Live data from Hacker News

Billion-record stolen Chinese database for sale on breach forum

theregister.com

131–140 of 258 posts

Re: Billion-record stolen Chinese database for sale on breach forum

#131
post #107

Earlier quoted context omitted.

Wow that's bigger than Equifax

The linkedin "leak" was just a scrape of public data.

Is there any word out how they managed to avoid linkedins relentless rate limiting? For example my account gets rate limited for normal browsing

Re: Billion-record stolen Chinese database for sale on breach forum

#132
post #115

Earlier quoted context omitted.

I wonder if you could make a luhn-like check that would require an additional approval step to post if it comes back positive. Something like "It looks like you may be posting a secret *****. Do you wish to continue?

If vendors agreed to a common prefix on all secret key values then it'd be easy for everyone to add checks, to everything. Something like "_SECRET88_". Of course, then your secret key checker would need to build that string by concatenating so that it wouldn't set off itself.

How about scanning for any string with high entropy? Might be easier to get buy-in if we don’t all have to bike-shed over what the prefix is.

Re: Billion-record stolen Chinese database for sale on breach forum

#134
post #3

What do we do now? It seems the majority of people on the planet now have had some of their data leaked. Or are becoming ever more entangled with government and corporate systems which control and peddle their information as they see fit. Is it ultimately a big nothing burger, or is this some singularity we are passing through?

> What do we do now?

I was thinking - if I had this, what could I do with the personal records of a billion Chinese people?

And I must conclude - absolutely nothing. It's of no interest to me.

Now, I probably lack sufficient criminal imagination, but the point is stuff like this is hard to fence because there's a very small market of buyers. In an article I wrote for Routledge about the markets for stolen digital data (specifically movie and album releases) I suggested that the underlying problem is there's symbiosis between leakers and buyers.

If you want to do anything, target the buyers. There's less of them. Don't try to secure inherently insecure massively centralised systems (Blotto + Dolev Yeo problem) . Or chase leakers. Or blame users. Or fire the CIO. Find out who wants this stuff and take down the show from the demand-side.

But hold on! Guess who the buyers are. And guess what sincere will exists within "law enforcement" to tackle this sort of "cybercrime".

Re: Billion-record stolen Chinese database for sale on breach forum

#135
post #55

Karen Hao (WSJ): "I downloaded the sample the hacker provided and called dozens of people listed. Nine picked up & confirmed exactly what the data said." https://twitter.com/_KarenHao/status/1543949945614393344 (thread)

That WSJ article is so much better than the posted one, I mean what even is "the register"

Re: Billion-record stolen Chinese database for sale on breach forum

#136
post #91
post #85

Earlier quoted context omitted.

Well, leak can mean a lot of things. The standard "leak" of names and addresses of people is totally meaningless, though HN "privacy" obsessives blow it out of the water all the time. It's basically public information, we used to have everyone in phone books in the US and almost no one cared. Cell phone number is a riskier one because of the opportunity for 2FA hacks. It's not hard to get people's cell phone numbers…

Names and addresses can absolutely be used to stalk and harass people, and there are password reset flows that involve physically mailing secrets to people. Perhaps almost no one cared about phone books, but if you thought about the differences between phone books and a website for a moment, you'd see that these are different technologies that have different implications, and that it is entirely reasonable for people…

Names and addresses are already public information in the US. It's not that big of a deal.

Re: Billion-record stolen Chinese database for sale on breach forum

#138
post #19

Earlier quoted context omitted.

Binance CEO confirmed this version: https://twitter.com/cz_binance/status/1543905416748359680

Starting today, this will be known as "Shanghai'd credentials" and be reason #1 why we use ephemeral credentials (e.g. AWS STS/SSO) rather than static credentials (e.g. IAM Users)

This is not at all the takeaway from this. It's "this shitty developer should not have had access to this data in the first place". With a nuance of "this database probably shouldn't exist in this form in one place to begin with".

Re: Billion-record stolen Chinese database for sale on breach forum

#139
post #19

Earlier quoted context omitted.

Binance CEO confirmed this version: https://twitter.com/cz_binance/status/1543905416748359680

Starting today, this will be known as "Shanghai'd credentials" and be reason #1 why we use ephemeral credentials (e.g. AWS STS/SSO) rather than static credentials (e.g. IAM Users)

Let's not. After the whole "China Virus" shit propagated by the right, I'd prefer if we tried not to associate vulnerabilities with specific people.

Re: Billion-record stolen Chinese database for sale on breach forum

#140

Earlier quoted context omitted.

nitter link, since Twitter put up what seems to be a timed login gate when I was halfway through reading the thread: https://nitter.net/_KarenHao/status/1543949945614393344

The app download nags on mobile web are so unbearable I stopped using Twitter entirely

I made a webapp home icon from my Firefox and picked out the app-bait popover with uBlock.

Basically just about every app (YouTube, Reddit, Facebook, ...) is better this way. I.e., no ads, erase-able elements, less spyware, defaults to no notification and sometimes even gets better functionality. For instance, it (browsers) gets rid of "hearts" in Duolingo for whatever damn reason, so you can practice however much you'd like in a day.

The downsides I've found is that you seemingly can't Chrome-cast from it, and it often creates new tabs instead of reusing existing ones or making it's own app-instance, so you gotta close all tabs every so often.

Post reply on HN