Slashdot Mirror


A Hacker Has Dumped Nearly One Billion User Records Over the Past Two Months (zdnet.com)

A hacker who spoke with ZDNet in February about wanting to put up for sale the data of over one billion users is getting dangerously close to his goal after releasing another 65.5 million records last week and reaching a grand total of 932 million records overall. From a report: The hacker's name is Gnosticplayers, and he's responsible for the hacks of 44 companies, including last week's revelations. Since mid-February, the hacker has been putting batches of hacked data on Dream Market, a dark web marketplace for selling illegal products, such as guns, drugs, and hacking tools. He's released data from companies like 500px, UnderArmor, ShareThis, GfyCat, and MyHeritage, just to name the bigger names. Releases have been grouped in four rounds -- Round 1 (620 million user records), Round 2 (127 million user records), Round 3 (93 million user records), and Round 4 (26.5 million user records).

37 of 72 comments (clear)

  1. You're saying shitty websites have poor security? by Anonymous Coward · · Score: 1

    "500px, UnderArmor, ShareThis, GfyCat, and MyHeritage, just to name the bigger names." Other than underarmor, THESE are the BIGGER NAMES? Lol.

  2. Re:So? by Anonymous Coward · · Score: 5, Funny

    My pass phrase is 1kb long.

    That is a insecure pass phrase. "1Kb L0nG$" would be better.

  3. Re:So? by JaredOfEuropa · · Score: 5, Funny

    My pass phrase is 1kb long. Good fucking luck with that

    Worst pickup line ever...

    --
    If construction was anything like programming, an incorrectly fitted lock would bring down the entire building...
  4. Re:So? by Locke2005 · · Score: 5, Funny

    "Do you think maybe he's compensating for something?" -- Shrek

    --
    I've abandoned my search for truth; now I'm just looking for some useful delusions.
  5. Re:In all seriousness... by Locke2005 · · Score: 1

    Nah; just fine him $1 for each user profile stolen, and keep him in jail until he pays off the entire fine.

    --
    I've abandoned my search for truth; now I'm just looking for some useful delusions.
  6. Re:So? by Anonymous Coward · · Score: 1

    My pass phrase is 1kb long.

    That is a insecure pass phrase. "1Kb L0nG$" would be better.

    Funny!

  7. In other news... by BringsApples · · Score: 2

    ...People all over the world are continuously giving their data away to FaceBook for free.

    --
    Politics; n. : A religion whereby man is god.
    1. Re:In other news... by Anonymous Coward · · Score: 1

      Someone finally sees the elephant in the room. Nobody notices because they're all too bloody busy with the noses in their mobiles clicking "Like" and "Subscribe".

  8. Re:So? by Nidi62 · · Score: 2

    My pass phrase is 1kb long.

    That is a insecure pass phrase. "1Kb L0nG$" would be better.

    Dammit! Now I have to change the combination on my luggage!

    --
    The only thing necessary for evil to triumph is for it to be pitted against a slightly greater evil
  9. life during wartime by Anonymous Coward · · Score: 1

    I've had my identity stole so many times
    I don't know what I look like!

  10. Re:In all seriousness... by Anonymous Coward · · Score: 1

    If sentence would be similar to what corporations get for breaking laws, the guy would get a fine of 1% of this net income and by appeal the sum would be halved.

  11. Re:So? by 93+Escort+Wagon · · Score: 1

    My pass phrase is 1kb long.

    Well, MY pass phrase has 1kg mass.

    --
    #DeleteChrome
  12. Re:In all seriousness... by ShanghaiBill · · Score: 1

    I would be heavily in favour of the death penalty for this moron.

    The focus should be on fixing security holes, rather than draconian punishments for those who inevitably exploit them.

  13. Re:In all seriousness... by gweihir · · Score: 1

    Just shows you are a vicious cave-man. The death-"penalty" has no deterrence value and is just revenge. As such it makes matters worse. Great job.

    --
    Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  14. Re:In all seriousness... by gweihir · · Score: 1

    That would make things better. But some people obviously prefer them to stay bad so they can indulge their sadistic fantasies...

    --
    Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  15. Sure sure by jbmartin6 · · Score: 2

    This appears to be the same person behind the "Collection #1" releases circa Jan 18th. it was just a collection of a bunch of older dumps i.e. data aggregated from other breaches. I didn't see any reason to think this person was behind all of the hacks, I got the sense he might also brag he could hack into any porn site on the Internet by putting in his mom's credit card number.

    --
    This posting is provided 'AS IS' without warranty of any kind, implied or otherwise.
  16. Re: In all seriousness... by Viol8 · · Score: 1

    Care to name anyone who's reoffended after being executed?

  17. Re:In all seriousness... by humankind · · Score: 1

    I'm not condoning his actions in the slightest.

    But you do realize what he's doing basically, Google and Facebook and many others also do every day?

  18. Advice by Required+Snark · · Score: 2, Interesting
    Never sign up for anything ever.

    Really. Don't do online payments, don't subscribe to news organizations, don't stream games, don't get email notifications, nothing. The only sort of safe exception is medical information under HIPPA.

    Remember no organization is at risk if they leak your info. The cost of a breach is just factored into the cost of doing business. That's why HIPPA is an exception. Medical information leaks are treated extremely seriously and they can even cause an organization to be shut down.

    The only one who is at risk if personal data becomes public is you. Organizations don't give a damn about you.

    --
    Why is Snark Required?
    1. Re:Advice by Anonymous Coward · · Score: 1

      Dammit, I wanna sign up just to get the points to mod you up.

    2. Re:Advice by Anonymous Coward · · Score: 1

      That's why HIPPA is an exception. Medical information leaks are treated extremely seriously and they can even cause an organization to be shut down.

      For those of us who work with HIPPA data on a daily basis vs. non-HIPPA data - yes its treated more seriously. BUT, at the end of the day - its another factored risk. Paraphrasing Fight Club:

      "Take the number of (HIPPA records), A, multiply by the probable rate of failure, B, multiply by the average out-of-court settlement, C. A times B times C equals X. If X is less than the cost of (properly securing against a data breach), we don't (bother with proper data security)."

      Business woman on plane:
      Are there a lot of these kinds of (exposures)?

      Narrator:
      You wouldn't believe.

      Business woman on plane:
      Which (HIPAA complaint) company do you work for?

      Narrator:
      A major one.

    3. Re:Advice by davesays · · Score: 1

      HIPPA is not an exception, it promises punishment of violations not guarantees of privacy... I respect your remarks, but even the DOD doesn't keep their stuff private.

    4. Re:Advice by jbmartin6 · · Score: 1

      Have there been any serious repercussions from HIPAA violations? Medical data get shared around so widely with various medical specialists, claims specialists, coders and re-coders, government agencies, research teams, etc. that 'secret' is no way to describe it. It is generally not in the forefront of news outlets since it is a bit harder to monetize, but there is plenty of medical fraud already going on with leaked health records.

      --
      This posting is provided 'AS IS' without warranty of any kind, implied or otherwise.
  19. Re:You're saying shitty websites have poor securit by bev_tech_rob · · Score: 1

    "500px, UnderArmor, ShareThis, GfyCat, and MyHeritage, just to name the bigger names." Other than underarmor, THESE are the BIGGER NAMES? Lol.

    IKR? Never heard of any of these short of UnderArmor and I haven't heard any news from that outfit for a long time.

    --
    You're messin' with my Zen Thing, man.....
  20. Re: In all seriousness... by Anonymous Coward · · Score: 1

    Care to name anyone who's reoffended after being executed?

    Exactly the same number as have reoffended after serving a life sentence without eligibility for parole. Killing them back accomplishes nothing, but does exclude the possibility of exoneration in the large number of cases where someone has been wrongly convicted.

  21. Re:So? by Anonymous Coward · · Score: 1

    The hash is most likely far shorter than that 1kb number, and I am not sure if that is kilobits or kilobytes being referenced. Assuming a strong SHA512 hash and a 1kb password, you have introduced many collisions with more modest length passwords.

  22. Re: In all seriousness... by sarren1901 · · Score: 1

    If you stop letting people appeal after appeal after appeal it wouldn't cost so much. Criminals like James Holmes where they is zero doubt of who committed the crime. Why keep those people alive? Saying it cost to much is just the system being broken. Killing someone is extremely cheap. Just ask James Holmes.

    For some reason though, we would rather waste money on keeping him alive. I guess he's worth our taxes dollars, eh? Surely no other way we could spend that money but instead we let him live.

    In extremely cases where there is lots of evidence, there should totally be an option of the death penalty and we really ought to be reforming that system itself. 30 years on death row? That's a miscarriage of justice.

  23. Re: In all seriousness... by gweihir · · Score: 1

    That is unlikely. Most people are not cave-men that think murder (whether by the state or otherwise) is acceptable.

    --
    Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  24. Re: In all seriousness... by gweihir · · Score: 1

    Wow, you really do not understand how things work. And even with your primitive approach, it would still not have any deterrence value.

    --
    Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  25. Re: In all seriousness... by gweihir · · Score: 1

    That is not what "deterrence" means.

    --
    Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  26. Or sign up under a false persona by ron_ivi · · Score: 1

    You get much more fun junk mail if you claim your income's >$400,000; and your interests include hunting rifles and endangered species.

  27. Re: In all seriousness... by Anonymous Coward · · Score: 1

    Care to name anyone who's reoffended after being executed?

    You thought you were trolling, but I've got a serious answer to that:

    Jesus Christ ("offended" the archaic laws in place in 1BC)

    Justice isn't always fair -- it's enforcing the laws in place at the time. One of the failings of our justice system is that the system itself can be wrong at times and yet we still strive for the harshest penalty for someone who may have been right in the truest sense.

  28. Re:In all seriousness... by Aighearach · · Score: 1

    I would be heavily in favour of the death penalty for this moron.

    The focus should be on fixing security holes, rather than draconian punishments for those who inevitably exploit them.

    Can't we do both?

    What is your theory as to why we can't have nice things?

  29. Re: In all seriousness... by Viol8 · · Score: 1

    Cave men like that saved your parents arse in WW2. Perhaps you think Hitler and the Japanese should have just had stern words spoken to them?

    Moron.

  30. Re: In all seriousness... by Viol8 · · Score: 1

    Who said deterence is the only goal? Prevention of further crimes by the criminal is just as important and the death penalty does that perfectly with the added bonus of not costing the same as a 4 star hotel to keep them incarcerated for their rest of their lives.

  31. Re:So? by David_Hart · · Score: 1

    My pass phrase is 1kb long.

    Well, MY pass phrase has 1kg mass.

    So, you've been logging into to Slashdot for the last 5 years just for this one post? Was it worth it?

  32. Re:So? by ebvwfbw · · Score: 1

    "Mail from Security Minded People."
    Please check the strength of your password using our free tool:
    www.www.com/passwordchecker.py

    Why my PW is 1kb... Should say it's strong. Let me cut & paste it in.
    See, says it the best it has ever seen!
    I'm so smart. I'm so smart...

    I joke about this, however I work someplace and the guy in charge of the windows people typed his password into the checker in less than 5 minutes. This was the day after phishing awareness training.

    If you want to keep things secure, get rid of passwords. At the very least go to MFA. People as a rule can't be trusted. Individuals - sure. People hell no. People are dumb. At any place - company, government agency, etc...you have people.