Live data from Hacker News

Billion-record stolen Chinese database for sale on breach forum

theregister.com

191–200 of 258 posts

Re: Billion-record stolen Chinese database for sale on breach forum

#191

- 10 BTC sounds a lot but it's peanuts for such large data sets. - 750k row of sample data is large enough for a leak by itself, many on reddit/twitter/fediverse have already started to explore the data set for gender ratio, age composition and frequency of raping cases, etc.

>many on reddit/twitter/fediverse have already started to explore the data set for gender ratio, age composition and frequency of raping cases, etc. Any links?

Plenty of Chinese ones in subs like /r/China_irl etc., not seeing much traction of this story/dataset in Western world, though (hell, even on HN it barely got any upvotes 2 days ago.)

Re: Billion-record stolen Chinese database for sale on breach forum

#193

Earlier quoted context omitted.

> What do we do now? I was thinking - if I had this, what could I do with the personal records of a billion Chinese people? And I must conclude - absolutely nothing. It's of no interest to me. Now, I probably lack sufficient criminal imagination, but the point is stuff like this is hard to fence because there's a very small market of buyers. In an article I wrote for Routledge about the markets for stolen digital dat…

After my data was leaked, now scammers periodically call my phone to let me know that "I'm from bank security and someone's recently tried to change phone number for your bank account" or "I'm from police and we're opening a criminal case against you". It was fun first few times, but now I'm considering changing my phone number because I could miss an actual bank security call. And I'm sure that plenty of gullible pe…

My voicemail now indicates that I am no longer answering unknown numbers and to please leave a message or text me if you can.

It’s a little lengthy, but it’s cut down on the number of spam calls I actually answer specifically and I’m reasonably sure that anyone who actually needs to get a hold of me has an easy path to do so.

Re: Billion-record stolen Chinese database for sale on breach forum

#194

Earlier quoted context omitted.

If the records are digital and non-air-gapped in any system of any country, you can assume that the US government has access to those records already. The exceptions to this assumption are exceedingly rare.

As a US citizen I want to believe bravado like this but I’m guessing this is just your fantasy world talking not actual knowledge of the government being competent, which in my personal experience seems extremely unlikely.

The government isn't competent as a whole.. but the intelligence agencies are rather powerful. I've worked for DARPA and IARPA and you wouldn't believe half the stuff I could say publicly and none of the stuff I can't disclose.

Re: Billion-record stolen Chinese database for sale on breach forum

#195
post #107

Earlier quoted context omitted.

Wow that's bigger than Equifax

LinkedIn doesn't have my Social Security number. It doesn't have a list of my bank accounts and credit cards. So, more people, but less damaging information.

Yeah, that's like a "how do I top that?" situation (Equifax)

Re: Billion-record stolen Chinese database for sale on breach forum

#196
post #167

Earlier quoted context omitted.

There's just a lot of randomness in what gets attention/traction off /newest. That's why HN doesn't try to prevent reposts of stories that haven't had significant attention yet. It sucks when you're earlier and don't 'win', but it evens out in the long run if you post lots of good stories, since sometimes the lottery works in your favor. One of these years we'll get around to implementing karma-sharing to spread cred…

What's the point of "winning" if everything is made up and the points don't matter? I get there's satisfaction in posting content that was useful, and HN isn't Fb/Twitter/Reddit and awash in ad $, but I feel fake internet points kinda manipulative since there's $ for the platform in your work.

One benefit of "winning" is that HN gives more agency (i.e., the ability to downvote) to accounts that have over a certain karmic threshold.

Re: Billion-record stolen Chinese database for sale on breach forum

#197
post #186

Earlier quoted context omitted.

I like your approach. So far I used profiles extensively. AWS_PROFILE is your friend. No idea why AWS doesn't heavily promote this everywhere they can.

> No idea why AWS doesn't heavily promote this everywhere they can. Not Invented Here

AWS SSO solves it better, and for any number of AWS accounts.

I still use aws-vault, though, when I'm not in a position to set up AWS SSO.

Re: Billion-record stolen Chinese database for sale on breach forum

#198
post #187

Earlier quoted context omitted.

I like your approach. So far I used profiles extensively. AWS_PROFILE is your friend. No idea why AWS doesn't heavily promote this everywhere they can.

AWS best practices is to use AWS SSO, which accomplishes this same effect but without any long-lived local credentials. It works really well.

Depending on your IdP there's a few tools in addition to AWS CLI v2 that works well in this space.

aws-vault is one of them, though out of support now, aws-okta [1] is another.

[1] https://github.com/segmentio/aws-okta

Re: Billion-record stolen Chinese database for sale on breach forum

#199
post #167

Earlier quoted context omitted.

Thanks for reposting this. The last link submitted by me only got 3 upvotes. Guess it sounded just too crazy to be true 2 days ago!

There's just a lot of randomness in what gets attention/traction off /newest. That's why HN doesn't try to prevent reposts of stories that haven't had significant attention yet. It sucks when you're earlier and don't 'win', but it evens out in the long run if you post lots of good stories, since sometimes the lottery works in your favor. One of these years we'll get around to implementing karma-sharing to spread cred…

I’m not interesting in “winning” points but do hoped this important story gets revealed and discussed earlier in this community I enjoyed participating. Thanks for taking time explaining this and appreciate all the efforts you put into HN community.

Re: Billion-record stolen Chinese database for sale on breach forum

#200

Earlier quoted context omitted.

As a US citizen I want to believe bravado like this but I’m guessing this is just your fantasy world talking not actual knowledge of the government being competent, which in my personal experience seems extremely unlikely.

The government isn't competent as a whole.. but the intelligence agencies are rather powerful. I've worked for DARPA and IARPA and you wouldn't believe half the stuff I could say publicly and none of the stuff I can't disclose.

Post the stuff you're able to talk about publicly, I'm interested!
Post reply on HN