Live data from Hacker News

The unattributable “db8151dd” data breach

troyhunt.com

61–70 of 155 posts

Re: The unattributable “db8151dd” data breach

#61
post #57
post #2

For the people that use unique per-merchant e-mail addresses (like someone+amazon@...), could you try some of those aliases on HaveIBeenPwned and see which ones come up in this breach? That might shed some light onto its origin.

I suspect that Troy Hunt would have noticed if there were many emails with "+someservice" in the dump since he can easily dump them all.

Not sure of this, because I assume only a tiny fraction of people does this, and those who do probably aren't consistent. E.g. for Amazon Prime, some might use "+amazon-prime", some "+amazonprime", some "+amazon" etc., so there would be very few overall repetitions even in a large data set.

Re: The unattributable “db8151dd” data breach

#63
post #38

I don't really get the utility of HIBP. The answer to the "have I been pawned?" question is, of course, yes, multiple times. I think about the only way to keep your email out of the hands of the bad guys is to not use it or give it to anyone ever, at which point you don't need an email address. What am I supposed to do whenever I'm involved in a new breach? Burn all my accounts and start again?

It depends how many emails do you keep. If you get a hit it’s a good idea to ensure that you keep control of the services related to that address (change passwords, set any extra security measures).

I mostly use it through 1Password, because it also notifies you when a service has enabled new security features like 2FA.

Re: The unattributable “db8151dd” data breach

#64

Earlier quoted context omitted.

I am listed, but it's an address that was never used to register or subscribe to anything online. It's also under a year old. It must've been vacuumed up from other people's contact or email data.

Or from the email provider, if it's not your own server. I know that e.g. GMX has had a leak at some point (or sold data), as an email I created there ages ago was used in phishing. Okay, that's lame, but they've also used the fake name I had given to GMX, spelled perfectly. I've never used that name anywhere when signing up, so it must come from the database.

I use a private email server.

Re: The unattributable “db8151dd” data breach

#65
post #27

Could it be Google+? 3 of 3 my Gmail addresses associated with their profile in some way were on it. Two of it I might have used to register a domain, but the last one I used for G+ and one other website only and none of any friends know this. Also I'm not in US or have US background, can't be from American friends' phones or retailer CRM.

This seems like a winner to me. Iterating a graph along some association explains the ordering mentioned in the blog post, and explains the breadth of connectivity.

Re: The unattributable “db8151dd” data breach

#66
post #62
post #58

Does elasticsearch have no authentication by default like mongodb or did someone deliberately make it public?

Fixed now, but this was a common sequence of events at one time: https://discuss.elastic.co/t/ransom-attack-on-elasticsearch-...

My god, it looks even worse than no security by default. It gives you a false sense of security then unlocks in your back when you are not watching.

Re: The unattributable “db8151dd” data breach

#67
post #30

> Why load it at all? Because every single time I ask about whether I should add data from an unattributable source, the answer is an overwhelming "yes" To be fair, you’re asking your followers on twitter. That’s as biased as you can have, I would be really surprised if the majority would say no.

This is a positive bias IMO, and any negative reactions that bubble up in the replies are going to be more useful.

Re: The unattributable “db8151dd” data breach

#68
Hi all, Alex here, CTO at Covve. Just got alerted of incident db8151dd in . We’re investigating as top priority with our security experts what relation this may have with Covve. We are monitoring the feedback in this blog and would really appreciate any additional information you may have on this as we investigate (alex@covve.com).

Re: The unattributable “db8151dd” data breach

#69
post #38

I don't really get the utility of HIBP. The answer to the "have I been pawned?" question is, of course, yes, multiple times. I think about the only way to keep your email out of the hands of the bad guys is to not use it or give it to anyone ever, at which point you don't need an email address. What am I supposed to do whenever I'm involved in a new breach? Burn all my accounts and start again?

Check account recovery procedures, change password for that website, check login history and active sessions, see if anyone had done anything that could be done through that credentials, on top of using random generated passwords in the first place.

And I think you’re about to describe Sign In with Apple.

Re: The unattributable “db8151dd” data breach

#70
post #38

I don't really get the utility of HIBP. The answer to the "have I been pawned?" question is, of course, yes, multiple times. I think about the only way to keep your email out of the hands of the bad guys is to not use it or give it to anyone ever, at which point you don't need an email address. What am I supposed to do whenever I'm involved in a new breach? Burn all my accounts and start again?

As the other comment also said, it's a public education service.

Remember that most of us on here have extremely advanced knowledge of the Internet and its workings. This is not the case for the vast majority of Internet users.

Post reply on HN