Live data from Hacker News

The unattributable “db8151dd” data breach

troyhunt.com

111–120 of 155 posts

Re: The unattributable “db8151dd” data breach

#111
post #92

After how many breach of ES clusters, Elastic will decide to make their db not accessible from external IP by default ?

That's the default for a long time already, but people actually want to use it from outside the server and so they configure the listener.

https://www.elastic.co/guide/en/elasticsearch/reference/6.3/...

Re: The unattributable “db8151dd” data breach

#112

Dataset for sale: [redacted] Similar data structure: https://stackblitz.com/edit/angular-soswe4?file=src%2Fapp%2F... Owner works for: https://covve.com Covve: This simple yet state-of-the-art app will revolutionise your business relations like you've never seen. Edit: Response: https://twitter.com/covve/status/1261287954967941120

The metadata in the breached records like "Imported from EverContacts" or similar supports the theory that it comes from a contacts app.

Curious why it has people's Github and Pintrest accounts when it's contact data.

Looks like it was mined from somewhere and combined with other data...

Unless people are putting their github urls in the contact apps?

Re: The unattributable “db8151dd” data breach

#113
post #30

> Why load it at all? Because every single time I ask about whether I should add data from an unattributable source, the answer is an overwhelming "yes" To be fair, you’re asking your followers on twitter. That’s as biased as you can have, I would be really surprised if the majority would say no.

I got notified that I'm in this breach, and I honestly don't know what (if anything) I can do with this information, which implies "If it's not actionable, why bother telling me at all?" Unique passwords per site, with a password manager? Done a long time ago. Should I change some of them? OK, which ones? there are hundreds. Details of what else about me is in this breech? Not clear where I can find that.

> Should I change some of them? OK, which ones? there are hundreds.

The ones that you know were pwned.

In theory you should change all passwords all the time, but this is a practical middle-ground between that and "never".

Re: The unattributable “db8151dd” data breach

#115
I did some quick searching for the dataformat included in the snippets from the article. Lots of repos with stored secrets that match:

https://github.com/acalvoa/SRID_CHANGER/blob/da367e68433b3fd...

Stored secret:

https://github.com/acalvoa/SRID_CHANGER/blob/master/config.p...

Will look more into this later

Re: The unattributable “db8151dd” data breach

#116

Earlier quoted context omitted.

A quick glance suggests there's barely any skill in there and it's all bottom-feeders so you'd expect this to be an easy bust for law enforcement worldwide and yet they seem to be happily operating with total impunity for quite some time.

Noobs and relatively skill makes me think H O N E Y P O T

No, more likely it's like street corner drug dealing, or say, the industrial area near me that has street walkers (well I presume it doesn't now because neither street walkers nor their johns want to die of COVID-19)

This stuff happens, at a low level, and prosecuting it is expensive and makes little real difference so why bother?

It's not even like busting shop lifters and petty burglars where at least you make the victim feel better by arresting somebody even if it likely isn't cost effective overall.

Re: The unattributable “db8151dd” data breach

#117
post #84

Earlier quoted context omitted.

If it takes you minutes to solve a recaptcha your problem might not be the recaptcha...

It might just be that you use Firefox. Seems anybody who doesn't use Chrome is automatically flagged even if you are logged in with a >12 years old gmail account that is linked to paid storage.

I use Firefox with numerous tracker blockers and only had to hit the checkbox.

Re: The unattributable “db8151dd” data breach

#118

Troy's fighting the good fight, but it's so freaking depressing. If he has hundreds of millions of records worth of personal data from just the breaches that have been shared with him, what _else_ is out there in the hands of criminals and corporations, neither of which have the public interest at heart—only naked self interest in exploiting members of the public for as much money as they can get?

Millions per day. This used to be part of one of my old jobs. A feed of stolen PII would drop into our SFTP server every morning and we'd process it.

There's no honour among thieves so there were a bunch of duplicates pretending to be "new" data, but yes there is a cottage industry of stealing smaller quantities of PII, focused particularly on email addresses and passwords (because those get re-used elsewhere) and credit card data (because you may be able to either buy something with it or at least fool your way past an immediate check on the card)

Do not re-use passwords. Like, that's the really easy "Wash your fucking hands" level lesson here. As someone who isn't employed to work with this data any more I'd say that 99% of the value isn't with like stolen passports (though we did see some passport data) or even credit cards, but the passwords.

If you hate that this is even a problem adopt and (if you write code or specify software) implement WebAuthn. Nobody would steal passwords if they didn't work. Not only does stealing WebAuthn credentials from a site's database not work (they're public, the secret that's valuable never leaves the user's FIDO dongle) crooks also wouldn't bother doing it, just like crooks don't steal farm machinery to pull candy vending machines off the wall and steal candy, whereas they do attack ATMs in exactly this way.

Re: The unattributable “db8151dd” data breach

#119

Earlier quoted context omitted.

Noobs and relatively skill makes me think H O N E Y P O T

No, more likely it's like street corner drug dealing, or say, the industrial area near me that has street walkers (well I presume it doesn't now because neither street walkers nor their johns want to die of COVID-19) This stuff happens, at a low level, and prosecuting it is expensive and makes little real difference so why bother? It's not even like busting shop lifters and petty burglars where at least you make the…

I remember one of the online British banks writing up a whole detailed post on how they knew exactly who has been stealing money from them.

They wrote up all of their information and sent it to the police who came back with: "Yeah, thanks. Here's the thing: this is non-violent crime and the total amount stolen is less than GBP 100,000" (don't remember the exact number but something thereabouts).

People like to think that the police are salivating for every crime that could come through the door. More realistically, they are an overworked group with less resources than they need to tackle and or solve many of the cases they are presented with.

Plus, just like you, they have to prioritize their work based on various dimensions of incentives such as what looks good to their boss, what is hard vs easy etc. For example, do you tackle the case that is small and easy to close with not a lot of publicity or the big case that may be harder to close but will net big wins in the PR budget?

Post reply on HN