Live data from Hacker News

Inside the "3 billion people" national public data breach

troyhunt.com

291–300 of 472 posts

Re: Inside the "3 billion people" national public data breach

#291

"there were no email addresses in the social security number files. If you find yourself in this data breach via HIBP, there's no evidence your SSN was leaked, and if you're in the same boat as me, the data next to your record may not even be correct. " Seems like Troy is skeptical about this being a real full breach?

>the data next to your record may not even be correct. "

American Express by way of Experian alerted me to my SSN having been leaked precisely by this incident.

The number was seemingly correct, but everything else associated with it such as name and address were nonsense.

So assuming we're talking about the same thing... can confirm?

Re: Inside the "3 billion people" national public data breach

#292

Earlier quoted context omitted.

I have been using a different site@mydomain email address for every service I've used for the past 15 years. I can point to exactly which site breach furnished my email address to the aggregators.

Care to call out some bad actors so others know to avoid business with them? I recently started using unique emails for everything I sign up for. Thankfully I haven’t seen anything yet, but I have little hope it will stay that way.

I second this request of releasing the results of this “digital tracer dye” experiment. If their respect for your personal data is that low, they deserve to be named and shamed. And more.

Re: Inside the "3 billion people" national public data breach

#293
post #286

What if we just made all this data free , some AI is going to compile them anyway (and probably already has). Deterrence is the best defense, right ?

It depends on the country. Where I live now even if I leak my name, date of birth, bank details, national id number, etc. you couldn't do much. We have a country wide 2FA system that all important businesses use (bank, utilities, health, government) to authenticate users.

I'm from the UK though, and previously was a 'victim' of identify theft where a few years ago someone walked into a phone store, and walked out with a new iPhone and contract in my name.

Re: Inside the "3 billion people" national public data breach

#295

Earlier quoted context omitted.

You probably are posting this as a joke, but without a clear technical solution to this problem, flooding the industry with bullshit data seems like a great avenue.

I have a silly standup joke along these lines, about how I'd Google things crazy things like "circus lawyer" or "giraffe mitigation tactics" to throw the algorithm off every now and then.

My friend is a thriller writer and is convinced he’s on some FBI list. He’s googling stuff such as “how to dissolve a body with quicklime” and all sorts of other fun stuff while researching for his books.

Re: Inside the "3 billion people" national public data breach

#296

> While the specifics of the data breach remain unclear, the trove of data was put up for sale on the dark web for $3.5 million in April, the complaint reads. I guess they failed to sell it because links to the leaked data on usdod.io have been available on Breachforum/Leakbase for over a week now. Someone created a magnet link yesterday and it's fully seeded so speeds are fast. The data in the breach is irreversibly…

Nobody's gonna pay that much money for it when you can get it from ad companies for pennies

Re: Inside the "3 billion people" national public data breach

#297
post #185

Earlier quoted context omitted.

Has anyone been able to reverse this base64 encryption? Whatever am I going to do with this?

It can't be reversed, unfortunately. base64 has been peer proven as mathematically unhackable.

Same for base16. That's why those pesky hash digests always use it.

Re: Inside the "3 billion people" national public data breach

#298

"there were no email addresses in the social security number files. If you find yourself in this data breach via HIBP, there's no evidence your SSN was leaked, and if you're in the same boat as me, the data next to your record may not even be correct. " Seems like Troy is skeptical about this being a real full breach?

I'm in the UK so I have no Social Security Number, and I still got the HIBP e-mail.

When I looked into it, it turns out the "original" breach is comprised of files named ssn.txt and ssn2.txt which only contains Americans details, and doesn't contain any e-mail addresses.

It seems what happened is there was one leak of US SSNs which the leakers attributed to NPD, then some people bundled that leak up with a bunch of other data (including e-mail addresses and details of non-americans) and who knows if the latter data actually came from NPD?

Re: Inside the "3 billion people" national public data breach

#299

Earlier quoted context omitted.

You probably are posting this as a joke, but without a clear technical solution to this problem, flooding the industry with bullshit data seems like a great avenue.

that was the idea behind certain applications and add-ons that would browse around to popular websites and randomly click ads so that marketers couldn't tell your actual interests from fake ones. Unfortunately that strategy is deeply flawed and dangerous because nobody cares if the data they have on you is accurate or not. They still can, and still will, use it against you at every opportunity. Every scrap of data th…

> might decide to raise the rates of every single member within that neighborhood or zip code

Wouldn't that be against redlining laws? https://en.wikipedia.org/wiki/Redlining

Re: Inside the "3 billion people" national public data breach

#300
post #42
post #8

Earlier quoted context omitted.

If you're willing to tempt fait, the best way to 'opt-out' is to tell people, when they call asking to speak to 'your name', that 'your name' sadly passed away recently.

I knew someone falsely declared dead (probably a paperwork mixed up around pensions when his ex-spouse died). Without warning, he lost all of his pensions, social security, medicare, etc, along with most financial institutions freezing accounts and canceling credit cards. Many long phone calls, letters, and lawyers eventually resolve most, but that never fully purged the public and private death records so there woul…

You'd think something like that would require a death certificate to actually happen
Post reply on HN