Live data from Hacker News

Inside the "3 billion people" national public data breach

troyhunt.com

261–270 of 472 posts

Re: Inside the "3 billion people" national public data breach

#261
post #185

Earlier quoted context omitted.

Here is a strongly encrypted base64 version to keep hackers out: bWFnbmV0Oj94dD11cm46YnRpaDozY2FhNzFmM2VjOGNiY2NjNmZjYTRmZWI3MTg1ZGEyYmFiMTQ5YmE3JmRuPU5QRCZ0cj11ZHA6Ly90cmFja2VyLm9wZW5iaXR0b3JyZW50LmNvbTo4MCZ0cj11ZHA6Ly90cmFja2VyLm9wZW50cmFja3Iub3JnOjEzMzcvYW5ub3VuY2U= Allegedly, the password (also base64 encrypted) is: aHR0cHM6Ly91c2RvZC5pby8=

Has anyone been able to reverse this base64 encryption? Whatever am I going to do with this?

https://www.base64decode.org/

I hope this helps you

Re: Inside the "3 billion people" national public data breach

#262

> While the specifics of the data breach remain unclear, the trove of data was put up for sale on the dark web for $3.5 million in April, the complaint reads. I guess they failed to sell it because links to the leaked data on usdod.io have been available on Breachforum/Leakbase for over a week now. Someone created a magnet link yesterday and it's fully seeded so speeds are fast. The data in the breach is irreversibly…

Now everyone just needs to send their email addresses to HIBP, i.e., email HIBP, so he can connect these identities with IP addresses and working email accounts. For peoples' protection of course. After everyone "has been pwned" then there is no need for HIBP. The answer is always "yes". Yet I am certain sites like "HIBP" will never go away. Something about email marketing. Some HN commenter(s) will inevitably try to…

> After everyone "has been pwned" then there is no need for HIBP.

You can be repeatedly pwned with updated/different information. It is not a one and done thing.

Re: Inside the "3 billion people" national public data breach

#263
post #185

Earlier quoted context omitted.

Has anyone been able to reverse this base64 encryption? Whatever am I going to do with this?

It can't be reversed, unfortunately. base64 has been peer proven as mathematically unhackable.

Username checks out.

Re: Inside the "3 billion people" national public data breach

#265

Earlier quoted context omitted.

Now everyone just needs to send their email addresses to HIBP, i.e., email HIBP, so he can connect these identities with IP addresses and working email accounts. For peoples' protection of course. After everyone "has been pwned" then there is no need for HIBP. The answer is always "yes". Yet I am certain sites like "HIBP" will never go away. Something about email marketing. Some HN commenter(s) will inevitably try to…

> After everyone "has been pwned" then there is no need for HIBP. You can be repeatedly pwned with updated/different information. It is not a one and done thing.

And people are born and die

Re: Inside the "3 billion people" national public data breach

#267

For non-Americans (and Americans) that don't quite understand what SSN is and why it's a problem, CGP Grey [1] has a great (and short) video about the history and why it's not technically an identifier, but has become one. [1] https://www.youtube.com/watch?v=Erp8IAUouus

It's so interesting how Australia went the other way and actually banned the use of any government-issued ID number as a primary identifier by any organisation other than the government department which issued that ID number. In the 80s, the very popular Aussie prime minister, Bob Hawke wanted to introduce a National ID card, complete with a unique number, that would then be used for everything from Medicare to tax f…

Shorten announced details yesterday of another attempt at an Australian digital id that actually seems informed by Optus and Medibank

https://www.abc.net.au/news/2024-08-13/trust-exchange-digita...

Re: Inside the "3 billion people" national public data breach

#268

Earlier quoted context omitted.

> After everyone "has been pwned" then there is no need for HIBP. You can be repeatedly pwned with updated/different information. It is not a one and done thing.

And people are born and die

Allegedly /s

Re: Inside the "3 billion people" national public data breach

#269

Earlier quoted context omitted.

You too can be a data broker! for (i = 0; i Does anyone really really care if the name is accurate if the SSN is present? More than half of the SSNs in the above dataset are valid.

You probably are posting this as a joke, but without a clear technical solution to this problem, flooding the industry with bullshit data seems like a great avenue.

I have a silly standup joke along these lines, about how I'd Google things crazy things like "circus lawyer" or "giraffe mitigation tactics" to throw the algorithm off every now and then.

Re: Inside the "3 billion people" national public data breach

#270
post #48
post #35

Earlier quoted context omitted.

my understanding is that there's a bit of a catch-22 with data removal - if you request that a data broker remove ALL of your information, it's impossible for them to keep you from reappearing in their sources later on because that would require them to retain your information (so they can filter you out if you appear again).

I’ve heard this claim, but they could use some sort of bloom filter pr cryptographic hashing to block profiles that contain previously-removed records. There could also be a shared, trusted opt-out service that accepted information and returned a boolean saying “opt-out” or “opt-in”. Ideally, it’d return “opt-out” in the no-information case.

Yup, it would be trivial to create a one way hash of various attributes to perma ‘opt out’ someone.

But how would they keep making money that way?

Post reply on HN