Live data from Hacker News

Data leak contains 26B records from numerous previous breaches

cybernews.com

21–30 of 150 posts

Re: Data leak contains 26B records from numerous previous breaches

#22

Until we stop implicitly trusting third parties with unencrypted data this sort of thing will continue to feel like not even news.

I'm unclear how encrypting the data would help. The same breach that gives access to the data, can also decrypt it.

(Also you wrote the same message twice.)

Re: Data leak contains 26B records from numerous previous breaches

#23
post #13

Earlier quoted context omitted.

Title says billions, not trillions.

are you counting ants as people?

Super pedantic response, yet current estimate is 20 quadrillion ants on Earth.

https://www.science.org/content/article/how-many-ants-live-e...

https://en.wikipedia.org/wiki/Orders_of_magnitude_(numbers)

    Humans: 8,000,000,000
    Trees:  3,000,000,000,000
    Ants:  20,000,000,000,000,000

Re: Data leak contains 26B records from numerous previous breaches

#26

That term is a bit clickbaity. Mother of all dumps would be more appropriate. This is all from old breaches.

It's more than just a bit clickbaity. There are probably dozens of us on HN who've compiled our own combo DB. This is what dehashed, snusbase, and hibp all are.

Re: Data leak contains 26B records from numerous previous breaches

#27
Meh... keep your passwords in an offline password manager and generated for each site. Don't store payment info anywhere, but if you do, make sure it's a generated CC number. Never link your checking or savings account to anything. Sure you'll miss out on some convenience, but you'll have your money and sanity.

Re: Data leak contains 26B records from numerous previous breaches

#28
post #19
post #4

I feel like the people who calculate that it's more cost effective to deal with the hit from a security breach vs spending money on good security have won. I have gone from feeling outraged to completely numb to these kind of disclosures and have pretty much just assumed that my information will inevitably be leaked somewhere by someone. Does anyone else feel this way? I just keep a close eye on my financial statemen…

I'd say it's an inevitable state of affairs. With networked general computers the amount of leaked information tends to 100% of available information over time. Unless you can design, build and run absolutely safe systems. Cybersecurity is a sham, a bolt on industry extracting rent out of the mobile internet junkies we've become. We want to have an endless stream of entertainment and trivia so bad we've actually buil…

[deleted]

Re: Data leak contains 26B records from numerous previous breaches

#29
post #22

Until we stop implicitly trusting third parties with unencrypted data this sort of thing will continue to feel like not even news.

I'm unclear how encrypting the data would help. The same breach that gives access to the data, can also decrypt it. (Also you wrote the same message twice.)

I think you misunderstand their suggestion. If you only gave service providers access to encrypted data (i.e. End-to-end encryption), then neither the service provider nor the leaker would be able to decrypt.

Whether or not that is a generally viable or desirable suggestion is a different question, but it is possible as demonstrated by Signal, Apple, etc.

Re: Data leak contains 26B records from numerous previous breaches

#30
post #4

I feel like the people who calculate that it's more cost effective to deal with the hit from a security breach vs spending money on good security have won. I have gone from feeling outraged to completely numb to these kind of disclosures and have pretty much just assumed that my information will inevitably be leaked somewhere by someone. Does anyone else feel this way? I just keep a close eye on my financial statemen…

Long since resigned.

It's impossible to keep a secret on the internet. You can't secure military technology, bank secrets, crypto tokens or prevent piracy.

Computers were designed to be open by default.

General purpose computing mannufactured across the planet with everybody having a hand in the supply chain has become the betrayal system.

Security follows the traditional Mafia protection scheme racket.

- Some Romanian hacker leaks data from your web server and sells it.

- You pay developers to close the vuln.

- You pay cybersecurity a protection fee to prevent it happening again.

- It happens again.

Developing a real technology that can give secure control back to the owner-operator goes against good business incentives. You can't farm users and share the wealth on a truly secure computing model.

Post reply on HN