Live data from Hacker News

Data leak contains 26B records from numerous previous breaches

cybernews.com

71–80 of 150 posts

Re: Data leak contains 26B records from numerous previous breaches

#71
post #54

Any magnet?

If you've followed other large / individual leaks, all this data is already there. If you just want a download for convenience, go to the black forums. Or check haveibeenpwned if you're curious for your own company / identity.

Re: Data leak contains 26B records from numerous previous breaches

#72
post #12

Earlier quoted context omitted.

It’s time for attorney generals to hold permanent identity monitoring pots and funds. The idea that someone can lose all your data and then pay for two years of identity monitoring is absurd. The people with the data can see that and can just wait two years to sell it. Social security numbers don’t reset after two years. If you lose data, you pay a data breach tax forever. Over time, your competitors will be able to…

I'm very open to government solutions, but at the same time I'm not sure they have a good track record. Despite that, this service should come from the government because anyone else has misaligned incentives. I specifically would want a privacy and security maximalist approach. What we have right now is completely unacceptable, especially given our current technology level. Though of course, the downside is also tha…

The service doesn’t need to come from the government. A marketplace of services of which I can choose my own provider would work.

Re: Data leak contains 26B records from numerous previous breaches

#73
post #55

Earlier quoted context omitted.

You contribute to campaigns of politicians (aka bribe) and write legislation for them to pass.

I don't have enough time left on this Earth to explain the concept in a way that politicians could implement, I'm in my 40s. In my preferred alternate universe, Keybase was sold to a benevolent billionaire. Or more realistically, a normal billionaire who intended to run it at a loss until he could leverage it to effect world domination, but managed to mess it up somehow and get it nationalized. Or something. I can dr…

The lobbyists write the legislation and provide the talking points.

Re: Data leak contains 26B records from numerous previous breaches

#74
All I see here is someone made a bigger list from multiple other lists from prior breaches. This isn't "the mother of all breaches", this is clickbait. Unless there is some new confirmed breach somewhere that in fact contains 26 billion records ex-filtrated, the only thing this is the mother of is a nothing burger.

Re: Data leak contains 26B records from numerous previous breaches

#75
post #31
post #12

Earlier quoted context omitted.

It’s time for attorney generals to hold permanent identity monitoring pots and funds. The idea that someone can lose all your data and then pay for two years of identity monitoring is absurd. The people with the data can see that and can just wait two years to sell it. Social security numbers don’t reset after two years. If you lose data, you pay a data breach tax forever. Over time, your competitors will be able to…

It should all be free, like getting credit reports is now. We need a robust and accessible way to manage our data personas, assuming that all of the supposed secrets are in fact public data.

As a reminder for any US Citizens, there is an official path to getting this from each of the main three for free[1] is the approved method verified by FTC [2].

1. https://annualcreditreport.com

2. https://consumer.ftc.gov/articles/free-credit-reports

Re: Data leak contains 26B records from numerous previous breaches

#76

Earlier quoted context omitted.

Exactly. The whole idea that end users are responsible for their stolen "identity" is absurd. It was a successful tactic used by banks and credit bureaus to shed their responsibility of proper verification when opening lines of credit or other accounts.

I would go one step further, saying that proper verification is prone to fraud because of failure in government (in the US; not sure about other countries). It still baffles me that identification typically comes down to two things: social security card and driver's license, and both are managed by agencies whose primary objective is not identification. IMHO, it's time for a single agency at either the fed or state l…

I'll go yet another step further, and say that the main opposition to having a better technical system of government identification is because we're lacking a comprehensive privacy law akin to the GDPR. As it stands if the government started say issuing smart cards for identify verification, then every business would gradually force their customers to identify themselves, for helping the commercial surveillance industry track everything they do. This is the current dynamic with mobile apps, phone numbers, and existing static identifiers, and it's only held back because one can feign not having them and/or being worried about giving out that info. Whereas with actually secure technicals, that friction basically disappears. And so the only way to prevent this dynamic (and make it so better identification isn't itself a security vulnerability) is by gaining the legal right to inspect/audit/reject the collection, use, and storage of such information in the first place.

Re: Data leak contains 26B records from numerous previous breaches

#78

Meh... keep your passwords in an offline password manager and generated for each site. Don't store payment info anywhere, but if you do, make sure it's a generated CC number. Never link your checking or savings account to anything. Sure you'll miss out on some convenience, but you'll have your money and sanity.

> Don't store payment info anywhere, but if you do, make sure it's a generated CC number.

Cries in Canadian. As far as I am aware there is no way up here to have more than one virtual card. Please correct me if I'm wrong.

Re: Data leak contains 26B records from numerous previous breaches

#79

Earlier quoted context omitted.

> It’s time for attorney generals Attorneys general They are attorneys, so that is the word to pluralize. What type of attorney are they? General

This is an explanation poor of why that's the plural correct. You make it sound like that's grammar normal English.

Him forgive, programmer he Forth a is.

You thank.

Re: Data leak contains 26B records from numerous previous breaches

#80
post #12

Earlier quoted context omitted.

It’s time for attorney generals to hold permanent identity monitoring pots and funds. The idea that someone can lose all your data and then pay for two years of identity monitoring is absurd. The people with the data can see that and can just wait two years to sell it. Social security numbers don’t reset after two years. If you lose data, you pay a data breach tax forever. Over time, your competitors will be able to…

> It’s time for attorney generals Attorneys general They are attorneys, so that is the word to pluralize. What type of attorney are they? General

Nah, it's just a convention adopted from French after the Norman Conquest.
Post reply on HN