Live data from Hacker News

Inside the "3 billion people" national public data breach

troyhunt.com

321–330 of 472 posts

Re: Inside the "3 billion people" national public data breach

#321

Earlier quoted context omitted.

You probably are posting this as a joke, but without a clear technical solution to this problem, flooding the industry with bullshit data seems like a great avenue.

that was the idea behind certain applications and add-ons that would browse around to popular websites and randomly click ads so that marketers couldn't tell your actual interests from fake ones. Unfortunately that strategy is deeply flawed and dangerous because nobody cares if the data they have on you is accurate or not. They still can, and still will, use it against you at every opportunity. Every scrap of data th…

> Every scrap of data they have, accurate or not, can be used to hurt you.

What are some examples of inaccurate data, as in completely false data, being able to hurt me?

Re: Inside the "3 billion people" national public data breach

#322

> While the specifics of the data breach remain unclear, the trove of data was put up for sale on the dark web for $3.5 million in April, the complaint reads. I guess they failed to sell it because links to the leaked data on usdod.io have been available on Breachforum/Leakbase for over a week now. Someone created a magnet link yesterday and it's fully seeded so speeds are fast. The data in the breach is irreversibly…

Now everyone just needs to send their email addresses to HIBP, i.e., email HIBP, so he can connect these identities with IP addresses and working email accounts. For peoples' protection of course. After everyone "has been pwned" then there is no need for HIBP. The answer is always "yes". Yet I am certain sites like "HIBP" will never go away. Something about email marketing. Some HN commenter(s) will inevitably try to…

There is trust involved here. And people trust Troy Hunt.

And of course you can download SHA ranges and do lookup offline: https://www.troyhunt.com/ive-just-launched-pwned-passwords-v...

He even previously encouraged to download via torrent, but now it seems there is a custom tool to download that data.

Re: Inside the "3 billion people" national public data breach

#323

Earlier quoted context omitted.

If they have your address; birthday; and SSN a whole lot. Generally, they could apply for credit cards; loans; set something to bill to you; etc... Fortunately, it's getting harder without previous addresses or other verification methods. For non-Americans that don't know, our Social Security number is generally assigned at birth or when you become a citizen by the Social Security Administration. Social Security is a…

Do you need SSN for voting? I heard that you don't need an ID (at least in some states) which was very weird for me but if they ask SSN instead, that is at least something I guess?

No, SSN is not used for voting.

Voting requirements and eligibility are set individually by each state, sometimes even in finer detail, New York City wanted to give immigrants the right to vote in local school board elections for example.

SSN are administered by the federal government and are opt-in(however most people apply for one) so it is not something a state can really use as a voting requirement.

State I currently live in(GA), you need to bring a photo ID for in person voting: - Drivers License(from any state or federal government) - State ID card - Student ID card - ID badge from any state or federal workplace - Passport - Military ID - Tribal ID Data was cross check to an online voter registration database.

Prior state (NC), I think the ID requirements were similar(possibly more relaxed) but at that time the data was checked to the voter roll, a book with the name and address of all the people in the precinct. When you went to vote, you signed by your name and then it was crossed off the list.

Re: Inside the "3 billion people" national public data breach

#324

Troy mentions "data opt-out services. Every person who used some sort of data opt-out service was not present." Anyone have experience with these sort of services? A search brings up a lot of scammy looking results. But if services exist to reduce my profile id be interested.

In the past I have just searched for my own name. And when I found a match, I would go to that site and request to be removed. It is a lot of work, but thus far it has been successful.

And I say this, because I was on a TV show years ago, so my real name is all over the internet from an entertainment point of view. But, if you search my real name, there are little to none pointing back to "public record" websites and the such.

Re: Inside the "3 billion people" national public data breach

#325

Earlier quoted context omitted.

I have been using a different site@mydomain email address for every service I've used for the past 15 years. I can point to exactly which site breach furnished my email address to the aggregators.

Care to call out some bad actors so others know to avoid business with them? I recently started using unique emails for everything I sign up for. Thankfully I haven’t seen anything yet, but I have little hope it will stay that way.

[deleted]

Re: Inside the "3 billion people" national public data breach

#326
post #147

Earlier quoted context omitted.

The US has three dumb points pushing back on this. The first is religious nuts who think it would be a "mark of the beast" The second is anti-government types who are, well, anti-government anything. The third is many business owners, because it would become much harder/risky to hire illegal immigrants to work.

> The third is many business owners, because it would become much harder/risky to hire illegal immigrants to work. Big one, but even though employing illegal immigrants is a crime, it's almost never prosecuted.

It's trivial as an immigrant to get a (stolen) SSN. Business owners are not responsible for checking if the SSN is stolen or not.

Re: Inside the "3 billion people" national public data breach

#327
post #184

Earlier quoted context omitted.

For argument sake, instead of outlawing data brokers wouldn’t it be better to design a better ID system that renders one’s name, dob, and SSN as harmless information? I don’t know what that would look like but if I had congresses attention I’d like them to fix the problem rather than playing whack-a-mole with banning data sources. I don’t think any actual solutions come from that.

Funny you should say that. Australia is trying to launch TEx -designed on open-source models to do this kind of thing. It's hitting the usual roadblocks of public acceptance of government mandated ID, in an economy which trashed the "australia card" idea back in the 80s. We're wiser now, we've been frogs boiled slowly: the downsides of central safe ID/auth are outweighed by the risks of loss of info giving everyone 1…

> layer-2 logs on our phones are constant.

Huh?

Re: Inside the "3 billion people" national public data breach

#328
post #249

Ahh, cool, pour the corpus through GPTs and start tweeting Congressional rep personal info at them until they pass a law to outlaw data brokers (in keeping with historical precedent [1] [2]). [1] https://en.wikipedia.org/wiki/Video_Privacy_Protection_Act [2] https://jolt.law.harvard.edu/digest/dodging-the-thought-poli...

We detached this subthread from https://news.ycombinator.com/item?id=41249125 .

I thought it was a legitimate proposal to the problem at hand, but respect and understand the decision. My apologies for taking the conversation potentially off topic.

https://paulgraham.com/founders.html

> Though the most successful founders are usually good people, they tend to have a piratical gleam in their eye. They're not Goody Two-Shoes type good. Morally, they care about getting the big questions right, but not about observing proprieties. That's why I'd use the word naughty rather than evil. They delight in breaking rules, but not rules that matter. This quality may be redundant though; it may be implied by imagination.

While scoped to founders, I think it broadly applies to a subset of curious people who are wired to solve problems, imho.

Re: Inside the "3 billion people" national public data breach

#329

Earlier quoted context omitted.

conveniently emitting the fact that this is a reaction to immigrants going around randomly attacking birtish people. If you aren't already consider workong for MSM.

That doesn't make it any less racist! But please give some more details on that. The only case I've heard about was a single attacker who was incorrectly called an immigrant.

To bring up more things in the broader context, were there not several "grooming gangs" that were active in Britain recently and the police were reluctant to investigate/prosecute them as it might appear racist?

Re: Inside the "3 billion people" national public data breach

#330

Earlier quoted context omitted.

You probably are posting this as a joke, but without a clear technical solution to this problem, flooding the industry with bullshit data seems like a great avenue.

that was the idea behind certain applications and add-ons that would browse around to popular websites and randomly click ads so that marketers couldn't tell your actual interests from fake ones. Unfortunately that strategy is deeply flawed and dangerous because nobody cares if the data they have on you is accurate or not. They still can, and still will, use it against you at every opportunity. Every scrap of data th…

Isn't something like regulation with strong data protection laws a bit late at this point? It seems fair to say that most people alive are already scooped up in 1 large data breach or another.

And that data has been made public likely in some form, and is probably replicated to dark corners of the planet.

Don't get me wrong, regulation on these industries seems like a no-brainer, but it seems unlikely to remediate the damage already done.

Post reply on HN