g. IAM Users)
I never heard about "ephemeral credentials" before your post. I have some Googling to do!
Re: Billion-record stolen Chinese database for sale on breach forum
#38Earlier quoted context omitted.
IIRC when Nazi Germany invaded Denmark in 1940, one of the first things the SS did was to send representatives to the local churches. In Denmark, every child was (I’m not sure if they still are actually?) registered at birth by the local parish in so called “church books”. With these “databases” in hand, the SS had a neat list of all names, and the approximate location of peoples homes. Those lists were used to ident…
Church books were used to find Jews? Do you have a source for that?
If you know who to rule out, you have a smaller pool of people to go after.
Re: Billion-record stolen Chinese database for sale on breach forum
#39Earlier quoted context omitted.
IIRC when Nazi Germany invaded Denmark in 1940, one of the first things the SS did was to send representatives to the local churches. In Denmark, every child was (I’m not sure if they still are actually?) registered at birth by the local parish in so called “church books”. With these “databases” in hand, the SS had a neat list of all names, and the approximate location of peoples homes. Those lists were used to ident…
"Fun" fact: It was IBM who helped tabulate data from the 1933 national census, which was then used to identify hundreds of thousands more Jews than would have been found by the Nazi party without their efforts. "Machine-tabulated census data greatly expanded the estimated number of Jews in Germany by identifying individuals with only one or a few Jewish ancestors. Previous estimates of 400,000 to 600,000 were abandon…
The IBM subsidiary in Nazi Germany selling and maintaining the tabulating machines was DeHoMag, Deutsche Hollerith Maschinen AG.
...
Re: Billion-record stolen Chinese database for sale on breach forum
#40Earlier quoted context omitted.
Binance CEO confirmed this version: https://twitter.com/cz_binance/status/1543905416748359680
Starting today, this will be known as "Shanghai'd credentials" and be reason #1 why we use ephemeral credentials (e.g. AWS STS/SSO) rather than static credentials (e.g. IAM Users)