Live data from Hacker News

Database leak exposes 3.3M Hello Kitty fans

csoonline.com

21–30 of 57 posts

Re: Database leak exposes 3.3M Hello Kitty fans

#22
post #11

Evening project: union Hello Kitty and Ashley Madison lists. No, some things are better left unknown.

I'm not sure what compels people to download and look at any of these leaks.

There's a real dichotomy between the mostly universal opinion on here that ad tracking is a terrible evil, but downloading and investigating people's private data that was illegally obtained and distributed is okay.

Re: Database leak exposes 3.3M Hello Kitty fans

#23
> unsalted SHA-1 password hashes

Can we please get password storage built in to databases as a dedicated column type already? There are N-to-infinity crappy languages and CMS's out there, but only a handful of databases. It's becoming clear that widespread standard library support for decent password hashing just isn't enough to get people moved over.

Re: Database leak exposes 3.3M Hello Kitty fans

#24
post #23

> unsalted SHA-1 password hashes Can we please get password storage built in to databases as a dedicated column type already? There are N-to-infinity crappy languages and CMS's out there, but only a handful of databases. It's becoming clear that widespread standard library support for decent password hashing just isn't enough to get people moved over.

That is a decent idea I've never heard of before. Have you tried submitting an issue to various database issue trackers?

Re: Database leak exposes 3.3M Hello Kitty fans

#25
post #11

Evening project: union Hello Kitty and Ashley Madison lists. No, some things are better left unknown.

I'm not sure what compels people to download and look at any of these leaks. There's a real dichotomy between the mostly universal opinion on here that ad tracking is a terrible evil, but downloading and investigating people's private data that was illegally obtained and distributed is okay.

> the mostly universal opinion ... downloading and investigating people's private data that was illegally obtained and distributed is okay

[citation needed]

Re: Database leak exposes 3.3M Hello Kitty fans

#26
post #11

Evening project: union Hello Kitty and Ashley Madison lists. No, some things are better left unknown.

I'm not sure what compels people to download and look at any of these leaks. There's a real dichotomy between the mostly universal opinion on here that ad tracking is a terrible evil, but downloading and investigating people's private data that was illegally obtained and distributed is okay.

It's interesting to look at? I don't think most people looking at the leaks are trying to profit (exception of people exploiting people based on the data). Ad systems however, are always looking at the data as a way to increase profits.

Re: Database leak exposes 3.3M Hello Kitty fans

#27
This is the same guy that uncovered the MacKeeper user database as well, which also used MongoDB. From what I've read, he just used Shodan to uncover these instances. This isn't meant to discredit him, but it interesting how we're calling people like this "security researchers".

Re: Database leak exposes 3.3M Hello Kitty fans

#28
post #23

> unsalted SHA-1 password hashes Can we please get password storage built in to databases as a dedicated column type already? There are N-to-infinity crappy languages and CMS's out there, but only a handful of databases. It's becoming clear that widespread standard library support for decent password hashing just isn't enough to get people moved over.

This sounds like such an obviously great idea that I don't know how I haven't heard it before. Can someone who understands how databases are built explain why this isn't an obviously great idea?

Re: Database leak exposes 3.3M Hello Kitty fans

#29
post #27

This is the same guy that uncovered the MacKeeper user database as well, which also used MongoDB. From what I've read, he just used Shodan to uncover these instances. This isn't meant to discredit him, but it interesting how we're calling people like this "security researchers".

I don't know who Vickery is but could he not be a security researcher who uses Shodan?

Re: Database leak exposes 3.3M Hello Kitty fans

#30
post #26

Earlier quoted context omitted.

I'm not sure what compels people to download and look at any of these leaks. There's a real dichotomy between the mostly universal opinion on here that ad tracking is a terrible evil, but downloading and investigating people's private data that was illegally obtained and distributed is okay.

It's interesting to look at? I don't think most people looking at the leaks are trying to profit (exception of people exploiting people based on the data). Ad systems however, are always looking at the data as a way to increase profits.

So violating people's personal privacy is okay if it's interesting to look at? I guess people who put hidden cameras in bathrooms feel the same way as you.
Post reply on HN