Live data from Hacker News

Billion-record stolen Chinese database for sale on breach forum

theregister.com

231–240 of 258 posts

Re: Billion-record stolen Chinese database for sale on breach forum

#231
post #16

Apparently there was a "blogpost" of a developer showing of their code, where they accidentally leaked access tokens in a piece of commented code: https://archive.ph/mP3bh This is completely unverified though, so take it with a grain of salt.

The consensus in Chinese community is while this is likely how the token got leaked, this alone isn't enough. To visit private Alibaba Cloud instance you can't just use some random IP. It's isolated from the Internet in certain way.

And we all know isolations based on network perimeter eventually falls apart, and because it encourages insecure opsec practices like this, people are going to have a big surprise when it happens.

Re: Billion-record stolen Chinese database for sale on breach forum

#232
post #188

Earlier quoted context omitted.

Assuming this unverified version of the story is true, the danger of accidentally leaking credentials in code is enormous and one of the reasons I continue to maintain and develop gitleaks. Those credentials[1] would have been caught by the gitleaks' generic rule [2] [1] https://regex101.com/r/CLg9TK/1 [2] https://github.com/zricethezav/gitleaks/blob/master/config/g...

Fantastic tool. We all know that _we_ wouldn't leak keys, but we have all been the person to 'rm -rf /' or 'delete * from prod where 1=1;', so it's just a matter of time. Is there a plugin that streamers could use to blur suspected keys on stream? Would that be something interesting to work on do you think? (I'm not a streamer but it sounds fun)

I think it would be a good tool to have, I had to contact a conference organizer once who switched tabs while sharing her screen in a recording and revealed a note in Google Keep that read "LastPass master password" xD

Re: Billion-record stolen Chinese database for sale on breach forum

#233
post #181

Earlier quoted context omitted.

It doesn't help that so many tools are like "give me your secret key in plain text in the config file" without at least offering a link to a webpage on the github of how you could secure your keys and use this software

hardcoded creds in example documentation... T_T Use vault, env vars, GitHub/GitLab secrets, anything but string literals!!!

If anyone’s looking for something more secure than vanilla env vars but simpler than Vault, you could check out EnvKey[1]. Disclaimer: I’m the founder.

It’s end-to-end encrypted, cloud or self-hosted, and very quick to integrate.

1 - https://envkey.com

Re: Billion-record stolen Chinese database for sale on breach forum

#234
post #107

Earlier quoted context omitted.

Wow that's bigger than Equifax

LinkedIn doesn't have my Social Security number. It doesn't have a list of my bank accounts and credit cards. So, more people, but less damaging information.

the data sets are more valuable when they're concentrated, so the leak of your address, voter registration, and SSN is now tied to your employment history and education

Re: Billion-record stolen Chinese database for sale on breach forum

#235
post #3

What do we do now? It seems the majority of people on the planet now have had some of their data leaked. Or are becoming ever more entangled with government and corporate systems which control and peddle their information as they see fit. Is it ultimately a big nothing burger, or is this some singularity we are passing through?

> What do we do now? I was thinking - if I had this, what could I do with the personal records of a billion Chinese people? And I must conclude - absolutely nothing. It's of no interest to me. Now, I probably lack sufficient criminal imagination, but the point is stuff like this is hard to fence because there's a very small market of buyers. In an article I wrote for Routledge about the markets for stolen digital dat…

> what could I do with the personal records of a billion Chinese people?

you use personal details to tailor phishing scams to the victim

If I know you have a grandson that lives in XinJiang I can cold call you and say i'm from the xinjiang police and we have your grandson here under arrest and then extort money from there

Re: Billion-record stolen Chinese database for sale on breach forum

#236
post #223

Earlier quoted context omitted.

https://www.alibabacloud.com/product/datahub is what they were using, and yeah their keys were in a commented out psvm tester method. pretty awful

Another reason why not everyone should use the cloud. Sure, the cloud can be as secure as on-prem or even safer in many cases. But it's just so easy to keep on-prem data safe by just not connecting it to the outside world. If no server can be accessed from anywhere but the premise, leaks like these just can't happen. A key won't help you unless you can break into the police building. Access just based on credentials…

What happened is the exact opposite:

The Shanghai police thinks like you, so they purchased a very expensive "private deployment of Alibaba Cloud", which in China usually works like this:

1. The customer build a data center.

2. Alibaba Cloud purchases servers, deploys them in the customer's data center along with all Alibaba Cloud software (same as in the public cloud).

3. Customers do whatever they want to the thing.

Basically by "private cloud" they really mean it, something AWS won't ever do.

In this case, the system is technically "not connected to the Internet", but we all know what this mean: it certainly will be occasionally.

Most cases I know, the customer cite "data security" as the reason why they would like to do this, because on-prem are always more secure right? But I hope we could agree on why this does not work:

- It is now very difficult for Alibaba Cloud to do ops work on these private deployments, so ... there will be maybe 2 releases per year, or in some cases never, including security patches. It's not rare to find a 5-years-old struts2 vuln in the control plane of such private deployments, and in the coming years it would be log4j2 I guess.

- Alibaba Cloud put serious effort into securing their public cloud, and even covering the ass for the customer. For example similar to GitHub+AWS secret scanning, they also proactively revoke access keys once the key appears on the Internet. The customers, on the other hand, usually do none of these.

In short, security is largely an Ops work and economies of scale also work here.

In the end these on-prem systems depend solely on network isolation for their security, and... air-gap does not always work.

Re: Billion-record stolen Chinese database for sale on breach forum

#237
post #17

Earlier quoted context omitted.

The previous big case I remember was linkedin leak with 700M users: https://news.ycombinator.com/item?id=27674393 At this point I've basically accepted that all my info will be found on sites like fastpeoplesearch.com and that anything I tell any company (or I guess in this case, govt too) will eventually be leaked, correlated, and used against me.

What's fastpeoplesearch.com? Some search engine for leaked credentials? (it appears to be geoblocked in Europe)

age, home address, phone number

names and relations to family members and all their phones and addresses

previous addresses

a lot of it is collected from voter registration data (so your party affilition can be gathered as well)

I was royally pissed when I moved into a new home and literally a day after I signed up for internet service with Spectrum cable I got spam calls that know what state I'm in and my new home address is up online before I ever get around to updating my ID etc so I assume my data was sold immediately by them

Re: Billion-record stolen Chinese database for sale on breach forum

#238
post #50

Earlier quoted context omitted.

IIRC there was a central registry of religion in the Netherlands that had the same effect. Can't find anything on that now, though (it's mentioned in Wikipedia in an unsourced paragraph; I think I first read about it on HN, actually). ----- Tangent: the info pages on the Anne Frank House site have sections cycling through different pastel background colours.[0] I've wondered before whether something like that would t…

> IIRC there was a central registry of religion in the Netherlands that had the same effect. > I think I first read about it on HN, actually That may have been my article: https://jacquesmattheij.com/if-you-have-nothing-to-hide/

I knew someone from the Netherlands would elaborate!

I actually saw the fact pointed out in a comment. It's brought up quite often here—even a fairly narrow query finds many instances:

https://hn.algolia.com/?query=netherlands%20religion%20nazi&...

Some have citations, too. HN is proving quite useful as a knowledge engine.

Re: Billion-record stolen Chinese database for sale on breach forum

#239
post #19
post #16

Apparently there was a "blogpost" of a developer showing of their code, where they accidentally leaked access tokens in a piece of commented code: https://archive.ph/mP3bh This is completely unverified though, so take it with a grain of salt.

Binance CEO confirmed this version: https://twitter.com/cz_binance/status/1543905416748359680

I don't know this guy, but how can he confirm this? does he possess any inner information? why I got the feeling that he is so eager to put a conclusion on this when it is still open for debate at this stage.

Re: Billion-record stolen Chinese database for sale on breach forum

#240
post #19

Earlier quoted context omitted.

Binance CEO confirmed this version: https://twitter.com/cz_binance/status/1543905416748359680

I don't know this guy, but how can he confirm this? does he possess any inner information? why I got the feeling that he is so eager to put a conclusion on this when it is still open for debate at this stage.

Binance is the largest cryptocurrency trading platform globally.

According to this tweet [0] they have a "threat intelligence" department that continually monitors for potential issues. It makes sense that they would be on the lookout for leaks of this nature, as they are highly dependent on correctly verifying and identifying their customers.

[0] https://twitter.com/cz_binance/status/1543700689611792386

Post reply on HN