The Shanghai police has a unique role in China and abroad. For example the Shanghai police is tasked with spreading pro-CCP propaganda globally on platforms like twitter and Facebook. There was an HN post about this a few months ago: https://news.ycombinator.com/item?id=29654137 Someone posted a comment explaining a little more about Shanghai's special relationship with the CCP/PLA: >Shanghai is a city with a unique…
Billion-record stolen Chinese database for sale on breach forum
101–110 of 258 posts
Re: Billion-record stolen Chinese database for sale on breach forum
#102Re: Billion-record stolen Chinese database for sale on breach forum
#103Earlier quoted context omitted.
It's incredibly disappointing actually how often this happens. I can't count the amount of SO questions I've had to edit from others posting live API Keys for everything from custom services to AWS.
I wonder if you could make a luhn-like check that would require an additional approval step to post if it comes back positive. Something like "It looks like you may be posting a secret *****. Do you wish to continue?
Something like giving false confidence to the user. Not the best idea.
Re: Billion-record stolen Chinese database for sale on breach forum
#104Earlier quoted context omitted.
When you do this is there a way to completely get rid of the information? Usually you can go back an look at the edit history to see the original post.
Wouldn't matter. Tons of bots are scraping every inch of the internet all the time, and if something been online for five seconds, it has been cached/stored somewhere. Always assume that anything you've put up on the internet, can forever be accessed by someone . The only thing you can do is rotating the token/secret.
Re: Billion-record stolen Chinese database for sale on breach forum
#105The Shanghai police has a unique role in China and abroad. For example the Shanghai police is tasked with spreading pro-CCP propaganda globally on platforms like twitter and Facebook. There was an HN post about this a few months ago: https://news.ycombinator.com/item?id=29654137 Someone posted a comment explaining a little more about Shanghai's special relationship with the CCP/PLA: >Shanghai is a city with a unique…
So I'm guessing that database would have quite a few activists listed in it and other anti-government people. Might even give someone a much-needed warning if they find themselves there.
Re: Billion-record stolen Chinese database for sale on breach forum
#106In 2018 I saw a local branch office were using Windows XP and an old Internet Explorer. You cannot expect that to be secure. This does not surprise me at all.
XP is very common on airports in China too.
Re: Billion-record stolen Chinese database for sale on breach forum
#107What do we do now? It seems the majority of people on the planet now have had some of their data leaked. Or are becoming ever more entangled with government and corporate systems which control and peddle their information as they see fit. Is it ultimately a big nothing burger, or is this some singularity we are passing through?
The previous big case I remember was linkedin leak with 700M users: https://news.ycombinator.com/item?id=27674393 At this point I've basically accepted that all my info will be found on sites like fastpeoplesearch.com and that anything I tell any company (or I guess in this case, govt too) will eventually be leaked, correlated, and used against me.
Re: Billion-record stolen Chinese database for sale on breach forum
#108Apparently there was a "blogpost" of a developer showing of their code, where they accidentally leaked access tokens in a piece of commented code: https://archive.ph/mP3bh This is completely unverified though, so take it with a grain of salt.
Re: Billion-record stolen Chinese database for sale on breach forum
#109Karen Hao (WSJ): "I downloaded the sample the hacker provided and called dozens of people listed. Nine picked up & confirmed exactly what the data said." https://twitter.com/_KarenHao/status/1543949945614393344 (thread)
nitter link, since Twitter put up what seems to be a timed login gate when I was halfway through reading the thread: https://nitter.net/_KarenHao/status/1543949945614393344
Re: Billion-record stolen Chinese database for sale on breach forum
#110Apparently there was a "blogpost" of a developer showing of their code, where they accidentally leaked access tokens in a piece of commented code: https://archive.ph/mP3bh This is completely unverified though, so take it with a grain of salt.
[1] https://regex101.com/r/CLg9TK/1
[2] https://github.com/zricethezav/gitleaks/blob/master/config/g...