Live data from Hacker News

Inside the "3 billion people" national public data breach

troyhunt.com

151–160 of 472 posts

Re: Inside the "3 billion people" national public data breach

#151
post #116

Are there any ways to check the breach to see if my information is there, other than downloading it myself? I’m not sure of the legality of doing so.

I've seen https://npd.pentester.com/ floating around

The data seems to be at least 15 years old.

Re: Inside the "3 billion people" national public data breach

#152

I am just dreading the day when a near simultaneous cyberattack on a high number of(more vulnerable like middle-lower income individuals) start in a DDoS fashion: 1. Credit histories will be(unlocked) used to file multiple credit applications and tax credits will be applied for. 2. Multiple Cell phones will be hijacked through Sim Hijacking or other zeroday attacks to make it very difficult to get back in. 3. A perso…

I am wondering what the numbers are like for this to be realistic.

I am not too sure of the end goal other than general chaos. Let’s say it’s 2 days of an attack, (that’s about how long any co-ordinated response would need at minimum).

So attackers need to sow chaos across the USA. They apply for a million unsecured loans of say 20k each. That’s 20 billion.

I honestly don’t know what the daily personal loan application rate is, but america has about 150M adults, 1% of them applying on the same day will not only raise flags but would basically grind the system to a halt - each loan office would have daily maximums and a massive spike coukd not be handled. And once the massive crowd is noticed and made public then the financial immune system comes into play.

I can imagine taking out the cell network through a sort of SS7 ddos, but I suspect that cell towers might have a dose more vulnerabilities (probably not as basic as all the admin passwords are ComC4astSux but close)

In general Chaos seems to come from attacking the limited services that act as our safety net (ambulance, police, sewage, electricity). We know these are vulnerable in non obvious ways - crowdstrike for example.

Making otherwise fit and healthy citizens have a shitty day is less impactful than we might think - it will be the “blip” day - as I say 48 hours later the Treasury secretary goes on TV and announces all personal loans that day got cancelled or some other fix - finance has a fairly good immune system when it sees the need.

But overall, if we are going to worry about some attacks, let’s look at the ones that attack our freshwater supplies - and that might not mean some terrorist - in the UK our sewage handling has been under attack by Private Equity for decades and SWAT teams are not allowed to shoot people in Belgravia

Re: Inside the "3 billion people" national public data breach

#153

Troy mentions "data opt-out services. Every person who used some sort of data opt-out service was not present." Anyone have experience with these sort of services? A search brings up a lot of scammy looking results. But if services exist to reduce my profile id be interested.

> Anyone have experience with these sort of services? Quite a bit. Often if you request removal or opt-out, you'll reappear in a matter of a few months in their system, regardless of whether you use a professional service as a proxy or do it yourself. The data brokers usually go out of their way to be annoying about it and will claim they can't do anything about you showing up in their aggregated sources later on. Th…

I've had a very bad experience with Liberty Mutual following a data opt-out from another service. They sent me on a runaround, ending with an email saying to follow "this link" to verify myself. (There was no link, only sketch.) I ended up getting a human on a phone through special means, and they sent me a fixed email with a working link.

I should be hearing back from them in the next 32 days, as this was 13 days ago.

Re: Inside the "3 billion people" national public data breach

#154

And where is this information that this random group supposedly has? I have yet to see proof of that being real

I was able to get a hand on it, and I was able to confirm that some records of loved ones are indeed present (although mine was not.)

Re: Inside the "3 billion people" national public data breach

#155
Several other commenters have brought about the sneaky wordplay involved in saying "identity theft" instead of simply calling it "fraud on the bank", and somehow turning the person into the victim rather than the bank that has been defrauded.

Has anyone tried to argue this point in court? Has this survived / how did this terminology shift survive judicial scrutiny?

Re: Inside the "3 billion people" national public data breach

#156

I am just dreading the day when a near simultaneous cyberattack on a high number of(more vulnerable like middle-lower income individuals) start in a DDoS fashion: 1. Credit histories will be(unlocked) used to file multiple credit applications and tax credits will be applied for. 2. Multiple Cell phones will be hijacked through Sim Hijacking or other zeroday attacks to make it very difficult to get back in. 3. A perso…

In the US, the government could help alot if they simply moved to a national ID system and dismantled social security numbers.

The national ID systems I've seen proposed have alot more security from the ground up, and could replace the passport system.

Re: Inside the "3 billion people" national public data breach

#157
post #113

Earlier quoted context omitted.

It's hard to make collection, aggregation, and sharing of facts illegal. Not to minimize the harm that can be done by such collections, but the law is justifiably looking for a scalpel treatment here to address the specific problem without putting the quest to understand reality on the wrong side of the line.

Europe figured it out.

Sure, I should probably have clarified "In the United States," where there's a First Amendment that most attempts to make fact-sharing illegal immediately fall afoul of.

There are definitely exceptions, but it puts strict scrutiny on any novel prior constraint of speech.

Re: Inside the "3 billion people" national public data breach

#158
post #142

Earlier quoted context omitted.

When someone named adamomada comes to the bank for a loan, the presumption is that adamomada will repay the loan. If they knew it wasn't you, they wouldn't have written the loan in the first place. They're asking you to repay it because they really do think it was you. If "it wasn't me" was all anyone had to do to get out of paying a loan, many people would do it.

It's much more subtle, fraud is accepted and part of the business. Even if you are not 100% certain of the identity of the person, what matters is how likely you are going to get paid back. For example, when you purchase online, some merchants do not check who is the owner of the card, or the address. It's done on purpose, because some people borrow the card of the others, some people don't want to use their card, et…

It’s not “accepted” as much as it is just simply impossible to completely avoid at any kind of scale.

Even if online payments were eliminated, and you had to show up in person with a birth certificate and passport to perform a transaction, fraud would be non-zero.

To have a functioning business, people need to be able to use the system.

Re: Inside the "3 billion people" national public data breach

#159
post #13

Troy mentions "data opt-out services. Every person who used some sort of data opt-out service was not present." Anyone have experience with these sort of services? A search brings up a lot of scammy looking results. But if services exist to reduce my profile id be interested.

Permission Slip by Consumer Reports (automated): https://permissionslipcr.com Simple Opt Out (manual list): https://simpleoptout.com

I use permission slip and I am not in the breach as far as I can tell

Re: Inside the "3 billion people" national public data breach

#160

I am just dreading the day when a near simultaneous cyberattack on a high number of(more vulnerable like middle-lower income individuals) start in a DDoS fashion: 1. Credit histories will be(unlocked) used to file multiple credit applications and tax credits will be applied for. 2. Multiple Cell phones will be hijacked through Sim Hijacking or other zeroday attacks to make it very difficult to get back in. 3. A perso…

In the US, the government could help alot if they simply moved to a national ID system and dismantled social security numbers. The national ID systems I've seen proposed have alot more security from the ground up, and could replace the passport system.

The US has done itself a disservice with their actions because few people trust the government. A national ID system means a database of all Americans that would very likely be used for surveillance and monitoring. I'm saying this as someone who has Global Entry so it's not like I'm afraid of being in a US database but I see the concerns.
Post reply on HN