[HN Gopher] HaveIBeenPwned adds yesterday's Facebook breach
       ___________________________________________________________________
        
       HaveIBeenPwned adds yesterday's Facebook breach
        
       Author : gnabgib
       Score  : 503 points
       Date   : 2021-04-04 18:53 UTC (1 days ago)
        
 (HTM) web link (haveibeenpwned.com)
 (TXT) w3m dump (haveibeenpwned.com)
        
       | jonplackett wrote:
       | In the details it says there are only 2,529,621 compromised
       | accounts added?
        
         | mikequinlan wrote:
         | There were very few email addresses in the data, and that is
         | what HaveIBeenPwned keys on.
        
       | skeletonjelly wrote:
       | That was quick! Hopefully he can put up the Ubiquity breach soon
       | too
        
         | ascorbic wrote:
         | I don't believe that's been leaked. Ubiquiti is still claiming
         | that they have no evidence that any data was stolen. While that
         | seems improbable, and it seems that's just because they didn't
         | have proper logging, it would be harder to maintain if the data
         | was available.
        
       | ryanlol wrote:
       | "yesterday's Facebook breach"? This data has been on sale for
       | many months.
        
       | underlines wrote:
       | I want the dump. I don't trust those pwn websites and I hold a
       | multi gigabyte large breach dump myself for the last 15 years.
       | 
       | Dumps should be made public, like exploits.
        
         | Gravyness wrote:
         | I also wanted the dumps but it seems only big players are
         | allowed to "find" these dumps
        
         | linuxdesktopfo wrote:
         | Indeed, people assume haveibeenpwned is trustworthy when it
         | seems to be a centralised place of valid emails from people
         | that care about security and thus might have or control
         | something of value?
        
           | celticninja wrote:
           | I mean hibp is run by Tory hunt who has a good record as
           | security researcher. So yes it's a centralised place but all
           | it does is aggregate breaches and makes them searchable (to a
           | degree, and not in a way that is useful for nefarious users).
           | The breaches are not shared but those breaches are out there
           | and nefarious users don't need hibp to get access to this
           | data. It is really only useful to end users who want to see
           | if they are at risk.
        
           | elwell wrote:
           | > haveibeenpwned is trustworthy
           | 
           | It's not _that_ hard to trust their honesty, the real
           | question is will haveibeenpwned get pwned itself?
        
             | ryankrage77 wrote:
             | Given that Troy is quite knowledgeable about how breaches
             | happen, if HIBP _does_ get breached, it will likely be due
             | to targeted hacking rather than negligence.
        
         | underlines wrote:
         | found it a minute later on btdb. The data is really not
         | interesting. It's like a 2021 version of a phonebook, that was
         | common when I was younger. Where it becomes a slight bit
         | dangerous, is that names and sometimes birthdates and emails
         | are linked to it.
         | 
         | username and SHA/MD5 password dumps are more interesting to
         | analyze though.
        
           | koheripbal wrote:
           | While I do see the Facebook data here... I don't see other
           | leaks.
           | 
           | Have you found other leaks on btdb eu previously?
        
           | antpls wrote:
           | How do you know it is the full data, and some of it was not
           | removed ?
        
       | techrat wrote:
       | It's hard to say definitively how old this data is due to this
       | being a partial breach, but at one time I had two separate login
       | email addresses for facebook.
       | 
       | Email address A was a gmail address and is a single dictionary
       | word. I moved away from it as a login email due to the tendency
       | of people to blindly spam it and it being used as a throwaway
       | email address when people sign up for accounts. At this point
       | I've had to purge a half dozen accounts people created on
       | Facebook using my gmail address. The most recent one was created
       | 4 months ago. Due to a rapid succession of logins (South Africa
       | and United States) geometrically far apart, it was flagged and
       | disabled.
       | 
       | I started using a different email address for my Facebook login a
       | little less than 2 years ago. It is a custom domain name.
       | 
       | Neither showed up in the Have I Been Pwned lookup tool under this
       | Facebook breech.
        
       | akarma wrote:
       | The creator of HaveIBeenPwned clarified on Twitter that there's
       | no plans to add "search by phone number," so odds are that, if
       | your data is in this leak, you won't see it through
       | HaveIBeenPwned.
       | 
       | >500m Facebook records were leaked and <10m records have an email
       | address -- far more records are phone number but no email.
       | 
       | [1] https://twitter.com/troyhunt/status/1378463581604220931
        
         | Black101 wrote:
         | How easy would it be to implement a new field? very.
        
         | stjohnswarts wrote:
         | Is there a problem with searching by email to confirm you're in
         | the breach? It seemed to work for me.
        
         | thamer wrote:
         | Indeed I found my name and phone number in the new Facebook
         | leak, but my email address wasn't listed.
         | 
         | I would recommend people check for themselves.
        
           | geoduck14 wrote:
           | How do you search by name?
        
             | thamer wrote:
             | Not saying I did this, but in theory you could download the
             | data from one of the links in this thread and grep for your
             | name: https://news.ycombinator.com/item?id=26682774
        
         | kace91 wrote:
         | Is there any (legal) way to see the leak? or at least to know
         | if your data is among the leaked set?
         | 
         | No interest in seeing other people's info, but I want to know
         | if I'm affected.
        
           | Black101 wrote:
           | is it illegal to download a leak? I don't think so which is
           | why I downloaded many of them.
        
             | 3np wrote:
             | Depends on your jurisdiction. Might be legal, might be a
             | jailable offense.
        
               | faeyanpiraat wrote:
               | How can I check?
        
               | Black101 wrote:
               | You can't check... just wait and see if they put you in
               | jail.
               | 
               | Unless you hire an attorney that knows these laws...
               | because not even attorneys can know all laws.
        
           | vorpalhex wrote:
           | It's floating around in the usual places, including
           | bittorrent.
        
           | tacker2000 wrote:
           | Search telegram for fbleaks
        
             | helloworld11 wrote:
             | how does one search telegram? Isn't it just a person to
             | person messaging app?
        
               | CompuHacker wrote:
               | I had a similar confusion; apparently you can form long-
               | running, multi-thousand user, searchable chat rooms.
        
               | denysvitali wrote:
               | They're called channels (when it's X to many), or super
               | groups (when you have more than N people talking with
               | each other).
        
           | nhumrich wrote:
           | On the flip side, this data is already public. (its a leak).
           | And by HIBP exposing it, the cost of selling this data goes
           | down, playing the long game to help us. By HIBP locking down
           | this data, you get a false sense of security. (it _is_ still
           | public info, just only in sketchier places), and there
           | becomes a higher market for selling it.
        
           | Natsu wrote:
           | I found it on some sketchy download site that I had to use
           | jdownloader for and solve many captchas based on a tip from a
           | past HN story.
           | 
           | After that, you'll find that the data is poorly and
           | inconsistently encoded (lots of ugly BOMs), a bunch of files
           | are split in weird ways (that I had to concatenate then give
           | sensible names to). Figuring out what order they go in
           | (they're not all split on a record boundary!) may take some
           | translation, too. After that, a bunch of them have bad,
           | broken CVS headers and you have to find something that can
           | manage huge files to edit the first couple of lines.
           | 
           | Then you find that all of them use different delimiters
           | (colon or comma), some of them quote each entry, and they
           | each have a different set of data that doesn't match up at
           | all. I'm still trying to figure out what the data in each
           | file is and see if it can be normalized into one schema.
           | 
           | So it's about like downloading a phonebook for half the world
           | with some extra mystery data that has no description where
           | you have to guess what it even means.
           | 
           | Interestingly, I checked for a family member who deleted
           | their FB a few years ago and they're not in there. It'd be
           | interesting to see if there are any accounts that deleted
           | before 2019 in the data or not. I suspect not, but this isn't
           | enough of a test to prove it.
        
             | beowulfey wrote:
             | really? i only checked one of the country zips but it was 6
             | colon-delimited txt files that were easy to grep to see if
             | any numbers i knew were in there
        
               | Natsu wrote:
               | They're all over the place. There are several dozen
               | files, each named after a country. Some contain a single
               | text file that's normal, others have different
               | delimiters, encodings and other nonsense. The last record
               | of some of the split files is split across files, etc.
               | 
               | This is not particularly high quality data, I'm sure a
               | lot of people didn't look at the data very much and just
               | ignored a few lines of errors on import or did simple
               | greps as you say because it's a pain in the rear to find
               | editors that even can handle multi-GB files, etc. Even
               | good converters like iconv can bomb out on, I think it
               | was Qatar (which was also little endian UTF-16 with a
               | BOM), etc.
               | 
               | But yes, it's all over the place. I love how one of them
               | decided to number things 1, 2, III, 4, though maybe that
               | was the translator, I dunno, I never learned to read
               | Arabic letters...
        
             | wyldfire wrote:
             | Does anyone...that you might know of...have the tidied-
             | up/demultiplexed/transmogrified version of the dump
             | available?
        
               | Natsu wrote:
               | I haven't seen one or it would've saved me a ton of
               | trouble. I think it might be quite a while before I
               | finish putting this into an sqlite database given all the
               | schema nonsense and the weekend being almost over now.
        
               | Natsu wrote:
               | There seems to be a lot of data that includes the
               | delimiters in what's supposed to be data, just to make it
               | even more helpful.
               | 
               | Because yeah, let's just store a lot of data with commas
               | in a CSV file, that won't make it obnoxious to parse or
               | anything...
        
             | 3np wrote:
             | I've had my phone number linked to FB since forever and my
             | info is not in the leak. Neither is my brother. My mom is,
             | though.
        
               | reaperducer wrote:
               | I'm not in it, but my cat is. I wonder what kind of spam
               | he'll start getting.
        
           | edoceo wrote:
           | Can't you search the mentioned site?
           | 
           | There were links to a ufile folder with all the zips on here
           | yesterday.
           | 
           | I took a peek, relieved I wasn't in there.
        
             | gruez wrote:
             | >There were links to a ufile folder with all the zips on
             | here yesterday.
             | 
             | The pastebin with the links got taken down, although
             | there's an archive.is mirror of it. The forum where it's
             | from also has torrent magnet links.
             | 
             | >I took a peek, relieved I wasn't in there.
             | 
             | AFAIK it was publicly scraped data combined with the
             | exploit to get phone numbers[1]. If you didn't have a
             | public profile you're probably safe.
             | 
             | [1] https://news.ycombinator.com/item?id=25624982
        
           | saddlerustle wrote:
           | Only public profile data was leaked, and your phone number if
           | you've enabled looking up your profile by phone number.
           | Facebook's privacy checkup flow will walk you through these
           | settings: https://www.facebook.com/privacy/checkup
        
             | [deleted]
        
             | Ovah wrote:
             | I'm pretty sure everybody was 'opted-in' to this feature by
             | default. Afaik I have never actively enabled it and yet I'm
             | in the leak. I provided FB my phone number for 2FA
             | purposes. I'm dumbfounded if they actually allowed people
             | to look up my profile with my 2FA info.
        
               | prostoalex wrote:
               | That actually happened
               | https://techcrunch.com/2019/03/03/facebook-phone-number-
               | look...
        
               | freebuju wrote:
               | Every privacy offending feature on FB is 100% by default
               | opt-out. This is their ethos. When you gave them your
               | number, you gave them a way to not only permanently &
               | consistenly identify you but also let others "discover"
               | you/r profile aka reason for this leak. Using your number
               | as 2FA auth is just a side bonus.
        
               | DaiPlusPlus wrote:
               | > Every privacy offending feature on FB is 100% by
               | default opt-out
               | 
               | Uh, what?
        
               | DaiPlusPlus wrote:
               | To clarify: my reading of the parent posting was that "by
               | default opt-out" meaning the user _is_ opted-out by
               | default, which is contrary to my understanding privacy-
               | eroding features of Facebook are turned-on (i.e.
               | "default to opt-in").
        
               | chrisweekly wrote:
               | ^ Yeah, this in its own is almost as big a scandal as the
               | breach per se. Just what the f.
        
         | ginko wrote:
         | Looks like he's considering adding phone number search. There's
         | a poll further down in the thread.
        
           | [deleted]
        
         | davidjohnstone wrote:
         | I created https://www.thenewseachday.com/facebook-phone-
         | numbers-us and https://www.thenewseachday.com/facebook-phone-
         | numbers-austra... to check if phone numbers are in the data.
         | (The data is split by country and I've made them for the US and
         | Australia so far.)
        
           | vxNsr wrote:
           | While I appreciate what you did there by allowing search by
           | phone number. The home page of that website is terrible, you
           | claim to be a website for news but it's really just far left
           | propaganda, interspersed with communist agenda items, and a
           | smattering of kinda center left articles.
        
             | sn_master wrote:
             | In this day and age, "news" and "propaganda" are
             | interchangable.
        
               | hh3k0 wrote:
               | They always have been. There's no mythical past in which
               | the powers that be have not used it for their agenda.
        
             | hh3k0 wrote:
             | > The home page of that website is terrible, you claim to
             | be a website for news but it's really just far left
             | propaganda, interspersed with communist agenda items
             | 
             | Can you provide some examples?
        
             | darcmage wrote:
             | The majority of articles are from CNN, NYT and Politco.
        
               | vxNsr wrote:
               | Yes and? Anyone who has been paying attention would agree
               | that CNN, NYT, and Politico are all far left or center
               | left depending on the author of the piece in question.
               | I've been watching WH press briefings since Obama and I
               | had to stop for a few years of trump just bec of the
               | vitriol that was hurled at the press secretary. Suddenly
               | under Biden these same reporters have become as docile as
               | sheep again despite the same scandals happening daily...
               | I wonder why?
        
             | Thorrez wrote:
             | I see a post from Glenn Greenwald. I think most would
             | consider him right leaning. I also see a post from The
             | Dispatch, which Wikipedia describes as "center-right".
        
               | CodeGlitch wrote:
               | Anyone who is seen as critical of modern woke ideology is
               | labelled "right wing". I read a post on HN the other day
               | labelling the current British conservative party as
               | "extreme right". These people must live in a Twitter
               | bubble or something.
        
               | newnamenewface wrote:
               | Glenn Greenwald is right leaning? I disagree with your
               | appraisal that most would consider him that. He's highly
               | critical of mainstream liberal media which creates the
               | sense he must be 'on the other side,' but he's definitely
               | a left liberal.
        
               | hnbad wrote:
               | I think there's a failure of communication here because
               | Americans[0] tend to conflate "liberal" with "left"
               | although liberalism is not at all leftist and is far more
               | compatible with right-wing ideologies than leftism.
               | 
               | In the most general sense left-wing ideologies are about
               | abolishing hierarchies whereas right-wing ideologies are
               | about either sustaining or enacting them. The difference
               | between liberalism and conservatism is that the former
               | promotes hierarchies that follow from property rights and
               | the latter infers them from tradition (e.g. God's will or
               | "natural order").
               | 
               | Just like anarchists and state communists can have
               | leftist infighting it's possible for there to be
               | infighting on the right. As the US has literally spent
               | decades fighting leftist ideologies, the predominant
               | political discourse in the US takes place between
               | different flavors of the right.
               | 
               | No major media outlet in the US will promote abolishing
               | property ownership or collectivising the means of
               | production. When we talk about "leftism" in US media this
               | usually refers to socially progressive ideas like public
               | healthcare, individualist attitudes to anti-racism,
               | LGBTQIA+ rights and so on. While these ideas naturally
               | follow from most leftist ideologies, they're not
               | addressing the underlying social hierarchies or systemic
               | criticism. Case in point: abolishing the police is a
               | systemic critique if taken literally, but in the public
               | discourse this has been reduced to police reform, which
               | is about tweaking the system, not replacing or abolishing
               | it.
               | 
               | [0] While this is not unique to the US, I'm focusing on
               | the US here because of the original context. There are
               | more discussions to be had about how this presents in
               | other countries and how the Cold War affected those but
               | this is not the time.
        
               | bscphil wrote:
               | Great comment.
               | 
               | It might be a good summary to say that Greenwald is
               | intensely liberal in his stance on civil rights, so much
               | so that he doesn't fit on the American liberal-
               | conservative spectrum on this issue. He's willing to
               | compromise with both liberals and conservatives to help
               | get his message out. His overall stance is not left wing,
               | because most of his other views (at least the stuff he
               | emphasizes) are more (American) libertarian or
               | liberal/conservative, not genuinely left wing.
        
               | Thorrez wrote:
               | I guess you're right that "most" was overly strong. But
               | reading his twitter I can't help but think of him as
               | anything but right leaning.
               | 
               | Just today he's got a tweet about "Russiagate"[1], one
               | criticizing "British centrists and liberals"[2], one with
               | him being interviewed positively on Fox News[3], two
               | criticizing Hunter Biden[4][5], one criticizing "House
               | Democrats' HR-1 bill"[6], one criticizing vaccine
               | passports[7].
               | 
               | [1]
               | https://twitter.com/ggreenwald/status/1378820440995549185
               | 
               | [2]
               | https://twitter.com/ggreenwald/status/1378817844490690562
               | 
               | [3]
               | https://twitter.com/ggreenwald/status/1378789892638056449
               | 
               | [4]
               | https://twitter.com/ggreenwald/status/1378785636325470211
               | 
               | [5]
               | https://twitter.com/ggreenwald/status/1378709242425831426
               | 
               | [6]
               | https://twitter.com/ggreenwald/status/1378714859957841928
               | 
               | [7]
               | https://twitter.com/ggreenwald/status/1378714144556335107
        
               | vxNsr wrote:
               | Maybe it says something about the news and your
               | perceptions that someone who entirely agrees with the
               | progressive social and political agenda is so critical of
               | what is currently passing for progressive ideas and
               | champions these days.
        
               | Thorrez wrote:
               | Sorry, I accidentally posted my comment before I finished
               | it. Now I finished it with an edit.
               | 
               | To your point, his tweets seem to be entirely criticizing
               | liberals; I don't see him criticizing conservatives. I'm
               | not saying criticizing liberals is bad or that he should
               | be criticizing conservatives. I'm saying that someone who
               | spends all their time criticizing liberals and repeating
               | right-leaning talking points is right leaning.
        
               | CodeGlitch wrote:
               | You can be critical of your own tribe without being on
               | the other side. In fact in some ways it's more effective
               | as it can shine a light on the crazies in your own tribe
               | so that the moderates are seen as better.
        
               | merricksb wrote:
               | Aaron Mate, who made the actual tweet about "Russiagate"
               | that Greenwald merely made a passing reply to, is about
               | as solid in his traditional left-wing bonafides as anyone
               | can be, following in the footsteps of his father Gabor, a
               | medical practitioner, researcher and author with a
               | decades-long public profile espousing traditional left-
               | wing values.
               | 
               | Aaron Mate's skepticism of the Russia narrative is not
               | out of any support for Trump whatsoever - he's been
               | highly critical of Trump - but is part of a track record
               | of earnest investigative reporting about Russia that few
               | other western journalists can match. One should never
               | forget that as recently as 2012, to consider Russia any
               | kind of threat to the US, which the Romney Republican
               | campaign did back then, attracted mockery and derision
               | from Democrats, and it was only in early 2017, just 4
               | years ago, that it suddenly flipped such that expressing
               | skepticism about the influence of Russia in US politics
               | suddenly became part of "right-leaning talking points".
               | 
               | All Mate is doing is remaining consistent with what has
               | been the accepted Democrat/left-wing position for many
               | years, right up until Clinton lost the unlosable
               | election.
               | 
               | When Mate and Greenwald spend their time "criticizing
               | liberals", their criticisms are always focused on the
               | modern-day Democrats' track record of becoming too
               | entangled with the big-corporate and
               | military/intelligence establishment, and in doing so,
               | abandoning their supposed left-wing ideals.
               | 
               | Just because some right-wingers criticise the
               | Democrats/liberals for the same reason, does not make
               | Mate and Greenwald right-leaning; they are simply staying
               | true to the left-wing values they've held for decades.
        
               | cycomanic wrote:
               | Well Greenwald has been posting some antimigration
               | articles messages using language that skims very close to
               | hard-right wording. Maybe he doesn't neatly fit into the
               | (American) left/right schema, but by now he is mainly
               | just a "bad media" propagandist.
               | 
               | Also I can't take anyone seriously who claims to
               | criticise mainstream media (almost always the more
               | Liberal slanted one), but goes regularly on Tucker
               | Carlsson without ever seriously criticising them. To see
               | how to properly criticise Fox and Tucker search for the
               | leaked interview with rudger bergman.
        
               | merricksb wrote:
               | > Greenwald has been posting some antimigration articles
               | messages using language that skims very close to hard-
               | right wording
               | 
               | That's an inflammatory claim, that needs direct
               | quotes/links to be taken seriously. But lest it be
               | forgotten that there has long been an acceptance among
               | traditional left-wingers (including Bernie until it
               | became unacceptable to too many of his followers) of the
               | need for some immigration controls in order to protect
               | the most vulnerable workers, and historically the loudest
               | voices for open borders are Laissez-faire/social-
               | Darwinist libertarians, most notably the Kochs.
               | 
               | > Maybe he doesn't neatly fit into the (American)
               | left/right schema
               | 
               | I think this is quite false: he fits into the traditional
               | left/right spectrum as a bona-fide leftist. It's the
               | mainstream Democratic Party that has moved towards
               | corporatism and militarism.
               | 
               | > regularly on Tucker Carlsson without ever seriously
               | criticising them
               | 
               | What would it change for him to criticize them; to try to
               | impress the people who would still hate him anyway?
               | Carlson gives him airtime and the opportunity to express
               | his position to an audience of people whose minds he
               | might be able to change about a few things. Why waste
               | that opportunity with token criticism?
        
               | cycomanic wrote:
               | >> Greenwald has been posting some antimigration articles
               | messages using language that skims very close to hard-
               | right wording
               | 
               | >That's an inflammatory claim, that needs direct
               | quotes/links to be taken seriously. But lest it be
               | forgotten that there has long been an acceptance among
               | traditional left-wingers (including Bernie until it
               | became unacceptable to too many of his followers) of the
               | need for some immigration controls in order to protect
               | the most vulnerable workers, and historically the loudest
               | voices for open borders are Laissez-faire/social-
               | Darwinist libertarians, most notably the Kochs.
               | 
               | Maybe in the context of what counts as left in the US.
               | But the socialist left movement was always an
               | international movement (I give you three guesses what the
               | anthem is called). Regarding some of the Greenwalds
               | words:
               | 
               | "Current illegal immigration - whereby unmanageably
               | endless hordes of people pour over the border in numbers
               | far too large to assimilate, and who consequently have no
               | need, motivation or ability to assimilate - renders
               | impossible the preservation of any national identity"
               | http://glenngreenwald.blogspot.com/2005/12/yelling-
               | racist-as...
               | 
               | Calling immigrants "hordes" is quite definitely language
               | that is what I consider "hard-right". It dehumanises
               | people and tries to instil fear and a violent counter-
               | reaction.
               | 
               | >> Maybe he doesn't neatly fit into the (American)
               | left/right schema
               | 
               | >I think this is quite false: he fits into the
               | traditional left/right spectrum as a bona-fide leftist.
               | It's the mainstream Democratic Party that has moved
               | towards corporatism and militarism.
               | 
               | The mainstream democratic party was never not corporatist
               | and militaristic. There has not been a change. However,
               | I'm interested what in your eye's qualifies Greenwald as
               | a bona-fide leftist (whatever that means)
               | 
               | >> regularly on Tucker Carlsson without ever seriously
               | criticising them
               | 
               | > What would it change for him to criticize them; to try
               | to impress the people who would still hate him anyway?
               | Carlson gives him airtime and the opportunity to express
               | his position to an audience of people whose minds he
               | might be able to change about a few things. Why waste
               | that opportunity with token criticism?
               | 
               | Funny, he does criticise the NYT and many other media
               | outlets though. But you're not wrong, he can express his
               | position to an audience, but he's not trying to change
               | minds, he actually agrees with much that Tucker Carlson
               | says. That means he agrees with the agenda of a
               | billionaire who has been using his media to clearly push
               | a neocon, hard-right agenda worldwide. Considering that
               | Greenwald is somehow building this persona of a media
               | critic who points out the "agenda" of mainstream media,
               | it is somewhat contradictory to go on those shows without
               | a word of criticism and without blinking an eye.
        
               | BlueTemplar wrote:
               | The first communist international was mainly about
               | antiimmigration.
               | 
               | Were they "hard-right" too ?
        
               | cycomanic wrote:
               | That's a pretty bold statement, you have any sources to
               | back that up?
               | 
               | The first international was about uniting international
               | workers, there are in fact several writings who say that
               | the bourgeoisie use nationalism and anti-immigrant
               | sentiments to divide the working class.
        
               | supportlocal4h wrote:
               | Somebody who spends all day critiquing NBA players is
               | probably not a football analyst.
        
               | LocalH wrote:
               | Do you realize that left/right in the US are pretty much
               | right/far-right to the rest of the world?
        
               | vxNsr wrote:
               | As others have said, you're so enmeshed in "progressive"
               | dogma that you can't even recognize true liberal ideas.
               | Greenwald is as liberal as they come the fact that the
               | democrat party has become so fascist while pretending to
               | be liberal and progressive doesn't mean he's changed.
               | They have and he's refusing to toe the party line for
               | them.
               | 
               | All your examples are him sticking to true liberalism
               | while the ideas he criticizes are extremist autocratic
               | ideology that wouldn't be out of place in 1935 Italy.
               | 
               | I say this as someone who vehemently disagrees with much
               | of both glens ideology and the insanity that is the
               | Democrat party platform.
               | 
               | To go line by line on your points:
               | 
               | 1) I'm not sure what you're trying to prove here but as
               | others have said glen is sticking to what has always been
               | liberal Americans stance on Russia, it's a non-issue.
               | 
               | 2) not sure about this one bec I don't have any knowledge
               | of UK politics
               | 
               | 3-5) Hunter Biden is a real story and just bec it hurts
               | the DNC candidate should t prevent reporters from talking
               | about it. The fact that so many have decided to put their
               | head in the sand is worrying. But Greenwald has never
               | shied away from exposing the dirty underbelly of the
               | elites. The fact that this time it exposes Biden to
               | corruption claims shouldn't stop the sorry from coming to
               | light.
               | 
               | 6) Criticizing a DNC bill doesn't make a you national
               | socialist workers' party member. It makes you a thinking
               | person. If you can't criticize a bad bill bec of who
               | sponsored it you've got big problems.
               | 
               | 7) see above. He's highlighting problems that a normal
               | progressive person would have, just bec you don't like
               | it... that just means you're less progressive than you
               | thought, doesn't make him a fascist.
        
               | [deleted]
        
           | exikyut wrote:
           | Serious question: the initial leak misspelt "Austria" as
           | "Austriaia", and chaos has ensued... the initial forum leak
           | along with all ufile references and telegram groups I've been
           | able to find all seem to have this "bug".
           | 
           | So I'm very interested about any insight you may have.
        
             | davidjohnstone wrote:
             | I don't have much insight on this. I accidentally
             | downloaded that one first when I meant to download the
             | Australian one, but quickly realised my mistake because the
             | CSV file inside the archive was correctly spelt. Then I got
             | the actual Australian one.
        
         | arnaudsm wrote:
         | I'm working on exactly that, using k-anonymity too. I expect to
         | release my tool within 24h
        
           | hugoromano wrote:
           | where should we go for your tool?
        
             | arnaudsm wrote:
             | It's now live on https://fbleak.info/, and it's open-source
             | !
        
           | 1vuio0pswjnm7 wrote:
           | This is a easy way to collect phone numbers of concerned
           | Facebook users.
           | 
           | Facebook then allows the person collecting phone numbers to
           | search for the name of the user associated with a phone
           | number (or email address).
           | 
           | https://mbasic.facebook.com/login/identify/?ctx=recover
        
             | technion wrote:
             | I believe this has been limited more recently. I just put
             | my number in there and it just says that I can click OK to
             | text myself a password reset, but didn't leak any details
             | on screen.
        
           | LilBytes wrote:
           | Looking forward to the Show HN. Keep us posted.
        
             | arnaudsm wrote:
             | The Website is now live at https://fbleak.info/ !
             | 
             | Discussion here:
             | https://news.ycombinator.com/item?id=26702473
        
               | usr1106 wrote:
               | US only :(
        
           | sagarm wrote:
           | How could a tool that checks for a specific phone number be
           | k-anonymous?
        
             | Godel_unicode wrote:
             | It can't. Or at least, not while remaining useful for the
             | haveibeenpwned use case.
             | 
             | It's also an interesting choice for a search tool for a
             | quasi-public dataset.
        
             | GoblinSlayer wrote:
             | In the same way as for passwords.
        
               | nikisweeting wrote:
               | Nah because you can iterate through all phone numbers
               | pretty quickly.
        
               | fX0rObfoMN4 wrote:
               | Phone numbers are only 10 digits. That is only 10 billion
               | combinations. For SHA1 which pwned passwords uses that it
               | should only take a couple seconds on a decent system.
               | Even with SHA256 it could be done in like a minute.
        
             | arnaudsm wrote:
             | By using partial sha256 hashes + padding, and doing the
             | checking locally
        
       | hnbad wrote:
       | Given that this may include data about EU residents and the GDPR
       | has strict rules about data breaches and may even impose fines in
       | cases of negligence I wonder if anything will come from this.
        
       | Panini_Jones wrote:
       | Was there a new breach yesterday or is this the 2019 one?
        
         | dgellow wrote:
         | If you click on the link you will see the description.
         | 
         | > Breach date: 1 August 2019
         | 
         | > Date added to HIBP: 4 April 2021
        
       | andix wrote:
       | In this leak every entry has a phone number and a name. But only
       | a few have an email address connected.
       | 
       | So it would be nice to have a service where you put in a phone
       | number and it will list what information is available for it.
       | Like this:                 [X] Phone Number       [X] Name
       | [X] Current location       [ ] Previous location       [ ]
       | Current employer       [ ] Email address       [X] Birthday
       | [ ] Full date of birth (with year)
        
       | teekert wrote:
       | I wonder if this includes WhatsApp data and in what form. It
       | would give me some extra ammo to get people to switch to Signal
       | ;)
        
         | dillondoyle wrote:
         | Not that I can tell
         | 
         | The cols (ive only loaded the US version) seem to be cell_phone
         | | fb_id | first_name | last_name | gender | lives | from |
         | releationship_status? | works_at | ?some year month maybe date
         | sms was given | email | bday?
        
       | intricatedetail wrote:
       | Did they acted on this like GDPR requires them to? Who should be
       | reporting it?
        
         | [deleted]
        
       | pvorb wrote:
       | One thing that really keeps annoying me about HaveIBeenPwned is
       | the fact that I can enter anyone's email and get their status
       | immediately. This way I can anonymously check if that email had
       | an account at a breached site at the time of the breach. The
       | obvious solution would be sending out a link via email before
       | results can be looked up, but this might not be in
       | HaveIBeenPwned's interest.
        
         | tgsovlerkhgsel wrote:
         | On the other hand, that means I don't have to do an annoying
         | verification dance to look up my pwnages, and can help others
         | look up their breach information without having to explain to
         | them over the phone how to click a link in an e-mail.
        
         | rkagerer wrote:
         | Some kind of "prove it's you" function would be great.
         | 
         | When you register for notifications it sends out a verification
         | email. That would be a good time to let you disable public
         | lookup of your email address.
         | 
         | I also wish HIBP could securely disclose the snippet of
         | information from a leak that's relevant to you. Knowing the
         | password or hash characteristics, phone number, etc. could aid
         | in mitigation, and seeing the raw impact might help motivate
         | ordinary users to improve their security hygiene.
         | 
         | Suggested that idea to Troy in the past, and got the impression
         | he's not amenable, largely due to the risks of hosting PII.
         | Can't really blame him.
        
           | unholiness wrote:
           | > That would be a good time to let you disable public lookup
           | of your email address.
           | 
           | https://haveibeenpwned.com/OptOut
        
         | globular-toast wrote:
         | The point of hibp is this information is now public. Putting it
         | behind some kind of identity check would be security by
         | obscurity. The bad guys have the raw data and can look up any
         | address at will.
        
           | koheripbal wrote:
           | Public isn't "binary". Finding the leaked files, downloading
           | them (often paying to do so), aggregating all the data from
           | all of them and searching them all is a huge pain-in-the-
           | butt.
           | 
           | 99.99% of people would not go through this effort and lack
           | the skill/knowledge, even if they were motivated against
           | someone.
        
             | globular-toast wrote:
             | Maybe not, but the people you need to worry about would.
        
         | CGamesPlay wrote:
         | This isn't universally true, the site does have a notion of
         | "sensitive breaches" which will not be visible to someone who
         | cannot confirm ownership of the email address.
         | 
         | https://haveibeenpwned.com/FAQs#SensitiveBreach
        
           | diarrhea wrote:
           | The list of examples reads like my browser bookmarks list.
        
           | pvorb wrote:
           | I didn't know about this, thanks. So it's already
           | implemented. I'd just prefer if every breach was marked as
           | sensitive.
        
         | tjpnz wrote:
         | It's possible to opt out. But that does require knowing HIBP
         | exists.
        
         | sneak wrote:
         | It's not HIBP that caused that data leak. The fact of which
         | emails have accounts on which sites is public following the
         | breach/leak of that site's data.
        
           | Rebelgecko wrote:
           | Even though HIBP didn't cause the data leak, their
           | aggregation makes it a lot easier to see which websites
           | someone uses.
        
             | sneak wrote:
             | This is a good argument for my recommended practice of
             | using a different domain/email for login accounts and
             | personal correspondence.
             | 
             | My public email address is not the one I use for logins
             | anywhere.
        
           | pvorb wrote:
           | Yes, but you'd actually have to look for or even buy the
           | leaks themselves in order to find out if somebody has been
           | "pwned". I'm not arguing against the service in general, but
           | there's an obvious way to improve privacy.
        
             | techrat wrote:
             | The lookup doesn't tell you anything more than someone
             | exists in a breech. You'd still have to have the data
             | itself.
             | 
             | If you have the data itself, then lookup is as simple as
             | 'grep' or 'ctrl-f'
             | 
             | So anyone who has the means to compromise someone they're
             | looking up by having the data doesn't need the
             | HaveIBeenPwned tool in the first place.
             | 
             | Moot point, IMHO.
        
               | 55555 wrote:
               | what if I use HIBP to check if any of my friends had
               | registered accounts on a Furry Findom forum, which was
               | recently breached? It's potentially embarrassing.
        
               | MrGilbert wrote:
               | This breach would be marked as "sensitive", so you
               | wouldn't be able to look that up without confirmation of
               | ownership.
        
               | unholiness wrote:
               | You can't, because that specific breach has been marked
               | as sensitive:
               | https://haveibeenpwned.com/FAQs#SensitiveBreach
        
               | techrat wrote:
               | I'd argue reasonably smart people would use a different,
               | non distributed/shared email address for sensitive things
               | like fetish sites...
               | 
               | ...and that your friends deserve a better friend than
               | someone who would look up their email addresses to
               | embarrass them.
        
             | zamadatix wrote:
             | It seems a bit like the FBI warning at the beginning of
             | DVDs, the only people that are going to be bothered by it
             | are people that were going to play by the rules in the
             | first place. The privacy was already lost, you can't
             | increase it again retroactively.
             | 
             | The ones marked sensitive have more a pattern of "we don't
             | want to be caught in a court caste about hosting the info"
             | than a pattern of trying to improve privacy in the ways
             | this thread is suggesting.
        
         | Abishek_Muthian wrote:
         | But only due to HIBP integration in browser's password manager
         | many come to know about their account leak even when the
         | company which was breached didn't disclose it (as is the case
         | in most countries).
         | 
         | There's still a need gap to detect leaked file data online, Say
         | after a ransomware attack our files end-up in pastebin[1];
         | currently there seems to be no way to know unless manually
         | monitoring sites where leaked data is posted or for the
         | attacker to themselves let you know.
         | 
         | [1] Added in my profile.
        
         | IshKebab wrote:
         | Yes then they could also show the actual data leaked. I'm
         | supposedly in 11 breaches that include things like my date of
         | birth and physical address. Maybe. But I don't really know.
         | 
         | Did I give a fake DOB. Is it a previous address? Do they
         | actually even have an address or is it just NULL for me? HIBP
         | won't tell me.
        
       | bottled_poe wrote:
       | The percentage of breaches in this database which is "Mongdo DB
       | instance exposed to internet without a password"... yikes. Why on
       | earth is no password the default?
        
         | xmprt wrote:
         | The popularity of MongoDB was a direct result of how simple it
         | was to set up.
        
         | Sebguer wrote:
         | It's even better, for years the default was no password /and/
         | binding on 0.0.0.0.
        
         | TheSpiceIsLife wrote:
         | My tin-foil-hat wants to believe it has something to do with
         | MongoDB's CIA funding.
         | 
         | https://en.wikipedia.org/wiki/MongoDB_Inc.
         | 
         | PS Hello from the south island
        
           | chx wrote:
           | Apply Hanlon's razor instead.
           | 
           | Consider just how "excellent" MongoDB was as a database
           | before they bought Wiretiger and made it default. Ahem.
        
       | ttz wrote:
       | Kind of a shitpost:
       | 
       | Anyone read the post title as "HaveLBeenPwned", like Havel from
       | Dark Souls? Who often pwned you the first time around...
        
       | hathym wrote:
       | Tunisia population is 12 millions but there is 39 millions users
       | in the breach. very strange!!
        
         | Digit-Al wrote:
         | Not that strange at all. A lot of people all over the world
         | have multiple email addresses. Myself for instance, I have an
         | email address from my telecom provider, I have a Yahoo! email
         | address from when I signed up years ago, my Google account has
         | about two or three different ways of referring to the email
         | address, plus I have my own domain; so I have about five
         | different personal email addresses, plus my work email address.
        
       | SergeAx wrote:
       | Interestingly, Russia files are missing huge range of phone
       | codes, from +7(910) to +7(929).
       | 
       | There are 3 top mobile operators in Russia: MTS, Beeline and
       | Megaphone. Each of them has its own set of phone codes. Majority
       | of MTS and better half of Megaphone numbers are not affected, but
       | all Beeline codes are exposed.
        
         | joshspankit wrote:
         | Interesting agreed.
         | 
         | Have you checked the other entries to see if they are mis-
         | categorized?
        
       | I_am_tiberius wrote:
       | I just searched myself and found that my "Apollo" information was
       | leaked in 2018. I don't know what "Apollo" is though and don't
       | think they should have my details. Does anyone know details about
       | that leak?
        
         | TechBro8615 wrote:
         | It was a company that scraped public LinkedIn profiles and then
         | got their database popped.
        
           | I_am_tiberius wrote:
           | That means my email address must have been accessible
           | publicly.
        
             | TechBro8615 wrote:
             | Yeah I'm not sure, they might have scraped other info too
             | e.g. GitHub. Frankly I think it's kind of silly to
             | categorize this as a "breach" when all the data was
             | publicly available. And if you're trying to hide your
             | email, you're fighting a losing battle already. Best to
             | just assume your email is public knowledge.
        
           | neogodless wrote:
           | It's odd because an email I only use on Facebook is in the
           | Apollo leak (and the Zynga one due to Words with Friends on
           | Facebook.) So does Apollo have information from more than
           | just Linkedin?
        
           | underlines wrote:
           | public information became public?
        
       | cyberlab wrote:
       | How is it legal for HIBP to keep copies of breach corpuses on
       | their servers? For me personally, having corpuses on my hard-
       | drive is like dealing with radioactive waste. There's so much PII
       | to mull over that it feels naughty to sift through. There's even
       | people on social media bragging about 'self doxing' their own
       | info (just like with using HIBP), but using a local copy instead.
        
         | nathanfig wrote:
         | I presume they keep a table mapping email addresses to breaches
         | and that's it.
        
           | cyberlab wrote:
           | Yes but how is it legal to have multiple corpuses sitting on
           | a gigantic server? Surely governments or even a LEA would
           | want to regulate that? Having all that PII is like hoarding a
           | bunch of radioactive waste.
        
             | wan23 wrote:
             | They don't need to keep the data around longer than it
             | takes to extract the affected email addresses, and that
             | doesn't need to be done on a server at all.
        
         | philjohn wrote:
         | Do they store the full breach there, or is the PII put through
         | a one-way hash and that used for matching?
        
       | lifeplusplus wrote:
       | how can i access the entire DB?
        
         | koheripbal wrote:
         | These sorts of leaks are usually available over torrent from
         | any torrent search engine.
        
         | coolspot wrote:
         | Use any MySQL client to connect.
         | 
         | Host: db.facebook.com
         | 
         | User: production
         | 
         | Password: password
         | 
         | Please don't change any data!
        
           | underlines wrote:
           | wrong! you have to use the postgres driver
        
           | ben509 wrote:
           | How the hell did you find out my Facebook password?! Mark
           | SUCKERberg is about to get a very angry comment from me!
        
       ___________________________________________________________________
       (page generated 2021-04-05 23:02 UTC)