Live data from Hacker News

Data leak contains 26B records from numerous previous breaches

cybernews.com

41–50 of 150 posts

Re: Data leak contains 26B records from numerous previous breaches

#41
post #6

Earlier quoted context omitted.

With email addresses you can use multiple to not be too affected. But phone numbers are less replaceable than email addresses... And what's annoying is that more and more things now also require phone numbers (like, seriously, in the past an email address was enough but today the simplest thing you want to signup for uses some third party booking platform (which means yet one more party that gets to leak your data) t…

The simplest thing require full name, address, birthdate, age, yes age, mobile phone, fiscal number, last four digits of the credit card, expiration date of credit card, yomama’s maiden name, the middle 8 digits of your credit, your last used password, your pet’s name, the name of the high school you attended, favorite football team, a front and side pictures no smile no hats no glasses, hi resolution scan of governm…

Hey! Don’t you have all digits of my CC now?!

Re: Data leak contains 26B records from numerous previous breaches

#42

That term is a bit clickbaity. Mother of all dumps would be more appropriate. This is all from old breaches.

The funny thing to me about this title is who brought that term to English in the first place. It came into the vernacular back in 1991 when Saddam Hussein claimed the Kuwait War would become "the mother of all wars". It didn't. It lasted about 24 hours, but the phrase has lasted much longer. It's so weird how language evolves, who has the power to do it, and who doesn't.

So for me, the title means that this breach is only of importance to the people who want it to be. Everyone else will simply ignore it after 24 hours, just like the first Kuwait War.

Re: Data leak contains 26B records from numerous previous breaches

#43
post #12
post #4

I feel like the people who calculate that it's more cost effective to deal with the hit from a security breach vs spending money on good security have won. I have gone from feeling outraged to completely numb to these kind of disclosures and have pretty much just assumed that my information will inevitably be leaked somewhere by someone. Does anyone else feel this way? I just keep a close eye on my financial statemen…

It’s time for attorney generals to hold permanent identity monitoring pots and funds. The idea that someone can lose all your data and then pay for two years of identity monitoring is absurd. The people with the data can see that and can just wait two years to sell it. Social security numbers don’t reset after two years. If you lose data, you pay a data breach tax forever. Over time, your competitors will be able to…

> two years

TWO years?

I have had my data pwn3d a couple of times. One was six months', the other was one year, and Experian used that as leverage to unendingly nag me to buy into them.

Re: Data leak contains 26B records from numerous previous breaches

#44

Meh... keep your passwords in an offline password manager and generated for each site. Don't store payment info anywhere, but if you do, make sure it's a generated CC number. Never link your checking or savings account to anything. Sure you'll miss out on some convenience, but you'll have your money and sanity.

It's unethical, but technically any pressed key or input while on a website could be saved to the site's servers or any servers it ever interacts with, even if you don't save it. So, in addition to your guideline, try to limit the number of websites you input any PII into. IN ADDITION to that, you need to limit the number of people who will take your information in real life and input your information into a system, for example, at a grocery store, gym, bank, dentist, insurance form, or any other service like that.

In a way, it's miraculous if one's identity HASN'T been used in nefarious ways without their knowledge, yet.

Re: Data leak contains 26B records from numerous previous breaches

#45
post #40

Clearly better security is always better but sometimes I think there needs to be a different way of approaching identity validation etc. Like, maybe we need to assume everyone's records are leaked somewhere all the time? I'm not sure what that means in practice but I e.g., am not sure that "identity theft" should be a scary thing if the other side of the system is working optimally.

> I'm not sure what that means in practice but I e.g., am not sure that "identity theft" should be a scary thing if the other side of the system is working optimally.

For that, the US needs to follow what virtually all EU member states have done, and provide every citizen with a government-issued ID card with NFC that can be used to authenticate against a website (e.g. a bank), and browsers would need to agree on a web standard allowing interfacing with such cards (there is Web NFC but it's by far not enough).

The problem is, this is politically untenable in the US for a bunch of reasons - the right wing complains about "big government" and fears a "nanny state" that tracks everyone and everything, and the left wing complains because ID cards cost money and would exclude people without proper documentation.

Additionally, passports don't store your residential address and people don't necessarily want the government to know said address, which means they are useless to banks as a factor proving "person X lives at address Y".

Re: Data leak contains 26B records from numerous previous breaches

#46
post #12

Earlier quoted context omitted.

It’s time for attorney generals to hold permanent identity monitoring pots and funds. The idea that someone can lose all your data and then pay for two years of identity monitoring is absurd. The people with the data can see that and can just wait two years to sell it. Social security numbers don’t reset after two years. If you lose data, you pay a data breach tax forever. Over time, your competitors will be able to…

Further cementing this broken idea of "identity" as something that can be stolen is most certainly not what we need! Rather we need AG's to start going after companies that attempt to collect negligently verified and other fake debts for the outright brazen fraud that it is, and a law that allow victims to procedurally recover triple damages for time/money spent defending against these companies and helping the compa…

Exactly. The whole idea that end users are responsible for their stolen "identity" is absurd.

It was a successful tactic used by banks and credit bureaus to shed their responsibility of proper verification when opening lines of credit or other accounts.

Re: Data leak contains 26B records from numerous previous breaches

#47
post #4

I feel like the people who calculate that it's more cost effective to deal with the hit from a security breach vs spending money on good security have won. I have gone from feeling outraged to completely numb to these kind of disclosures and have pretty much just assumed that my information will inevitably be leaked somewhere by someone. Does anyone else feel this way? I just keep a close eye on my financial statemen…

I just went through a call with my credit card company. 4 transfers later the only verification I've been asked is the last 4 of my social, my name, and when I was at the "highest level" of security they took the amazing step to... call me back. All because my credit card, which is travel focused, got flagged because I bought a You are not alone. It is an __absolute joke__ that my github account is more secure than any banking service I use. How is it that the only 2FA they offer is text message? A method that's been known to be terrible for over a decade now. Where are my OTPs? They give me apps on my phone, why not push verification there? (Vanguard recently started doing this) Why can't I set up hardware keys or public private keypairs? Sure, I get that you still got to service grandma and grandpa, but at least give me something. In today's day and age the two most important services I have are email and banking. The former is impossible to resolve when shit hits the fan and the latter doesn't even implement basic security.

Something is very wrong, and I'm not sure it is even about money (unless short term vs long term). Dinky little websites implement better security than most baking services. Clearly the banks could reduce their spending on fraud detection and resolution if they added some basic security.

I will note that I had a Capital One account that used the card as a 2FA into the phone app. Was neat, other than Capital One was a whole shitshow on its own.

I'm also very surprised at how much spam gets through services like Gmail and Twitter which could be easily detected by Naive Bayes filters. Something is very wrong.

Re: Data leak contains 26B records from numerous previous breaches

#48
post #12
post #4

I feel like the people who calculate that it's more cost effective to deal with the hit from a security breach vs spending money on good security have won. I have gone from feeling outraged to completely numb to these kind of disclosures and have pretty much just assumed that my information will inevitably be leaked somewhere by someone. Does anyone else feel this way? I just keep a close eye on my financial statemen…

It’s time for attorney generals to hold permanent identity monitoring pots and funds. The idea that someone can lose all your data and then pay for two years of identity monitoring is absurd. The people with the data can see that and can just wait two years to sell it. Social security numbers don’t reset after two years. If you lose data, you pay a data breach tax forever. Over time, your competitors will be able to…

I'm very open to government solutions, but at the same time I'm not sure they have a good track record. Despite that, this service should come from the government because anyone else has misaligned incentives. I specifically would want a privacy and security maximalist approach. What we have right now is completely unacceptable, especially given our current technology level. Though of course, the downside is also that this database becomes a big target (and that's why I want a maximalist approach). I don't know what the solution is, but I'm sure there are security experts here on HN that can lay out better paths and I'm interested in actually hearing what systems I should be advocating for (with more specificity than the generic thing I said).

I do think we should also push back against surveillance capitalism. This has been a disaster. Such data breaches are a result of this system (and clearly it isn't even unique to the western world). I think any government has the power to hold these companies accountable in at least some form or another. Big dogs like US, China, and Germany should be leaders, but clearly they aren't as this stuff keeps happening.

Re: Data leak contains 26B records from numerous previous breaches

#49
post #12
post #4

I feel like the people who calculate that it's more cost effective to deal with the hit from a security breach vs spending money on good security have won. I have gone from feeling outraged to completely numb to these kind of disclosures and have pretty much just assumed that my information will inevitably be leaked somewhere by someone. Does anyone else feel this way? I just keep a close eye on my financial statemen…

It’s time for attorney generals to hold permanent identity monitoring pots and funds. The idea that someone can lose all your data and then pay for two years of identity monitoring is absurd. The people with the data can see that and can just wait two years to sell it. Social security numbers don’t reset after two years. If you lose data, you pay a data breach tax forever. Over time, your competitors will be able to…

I think an easier approach would be some sort of mandatory indemnity. Rather than trying to impose specific practices which very well may vary greatly depending on the domain, just levy automatic penalties for breaches and set them high enough to encourage action.

Re: Data leak contains 26B records from numerous previous breaches

#50
Question that sounds idiotic but is quite serious: how do I make it illegal to lend money to me without confirmation via Keybase? (edit: or some similar cryptographic identity proof)

The only reason to keep my name/address/SSN secret is that companies will lend money to a person who has that info, and then try to make me liable for it regardless of whether that person was me. That's a problem, but the solution isn't for me to keep my identity secret, it's for companies to stop doing that.

I should be able to march into some government office, prove my identity to their satisfaction, and give them a private key. Then, if Wells Fargo lends money to someone who can't prove ownership of that key, that's Wells Fargo's problem. Keybase does this fairly well, and is essentially abandonware since the founders were (if I remember right) acquihired by Signal. So, can we just nationalize it or build something similar, declare it to be SSNv2, and move on with our lives?

Post reply on HN