Live data from Hacker News

Inside the "3 billion people" national public data breach

troyhunt.com

361–370 of 472 posts

Re: Inside the "3 billion people" national public data breach

#361
post #69

Earlier quoted context omitted.

> Someone created a magnet link yesterday Are you against simply sharing the infohash here? I'd like to download the leak to see what information it has on myself and my family, but I don't really relish the idea of signing up for a breachforums account and sifting though its posts if I can avoid it.

Here is a strongly encrypted base64 version to keep hackers out: bWFnbmV0Oj94dD11cm46YnRpaDozY2FhNzFmM2VjOGNiY2NjNmZjYTRmZWI3MTg1ZGEyYmFiMTQ5YmE3JmRuPU5QRCZ0cj11ZHA6Ly90cmFja2VyLm9wZW5iaXR0b3JyZW50LmNvbTo4MCZ0cj11ZHA6Ly90cmFja2VyLm9wZW50cmFja3Iub3JnOjEzMzcvYW5ub3VuY2U= Allegedly, the password (also base64 encrypted) is: aHR0cHM6Ly91c2RvZC5pby8=

I get it now, but I have so much imposter syndrome that I wasn't sure if this was ACTUALLY something I needed to figure out -__-

Re: Inside the "3 billion people" national public data breach

#362

Can't the SSA just issue 330 million new social security numbers, and tell people to be more careful with them from this point forward?

The SSA has shown absolutely no urgency on this issue. Their existing policy is that having your SSN compromised is not enough to issue a new number. You have to actually be a victim of a financial or identity crime that abused your SSN for them to consider a new number. In reality what they should be doing is giving everyone accounts that can generate tokens for use with each transaction, to maintain a trail of wher…

They can't issue new numbers in bulk without revamping the system because they'd run out. The urgent fix wouldn't work.

If the system needs to be revamped, then step one should be pressure/force so that companies stop treating the numbers as secret. And if we do that we don't need new numbers anymore.

Re: Inside the "3 billion people" national public data breach

#363
post #69

Earlier quoted context omitted.

> Someone created a magnet link yesterday Are you against simply sharing the infohash here? I'd like to download the leak to see what information it has on myself and my family, but I don't really relish the idea of signing up for a breachforums account and sifting though its posts if I can avoid it.

Here is a strongly encrypted base64 version to keep hackers out: bWFnbmV0Oj94dD11cm46YnRpaDozY2FhNzFmM2VjOGNiY2NjNmZjYTRmZWI3MTg1ZGEyYmFiMTQ5YmE3JmRuPU5QRCZ0cj11ZHA6Ly90cmFja2VyLm9wZW5iaXR0b3JyZW50LmNvbTo4MCZ0cj11ZHA6Ly90cmFja2VyLm9wZW50cmFja3Iub3JnOjEzMzcvYW5ub3VuY2U= Allegedly, the password (also base64 encrypted) is: aHR0cHM6Ly91c2RvZC5pby8=

I dug into this a little and one of the files is 164GB. How do you even work with these files? That is, how would I search for my SSN on my windows box?

Re: Inside the "3 billion people" national public data breach

#364
I was wondering why Google suddenly turned on "prompt authentication" on zero-security feature accounts yesterday. Now I "must" have a phone nearby to use Gmail... Tap to authenticate every time you want to look at ... ad spam.

With this, Ticketmaster, and the CDK Global car theft, is there anybody on Earth who doesn't need data protection? Poor people in Somalia need data breach notices. People who are not even on the WWW need data breach notices...

Re: Inside the "3 billion people" national public data breach

#365

It's worth remembering that the main reason this kind of data breach is a real problem is mostly due to the incompetence of the IRS. For any serious financial organization, knowing a person's SSN, name, address, etc doesn't allow you to access or withdraw that person's finances. But the stupidity of the IRS means that people are easily targeted by false tax return attacks. File a fake tax return for someone, using th…

This comment is shockingly misguided.

The IRS doesn't have the authority to mandate the creation of a secure national ID system and enforce it's use by the financial system. Only congress has the ability to really do that. The IRS collects revenue.

Even if it did have that authority, it doesn't have the budget to accomplish that goal.

Re: Inside the "3 billion people" national public data breach

#366

Earlier quoted context omitted.

The reason the Shaggy defense doesn't work is the default assumption of the courts is that you're a deadbeat trying to game the system. This assumption comes about because in the majority of cases it is the truth. The system would be a lot nicer if there weren't people trying to scam it every hour of every day of the week.

Doesn't that violate innocent until proven guilty?

Welcome to the legal system in the real world. Pro tip: for the best outcomes for you be sure to be rich before engaging.

Re: Inside the "3 billion people" national public data breach

#367
post #338
post #253

Earlier quoted context omitted.

Only in the US. In the EU and other jurisdictions is does have protection [1]. [1] https://en.wikipedia.org/wiki/Copyright_law_of_the_European_...

So I could copyright my SSN in the EU and sue Equifax et al.?

Not on an individual basis. If you collected a large number of them and someone copied them from you, then you could have a database right claim, which is sort of similar to copyright, but much less powerful. https://en.wikipedia.org/wiki/Database_right

Re: Inside the "3 billion people" national public data breach

#368
post #365

It's worth remembering that the main reason this kind of data breach is a real problem is mostly due to the incompetence of the IRS. For any serious financial organization, knowing a person's SSN, name, address, etc doesn't allow you to access or withdraw that person's finances. But the stupidity of the IRS means that people are easily targeted by false tax return attacks. File a fake tax return for someone, using th…

This comment is shockingly misguided. The IRS doesn't have the authority to mandate the creation of a secure national ID system and enforce it's use by the financial system. Only congress has the ability to really do that. The IRS collects revenue. Even if it did have that authority, it doesn't have the budget to accomplish that goal.

isn't it funny how no government service is ever at fault, it's always just a problem of funding? The IRS is good, just under funded. Public schools are good, just under funded. The NHS is good, just under funded. The roads are good, just under funded

except then funding is raised, and it's still a problem of funding. and inevitably, it's the evil side of the government (you know the one) that is to blame, even if there is no money to spend.

how does a public service determine when they have enough funding?

Re: Inside the "3 billion people" national public data breach

#369

Earlier quoted context omitted.

Here is a strongly encrypted base64 version to keep hackers out: bWFnbmV0Oj94dD11cm46YnRpaDozY2FhNzFmM2VjOGNiY2NjNmZjYTRmZWI3MTg1ZGEyYmFiMTQ5YmE3JmRuPU5QRCZ0cj11ZHA6Ly90cmFja2VyLm9wZW5iaXR0b3JyZW50LmNvbTo4MCZ0cj11ZHA6Ly90cmFja2VyLm9wZW50cmFja3Iub3JnOjEzMzcvYW5ub3VuY2U= Allegedly, the password (also base64 encrypted) is: aHR0cHM6Ly91c2RvZC5pby8=

I dug into this a little and one of the files is 164GB. How do you even work with these files? That is, how would I search for my SSN on my windows box?

That's not even that big? `cat big_file | grep -v my_term` would go line-by-line and show any lines matching your query. If you're doing a lot of queries, you'd probably want to index it, so you throw it into a sqlite database with the usual SQL utils.

Edit: I missed you said Windows. Probably Powershell have similar utilities, so you can do `ReadFileLineByLine \r \d big_file | ReturnHitBySearchTerm \v \t \s my_term` or something similar.

Re: Inside the "3 billion people" national public data breach

#370
post #322

Earlier quoted context omitted.

Now everyone just needs to send their email addresses to HIBP, i.e., email HIBP, so he can connect these identities with IP addresses and working email accounts. For peoples' protection of course. After everyone "has been pwned" then there is no need for HIBP. The answer is always "yes". Yet I am certain sites like "HIBP" will never go away. Something about email marketing. Some HN commenter(s) will inevitably try to…

There is trust involved here. And people trust Troy Hunt. And of course you can download SHA ranges and do lookup offline: https://www.troyhunt.com/ive-just-launched-pwned-passwords-v... He even previously encouraged to download via torrent, but now it seems there is a custom tool to download that data.

The offline lookup is just for passwords (the pwned passwords service) and is used to prevent people from using known breached passwords.

There is no offline availability for the Have I Been Pwned data on which emails were present in which breaches. Access to thus data is rate limited and paid API keys are needed for bulk access.

Post reply on HN