Live data from Hacker News

Billion-record stolen Chinese database for sale on breach forum

theregister.com

121–130 of 258 posts

Re: Billion-record stolen Chinese database for sale on breach forum

#121
post #16

Apparently there was a "blogpost" of a developer showing of their code, where they accidentally leaked access tokens in a piece of commented code: https://archive.ph/mP3bh This is completely unverified though, so take it with a grain of salt.

poor developer. He may spend this life at a "re-education camp"

Re: Billion-record stolen Chinese database for sale on breach forum

#122

The leaked screenshot of the data's metadata looks like the output of Elasticsearch's /_cat command. Someone probably left the port 9200 open to the public, or stored the index on a public cloud but somehow leaked its keys either on github-like service or in some discussion forum -- a typical mistake that engineers make.

https://www.alibabacloud.com/product/datahub is what they were using, and yeah their keys were in a commented out psvm tester method. pretty awful

Re: Billion-record stolen Chinese database for sale on breach forum

#123
post #11

Is it 1 billion in long scale or small scale?

For anyone wondering what that is, English uses short-scale, i.e. 1 billion = 1000 million, some other languages / countries use long-scale i.e. 1 billion = 1 million million.

https://en.wikipedia.org/wiki/Long_and_short_scales

Re: Billion-record stolen Chinese database for sale on breach forum

#124
post #42
post #36

Earlier quoted context omitted.

Church books were used to find Jews? Do you have a source for that?

Antisemitism was not really about religion. Many Jews had actually converted to Christianity for generations. The Nazis still considered them to be Jews.

Ahh...well there is the famous saying, "I decide who is a Jew." It was used on the head of the German Manhattan Project and a Jewish head (like a headmaster some shit) of a concentration camp, forget which one. And that's why we say "German Manhattan Project" stedda "Americaner Atomwaffenunternehmen" (I made that word up, it is correct in German to make words up, that means atom weapon undertaking), because German antisemitism amounted to forfeiting the bomb.

That was the price, the defeat of their last hope against the Allies. All of the Great Jews that slapped those firecrackers together were exiled due to antisemitism: Fermi, Szílard, Einstein (to get the president to read the letter to get the Los Alamos show on the road in the first place, get Roosevelt to read top to bottom left to right, no easy task), von Neumann (spesh because of his schizophrenia, no concentration camp for him, he would have been experimented on to then do that same sin to everybody in the camps, Schizophrenic Jews were at the absolute bottom o the Nazi world order).

I just posted about this. https://news.ycombinator.com/item?id=31990431

Fermi was originally a fascist, it basically made sense to him as a way of organizing a country.

Only non-Jew in the top desks of Los Alamos. Why? Only when the racial laws against his Jewish wife and children did he pack his shit and leave for America.

And Fermi was packing heat.

Re: Billion-record stolen Chinese database for sale on breach forum

#125

Earlier quoted context omitted.

In history what have databases of people and state actor interests usually led to if any events are similar?

Not quite the same, but the US used census records that were supposed to be protected to round up the west coast japanese for their internment during WWII.

They were "protected". That is, they didn't leak out of the government into private hands. But that still turned out pretty badly.

In fact, information in the government's hands is the most dangerous, because they have more power than anyone else to use it against you.

(On the other hand, as others have said about Denmark and Netherlands, data that was not in government hands became in government hands, and was used against people. So it's not "safer" if it's in private hands, except to the degree that the government has to go through the extra step of getting it.)

Re: Billion-record stolen Chinese database for sale on breach forum

#126
post #107
post #17

Earlier quoted context omitted.

The previous big case I remember was linkedin leak with 700M users: https://news.ycombinator.com/item?id=27674393 At this point I've basically accepted that all my info will be found on sites like fastpeoplesearch.com and that anything I tell any company (or I guess in this case, govt too) will eventually be leaked, correlated, and used against me.

Wow that's bigger than Equifax

The linkedin "leak" was just a scrape of public data.

Re: Billion-record stolen Chinese database for sale on breach forum

#127
post #53
post #3

What do we do now? It seems the majority of people on the planet now have had some of their data leaked. Or are becoming ever more entangled with government and corporate systems which control and peddle their information as they see fit. Is it ultimately a big nothing burger, or is this some singularity we are passing through?

Covid is a good excuse to wear a mask, and pair it with a set of mirror sun glasses in public. Maybe that's how we live now.

We should probably consider a person's voice-print, too. To be safe, you need a mask with a real-time voice changer.

Re: Billion-record stolen Chinese database for sale on breach forum

#128
post #115

Earlier quoted context omitted.

I wonder if you could make a luhn-like check that would require an additional approval step to post if it comes back positive. Something like "It looks like you may be posting a secret *****. Do you wish to continue?

If vendors agreed to a common prefix on all secret key values then it'd be easy for everyone to add checks, to everything. Something like "_SECRET88_". Of course, then your secret key checker would need to build that string by concatenating so that it wouldn't set off itself.

More and more providers have been adding unique prefixes to their tokens and access keys which makes detection much easier. Ex, GitLab adds `glpat-` to their PAT.

A project I maintain, Gitleaks, can easily detect "unique" secrets and does a pretty good job at detecting "generic" secrets too. In this case, the generic gitleaks rule would have caught the secrets [1]. You can see the full rule definition here [2] and how the rule is constructed here [3].

[1] https://regex101.com/r/CLg9TK/1

[2] https://github.com/zricethezav/gitleaks/blob/master/config/g...

[3] https://github.com/zricethezav/gitleaks/blob/master/cmd/gene...

Re: Billion-record stolen Chinese database for sale on breach forum

#129

Earlier quoted context omitted.

nitter link, since Twitter put up what seems to be a timed login gate when I was halfway through reading the thread: https://nitter.net/_KarenHao/status/1543949945614393344

Nitter is the only sane way to read twitter nowadays. Even if I still had an account it would be better for reading.

I keep getting timeouts from them interestingly

Re: Billion-record stolen Chinese database for sale on breach forum

#130
post #3

What do we do now? It seems the majority of people on the planet now have had some of their data leaked. Or are becoming ever more entangled with government and corporate systems which control and peddle their information as they see fit. Is it ultimately a big nothing burger, or is this some singularity we are passing through?

> What do we do now? Well, if you look at (global) society as a dynamical system it seems to me that there are two stable basins or attractors, call them "Star Trek" and "North Korea". In the "Star Trek" future the people in charge are themselves also subject to the panopticon, and the world is ruled fairly and humanely. (The other name I use for this is the "Tyranny of Mrs. Grundy".) In the "North Korea" future ther…

> Well, if you look at (global) society as a dynamical system it seems to me that there are two stable basins or attractors, call them "Star Trek" and "North Korea".

Nice analogy. Do you really believe, that us being on an utopian trajectory is realistic?

Post reply on HN