Live data from Hacker News

Data leak contains 26B records from numerous previous breaches

cybernews.com

61–70 of 150 posts

Re: Data leak contains 26B records from numerous previous breaches

#61

Question that sounds idiotic but is quite serious: how do I make it illegal to lend money to me without confirmation via Keybase? (edit: or some similar cryptographic identity proof) The only reason to keep my name/address/SSN secret is that companies will lend money to a person who has that info, and then try to make me liable for it regardless of whether that person was me. That's a problem, but the solution isn't…

Speaking of Keybase, is it still supported? I just launched mine after a multi-week hiatus, and I'm getting an error: "x509: certificate signed by unknown authority" Hmmm.

Re: Data leak contains 26B records from numerous previous breaches

#62
post #12
post #4

I feel like the people who calculate that it's more cost effective to deal with the hit from a security breach vs spending money on good security have won. I have gone from feeling outraged to completely numb to these kind of disclosures and have pretty much just assumed that my information will inevitably be leaked somewhere by someone. Does anyone else feel this way? I just keep a close eye on my financial statemen…

It’s time for attorney generals to hold permanent identity monitoring pots and funds. The idea that someone can lose all your data and then pay for two years of identity monitoring is absurd. The people with the data can see that and can just wait two years to sell it. Social security numbers don’t reset after two years. If you lose data, you pay a data breach tax forever. Over time, your competitors will be able to…

  > It’s time for attorney generals
Attorneys general

They are attorneys, so that is the word to pluralize. What type of attorney are they? General

Re: Data leak contains 26B records from numerous previous breaches

#63
My first thought was "Is this Troy Hunt's hard drive?" but I'm assuming that more bad actors collect security breach data than security researchers. With cyber crime & scams on the rise and earning billions, the value of all that mineable data for bad actors must be high.

Re: Data leak contains 26B records from numerous previous breaches

#65
post #49
post #12

Earlier quoted context omitted.

It’s time for attorney generals to hold permanent identity monitoring pots and funds. The idea that someone can lose all your data and then pay for two years of identity monitoring is absurd. The people with the data can see that and can just wait two years to sell it. Social security numbers don’t reset after two years. If you lose data, you pay a data breach tax forever. Over time, your competitors will be able to…

I think an easier approach would be some sort of mandatory indemnity. Rather than trying to impose specific practices which very well may vary greatly depending on the domain, just levy automatic penalties for breaches and set them high enough to encourage action.

This will just make companies more litigious. They'll sue to silence leakers and deny wrongdoing. The leaking will still happen.

Re: Data leak contains 26B records from numerous previous breaches

#66

Question that sounds idiotic but is quite serious: how do I make it illegal to lend money to me without confirmation via Keybase? (edit: or some similar cryptographic identity proof) The only reason to keep my name/address/SSN secret is that companies will lend money to a person who has that info, and then try to make me liable for it regardless of whether that person was me. That's a problem, but the solution isn't…

Speaking of Keybase, is it still supported? I just launched mine after a multi-week hiatus, and I'm getting an error: "x509: certificate signed by unknown authority" Hmmm.

I'm not sure? Mine still works but I've had to manually upgrade it a few times. For a scheme like this we'd probably need to reimplement it (just the public keyring and challenge proofs on social media platforms, not the crypto cruft). Helpfully I think the client is FOSS.

Re: Data leak contains 26B records from numerous previous breaches

#68
post #12

Earlier quoted context omitted.

It’s time for attorney generals to hold permanent identity monitoring pots and funds. The idea that someone can lose all your data and then pay for two years of identity monitoring is absurd. The people with the data can see that and can just wait two years to sell it. Social security numbers don’t reset after two years. If you lose data, you pay a data breach tax forever. Over time, your competitors will be able to…

> It’s time for attorney generals Attorneys general They are attorneys, so that is the word to pluralize. What type of attorney are they? General

This is an explanation poor of why that's the plural correct. You make it sound like that's grammar normal English.

Re: Data leak contains 26B records from numerous previous breaches

#69
post #32

Earlier quoted context omitted.

Agreed, perhaps requiring companies who handle sensitive data to carry insurance and licensing engineers who build those systems, something like the PE.

> licensing engineers who build those systems The IT and software industries would really change. Perhaps for the better, but perhaps not.

I can't possibly see it becoming worse. This isn't the 90s any more, computing and the internet are no longer cute novelties but infrastructure just as critical as electricity or airport communication. Software "engineering" has been due for the professional licensure and direct liability that every other serious industry has had for a century.

Re: Data leak contains 26B records from numerous previous breaches

#70
post #4

I feel like the people who calculate that it's more cost effective to deal with the hit from a security breach vs spending money on good security have won. I have gone from feeling outraged to completely numb to these kind of disclosures and have pretty much just assumed that my information will inevitably be leaked somewhere by someone. Does anyone else feel this way? I just keep a close eye on my financial statemen…

The problem is that as long as there are attackers willing to spend resources, there is no limit to spending money on security, it is adversarial. At some point, security will cost more than what you are securing, and that's when people drop the ball and prefer to deal with the consequences.

Same ideas as with bicycles. Thieves now have sufficiently advanced tools that people stop buying the kind locks that could possibly stop them, and instead just assume that left unattended in the outside, their bike will be stolen eventually, and deal with it. For example by not having nice bikes, or by not biking unless there is a safe place for that bike.

So yeah, leaks will happen. Unless maybe you get a combination of well designed and enforced security standards, harsh penalties for cybercrime, and international collaboration.

Post reply on HN