Live data from Hacker News

Data leak contains 26B records from numerous previous breaches

cybernews.com

121–130 of 150 posts

Re: Data leak contains 26B records from numerous previous breaches

#121
post #99

Earlier quoted context omitted.

This would be create an incentive to attack a competing company until you breach it 5x, causing its destruction. Competitors would be attacking each other nonstop. Like 3 check chess, but in Delaware.

I don't have a huge problem with that to be honest. Maybe not fifth breach, but something along those lines. Well-funded attackers and competing nations are already attacking these companies, so adding their competitors to the mix doesn't change a lot.

Yep. And if staying in business means keeping your website secure, well, isn’t that the goal?

I think part of the problem is that hacker movies make people think hacking is inevitable. Like you can’t actually protect your site and your data from the average punk on roller skates, so why bother? But that’s not true at all. Gmail has - as far as we know - never been breached by anything short of a nation state attacker. And I’m sure a lot of people have tried. You just need to actually care about security and follow best practices (like doing audits / red team and keep up to date with security patches). But most companies only seem interested in properly investing in security if it’s an existential threat.

Re: Data leak contains 26B records from numerous previous breaches

#122
post #109

Earlier quoted context omitted.

The government is the problem. They issue me a single identification number that can be used anywhere at anytime without any verification or notification that it has been used, and it's next to impossible to get a new one issued. This is madness. A state funded "insurance" system to backstop this mistake is an unworkable hack that seeks to ignore the fundamental problem.

The government only claimed to identify you with that number for one purpose. The motivation for fraud would be a lot lower if that was the way it was still. The problem is third parties abused that number for their own purposes. Imagine if some company somewhere started using phone numbers as identifiers, and criminals started defrauding that company by "stealing" other people's phone numbers. Would you blame the ph…

They themselves abused it as anyone in military service is well aware. Then they required you to put it on your IRS forms, even though the Social Security Administration is a wholly independent agency. Then they required banks to capture it for any customer.

It goes on.. third parties weren't the worst and they didn't start it and some are required by law.

Imagine if Credit Card companies were as blatantly incompetent and as reckless as the government? The reason they aren't is because they hold most of the liability at all times, and there's a lot of good laws that set them up for huge damages if the make a mistake. The reason the government doesn't care is because no one holds them accountable.

If you have an interest bearing account, you need to provide an SSN, and even though the regulation has since been changed, you needed it for any account for 30 years or so. Anyways, if my SSN suddenly starts being used 12 states away from where it has been the last few decades, _nobody_ notices. The government is the only agency that could and they just don't.

Re: Data leak contains 26B records from numerous previous breaches

#123
post #42

That term is a bit clickbaity. Mother of all dumps would be more appropriate. This is all from old breaches.

The funny thing to me about this title is who brought that term to English in the first place. It came into the vernacular back in 1991 when Saddam Hussein claimed the Kuwait War would become "the mother of all wars". It didn't. It lasted about 24 hours, but the phrase has lasted much longer. It's so weird how language evolves, who has the power to do it, and who doesn't. So for me, the title means that this breach i…

I originally wanted to "correct" you because of the 1968 Mother of All Demos, but TIL it wasn't even given that name until 1994.

https://en.wikipedia.org/wiki/The_Mother_of_All_Demos#Origin...

Re: Data leak contains 26B records from numerous previous breaches

#124
post #4

I feel like the people who calculate that it's more cost effective to deal with the hit from a security breach vs spending money on good security have won. I have gone from feeling outraged to completely numb to these kind of disclosures and have pretty much just assumed that my information will inevitably be leaked somewhere by someone. Does anyone else feel this way? I just keep a close eye on my financial statemen…

I don't. I grew up where break-ins were not an uncommon occurance, so anything that shares my name, finances and address feels like gross negligence.

Re: Data leak contains 26B records from numerous previous breaches

#125

Earlier quoted context omitted.

> It’s time for attorney generals Attorneys general They are attorneys, so that is the word to pluralize. What type of attorney are they? General

I think its monomorphization: Attorneys:: ().

Wouldn't that be Vector::>() ?

Re: Data leak contains 26B records from numerous previous breaches

#126
post #4

I feel like the people who calculate that it's more cost effective to deal with the hit from a security breach vs spending money on good security have won. I have gone from feeling outraged to completely numb to these kind of disclosures and have pretty much just assumed that my information will inevitably be leaked somewhere by someone. Does anyone else feel this way? I just keep a close eye on my financial statemen…

Probably about 10-12 years ago I almost exclusively used +emails so I could determine with pretty high confidence who had breaches and failed to disclose OR identify companies that had sold my data without disclosure. One of the most recent examples was Robinhood Holdings. +emails only got me so far as 50% of sites don’t properly support the RFC5233 subaddressing standard and it ended up being a massive pain when a s…

yea, glad i didn't hop on the +mail thing.

catch-all email domains just work, thou it's a bit of a hassle to configure the sending address depending on the mua (ios mail grr)

Re: Data leak contains 26B records from numerous previous breaches

#127
post #4

I feel like the people who calculate that it's more cost effective to deal with the hit from a security breach vs spending money on good security have won. I have gone from feeling outraged to completely numb to these kind of disclosures and have pretty much just assumed that my information will inevitably be leaked somewhere by someone. Does anyone else feel this way? I just keep a close eye on my financial statemen…

> I feel like the people who calculate that it's more cost effective to deal with the hit from a security breach vs spending money on good security have won.

and it's not like it wasn't forseeable 20/40/60 years ago. thou the question remains what would be the alternative?

what really bugs me is the fact that it essentially puts all the 'nothing to hide, have my data' folks in the right because, yea, why bother.

Re: Data leak contains 26B records from numerous previous breaches

#128
post #74

All I see here is someone made a bigger list from multiple other lists from prior breaches. This isn't "the mother of all breaches", this is clickbait. Unless there is some new confirmed breach somewhere that in fact contains 26 billion records ex-filtrated, the only thing this is the mother of is a nothing burger.

I checked for some of my old emails in the list. As far as I can tell, "26B" is due to duplicates and fake data. There were dozens of entries for sites that were never registered for with passwords that were never used. I'd be surprised if it was less than 80% junk.

Re: Data leak contains 26B records from numerous previous breaches

#129

Earlier quoted context omitted.

Further cementing this broken idea of "identity" as something that can be stolen is most certainly not what we need! Rather we need AG's to start going after companies that attempt to collect negligently verified and other fake debts for the outright brazen fraud that it is, and a law that allow victims to procedurally recover triple damages for time/money spent defending against these companies and helping the compa…

Exactly. The whole idea that end users are responsible for their stolen "identity" is absurd. It was a successful tactic used by banks and credit bureaus to shed their responsibility of proper verification when opening lines of credit or other accounts.

Strong disagree that such a responsibility exists. I should be able to open a bank account with _nothing_, save perhaps a _de minimis_ initial deposit (one penny, or similar).

I can walk into a shop with a handful of cash, buy an item, and leave without anyone knowing who I was. That should be true of any good or service, including banking, that does not require additional data for direct practical reasons related to the provision of the service, e.g. cleaners need to know where you live. "Prevention of fraud/laundering/terrorism/whatever" is not such a reason.

Re: Data leak contains 26B records from numerous previous breaches

#130
post #90

Earlier quoted context omitted.

As a reminder for any US Citizens, there is an official path to getting this from each of the main three for free[1] is the approved method verified by FTC [2]. 1. https://annualcreditreport.com 2. https://consumer.ftc.gov/articles/free-credit-reports

This still puts the burden on the consumer of having to verify that their credit file is accurate, not to mention the even bigger burden of trying to correct it.

Furthermore it's a reactive measure. Locking credit reports and unlocking as needed can help mitigate some risks.
Post reply on HN