41 ms·
Billion-record stolen Chinese database for sale on breach forum
- neallindsay 4y agoThis has to be the largest leak of personal information yet, right?
- O__________O 4y agoA lot of the press is saying it is, but unclear since “entries” is as vague as the “records” in this 1.2 billion leak: https://www.wired.com/story/billion-records-exposed-online/ https://www.wired.com/story/billion-records-exposed-online/ Appears this leak is a single dataset — one I linked to is multiple datasets.
- nicce 4y agoFacebook leaked much more couple years ago. Somehow everyone has forget that. Some example news: https://www.privacyaffairs.com/facebook-data-sold-on-hacker-forum/ https://www.privacyaffairs.com/facebook-data-sold-on-hacker-...
- jsnell 4y agoThat was not a data leak. It was a compilation of scraped, publicly available data.
- hansel_der 4y agoprivate data was publicized without consent, a leak indeed.
- mvdwoord 4y agoWhat do we do now? It seems the majority of people on the planet now have had some of their data leaked. Or are becoming ever more entangled with government and corporate systems which control and peddle their information as they see fit. Is it ultimately a big nothing burger, or is this some singularity we are passing through?
- pyinstallwoes 4y agoIn history what have databases of people and state actor interests usually led to if any events are similar?
- mvdwoord 4y agoI would say, impossible to compare. Digital changes the cost of acting upon this information, for good or bad purposes. Obvious comparisons to e.g. the Netherlands' famous over-registering of religion and how the Nazis abused that. But I feel this is long term potentially worse than that. Not in the level of horribleness, but in the effect on society moving forward.
- pyinstallwoes 4y agoCan you extrapolate that on what the effect on society looks like in your assessment?
- MadsRC 4y agoIIRC when Nazi Germany invaded Denmark in 1940, one of the first things the SS did was to send representatives to the local churches. In Denmark, every child was (I’m not sure if they still are actually?) registered at birth by the local parish in so called “church books”. With these “databases” in hand, the SS had a neat list of all names, and the approximate location of peoples homes. Those lists were used to identify and prosecute jews.
- markus_zhang 4y ago"Looks genuine" from my Chinese friends. Also this might be leaked through a hardcoded token in some code posted on CSDN (sort of blog for programmers).
- luke-stanley 4y agoIn 2018 I saw a local branch office were using Windows XP and an old Internet Explorer. You cannot expect that to be secure. This does not surprise me at all.
- Haemm0r 4y agoXP is very common on airports in China too.
- dontbenebby 4y agoit's in US ones too, it's an industry wide issue in the aviation sector, don't hack the airport, people will come for you and if you are lucky they will be carrying badges
- anewpersonality 4y agoWhatever happened with the Gatwick drone?
- baybal2 4y agoSurprise, it's 2022, and XP is still a de-facto standard Windows version, with hacked Win7 slowly gaining. Why? Tons of Software was written for XP, and then abandoned without any support. Many of that stuff in the government sector. A lot of online banking clients outright say "only works on XP," and copyright years reads 2006. This is similar how Android 7+ support was almost nuked in China for nearly a year because Tencent didn't want to port Wechat to newer APIs cuz "nobody uses Android newer than 4.X in China"
- ceeplusplus 4y agoThat was not why they refused to port it to newer APIs though. It was because Google changed the permissions API to be more granular and request permissions at runtime, which would have meant Tencent would have to request tons of permissions to gather user data (presumably users would not be inclined to grant so many permissions).
- pedro2 4y agoIs it 1 billion in long scale or small scale?
- ginko 4y agoLast I checked there weren't 10^12 people living on earth just yet.
- pedro2 4y agoI honestly didn't know that. One gets used to short scale on the Internet.
- hansel_der 4y agoit's about 1MMM
- sgjohnson 4y agoWhy would it be in long scale? Is long scale even used in english at all?
- pedro2 4y agoIt was a joke. But it made me realize, thanks to the comment above, that Earth's population is around 8 thousand millions, and not 8 billion as I'd come to believe.
- deleted 4y ago[deleted]
- bitdivision 4y agoFor anyone wondering what that is, English uses short-scale, i.e. 1 billion = 1000 million, some other languages / countries use long-scale i.e. 1 billion = 1 million million. https://en.wikipedia.org/wiki/Long_and_short_scales https://en.wikipedia.org/wiki/Long_and_short_scales
- tremendo 4y ago
- FollowingTheDao 4y ago
- pedro2 4y agoAnd not receive those sweet dollars? I am sorry sir, I will not.
- noirbot 4y agoGovernments have been collecting (and poorly securing) this sort of information and more for most of recorded history. It's not to say that I like it, or would work for somewhere like Meta or the like, but plenty of these major data leaks have been from places that used to collect and store physical data bases of this stuff since before most of us were alive. I'm talking calmly about this because people have been screaming in my ear about it for 20 years, and I listened. And then I lived my life around the fact that this was going to be happening whether you scream yourself hoarse or not, at least for now.
- FollowingTheDao 4y ago[flagged]
- Agamus 4y agoFive years! I've been screaming that for at least 15 years, and I'm pretty sure I'm a noob to the discussion.
- FollowingTheDao 4y agoI am with you, I was just minimizing.
- tpaksoy 4y agoApparently there was a "blogpost" of a developer showing of their code, where they accidentally leaked access tokens in a piece of commented code: https://archive.ph/mP3bh https://archive.ph/mP3bh This is completely unverified though, so take it with a grain of salt.
- bilekas 4y agoIt's incredibly disappointing actually how often this happens. I can't count the amount of SO questions I've had to edit from others posting live API Keys for everything from custom services to AWS.
- swimfar 4y agoWhen you do this is there a way to completely get rid of the information? Usually you can go back an look at the edit history to see the original post.
- bilekas 4y agoYeah mods can clear the review history - for this very reason! But as mentioned below - Still advised to change your keys for obvious reasons
- aembleton 4y agoChange the keys.
- capableweb 4y agoWouldn't matter. Tons of bots are scraping every inch of the internet all the time, and if something been online for five seconds, it has been cached/stored somewhere. Always assume that anything you've put up on the internet, can forever be accessed by someone. The only thing you can do is rotating the token/secret.
- teddyh 4y agohttp://www.threepanelsoul.com/comic/on-that-guy http://www.threepanelsoul.com/comic/on-that-guy
- keewee7 4y agoThe Shanghai police has a unique role in China and abroad. For example the Shanghai police is tasked with spreading pro-CCP propaganda globally on platforms like twitter and Facebook. There was an HN post about this a few months ago: https://news.ycombinator.com/item?id=29654137 https://news.ycombinator.com/item?id=29654137 Someone posted a comment explaining a little more about Shanghai's special relationship with the CCP/PLA: >Shanghai is a city with a unique role in the progression of the CCP and its global efforts. Also PLA Unit 61398 is in Pudong, the shanghai district mentioned in the article. Overall there's a lot of CCP/PLA-adjacent tech talent in the area, and of course the local police still ultimately report to the CCP. https://news.ycombinator.com/item?id=29656017 https://news.ycombinator.com/item?id=29656017
- WilTimSon 4y agoSo I'm guessing that database would have quite a few activists listed in it and other anti-government people. Might even give someone a much-needed warning if they find themselves there.
- stjohnswarts 4y agoI was having this exact conversation with a friend last night. Give them warning, especially people in Hong Kong.
- dontbenebby 4y ago
- drexlspivey 4y agoIt's obviously a database of all Chinese citizens so yes those people are included alongside everyone else
- nonethewiser 4y agoPeople didn't think Shanghai was open so that the world could come IN to China, did they? It's about the opposite direction.
- throwaway4good 4y agoWho would buy this? How could anyone possibly make money off this data set? I could understand if the Chinese government would pay for it to avoid embarrassment but making the sale public kinda voids that.
- hutzlibu 4y ago"Who would buy this?" Foreign intelligence agencies for classic espionage. If you want to do blackmailing in china, such a DB would be a good start. Otherwise, data brokers. Advertisement, financial credibility, trustworthines of buisness partners etc.
- throwaway4good 4y agoI don't know how it works in China but where I am a person's criminal record is not public but not exactly private either. In the sense that an employer can ask for your criminal record and you have the choice giving a printout of it or not having your job. Making it kind of hard to see how the knowledge of a criminal record could be used to blackmail someeone. As for "data brokers. Advertisement, financial credibility, trustworthines of buisness partners etc.". Maybe. But these companies would turn themselves into criminals by using or purchasing this information.
- hutzlibu 4y agoIt is likely, that this DB contains more information, than what a formal printout gives. "But these companies would turn themselves into criminals by using or purchasing this information." Which is why they probably would not deal with the information gathering directly, but use a service of a data analyst company. When they do something illegal, nobody who contracted then did ever know anything. I think this game is played in china as well.
- hansel_der 4y agorest assured that intelligence agencies have means of accessing police records in other nations. this data is only interesting to the low end of data brokers, advertisers and other scammers, hence the rather low price.
- cm2187 4y ago> This database contains many TB of data and information on Billions of Chinese citizens how many billions?
- _Algernon_ 4y agoI'd assume between 1 and 1.402
- r721 4y agoKaren Hao (WSJ): "I downloaded the sample the hacker provided and called dozens of people listed. Nine picked up & confirmed exactly what the data said." https://twitter.com/_KarenHao/status/1543949945614393344 https://twitter.com/_KarenHao/status/1543949945614393344 (thread)
- twicetwice 4y agonitter link, since Twitter put up what seems to be a timed login gate when I was halfway through reading the thread: https://nitter.net/_KarenHao/status/1543949945614393344 https://nitter.net/_KarenHao/status/1543949945614393344
- black_puppydog 4y agoNitter is the only sane way to read twitter nowadays. Even if I still had an account it would be better for reading.
- moneywoes 4y agoI keep getting timeouts from them interestingly
- boomboomsubban 4y agoA different instance may work for you https://github.com/zedeus/nitter/wiki/Instances https://github.com/zedeus/nitter/wiki/Instances
- hackernewds 4y agoThe app download nags on mobile web are so unbearable I stopped using Twitter entirely
- BbzzbB 4y agoI made a webapp home icon from my Firefox and picked out the app-bait popover with uBlock. Basically just about every app (YouTube, Reddit, Facebook, ...) is better this way. I.e., no ads, erase-able elements, less spyware, defaults to no notification and sometimes even gets better functionality. For instance, it (browsers) gets rid of "hearts" in Duolingo for whatever damn reason, so you can practice however much you'd like in a day. The downsides I've found is that you seemingly can't Chrome-cast from it, and it often creates new tabs instead of reusing existing ones or making it's own app-instance, so you gotta close all tabs every so often.
- dang 4y agoRelated: Hacker claims they stole police data on a billion Chinese citizens - https://news.ycombinator.com/item?id=31984663 https://news.ycombinator.com/item?id=31984663 - July 2022 (1 comment) Hacker claims to have obtained data on 1B Chinese citizens - https://news.ycombinator.com/item?id=31980101 https://news.ycombinator.com/item?id=31980101 - July 2022 (1 comment) Hacker claims to have stolen 1 bln records of Chinese citizens from police - https://news.ycombinator.com/item?id=31977354 https://news.ycombinator.com/item?id=31977354 - July 2022 (1 comment) Police data of 1B Chinese people leaked - https://news.ycombinator.com/item?id=31969617 https://news.ycombinator.com/item?id=31969617 - July 2022 (4 comments) Shanghai Police leaking 20TB Chinese citizens data? - https://news.ycombinator.com/item?id=31962526 https://news.ycombinator.com/item?id=31962526 - July 2022 (3 comments)
- freewizard 4y agoThanks for reposting this. The last link submitted by me only got 3 upvotes. Guess it sounded just too crazy to be true 2 days ago!
- dang 4y agoThere's just a lot of randomness in what gets attention/traction off /newest. That's why HN doesn't try to prevent reposts of stories that haven't had significant attention yet. It sucks when you're earlier and don't 'win', but it evens out in the long run if you post lots of good stories, since sometimes the lottery works in your favor. One of these years we'll get around to implementing karma-sharing to spread credit across multiple submitters.
- silentsea90 4y agoWhat's the point of "winning" if everything is made up and the points don't matter? I get there's satisfaction in posting content that was useful, and HN isn't Fb/Twitter/Reddit and awash in ad $, but I feel fake internet points kinda manipulative since there's $ for the platform in your work.
- 4y ago
- hintymad 4y agoThe leaked screenshot of the data's metadata looks like the output of Elasticsearch's /_cat command. Someone probably left the port 9200 open to the public, or stored the index on a public cloud but somehow leaked its keys either on github-like service or in some discussion forum -- a typical mistake that engineers make.
- flatiron 4y agohttps://www.alibabacloud.com/product/datahub https://www.alibabacloud.com/product/datahub is what they were using, and yeah their keys were in a commented out psvm tester method. pretty awful
- dx034 4y agoAnother reason why not everyone should use the cloud. Sure, the cloud can be as secure as on-prem or even safer in many cases. But it's just so easy to keep on-prem data safe by just not connecting it to the outside world. If no server can be accessed from anywhere but the premise, leaks like these just can't happen. A key won't help you unless you can break into the police building. Access just based on credentials seems so wrong anyway. There should always be whitelisted IPs for sensitive stuff like that.
- rfoo 4y agoWhat happened is the exact opposite: The Shanghai police thinks like you, so they purchased a very expensive "private deployment of Alibaba Cloud", which in China usually works like this: 1. The customer build a data center. 2. Alibaba Cloud purchases servers, deploys them in the customer's data center along with all Alibaba Cloud software (same as in the public cloud). 3. Customers do whatever they want to the thing. Basically by "private cloud" they really mean it, something AWS won't ever do. In this case, the system is technically "not connected to the Internet", but we all know what this mean: it certainly will be occasionally. Most cases I know, the customer cite "data security" as the reason why they would like to do this, because on-prem are always more secure right? But I hope we could agree on why this does not work: - It is now very difficult for Alibaba Cloud to do ops work on these private deployments, so ... there will be maybe 2 releases per year, or in some cases never, including security patches. It's not rare to find a 5-years-old struts2 vuln in the control plane of such private deployments, and in the coming years it would be log4j2 I guess. - Alibaba Cloud put serious effort into securing their public cloud, and even covering the ass for the customer. For example similar to GitHub+AWS secret scanning, they also proactively revoke access keys once the key appears on the Internet. The customers, on the other hand, usually do none of these. In short, security is largely an Ops work and economies of scale also work here. In the end these on-prem systems depend solely on network isolation for their security, and... air-gap does not always work.
- himinlomax 4y agoThis is interesting, this could be a major blow to the Chinese dictatorship.
- hansel_der 4y agowhy?
- nonethewiser 4y agoI am guessing he means that it highlights the incompetence or even just the consequences of centralizing power. Personally I don't expect this to bear true. Historically in China, government failures have been cited as evidence for further centralizing the power of the federal government. And this argument is bought hook-line-and-sinker by the people. I don't think that will change until there is serious economic hardship.
- upupandup 4y agoi dont think so. Chinese citizens seems unable to fight back against the military. they have no access to guns, or mass riots will break CCP's will just look at north korea and cuba if you want to get a sense for how long these regimes last. USSR was an exception.
- dx034 4y agoThe Equifax breach also didn't cause riots in the US. I don't see how that's different here.
- khana 4y ago
- nonethewiser 4y agoUltimately the fault lies in the police and government for having this data.
- contingencies 4y agoAnyone care to compose a classical Chinese poem featuring 雲 (cloud)?
- spoonfeeder006 4y agoThis makes me really sad for all those people, especially the people advertised on the sample
- dQw4w9WgXcQ 4y agoExcellent, a fair trade for all the TikTok data Hoover-ing they've been doing on US citizens.
- bell-cot 4y agoKinda interesting that The Register does not even speculate about steps which China's higher-level security services might take in response, to "memorably demonstrate their displeasure" at the theft. (A certain cynical attitude is usually part of The Register's stock-in-trade.)
- dredmorbius 4y agoPerhaps The Register is aware that it cannot out-cynic the Chinese.
- daniel-cussen 4y ago
- freewizard 4y ago- 10 BTC sounds a lot but it's peanuts for such large data sets. - 750k row of sample data is large enough for a leak by itself, many on reddit/twitter/fediverse have already started to explore the data set for gender ratio, age composition and frequency of raping cases, etc.
- rejectfinite 4y ago>many on reddit/twitter/fediverse have already started to explore the data set for gender ratio, age composition and frequency of raping cases, etc. Any links?
- thrdbndndn 4y agoPlenty of Chinese ones in subs like /r/China_irl etc., not seeing much traction of this story/dataset in Western world, though (hell, even on HN it barely got any upvotes 2 days ago.)
- pierrefermat1 4y agoHad a look around on china_irl and couldn't find it, a link would be appreciated!
- thrdbndndn 4y agohttps://www.reddit.com/r/China_irl/comments/vqkfyt/ https://www.reddit.com/r/China_irl/comments/vqkfyt/ https://www.reddit.com/r/China_irl/comments/vr214w/ https://www.reddit.com/r/China_irl/comments/vr214w/ https://www.reddit.com/r/China_irl/comments/vr2lij/ https://www.reddit.com/r/China_irl/comments/vr2lij/ https://www.reddit.com/r/China_irl/comments/vqfwic/ https://www.reddit.com/r/China_irl/comments/vqfwic/ Take these threads with giant grain of salt though, they're far from thorough and some of them lack basic understanding of statistics. And I personally don't think the dataset (at least the sample) is actually random so not really a good representation of China's demographics.
- challenger-derp 4y ago
- hrgiger 4y agoWell I imagine cloud sales teams reaching out haveibeenpwned with attractive storage offers
- m3kw9 4y agoWaiting for a site to search the in 3,2,1
- bamboozled 4y agoSo it was, the great fire wall has been breached..hard.
- nirui 4y ago> While the Shanghai government and police department have largely been silent over the leak, Someone/some team in the police department is probably in serious panic right now. Not only because the data is leaked, but also because the leak has displayed an example of what they are actually recording. For example, according to the posts that other people has posted online (probably rumor and speculations), the `address_merge_with_mobile_data.json` file is a collection of external data submitted to the police database. In the file, there are data source types such as: - shga_dwd.base_shangyun_lhrytbxx_df - shga_dwd.base_wahlw_base_teladsllibrarytab_df - shga_wa.ods_nb_tab_goods - shga_wa.ods_nb_app_icpoof_expressdelivery - shga_wa.ods_nb_app_icpoof_delivery - shga_wa.ods_nb_app_icpoof_expressdelivery - shga_wa.ods_nb_app_icpoof_foodorder That's a lot of data that are not directly related to census, social safety, or law enforcement. I guess if you're ordering food online in China, probably need to give yourself a nice nickname first instead of just using your real name then.
- duxup 4y ago> That's a lot of data that are not directly related to census, social safety, or law enforcement. Is that a … concept in China? That the police should only have data “ directly related to census, social safety, or law enforcement”? I wonder how strange or surprising to locals this might be or maybe not be?
- nirui 4y agoI don't think Chinese people actually cares, most people don't even know what "Data" actually is, let alone how "Data" effects them. The altitude of most people here (I'm a Chinese BTW) is "I did nothing wrong, so why should I care?". But, it's one thing to hear the humor, it's another thing when you can actually see it. People will have different opinions about privacy when their wives asks them why their business trip to another city showed up as a hotel night 500 meters away from home on the government database.
- challenger-derp 4y ago>People will have different opinions about privacy when their wives asks them why their business trip to another city showed up as a hotel night 500 meters away from home on the government database. Had a good chuckle. But then it got me thinking about other situations in which government-leak-induced friction that might lead to cause for legal action. The government demands and collates data presumably supported by legal under-pinnings that citizens must comply with. When these are leaked, shouldn't the government bear legal, fiduciary, etc. responsibility? With great data, comes great responsibility, no?