Live data from Hacker News

1.9M Bell customer email addresses stolen by 'anonymous hacker'

cbc.ca

11–20 of 23 posts

Re: 1.9M Bell customer email addresses stolen by 'anonymous hacker'

#11
post #7

Perhaps I have security breach fatigue, but I am somewhat fed up with the usual "emails stolen" headline. An address and a name are by definition publicly available records. You can steal them simply by walking down the street and taking down mailbox names (or requesting these records from the city hall). Of course the fact that these names are Bell's customers gives someone one more bit of information, but again not…

The reason this is bad is because fresh email lists like this are used with common password lists to bruteforce logins to common sites. With 1.9 million valid emails, odds are some have used insercured passwords on some sites.

Because of this, emails are private information. If you are not posting it publicly, you will only be sharing it with friends and trusted companies. All of which should keep it secret and never have them leaked.

Re: 1.9M Bell customer email addresses stolen by 'anonymous hacker'

#13
post #7

Perhaps I have security breach fatigue, but I am somewhat fed up with the usual "emails stolen" headline. An address and a name are by definition publicly available records. You can steal them simply by walking down the street and taking down mailbox names (or requesting these records from the city hall). Of course the fact that these names are Bell's customers gives someone one more bit of information, but again not…

No. Stop. An email address is not a publicly available record.

And I have no idea how on earth you could think it would be.

Re: 1.9M Bell customer email addresses stolen by 'anonymous hacker'

#14
post #7

Perhaps I have security breach fatigue, but I am somewhat fed up with the usual "emails stolen" headline. An address and a name are by definition publicly available records. You can steal them simply by walking down the street and taking down mailbox names (or requesting these records from the city hall). Of course the fact that these names are Bell's customers gives someone one more bit of information, but again not…

The issue is that Bell tried to keep customer information secure, but could not. Luckily it's low impact (in your opinion), but it could have been high impact information.

EDIT: another thing, it's Bell - an internet service provider who should have a higher standard in security. Not some email distribution list of a mom & pop shop where you willingly provided your email address (ie. made it publicly available).

Re: 1.9M Bell customer email addresses stolen by 'anonymous hacker'

#15
post #13
post #7

Perhaps I have security breach fatigue, but I am somewhat fed up with the usual "emails stolen" headline. An address and a name are by definition publicly available records. You can steal them simply by walking down the street and taking down mailbox names (or requesting these records from the city hall). Of course the fact that these names are Bell's customers gives someone one more bit of information, but again not…

No. Stop. An email address is not a publicly available record. And I have no idea how on earth you could think it would be.

>No. Stop. An email address is not a publicly available record.

Sure it is. it's given out extensively for individuals to contact you. Same as a phone number used to be published in a phone book. Same as we publish public keys and same as your username here is public.

It is by definition, something that is shared to the public for public use... as opposed to a secret like a passphrase or private key.

Re: 1.9M Bell customer email addresses stolen by 'anonymous hacker'

#16
post #13

Earlier quoted context omitted.

No. Stop. An email address is not a publicly available record. And I have no idea how on earth you could think it would be.

>No. Stop. An email address is not a publicly available record. Sure it is. it's given out extensively for individuals to contact you. Same as a phone number used to be published in a phone book. Same as we publish public keys and same as your username here is public. It is by definition, something that is shared to the public for public use... as opposed to a secret like a passphrase or private key.

And if you only give an email address to a single company to open an account with them? Is that public too? Not everyone has a single email address they give to anyone who asks for it.

There's "public" as in you're not the only person who knows it (not secret) and there's "public" as in it is freely available to anyone who wants it without any interaction with you personally.

Re: 1.9M Bell customer email addresses stolen by 'anonymous hacker'

#17
post #13

Earlier quoted context omitted.

No. Stop. An email address is not a publicly available record. And I have no idea how on earth you could think it would be.

>No. Stop. An email address is not a publicly available record. Sure it is. it's given out extensively for individuals to contact you. Same as a phone number used to be published in a phone book. Same as we publish public keys and same as your username here is public. It is by definition, something that is shared to the public for public use... as opposed to a secret like a passphrase or private key.

Yes, it is given out to individuals and corporations voluntarily by me. Normally noone have the means to find out what email address I have without asking me. Hence it is NOT a public record.

A phone number can be unlisted (the term differs between different countries) - which is not the same as being "hidden/private" it just means that it isn't a publicly available record and not listed in phone books.

How can this be a foreign concept?

Re: 1.9M Bell customer email addresses stolen by 'anonymous hacker'

#18
Original posting:

https://pastebin.com/zHffB8rA

This contains a bit more data than they were suggesting and a tar file for a .mozilla directory, possibly containing some saved passwords?

It appears to include b1* usernames and maybe passwords (Used for Bell PPPoE credentials), might be enough to steal someone's bandwidth or make it look like someone else downloaded something rather illegal.

Re: 1.9M Bell customer email addresses stolen by 'anonymous hacker'

#19
post #13

Earlier quoted context omitted.

No. Stop. An email address is not a publicly available record. And I have no idea how on earth you could think it would be.

>No. Stop. An email address is not a publicly available record. Sure it is. it's given out extensively for individuals to contact you. Same as a phone number used to be published in a phone book. Same as we publish public keys and same as your username here is public. It is by definition, something that is shared to the public for public use... as opposed to a secret like a passphrase or private key.

Yeah, I wish. I've done >50 FOIA requests for email communications' metadata across the US and one of the more common rejection reasons is specifically that email addresses are NOT public records. Sure, the domain name is, but that's about it.
Post reply on HN