Live data from Hacker News

My docs got dropped in the Stratfor leak

kyleisom.net

1–10 of 26 posts

Re: My docs got dropped in the Stratfor leak

#4
Yes, the security of Stratfor was unacceptably lax, and yes, getting mad is generally a waste of energy, but you can't legitimately compare the criminals who broke into Stratfor and committed credit-card fraud to a five-year-old who's gotten into the cookie jar. They are old enough to take responsibility for and be held accountable for their actions; a five-year-old is not.

Re: My docs got dropped in the Stratfor leak

#5
Me too. I'm actually pretty pissed at Stratfor because it's a huge inconvenience.

Unfortunately, I used an email address that I use on other sites, so now I have to decide whether or not to create a new email account for everywhere else, which is extremely, extremely annoying. Luckily, I used a separate password for Stratfor (12+ characters).

Also, unfortunately, the cc was my main cc number, so that means I have to change EVERYTHING, which is a huge hassle.

I guess this means I just have to keep creating throwaway email addresses for every new service that I sign up for, which is turning into a management nightmare.

Re: My docs got dropped in the Stratfor leak

#6
post #4

Yes, the security of Stratfor was unacceptably lax, and yes, getting mad is generally a waste of energy, but you can't legitimately compare the criminals who broke into Stratfor and committed credit-card fraud to a five-year-old who's gotten into the cookie jar. They are old enough to take responsibility for and be held accountable for their actions; a five-year-old is not.

Interesting, I hadn't thought along those lines when I wrote that because I was focused on how lax the security was, and not thinking about culpability. I updated the post with a note about that.

Re: My docs got dropped in the Stratfor leak

#7
post #3

Have any of these sites been brought to court for criminal negligence? If CC# are getting dumped, they probably broke a bunch of PCI rules too.

Like I said, I've love to see legislative effort aimed at making this sort of negligence criminal; I have absolutely no legal background so I have no idea if there's current legal ground to pursue on.

They did store CVVs and expiration dates in addition to credit card numbers, so I'd imagine there's some sort of PCI violation going on.

Re: My docs got dropped in the Stratfor leak

#8
post #3

Have any of these sites been brought to court for criminal negligence? If CC# are getting dumped, they probably broke a bunch of PCI rules too.

IIRC and IANAL, but someone mentioned a Texas law that requires companies to properly protect customer data. Stratfor is based in Austin.

I wouldn't want to be in their shoes.

Re: My docs got dropped in the Stratfor leak

#10
post #4

Yes, the security of Stratfor was unacceptably lax, and yes, getting mad is generally a waste of energy, but you can't legitimately compare the criminals who broke into Stratfor and committed credit-card fraud to a five-year-old who's gotten into the cookie jar. They are old enough to take responsibility for and be held accountable for their actions; a five-year-old is not.

And, unlike a five year-old, they have the aptitude to pick specific targets and continue to do so. Tactics of a hack are secondary. Intrusion is intrusion, and whether or not they sneak in like a spy in a James Bond movie or just walk in the back door is far, far down their list of their goals.

Can we get past relating them to children now? Many of them are professionals, and if we're lucky, will soon enough be ones who are running next Stratfor. Afterall, folks like these guys founded the infosec industry.

Post reply on HN