7 ms·
The unattributable “db8151dd” data breach
- Nextgrid 6y agoFor the people that use unique per-merchant e-mail addresses (like someone+amazon@...), could you try some of those aliases on HaveIBeenPwned and see which ones come up in this breach? That might shed some light onto its origin.
- alias_neo 6y agoThat was my first though, I also use "company@mydomain" sometimes. Too many to go through... if only I could get hold of my record....
- Nextgrid 6y agoI believe HIBP offers domain admins a way to get all their pwned users after domain verification.
- deleted 6y ago[deleted]
- esnard 6y agoInstructions are on this page: https://haveibeenpwned.com/DomainSearch https://haveibeenpwned.com/DomainSearch
- jraph 6y agoFor people who care, it uses reCAPTCHA. I stopped there.
- smichel17 6y agoThanks for saving me a click. No desire to play "guess how many minutes I'll have to spend clicking sidewalks" today.
- noxford1 6y agoIf it takes you minutes to solve a recaptcha your problem might not be the recaptcha...
- throwanem 6y agoYou tend to see a whole lot more challenges if you're on a VPN. It taking a couple of minutes isn't at all implausible.
- eitland 6y agoIt might just be that you use Firefox. Seems anybody who doesn't use Chrome is automatically flagged even if you are logged in with a >12 years old gmail account that is linked to paid storage.
- smichel17 6y agoreCAPTCHA adjusts how many it makes you solve depending on how much info it can gather on you. If I disable my privacy settings & extensions I never need to solve more than 1-2. I'm not usually willing to do that.
- UI_at_80x24 6y ago
- alias_neo 6y agoThat's really useful info, thanks. I'll check it out this weekend.
- edent 6y agoI use unique emails. My record in this breach is just a generic "contact@" address.
- Nextgrid 6y agoCould it be from whois data? Seems like a reasonable place for which to submit such a generic address.
- jerome-jh 6y agoOr could be the spammers sanitized them.
- Scoundreller 6y agoHow would they know which to sanitize???
- deng 6y agoBTW, since many people don't seem to be aware of this: If you have your own domain, you can get informed by haveibeenpwned automatically if any mail address from that domain is in a breach. All that is required is that you're reachable on that domain through an address like 'postmaster'. This feature can be found under 'domain search'. Since I use a new address for pretty much anything this is very handy.
- mysterypie 6y agoI have a large list of unique emails to test, but they are not from a domain I control. It seems that I can test these through the API, but is there any simpler way? I tried obvious things like putting a list of comma-separated email addresses in the search form, but it doesn't work.
- numpad0 6y agoKinda lets adversaries figure which account used which password from which breach and until which point
- pricechild 6y agoThat's a brilliant tip, thank you!
- rpadovani 6y agoWow, thanks, I've never used the notification alert service since I use a custom email for every site I sign up. That's cool, thanks!
- koheripbal 6y agoUnfotunately, it no longer seems to list the impacted email addresses in those domains have been comprimised, so it's not too useful.
- Jestar342 6y agoI've found it does list them if you request the full report, but that the initial email doesn't. (note the last time I used this functionality was about 3 weeks ago, I accept it may have changed since then)
- alberts00 6y agoHaveIBeenPwned now has feature set to find e-mail addresses which were breached under a domain, there is normally no need to search for separate aliases if you own the e-mail domain. https://haveibeenpwned.com/DomainSearch https://haveibeenpwned.com/DomainSearch
- koheripbal 6y agoUnfortunately the email notifications don't tell you WHICH email addresses leaked.
- funnybeam 6y agoYes they do, you just have to click the link in the email and request the full report
- huhtenberg 6y agoI am listed, but it's an address that was never used to register or subscribe to anything online. It's also under a year old. It must've been vacuumed up from other people's contact or email data.
- luckylion 6y agoOr from the email provider, if it's not your own server. I know that e.g. GMX has had a leak at some point (or sold data), as an email I created there ages ago was used in phishing. Okay, that's lame, but they've also used the fake name I had given to GMX, spelled perfectly. I've never used that name anywhere when signing up, so it must come from the database.
- huhtenberg 6y agoI use a private email server.
- StavrosK 6y agoI use the format you mention for almost everything, but my email address in this breach is one I haven't use in something like ten years.
- tinus_hn 6y agoRemember that once you try an email on a service like that, it’s no longer unique to the merchant.
- Qwuke 6y agoIf hibp started using something that guarantees k-anonymity when checking for an email, like their password service does[1], then I think it'd be possible to keep the email unique. 1: https://www.troyhunt.com/ive-just-launched-pwned-passwords-version-2/ https://www.troyhunt.com/ive-just-launched-pwned-passwords-v...
- cr3ative 6y agoIt's got my generic one (firstname@), and an older Facebook login email address (facebook@, changed now since Kickstarter leaked that one). Interesting.
- eganist 6y agoI follow this pattern exclusively, though I haven't actually received any recent HIBP notifications. I'll do a manual check. Edit: three personal domains registered nothing. One corporate domain registered a double digit hit. If I discern any clues I'll get back to the thread.
- willvarfar 6y agoDoes hibp know enough about the regular providers such as gmail that support this, to be able to attribute someone+amazon@gmail.com with someone@gmail.com?
- mattlondon 6y agoMy gmail is on it, but not my burner-domain. So either the data is old (year or two), or they got my gmail from somewhere else. I'd be interested to see the whole dump to see my full record...
- koheripbal 6y agoa year is not "old"
- PanMan 6y agoI did, and I usually use site specific emails (eg amazon@username ) but it found my "generic" firstname@username email... So no insights there.
- simias 6y agoI suspect that Troy Hunt would have noticed if there were many emails with "+someservice" in the dump since he can easily dump them all.
- blauditore 6y agoNot sure of this, because I assume only a tiny fraction of people does this, and those who do probably aren't consistent. E.g. for Amazon Prime, some might use "+amazon-prime", some "+amazonprime", some "+amazon" etc., so there would be very few overall repetitions even in a large data set.
- simias 6y agoRight but grepping for "+" in emails is also high on the list of things I'd do to identify an unknown information dump. Given that he's used to dealing with those I'd be surprised if he hadn't thought of that, although it probably doesn't hurt asking him if he did try it.
- css 6y agoFor me, the HaveIBeenPwned domain search only lists one item in this breach: my LinkedIn@... email. Searching my inbox shows that the only emails sent to that address are from LinkedIn, so it probably came from a company I sent a job application (LinkedIn Easy Apply) to at some point.
- devinegan 6y agoThis. My e-mail in the breach is a LinkedIn specific email. It has to be part of the clue to attribution. Social media scraping, possibly from multiple sources seems to be more likely than another LinkedIn breach.
- VectorLock 6y agoSo many things disallow + in email addresses I don't even bother any more.
- Scoundreller 6y agoOr accepts it at account creation, but not at login!
- multidim 6y agoAll services so far seem to accept dots, but the number of possible dot arrangements can be quite limited, and it is a pain to actually use (figure out next one to use, figure out associated service from dot arrangement, etc).
- VectorLock 6y agoGmail won't let you put anything arbitrary with dots. So if you're whatever@gmail.com you can use what.ever@gmail.com but not whatever+somemerchant@gmail.com. Other email system obviously can work however they want.
- m-p-3 6y agoI'm waiting for Firefox Relay to become available just to better control who has my email address and the flow of emails, but I'm worried it will make the task more difficult to follow breaches. Maybe Mozilla could partner with HaveIBeenPwned to help dealing with that?
- guessmyname 6y ago> Email addresses, Job titles, Names, Phone numbers, Physical addresses, Social media profiles I just got the email notification from HIBP (Have I Been Pwned) a few minutes ago [1], but I am not worried about the compromised data because 1) my personal email address, job title and phone number are all visible in my resume which is publicly available in my website, I actually encourage people —mostly tech recruiters— to download the PDF and contact me via email or phone all the time and 2) my physical address is irrelevant because I have been moving houses every year for the last seven (7) years (even across countries a couple of times. All the social media accounts I have are completely empty, I just keep them around to get a hold on to my nickname. I recently found, in my website’s HTTP logs, several requests from a web crawler controlled by ZoomInfo [3] an American subscription-based software as a service (SaaS) company that sells access to its database of information about business people and companies to sales, marketing and recruiting professionals. I was going to configure my firewall to block these requests but then I remembered —hey! my website only has information I am comfortable sharing, so it doesn’t matter— but I’ve been thinking it is just a matter of time before someone hacks one of their systems and leaks their database. In my previous-previous job I found a fairly simple (persistent) XSS vulnerability in BambooHR that allowed non-authorized users to access data from all employees registered in the website including Social Security Numbers (SSN). I told my boss and we immediately edited everything before migrating to a different system. We never knew if BambooHR fixed the vulnerabilities and I wouldn’t be surprised if the data was leaked before or after I found the security hole. Software security is such a Whac-A-Mole game, even if you get the budget to conduct security audits on your code, there is always going to be a weak link somewhere in the chain and that will be your doom. This is one of the many reasons why I left that job as a Security Engineer, the other reasons were Meltdown [3] and Spectre [4] they both made me realize I was fighting for a lost cause. [1] https://haveibeenpwned.com/NotifyMe https://haveibeenpwned.com/NotifyMe [2] https://en.wikipedia.org/wiki/ZoomInfo https://en.wikipedia.org/wiki/ZoomInfo [3] https://en.wikipedia.org/wiki/Meltdown_%28security_vulnerability%29 https://en.wikipedia.org/wiki/Meltdown_%28security_vulnerabi... [4] https://en.wikipedia.org/wiki/Spectre_%28security_vulnerability%29 https://en.wikipedia.org/wiki/Spectre_%28security_vulnerabil...
- Thoughtful 6y agoOn the BambooHR issue, can you elaborate a bit more?
- r1ch 6y agoIs this dump online anywhere? I got the notification from HIBP but it only tells me my email address appeared and I'm curious how accurate the rest of the data is.
- celticninja 6y agoexactly what I want to check. it's almost expected that at some point my email address is going to end up in a breach, but there is a chance that by reviewing the data I can ascertain where it came from, at least in part .
- esnard 6y ago> Back in Feb, Dehashed reached out to me with a massive trove of data I guess searching on https://www.dehashed.com/ https://www.dehashed.com/ should give you some additional data.
- deleted 6y ago[deleted]
- londons_explore 6y ago> Recommended by Andie [redacted last name]. Arranged for carpenter apprentice Devon [redacted last name] to replace bathroom vanity top at [redacted street address], Vancouver, on 02 October 2007. Given that, surely Troy can contact those people and ask "who knew this info?". Not many people would know who replaced my bathroom vanity top...
- pfundstein 6y agoSure but perhaps Devon used a SAAS CRM system whose servers were breached... Or maybe Andie posted on Devon's public Facebook page to organise the job. Maybe it's just the LinkedIn leaks resurfacing, etc, etc.
- secfirstmd 6y agoOne of my emails is currently on: "Pwned on 19 breached sites and found 5 pastes. If this is public breaches, I would guess in reality I can probably assume it's on double/triple that for sites that have been breached but the data hasn't been posted online.
- numpad0 6y agoCould it be Google+? 3 of 3 my Gmail addresses associated with their profile in some way were on it. Two of it I might have used to register a domain, but the last one I used for G+ and one other website only and none of any friends know this. Also I'm not in US or have US background, can't be from American friends' phones or retailer CRM.
- deleted 6y ago[deleted]
- onefuncman 6y agoThis seems like a winner to me. Iterating a graph along some association explains the ordering mentioned in the blog post, and explains the breadth of connectivity.
- anoncareer0212 6y agoshocked to read this, you can immediately rule it out after reading the article or looking at the sample data
- Jaxkr 6y agoIt’s covve, a free personal crm app
- dgellow 6y ago> Why load it at all? Because every single time I ask about whether I should add data from an unattributable source, the answer is an overwhelming "yes" To be fair, you’re asking your followers on twitter. That’s as biased as you can have, I would be really surprised if the majority would say no.
- onefuncman 6y agoThis is a positive bias IMO, and any negative reactions that bubble up in the replies are going to be more useful.
- SideburnsOfDoom 6y agoI got notified that I'm in this breach, and I honestly don't know what (if anything) I can do with this information, which implies "If it's not actionable, why bother telling me at all?" Unique passwords per site, with a password manager? Done a long time ago. Should I change some of them? OK, which ones? there are hundreds. Details of what else about me is in this breech? Not clear where I can find that.
- ric2b 6y ago> Should I change some of them? OK, which ones? there are hundreds. The ones that you know were pwned. In theory you should change all passwords all the time, but this is a practical middle-ground between that and "never".
- SideburnsOfDoom 6y ago> The ones that you know were pwned. Breaches like this one give no indication of which password is exposed, if any. AFAIK, there is nothing actionable.
- wjnc 6y agoQuestion: It was my understanding that a lawyer could sue the cloud provider for customer details of the cloud service in detail? It would be relevant information in determining liability for leaking this PII.
- wincent 6y agoI don't really get the utility of HIBP. The answer to the "have I been pawned?" question is, of course, yes, multiple times. I think about the only way to keep your email out of the hands of the bad guys is to not use it or give it to anyone ever, at which point you don't need an email address. What am I supposed to do whenever I'm involved in a new breach? Burn all my accounts and start again?
- Normal_gaussian 6y agoThe monitoring service is useful, when a leak is detected you can reset that password. Knowing that you have been historically breached is less useful.. Until I need to convince somebody to start taking account security seriously. Its quite sobering to discover that data breaches are commonplace.
- xondono 6y agoIt depends how many emails do you keep. If you get a hit it’s a good idea to ensure that you keep control of the services related to that address (change passwords, set any extra security measures). I mostly use it through 1Password, because it also notifies you when a service has enabled new security features like 2FA.
- numpad0 6y agoCheck account recovery procedures, change password for that website, check login history and active sessions, see if anyone had done anything that could be done through that credentials, on top of using random generated passwords in the first place. And I think you’re about to describe Sign In with Apple.
- sbarre 6y agoAs the other comment also said, it's a public education service. Remember that most of us on here have extremely advanced knowledge of the Internet and its workings. This is not the case for the vast majority of Internet users.
- koheripbal 6y agoIf you use a password manager to give you unique passwords per site, then these alerts allow you to only change the impacted site's passwords. ...though in a case like this it wouldn't help since we don't know the site.
- forgotmypw23 6y agoThe first thing that comes to mind is recaptcha with some overlays. they would know almost every account you've registered for.
- bluesign 6y agoIt’s contact data from iOS and android phones probably scraped via some malware app/apps
- throwaway9993 6y agoDataset for sale: [redacted] Similar data structure: https://stackblitz.com/edit/angular-soswe4?file=src%2Fapp%2Fapp.component.ts https://stackblitz.com/edit/angular-soswe4?file=src%2Fapp%2F... Owner works for: https://covve.com https://covve.com Covve: This simple yet state-of-the-art app will revolutionise your business relations like you've never seen. Edit: Response: https://twitter.com/covve/status/1261287954967941120 https://twitter.com/covve/status/1261287954967941120
- eganist 6y agoThe responses to the comment just below you (https://news.ycombinator.com/item?id=23190102 https://news.ycombinator.com/item?id=23190102) (and the nature of some of the corporate hits I've seen) seem to be consistent with a contacts database of sorts. Not sure I'd go so far as to accuse a specific company on a public forum. But in this regard, the idea that a contact management app could be behind this DB is plausible.
- eganist 6y agoAdding: this dump appears to be from a source with data at least as recent as April 2019 based on a dataset I'm working with.
- mattlondon 6y agoForked the stackblitz for posterity https://stackblitz.com/edit/angular-3nxvlm?file=src/app/app.component.ts https://stackblitz.com/edit/angular-3nxvlm?file=src/app/app....
- Redoubts 6y agoOh man, what is even going on with that raid forum.
- Nextgrid 6y agoA quick glance suggests there's barely any skill in there and it's all bottom-feeders so you'd expect this to be an easy bust for law enforcement worldwide and yet they seem to be happily operating with total impunity for quite some time.
- cm2187 6y agoDoes elasticsearch have no authentication by default like mongodb or did someone deliberately make it public?
- leetbulb 6y agoNo authentication by default.
- tyingq 6y agoFixed now, but this was a common sequence of events at one time: https://discuss.elastic.co/t/ransom-attack-on-elasticsearch-cluster/71310/18 https://discuss.elastic.co/t/ransom-attack-on-elasticsearch-...
- cm2187 6y agoMy god, it looks even worse than no security by default. It gives you a false sense of security then unlocks in your back when you are not watching.
- alexproto 6y agoHi all, Alex here, CTO at Covve. Just got alerted of incident db8151dd in . We’re investigating as top priority with our security experts what relation this may have with Covve. We are monitoring the feedback in this blog and would really appreciate any additional information you may have on this as we investigate (alex@covve.com).
- deleted 6y ago[deleted]
- service_bus 6y agoIt appears your organization left an elasticsearch database exposed to the internet. This happens frequently due to poor configuration. You're either going to have logs pointing to an IP that the individual used to siphon your data, or nothing. With an exposed elasticsearch database, you possibly had the data being siphoned by many parties, and are only aware now because of this particular incident. If you have any operations regarding customers in Europe, you need to notify your relevant Data Protection Authority https://edpb.europa.eu/about-edpb/board/members_en https://edpb.europa.eu/about-edpb/board/members_en You should also sign your engineers up for this course: https://www.elastic.co/training/specializations/elastic-stack-management/fundamentals-of-securing-elasticsearch https://www.elastic.co/training/specializations/elastic-stac...
- michaelcampbell 6y agoAs of this writing, I don't think it's been determined yet whose organization this data came from, has it? All we have so far is a similarity in data format/structure.
- polote 6y agoAlmost all their employees have their emails in the breach : https://covve.com/about https://covve.com/about email format is <first_character_firstname>.<lastname>@covve.com
- the_mitsuhiko 6y ago
- throwaway834792 6y agoBased on a large (over 50 results) domain search for a company I work for, the data I found was very old, circa 2014. I know this because almost everyone in the domain search stopped working for the company on or after 2014. Everyone else has worked at the company since 2013 or earlier.
- koheripbal 6y agoThe email notification doesnt list the emails impacted. Do you need to rerun the full report to get the details?
- Nextgrid 6y agoIf you run the domain report manually on the HIBP website you get the actual email addresses involved.
- eganist 6y agoHeads up, found at least one match for 2019 from a dataset I'm working with.
- lawnchair_larry 6y agoThat doesn’t set an upper bound on when the breach happened, it sets a lower bound. Old email addresses aren’t deleted by whoever had them. It just means it contains data from at least 2014, up to and including 2019.
- xenophonf 6y agoTroy's fighting the good fight, but it's so freaking depressing. If he has hundreds of millions of records worth of personal data from just the breaches that have been shared with him, what _else_ is out there in the hands of criminals and corporations, neither of which have the public interest at heart—only naked self interest in exploiting members of the public for as much money as they can get?
- cantrevealname 6y ago> what _else_ is out there in the hands of criminals and corporations Don't forget governments. Whatever criminals and corporations have that they shouldn't have, governments probably have an order of magnitude more.
- tialaramex 6y agoMillions per day. This used to be part of one of my old jobs. A feed of stolen PII would drop into our SFTP server every morning and we'd process it. There's no honour among thieves so there were a bunch of duplicates pretending to be "new" data, but yes there is a cottage industry of stealing smaller quantities of PII, focused particularly on email addresses and passwords (because those get re-used elsewhere) and credit card data (because you may be able to either buy something with it or at least fool your way past an immediate check on the card) Do not re-use passwords. Like, that's the really easy "Wash your fucking hands" level lesson here. As someone who isn't employed to work with this data any more I'd say that 99% of the value isn't with like stolen passports (though we did see some passport data) or even credit cards, but the passwords. If you hate that this is even a problem adopt and (if you write code or specify software) implement WebAuthn. Nobody would steal passwords if they didn't work. Not only does stealing WebAuthn credentials from a site's database not work (they're public, the secret that's valuable never leaves the user's FIDO dongle) crooks also wouldn't bother doing it, just like crooks don't steal farm machinery to pull candy vending machines off the wall and steal candy, whereas they do attack ATMs in exactly this way.
- heavenlyblue 6y agoOne of the cool things of having a password manager is that a password manager can’t auto-complete the form for websites not sharing the domain with the old one. If you don’t know the password yourself, then phishing is less effective as it’s quite rare that your password manager forgets that it needs to fill out the form for you.
- polote 6y agoAfter how many breach of ES clusters, Elastic will decide to make their db not accessible from external IP by default ?
- zaat 6y agoThat's the default for a long time already, but people actually want to use it from outside the server and so they configure the listener. https://www.elastic.co/guide/en/elasticsearch/reference/6.3/network.host.html https://www.elastic.co/guide/en/elasticsearch/reference/6.3/...
- outworlder 6y agoEven then, that also means that their machine has a public routable IP and can answer incoming requests from the internet. My question is: why?
- Sebb767 6y agoFor many cloud VMs you spin up, it's the default. Having your servers behind a NAT not only requires a lot more infrastructure knowledge (you need to know you need it and manage access and routing), but also quite a bit more capital investment; i.e. you need to set up a full infrastructure compared to spinning up two+ VMs. That's not to say it's a good thing, but I'm always surprised by the lack of deeper network knowledge by a lot of engineers (and that's not meant degrading - it's not something that you get for free when programming). Lastly, you did probably start the project with a single VM - and at that point it's far harder to say when the point comes to move to a NAT, even more given that getting your second server is probably needed in a sudden spike and the switch is a lot of work with no immediate payoff.
- wnevets 6y agoAm I the only one who dislikes some of those column names? isNonIndividual, IsNonVisibleToOthers, ShowableNonVisibleToOthers
- akersten 6y agoI can smell the enterprise ball-of-mud spaghetti code from here :)
- outworlder 6y agoNegative flags sucks.
- voidmain0001 6y agoFirefox Monitor includes the db8151dd data: https://monitor.firefox.com/?breach=db8151dd https://monitor.firefox.com/?breach=db8151dd
- yahelc 6y agoProbably because they include HIBP data https://www.troyhunt.com/were-baking-have-i-been-pwned-into-firefox-and-1password/ https://www.troyhunt.com/were-baking-have-i-been-pwned-into-...
- tru3_power 6y agoI did some quick searching for the dataformat included in the snippets from the article. Lots of repos with stored secrets that match: https://github.com/acalvoa/SRID_CHANGER/blob/da367e68433b3fd8a3a04e679e3d74b45bc051e3/src/de/micromata/opengis/kml/v_2_2_0/xal/AdministrativeArea.java https://github.com/acalvoa/SRID_CHANGER/blob/da367e68433b3fd... Stored secret: https://github.com/acalvoa/SRID_CHANGER/blob/master/config.properties https://github.com/acalvoa/SRID_CHANGER/blob/master/config.p... Will look more into this later
- amatecha 6y agoEhhh, to me those seem like pretty common fields for any kind of contact data. It doesn't have some of the more unusual or IMO implementation-specific fields like "ShowableNonVisibleToOthers" or "PopulatedCleanNumber", for example.
- typpo 6y agoI use a unique email on my personal domain for everything I sign up for. The email contained in this breach is the one I provided to Facebook. It was probably hacked or sold from one of the handful of apps I've connected with FB over the years.
- killswitched 6y agoSome emails that turned up on my end: Dr. Dobbs and New Relic, although the leaks occurred from parties to whom these sites had provided my data, including at least unique email addresses.
- jonykakarov 6y agowhat I can't understand is that I never heard of this covve app neither most of the affected users in the comment section on reddit or troy website or even here as no one thought of it , and my email does exist on the breach, also the data seem to be huge (103,150,616 rows/90GB)for an app that have about 100k install, need some explanations here.