Live data from Hacker News

Data leak contains 26B records from numerous previous breaches

cybernews.com

51–60 of 150 posts

Re: Data leak contains 26B records from numerous previous breaches

#51
post #4

I feel like the people who calculate that it's more cost effective to deal with the hit from a security breach vs spending money on good security have won. I have gone from feeling outraged to completely numb to these kind of disclosures and have pretty much just assumed that my information will inevitably be leaked somewhere by someone. Does anyone else feel this way? I just keep a close eye on my financial statemen…

I just went through a call with my credit card company. 4 transfers later the only verification I've been asked is the last 4 of my social, my name, and when I was at the "highest level" of security they took the amazing step to... call me back. All because my credit card, which is travel focused, got flagged because I bought a You are not alone. It is an __absolute joke__ that my github account is more secure than a…

I can log into chase.com with my password in any case. Banking security is an absolute joke.

The interesting part is that if I have to do a 2FA SMS challenge, I am required to re-enter my password. At this point the password checking becomes case sensitive.

Re: Data leak contains 26B records from numerous previous breaches

#52
post #12

Earlier quoted context omitted.

It’s time for attorney generals to hold permanent identity monitoring pots and funds. The idea that someone can lose all your data and then pay for two years of identity monitoring is absurd. The people with the data can see that and can just wait two years to sell it. Social security numbers don’t reset after two years. If you lose data, you pay a data breach tax forever. Over time, your competitors will be able to…

Further cementing this broken idea of "identity" as something that can be stolen is most certainly not what we need! Rather we need AG's to start going after companies that attempt to collect negligently verified and other fake debts for the outright brazen fraud that it is, and a law that allow victims to procedurally recover triple damages for time/money spent defending against these companies and helping the compa…

This is the best comment ever. Thank you! ... The narrative around "identity theft" and "personal data" needs to change.

Re: Data leak contains 26B records from numerous previous breaches

#53
post #42

That term is a bit clickbaity. Mother of all dumps would be more appropriate. This is all from old breaches.

The funny thing to me about this title is who brought that term to English in the first place. It came into the vernacular back in 1991 when Saddam Hussein claimed the Kuwait War would become "the mother of all wars". It didn't. It lasted about 24 hours, but the phrase has lasted much longer. It's so weird how language evolves, who has the power to do it, and who doesn't. So for me, the title means that this breach i…

Google Ngram viewer does indicate a sharp rise in use of the phrase starting in 1990:

https://books.google.com/ngrams/graph?content=the+mother+of+...

Re: Data leak contains 26B records from numerous previous breaches

#55

Question that sounds idiotic but is quite serious: how do I make it illegal to lend money to me without confirmation via Keybase? (edit: or some similar cryptographic identity proof) The only reason to keep my name/address/SSN secret is that companies will lend money to a person who has that info, and then try to make me liable for it regardless of whether that person was me. That's a problem, but the solution isn't…

You contribute to campaigns of politicians (aka bribe) and write legislation for them to pass.

Re: Data leak contains 26B records from numerous previous breaches

#56
post #4

I feel like the people who calculate that it's more cost effective to deal with the hit from a security breach vs spending money on good security have won. I have gone from feeling outraged to completely numb to these kind of disclosures and have pretty much just assumed that my information will inevitably be leaked somewhere by someone. Does anyone else feel this way? I just keep a close eye on my financial statemen…

The SEC had a disclosure recently which had an effect on the bitcoin market. They turned off MFA and forgot to re-enable it supposedly as well as it was a sim swap attack.

The OPM data breach was bad. So much data on there about the individuals and a few degrees of association away from them. Every security question and answer are there.

I had 4 data breaches last year and one so far this year I just posted about today that I have no idea how they got my information (0). Mail was stolen by a petty theft and identity theft ring which called to try to get more out of me a couple years ago.

Freezing your credit is the best course of action. I don’t really worry about it much anymore.

(0) https://news.ycombinator.com/item?id=39101272

Re: Data leak contains 26B records from numerous previous breaches

#58
post #55

Question that sounds idiotic but is quite serious: how do I make it illegal to lend money to me without confirmation via Keybase? (edit: or some similar cryptographic identity proof) The only reason to keep my name/address/SSN secret is that companies will lend money to a person who has that info, and then try to make me liable for it regardless of whether that person was me. That's a problem, but the solution isn't…

You contribute to campaigns of politicians (aka bribe) and write legislation for them to pass.

I don't have enough time left on this Earth to explain the concept in a way that politicians could implement, I'm in my 40s. In my preferred alternate universe, Keybase was sold to a benevolent billionaire. Or more realistically, a normal billionaire who intended to run it at a loss until he could leverage it to effect world domination, but managed to mess it up somehow and get it nationalized. Or something. I can dream...

Re: Data leak contains 26B records from numerous previous breaches

#59

Earlier quoted context omitted.

Further cementing this broken idea of "identity" as something that can be stolen is most certainly not what we need! Rather we need AG's to start going after companies that attempt to collect negligently verified and other fake debts for the outright brazen fraud that it is, and a law that allow victims to procedurally recover triple damages for time/money spent defending against these companies and helping the compa…

Exactly. The whole idea that end users are responsible for their stolen "identity" is absurd. It was a successful tactic used by banks and credit bureaus to shed their responsibility of proper verification when opening lines of credit or other accounts.

I would go one step further, saying that proper verification is prone to fraud because of failure in government (in the US; not sure about other countries). It still baffles me that identification typically comes down to two things: social security card and driver's license, and both are managed by agencies whose primary objective is not identification. IMHO, it's time for a single agency at either the fed or state level that's in charge of just identification. That's it. Fund that agency and let them do it properly. However, inevitably someone will scream "Big Brother!", and we'll end up back where we started, with this Rube Goldberg system that basically leaves individuals to fend for themselves.

Re: Data leak contains 26B records from numerous previous breaches

#60
post #12
post #4

I feel like the people who calculate that it's more cost effective to deal with the hit from a security breach vs spending money on good security have won. I have gone from feeling outraged to completely numb to these kind of disclosures and have pretty much just assumed that my information will inevitably be leaked somewhere by someone. Does anyone else feel this way? I just keep a close eye on my financial statemen…

It’s time for attorney generals to hold permanent identity monitoring pots and funds. The idea that someone can lose all your data and then pay for two years of identity monitoring is absurd. The people with the data can see that and can just wait two years to sell it. Social security numbers don’t reset after two years. If you lose data, you pay a data breach tax forever. Over time, your competitors will be able to…

[deleted]
Post reply on HN