Live data from Hacker News

The unattributable “db8151dd” data breach

troyhunt.com

81–90 of 155 posts

Re: The unattributable “db8151dd” data breach

#81
post #57

Earlier quoted context omitted.

I suspect that Troy Hunt would have noticed if there were many emails with "+someservice" in the dump since he can easily dump them all.

Not sure of this, because I assume only a tiny fraction of people does this, and those who do probably aren't consistent. E.g. for Amazon Prime, some might use "+amazon-prime", some "+amazonprime", some "+amazon" etc., so there would be very few overall repetitions even in a large data set.

Right but grepping for "+" in emails is also high on the list of things I'd do to identify an unknown information dump. Given that he's used to dealing with those I'd be surprised if he hadn't thought of that, although it probably doesn't hurt asking him if he did try it.

Re: The unattributable “db8151dd” data breach

#83
Troy's fighting the good fight, but it's so freaking depressing. If he has hundreds of millions of records worth of personal data from just the breaches that have been shared with him, what _else_ is out there in the hands of criminals and corporations, neither of which have the public interest at heart—only naked self interest in exploiting members of the public for as much money as they can get?

Re: The unattributable “db8151dd” data breach

#84

Earlier quoted context omitted.

Thanks for saving me a click. No desire to play "guess how many minutes I'll have to spend clicking sidewalks" today.

If it takes you minutes to solve a recaptcha your problem might not be the recaptcha...

It might just be that you use Firefox.

Seems anybody who doesn't use Chrome is automatically flagged even if you are logged in with a >12 years old gmail account that is linked to paid storage.

Re: The unattributable “db8151dd” data breach

#85

Based on a large (over 50 results) domain search for a company I work for, the data I found was very old, circa 2014. I know this because almost everyone in the domain search stopped working for the company on or after 2014. Everyone else has worked at the company since 2013 or earlier.

The email notification doesnt list the emails impacted. Do you need to rerun the full report to get the details?

If you run the domain report manually on the HIBP website you get the actual email addresses involved.

Re: The unattributable “db8151dd” data breach

#86

Based on a large (over 50 results) domain search for a company I work for, the data I found was very old, circa 2014. I know this because almost everyone in the domain search stopped working for the company on or after 2014. Everyone else has worked at the company since 2013 or earlier.

Heads up, found at least one match for 2019 from a dataset I'm working with.

Re: The unattributable “db8151dd” data breach

#87
post #54

Dataset for sale: [redacted] Similar data structure: https://stackblitz.com/edit/angular-soswe4?file=src%2Fapp%2F... Owner works for: https://covve.com Covve: This simple yet state-of-the-art app will revolutionise your business relations like you've never seen. Edit: Response: https://twitter.com/covve/status/1261287954967941120

The responses to the comment just below you ( https://news.ycombinator.com/item?id=23190102 ) (and the nature of some of the corporate hits I've seen) seem to be consistent with a contacts database of sorts. Not sure I'd go so far as to accuse a specific company on a public forum. But in this regard, the idea that a contact management app could be behind this DB is plausible.

Adding: this dump appears to be from a source with data at least as recent as April 2019 based on a dataset I'm working with.

Re: The unattributable “db8151dd” data breach

#88

Hi all, Alex here, CTO at Covve. Just got alerted of incident db8151dd in . We’re investigating as top priority with our security experts what relation this may have with Covve. We are monitoring the feedback in this blog and would really appreciate any additional information you may have on this as we investigate (alex@covve.com).

[deleted]

Re: The unattributable “db8151dd” data breach

#89

Hi all, Alex here, CTO at Covve. Just got alerted of incident db8151dd in . We’re investigating as top priority with our security experts what relation this may have with Covve. We are monitoring the feedback in this blog and would really appreciate any additional information you may have on this as we investigate (alex@covve.com).

It appears your organization left an elasticsearch database exposed to the internet. This happens frequently due to poor configuration.

You're either going to have logs pointing to an IP that the individual used to siphon your data, or nothing.

With an exposed elasticsearch database, you possibly had the data being siphoned by many parties, and are only aware now because of this particular incident.

If you have any operations regarding customers in Europe, you need to notify your relevant Data Protection Authority

https://edpb.europa.eu/about-edpb/board/members_en

You should also sign your engineers up for this course:

https://www.elastic.co/training/specializations/elastic-stac...

Re: The unattributable “db8151dd” data breach

#90

Troy's fighting the good fight, but it's so freaking depressing. If he has hundreds of millions of records worth of personal data from just the breaches that have been shared with him, what _else_ is out there in the hands of criminals and corporations, neither of which have the public interest at heart—only naked self interest in exploiting members of the public for as much money as they can get?

> what _else_ is out there in the hands of criminals and corporations

Don't forget governments. Whatever criminals and corporations have that they shouldn't have, governments probably have an order of magnitude more.

Post reply on HN