Live data from Hacker News

SoundCloud Data Breach Now on HaveIBeenPwned

haveibeenpwned.com

41–50 of 113 posts

Re: SoundCloud Data Breach Now on HaveIBeenPwned

#41

By aggregating breach data by email, this tool inadvertently exposes users's full web history, including sensitive sites like crypto/adult/dating platforms, to anyone who knows their address Fun

From the FAQ [1]:

What is a "sensitive breach"?

HIBP enables you to discover if your account was exposed in most of the data breaches by directly searching the system. However, certain breaches are particularly sensitive in that someone's presence in the breach may adversely impact them if others are able to find that they were a member of the site. These breaches are classed as "sensitive" and may not be publicly searched.

A sensitive data breach can only be searched by the verified owner of the email address being searched for. This is done by signing in to the dashboard which involves verifying you can receive an email to the entered address. Once signed in, all breaches (including sensitive ones) are visible in the "Breaches" section under "Personal".

There are presently 82 sensitive breaches in the system including Adult FriendFinder (2015), Adult FriendFinder (2016), Adult-FanFiction.Org, Ashley Madison, Beautiful People, Bestialitysextaboo, Brazzers, BudTrader, Carding Mafia (December 2021), Carding Mafia (March 2021), Catwatchful, CityJerks, Cocospy, Color Dating, CrimeAgency vBulletin Hacks, CTARS, CyberServe, Date Hot Brunettes, DC Health Link, Doxbin and 62 more.

[1] https://haveibeenpwned.com/FAQs#SensitiveBreach

Re: SoundCloud Data Breach Now on HaveIBeenPwned

#42

Earlier quoted context omitted.

You can export your entire profile using yt-dlp. Of course you have to do it, when you are still a paying customer.

Why would someone that writes their own songs, mixes in GarageBand, uploads to a 3rd party website need to use yt-dlp to get back the files that they themselves made? Yes, I'm intentionally victim blaming here. The victim is complaining about a 3rd party site deleting files. Who cares? Why would you have as your only source of your files the copies stored by the 3rd party?

You get a point there, but export is mostly about metadata, eg images and description.

Data loss happens too. Soundcloud may be your only source of your own tracks.

Re: SoundCloud Data Breach Now on HaveIBeenPwned

#43
post #35

Earlier quoted context omitted.

Maybe the two public data points weren't connected before? I don't use SoundCloud, but if profiles didn't have contact information like Email Address on them then it could be meaningful to now connect those two dots. Like, 'Hey look, Person A, who is known to use email address X, kept Lost Prophets as one of their liked artists even after 2013!'

But, why care? (Yes, we can “care” that there was a leak - but… why worry? what new risk exists today that didn’t yesterday?) The data in the leak (other than follower count, etc) was already available for purchase from Zoominfo, 8sense, or a variety of other data brokers or other legal marketplaces for PII. I suppose the risk now is that the data is freely available and no longer behind a data broker’s paywall?

I'm confused, where were scrapers/data brokers/Zoominfo etc. were getting email addresses for SoundCloud accounts?

Re: SoundCloud Data Breach Now on HaveIBeenPwned

#44
post #9

Earlier quoted context omitted.

that just sounds like customer not paying for service not getting the service

The service is freemium, so they had a limited account. Decided to pay for a premium account. And apparently can’t downgrade and get back what they once had.

I'm just guessing, but this:

> and have posted my rough mixes [...] on my SoundCloud for more then ten years

...easily implies >3h of uploads, which is over the free plan limit. If you're over that limit and stop paying, yes, it makes perfect sense that they'd threaten with deletion of some of your existing uploads.

Re: SoundCloud Data Breach Now on HaveIBeenPwned

#45
post #35

Earlier quoted context omitted.

But, why care? (Yes, we can “care” that there was a leak - but… why worry? what new risk exists today that didn’t yesterday?) The data in the leak (other than follower count, etc) was already available for purchase from Zoominfo, 8sense, or a variety of other data brokers or other legal marketplaces for PII. I suppose the risk now is that the data is freely available and no longer behind a data broker’s paywall?

I'm confused, where were scrapers/data brokers/Zoominfo etc. were getting email addresses for SoundCloud accounts?

They don’t. I’m confused why that info is valuable.

Re: SoundCloud Data Breach Now on HaveIBeenPwned

#47

Earlier quoted context omitted.

They first hide your songs and as time goes on they start threaten to delete your songs if you dont pay

What should they do instead? spend money continuously holding your music on disk forever even though you aren't paying them for the service? Sounds like they are being cool about it by keeping it around for a while and warning you before deleting it.

Overall what Im saying is they treat their non-paying customers better then their paying ones. Once I was a paying customer after having and using my free account for over 7 years then converting to a paying customer and having to cancel Soundcloud became hostile.

Re: SoundCloud Data Breach Now on HaveIBeenPwned

#50

So I guess I should watch out for scams being sent to "soundcloud@" on a personal domain. Oh no, how will I distinguish them from my legitimate banking email???

Clever spammers (there are some!) see the presence of company@ and assume the user will have similar emails for other accounts, so it might be worth trying ebays scams to ebay@ or banking scams to chase@ or boa@. Sending is cheap so why not, you're not trying to fool everyone, only a few.

I use a unique string per company but it's not guessable in advance, but it's obvious when looking at it and squinting a bit, for example (and these are not the exact ones I use): sundclod@ or ebuy@ or amzoon@

Sure I have to remember them but it's easy for me to check and my password manager is filling them in for me 99.99% of the time.

I can filter on those emails instead, and I also know that anything coming to soundcloud@ or ebay@ or amazon@ is definitely spam as I've never used those addresses myself.

If sundclod@ appears in a leak I can (hopefully) change my account email at Soundcloud to sondclud@ and then confine sundclod@ to /dev/null

Post reply on HN