Live data from Hacker News

Inside the "3 billion people" national public data breach

troyhunt.com

391–400 of 472 posts

Re: Inside the "3 billion people" national public data breach

#391
post #322

Earlier quoted context omitted.

Now everyone just needs to send their email addresses to HIBP, i.e., email HIBP, so he can connect these identities with IP addresses and working email accounts. For peoples' protection of course. After everyone "has been pwned" then there is no need for HIBP. The answer is always "yes". Yet I am certain sites like "HIBP" will never go away. Something about email marketing. Some HN commenter(s) will inevitably try to…

There is trust involved here. And people trust Troy Hunt. And of course you can download SHA ranges and do lookup offline: https://www.troyhunt.com/ive-just-launched-pwned-passwords-v... He even previously encouraged to download via torrent, but now it seems there is a custom tool to download that data.

The downloads are the way to go IMHO. But this is coming a little too late. "HIBP" is already making money from "paid API" and other commercial nonsense. Profiting from data breaches. While posing as a hero, catering to a dedicated following. This is, IMHO, everything that is wrong with the web.

The issue I am raising is not whether a particular website operator claiming to be in posession of data breach dumps, that any web user can download themselves, is "trustworthy" or not. The point I am raising is the unnecessary data collection. If these downloads were available from the website from day one, then there would be no "paid API" nor partnerships with so-called "tech" companies or HN HIBP following. There would not be "HIBP" proponents trying to suppress any criticism of it, defending its every move despite its past mistakes. Most importantly, there would less/no need for "trust".

HIBP is a particularly ugly symbol of the problem of web intermediaries/middlemen and everything/anything "as a service". As expected, HN commenters will not like this viewpoint as they may themselves be trying to profit from such intermediation and the data collection it enables. They may have even convinced themselves they are doing good.

Re: Inside the "3 billion people" national public data breach

#392
post #365

Earlier quoted context omitted.

This comment is shockingly misguided. The IRS doesn't have the authority to mandate the creation of a secure national ID system and enforce it's use by the financial system. Only congress has the ability to really do that. The IRS collects revenue. Even if it did have that authority, it doesn't have the budget to accomplish that goal.

isn't it funny how no government service is ever at fault, it's always just a problem of funding? The IRS is good, just under funded. Public schools are good, just under funded. The NHS is good, just under funded. The roads are good, just under funded except then funding is raised, and it's still a problem of funding. and inevitably, it's the evil side of the government (you know the one) that is to blame, even if th…

When exactly has funding EVER been raised for any of those things??

That's one of the biggest political fights in the past century: austerity, cutting public spending, and means-testing the fuck out of every social program the government even still offers. This has been the case since the 80s reagan-thatcher year. You can literally look at the budgets of major cities and easily see where the majority of spending goes. Hint: it ain't public schools. Were you not paying attention when people were talking about how much police departments get paid out of the budgets of their cities a couple years back? Have you EVER thought to actually substantiate your beliefs by actually looking up the policies that effect public spending and government budgets?

Is the answer "no"?

And it isn't just a problem with funding, it's a legislative and cultural problem too. But in the short term, without drafting up new laws or changing the culture of society, the best we can do to fix these issues is provide more funding.

Re: Inside the "3 billion people" national public data breach

#393

Earlier quoted context omitted.

Which would never work because real life data is messy so the hashes would not match. Even something as simple as SSN + DOB runs into loads of potential formatting and data entry issues you'll have to perfectly solve before such a system could work, and even that makes assumptions as to what data will be available from each dataset. Some may be only name and address. Some may include DoB, but the person might have li…

> Even something as simple as SSN + DOB runs into loads of potential formatting and data entry issues you'll have to perfectly solve You don’t have to solve it perfectly to be an improvement. Also this is BS. Not every bit of data is perfectly formatted and structured but both of your examples are structured data. You can 100% reliably and deterministically hash this data. There’s so much in your argument that can be…

People switch digits in their SSN.

Re: Inside the "3 billion people" national public data breach

#394

Earlier quoted context omitted.

> Every scrap of data they have, accurate or not, can be used to hurt you. What are some examples of inaccurate data, as in completely false data, being able to hurt me?

You can never know what might prejudice someone else against you. Maybe you get flagged as being gay when you aren't, or as holding certain religious or political views that you don't. Extremists, activists, and protestors can go to a data broker and buy up lists of people to harass or attack. Data brokers have already been caught collecting data on people who visited Planned Parenthood locations and selling that dat…

> Maybe you get flagged as being gay when you aren't, or as holding certain religious or political views that you don't.

Very true! Great examples and reply, thank you!

Re: Inside the "3 billion people" national public data breach

#395

Earlier quoted context omitted.

There were just a series of mass race riots by right-wingers across the UK, in which they went around smashing up shops owned by immigrants and beating up people who don't look white. This isn't about illegal immigration. It's about racism.

conveniently emitting the fact that this is a reaction to immigrants going around randomly attacking birtish people. If you aren't already consider workong for MSM.

No, it's not based on that.

It was based on a false rumor that spread on social media that the perpetrator of a recent triple murder was a Muslim asylum seeker. It turns out that the perpetrator is a British citizen who was born in Britain and is Christian.

What this reminds me of are pogroms in Eastern Europe, which were often sparked by false rumors about Jews.

Re: Inside the "3 billion people" national public data breach

#396
post #273

Earlier quoted context omitted.

This is a solved problem. If the ID is on your phone, you can make it so that the transaction details have to be digitally signed by the person authorizing them in order to be valid. Then, if 3€ shows up on your phone, that's what you're authorizing, not 300€.

Sure, given an advanced enough device anything is possible. But I think here we are still discussing a "card" form factor for ID? (Being an "unperson" simply because you don't have a smartphone or have a rooted one would be "interesting").

You wouldn't be an "unperson" without a smartphone, but your financial transactions might not be as secure.

Re: Inside the "3 billion people" national public data breach

#397

Earlier quoted context omitted.

It adds context which people who manipulate the overtone window for political games and name calling like to exclude. The person was a immigrants child. Considering there obvious (violent) refusal to integrate they are too an immigrant.

It's completely bonkers to have retaliation like that against a single attack that isn't part of a pattern. Like, that context arguably makes it worse than if there was no inciting incident, because it's so blatantly blaming a huge group for one person .

It's like justifying pogroms against Jews because one Jewish person committed a crime. It's racist and utterly disgusting.

Re: Inside the "3 billion people" national public data breach

#398
post #191

Earlier quoted context omitted.

That seems entirely like an implementation detail that doesn't have anything to do with the smart card interface itself. It's not like it's rocket science to have the reader application detail what the request is used for, and encoding it in the request/response, verified when used, so that it can't be used for anything but the approved purpose.

> It's not like it's rocket science to have the reader application detail what the request is used for, and encoding it in the request/response The reader application can, sure, but what ensures that that "reader application" is genuine and can't be subverted? The card's own processor is supposedly tamperproof, but all the display etc. is in the reader which is probably owned and controlled by whatever third-party yo…

This is already a more restricted type of attack than the common identify theft that's rampant right now in the US.

What you're describing requires the actual terminal you're interacting with to be malicious, and it can only be used to authorize individual transactions.

As things stand in the US, a much broader class of attacks are not only possible but common, in which the attacker takes over the identify of the victim and can authorize any number of transactions in their name.

Re: Inside the "3 billion people" national public data breach

#399
post #75
post #37

Earlier quoted context omitted.

I’m optimistic for Harris, not just because she’s so much younger and less beholden to industry, but because she created an entire unit for privacy protection when she was the California AG: https://oag.ca.gov/news/press-releases/attorney-general-kama...

There has never been a US president that had anything close to ethical behaviour (to wit: the ones that existed after drone strikes became a thing all signed off on drone strikes. Those hit a lot of innocent people. The US has never stopped having slavery. I could go on). It is really the height of fanciful thinking to believe that the flavour of the month US leader will be any different.

That’s absurdly naive – it’s like saying every picture is the same because they aren’t entirely (255, 255, 255) pixels. If your goal is to do anything other than feel smug, consider the impact such non-serious positions have on how other people will perceive anything more serious you say.

Re: Inside the "3 billion people" national public data breach

#400
post #110
post #34

Earlier quoted context omitted.

Yes. 99% of the time “identity theft” means a huge company cut corners on their security policies and wants us to subsidize their negligence. Every so often there are cases like that guy who pretended to be his former coworker for decades but they’re rare enough that they make the news internationally. Most of the time it used to be things like instant credit applications where they didn’t “slow” purchases with ID ch…

Not good news. Doesn't matter if the business is presumed competent. What matters is that the business can steal your assets to pay for their losses.

So … actually good news? It most definitely does matter that businesses are now expected to prove the case more reliably than they used to.
Post reply on HN