Live data from Hacker News

Data leak contains 26B records from numerous previous breaches

cybernews.com

131–140 of 150 posts

Re: Data leak contains 26B records from numerous previous breaches

#131
post #4

I feel like the people who calculate that it's more cost effective to deal with the hit from a security breach vs spending money on good security have won. I have gone from feeling outraged to completely numb to these kind of disclosures and have pretty much just assumed that my information will inevitably be leaked somewhere by someone. Does anyone else feel this way? I just keep a close eye on my financial statemen…

That's why you register with garbage personal details.

Re: Data leak contains 26B records from numerous previous breaches

#132

Earlier quoted context omitted.

100% with you. At this point my data has been breached so many times I don't even know what the point of caring is. I don't have privacy anymore. Like you I just have credit monitoring and watch my financial statements and hope for the best. This world sucks.

Know what? I heard it was illegal in the UK to give websites fake information. But looking at that list of websites justifies what I have been doing for the past 18 years religiously. When a website asks my age, I give it a fake one. When a shop asks for my debit card details I give it my initials J B and then I will confirm the sms security from my bank when the initials flag 30% of the time. Giving every company re…

100% with you. It depends on the site but yeah a lot of my information is fake. I really don't understand why so many websites think they need things like my address or phone number anyway. Good thing I live on 100 YouDontNeedThis Blvd!

Re: Data leak contains 26B records from numerous previous breaches

#133

Earlier quoted context omitted.

It also incentivizes holding as little personal data as possible and increases the probability of coordinated adoption of systems[1][2][3][4][5] of identification/verification that minimize collateral damage. 1. https://sovrin.org/ 2. https://github.com/sertoID/ 3. https://www.hyperledger.org/projects/hyperledger-indy 4. https://identity.foundation/ion/ 5. https://www.civic.com/

> incentivizes holding as little personal data as possible The government does not want to incentivize that. https://en.wikipedia.org/wiki/Third-party_doctrine

I get the impression incentivizing holding little personal data is one of the goals of GDPR

Re: Data leak contains 26B records from numerous previous breaches

#134
post #109

Earlier quoted context omitted.

The government is the problem. They issue me a single identification number that can be used anywhere at anytime without any verification or notification that it has been used, and it's next to impossible to get a new one issued. This is madness. A state funded "insurance" system to backstop this mistake is an unworkable hack that seeks to ignore the fundamental problem.

The government only claimed to identify you with that number for one purpose. The motivation for fraud would be a lot lower if that was the way it was still. The problem is third parties abused that number for their own purposes. Imagine if some company somewhere started using phone numbers as identifiers, and criminals started defrauding that company by "stealing" other people's phone numbers. Would you blame the ph…

Don't we blame phone companies for being vulnerable to SIM card swapping?

Re: Data leak contains 26B records from numerous previous breaches

#136
post #129

Earlier quoted context omitted.

Exactly. The whole idea that end users are responsible for their stolen "identity" is absurd. It was a successful tactic used by banks and credit bureaus to shed their responsibility of proper verification when opening lines of credit or other accounts.

Strong disagree that such a responsibility exists. I should be able to open a bank account with _nothing_, save perhaps a _de minimis_ initial deposit (one penny, or similar). I can walk into a shop with a handful of cash, buy an item, and leave without anyone knowing who I was. That should be true of any good or service, including banking, that does not require additional data for direct practical reasons related to…

I'm sympathetic to your comment, but we are talking about the issuing of credit. Surely you see that this idea is a non-starter for a bank issuing credit?

This is further complicated by US bank accounts including an intrinsic bit of credit from writing checks and other ACH debits.

Re: Data leak contains 26B records from numerous previous breaches

#137
post #108
post #4

I feel like the people who calculate that it's more cost effective to deal with the hit from a security breach vs spending money on good security have won. I have gone from feeling outraged to completely numb to these kind of disclosures and have pretty much just assumed that my information will inevitably be leaked somewhere by someone. Does anyone else feel this way? I just keep a close eye on my financial statemen…

The easiest thing is to just stop registering for useless garbage.

Recently both my mortgage company, who bought my mortgage from another company without any say from me in the matter, had a giant leak. You heard about it. I'm hardly alone .

Then Comcast/Xfinity, same thing. I have 2 options for internet, now, it seems. Comcast or now starlink.

Point is, you can plunk your information into relative bare-minimum of sketchiness -- and you'll still be screwed over.

Re: Data leak contains 26B records from numerous previous breaches

#138
post #83

Earlier quoted context omitted.

There's only a limited number of things that can be done that way. Basically point-to-point messaging. Most things aren't going to work with that model. Can Amazon ship you products without knowing what you ordered? Can you send and receive email on multiple devices without the provider having your email? Can you join public chat groups? Can you view your lab results without the lab having them? And don't say "the la…

> Can Amazon ship you products without knowing what you ordered Well the whole point of not implicitly trusting third parties would be to remove Amazon from the equation altogether and instead be P2P with the shipper with just a protocol between us. If we need a third party, we can find another peer for that based on the intersection of our trust graphs. It doesn't have to be a global conglomerate with an IT departme…

You replied to basically nothing I said, other than to say: It's better if everything is split up into smaller companies that are not interesting targets.

Nothing you said addressed the uselessness of encryption for this task.

PS. I hope you are aware that Amazon also sells things themselves, they are not just a shipper? And that even if Amazon sells for a 3rd party, you handle returns, etc, via Amazon? So even your singular example demonstrates exactly what I said: this idea would not work.

Re: Data leak contains 26B records from numerous previous breaches

#139
post #129

Earlier quoted context omitted.

Exactly. The whole idea that end users are responsible for their stolen "identity" is absurd. It was a successful tactic used by banks and credit bureaus to shed their responsibility of proper verification when opening lines of credit or other accounts.

Strong disagree that such a responsibility exists. I should be able to open a bank account with _nothing_, save perhaps a _de minimis_ initial deposit (one penny, or similar). I can walk into a shop with a handful of cash, buy an item, and leave without anyone knowing who I was. That should be true of any good or service, including banking, that does not require additional data for direct practical reasons related to…

That is fine for opening a deposit account. The fraud we're talking about is for obtaining credit or future financial obligations. It is wrong to let this be done with so little proof of identity and enforce the obligation in courts.

Banks have notaries of the public. After you have established a relationship with a bank, the notary may have enough evidence to authenticate you for others. If you have continued to use the bank in an anonymous manner, then you should not be authenticated to others.

Re: Data leak contains 26B records from numerous previous breaches

#140
post #109

Earlier quoted context omitted.

The government only claimed to identify you with that number for one purpose. The motivation for fraud would be a lot lower if that was the way it was still. The problem is third parties abused that number for their own purposes. Imagine if some company somewhere started using phone numbers as identifiers, and criminals started defrauding that company by "stealing" other people's phone numbers. Would you blame the ph…

They themselves abused it as anyone in military service is well aware. Then they required you to put it on your IRS forms, even though the Social Security Administration is a wholly independent agency. Then they required banks to capture it for any customer. It goes on.. third parties weren't the worst and they didn't start it and some are required by law. Imagine if Credit Card companies were as blatantly incompeten…

It seldom creates significant inconvenience or financial obligations when someone pays additional taxes in your name. It only becomes a significant problem when the fraudster is obtaining money or services in your name.

The burden of authentication is not on the entity who issued a simple ID number, it is on those who go on to use it as if it is a secret.

I think your trust in credit card companies is misplaced. The only thing that holds them back is consumer protection laws, and they fight those however they can. Jack up rates, check. Grant credit at a sales point of presence with a minimum wage sales clerk doing identification, check. Sell or trade your payment history, check.

In some moral systems, lending money to make money itself is outright wrong. If you maintain a balance on your credit card for day to day expenses, any financial advisor will tell you to stop that.

Post reply on HN