Live data from Hacker News

Inside the "3 billion people" national public data breach

troyhunt.com

411–420 of 472 posts

Re: Inside the "3 billion people" national public data breach

#411

Earlier quoted context omitted.

My friend is a thriller writer and is convinced he’s on some FBI list. He’s googling stuff such as “how to dissolve a body with quicklime” and all sorts of other fun stuff while researching for his books.

The quicklime method shouldn't be particularly fast, at least that's what my chemical intuition says (CaOH2 is barely soluble in water). What a bad name!

> What a bad name!

The quick doesn't mean "fast". It means "alive".

Re: Inside the "3 billion people" national public data breach

#412
post #69

Earlier quoted context omitted.

> Someone created a magnet link yesterday Are you against simply sharing the infohash here? I'd like to download the leak to see what information it has on myself and my family, but I don't really relish the idea of signing up for a breachforums account and sifting though its posts if I can avoid it.

Here is a strongly encrypted base64 version to keep hackers out: bWFnbmV0Oj94dD11cm46YnRpaDozY2FhNzFmM2VjOGNiY2NjNmZjYTRmZWI3MTg1ZGEyYmFiMTQ5YmE3JmRuPU5QRCZ0cj11ZHA6Ly90cmFja2VyLm9wZW5iaXR0b3JyZW50LmNvbTo4MCZ0cj11ZHA6Ly90cmFja2VyLm9wZW50cmFja3Iub3JnOjEzMzcvYW5ub3VuY2U= Allegedly, the password (also base64 encrypted) is: aHR0cHM6Ly91c2RvZC5pby8=

I can't believe HN mods think it's ok to leave this comment up. I don't know of a way to report it myself unfortunately.

Re: Inside the "3 billion people" national public data breach

#413

Earlier quoted context omitted.

The quicklime method shouldn't be particularly fast, at least that's what my chemical intuition says (CaOH2 is barely soluble in water). What a bad name!

> What a bad name! The quick doesn't mean "fast". It means "alive".

In the most general context it means "with the characteristics of the living" (as seen through a middle ages lens).

In the context of "quicklime" the quick refers to the heat of the reaction when making lime for slaking on walls, etc.

"Quick" historicaly has been applied to plants and animals (alive), rivers and streams (moving), coals, fires, quicklime (burning, heat producing, glowing), to speeches and pamphlets (Lively, full of vigour or sharp argument), to tastes, to smells, and more.

The full blown Oxford English Dictionary entry for quick is a lengthy one, multiple cases and variations over a page and more.

Re: Inside the "3 billion people" national public data breach

#414
post #300
post #42

Earlier quoted context omitted.

I knew someone falsely declared dead (probably a paperwork mixed up around pensions when his ex-spouse died). Without warning, he lost all of his pensions, social security, medicare, etc, along with most financial institutions freezing accounts and canceling credit cards. Many long phone calls, letters, and lawyers eventually resolve most, but that never fully purged the public and private death records so there woul…

You'd think something like that would require a death certificate to actually happen

There _was_ a death certificate, just not his

>probably a paperwork mixed up around pensions when his ex-spouse died

Re: Inside the "3 billion people" national public data breach

#415
post #409

Earlier quoted context omitted.

> It’s only a tool of oppression if you have a government prone to abuse and without constraints. Untrue for three reasons. One, it's a spectrum, and where you are can change. While the current US government is pretty bad, they're not rounding up citizens based on their race and throwing them into internment camps right now. But they have in the past, so let's not leave them anything that helps them if they decide to…

> The single identifier is what enables them to be linked > If someone is signed into Google and then signs into their bank, does that mean they're the same person, or just two people who use the same computer? You misunderstood my argument as “it’s okay to make things worse” rather than “spend your time on things which can matter”. You’re grossly overstating the importance of the unique identifier in era where datab…

> The modern Stasi wouldn’t need to an army of clerks to link government IDs, they’d pay Google or some other ad tech companies who’ve already linked your online activities (how many people even know if their bank uses Google Analytics?) and your email addresses and your phone numbers and your credit card transactions and the location data which the phone companies and mobile app analytics firms have already collected, etc.

But it's not about clerks.

You go to your bank and sign in. If the bank is using Google Analytics then Google knows you've signed into your bank. But they don't know that this is the same "you" that signs into YouTube under a different account on a different machine.

If you make a government ID which is trivial to check over the internet then everything would start checking it, and then Google would know that it's the same "you" because you'd have to present your ID in order to use YouTube and it's the same ID you have to present to the bank.

> Even if you had your Amazon burner on a separate network, used a different email address with a different provider than you do for everything else, perfectly adhere to not using it for social media, etc. all you have to do is forget to turn off your phone once to link them, especially if you don’t live in a very crowded environment with many new people coming and going at unpredictable intervals.

This is the spy scenario where they magically associate the phone with you based on a single ambiguous data point. It doesn't work like that because if it did you could do it on purpose to link your identity with someone else. It also assumes that the other problems can't be improved. Suppose we stop forcing people to disclose a single identifier and we get phones that don't forcibly report our locations to large institutions. Then you have defense in depth and can make a single mistake without being automatically screwed.

> Yes, having one identifier would make it easier but they’re already doing a good enough job that anyone who cares about it should be thinking about the safeguards which prevent abuse rather than pretending that there’s one weird trick to stop it.

It's not that there's one trick to stop it, it's that forcing a single identity to be disclosed in order to do anything would defeat all other privacy measures. There is no point in preventing browser fingerprinting or using a VPN with a shared IP address or posting under a pseudonym if everything you do is still tied to your centralized ID number which in turn is tied to your face and home address and full transaction history with every extant bureaucracy.

> If we were in a scenario where any of the feared outcomes of a government are imminent, the range of bad outcomes either way overlap too much for the difference to matter.

Those are just the worst-case scenarios. If you get Nazis, they're going to push this on everyone anyway as soon as they can. It's better to slow them down as much as possible than leave everything already implemented and all they have to do is turn key, but that's hardly the only bad thing that can happen.

If corporations know everything about you, they can use machine learning to do price discrimination. They can predict when is the best time to present you with an agreement that has you sign your rights away for a song. They can influence public opinion to control election outcomes. Censor whistleblowers who are now incapable of publishing anything under a pseudonym. Blackmail anyone because no one has any secrets from them.

The longer it's possible for people to do these things, the more likely that they happen, and the more often. So it needs to be made not just illegal but technologically unavailable. That way it's harder to happen because they have to do two things and not just one.

Especially because many of these things are not necessarily things done by people who are already in power, they're things done by people who have the surveillance data and use it to seize power. "Accountability" doesn't work if the technology can be used to seize control of the government before the government can enforce a prohibition on that use of the technology.

Re: Inside the "3 billion people" national public data breach

#416

Earlier quoted context omitted.

Sorry, I value my legal rights over the viability of the data broker industry. If they can’t figure out a way for lawfully not collecting my data, they should not collect data period.

I mean, if we’re not allowed to know that we’re not allowed to surveil the shit out of you, it seems like something we can’t worry about

Not really my problem, I’ll sue you when you get breached.

Re: Inside the "3 billion people" national public data breach

#417

Earlier quoted context omitted.

I agree. The IRS should be better funded so they can afford to update their systems and hire more tech experts.

I hope this is meant to be satirical. The IRS has a massive budget. Maybe just reallocate their current funds instead of giving them more is a better idea.

I don’t think the parent is satirical at all; as an enumerated power, the IRS needs modernization and better funding.

Recent hiring expansions have increased audits for high earners and generated additional revenue. Turbotax’s lobbyists are losing influence and we’re enjoying free filing options for individuals in some states. It’s also reasonable to say that a revenue service is not responsible for defining authentication security standards.

Why do you think reallocating funds is worth it as a response to this issue? Where would those funds go?

Re: Inside the "3 billion people" national public data breach

#418
post #322

Earlier quoted context omitted.

There is trust involved here. And people trust Troy Hunt. And of course you can download SHA ranges and do lookup offline: https://www.troyhunt.com/ive-just-launched-pwned-passwords-v... He even previously encouraged to download via torrent, but now it seems there is a custom tool to download that data.

The downloads are the way to go IMHO. But this is coming a little too late. "HIBP" is already making money from "paid API" and other commercial nonsense. Profiting from data breaches. While posing as a hero, catering to a dedicated following. This is, IMHO, everything that is wrong with the web. The issue I am raising is not whether a particular website operator claiming to be in posession of data breach dumps, that…

He actually tried to sell the company at one point in time. He got a stressfull time, approaching burn out. Around 2019 he tried to sell HIBP: https://www.troyhunt.com/project-svalbard-the-future-of-have...

> ... but it was the first time since the overhead of managing the service had gone off the charts.

Around 2020 he decided not to: https://www.troyhunt.com/project-svalbard-have-i-been-pwned-...

He then reveals source of stress and the way it impacted HIBP: https://www.troyhunt.com/sustaining-performance-under-extrem...

Just think about it: HIBP hinges on a person doing his stuff, putting in his time and finances. That affects personal life. However that is a very valuable utility that guy is doing. Good that CF donates cache and help is here and there... but do you think you would have managed that service better?

Would it have been better if HIBP was sold and managed by a real company? Who knows. But long term it is of course healthier if HIBP isn't affected by a single person personal life situations.

Re: Inside the "3 billion people" national public data breach

#419

Earlier quoted context omitted.

It adds context which people who manipulate the overtone window for political games and name calling like to exclude. The person was a immigrants child. Considering there obvious (violent) refusal to integrate they are too an immigrant.

It's completely bonkers to have retaliation like that against a single attack that isn't part of a pattern. Like, that context arguably makes it worse than if there was no inciting incident, because it's so blatantly blaming a huge group for one person .

its not a single attack but not like the news you listen to would report that.

it is a pattern.

Re: Inside the "3 billion people" national public data breach

#420

Earlier quoted context omitted.

To bring up more things in the broader context, were there not several "grooming gangs" that were active in Britain recently and the police were reluctant to investigate/prosecute them as it might appear racist?

Police were reluctant to investigate celebrity grooming gangs, Rolf Harris, Jimmy Saville, Gary Glitter, Huw Edwards, Russell Brand, etc. Police were reluctant to investigate political grooming gangs, those in the House of Lords, nobility, etc. Police were reluctant to investigate religuous grooming gangs, Christian Brothers ets. I can't see how immigrant pedos are infinity worse rather than just more of the same. Th…

there are literal no go zones the police will not touch out of fear. If you can't figure out how law less zones and being socially untouchable could make doing crimes easier and harder to prevent, then there is nothing that could convince you.
Post reply on HN