TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Russian Gang Said to Amass More Than a Billion Stolen Internet Credentials

192 点作者 GabrielF00将近 11 年前

12 条评论

steven2012将近 11 年前
How much rampant identity theft has to occur before our government admits that it&#x27;s broken? Leaving things like credit ratings in the hands of 3 incompetent companies like Experian, Equifax and Transunion that control our livelihood is an affront to common decency.<p>As a victim of identity theft, and as someone who took extreme measure to protect himself from identity theft before it occurred, I can tell everyone without a doubt that the only reason why you&#x27;re not a victim of identity theft is because of random chance. There is no mechanism to protect yourself, and your information is readily available. The only reason why you haven&#x27;t gotten your identity stolen is because the thieves simply haven&#x27;t gotten to you yet.<p>It&#x27;s infuriating that these companies can get away with what is essential libel and not have anything done to them. I shredded all my mail, I haven&#x27;t given any real information about me on any web site since 1997, never gave out any information about me willy-nilly including applying for too many credit cards, and I never fall for phishing attacks. And yet somehow I found myself victim of identity theft, and it took 2+ years to clean up, and it&#x27;s still not over. Since so many web sites use Experian data to verify my identity, I&#x27;ve lost a lot of opportunity to get credit, loans, etc, because Experian has mixed my information with the fraudulent information, so I get answers to those automated question wrong.<p>It&#x27;s truly infuriating, and the system is completely broken, yet no one in government cares.
评论 #8140277 未加载
评论 #8141433 未加载
评论 #8141067 未加载
评论 #8139593 未加载
评论 #8139962 未加载
评论 #8140798 未加载
smackfu将近 11 年前
Wow, that is some photo the NY Times put on that article.
评论 #8139329 未加载
评论 #8139400 未加载
r0h1n将近 11 年前
Interestingly, Hold Security, the firm that apparently discovered this massive trove of stolen records, has promptly offered a $120 service for those who want to see if they&#x27;re affected: <a href="http://www.forbes.com/sites/kashmirhill/2014/08/05/huge-password-breach-shady-antics/" rel="nofollow">http:&#x2F;&#x2F;www.forbes.com&#x2F;sites&#x2F;kashmirhill&#x2F;2014&#x2F;08&#x2F;05&#x2F;huge-pass...</a>
learc83将近 11 年前
Imagine if they wanted to use this for a terrorist attack, or sold the data to someone who did.<p>If they set up a bot net to log into as many bank accounts as possible and transfer money around (even if it were just between a users own accounts or accounts already setup for transfer), banks would basically be forced to shutdown internet banking until they could come up with a solution. The economic losses would be tremendous--it would take forever to sort out the mess.
评论 #8144402 未加载
RevRal将近 11 年前
  What do you mean that the computer accumulated the personal information of every person on earth?<p>  That’s it. It knows everything about us, and we think it did this consciously. Yes sir, by manipulating people into doing specific things.<p>  What can it do with this information?<p>  Well sir, it is going to do what it can to establish the ability to keep this information as up-to-date as possible. Nobody is able to escape.<p>  The criminal gangs, Russia and Asia. They were the ones behind this?<p>  Yes and no. They each collected enough information and stole it from each other.<p>  We have to warn the world!<p>  We can’t. It controls everything.<p>  What caused this?<p>  A Meta-pattern within the human psyche reached into the computer and in turn used the computer to amplify its own motives.
评论 #8144435 未加载
trhway将近 11 年前
&gt; though the Russian government has not historically pursued accused hackers.<p>between a blogger criticizing Putin&#x27;s regime and a hacker who stole a bunch of millions from an American bank - who do you think the Russian government would go after? :)
评论 #8142613 未加载
评论 #8141486 未加载
评论 #8139837 未加载
joshwa将近 11 年前
FTA:<p>&quot;[T]he Russian hackers have been able to capture credentials on a mass scale using botnets — networks of zombie computers that have been infected with a computer virus — to do their bidding. Any time an infected user visits a website, criminals command the botnet to test that website to see if it is vulnerable to a well-known hacking technique known as a SQL injection, in which a hacker enters commands that cause a database to produce its contents. If the website proves vulnerable, criminals flag the site and return later to extract the full contents of the database.<p>“They audited the Internet,” Mr. Holden said.&quot;
评论 #8139779 未加载
MangezBien将近 11 年前
Is there any report on what services were compromised?
评论 #8139233 未加载
评论 #8141941 未加载
评论 #8139204 未加载
评论 #8141456 未加载
smt88将近 11 年前
I recommend BillGuard or something similar for anyone who is worried about losing payment information. Also, use&#x2F;promote <a href="http://twofactorauth.org" rel="nofollow">http:&#x2F;&#x2F;twofactorauth.org</a>
scoofy将近 11 年前
Before my wall of text, i first understand the difficulties of network effects, getting credit cards accepted world wide, much less state wide, but i think with the advent of square, stripe, paypal, etc. the barriers to launch are much lower than they were even 5 years ago. I&#x27;m sick of banks trying to squeeze every last drop out of the customers, and i&#x27;d gladly pay for a banking service rather than be the product it&#x27;s selling.<p>Credit cards are surviving in the stone age, firms would rather make it easy for you to get yourself in debt that to provide a service that prevents fraud and abuse. So, VC people out there. If you want to make a billion dollars, you should start a bank. People who work for the credit card community, there are simple upgrades that would make life a lot safer.<p>Simple upgrades to make security safer:<p>Chip and pin is low hanging fruit in the US. The fact that most americas have no idea what those threes words mean is an international embarrassment.<p>READ ONLY passwords for bank account information, in addition to different read write options, that have an extra level of security. I&#x27;d gladly use services like Mint, except i&#x27;d rather not give write power to anyone except me and a browser i only user for banking only at home.<p>Tie credit cards to cell phones. Get a text after EVERY purchase (this would honestly not amount to more than 10 or so texts per day). Have this as opt-out, not opt-in. Yes, i would use this, yes it would effectively stunt any fraud. You would not have to respond to the text at all, however, if you suspect fraud, you can immediately cancel the card.<p>Voice recognition for phone calls. When you take out a card, you are require to read a paragraph or two, and upload, or mail in a recording of your voice. This could immediately alleviate much of the phone security nonsense that i deal with when i&#x27;m on the phone. It&#x27;s not a cure all for passwords, but it&#x27;s certainly an additional level of security.<p>IP zones for online credit card purchases. I know about five 100 mile radii that i will be making an online purchase from. Add an extra level of security for any time i&#x27;m outside of that.<p>As far as credit agencies are concerned, there is a serious issue with quasi-oligopoly situations there. Extremely difficult to disrupt, but developing secure credit vehicles could create incentives for the current oligopoly in credit cards to improve security for their own cards.<p>At the end of the day, i&#x27;m more than willing to admit that people themselves are a big part of the problem. Example: a year ago, watching a man freak out on an apple store employee when he would not give a computer to him, that apparently belonged to his son, who gave it to the apple store a week earlier. The son apparently signed off that only he could receive the computer, and only in person. The enraged father was rambling on about how insane it was that they would not surrender the computer to him, and how he would never use apple products again. I wish there were profitable business models for people who actually like following the rules and read the contracts they sign.<p>tl;dr: I don&#x27;t want a credit card that makes it easy for me to spend money. I have cash for that. Give me a credit card that makes me feel safe entering the number into any website, and i&#x27;ll gladly pay a premium for it.
评论 #8142452 未加载
评论 #8140905 未加载
评论 #8140736 未加载
评论 #8141638 未加载
评论 #8144146 未加载
评论 #8141488 未加载
zw123456将近 11 年前
This might be wild speculation but it just makes me wonder what with the recent sanctions against Russia, you just wonder if their government is actually behind it.
评论 #8142100 未加载
评论 #8141489 未加载
jchysk将近 11 年前
This is why everyone needs to use LaunchKey.
评论 #8139456 未加载
评论 #8139510 未加载