Earlier quoted context omitted.
Wow that's bigger than Equifax
The linkedin "leak" was just a scrape of public data.
Billion-record stolen Chinese database for sale on breach forum
131–140 of 258 posts
Re: Billion-record stolen Chinese database for sale on breach forum
#132Earlier quoted context omitted.
I wonder if you could make a luhn-like check that would require an additional approval step to post if it comes back positive. Something like "It looks like you may be posting a secret *****. Do you wish to continue?
If vendors agreed to a common prefix on all secret key values then it'd be easy for everyone to add checks, to everything. Something like "_SECRET88_". Of course, then your secret key checker would need to build that string by concatenating so that it wouldn't set off itself.
Re: Billion-record stolen Chinese database for sale on breach forum
#133Re: Billion-record stolen Chinese database for sale on breach forum
#134What do we do now? It seems the majority of people on the planet now have had some of their data leaked. Or are becoming ever more entangled with government and corporate systems which control and peddle their information as they see fit. Is it ultimately a big nothing burger, or is this some singularity we are passing through?
I was thinking - if I had this, what could I do with the personal records of a billion Chinese people?
And I must conclude - absolutely nothing. It's of no interest to me.
Now, I probably lack sufficient criminal imagination, but the point is stuff like this is hard to fence because there's a very small market of buyers. In an article I wrote for Routledge about the markets for stolen digital data (specifically movie and album releases) I suggested that the underlying problem is there's symbiosis between leakers and buyers.
If you want to do anything, target the buyers. There's less of them. Don't try to secure inherently insecure massively centralised systems (Blotto + Dolev Yeo problem) . Or chase leakers. Or blame users. Or fire the CIO. Find out who wants this stuff and take down the show from the demand-side.
But hold on! Guess who the buyers are. And guess what sincere will exists within "law enforcement" to tackle this sort of "cybercrime".
Re: Billion-record stolen Chinese database for sale on breach forum
#135Karen Hao (WSJ): "I downloaded the sample the hacker provided and called dozens of people listed. Nine picked up & confirmed exactly what the data said." https://twitter.com/_KarenHao/status/1543949945614393344 (thread)
Re: Billion-record stolen Chinese database for sale on breach forum
#136Earlier quoted context omitted.
Well, leak can mean a lot of things. The standard "leak" of names and addresses of people is totally meaningless, though HN "privacy" obsessives blow it out of the water all the time. It's basically public information, we used to have everyone in phone books in the US and almost no one cared. Cell phone number is a riskier one because of the opportunity for 2FA hacks. It's not hard to get people's cell phone numbers…
Names and addresses can absolutely be used to stalk and harass people, and there are password reset flows that involve physically mailing secrets to people. Perhaps almost no one cared about phone books, but if you thought about the differences between phone books and a website for a moment, you'd see that these are different technologies that have different implications, and that it is entirely reasonable for people…
Re: Billion-record stolen Chinese database for sale on breach forum
#137Re: Billion-record stolen Chinese database for sale on breach forum
#138Earlier quoted context omitted.
Binance CEO confirmed this version: https://twitter.com/cz_binance/status/1543905416748359680
Starting today, this will be known as "Shanghai'd credentials" and be reason #1 why we use ephemeral credentials (e.g. AWS STS/SSO) rather than static credentials (e.g. IAM Users)
Re: Billion-record stolen Chinese database for sale on breach forum
#139Earlier quoted context omitted.
Binance CEO confirmed this version: https://twitter.com/cz_binance/status/1543905416748359680
Starting today, this will be known as "Shanghai'd credentials" and be reason #1 why we use ephemeral credentials (e.g. AWS STS/SSO) rather than static credentials (e.g. IAM Users)
Re: Billion-record stolen Chinese database for sale on breach forum
#140Earlier quoted context omitted.
nitter link, since Twitter put up what seems to be a timed login gate when I was halfway through reading the thread: https://nitter.net/_KarenHao/status/1543949945614393344
The app download nags on mobile web are so unbearable I stopped using Twitter entirely
Basically just about every app (YouTube, Reddit, Facebook, ...) is better this way. I.e., no ads, erase-able elements, less spyware, defaults to no notification and sometimes even gets better functionality. For instance, it (browsers) gets rid of "hearts" in Duolingo for whatever damn reason, so you can practice however much you'd like in a day.
The downsides I've found is that you seemingly can't Chrome-cast from it, and it often creates new tabs instead of reusing existing ones or making it's own app-instance, so you gotta close all tabs every so often.