Earlier quoted context omitted.
I suspect that Troy Hunt would have noticed if there were many emails with "+someservice" in the dump since he can easily dump them all.
Not sure of this, because I assume only a tiny fraction of people does this, and those who do probably aren't consistent. E.g. for Amazon Prime, some might use "+amazon-prime", some "+amazonprime", some "+amazon" etc., so there would be very few overall repetitions even in a large data set.
The unattributable “db8151dd” data breach
81–90 of 155 posts
Re: The unattributable “db8151dd” data breach
#82It’s contact data from iOS and android phones probably scraped via some malware app/apps
Re: The unattributable “db8151dd” data breach
#83Re: The unattributable “db8151dd” data breach
#84Earlier quoted context omitted.
Thanks for saving me a click. No desire to play "guess how many minutes I'll have to spend clicking sidewalks" today.
If it takes you minutes to solve a recaptcha your problem might not be the recaptcha...
Seems anybody who doesn't use Chrome is automatically flagged even if you are logged in with a >12 years old gmail account that is linked to paid storage.
Re: The unattributable “db8151dd” data breach
#85Based on a large (over 50 results) domain search for a company I work for, the data I found was very old, circa 2014. I know this because almost everyone in the domain search stopped working for the company on or after 2014. Everyone else has worked at the company since 2013 or earlier.
The email notification doesnt list the emails impacted. Do you need to rerun the full report to get the details?
Re: The unattributable “db8151dd” data breach
#86Based on a large (over 50 results) domain search for a company I work for, the data I found was very old, circa 2014. I know this because almost everyone in the domain search stopped working for the company on or after 2014. Everyone else has worked at the company since 2013 or earlier.
Re: The unattributable “db8151dd” data breach
#87Dataset for sale: [redacted] Similar data structure: https://stackblitz.com/edit/angular-soswe4?file=src%2Fapp%2F... Owner works for: https://covve.com Covve: This simple yet state-of-the-art app will revolutionise your business relations like you've never seen. Edit: Response: https://twitter.com/covve/status/1261287954967941120
The responses to the comment just below you ( https://news.ycombinator.com/item?id=23190102 ) (and the nature of some of the corporate hits I've seen) seem to be consistent with a contacts database of sorts. Not sure I'd go so far as to accuse a specific company on a public forum. But in this regard, the idea that a contact management app could be behind this DB is plausible.
Re: The unattributable “db8151dd” data breach
#88Hi all, Alex here, CTO at Covve. Just got alerted of incident db8151dd in . We’re investigating as top priority with our security experts what relation this may have with Covve. We are monitoring the feedback in this blog and would really appreciate any additional information you may have on this as we investigate (alex@covve.com).
Re: The unattributable “db8151dd” data breach
#89Hi all, Alex here, CTO at Covve. Just got alerted of incident db8151dd in . We’re investigating as top priority with our security experts what relation this may have with Covve. We are monitoring the feedback in this blog and would really appreciate any additional information you may have on this as we investigate (alex@covve.com).
You're either going to have logs pointing to an IP that the individual used to siphon your data, or nothing.
With an exposed elasticsearch database, you possibly had the data being siphoned by many parties, and are only aware now because of this particular incident.
If you have any operations regarding customers in Europe, you need to notify your relevant Data Protection Authority
https://edpb.europa.eu/about-edpb/board/members_en
You should also sign your engineers up for this course:
https://www.elastic.co/training/specializations/elastic-stac...
Re: The unattributable “db8151dd” data breach
#90Troy's fighting the good fight, but it's so freaking depressing. If he has hundreds of millions of records worth of personal data from just the breaches that have been shared with him, what _else_ is out there in the hands of criminals and corporations, neither of which have the public interest at heart—only naked self interest in exploiting members of the public for as much money as they can get?
Don't forget governments. Whatever criminals and corporations have that they shouldn't have, governments probably have an order of magnitude more.