Live data from Hacker News

Billion-record stolen Chinese database for sale on breach forum

theregister.com

61–70 of 258 posts

Re: Billion-record stolen Chinese database for sale on breach forum

#61
post #24

The Shanghai police has a unique role in China and abroad. For example the Shanghai police is tasked with spreading pro-CCP propaganda globally on platforms like twitter and Facebook. There was an HN post about this a few months ago: https://news.ycombinator.com/item?id=29654137 Someone posted a comment explaining a little more about Shanghai's special relationship with the CCP/PLA: >Shanghai is a city with a unique…

So I'm guessing that database would have quite a few activists listed in it and other anti-government people. Might even give someone a much-needed warning if they find themselves there.

I was having this exact conversation with a friend last night. Give them warning, especially people in Hong Kong.

Re: Billion-record stolen Chinese database for sale on breach forum

#62
post #3

What do we do now? It seems the majority of people on the planet now have had some of their data leaked. Or are becoming ever more entangled with government and corporate systems which control and peddle their information as they see fit. Is it ultimately a big nothing burger, or is this some singularity we are passing through?

All you can do (in the USA) is freeze your credit and sign up for one of the free (or paid) credit monitoring services. That only protects you from financial ruin though. Not sure about people using your credentials to commit fraud, fake birth certificates, etc.

Re: Billion-record stolen Chinese database for sale on breach forum

#64
post #11

Is it 1 billion in long scale or small scale?

Why would it be in long scale? Is long scale even used in english at all?

It was a joke. But it made me realize, thanks to the comment above, that Earth's population is around 8 thousand millions, and not 8 billion as I'd come to believe.

Re: Billion-record stolen Chinese database for sale on breach forum

#65

Earlier quoted context omitted.

"Who would buy this?" Foreign intelligence agencies for classic espionage. If you want to do blackmailing in china, such a DB would be a good start. Otherwise, data brokers. Advertisement, financial credibility, trustworthines of buisness partners etc.

I don't know how it works in China but where I am a person's criminal record is not public but not exactly private either. In the sense that an employer can ask for your criminal record and you have the choice giving a printout of it or not having your job. Making it kind of hard to see how the knowledge of a criminal record could be used to blackmail someeone. As for "data brokers. Advertisement, financial credibili…

It is likely, that this DB contains more information, than what a formal printout gives.

"But these companies would turn themselves into criminals by using or purchasing this information."

Which is why they probably would not deal with the information gathering directly, but use a service of a data analyst company. When they do something illegal, nobody who contracted then did ever know anything. I think this game is played in china as well.

Re: Billion-record stolen Chinese database for sale on breach forum

#66
post #15

This has to be the largest leak of personal information yet, right?

Facebook leaked much more couple years ago. Somehow everyone has forget that. Some example news: https://www.privacyaffairs.com/facebook-data-sold-on-hacker-...

That was not a data leak. It was a compilation of scraped, publicly available data.

Re: Billion-record stolen Chinese database for sale on breach forum

#67
post #3

What do we do now? It seems the majority of people on the planet now have had some of their data leaked. Or are becoming ever more entangled with government and corporate systems which control and peddle their information as they see fit. Is it ultimately a big nothing burger, or is this some singularity we are passing through?

> What do we do now?

Well, if you look at (global) society as a dynamical system it seems to me that there are two stable basins or attractors, call them "Star Trek" and "North Korea".

In the "Star Trek" future the people in charge are themselves also subject to the panopticon, and the world is ruled fairly and humanely. (The other name I use for this is the "Tyranny of Mrs. Grundy".)

In the "North Korea" future there are (human or AI or hybrid) masters and brain-chipped cyborg slaves, and rule is absolute and enforced with digital precision.

(Of course, this is all predicated on the idea that we can't put the genie back in the bottle in re: ubiquitous surveillance. I think that's likely the case (although I do not like it) but I'm not going to make the argument here unless someone asks.)

Given the above the thing to do is work to make politicians subject to 24/7 total surveillance (ASAP, before everybody else) so we can keep an eye on them. This policy would also presumably weed out the crazies and corrupt, eh?

Re: Billion-record stolen Chinese database for sale on breach forum

#68
Related:

Hacker claims they stole police data on a billion Chinese citizens - https://news.ycombinator.com/item?id=31984663 - July 2022 (1 comment)

Hacker claims to have obtained data on 1B Chinese citizens - https://news.ycombinator.com/item?id=31980101 - July 2022 (1 comment)

Hacker claims to have stolen 1 bln records of Chinese citizens from police - https://news.ycombinator.com/item?id=31977354 - July 2022 (1 comment)

Police data of 1B Chinese people leaked - https://news.ycombinator.com/item?id=31969617 - July 2022 (4 comments)

Shanghai Police leaking 20TB Chinese citizens data? - https://news.ycombinator.com/item?id=31962526 - July 2022 (3 comments)

Re: Billion-record stolen Chinese database for sale on breach forum

#69
post #50
post #18

Earlier quoted context omitted.

IIRC when Nazi Germany invaded Denmark in 1940, one of the first things the SS did was to send representatives to the local churches. In Denmark, every child was (I’m not sure if they still are actually?) registered at birth by the local parish in so called “church books”. With these “databases” in hand, the SS had a neat list of all names, and the approximate location of peoples homes. Those lists were used to ident…

IIRC there was a central registry of religion in the Netherlands that had the same effect. Can't find anything on that now, though (it's mentioned in Wikipedia in an unsourced paragraph; I think I first read about it on HN, actually). ----- Tangent: the info pages on the Anne Frank House site have sections cycling through different pastel background colours.[0] I've wondered before whether something like that would t…

> IIRC there was a central registry of religion in the Netherlands that had the same effect.

> I think I first read about it on HN, actually

That may have been my article:

https://jacquesmattheij.com/if-you-have-nothing-to-hide/

Re: Billion-record stolen Chinese database for sale on breach forum

#70
The leaked screenshot of the data's metadata looks like the output of Elasticsearch's /_cat command. Someone probably left the port 9200 open to the public, or stored the index on a public cloud but somehow leaked its keys either on github-like service or in some discussion forum -- a typical mistake that engineers make.
Post reply on HN