Live data from Hacker News

Inside the "3 billion people" national public data breach

troyhunt.com

421–430 of 472 posts

Re: Inside the "3 billion people" national public data breach

#421

Earlier quoted context omitted.

It's completely bonkers to have retaliation like that against a single attack that isn't part of a pattern. Like, that context arguably makes it worse than if there was no inciting incident, because it's so blatantly blaming a huge group for one person .

It's like justifying pogroms against Jews because one Jewish person committed a crime. It's racist and utterly disgusting.

are you implying that there are jewish grooming gangs that operate above the law?

Re: Inside the "3 billion people" national public data breach

#422
post #192

Earlier quoted context omitted.

Except it's being implemented by the people who brought you robodebt. So i imagine the "Number of people driven to suicide" KPI is going to be pretty high. They're not going to want to ship something that performs worse.

Yes. There is that. But it's only true to the extent all government things are brought to you by the government. If the underlying IMS system used for datamatching by ATO and Centerlink is the product of the same s/w development group I'd be a bit surprised. It's different code. But I am by tendency an optimist, and the open-source part (if they do that) means we can have eyes on their crypto assumptions behind the p…

I mean it's literally being built by services australia with all the baggage of that organisation.

The execs are mostly the same. the product contracts run by the same people and even the minister is now the same again. they have no interest in changing or correcting.

Re: Inside the "3 billion people" national public data breach

#423

Earlier quoted context omitted.

It's like justifying pogroms against Jews because one Jewish person committed a crime. It's racist and utterly disgusting.

are you implying that there are jewish grooming gangs that operate above the law?

Are you implying that small numbers of Muslim criminals justify mob violence against random Muslims on the street?

Re: Inside the "3 billion people" national public data breach

#424
Perhaps HN readers would appreciate a detailed account of what the NPD torrents contain.

The torrent deliver two files like so:

  NPD202401.7z  33,456,912,010 bytes (32GB)
  NPD202402.7z  20,548,499,322 bytes (20GB)
Uncompressing NPD202401.7z results in:

  ssn.txt 176,806,109,779 bytes (165GB)
  wc -l ssn.txt ==>> 1,698,302,005 lines
Uncompressing NPD202402.7z results in:

  ssn2.txt 120,722,361,611 bytes (113GB)
  wc -l ssn2.txt ==>> 997,379,508 lines
This is a total of 1698302005+997379508 = 2,695,681,513 lines.

Each line is a comma separated record with these fields:

ID,firstname,lastname,middlename,name_suff,dob,address,city,county_name,st,zip,phone1,aka1fullname,aka2fullname,aka3fullname,StartDat,alt1DOB,alt2DOB,alt3DOB,ssn

Generally records have ID, firstname, lastname, middlename, address, city, county_name, st, zip, and ssn. Most records do not have the fields for name_suff (name suffix), phone1, aka1fullname, aka2fullname, aka3fullname, StartDat, alt1DOB, alt2DOB, and alt3DOB.

There are no emails at all. There is no "@" in the files anywhere. Phone numbers are very rare.

I don't know what the ID number at the head of each line represents. I presume it is an internal index used by the organization that compiled the data. The SSN is at the end of each line.

The files have U.S. addresses only as far as I can tell. Nothing from Mexico, Canada, or other foreign countries.

Many of the lines (records) concern the same person at various addresses. Of 7 random people who I personally know that I checked on, all had entries. There were between 3 and 20 lines (records) for these 7 persons, averaging about 10. They usually differed only in the address field. Going by an estimate of 10 records per person, the 2.6 billion lines represents about 2695681513/10 = 269,568,151 distinct persons in the U.S.

The U.S. population is about 337M where 78% is over 18 years of age. In other words, 337000000*0.78 = 262,860,000 Americans are adults. This is pretty close to my estimate of 269,568,151 distinct individuals in the NPD data files.

Of the 7 persons I checked on, the names were spelled correctly, although the middle name was sometimes just an initial. I searched each person by multiple methods (address, last name, birth date) so I believe I would have detected names that were spelled slightly wrong.

The addresses appeared correct but there was no way to tell which was the current address and the order in which they lived at each address. There is a StartDat field but it was almost never filled in. The latest entry was not always the most current address. In a couple cases, the current address, where the person has been living for several years, was absent.

The birth dates were correct in a couple cases, were abbreviated in three cases (that is, instead of showing 19800704, meaning July 4 1980, it showed 19800700, meaning July 1980 without an exact day), and was wrong for one person by a wide margin.

All 7 persons I checked had SSN numbers. It was correct for 1 person but I don't know for the other 6. The SSN numbers were consistent for each of the 7 persons I checked on. By this I mean that a person did not have more than 1 SSN number, at least among the 7 persons I checked on.

Re: Inside the "3 billion people" national public data breach

#425
post #69

Earlier quoted context omitted.

> Someone created a magnet link yesterday Are you against simply sharing the infohash here? I'd like to download the leak to see what information it has on myself and my family, but I don't really relish the idea of signing up for a breachforums account and sifting though its posts if I can avoid it.

Here is a strongly encrypted base64 version to keep hackers out: bWFnbmV0Oj94dD11cm46YnRpaDozY2FhNzFmM2VjOGNiY2NjNmZjYTRmZWI3MTg1ZGEyYmFiMTQ5YmE3JmRuPU5QRCZ0cj11ZHA6Ly90cmFja2VyLm9wZW5iaXR0b3JyZW50LmNvbTo4MCZ0cj11ZHA6Ly90cmFja2VyLm9wZW50cmFja3Iub3JnOjEzMzcvYW5ub3VuY2U= Allegedly, the password (also base64 encrypted) is: aHR0cHM6Ly91c2RvZC5pby8=

Elsewhere in this thread I posted a detailed commentary on what the torrent contains.

Re: Inside the "3 billion people" national public data breach

#426

Earlier quoted context omitted.

Police were reluctant to investigate celebrity grooming gangs, Rolf Harris, Jimmy Saville, Gary Glitter, Huw Edwards, Russell Brand, etc. Police were reluctant to investigate political grooming gangs, those in the House of Lords, nobility, etc. Police were reluctant to investigate religuous grooming gangs, Christian Brothers ets. I can't see how immigrant pedos are infinity worse rather than just more of the same. Th…

there are literal no go zones the police will not touch out of fear. If you can't figure out how law less zones and being socially untouchable could make doing crimes easier and harder to prevent, then there is nothing that could convince you.

> there are literal no go zones the police will not touch out of fear.

GPS coords then? Street names?

Any chance of a decent curry?

Re: Inside the "3 billion people" national public data breach

#427

Earlier quoted context omitted.

Governments murdered hundreds of millions of their own people during the 20th century, and the 21st is shaping up to tell the 20th to hold its beer. Any proposal for modern ID needs to have Constitutional protections, checks, and balances or it will eventually devolve into a digital police state.

A lack of national ID cards would not have hindered the Nazis in carrying out mass murder one bit.

More apropros to the current situation, Henryk Jagoda and the bolsheviks killed/starved between 29 million to 113 million people, depending on estimates. They certainly ID's people, based on ethnicity, religion, political affiliation, and class status.

My point is to not make it easier for them.

Re: Inside the "3 billion people" national public data breach

#428

Earlier quoted context omitted.

Care to call out some bad actors so others know to avoid business with them? I recently started using unique emails for everything I sign up for. Thankfully I haven’t seen anything yet, but I have little hope it will stay that way.

Surprisingly, there aren't that many. When I started, I thought I would catch my email address being resold. The only reseller has been Democrat politicians or funding sites like Go Blue. The other one is Engagez, which is some kind of tech vendor expo I signed up for with some meetup event. The most widely spread breached address is LinkedIn by a wide margin. Houzz is second. Zynga, Imgur are also in contention. Whe…

>I so jealously guard my personal address. A well meaning friend invited me to something with evite. And that's all it took.

I hate when this stuff happens. I setup an email address like that for myself and I have never used it because I’m so afraid it will have something like that happen.

My dad is guilty of doing stuff like that often. He was renting a VRBO for the family and wanted us all to see the invite, but he threw in my email address that I only use for family correspondence. When I went to sign up (because he didn’t tell me this), I used a different address and it was a mess. I had to get him to re-invite me to the trip with the new email, but VRBO still started sending me some nonsense to my good email. He also gave it to some financial planner he uses and they started emailing me left and right. I was really upset. Like you said, he means well with it, but I don’t think anyone should be handing out other people’s email addresses.

The other thing that can get you are social sites that ask users to upload their contacts to find people they know. If your friend or family member uploads their address book, you’re account ends up in the Facebook, LinkedIn, Twitter, or whatever other site might do it. I’ve never used that feature for this reason, I don’t want to do that to people. But I know some of my friends and family have done it and my addresses are sitting in other DBs because of it, probably with my name, phone number, address, and maybe even birthday as well.

Re: Inside the "3 billion people" national public data breach

#429
post #369

Earlier quoted context omitted.

That's not even that big? `cat big_file | grep -v my_term` would go line-by-line and show any lines matching your query. If you're doing a lot of queries, you'd probably want to index it, so you throw it into a sqlite database with the usual SQL utils. Edit: I missed you said Windows. Probably Powershell have similar utilities, so you can do `ReadFileLineByLine \r \d big_file | ReturnHitBySearchTerm \v \t \s my_term`…

You absolutely do not want to use "-v" with that grep. Nor do you want to use cat (UUoCA) but that's very much a minor point in comparison.

UUoCA: https://porkmail.org/era/unix/award

I hadn't heard of it before.

Re: Inside the "3 billion people" national public data breach

#430
post #239

Earlier quoted context omitted.

Governments murdered hundreds of millions of their own people during the 20th century, and the 21st is shaping up to tell the 20th to hold its beer. Any proposal for modern ID needs to have Constitutional protections, checks, and balances or it will eventually devolve into a digital police state.

How? Everyone's like "a government went on and extermination campaign" and for some reason what would've stopped them is the difficulty in identifying who to exterminate? As though genocides much care about accuracy. The big secret of Nazi Germany that isn't a secret at all I is that they put a lot more then just Jews in those camps.

There are key differences between today and the 20th century that you are ignoring. Widely enforced digital ID not only makes it easier for them to identify who to genocide, it forces total compliance with the state, because if you do not fully comply, you risk death, imprisonment, or having your freedom and bank account revoked.
Post reply on HN