Earlier quoted context omitted.
I've been using ES off and on since before 1.0 came out. It has always baffled me that ES doesn't require a username and password by default. ES is a database that has to exist on a network to be usable. Heck, it expects that you have multiple nodes, and will complain if you don't. So one of the first things you do is expose it to the network so you can use it. Yes, it takes some serious incompetence to not realize y…
It has to exist on a private network behind a firewall with ports open to application servers and other es nodes only. Running things on a public ip address is a choice that should not be taken lightly. Clustering over the public internet is not a thing with Elasticsearch (or similar products). If you are running mysql or postgres on a public ip address it would be equally stupid and irresponsible regardless of the u…
Personal and social information of 1.2B people discovered in data leak
391–400 of 440 posts
Re: Personal and social information of 1.2B people discovered in data leak
#392Earlier quoted context omitted.
This is ridiculous. Software should be built in the best method of delivering maximum value to its users. A trade-off for usability can be made for certain cases like ease-of-use for new software. Redis was part of this a while ago http://antirez.com/news/96 . Engineers should know their tools before using them. It's a huge part of our jobs. You could introduce a ton of other vulnerabilities in software: XSS, SQL inj…
"Software should be built in the best method of delivering maximum value to its users." Yes, and defaulting to insecure, thus repeatedly causing huge data breaches, is the exact opposite of delivering maximum value to users. It's delivering maximum liability .
Re: Personal and social information of 1.2B people discovered in data leak
#393Earlier quoted context omitted.
My gmail is my first initial followed by my last name. There are other people on this planet with same first initial and last name, some of whom seem to think that must be their email too, because I keep on getting emails where they used it to sign up for things.
I had a lady send me a zip file that contained a VPN client, certificate and a word document with usernames and passwords to the VPN and a number of industrial control systems at the factory she was a manager of. She sent it religiously, every 90 days.
Re: Personal and social information of 1.2B people discovered in data leak
#394Re: Personal and social information of 1.2B people discovered in data leak
#395I just had a look at “my” data on this and it is almost hilariously wrong.
Re: Personal and social information of 1.2B people discovered in data leak
#396Earlier quoted context omitted.
> Out of the box it does not even bind to a public internet address. Bind to all interfaces used to be the default in 1.x - it changed pretty much because people were footgunning themselves. Coupled with lack of security in the base/free distribution, that made for a dangerous pitfall. At least now security is finally part of the free offering, but the OSS version still comes with no access control at all.
You typically use these in pods which share networking but are not available from outside. It doesn't matter then if you bind it to 0.0.0.0.
To add on that: No security also means no TLS, neither in the cluster communication, no TLS speaking to the client etc.
Re: Personal and social information of 1.2B people discovered in data leak
#397Earlier quoted context omitted.
Would it be better if this was a paid service? If the issue access to the data, then maybe we should ask if this data should be collected in the first place.
> If the issue access to the data, then maybe we should ask if this data should be collected in the first place. Outlawing the collection of data would be hard and is unlikely to work, but the fact that companies like AT&T are allowed to sell your data, as they did with OP's (where else would that unused phone number come from), is an angle new legislation can use. The EU now already has a piece of legislation aimed…
Re: Personal and social information of 1.2B people discovered in data leak
#398Re: Personal and social information of 1.2B people discovered in data leak
#399It's a tragedy that all of this data was available to anyone in a public database instead of.... checks notes... available to anyone who was willing to sign up for a free account that allowed them 1,000 queries. It seems like PDL's core business model is irresponsible regarding their stewardship of the data they've harvested.
Disclaimer: I'm one of the creators of yourdigitalrights.org.
Re: Personal and social information of 1.2B people discovered in data leak
#400Earlier quoted context omitted.
OxyData and OxyLabs seem to be sister companies[1]: the former sells data as a product, the latter sells scraping as a service. [1] https://vpnscam.com/wp-content/uploads/2018/08/2018-08-24-09...
Tesonet is true cancer. I am amazed how unethical (and successful) they are. Knowing how quickly it's expanding, do the employees are just as unethical or they do not connect the dots (company got too big)? I hate fb, et al as any other person here, but most of people know that "if it's free - you are the product". Though with NordVPN users are paying money and are getting stabbed in the back.
could you please expand on this claim?