Live data from Hacker News

The 773M Record “Collection #1” Data Breach

troyhunt.com

111–120 of 128 posts

Re: The 773M Record “Collection #1” Data Breach

#111
post #3

This is frankly terrifying and very ironic. Websites put so much effort into tracking every little thing about their users, from where they come from to what they do. Hotjar ( https://hotjar.com ) goes ahead and tracks mouse movements and now we even have crazy f-ed up startups like Peekmap ( https://peekmap.com ) that claim to predict eye gaze without the webcam. And yet they get pwned so easily. So much effort into…

I think you should have disclosed that you are part of Peekmap's team: https://angel.co/peekmap/jobs

This post looks almost like an ad. I hope, then, you are putting effort into "enforcing user security".

Re: The 773M Record “Collection #1” Data Breach

#112
post #111
post #3

This is frankly terrifying and very ironic. Websites put so much effort into tracking every little thing about their users, from where they come from to what they do. Hotjar ( https://hotjar.com ) goes ahead and tracks mouse movements and now we even have crazy f-ed up startups like Peekmap ( https://peekmap.com ) that claim to predict eye gaze without the webcam. And yet they get pwned so easily. So much effort into…

I think you should have disclosed that you are part of Peekmap's team: https://angel.co/peekmap/jobs This post looks almost like an ad. I hope, then, you are putting effort into "enforcing user security".

wow what odd way to promote his startup. super disingenuous. I hope know one ends up applying there after seeing this.

Re: The 773M Record “Collection #1” Data Breach

#113

Earlier quoted context omitted.

I think it's time for an external, trustworthy entity to spawn that would vet and endorse companies that respect their users. Something like the "USDA Organic" label but for user privacies. Maybe it'd be an EFF-like entity that audits companies in exchange for a fee and endorse that "Company X, and the product/services it uses, are respecting user privacy". We could then derive a chain of trust between companies, may…

I've gone back and forth on this. The very likely outcome of such a thing in practice is another PCI-like process. We both know an "EFF-like" organisation selected by a Government will one of the big accounting firms or similar in practice. Particularly once there's a certification fee, it quickly becomes a racket, where people with strong ethics and skills get pushed aside by someone who paid a fortune to sit a cour…

You're catastrophizing by jumping to a negative outcome, similar to a cognitive distortion. It doesn't have to become a racket; that is a leadership choice. Individual identity issuing, public key certifying authority, banking, news, healthcare, truth-worthiness and many more areas would all be served best by non-profits that are funded by a combination of grants, modest fees and/or donations. There are some human activities that are too important to be privatized, like the fire department and the NTSB... whether the government should or shouldn't be responsible for running X is a topic for another time.

Re: The 773M Record “Collection #1” Data Breach

#115
post #3

This is frankly terrifying and very ironic. Websites put so much effort into tracking every little thing about their users, from where they come from to what they do. Hotjar ( https://hotjar.com ) goes ahead and tracks mouse movements and now we even have crazy f-ed up startups like Peekmap ( https://peekmap.com ) that claim to predict eye gaze without the webcam. And yet they get pwned so easily. So much effort into…

"crazy f-ed up startups like Peekmap".

Sounds synonomous with "scum bag" to me, priansch.

Re: The 773M Record “Collection #1” Data Breach

#116
post #111
post #3

This is frankly terrifying and very ironic. Websites put so much effort into tracking every little thing about their users, from where they come from to what they do. Hotjar ( https://hotjar.com ) goes ahead and tracks mouse movements and now we even have crazy f-ed up startups like Peekmap ( https://peekmap.com ) that claim to predict eye gaze without the webcam. And yet they get pwned so easily. So much effort into…

I think you should have disclosed that you are part of Peekmap's team: https://angel.co/peekmap/jobs This post looks almost like an ad. I hope, then, you are putting effort into "enforcing user security".

Holy cow good catch.

This is very weird.....

EDIT: Nice to see their open development position is an unpaid internship.

Re: The 773M Record “Collection #1” Data Breach

#117
post #111
post #3

This is frankly terrifying and very ironic. Websites put so much effort into tracking every little thing about their users, from where they come from to what they do. Hotjar ( https://hotjar.com ) goes ahead and tracks mouse movements and now we even have crazy f-ed up startups like Peekmap ( https://peekmap.com ) that claim to predict eye gaze without the webcam. And yet they get pwned so easily. So much effort into…

I think you should have disclosed that you are part of Peekmap's team: https://angel.co/peekmap/jobs This post looks almost like an ad. I hope, then, you are putting effort into "enforcing user security".

>> “and now we even have crazy f-ed up startups like Peekmap (https://peekmap.com) that claim to predict eye gaze without the webcam.”

Emphasis on ‘claim’. Considering he built this product, it would insinuate they don’t actually have this capability and are instead selling lies, pipe dreams and bullshit.

Re: The 773M Record “Collection #1” Data Breach

#118
post #64
post #43

Earlier quoted context omitted.

Bitwarden ( https://bitwarden.com/ ) is great and scores well in feature comparisons -- there was one on here recently. It's open source and has recently been audited too. It's free for the basic service, and really cheap for additional features. Great mobile apps and a web vault. And you can self-host. No bad points really.

The things that held me back from Bitwarden is the relatively short age of the company at 2~ years and the fact that there is only one dev. I'm reaching here. But even though the code is open source, he still owns the distribution. He can potentially be compromised (whether maliciously or not) and release an update that uploads the entire vault to him unencrypted. It could take a while before the internet caught on t…

All valid points. I guess nothing is perfect and you just need to decide where you're happy to compromise.

Re: The 773M Record “Collection #1” Data Breach

#119
post #46

Earlier quoted context omitted.

Well it claims to take the first 5 characters of the SHA of the plaintext. But it also pulls untrusted code/CSS from various sites over HTTP. It's far from unclear who controls that code. For instance this wall of code: http://az416426.vo.msecnd.net/scripts/a/ai.0.js A more sane approach would be to just put your passwords in a file, maybe by export from your database manager. Take a sha1 of each password, then submi…

Not trying to be a pedant, but wouldn’t “[...]it’s far from clear[...]” be (more?) correct? If it’s ‘far from unclear’, it would seem to imply things are rather clear, IMHO.

Heh, sure, "far from clear" is what I meant to say.

It would take substantial time, expertise, and effort to audit that single web page. Even then any of the numerous pieces could change at any time.

So the risk is high, especially for something you are putting trusted passwords into.

Re: The 773M Record “Collection #1” Data Breach

#120

Anyone got a link to the actual data?

There's a .torrent of Collection #1 available here:

http://www.mediafire.com/file/mluhkk4dpqi8vfm/Collection_1.t...

I found the link via a comment on /r/pwned [1]. I think it originally came from RaidForums [2].

[1] https://www.reddit.com/r/pwned/comments/agsjie/troy_hunt_the...

[2] https://raidforums.com/Thread-Collection-1-5-Zabagur-AntiPub...

Post reply on HN