Live data from Hacker News

The unattributable “db8151dd” data breach

troyhunt.com

151–155 of 155 posts

Re: The unattributable “db8151dd” data breach

#151

Earlier quoted context omitted.

So many things disallow + in email addresses I don't even bother any more.

All services so far seem to accept dots, but the number of possible dot arrangements can be quite limited, and it is a pain to actually use (figure out next one to use, figure out associated service from dot arrangement, etc).

Gmail won't let you put anything arbitrary with dots. So if you're whatever@gmail.com you can use what.ever@gmail.com but not whatever+somemerchant@gmail.com. Other email system obviously can work however they want.

Re: The unattributable “db8151dd” data breach

#152

Dataset for sale: [redacted] Similar data structure: https://stackblitz.com/edit/angular-soswe4?file=src%2Fapp%2F... Owner works for: https://covve.com Covve: This simple yet state-of-the-art app will revolutionise your business relations like you've never seen. Edit: Response: https://twitter.com/covve/status/1261287954967941120

haha, I found exactly the same! https://twitter.com/amatecha/status/1261231178423517184 A user who replied to me also shared some anecdotes that indicate further evidence towards that being the source (a private email address only used for GSuite admin purposes, on her iOS device, upon which she had Covve installed) -- thread here https://twitter.com/angelalgibson/status/1261314415829237761

Covve has actually made a post and confirmed it was indeed their server that was breached: https://covve.com/opinion/security-incident/

Re: The unattributable “db8151dd” data breach

#153

Hi all, Alex here, CTO at Covve. Just got alerted of incident db8151dd in . We’re investigating as top priority with our security experts what relation this may have with Covve. We are monitoring the feedback in this blog and would really appreciate any additional information you may have on this as we investigate (alex@covve.com).

You stupid fucks should be sued for this. You all should be banned from the business for life. How lame can your employees be if they are unable to secure their working environments. You should all face criminal charges for this fuckup.

Take off the jokes from your website, because it looks pathetic:

"Keeps your data private and safe -Covve has been designed with privacy and security as a priority [yeah, right! the design is way out from the reality] -Your data belongs to you, we never resell or share data. We never expose personal information without your consent. [is this a fucking joke?] -Covve’s platforms are kept up to date with the latest security fixes and using the best practices. [best practices my ass...]"

Re: The unattributable “db8151dd” data breach

#154
post #38

I don't really get the utility of HIBP. The answer to the "have I been pawned?" question is, of course, yes, multiple times. I think about the only way to keep your email out of the hands of the bad guys is to not use it or give it to anyone ever, at which point you don't need an email address. What am I supposed to do whenever I'm involved in a new breach? Burn all my accounts and start again?

For me it's a shortcut to explain why it's always a risk to divulge personal information to 3rd parties, however trustworthy they seem.

Re: The unattributable “db8151dd” data breach

#155
what I can't understand is that I never heard of this covve app neither most of the affected users in the comment section on reddit or troy website or even here as no one thought of it , and my email does exist on the breach, also the data seem to be huge (103,150,616 rows/90GB)for an app that have about 100k install, need some explanations here.
Post reply on HN