Live data from Hacker News

Inside the "3 billion people" national public data breach

troyhunt.com

441–450 of 472 posts

Re: Inside the "3 billion people" national public data breach

#441
post #13

Troy mentions "data opt-out services. Every person who used some sort of data opt-out service was not present." Anyone have experience with these sort of services? A search brings up a lot of scammy looking results. But if services exist to reduce my profile id be interested.

Permission Slip by Consumer Reports (automated): https://permissionslipcr.com Simple Opt Out (manual list): https://simpleoptout.com

I manually did a handful of opt-outs and am not in the list.

Re: Inside the "3 billion people" national public data breach

#442
post #69

> While the specifics of the data breach remain unclear, the trove of data was put up for sale on the dark web for $3.5 million in April, the complaint reads. I guess they failed to sell it because links to the leaked data on usdod.io have been available on Breachforum/Leakbase for over a week now. Someone created a magnet link yesterday and it's fully seeded so speeds are fast. The data in the breach is irreversibly…

> Someone created a magnet link yesterday Are you against simply sharing the infohash here? I'd like to download the leak to see what information it has on myself and my family, but I don't really relish the idea of signing up for a breachforums account and sifting though its posts if I can avoid it.

You can check to see if you were in the breach here:

https://npd.pentester.com/search

This will save you the effort of a 30min search per `grep` on the original breached files.

Re: Inside the "3 billion people" national public data breach

#443

Earlier quoted context omitted.

Good news loyal customer, we now support 2-factor authentication! ... over SMS!

I had phone number stolen (sim swap) two months ago and am still dealing with random things. 2FA over SMS is not a valid form of 2FA and I will die on that hill.

I keep telling my bank this but they simply do not care.

Re: Inside the "3 billion people" national public data breach

#444
post #69

Earlier quoted context omitted.

> Someone created a magnet link yesterday Are you against simply sharing the infohash here? I'd like to download the leak to see what information it has on myself and my family, but I don't really relish the idea of signing up for a breachforums account and sifting though its posts if I can avoid it.

Here is a strongly encrypted base64 version to keep hackers out: bWFnbmV0Oj94dD11cm46YnRpaDozY2FhNzFmM2VjOGNiY2NjNmZjYTRmZWI3MTg1ZGEyYmFiMTQ5YmE3JmRuPU5QRCZ0cj11ZHA6Ly90cmFja2VyLm9wZW5iaXR0b3JyZW50LmNvbTo4MCZ0cj11ZHA6Ly90cmFja2VyLm9wZW50cmFja3Iub3JnOjEzMzcvYW5ub3VuY2U= Allegedly, the password (also base64 encrypted) is: aHR0cHM6Ly91c2RvZC5pby8=

FYI: This is only the two social security files, not the whole breach.

Re: Inside the "3 billion people" national public data breach

#445

Earlier quoted context omitted.

In the US, the government could help alot if they simply moved to a national ID system and dismantled social security numbers. The national ID systems I've seen proposed have alot more security from the ground up, and could replace the passport system.

The US doesn't need a national ID. It needs a national PKI. The US Postal Service is in a great position to be the one who executes it. They have access to delivery physical goods to the entire country. They have the staff and procedures to do identity verification for their current products that could be extended to a PKI offering. It'll never fly, politically.

If you look at the best National ID systems in Europe, effective it’s all leveraging PKI. It needs a name, of course (National ID) and a purpose, however the entire core of these systems rest on PKI

Re: Inside the "3 billion people" national public data breach

#446
post #273

Earlier quoted context omitted.

This is a solved problem. If the ID is on your phone, you can make it so that the transaction details have to be digitally signed by the person authorizing them in order to be valid. Then, if 3€ shows up on your phone, that's what you're authorizing, not 300€.

Sure, given an advanced enough device anything is possible. But I think here we are still discussing a "card" form factor for ID? (Being an "unperson" simply because you don't have a smartphone or have a rooted one would be "interesting").

Most places with digital IDs use either a phone card reader or the phone’s own NFC terminal to read a contactless smart card. The cryptographic key comes from the smart card, with the phone as a payment terminal.

Nothing advanced is required. And sure, your phone can be hacked, but there’s only so much fearmongering to go around.

Re: Inside the "3 billion people" national public data breach

#447

Earlier quoted context omitted.

Here is a strongly encrypted base64 version to keep hackers out: bWFnbmV0Oj94dD11cm46YnRpaDozY2FhNzFmM2VjOGNiY2NjNmZjYTRmZWI3MTg1ZGEyYmFiMTQ5YmE3JmRuPU5QRCZ0cj11ZHA6Ly90cmFja2VyLm9wZW5iaXR0b3JyZW50LmNvbTo4MCZ0cj11ZHA6Ly90cmFja2VyLm9wZW50cmFja3Iub3JnOjEzMzcvYW5ub3VuY2U= Allegedly, the password (also base64 encrypted) is: aHR0cHM6Ly91c2RvZC5pby8=

I can't believe HN mods think it's ok to leave this comment up. I don't know of a way to report it myself unfortunately.

Excuse me, why is linking to something bad? Especially when it contains your own data?

Re: Inside the "3 billion people" national public data breach

#448
post #293
post #286

What if we just made all this data free , some AI is going to compile them anyway (and probably already has). Deterrence is the best defense, right ?

It depends on the country. Where I live now even if I leak my name, date of birth, bank details, national id number, etc. you couldn't do much. We have a country wide 2FA system that all important businesses use (bank, utilities, health, government) to authenticate users. I'm from the UK though, and previously was a 'victim' of identify theft where a few years ago someone walked into a phone store, and walked out wit…

Is the country wide 2FA implemented by the country or a private company? While rare, what if a person does not have access to the 2FA mechanism, and what mechanisms are permitted to confirm an identity?

Re: Inside the "3 billion people" national public data breach

#449

Earlier quoted context omitted.

I can't believe HN mods think it's ok to leave this comment up. I don't know of a way to report it myself unfortunately.

Excuse me, why is linking to something bad? Especially when it contains your own data?

https://en.wikipedia.org/wiki/Doxing?lang=en
Post reply on HN