Live data from Hacker News

Notes on the Celebrity Data Theft

nikcub.com

11–20 of 292 posts

Re: Notes on the Celebrity Data Theft

#11
While I am complete appalled by the data breach and hope that similar things never happens to anyone again

I would like to propose a purely thought experiment:

The hacker reported sold the nude photos of Jennifer lawrence for a mere sum of $130 using bitcoin.

If we apply game theory here, these kind of data is very difficult to monetize. If you sell one copy of the data, it is then immediately distributed online for free. Although, nude photos of celebs are arguably very valuable.

The question is: What is the ideal path for these people to maximize profits?

I think the better alternative would have been a kick starter type model where the attacker will only release photos if reaches a funding goal (let's say $50k). The attacker might release less revealing photos to build interests in the goal funding.

I often hear about decentralized kickstarter models with bitcoin (mutlsig; or ANYONE_CAN_PAY hash type). But I always thought of them as gimmicky. This is actually a use case for it.

So going beyond, celeb photo breach, this similar model should be applied to many more scenarios. ie.

1. you have a valuable asset,

2. but it loses value immediately after the first distribution

3. so you must capture all of the value at distribution

Note:

Anyone can pay: https://bitcoin.org/en/developer-guide#term-sighash-anyoneca...

Re: Notes on the Celebrity Data Theft

#12
post #2

I wrote this in the other thread on the leak before it died: > Even if the leaks result from one at a time social engineering, it still really calls into question the practical security of the cloud. I doubt it's much harder to steal, e.g. confidential business documents from executives' cloud accounts than it is to steal pictures from celebrities' cloud accounts. > If I were a big organization with confidential info…

You are so right on the money. We used to see hacking into celebrities' gmail inboxes, social accounts, dropbox stores - all through social engineering. We now see hacking into icloud. Next we will see hacking into gdrive, onedrive or some samsung cloud - if enough celebrities start using Android or Winphone. The pattern is the same, so is the weakest point - the actual user. Maybe it's time to educate people more instead of writing more security software.

Re: Notes on the Celebrity Data Theft

#13
Icloud hacking was mentioned and everyone has jumped on it. Many cell transmissions are unencrypted. MITM attacks should not be thrown out as a possibility. Malware is also a vector, including apps.

Re: Notes on the Celebrity Data Theft

#15

While I am complete appalled by the data breach and hope that similar things never happens to anyone again I would like to propose a purely thought experiment: The hacker reported sold the nude photos of Jennifer lawrence for a mere sum of $130 using bitcoin. If we apply game theory here, these kind of data is very difficult to monetize. If you sell one copy of the data, it is then immediately distributed online for…

I believe that this applies to many products using digital distribution that meet the following:

1. The asset takes requires a significant amount of resources.

2. The asset will require all resources in order to distribute.

3. No further resources are required after distribution.

Music, books, art, and even software that does not require updates would fall into this category.

Re: Notes on the Celebrity Data Theft

#16
post #5
post #2

I wrote this in the other thread on the leak before it died: > Even if the leaks result from one at a time social engineering, it still really calls into question the practical security of the cloud. I doubt it's much harder to steal, e.g. confidential business documents from executives' cloud accounts than it is to steal pictures from celebrities' cloud accounts. > If I were a big organization with confidential info…

> data never leaves a company desktop, laptop, or blackberry. That's not all that draconian. Data never leaves the servers, full stop. (Other than for back-up purposes and those had better be encrypted.)

Seconded. Corporate network only as the place from where company managed clients are allowed to access production network, where the data stays. Even when someone manages to steal all the electronics from the office, he still doesn't get any data/source code/whatever. Easier said than done though.

Re: Notes on the Celebrity Data Theft

#17

While I am complete appalled by the data breach and hope that similar things never happens to anyone again I would like to propose a purely thought experiment: The hacker reported sold the nude photos of Jennifer lawrence for a mere sum of $130 using bitcoin. If we apply game theory here, these kind of data is very difficult to monetize. If you sell one copy of the data, it is then immediately distributed online for…

https://en.wikipedia.org/wiki/Assassination_market

Re: Notes on the Celebrity Data Theft

#19
post #16
post #5

Earlier quoted context omitted.

> data never leaves a company desktop, laptop, or blackberry. That's not all that draconian. Data never leaves the servers, full stop. (Other than for back-up purposes and those had better be encrypted.)

Seconded. Corporate network only as the place from where company managed clients are allowed to access production network, where the data stays. Even when someone manages to steal all the electronics from the office, he still doesn't get any data/source code/whatever. Easier said than done though.

And you're still going to have to do a lot of work to prevent exfiltration from the servers other than for backup-purposes and track your back-ups and who has access to them.
Post reply on HN