Live data from Hacker News

Inside the "3 billion people" national public data breach

troyhunt.com

401–410 of 472 posts

Re: Inside the "3 billion people" national public data breach

#401

Earlier quoted context omitted.

That doesn't make it any less racist! But please give some more details on that. The only case I've heard about was a single attacker who was incorrectly called an immigrant.

To bring up more things in the broader context, were there not several "grooming gangs" that were active in Britain recently and the police were reluctant to investigate/prosecute them as it might appear racist?

Police were reluctant to investigate celebrity grooming gangs, Rolf Harris, Jimmy Saville, Gary Glitter, Huw Edwards, Russell Brand, etc.

Police were reluctant to investigate political grooming gangs, those in the House of Lords, nobility, etc.

Police were reluctant to investigate religuous grooming gangs, Christian Brothers ets.

I can't see how immigrant pedos are infinity worse rather than just more of the same.

The reluctance to investigate seems to be the issue, now it's compounded by scapegoating.

Re: Inside the "3 billion people" national public data breach

#402
post #382

Earlier quoted context omitted.

I still don't get why people are calling these "religious fears". The parable from the book is because the problem is very old, but the problem is exactly the same as it ever was: If a central authority gives everyone a serial number then it will be used to track them by powerful institutions, which is a tool of oppression. This is the massive mistake we made with social security numbers, and their inherent insecurit…

> I still don't get why people are calling these "religious fears That’s what the people making those claims are talking about. If you haven’t talked with paranoid religious extremists before, it’s eye-opening: they are literally saying that a mandatory government ID will serve the beast mentioned in Revelations. That’s not the only concern or group raising it by any means but I mentioned it because governments have…

> It’s only a tool of oppression if you have a government prone to abuse and without constraints.

Untrue for three reasons.

One, it's a spectrum, and where you are can change. While the current US government is pretty bad, they're not rounding up citizens based on their race and throwing them into internment camps right now. But they have in the past, so let's not leave them anything that helps them if they decide to Be Evil again eh?

Two, there are different governments. Suppose the federal government is bad but not heinously bad and the Colorado government is pretty good but the Mississippi government is corrupt and racist and oppressive. Create the system federally and you're handing it to Mississippi officials to abuse, whereas they couldn't create their own because free travel between the states is constitutionally protected.

Three, it's not just governments. Create something like this and corporations will use it. Then all you need is for the government to fail to stop them, which is the status quo.

> In 2024, however, all not having one means is that they use software to link them – the context for this story is the huge industry doing that for all kinds of data, and they don’t mind having to link a couple of different identifiers.

The single identifier is what enables them to be linked -- it's why the surveillance apparatus keeps pushing it on us. Without it you have to speculate and will commonly get it wrong. If someone is signed into Google and then signs into their bank, does that mean they're the same person, or just two people who use the same computer?

If you pull an old PC off a skid destined for the recycler and use it exclusively for buying things on Amazon (which inherently has your shipping address), and use a different machine for social media which you never use for Amazon, a single identifier would still force you to associate the two no matter what measures you use to separate them.

It is important to preserve the ability to keep them separate.

Also notice the form of your argument: Things are currently bad so it's fine to make them worse in a way that's sticky and hard to undo. Maybe instead we should make things better?

Re: Inside the "3 billion people" national public data breach

#403

Earlier quoted context omitted.

> Even something as simple as SSN + DOB runs into loads of potential formatting and data entry issues you'll have to perfectly solve You don’t have to solve it perfectly to be an improvement. Also this is BS. Not every bit of data is perfectly formatted and structured but both of your examples are structured data. You can 100% reliably and deterministically hash this data. There’s so much in your argument that can be…

People switch digits in their SSN.

Then it’s different… Better vs perfect.

If you can’t get your SSN right, you can’t expect a company to delete it.

Re: Inside the "3 billion people" national public data breach

#404
post #69

Earlier quoted context omitted.

> Someone created a magnet link yesterday Are you against simply sharing the infohash here? I'd like to download the leak to see what information it has on myself and my family, but I don't really relish the idea of signing up for a breachforums account and sifting though its posts if I can avoid it.

fyi that is likely to be a crime, at the very least has been cases of websites being punished for linking to illegally distributed IP (even if not hosting it).

Where's the IP?

It's like phone books--a collection of data, no creative content.

Re: Inside the "3 billion people" national public data breach

#405

"there were no email addresses in the social security number files. If you find yourself in this data breach via HIBP, there's no evidence your SSN was leaked, and if you're in the same boat as me, the data next to your record may not even be correct. " Seems like Troy is skeptical about this being a real full breach?

A lot of these data brokers hold wildly inaccurate information.

Yes, but they can also be pretty accurate.

While I have never dealt with one of the paid services someone ran one on me as an example of what is out there (nothing malicious about it) and just about everything on it was accurate or close to it. Only one thing on it wasn't at least pretty close to the truth--it had me living in a state I've never set foot in. And quite a few other people seemed to have the same address at one point or another.

Re: Inside the "3 billion people" national public data breach

#406
post #388

Earlier quoted context omitted.

I'm not trying to be combative, but this sentiment just doesn't pass the smell test to me. Yes, I agree that there is a cultural undercurrent of fear around a national ID system, and I also agree that politicians are likely to game their political capital for the greatest return in their career. What I do NOT believe is that the Social Security number just sort of came about and started being used by government servi…

>What I do NOT believe is that the Social Security number just sort of came about and started being used by government services such as the IRS without anyone being responsible for that huge organizational decision or the initial (current?) lack of security controls around its implementation. They didn’t “just sort of come about”, they were created for this exact purpose of tracking government services. Over the year…

> They were created as usernames, but people treated them as passwords.

Fully agree, but I don't see how this refutes what I and the root-level comment (anti-IRS sentiment aside) are saying.

> the lack of security around SSNs is because they weren't intended to be secret.

The lack of security is not BECAUSE they weren't intended to be secret. The lack of security is because numerous organizations (including the IRS, until their introduction of an IP PIN) treated these "usernames" as though they were passwords.

It's not a design problem with original intent of SSNs, it's an implementation problem with any organization using them improperly. Gov't services are just as responsible as banks and credit agencies when they misuse them.

Re: Inside the "3 billion people" national public data breach

#407
post #399
post #75

Earlier quoted context omitted.

There has never been a US president that had anything close to ethical behaviour (to wit: the ones that existed after drone strikes became a thing all signed off on drone strikes. Those hit a lot of innocent people. The US has never stopped having slavery. I could go on). It is really the height of fanciful thinking to believe that the flavour of the month US leader will be any different.

That’s absurdly naive – it’s like saying every picture is the same because they aren’t entirely (255, 255, 255) pixels. If your goal is to do anything other than feel smug, consider the impact such non-serious positions have on how other people will perceive anything more serious you say.

Respectfully, you are wrong. Nothing I've said is untrue.

I gave you examples, where you reciprocated with a personal attack. This is one of the ways in which US internal politics has become infantile and tedious. I would appreciate it if you left it there.

Re: Inside the "3 billion people" national public data breach

#408

It's worth remembering that the main reason this kind of data breach is a real problem is mostly due to the incompetence of the IRS. For any serious financial organization, knowing a person's SSN, name, address, etc doesn't allow you to access or withdraw that person's finances. But the stupidity of the IRS means that people are easily targeted by false tax return attacks. File a fake tax return for someone, using th…

I agree. The IRS should be better funded so they can afford to update their systems and hire more tech experts.

I hope this is meant to be satirical. The IRS has a massive budget. Maybe just reallocate their current funds instead of giving them more is a better idea.

Re: Inside the "3 billion people" national public data breach

#409
post #382

Earlier quoted context omitted.

> I still don't get why people are calling these "religious fears That’s what the people making those claims are talking about. If you haven’t talked with paranoid religious extremists before, it’s eye-opening: they are literally saying that a mandatory government ID will serve the beast mentioned in Revelations. That’s not the only concern or group raising it by any means but I mentioned it because governments have…

> It’s only a tool of oppression if you have a government prone to abuse and without constraints. Untrue for three reasons. One, it's a spectrum, and where you are can change. While the current US government is pretty bad, they're not rounding up citizens based on their race and throwing them into internment camps right now. But they have in the past, so let's not leave them anything that helps them if they decide to…

> The single identifier is what enables them to be linked

> If someone is signed into Google and then signs into their bank, does that mean they're the same person, or just two people who use the same computer?

You misunderstood my argument as “it’s okay to make things worse” rather than “spend your time on things which can matter”. You’re grossly overstating the importance of the unique identifier in era where databases are widespread. In your examples, you’re characterizing as hypothetical risks things which are routinely done by private companies right now. The modern Stasi wouldn’t need to an army of clerks to link government IDs, they’d pay Google or some other ad tech companies who’ve already linked your online activities (how many people even know if their bank uses Google Analytics?) and your email addresses and your phone numbers and your credit card transactions and the location data which the phone companies and mobile app analytics firms have already collected, etc. As a government agency, they’d even get stuff like the precise locations your phone is at. Even if you had your Amazon burner on a separate network, used a different email address with a different provider than you do for everything else, perfectly adhere to not using it for social media, etc. all you have to do is forget to turn off your phone once to link them, especially if you don’t live in a very crowded environment with many new people coming and going at unpredictable intervals.

Yes, having one identifier would make it easier but they’re already doing a good enough job that anyone who cares about it should be thinking about the safeguards which prevent abuse rather than pretending that there’s one weird trick to stop it. If we were in a scenario where any of the feared outcomes of a government are imminent, the range of bad outcomes either way overlap too much for the difference to matter.

The key thing to understand is that they don’t need it to be perfect: authoritarian governments don’t need to jail everyone who disagrees as long as they keep those people from organizing an effective opposition. If you’re opposed to them but keeping quiet and not doing much, they win. If you pull off perfect opsec and stay undetected, but they catch you because someone you know made a mistake, they win.

Worse, in the absence of effective accountability, minor mistakes only help build the fear of doing anything dodgy or subversive – if news gets out that someone went to a protest and the cops busted their roommate after linking the wrong phone, it _might_ help that one person be released but it will definitely ensure that a hundred other people get kicked out or turned in by roommates who don’t want to have the same thing happen to them (read accounts from East Germany, Russia, China, Mexico in the 70s, etc. for a reminder of how toxic the effects on social networks are), and a thousand people will stay quiet and avoid the next protest.

Re: Inside the "3 billion people" national public data breach

#410

Earlier quoted context omitted.

I have been using a different site@mydomain email address for every service I've used for the past 15 years. I can point to exactly which site breach furnished my email address to the aggregators.

Care to call out some bad actors so others know to avoid business with them? I recently started using unique emails for everything I sign up for. Thankfully I haven’t seen anything yet, but I have little hope it will stay that way.

Surprisingly, there aren't that many. When I started, I thought I would catch my email address being resold. The only reseller has been Democrat politicians or funding sites like Go Blue. The other one is Engagez, which is some kind of tech vendor expo I signed up for with some meetup event.

The most widely spread breached address is LinkedIn by a wide margin. Houzz is second. Zynga, Imgur are also in contention.

When I started getting porn spam from the Diver's Alert Network, I alerted them to a breach. They misunderstood and just told me how to change my password.

The most annoying thing is that I found my personal robert@ email address is HIBP under the evite breach. I so jealously guard my personal address. A well meaning friend invited me to something with evite. And that's all it took.

Post reply on HN