3 ms·
People's inability to understand basic security shouldn't amaze me anymore, yet every time I see things like this I still wonder how many stupid things we don't
by coldcode 9y ago
People's inability to understand basic security shouldn't amaze me anymore, yet every time I see things like this I still wonder how many stupid things we don't ever find out about.
- Nomentatus 9y agoI suppose you mean that leaving an open to the world webserver copy lying about without even a password, much less encryption was an idiot's blunder - but that wasn't a legitimate site. It's way downstream of the actual information heist, if I read the article correctly. Nobody got phished. The information was originally gathered by some legitimate institution, perhaps government, and then sold or stolen. I wouldn't be surprised if Dracore was founded from the start by a leak from an insider who figured out he could quit his govt job, take the database with him, and found a nice business that would make money while he slept. Basic security by individuals at home can't prevent such "inside jobs." I once knew someone who was offered a million dollars for a copy of a very small corner of a records pile that was part of their normal work responsibilities over a few drinks and said no; I'm less surprised that others might have said yes. What I call the "mass effect", that is, the fact that 60 million records could fit onto anyone's phone (if it had an external chip smaller than the one in my otherwise cheap phone) makes such inside jobs very hard to defend against; on the "who will watch the watchers" principle. "Mass effect" so called because information is losing mass extremely quickly, a whole lot of it now weighs almost nothing. You can just saunter out the door with it.