Live data from Hacker News

The 773M Record “Collection #1” Data Breach

troyhunt.com

81–90 of 128 posts

Re: The 773M Record “Collection #1” Data Breach

#81
Someone from a well-known leak forum is claiming that the "Collection #1" discovered by Troy Hunt is only part #1 of all available collections (there are at least 5, and additional other dumps). He also posted a screenshot of the original sales thread of the owner. The dumps together seem to have a total size of almost 1TB.

Not sure whether it's cool to post any links here.

Re: The 773M Record “Collection #1” Data Breach

#82

Reading this tweet ( https://twitter.com/troyhunt/status/1085095504197779456 ), I've just donated the price of a coffee to Troy ( https://haveibeenpwned.com/Donate ), and you should too. HIBP is quickly becoming a critical piece of the Internet security infrastructure, and Troy should be lauded for undertaking it basically by himself.

I like the service. I just donated, too.

Re: The 773M Record “Collection #1” Data Breach

#84
post #3

This is frankly terrifying and very ironic. Websites put so much effort into tracking every little thing about their users, from where they come from to what they do. Hotjar ( https://hotjar.com ) goes ahead and tracks mouse movements and now we even have crazy f-ed up startups like Peekmap ( https://peekmap.com ) that claim to predict eye gaze without the webcam. And yet they get pwned so easily. So much effort into…

How does Peekmap work? Their website contains no details. I just can't imagine how you can reliably track a users eye gaze without a webcam - is it just some snake oil pretending to solve everything with AI?

I assume they ran experiments with test subjects navigating websites with both eye and mouse movement tracking, and then trained a model to predict eye tracking from the mouse movement.

Re: The 773M Record “Collection #1” Data Breach

#85
post #60

Earlier quoted context omitted.

and receive no meaningful legal consequences. These people should be on the hook for all damage done with this dump, but they won't be, so it doesn't really matter. It's not ironic, it's just business as usual. Collecting data on users should be extremely risky, even if they consent to it's collection.

We are getting there, thanks to the EU. The GDPR directive has teeth, and it /will/ affect all larger US companies as well. Fines of up to 4% of yearly revenue area no joke: https://www.forbes.com/sites/bernardmarr/2018/06/11/gdpr-the...

Have there been any notable cases of actual enforcement GDPR enforcement yet?

Re: The 773M Record “Collection #1” Data Breach

#87

so strange ... i’ve checked again if i was pwned and on the top there is a service i’ve never signed up - Apollo, a sales acceleration platform i’m a simple dev and never subscribed to a sales service ....

I got the same. Anyone here know what is Apollo?

Re: The 773M Record “Collection #1” Data Breach

#88

Reading this tweet ( https://twitter.com/troyhunt/status/1085095504197779456 ), I've just donated the price of a coffee to Troy ( https://haveibeenpwned.com/Donate ), and you should too. HIBP is quickly becoming a critical piece of the Internet security infrastructure, and Troy should be lauded for undertaking it basically by himself.

Please donate big bucks to the guy who loves to show off his wealth on Twitter. Troy surely doesn't miss an opportunity to brag about having a portfolio of properties, a mansion on the gold coast, expensive cars, a jet ski, a boat, etc. I'm sure poor Troy needs your pocket money to pay for an estimated bill which is actually substantially less than what it actually will be.

After that please also donate your hard earned money to Bill Gates. He voluntarily spends 100% of his time being a philanthropist. He also desperately needs some poor people to pay for his coffee.

Re: The 773M Record “Collection #1” Data Breach

#89
post #69

Here's one more record to add: my HN password is my username. Feel free to use this account for anonymous well-intentioned posting.

Heh, plausible deniability ... but with a non-trivial risk of someone else locking you out from your own account.

So far, so good.

Re: The 773M Record “Collection #1” Data Breach

#90
post #46
post #37

Earlier quoted context omitted.

He's suggesting using (the link is from your link): https://haveibeenpwned.com/Passwords Which does upload your password, which I think is an unacceptable risk.

Well it claims to take the first 5 characters of the SHA of the plaintext. But it also pulls untrusted code/CSS from various sites over HTTP. It's far from unclear who controls that code. For instance this wall of code: http://az416426.vo.msecnd.net/scripts/a/ai.0.js A more sane approach would be to just put your passwords in a file, maybe by export from your database manager. Take a sha1 of each password, then submi…

Not trying to be a pedant, but wouldn’t “[...]it’s far from clear[...]” be (more?) correct?

If it’s ‘far from unclear’, it would seem to imply things are rather clear, IMHO.

Post reply on HN