Live data from Hacker News

Data leak contains 26B records from numerous previous breaches

cybernews.com

101–110 of 150 posts

Re: Data leak contains 26B records from numerous previous breaches

#101
post #55

Question that sounds idiotic but is quite serious: how do I make it illegal to lend money to me without confirmation via Keybase? (edit: or some similar cryptographic identity proof) The only reason to keep my name/address/SSN secret is that companies will lend money to a person who has that info, and then try to make me liable for it regardless of whether that person was me. That's a problem, but the solution isn't…

You contribute to campaigns of politicians (aka bribe) and write legislation for them to pass.

Or scour through these breaches, thinking of how to embarrass the lawmakers with info you find in them. Maybe when it affects the fancy people, they will start making laws to protect themselves, and hopefully include us in it.

Re: Data leak contains 26B records from numerous previous breaches

#102
post #4

I feel like the people who calculate that it's more cost effective to deal with the hit from a security breach vs spending money on good security have won. I have gone from feeling outraged to completely numb to these kind of disclosures and have pretty much just assumed that my information will inevitably be leaked somewhere by someone. Does anyone else feel this way? I just keep a close eye on my financial statemen…

I just went through a call with my credit card company. 4 transfers later the only verification I've been asked is the last 4 of my social, my name, and when I was at the "highest level" of security they took the amazing step to... call me back. All because my credit card, which is travel focused, got flagged because I bought a You are not alone. It is an __absolute joke__ that my github account is more secure than a…

[deleted]

Re: Data leak contains 26B records from numerous previous breaches

#103
post #4

I feel like the people who calculate that it's more cost effective to deal with the hit from a security breach vs spending money on good security have won. I have gone from feeling outraged to completely numb to these kind of disclosures and have pretty much just assumed that my information will inevitably be leaked somewhere by someone. Does anyone else feel this way? I just keep a close eye on my financial statemen…

100% with you. At this point my data has been breached so many times I don't even know what the point of caring is. I don't have privacy anymore. Like you I just have credit monitoring and watch my financial statements and hope for the best. This world sucks.

Know what? I heard it was illegal in the UK to give websites fake information. But looking at that list of websites justifies what I have been doing for the past 18 years religiously. When a website asks my age, I give it a fake one. When a shop asks for my debit card details I give it my initials J B and then I will confirm the sms security from my bank when the initials flag 30% of the time. Giving every company real data just means it gets leaked. That list of hacked domain names covers just about everyone. Wow.

Re: Data leak contains 26B records from numerous previous breaches

#104

Earlier quoted context omitted.

I'll go yet another step further, and say that the main opposition to having a better technical system of government identification is because we're lacking a comprehensive privacy law akin to the GDPR. As it stands if the government started say issuing smart cards for identify verification, then every business would gradually force their customers to identify themselves, for helping the commercial surveillance indus…

There's also a significant constituency that believes any nationwide system of identity is the "mark of the beast" as spoken of in the Bible.

It feels like the people who literally believe this as an actual political concern is a vanishingly small contingent, especially given that the ship has already sailed with SSNs and the like, making this more of a partisan talking point strawman. Of course I do respect that the relevant political party has made their whole platform one of stirring up such tempests in teapots instead of focusing on substantive policy. But still regardless of the possible superstitious narratives that objections may end up taking, the best way to eliminate objections is to address the actual practical concerns. And that is chiefly the myriad of ways in which existing identifiers are being abused.

Re: Data leak contains 26B records from numerous previous breaches

#105
post #42

Earlier quoted context omitted.

The funny thing to me about this title is who brought that term to English in the first place. It came into the vernacular back in 1991 when Saddam Hussein claimed the Kuwait War would become "the mother of all wars". It didn't. It lasted about 24 hours, but the phrase has lasted much longer. It's so weird how language evolves, who has the power to do it, and who doesn't. So for me, the title means that this breach i…

Google Ngram viewer does indicate a sharp rise in use of the phrase starting in 1990: https://books.google.com/ngrams/graph?content=the+mother+of+...

"The mother of all X" (battles/wars/bombs/etc.)

a hyperbole that has been used to refer to something as "great" or "the greatest of its kind", became a popular snowclone template in the 1990s. The phrase entered American popular culture in September 1990 at the outset of the Gulf War, when Saddam Hussein's Revolutionary Command Council warned the U.S.-led Coalition against military action in Kuwait with the statement: "Let everyone understand that this battle is going to become the mother of all battles."[

https://en.wikipedia.org/wiki/Snowclone#The_mother_of_all_X

Re: Data leak contains 26B records from numerous previous breaches

#106
post #4

I feel like the people who calculate that it's more cost effective to deal with the hit from a security breach vs spending money on good security have won. I have gone from feeling outraged to completely numb to these kind of disclosures and have pretty much just assumed that my information will inevitably be leaked somewhere by someone. Does anyone else feel this way? I just keep a close eye on my financial statemen…

> Does anyone else feel this way?

Since the mid 2000s.

I worked very hard trying to figure out how to protect patient data.

To do so requires translucent database techniques.

Which means encrypting all potential PII data at rest at the field level. Exactly like how passwords are stored, extended to all PII.

Which requires globally unique identifiers issued by CAs. Just like RealID.

Nothing will improve until people accept this fundamental technical truth.

Also, on the policy side, PII needs be be changed from an asset to a liability. And ban data hoarding stuff like targeted ads and relevant search.

Re: Data leak contains 26B records from numerous previous breaches

#108
post #4

I feel like the people who calculate that it's more cost effective to deal with the hit from a security breach vs spending money on good security have won. I have gone from feeling outraged to completely numb to these kind of disclosures and have pretty much just assumed that my information will inevitably be leaked somewhere by someone. Does anyone else feel this way? I just keep a close eye on my financial statemen…

The easiest thing is to just stop registering for useless garbage.

Re: Data leak contains 26B records from numerous previous breaches

#109

Earlier quoted context omitted.

I'm very open to government solutions, but at the same time I'm not sure they have a good track record. Despite that, this service should come from the government because anyone else has misaligned incentives. I specifically would want a privacy and security maximalist approach. What we have right now is completely unacceptable, especially given our current technology level. Though of course, the downside is also tha…

The government is the problem. They issue me a single identification number that can be used anywhere at anytime without any verification or notification that it has been used, and it's next to impossible to get a new one issued. This is madness. A state funded "insurance" system to backstop this mistake is an unworkable hack that seeks to ignore the fundamental problem.

The government only claimed to identify you with that number for one purpose. The motivation for fraud would be a lot lower if that was the way it was still.

The problem is third parties abused that number for their own purposes.

Imagine if some company somewhere started using phone numbers as identifiers, and criminals started defrauding that company by "stealing" other people's phone numbers. Would you blame the phone company for that? Of course not.

The problem is that banks and anyone else using SSNs need to do more due diligence than checking SSNs, but they don't want to because it would be expensive and add friction to signing up for their "products".

Re: Data leak contains 26B records from numerous previous breaches

#110

Question that sounds idiotic but is quite serious: how do I make it illegal to lend money to me without confirmation via Keybase? (edit: or some similar cryptographic identity proof) The only reason to keep my name/address/SSN secret is that companies will lend money to a person who has that info, and then try to make me liable for it regardless of whether that person was me. That's a problem, but the solution isn't…

Minus all the complicated implementation details, this is possible.

It's called a credit freeze: https://www.usa.gov/credit-freeze

Post reply on HN