Live data from Hacker News

Personal and social information of 1.2B people discovered in data leak

dataviper.io

421–430 of 440 posts

Re: Personal and social information of 1.2B people discovered in data leak

#421
post #275

Earlier quoted context omitted.

It has to exist on a private network behind a firewall with ports open to application servers and other es nodes only. Running things on a public ip address is a choice that should not be taken lightly. Clustering over the public internet is not a thing with Elasticsearch (or similar products). If you are running mysql or postgres on a public ip address it would be equally stupid and irresponsible regardless of the u…

Software should be secure by default. Don't blame the user. mySQL in comparison wont even let you install without setting a root password. And it only listen on localhost/unix-socket by default. Then you need to explicitly add another user if you want to allow it to login from a non local ip. I don't think it's even possible - to both set a blank root password and allow it to login from a public IP. So you really thi…

While I don't think blaming labor is constructive or ethical, it seems like most tools pose danger to users in proportion to utility. For example, cars can squish people, electricity can fry people, and power tools can remove limbs.

Typically, people start out using knives and bicycles as children, learn through experience that crashing and getting cut hurt, and carry those lessons forward when they start using tablesaws and cars later in life. How does this apply to elasticsearch? I have no idea.

Re: Personal and social information of 1.2B people discovered in data leak

#422

People data labs's data is pretty accurate. Here is mine: https://api.peopledatalabs.com/v4/person?api_key=9c6a1382204... You can try it for yourself by changing the email. All of the information is public, so I don't mind. They are basically doing data integration.

I don't know how accurate the coordinates of your address in India are, but it's 5 minutes away from me. Small world, huh?

Re: Personal and social information of 1.2B people discovered in data leak

#423
post #263

Earlier quoted context omitted.

Tesonet is true cancer. I am amazed how unethical (and successful) they are. Knowing how quickly it's expanding, do the employees are just as unethical or they do not connect the dots (company got too big)? I hate fb, et al as any other person here, but most of people know that "if it's free - you are the product". Though with NordVPN users are paying money and are getting stabbed in the back.

> NordVPN users are paying money and are getting stabbed in the back. could you please expand on this claim?

From the comment they replied to: https://vpnscam.com/

Re: Personal and social information of 1.2B people discovered in data leak

#424

Earlier quoted context omitted.

Ah... but that is very inconvenient :( I guess comfort comes at a cost. Is there at least a less shady provider if I would like to compromise myself but a bit less than nordvpn? How far do we go in assuming all are bad?

You could set up your own VPN on a server you run.

Yes. This. And is free to setup on big cloud services. Like free 24/7 with whatever amount of data. Guides are online.

Re: Personal and social information of 1.2B people discovered in data leak

#425

Earlier quoted context omitted.

Would it be better if this was a paid service? If the issue access to the data, then maybe we should ask if this data should be collected in the first place.

> If the issue access to the data, then maybe we should ask if this data should be collected in the first place. Outlawing the collection of data would be hard and is unlikely to work, but the fact that companies like AT&T are allowed to sell your data, as they did with OP's (where else would that unused phone number come from), is an angle new legislation can use. The EU now already has a piece of legislation aimed…

I was recently told how private detectives from a national agency would actually go door-to-door (over a minimal area) under the pretext of AT&T store / sales employees. They’d try to convince their target (and some incidental neighbors as cover) to switch their bundled services to AT&T.

The private agents were armed with the latest available discounts (which you could find for yourself if you tried). But their skills made them particularly more successful than a typical front-line sales employee.

The catch? It wasn’t a scam, and they really were trying to get their targets to switch. It seems that AT&T was more willing to sell consumer data than the general public is aware of. Converting their targets to AT&T granted their agency access to additional data which they then to passed onto their clients. And the target gets a discount, too. Win-Win-Win? :)

Re: Personal and social information of 1.2B people discovered in data leak

#426

Earlier quoted context omitted.

> At some point you just have to call out people for being utter morons. The blame is on them, 100%. [...] Your attitude is a symptom of a broader issue that plagues this industry: Indifference to risk*probability. If you don't ship software with "secure defaults" (depending on the threat/attack model), you essentially are handing out loaded shotguns, then blaming the "dumb" user when they inevitably point it at thei…

Is it a secondary concern, though? As a startup, uptake is as vital as oxygen

They're not a startup.

Re: Personal and social information of 1.2B people discovered in data leak

#427
post #295

Earlier quoted context omitted.

Surely by making it difficult to cancel they’re really just making it easier for people to get discounts. If I were a Comcast customer I’d be calling up to cancel every few months.

He's dead , he doesn't need discounts.

Obviously. Which is why I used a plural—I was referring to Comcast’s overall customer base.

Re: Personal and social information of 1.2B people discovered in data leak

#428
post #81

Earlier quoted context omitted.

I remember there was some brewhaha a while back about how Shodan was able to discover services on IPv6 since the address space was so sparse. Apparently they were running enough of their own NTP servers to reliably map out lots of devices on IPv6.

Not being able to map ipv6 space is a myth. There's plenty of workarounds.

Such as? Not too familiar with the subject, would love to know how.

Re: Personal and social information of 1.2B people discovered in data leak

#429

Earlier quoted context omitted.

Not being able to map ipv6 space is a myth. There's plenty of workarounds.

Such as? Not too familiar with the subject, would love to know how.

It's pretty old news these days, guessing it's mostly what's leaked out of private to public sector stuff, is probably just the beginning really.

Would suggest starting at arxiv. This is not a hidden field for the active and/or keen researcher.

Re: Personal and social information of 1.2B people discovered in data leak

#430

Earlier quoted context omitted.

One obvious answer in that case would be to establish who is buying the data from them and treat any PDL data as potentially tainted. If you find a downstream customer who does have a presence, then investigate accordingly. You might not be able to fine PDL directly, but you could certainly make the offending data risky or unprofitable...

Sure, but how do you propose doing that? Send another strongly worded letter to PDL demanding their customer list?

Usually you'd either track known errors in the dataset (implying that the companies had either bought it from PDL or copied the leak), or you'd ask the banks (who do have a presence) which accounts were paying them and who owned the accounts. If Bitcoin's involved at all, you assume there's something fishy going on and investigate accordingly.

(Assuming anyone were bothered enough to actually do this, of course.)

Post reply on HN