Live data from Hacker News

SoundCloud Data Breach Now on HaveIBeenPwned

haveibeenpwned.com

81–90 of 113 posts

Re: SoundCloud Data Breach Now on HaveIBeenPwned

#81

Earlier quoted context omitted.

For some services, like Anthropic/Claude's stubborn refusal to let you remove your payment method, deleting isn't even an option.

I ran into this with Sony. The website said to call, so I did. After 45 minutes on hold the guy just hung up on me saying he couldn’t help, without even really listening to me. For a company that’s been hacked as many times as Sony, I find this to be pretty pathetic.

[deleted]

Re: SoundCloud Data Breach Now on HaveIBeenPwned

#83

making mountains out of mole hills. this type of panic is really common in the infosec world.

How so? I tend to disagree with the general statement that this is common in the infosec world, but I'd like to understand better what you mean by that.

Re: SoundCloud Data Breach Now on HaveIBeenPwned

#84

Earlier quoted context omitted.

For some services, like Anthropic/Claude's stubborn refusal to let you remove your payment method, deleting isn't even an option.

I ran into this with Sony. The website said to call, so I did. After 45 minutes on hold the guy just hung up on me saying he couldn’t help, without even really listening to me. For a company that’s been hacked as many times as Sony, I find this to be pretty pathetic.

I'm not surprised.

Different company, same story.

Re: SoundCloud Data Breach Now on HaveIBeenPwned

#86
People should be using email alias. 1 unique alias per 1 uniques service and websites for proper segregation. If any of the unique alias leaked or getting spammed you'd know where the source is and blocking that specific alias would limit the breach. Theres simplelogin.io, addy.io, firefox relay, apple hide-my-email, custom domain catchall etc for that.

Re: SoundCloud Data Breach Now on HaveIBeenPwned

#87

I went through and deleted a bunch of accounts a while ago, SoundCloud being one of them. It looks like I don't show up in the breach. It's nice to know SoundCloud actually deleted my data, I'm never totally sure what happens on the backend.

I still have two active accounts and neither of those were in the breach of the 20% of accounts.

Re: SoundCloud Data Breach Now on HaveIBeenPwned

#88

making mountains out of mole hills. this type of panic is really common in the infosec world.

How so? I tend to disagree with the general statement that this is common in the infosec world, but I'd like to understand better what you mean by that.

Impact in this case, is non-existent (Wow they got my email)

> I'd like to understand better what you mean by that.

Recall there was a period where every CPU sidechannel attack had a dedicated (wow) website and a rock band name assigned to it (when in reality their impact again, was/is limited).

Re: SoundCloud Data Breach Now on HaveIBeenPwned

#89

By aggregating breach data by email, this tool inadvertently exposes users's full web history, including sensitive sites like crypto/adult/dating platforms, to anyone who knows their address Fun

From the FAQ [1]: What is a "sensitive breach"? HIBP enables you to discover if your account was exposed in most of the data breaches by directly searching the system. However, certain breaches are particularly sensitive in that someone's presence in the breach may adversely impact them if others are able to find that they were a member of the site. These breaches are classed as "sensitive" and may not be publicly se…

You don't get to gatekeep what counts as "sensitive", all of my privacy is non-negotiable

Re: SoundCloud Data Breach Now on HaveIBeenPwned

#90

Earlier quoted context omitted.

The marketing move of offering an unlimited plan reveals that storage and traffic are not that expensive and someone made a choice that light users will subsidize heavy users. With that, hiding your data from you and subsequently deleting it, at least without first encouraging you to download it within some post-downgrade grace period, would be a choice, not necessity, and is user-hostile. If it is an actual necessit…

No matter their actual costs to provide the service, I'm struggling to see why they should not immediately delete all of your stored files upon cancellation of the storage service. They are a European company, so you are the customer, not the product and recipient of subsidies. They use less manipulation and dark patterns than an equivalent American company. You pay, you get service. You don't pay, you don't get serv…

> you are the customer, not the product and recipient of subsidies

They also do advertisement (promoted tracks and audio ads) but this is irrelevant to my point, what I described applies regardless, including the fact that heavy users of the unlimited plan and free users definitely receive subsidies, both from light users and from ad revenue of the platform.

> You pay, you get service. You don't pay, you don't get service

The definition of the service you receive and how good it is includes what happens when you decide to off-ramp from receiving it. Changing your service plan is your indication that you want to change service, what happens after that is how they handle it. There is no stipulation whatsoever that things stop being available to you immediately.

In fact, in case of SoundCloud, they themselves prove this, because they did not delete data but instead continued to keep data for free, which means providing you a service that you presumably stopped paying for. The silly move of them was to do that and not allow you to download it, and then emailing the victim urging them to pay to access this data, which makes it 100% a dark pattern and means they are effectively blackmailing customers with proven ability and willingness to pay.

If I remember right, Apple (an American company) handles it better and gives you a month to download excess data if you downgrade, but sure, “dark patterns”.

> There is no need for a grace period when you knowingly and voluntarily make the decision to terminate a file storage service.

If you terminate your use of a file storage service, you would expect your personal data to be deleted. However, no one terminated their use of a service, somebody apparently downgraded their payment plan (temporarily or not).

Post reply on HN