[HN Gopher] HaveIBeenPwned adds yesterday's Facebook breach
___________________________________________________________________
HaveIBeenPwned adds yesterday's Facebook breach
Author : gnabgib
Score : 503 points
Date : 2021-04-04 18:53 UTC (1 days ago)
(HTM) web link (haveibeenpwned.com)
(TXT) w3m dump (haveibeenpwned.com)
| jonplackett wrote:
| In the details it says there are only 2,529,621 compromised
| accounts added?
| mikequinlan wrote:
| There were very few email addresses in the data, and that is
| what HaveIBeenPwned keys on.
| skeletonjelly wrote:
| That was quick! Hopefully he can put up the Ubiquity breach soon
| too
| ascorbic wrote:
| I don't believe that's been leaked. Ubiquiti is still claiming
| that they have no evidence that any data was stolen. While that
| seems improbable, and it seems that's just because they didn't
| have proper logging, it would be harder to maintain if the data
| was available.
| ryanlol wrote:
| "yesterday's Facebook breach"? This data has been on sale for
| many months.
| underlines wrote:
| I want the dump. I don't trust those pwn websites and I hold a
| multi gigabyte large breach dump myself for the last 15 years.
|
| Dumps should be made public, like exploits.
| Gravyness wrote:
| I also wanted the dumps but it seems only big players are
| allowed to "find" these dumps
| linuxdesktopfo wrote:
| Indeed, people assume haveibeenpwned is trustworthy when it
| seems to be a centralised place of valid emails from people
| that care about security and thus might have or control
| something of value?
| celticninja wrote:
| I mean hibp is run by Tory hunt who has a good record as
| security researcher. So yes it's a centralised place but all
| it does is aggregate breaches and makes them searchable (to a
| degree, and not in a way that is useful for nefarious users).
| The breaches are not shared but those breaches are out there
| and nefarious users don't need hibp to get access to this
| data. It is really only useful to end users who want to see
| if they are at risk.
| elwell wrote:
| > haveibeenpwned is trustworthy
|
| It's not _that_ hard to trust their honesty, the real
| question is will haveibeenpwned get pwned itself?
| ryankrage77 wrote:
| Given that Troy is quite knowledgeable about how breaches
| happen, if HIBP _does_ get breached, it will likely be due
| to targeted hacking rather than negligence.
| underlines wrote:
| found it a minute later on btdb. The data is really not
| interesting. It's like a 2021 version of a phonebook, that was
| common when I was younger. Where it becomes a slight bit
| dangerous, is that names and sometimes birthdates and emails
| are linked to it.
|
| username and SHA/MD5 password dumps are more interesting to
| analyze though.
| koheripbal wrote:
| While I do see the Facebook data here... I don't see other
| leaks.
|
| Have you found other leaks on btdb eu previously?
| antpls wrote:
| How do you know it is the full data, and some of it was not
| removed ?
| techrat wrote:
| It's hard to say definitively how old this data is due to this
| being a partial breach, but at one time I had two separate login
| email addresses for facebook.
|
| Email address A was a gmail address and is a single dictionary
| word. I moved away from it as a login email due to the tendency
| of people to blindly spam it and it being used as a throwaway
| email address when people sign up for accounts. At this point
| I've had to purge a half dozen accounts people created on
| Facebook using my gmail address. The most recent one was created
| 4 months ago. Due to a rapid succession of logins (South Africa
| and United States) geometrically far apart, it was flagged and
| disabled.
|
| I started using a different email address for my Facebook login a
| little less than 2 years ago. It is a custom domain name.
|
| Neither showed up in the Have I Been Pwned lookup tool under this
| Facebook breech.
| akarma wrote:
| The creator of HaveIBeenPwned clarified on Twitter that there's
| no plans to add "search by phone number," so odds are that, if
| your data is in this leak, you won't see it through
| HaveIBeenPwned.
|
| >500m Facebook records were leaked and <10m records have an email
| address -- far more records are phone number but no email.
|
| [1] https://twitter.com/troyhunt/status/1378463581604220931
| Black101 wrote:
| How easy would it be to implement a new field? very.
| stjohnswarts wrote:
| Is there a problem with searching by email to confirm you're in
| the breach? It seemed to work for me.
| thamer wrote:
| Indeed I found my name and phone number in the new Facebook
| leak, but my email address wasn't listed.
|
| I would recommend people check for themselves.
| geoduck14 wrote:
| How do you search by name?
| thamer wrote:
| Not saying I did this, but in theory you could download the
| data from one of the links in this thread and grep for your
| name: https://news.ycombinator.com/item?id=26682774
| kace91 wrote:
| Is there any (legal) way to see the leak? or at least to know
| if your data is among the leaked set?
|
| No interest in seeing other people's info, but I want to know
| if I'm affected.
| Black101 wrote:
| is it illegal to download a leak? I don't think so which is
| why I downloaded many of them.
| 3np wrote:
| Depends on your jurisdiction. Might be legal, might be a
| jailable offense.
| faeyanpiraat wrote:
| How can I check?
| Black101 wrote:
| You can't check... just wait and see if they put you in
| jail.
|
| Unless you hire an attorney that knows these laws...
| because not even attorneys can know all laws.
| vorpalhex wrote:
| It's floating around in the usual places, including
| bittorrent.
| tacker2000 wrote:
| Search telegram for fbleaks
| helloworld11 wrote:
| how does one search telegram? Isn't it just a person to
| person messaging app?
| CompuHacker wrote:
| I had a similar confusion; apparently you can form long-
| running, multi-thousand user, searchable chat rooms.
| denysvitali wrote:
| They're called channels (when it's X to many), or super
| groups (when you have more than N people talking with
| each other).
| nhumrich wrote:
| On the flip side, this data is already public. (its a leak).
| And by HIBP exposing it, the cost of selling this data goes
| down, playing the long game to help us. By HIBP locking down
| this data, you get a false sense of security. (it _is_ still
| public info, just only in sketchier places), and there
| becomes a higher market for selling it.
| Natsu wrote:
| I found it on some sketchy download site that I had to use
| jdownloader for and solve many captchas based on a tip from a
| past HN story.
|
| After that, you'll find that the data is poorly and
| inconsistently encoded (lots of ugly BOMs), a bunch of files
| are split in weird ways (that I had to concatenate then give
| sensible names to). Figuring out what order they go in
| (they're not all split on a record boundary!) may take some
| translation, too. After that, a bunch of them have bad,
| broken CVS headers and you have to find something that can
| manage huge files to edit the first couple of lines.
|
| Then you find that all of them use different delimiters
| (colon or comma), some of them quote each entry, and they
| each have a different set of data that doesn't match up at
| all. I'm still trying to figure out what the data in each
| file is and see if it can be normalized into one schema.
|
| So it's about like downloading a phonebook for half the world
| with some extra mystery data that has no description where
| you have to guess what it even means.
|
| Interestingly, I checked for a family member who deleted
| their FB a few years ago and they're not in there. It'd be
| interesting to see if there are any accounts that deleted
| before 2019 in the data or not. I suspect not, but this isn't
| enough of a test to prove it.
| beowulfey wrote:
| really? i only checked one of the country zips but it was 6
| colon-delimited txt files that were easy to grep to see if
| any numbers i knew were in there
| Natsu wrote:
| They're all over the place. There are several dozen
| files, each named after a country. Some contain a single
| text file that's normal, others have different
| delimiters, encodings and other nonsense. The last record
| of some of the split files is split across files, etc.
|
| This is not particularly high quality data, I'm sure a
| lot of people didn't look at the data very much and just
| ignored a few lines of errors on import or did simple
| greps as you say because it's a pain in the rear to find
| editors that even can handle multi-GB files, etc. Even
| good converters like iconv can bomb out on, I think it
| was Qatar (which was also little endian UTF-16 with a
| BOM), etc.
|
| But yes, it's all over the place. I love how one of them
| decided to number things 1, 2, III, 4, though maybe that
| was the translator, I dunno, I never learned to read
| Arabic letters...
| wyldfire wrote:
| Does anyone...that you might know of...have the tidied-
| up/demultiplexed/transmogrified version of the dump
| available?
| Natsu wrote:
| I haven't seen one or it would've saved me a ton of
| trouble. I think it might be quite a while before I
| finish putting this into an sqlite database given all the
| schema nonsense and the weekend being almost over now.
| Natsu wrote:
| There seems to be a lot of data that includes the
| delimiters in what's supposed to be data, just to make it
| even more helpful.
|
| Because yeah, let's just store a lot of data with commas
| in a CSV file, that won't make it obnoxious to parse or
| anything...
| 3np wrote:
| I've had my phone number linked to FB since forever and my
| info is not in the leak. Neither is my brother. My mom is,
| though.
| reaperducer wrote:
| I'm not in it, but my cat is. I wonder what kind of spam
| he'll start getting.
| edoceo wrote:
| Can't you search the mentioned site?
|
| There were links to a ufile folder with all the zips on here
| yesterday.
|
| I took a peek, relieved I wasn't in there.
| gruez wrote:
| >There were links to a ufile folder with all the zips on
| here yesterday.
|
| The pastebin with the links got taken down, although
| there's an archive.is mirror of it. The forum where it's
| from also has torrent magnet links.
|
| >I took a peek, relieved I wasn't in there.
|
| AFAIK it was publicly scraped data combined with the
| exploit to get phone numbers[1]. If you didn't have a
| public profile you're probably safe.
|
| [1] https://news.ycombinator.com/item?id=25624982
| saddlerustle wrote:
| Only public profile data was leaked, and your phone number if
| you've enabled looking up your profile by phone number.
| Facebook's privacy checkup flow will walk you through these
| settings: https://www.facebook.com/privacy/checkup
| [deleted]
| Ovah wrote:
| I'm pretty sure everybody was 'opted-in' to this feature by
| default. Afaik I have never actively enabled it and yet I'm
| in the leak. I provided FB my phone number for 2FA
| purposes. I'm dumbfounded if they actually allowed people
| to look up my profile with my 2FA info.
| prostoalex wrote:
| That actually happened
| https://techcrunch.com/2019/03/03/facebook-phone-number-
| look...
| freebuju wrote:
| Every privacy offending feature on FB is 100% by default
| opt-out. This is their ethos. When you gave them your
| number, you gave them a way to not only permanently &
| consistenly identify you but also let others "discover"
| you/r profile aka reason for this leak. Using your number
| as 2FA auth is just a side bonus.
| DaiPlusPlus wrote:
| > Every privacy offending feature on FB is 100% by
| default opt-out
|
| Uh, what?
| DaiPlusPlus wrote:
| To clarify: my reading of the parent posting was that "by
| default opt-out" meaning the user _is_ opted-out by
| default, which is contrary to my understanding privacy-
| eroding features of Facebook are turned-on (i.e.
| "default to opt-in").
| chrisweekly wrote:
| ^ Yeah, this in its own is almost as big a scandal as the
| breach per se. Just what the f.
| ginko wrote:
| Looks like he's considering adding phone number search. There's
| a poll further down in the thread.
| [deleted]
| davidjohnstone wrote:
| I created https://www.thenewseachday.com/facebook-phone-
| numbers-us and https://www.thenewseachday.com/facebook-phone-
| numbers-austra... to check if phone numbers are in the data.
| (The data is split by country and I've made them for the US and
| Australia so far.)
| vxNsr wrote:
| While I appreciate what you did there by allowing search by
| phone number. The home page of that website is terrible, you
| claim to be a website for news but it's really just far left
| propaganda, interspersed with communist agenda items, and a
| smattering of kinda center left articles.
| sn_master wrote:
| In this day and age, "news" and "propaganda" are
| interchangable.
| hh3k0 wrote:
| They always have been. There's no mythical past in which
| the powers that be have not used it for their agenda.
| hh3k0 wrote:
| > The home page of that website is terrible, you claim to
| be a website for news but it's really just far left
| propaganda, interspersed with communist agenda items
|
| Can you provide some examples?
| darcmage wrote:
| The majority of articles are from CNN, NYT and Politco.
| vxNsr wrote:
| Yes and? Anyone who has been paying attention would agree
| that CNN, NYT, and Politico are all far left or center
| left depending on the author of the piece in question.
| I've been watching WH press briefings since Obama and I
| had to stop for a few years of trump just bec of the
| vitriol that was hurled at the press secretary. Suddenly
| under Biden these same reporters have become as docile as
| sheep again despite the same scandals happening daily...
| I wonder why?
| Thorrez wrote:
| I see a post from Glenn Greenwald. I think most would
| consider him right leaning. I also see a post from The
| Dispatch, which Wikipedia describes as "center-right".
| CodeGlitch wrote:
| Anyone who is seen as critical of modern woke ideology is
| labelled "right wing". I read a post on HN the other day
| labelling the current British conservative party as
| "extreme right". These people must live in a Twitter
| bubble or something.
| newnamenewface wrote:
| Glenn Greenwald is right leaning? I disagree with your
| appraisal that most would consider him that. He's highly
| critical of mainstream liberal media which creates the
| sense he must be 'on the other side,' but he's definitely
| a left liberal.
| hnbad wrote:
| I think there's a failure of communication here because
| Americans[0] tend to conflate "liberal" with "left"
| although liberalism is not at all leftist and is far more
| compatible with right-wing ideologies than leftism.
|
| In the most general sense left-wing ideologies are about
| abolishing hierarchies whereas right-wing ideologies are
| about either sustaining or enacting them. The difference
| between liberalism and conservatism is that the former
| promotes hierarchies that follow from property rights and
| the latter infers them from tradition (e.g. God's will or
| "natural order").
|
| Just like anarchists and state communists can have
| leftist infighting it's possible for there to be
| infighting on the right. As the US has literally spent
| decades fighting leftist ideologies, the predominant
| political discourse in the US takes place between
| different flavors of the right.
|
| No major media outlet in the US will promote abolishing
| property ownership or collectivising the means of
| production. When we talk about "leftism" in US media this
| usually refers to socially progressive ideas like public
| healthcare, individualist attitudes to anti-racism,
| LGBTQIA+ rights and so on. While these ideas naturally
| follow from most leftist ideologies, they're not
| addressing the underlying social hierarchies or systemic
| criticism. Case in point: abolishing the police is a
| systemic critique if taken literally, but in the public
| discourse this has been reduced to police reform, which
| is about tweaking the system, not replacing or abolishing
| it.
|
| [0] While this is not unique to the US, I'm focusing on
| the US here because of the original context. There are
| more discussions to be had about how this presents in
| other countries and how the Cold War affected those but
| this is not the time.
| bscphil wrote:
| Great comment.
|
| It might be a good summary to say that Greenwald is
| intensely liberal in his stance on civil rights, so much
| so that he doesn't fit on the American liberal-
| conservative spectrum on this issue. He's willing to
| compromise with both liberals and conservatives to help
| get his message out. His overall stance is not left wing,
| because most of his other views (at least the stuff he
| emphasizes) are more (American) libertarian or
| liberal/conservative, not genuinely left wing.
| Thorrez wrote:
| I guess you're right that "most" was overly strong. But
| reading his twitter I can't help but think of him as
| anything but right leaning.
|
| Just today he's got a tweet about "Russiagate"[1], one
| criticizing "British centrists and liberals"[2], one with
| him being interviewed positively on Fox News[3], two
| criticizing Hunter Biden[4][5], one criticizing "House
| Democrats' HR-1 bill"[6], one criticizing vaccine
| passports[7].
|
| [1]
| https://twitter.com/ggreenwald/status/1378820440995549185
|
| [2]
| https://twitter.com/ggreenwald/status/1378817844490690562
|
| [3]
| https://twitter.com/ggreenwald/status/1378789892638056449
|
| [4]
| https://twitter.com/ggreenwald/status/1378785636325470211
|
| [5]
| https://twitter.com/ggreenwald/status/1378709242425831426
|
| [6]
| https://twitter.com/ggreenwald/status/1378714859957841928
|
| [7]
| https://twitter.com/ggreenwald/status/1378714144556335107
| vxNsr wrote:
| Maybe it says something about the news and your
| perceptions that someone who entirely agrees with the
| progressive social and political agenda is so critical of
| what is currently passing for progressive ideas and
| champions these days.
| Thorrez wrote:
| Sorry, I accidentally posted my comment before I finished
| it. Now I finished it with an edit.
|
| To your point, his tweets seem to be entirely criticizing
| liberals; I don't see him criticizing conservatives. I'm
| not saying criticizing liberals is bad or that he should
| be criticizing conservatives. I'm saying that someone who
| spends all their time criticizing liberals and repeating
| right-leaning talking points is right leaning.
| CodeGlitch wrote:
| You can be critical of your own tribe without being on
| the other side. In fact in some ways it's more effective
| as it can shine a light on the crazies in your own tribe
| so that the moderates are seen as better.
| merricksb wrote:
| Aaron Mate, who made the actual tweet about "Russiagate"
| that Greenwald merely made a passing reply to, is about
| as solid in his traditional left-wing bonafides as anyone
| can be, following in the footsteps of his father Gabor, a
| medical practitioner, researcher and author with a
| decades-long public profile espousing traditional left-
| wing values.
|
| Aaron Mate's skepticism of the Russia narrative is not
| out of any support for Trump whatsoever - he's been
| highly critical of Trump - but is part of a track record
| of earnest investigative reporting about Russia that few
| other western journalists can match. One should never
| forget that as recently as 2012, to consider Russia any
| kind of threat to the US, which the Romney Republican
| campaign did back then, attracted mockery and derision
| from Democrats, and it was only in early 2017, just 4
| years ago, that it suddenly flipped such that expressing
| skepticism about the influence of Russia in US politics
| suddenly became part of "right-leaning talking points".
|
| All Mate is doing is remaining consistent with what has
| been the accepted Democrat/left-wing position for many
| years, right up until Clinton lost the unlosable
| election.
|
| When Mate and Greenwald spend their time "criticizing
| liberals", their criticisms are always focused on the
| modern-day Democrats' track record of becoming too
| entangled with the big-corporate and
| military/intelligence establishment, and in doing so,
| abandoning their supposed left-wing ideals.
|
| Just because some right-wingers criticise the
| Democrats/liberals for the same reason, does not make
| Mate and Greenwald right-leaning; they are simply staying
| true to the left-wing values they've held for decades.
| cycomanic wrote:
| Well Greenwald has been posting some antimigration
| articles messages using language that skims very close to
| hard-right wording. Maybe he doesn't neatly fit into the
| (American) left/right schema, but by now he is mainly
| just a "bad media" propagandist.
|
| Also I can't take anyone seriously who claims to
| criticise mainstream media (almost always the more
| Liberal slanted one), but goes regularly on Tucker
| Carlsson without ever seriously criticising them. To see
| how to properly criticise Fox and Tucker search for the
| leaked interview with rudger bergman.
| merricksb wrote:
| > Greenwald has been posting some antimigration articles
| messages using language that skims very close to hard-
| right wording
|
| That's an inflammatory claim, that needs direct
| quotes/links to be taken seriously. But lest it be
| forgotten that there has long been an acceptance among
| traditional left-wingers (including Bernie until it
| became unacceptable to too many of his followers) of the
| need for some immigration controls in order to protect
| the most vulnerable workers, and historically the loudest
| voices for open borders are Laissez-faire/social-
| Darwinist libertarians, most notably the Kochs.
|
| > Maybe he doesn't neatly fit into the (American)
| left/right schema
|
| I think this is quite false: he fits into the traditional
| left/right spectrum as a bona-fide leftist. It's the
| mainstream Democratic Party that has moved towards
| corporatism and militarism.
|
| > regularly on Tucker Carlsson without ever seriously
| criticising them
|
| What would it change for him to criticize them; to try to
| impress the people who would still hate him anyway?
| Carlson gives him airtime and the opportunity to express
| his position to an audience of people whose minds he
| might be able to change about a few things. Why waste
| that opportunity with token criticism?
| cycomanic wrote:
| >> Greenwald has been posting some antimigration articles
| messages using language that skims very close to hard-
| right wording
|
| >That's an inflammatory claim, that needs direct
| quotes/links to be taken seriously. But lest it be
| forgotten that there has long been an acceptance among
| traditional left-wingers (including Bernie until it
| became unacceptable to too many of his followers) of the
| need for some immigration controls in order to protect
| the most vulnerable workers, and historically the loudest
| voices for open borders are Laissez-faire/social-
| Darwinist libertarians, most notably the Kochs.
|
| Maybe in the context of what counts as left in the US.
| But the socialist left movement was always an
| international movement (I give you three guesses what the
| anthem is called). Regarding some of the Greenwalds
| words:
|
| "Current illegal immigration - whereby unmanageably
| endless hordes of people pour over the border in numbers
| far too large to assimilate, and who consequently have no
| need, motivation or ability to assimilate - renders
| impossible the preservation of any national identity"
| http://glenngreenwald.blogspot.com/2005/12/yelling-
| racist-as...
|
| Calling immigrants "hordes" is quite definitely language
| that is what I consider "hard-right". It dehumanises
| people and tries to instil fear and a violent counter-
| reaction.
|
| >> Maybe he doesn't neatly fit into the (American)
| left/right schema
|
| >I think this is quite false: he fits into the
| traditional left/right spectrum as a bona-fide leftist.
| It's the mainstream Democratic Party that has moved
| towards corporatism and militarism.
|
| The mainstream democratic party was never not corporatist
| and militaristic. There has not been a change. However,
| I'm interested what in your eye's qualifies Greenwald as
| a bona-fide leftist (whatever that means)
|
| >> regularly on Tucker Carlsson without ever seriously
| criticising them
|
| > What would it change for him to criticize them; to try
| to impress the people who would still hate him anyway?
| Carlson gives him airtime and the opportunity to express
| his position to an audience of people whose minds he
| might be able to change about a few things. Why waste
| that opportunity with token criticism?
|
| Funny, he does criticise the NYT and many other media
| outlets though. But you're not wrong, he can express his
| position to an audience, but he's not trying to change
| minds, he actually agrees with much that Tucker Carlson
| says. That means he agrees with the agenda of a
| billionaire who has been using his media to clearly push
| a neocon, hard-right agenda worldwide. Considering that
| Greenwald is somehow building this persona of a media
| critic who points out the "agenda" of mainstream media,
| it is somewhat contradictory to go on those shows without
| a word of criticism and without blinking an eye.
| BlueTemplar wrote:
| The first communist international was mainly about
| antiimmigration.
|
| Were they "hard-right" too ?
| cycomanic wrote:
| That's a pretty bold statement, you have any sources to
| back that up?
|
| The first international was about uniting international
| workers, there are in fact several writings who say that
| the bourgeoisie use nationalism and anti-immigrant
| sentiments to divide the working class.
| supportlocal4h wrote:
| Somebody who spends all day critiquing NBA players is
| probably not a football analyst.
| LocalH wrote:
| Do you realize that left/right in the US are pretty much
| right/far-right to the rest of the world?
| vxNsr wrote:
| As others have said, you're so enmeshed in "progressive"
| dogma that you can't even recognize true liberal ideas.
| Greenwald is as liberal as they come the fact that the
| democrat party has become so fascist while pretending to
| be liberal and progressive doesn't mean he's changed.
| They have and he's refusing to toe the party line for
| them.
|
| All your examples are him sticking to true liberalism
| while the ideas he criticizes are extremist autocratic
| ideology that wouldn't be out of place in 1935 Italy.
|
| I say this as someone who vehemently disagrees with much
| of both glens ideology and the insanity that is the
| Democrat party platform.
|
| To go line by line on your points:
|
| 1) I'm not sure what you're trying to prove here but as
| others have said glen is sticking to what has always been
| liberal Americans stance on Russia, it's a non-issue.
|
| 2) not sure about this one bec I don't have any knowledge
| of UK politics
|
| 3-5) Hunter Biden is a real story and just bec it hurts
| the DNC candidate should t prevent reporters from talking
| about it. The fact that so many have decided to put their
| head in the sand is worrying. But Greenwald has never
| shied away from exposing the dirty underbelly of the
| elites. The fact that this time it exposes Biden to
| corruption claims shouldn't stop the sorry from coming to
| light.
|
| 6) Criticizing a DNC bill doesn't make a you national
| socialist workers' party member. It makes you a thinking
| person. If you can't criticize a bad bill bec of who
| sponsored it you've got big problems.
|
| 7) see above. He's highlighting problems that a normal
| progressive person would have, just bec you don't like
| it... that just means you're less progressive than you
| thought, doesn't make him a fascist.
| [deleted]
| exikyut wrote:
| Serious question: the initial leak misspelt "Austria" as
| "Austriaia", and chaos has ensued... the initial forum leak
| along with all ufile references and telegram groups I've been
| able to find all seem to have this "bug".
|
| So I'm very interested about any insight you may have.
| davidjohnstone wrote:
| I don't have much insight on this. I accidentally
| downloaded that one first when I meant to download the
| Australian one, but quickly realised my mistake because the
| CSV file inside the archive was correctly spelt. Then I got
| the actual Australian one.
| arnaudsm wrote:
| I'm working on exactly that, using k-anonymity too. I expect to
| release my tool within 24h
| hugoromano wrote:
| where should we go for your tool?
| arnaudsm wrote:
| It's now live on https://fbleak.info/, and it's open-source
| !
| 1vuio0pswjnm7 wrote:
| This is a easy way to collect phone numbers of concerned
| Facebook users.
|
| Facebook then allows the person collecting phone numbers to
| search for the name of the user associated with a phone
| number (or email address).
|
| https://mbasic.facebook.com/login/identify/?ctx=recover
| technion wrote:
| I believe this has been limited more recently. I just put
| my number in there and it just says that I can click OK to
| text myself a password reset, but didn't leak any details
| on screen.
| LilBytes wrote:
| Looking forward to the Show HN. Keep us posted.
| arnaudsm wrote:
| The Website is now live at https://fbleak.info/ !
|
| Discussion here:
| https://news.ycombinator.com/item?id=26702473
| usr1106 wrote:
| US only :(
| sagarm wrote:
| How could a tool that checks for a specific phone number be
| k-anonymous?
| Godel_unicode wrote:
| It can't. Or at least, not while remaining useful for the
| haveibeenpwned use case.
|
| It's also an interesting choice for a search tool for a
| quasi-public dataset.
| GoblinSlayer wrote:
| In the same way as for passwords.
| nikisweeting wrote:
| Nah because you can iterate through all phone numbers
| pretty quickly.
| fX0rObfoMN4 wrote:
| Phone numbers are only 10 digits. That is only 10 billion
| combinations. For SHA1 which pwned passwords uses that it
| should only take a couple seconds on a decent system.
| Even with SHA256 it could be done in like a minute.
| arnaudsm wrote:
| By using partial sha256 hashes + padding, and doing the
| checking locally
| hnbad wrote:
| Given that this may include data about EU residents and the GDPR
| has strict rules about data breaches and may even impose fines in
| cases of negligence I wonder if anything will come from this.
| Panini_Jones wrote:
| Was there a new breach yesterday or is this the 2019 one?
| dgellow wrote:
| If you click on the link you will see the description.
|
| > Breach date: 1 August 2019
|
| > Date added to HIBP: 4 April 2021
| andix wrote:
| In this leak every entry has a phone number and a name. But only
| a few have an email address connected.
|
| So it would be nice to have a service where you put in a phone
| number and it will list what information is available for it.
| Like this: [X] Phone Number [X] Name
| [X] Current location [ ] Previous location [ ]
| Current employer [ ] Email address [X] Birthday
| [ ] Full date of birth (with year)
| teekert wrote:
| I wonder if this includes WhatsApp data and in what form. It
| would give me some extra ammo to get people to switch to Signal
| ;)
| dillondoyle wrote:
| Not that I can tell
|
| The cols (ive only loaded the US version) seem to be cell_phone
| | fb_id | first_name | last_name | gender | lives | from |
| releationship_status? | works_at | ?some year month maybe date
| sms was given | email | bday?
| intricatedetail wrote:
| Did they acted on this like GDPR requires them to? Who should be
| reporting it?
| [deleted]
| pvorb wrote:
| One thing that really keeps annoying me about HaveIBeenPwned is
| the fact that I can enter anyone's email and get their status
| immediately. This way I can anonymously check if that email had
| an account at a breached site at the time of the breach. The
| obvious solution would be sending out a link via email before
| results can be looked up, but this might not be in
| HaveIBeenPwned's interest.
| tgsovlerkhgsel wrote:
| On the other hand, that means I don't have to do an annoying
| verification dance to look up my pwnages, and can help others
| look up their breach information without having to explain to
| them over the phone how to click a link in an e-mail.
| rkagerer wrote:
| Some kind of "prove it's you" function would be great.
|
| When you register for notifications it sends out a verification
| email. That would be a good time to let you disable public
| lookup of your email address.
|
| I also wish HIBP could securely disclose the snippet of
| information from a leak that's relevant to you. Knowing the
| password or hash characteristics, phone number, etc. could aid
| in mitigation, and seeing the raw impact might help motivate
| ordinary users to improve their security hygiene.
|
| Suggested that idea to Troy in the past, and got the impression
| he's not amenable, largely due to the risks of hosting PII.
| Can't really blame him.
| unholiness wrote:
| > That would be a good time to let you disable public lookup
| of your email address.
|
| https://haveibeenpwned.com/OptOut
| globular-toast wrote:
| The point of hibp is this information is now public. Putting it
| behind some kind of identity check would be security by
| obscurity. The bad guys have the raw data and can look up any
| address at will.
| koheripbal wrote:
| Public isn't "binary". Finding the leaked files, downloading
| them (often paying to do so), aggregating all the data from
| all of them and searching them all is a huge pain-in-the-
| butt.
|
| 99.99% of people would not go through this effort and lack
| the skill/knowledge, even if they were motivated against
| someone.
| globular-toast wrote:
| Maybe not, but the people you need to worry about would.
| CGamesPlay wrote:
| This isn't universally true, the site does have a notion of
| "sensitive breaches" which will not be visible to someone who
| cannot confirm ownership of the email address.
|
| https://haveibeenpwned.com/FAQs#SensitiveBreach
| diarrhea wrote:
| The list of examples reads like my browser bookmarks list.
| pvorb wrote:
| I didn't know about this, thanks. So it's already
| implemented. I'd just prefer if every breach was marked as
| sensitive.
| tjpnz wrote:
| It's possible to opt out. But that does require knowing HIBP
| exists.
| sneak wrote:
| It's not HIBP that caused that data leak. The fact of which
| emails have accounts on which sites is public following the
| breach/leak of that site's data.
| Rebelgecko wrote:
| Even though HIBP didn't cause the data leak, their
| aggregation makes it a lot easier to see which websites
| someone uses.
| sneak wrote:
| This is a good argument for my recommended practice of
| using a different domain/email for login accounts and
| personal correspondence.
|
| My public email address is not the one I use for logins
| anywhere.
| pvorb wrote:
| Yes, but you'd actually have to look for or even buy the
| leaks themselves in order to find out if somebody has been
| "pwned". I'm not arguing against the service in general, but
| there's an obvious way to improve privacy.
| techrat wrote:
| The lookup doesn't tell you anything more than someone
| exists in a breech. You'd still have to have the data
| itself.
|
| If you have the data itself, then lookup is as simple as
| 'grep' or 'ctrl-f'
|
| So anyone who has the means to compromise someone they're
| looking up by having the data doesn't need the
| HaveIBeenPwned tool in the first place.
|
| Moot point, IMHO.
| 55555 wrote:
| what if I use HIBP to check if any of my friends had
| registered accounts on a Furry Findom forum, which was
| recently breached? It's potentially embarrassing.
| MrGilbert wrote:
| This breach would be marked as "sensitive", so you
| wouldn't be able to look that up without confirmation of
| ownership.
| unholiness wrote:
| You can't, because that specific breach has been marked
| as sensitive:
| https://haveibeenpwned.com/FAQs#SensitiveBreach
| techrat wrote:
| I'd argue reasonably smart people would use a different,
| non distributed/shared email address for sensitive things
| like fetish sites...
|
| ...and that your friends deserve a better friend than
| someone who would look up their email addresses to
| embarrass them.
| zamadatix wrote:
| It seems a bit like the FBI warning at the beginning of
| DVDs, the only people that are going to be bothered by it
| are people that were going to play by the rules in the
| first place. The privacy was already lost, you can't
| increase it again retroactively.
|
| The ones marked sensitive have more a pattern of "we don't
| want to be caught in a court caste about hosting the info"
| than a pattern of trying to improve privacy in the ways
| this thread is suggesting.
| Abishek_Muthian wrote:
| But only due to HIBP integration in browser's password manager
| many come to know about their account leak even when the
| company which was breached didn't disclose it (as is the case
| in most countries).
|
| There's still a need gap to detect leaked file data online, Say
| after a ransomware attack our files end-up in pastebin[1];
| currently there seems to be no way to know unless manually
| monitoring sites where leaked data is posted or for the
| attacker to themselves let you know.
|
| [1] Added in my profile.
| IshKebab wrote:
| Yes then they could also show the actual data leaked. I'm
| supposedly in 11 breaches that include things like my date of
| birth and physical address. Maybe. But I don't really know.
|
| Did I give a fake DOB. Is it a previous address? Do they
| actually even have an address or is it just NULL for me? HIBP
| won't tell me.
| bottled_poe wrote:
| The percentage of breaches in this database which is "Mongdo DB
| instance exposed to internet without a password"... yikes. Why on
| earth is no password the default?
| xmprt wrote:
| The popularity of MongoDB was a direct result of how simple it
| was to set up.
| Sebguer wrote:
| It's even better, for years the default was no password /and/
| binding on 0.0.0.0.
| TheSpiceIsLife wrote:
| My tin-foil-hat wants to believe it has something to do with
| MongoDB's CIA funding.
|
| https://en.wikipedia.org/wiki/MongoDB_Inc.
|
| PS Hello from the south island
| chx wrote:
| Apply Hanlon's razor instead.
|
| Consider just how "excellent" MongoDB was as a database
| before they bought Wiretiger and made it default. Ahem.
| ttz wrote:
| Kind of a shitpost:
|
| Anyone read the post title as "HaveLBeenPwned", like Havel from
| Dark Souls? Who often pwned you the first time around...
| hathym wrote:
| Tunisia population is 12 millions but there is 39 millions users
| in the breach. very strange!!
| Digit-Al wrote:
| Not that strange at all. A lot of people all over the world
| have multiple email addresses. Myself for instance, I have an
| email address from my telecom provider, I have a Yahoo! email
| address from when I signed up years ago, my Google account has
| about two or three different ways of referring to the email
| address, plus I have my own domain; so I have about five
| different personal email addresses, plus my work email address.
| SergeAx wrote:
| Interestingly, Russia files are missing huge range of phone
| codes, from +7(910) to +7(929).
|
| There are 3 top mobile operators in Russia: MTS, Beeline and
| Megaphone. Each of them has its own set of phone codes. Majority
| of MTS and better half of Megaphone numbers are not affected, but
| all Beeline codes are exposed.
| joshspankit wrote:
| Interesting agreed.
|
| Have you checked the other entries to see if they are mis-
| categorized?
| I_am_tiberius wrote:
| I just searched myself and found that my "Apollo" information was
| leaked in 2018. I don't know what "Apollo" is though and don't
| think they should have my details. Does anyone know details about
| that leak?
| TechBro8615 wrote:
| It was a company that scraped public LinkedIn profiles and then
| got their database popped.
| I_am_tiberius wrote:
| That means my email address must have been accessible
| publicly.
| TechBro8615 wrote:
| Yeah I'm not sure, they might have scraped other info too
| e.g. GitHub. Frankly I think it's kind of silly to
| categorize this as a "breach" when all the data was
| publicly available. And if you're trying to hide your
| email, you're fighting a losing battle already. Best to
| just assume your email is public knowledge.
| neogodless wrote:
| It's odd because an email I only use on Facebook is in the
| Apollo leak (and the Zynga one due to Words with Friends on
| Facebook.) So does Apollo have information from more than
| just Linkedin?
| underlines wrote:
| public information became public?
| cyberlab wrote:
| How is it legal for HIBP to keep copies of breach corpuses on
| their servers? For me personally, having corpuses on my hard-
| drive is like dealing with radioactive waste. There's so much PII
| to mull over that it feels naughty to sift through. There's even
| people on social media bragging about 'self doxing' their own
| info (just like with using HIBP), but using a local copy instead.
| nathanfig wrote:
| I presume they keep a table mapping email addresses to breaches
| and that's it.
| cyberlab wrote:
| Yes but how is it legal to have multiple corpuses sitting on
| a gigantic server? Surely governments or even a LEA would
| want to regulate that? Having all that PII is like hoarding a
| bunch of radioactive waste.
| wan23 wrote:
| They don't need to keep the data around longer than it
| takes to extract the affected email addresses, and that
| doesn't need to be done on a server at all.
| philjohn wrote:
| Do they store the full breach there, or is the PII put through
| a one-way hash and that used for matching?
| lifeplusplus wrote:
| how can i access the entire DB?
| koheripbal wrote:
| These sorts of leaks are usually available over torrent from
| any torrent search engine.
| coolspot wrote:
| Use any MySQL client to connect.
|
| Host: db.facebook.com
|
| User: production
|
| Password: password
|
| Please don't change any data!
| underlines wrote:
| wrong! you have to use the postgres driver
| ben509 wrote:
| How the hell did you find out my Facebook password?! Mark
| SUCKERberg is about to get a very angry comment from me!
___________________________________________________________________
(page generated 2021-04-05 23:02 UTC)