Live data from Hacker News

Sega Europe suffers major security breach

vpnoverview.com

91–100 of 108 posts

Re: Sega Europe suffers major security breach

#91
post #90
post #86

Earlier quoted context omitted.

This sounds similar to justification used by ransomware groups.

Only under the most carelessly superficial analysis. Is there any limit to the vast, systemic negligence and enabled criminality which can be excused away into nothingness because the circumstances under which they were made public were problematic? This isn't a criminal prosecution of the company who was irresponsible with user data. If the people who exposed the negligence screwed up, that doesn't mean we have to a…

Mostly agree. It is unfortunate that the methods used by the messenger add distractions to the situation.

The point I am trying to make is the ends don't absolve the hacker from consequences. Ransomware operators often blame their victims for poor security and frame their actions as security-as-a-service.

Re: Sega Europe suffers major security breach

#92
post #91
post #90

Earlier quoted context omitted.

Only under the most carelessly superficial analysis. Is there any limit to the vast, systemic negligence and enabled criminality which can be excused away into nothingness because the circumstances under which they were made public were problematic? This isn't a criminal prosecution of the company who was irresponsible with user data. If the people who exposed the negligence screwed up, that doesn't mean we have to a…

Mostly agree. It is unfortunate that the methods used by the messenger add distractions to the situation. The point I am trying to make is the ends don't absolve the hacker from consequences. Ransomware operators often blame their victims for poor security and frame their actions as security-as-a-service.

> The point I am trying to make is the ends don't absolve the hacker from consequences.

I agree on this point. I see it as analogous to holding your allies to a standard that your adversaries are unwilling to uphold.

In this case I categorize both black hats and toxic data hoarding companies (including their techie apologist employees) as "adversaries" (though I don't assert you agree with my assessment).

> Ransomware operators often blame their victims for poor security and frame their actions as security-as-a-service.

Despicable victim blaming by the very party doing the victimizing.

I understand why advertising a VPN service can be seen as analogous, even if the scale of profiteering is not comparable.

The argument against toxic data hoarding is easier to make when untainted by exploitative profit motive.

Re: Sega Europe suffers major security breach

#93
post #19

By temporarily defacing the Sega website and modifying files I think they have crossed the line. Enumerating what access they have, rooting through S3 and reporting it is OK, but by messing around like script kiddies they can no longer claim good faith. Publicising that you've illegally defaced the website is a little silly. Of course, Sega should not have got themselves so completely owned. Sega deserved to be punis…

Nah man, don't blame the victim. If I don't lock my door it doesn't mean that I have invited burglars into my home.

Re: Sega Europe suffers major security breach

#94
post #24

Earlier quoted context omitted.

> By temporarily defacing the Sega website I may have missed it but what did they deface? I see a proof of script execution in what appears to be an uploaded file of a random string of letters and numbers .htm address. So if don’t correctly there is a near zero chance of any public user stumbling into the site.

They clearly said they modified careers.sega.co.uk and posted a screenshot of the careers site displaying vpnoverview's logo ( https://vpnoverview.com/wp-content/uploads/screenshot-about-... )

It's been taken down, but still available through https://web.archive.org/web/20211230160444/https://vpnovervi...

Re: Sega Europe suffers major security breach

#95
post #44
post #31

Earlier quoted context omitted.

>Sega deserved to be punished I don't understand this way of thinking. They made a serious security oversight, but that doesn't mean that they deserve to have their website defaced.

> Sega deserved to be punished, but these VPN twits have clearly committed a crime I think the rest of the sentence makes it clear the author didn't intend to support defacement as punishment.

Sure, but I'm saying that they don't deserve to be punished at all.

Re: Sega Europe suffers major security breach

#96

Earlier quoted context omitted.

If the third party has their own IAM users, you can create a cross-account trust relationship where you allow their IAM entity to assume a (scoped-down) role in your account. Then they are able to retrieve temporary credentials to assume this role.

One reason people don't like doing this is that by assuming this role you lose all the privileges in your own account. It's not something you can't overcome (e.g. by using separate credential chains in different parts of the app), but people are lazy.

You don't 'lose' anything, you gain a second set of creds that have an independent lifecycle. The only time this is awkward is if you're using the web console b/c you need to keep going through the assume role/return links.

Re: Sega Europe suffers major security breach

#97
post #19

By temporarily defacing the Sega website and modifying files I think they have crossed the line. Enumerating what access they have, rooting through S3 and reporting it is OK, but by messing around like script kiddies they can no longer claim good faith. Publicising that you've illegally defaced the website is a little silly. Of course, Sega should not have got themselves so completely owned. Sega deserved to be punis…

it seems like there's a couple of hundred consumer-facing VPN service providers, all with slick looking marketing websites to sell you a $5/mo service. lots of them are nothing more than 1 or 2 people and some rented 1U servers or dedicated servers somewhere on whatever ISP that can find with cheap IP transit / DIA rates. maybe a part time website design/graphic arts person they found via fiverr to make things look c…

> often with something like a corporate entity that exists in cyprus, panama or even weirder places.

Wait? How is Cyprus supposed to be a weird place to incorporate?

I suppose Delaware is weird too? It’s not like anyone is actually based there.

>looking at this in terms of the risk that a VPN provider presents to an ISP's reputation, IP space

None, because you obviously make the VPN provider bring their own IPs. And even if you don’t? Just block email and the IP reputation issue is solved.

>attracting unusual volumes and numbers of DDoS, etc..

This has calmed down so so much over the past years.

> fail to do that at your own risk.

Not much risk at all as long as you make them prepay their bills. Nobody is getting depeered because they offered colo to a sketchy VPN provider.

Literally nothing can happen, the big ISPs do not give a single fuck about this.

(I don’t have any involvement with VPN nonsense, but do have extensive experience with “bulletproof” hosting)

Re: Sega Europe suffers major security breach

#98

Earlier quoted context omitted.

Tangential to the thread, but I've never understood what people mean when they say this. Do you run all your personal traffic through a VPS or something? That's not really offering the same thing as most VPN's. It hides your traffic from your ISP so they can't sell your data and snoop on you, but doesn't accomplish some of the anonymizing that an actual multi-user VPN can provide by adding additional traffic under th…

One of the VMs that I have on a system in colocation is my own customized OpenVPN setup, where I also run the openssl CA for it. My phone, laptop, etc all have their own keys. It's set up for my own needs when I want to use a VPN from a weird place. Or simply to bypass artificial restrictions on traffic if I'm on amenity wifi in somebody's office, airport, hotel, etc. Since I can arbitrarily reconfigure it at will, a…

Thanks for responding, that sounds cool! I have contemplated a similar setup myself.

Re: Sega Europe suffers major security breach

#99

Earlier quoted context omitted.

Tangential to the thread, but I've never understood what people mean when they say this. Do you run all your personal traffic through a VPS or something? That's not really offering the same thing as most VPN's. It hides your traffic from your ISP so they can't sell your data and snoop on you, but doesn't accomplish some of the anonymizing that an actual multi-user VPN can provide by adding additional traffic under th…

One of the VMs that I have on a system in colocation is my own customized OpenVPN setup, where I also run the openssl CA for it. My phone, laptop, etc all have their own keys. It's set up for my own needs when I want to use a VPN from a weird place. Or simply to bypass artificial restrictions on traffic if I'm on amenity wifi in somebody's office, airport, hotel, etc. Since I can arbitrarily reconfigure it at will, a…

> thread about sec

> OpenVPN

Re: Sega Europe suffers major security breach

#100
post #27

Earlier quoted context omitted.

Not sure why my comment got downvoted, but it very much feels like HN is defending this kind of behavior. This is why we can’t have nice things.

You can't have nice things because you aggressively criminalized the white hats, thus were never warned by them before a black hat took your nice things away. > Why should I believe that you have not installed a rootkit or other tech that you did not subsequently disclose? Because doing that and also disclosing your identity would be incredibly stupid?

Honeypots etc make this absolutely true.
Post reply on HN