Live data from Hacker News

SoundCloud Data Breach Now on HaveIBeenPwned

haveibeenpwned.com

51–60 of 113 posts

Re: SoundCloud Data Breach Now on HaveIBeenPwned

#51

So I guess I should watch out for scams being sent to "soundcloud@" on a personal domain. Oh no, how will I distinguish them from my legitimate banking email???

We are the minority of users that had enough foresight to do this. I'd bet that _most_ people on this breach don't even know about the plus/dot trick with gmail (and I am sure other providers, too).

Re: SoundCloud Data Breach Now on HaveIBeenPwned

#52

SoundCloud is the worst company, so hostile to former paying users! I am a hobbyist songwriter and have posted my rough mixes (Apple's Music Memo app which adds drum and bass automagically with two clicks & then mix it in Garage Band) on my SoundCloud for more then ten years. I signed up for their Artist Pro account and was a member for of such consistently for a few years at $17 a month. Once you cancel they then ho…

that just sounds like customer not paying for service not getting the service

I'd pay for Soundcloud, but not sure what I'd get for over free version. It costs more than Apple Music and offering offline nowadays is lol feature.

Re: SoundCloud Data Breach Now on HaveIBeenPwned

#53

Earlier quoted context omitted.

They first hide your songs and as time goes on they start threaten to delete your songs if you dont pay

What should they do instead? spend money continuously holding your music on disk forever even though you aren't paying them for the service? Sounds like they are being cool about it by keeping it around for a while and warning you before deleting it.

As a listener I'd pay (a reasonable amount like Their best feature is social feed - I only see reposts from people I follow. But for branching out / discovery might be cool to see what their feed looks like, so something like "show followees feed".

Re: SoundCloud Data Breach Now on HaveIBeenPwned

#54
post #36

Earlier quoted context omitted.

Maybe the two public data points weren't connected before? I don't use SoundCloud, but if profiles didn't have contact information like Email Address on them then it could be meaningful to now connect those two dots. Like, 'Hey look, Person A, who is known to use email address X, kept Lost Prophets as one of their liked artists even after 2013!'

Yeah or this: https://news.ycombinator.com/item?id=26386418 SoundCloud is a weird place, people in entertainment have certain strong incentives. They figured out who I am, figured out all the email addresses I have, jacked the account attached to my SoundCloud, stole my account. I still to this day, don't know how they pwned my email (tfa was on but it didn't trigger suspicious activity it let them login without trig…

Organized crime stealing usernames was apparently a thing for a few years back there, interesting it wasn't limited to Twitter.

Re: SoundCloud Data Breach Now on HaveIBeenPwned

#55
post #35

Earlier quoted context omitted.

Maybe the two public data points weren't connected before? I don't use SoundCloud, but if profiles didn't have contact information like Email Address on them then it could be meaningful to now connect those two dots. Like, 'Hey look, Person A, who is known to use email address X, kept Lost Prophets as one of their liked artists even after 2013!'

But, why care? (Yes, we can “care” that there was a leak - but… why worry? what new risk exists today that didn’t yesterday?) The data in the leak (other than follower count, etc) was already available for purchase from Zoominfo, 8sense, or a variety of other data brokers or other legal marketplaces for PII. I suppose the risk now is that the data is freely available and no longer behind a data broker’s paywall?

Isn't that a huge GDPR violation?

Re: SoundCloud Data Breach Now on HaveIBeenPwned

#56
post #50

So I guess I should watch out for scams being sent to "soundcloud@" on a personal domain. Oh no, how will I distinguish them from my legitimate banking email???

Clever spammers (there are some!) see the presence of company@ and assume the user will have similar emails for other accounts, so it might be worth trying ebays scams to ebay@ or banking scams to chase@ or boa@ . Sending is cheap so why not, you're not trying to fool everyone, only a few. I use a unique string per company but it's not guessable in advance, but it's obvious when looking at it and squinting a bit, for…

For the more shady sites, I use first names or fake usernames.

Re: SoundCloud Data Breach Now on HaveIBeenPwned

#57
Glad that I removed my SoundCloud account right on time.

I think it’s only a matter of time before a service gets breached.

It's best to use unique random username, email, and password for every online account. Also, providing only the bare minimum of data and faking as much as possible is helpful in cases of data breaches.

Re: SoundCloud Data Breach Now on HaveIBeenPwned

#58

Earlier quoted context omitted.

What should they do instead? spend money continuously holding your music on disk forever even though you aren't paying them for the service? Sounds like they are being cool about it by keeping it around for a while and warning you before deleting it.

The marketing move of offering an unlimited plan reveals that storage and traffic are not that expensive and someone made a choice that light users will subsidize heavy users. With that, hiding your data from you and subsequently deleting it, at least without first encouraging you to download it within some post-downgrade grace period, would be a choice, not necessity, and is user-hostile. If it is an actual necessit…

No matter their actual costs to provide the service, I'm struggling to see why they should not immediately delete all of your stored files upon cancellation of the storage service.

They are a European company, so you are the customer, not the product and recipient of subsidies. They use less manipulation and dark patterns than an equivalent American company.

You pay, you get service. You don't pay, you don't get service. If they can't bill you, they should try to communicate with you for a few months before treating it as a cancellation. If you cancel, then your choice is clear and you should expect your service to be immediately terminated at the end of the current billing period. If their service is storing files for you, termination of the service means deletion of the files.

There is no need for a grace period when you knowingly and voluntarily make the decision to terminate a file storage service.

Re: SoundCloud Data Breach Now on HaveIBeenPwned

#59

Earlier quoted context omitted.

What should they do instead? spend money continuously holding your music on disk forever even though you aren't paying them for the service? Sounds like they are being cool about it by keeping it around for a while and warning you before deleting it.

Overall what Im saying is they treat their non-paying customers better then their paying ones. Once I was a paying customer after having and using my free account for over 7 years then converting to a paying customer and having to cancel Soundcloud became hostile.

Did you have more stored data than the limit for stored data for unpaid accounts?

Re: SoundCloud Data Breach Now on HaveIBeenPwned

#60

By aggregating breach data by email, this tool inadvertently exposes users's full web history, including sensitive sites like crypto/adult/dating platforms, to anyone who knows their address Fun

From the FAQ [1]: What is a "sensitive breach"? HIBP enables you to discover if your account was exposed in most of the data breaches by directly searching the system. However, certain breaches are particularly sensitive in that someone's presence in the breach may adversely impact them if others are able to find that they were a member of the site. These breaches are classed as "sensitive" and may not be publicly se…

> Bestialitysextaboo

I laughed pretty hard

Post reply on HN