Live data from Hacker News

Inside the "3 billion people" national public data breach

troyhunt.com

211–220 of 472 posts

Re: Inside the "3 billion people" national public data breach

#211

Earlier quoted context omitted.

The Google Authenticator app (just as a mainstream example) was released 14 years ago. When we're still waiting for a lot of banks to even support TOTP, consider me unimpressed with the level of effort banks are putting into securing my accounts.

Good news loyal customer, we now support 2-factor authentication! ... over SMS!

I had phone number stolen (sim swap) two months ago and am still dealing with random things.

2FA over SMS is not a valid form of 2FA and I will die on that hill.

Re: Inside the "3 billion people" national public data breach

#212

This sort of stuff will continue happening until the regulatory framework acknowledges a fundamental consumer right to privacy. If a data broker collects data without the consent of the consumer, then their only real risk is a class action lawsuit which drags on for six years, gets settled for a few days profit, and the consumer gets $13.50 after the legal fees. This massive skew in the risk reward calculus of data b…

[deleted]

Re: Inside the "3 billion people" national public data breach

#213

This sort of stuff will continue happening until the regulatory framework acknowledges a fundamental consumer right to privacy. If a data broker collects data without the consent of the consumer, then their only real risk is a class action lawsuit which drags on for six years, gets settled for a few days profit, and the consumer gets $13.50 after the legal fees. This massive skew in the risk reward calculus of data b…

They should tax companies so that operating data centers become more expensive. Increase price of electricity or property tax. That will inherently force companies to collect and store less data, hence less damage from breaches.

Re: Inside the "3 billion people" national public data breach

#214
the government should have put out honey pots or something, or maybe it’s time to get new numbers and just invalidate all the stolen data, there is clearly money for fixing this kind of thing but they’re using it to spy on us and do who knows what else instead

Re: Inside the "3 billion people" national public data breach

#215

Earlier quoted context omitted.

It isn't great, but I don't think there's much risk there. There's not really much of a motivation for some random person to get into my utility account. The balance is never positive. Utilities are physically bolted to my house. They're pretty heavily regulated too. If someone wanted to steal electricity from my house, they can use the outlet on my patio that has zero authentication whatsoever.

You should read some fraudster diaries. Having the SSN as authentication, means you can con the utilities employee into handing over all of your other personal information. Date of birth, current and past adresses, spouse or roommates, parents if they are with the same utility company. They can then turn around and use that information to apply for a credit card. Now all they need is to wait by your mailbox or pay th…

Yeah, I’m aware that any data that can be used to obtain more data is an issue. But I figure if someone knows my utility company and SSN, they probably already have an address. And with an address it’s easy to get the rest of that information through people search and public records.

Re: Inside the "3 billion people" national public data breach

#216
post #78

Earlier quoted context omitted.

For argument sake, instead of outlawing data brokers wouldn’t it be better to design a better ID system that renders one’s name, dob, and SSN as harmless information? I don’t know what that would look like but if I had congresses attention I’d like them to fix the problem rather than playing whack-a-mole with banning data sources. I don’t think any actual solutions come from that.

In many countries in Europe, your ID card contains a chip with a cryptographic key, much like chip&pin on a debit or credit card. Those bits of information are worthless when you need to create a cryptographic signature with your ID card to do almost anything important. If the card is lost or stolen they can just remove your old one from the keyserver. It's literally just public key crypto. Identity theft is rampant…

How is key revocation authenticated?

Re: Inside the "3 billion people" national public data breach

#217

Earlier quoted context omitted.

I will say that their list of reasons is deeply flawed. > Human beings can't read a bar code. - they can, and more importantly they almost never have to > A lot of our product comes from cottage industries in Asia that couldn't mark their goods with bar codes if they tried. - They can be added at the store/warehouse level, not every product needs one, and I've never seen a store that worked entirely on bar codes 100%…

How about this: without barcodes, you can't replace your clerks with self-checkout machines

Decathlon has RFID tags.

Re: Inside the "3 billion people" national public data breach

#218

> While the specifics of the data breach remain unclear, the trove of data was put up for sale on the dark web for $3.5 million in April, the complaint reads. I guess they failed to sell it because links to the leaked data on usdod.io have been available on Breachforum/Leakbase for over a week now. Someone created a magnet link yesterday and it's fully seeded so speeds are fast. The data in the breach is irreversibly…

Now everyone just needs to send their email addresses to HIBP, i.e., email HIBP, so he can connect these identities with IP addresses and working email accounts. For peoples' protection of course.

After everyone "has been pwned" then there is no need for HIBP. The answer is always "yes". Yet I am certain sites like "HIBP" will never go away. Something about email marketing.

Some HN commenter(s) will inevitably try to defend HIBP. But this comment also refers to sites "like HIBP" that use data breach dumps opportunistically to generate web traffic, collect IP and email addresses. Some folks just do not see what is wrong with the idea.

Re: Inside the "3 billion people" national public data breach

#219

Earlier quoted context omitted.

Hobby Lobby's CEO provided a handy list of reasons why they do not use bar codes, none of which have anything to do with them being marks of beasts https://www.snopes.com/fact-check/hobby-lobby-mark-of-the-be...

I will say that their list of reasons is deeply flawed. > Human beings can't read a bar code. - they can, and more importantly they almost never have to > A lot of our product comes from cottage industries in Asia that couldn't mark their goods with bar codes if they tried. - They can be added at the store/warehouse level, not every product needs one, and I've never seen a store that worked entirely on bar codes 100%…

Personally, Hobby Lobby's poor inventory management is a major frustration for me as a customer. Unlike other stores, they don't have any way for me to check online whether the product that I want is at their store. Granted, I avoid shopping at Hobby Lobby in general due to their owners regressive views; but at those times when I couldn't find something at a competitor it would have been helpful to be able to see if I could get it from them.

Re: Inside the "3 billion people" national public data breach

#220

Earlier quoted context omitted.

I never really understood why the onus is on any person to prove they didn’t do something. Shouldn’t the shaggy defence be sufficient? e.g. You get hauled into court for a lawsuit demanding the loan repayment, for a loan someone else used your name to get? - It wasn’t me. https://en.wikipedia.org/wiki/Shaggy_defense

The reason the Shaggy defense doesn't work is the default assumption of the courts is that you're a deadbeat trying to game the system. This assumption comes about because in the majority of cases it is the truth. The system would be a lot nicer if there weren't people trying to scam it every hour of every day of the week.

Doesn't that violate innocent until proven guilty?
Post reply on HN