Live data from Hacker News

Data leak contains 26B records from numerous previous breaches

cybernews.com

141–150 of 150 posts

Re: Data leak contains 26B records from numerous previous breaches

#141

Earlier quoted context omitted.

> incentivizes holding as little personal data as possible The government does not want to incentivize that. https://en.wikipedia.org/wiki/Third-party_doctrine

I get the impression incentivizing holding little personal data is one of the goals of GDPR

Fair enough, I should have said "The US government does not want..."

Mention of attorneys general and social security numbers in OP's posting put me in a US mindset.

Re: Data leak contains 26B records from numerous previous breaches

#142
post #138

Earlier quoted context omitted.

> Can Amazon ship you products without knowing what you ordered Well the whole point of not implicitly trusting third parties would be to remove Amazon from the equation altogether and instead be P2P with the shipper with just a protocol between us. If we need a third party, we can find another peer for that based on the intersection of our trust graphs. It doesn't have to be a global conglomerate with an IT departme…

You replied to basically nothing I said, other than to say: It's better if everything is split up into smaller companies that are not interesting targets. Nothing you said addressed the uselessness of encryption for this task. PS. I hope you are aware that Amazon also sells things themselves, they are not just a shipper? And that even if Amazon sells for a 3rd party, you handle returns, etc, via Amazon? So even your…

Not smaller companies. No companies. Individual people. That's a little different than "smaller".

As for returns and such, that's what the explicitly trusted third party is for: Jimbob. He can meditate disputes because both parties trust him in that domain (or they trust someone who...) Maybe that limits the scope somewhat, but global scale is overrated. Transitive trust ought to get you plenty far.

As for encryption, Jimbob need not know either address to fulfill his role. Encryption is for hiding such things from him (and from the operator of any nodes that are needed to for the protocol to function).

As for not having a design ready for every one of your examples. You've got me there. My point is merely that the space of solutions to these problems which do not require implicit trust of somebody's IT department is larger than you presume, and largely unexplored.

Re: Data leak contains 26B records from numerous previous breaches

#143
post #12
post #4

I feel like the people who calculate that it's more cost effective to deal with the hit from a security breach vs spending money on good security have won. I have gone from feeling outraged to completely numb to these kind of disclosures and have pretty much just assumed that my information will inevitably be leaked somewhere by someone. Does anyone else feel this way? I just keep a close eye on my financial statemen…

It’s time for attorney generals to hold permanent identity monitoring pots and funds. The idea that someone can lose all your data and then pay for two years of identity monitoring is absurd. The people with the data can see that and can just wait two years to sell it. Social security numbers don’t reset after two years. If you lose data, you pay a data breach tax forever. Over time, your competitors will be able to…

Or rather we should double down on aliases: everything must store aliases instead of real data.

Re: Data leak contains 26B records from numerous previous breaches

#144

Earlier quoted context omitted.

I would go one step further, saying that proper verification is prone to fraud because of failure in government (in the US; not sure about other countries). It still baffles me that identification typically comes down to two things: social security card and driver's license, and both are managed by agencies whose primary objective is not identification. IMHO, it's time for a single agency at either the fed or state l…

I'll go yet another step further, and say that the main opposition to having a better technical system of government identification is because we're lacking a comprehensive privacy law akin to the GDPR. As it stands if the government started say issuing smart cards for identify verification, then every business would gradually force their customers to identify themselves, for helping the commercial surveillance indus…

Digital identification can be done correctly, i.e. give business one time pseudonym maybe with one time email pseudonym. Then businesses won't ask for such identification :)

Or it can require ATM, which is not frictionless.

Businesses already ask for phone numbers anyway. Can it become worse?

Re: Data leak contains 26B records from numerous previous breaches

#145

Earlier quoted context omitted.

I'll go yet another step further, and say that the main opposition to having a better technical system of government identification is because we're lacking a comprehensive privacy law akin to the GDPR. As it stands if the government started say issuing smart cards for identify verification, then every business would gradually force their customers to identify themselves, for helping the commercial surveillance indus…

There's also a significant constituency that believes any nationwide system of identity is the "mark of the beast" as spoken of in the Bible.

Phone numbers already do that.

Re: Data leak contains 26B records from numerous previous breaches

#146

Earlier quoted context omitted.

I'll go yet another step further, and say that the main opposition to having a better technical system of government identification is because we're lacking a comprehensive privacy law akin to the GDPR. As it stands if the government started say issuing smart cards for identify verification, then every business would gradually force their customers to identify themselves, for helping the commercial surveillance indus…

Digital identification can be done correctly, i.e. give business one time pseudonym maybe with one time email pseudonym. Then businesses won't ask for such identification :) Or it can require ATM, which is not frictionless. Businesses already ask for phone numbers anyway. Can it become worse?

Phone numbers are bad, but of course it could be worse. Phone numbers have both escape hatches (VOIP, shared number burner services, or your own psuedonymous SIM + device ID), and friction (people are wary of businesses spamming them).

Pseudonyms don't work for the topic under discussion, issuing credit. And for the general case, since credit issuers would be able to require you to do a non-psuedonym identification, then any other entity can require this as well, unless there were a privacy law.

(no idea what you mean by "ATM")

Re: Data leak contains 26B records from numerous previous breaches

#147

Earlier quoted context omitted.

I think its monomorphization: Attorneys:: ().

Wouldn't that be Vector:: >() ?

SMASH EVERYTHING INTO FLAT ENGLISH, GIVING COBOL!

LIST OF GENERAL ATTORNEYS FTW!

(SEE HOW EVEN THE ACRONYM AT THE END OF THE SENTENCE FITS INTO COBOL SYNTAX, BEING IN UPPERCASE?)

COMPILE IN A FLASH, DEBUG AT LEISURE.

AND DON'T FORGET YOUR COBOL PERIODS.

Re: Data leak contains 26B records from numerous previous breaches

#149

Earlier quoted context omitted.

Digital identification can be done correctly, i.e. give business one time pseudonym maybe with one time email pseudonym. Then businesses won't ask for such identification :) Or it can require ATM, which is not frictionless. Businesses already ask for phone numbers anyway. Can it become worse?

Phone numbers are bad, but of course it could be worse. Phone numbers have both escape hatches (VOIP, shared number burner services, or your own psuedonymous SIM + device ID), and friction (people are wary of businesses spamming them). Pseudonyms don't work for the topic under discussion, issuing credit. And for the general case, since credit issuers would be able to require you to do a non-psuedonym identification,…

>Pseudonyms don't work for the topic under discussion, issuing credit.

Because businesses want spammable addresses. That's why they won't ask for properly designed digital identification.

By ATM I mean you use ATM with your card to authenticate yourself. You can't use a smart card with thin air, can you?

Re: Data leak contains 26B records from numerous previous breaches

#150
post #42

That term is a bit clickbaity. Mother of all dumps would be more appropriate. This is all from old breaches.

The funny thing to me about this title is who brought that term to English in the first place. It came into the vernacular back in 1991 when Saddam Hussein claimed the Kuwait War would become "the mother of all wars". It didn't. It lasted about 24 hours, but the phrase has lasted much longer. It's so weird how language evolves, who has the power to do it, and who doesn't. So for me, the title means that this breach i…

"This aggression will not stand", as The Dude says
Post reply on HN