N4ughtySecTU posts old Cell C contract subscriber database, and private ANC member data

"they found an account whose password was “password”"

There is your problem, right there. We all know you should use numbers and special characters. That is why all my passwords are 'password#01'.

Idiots.
Poor form jannie..

P@55w0rd! Is all you nees
 
According to the metadata of the leaked files, the ANC database is from 21 August 2017, while the Cell C database is dated 3 October 2010.
Is MyBB 100% sure that these "hackers" didn't buy those off the dark web (from a real hacker group that got the data years ago and has been selling it ever since)?

N4ughtySecTU is starting to sound like one/both of Zuma's twins (and no I'm not referring to his m00bs).
 
Is MyBB 100% sure that these "hackers" didn't buy those off the dark web (from a real hacker group that got the data years ago and has been selling it ever since)?

This was exactly my thoughts.
 
Well they need to cross reference the leaks, should be easy to do.
The dates of the info they chose to release are suspicious.

They can't, because they most likely did not get the information from Transunion servers. Unless, unless of course, Transunion themselves bought these databases in circulation and integrated the data into their own system and keeping copies of the databases on the server.
 
Credit Beaureaus should not keep anything more than your full name and ID number. Everything else is not required to keep credit records for a person.
 
Credit Beaureaus should not keep anything more than your full name and ID number. Everything else is not required to keep credit records for a person.

So they should not keep your credit payment history? :unsure: What is the purpose of your "full name and ID number" bureau?

And no details like addresses so that red flags can be raised if none of the new credit request info matches?
 
Last edited:
You can view people's passwords?
Nah, like @supersunbird pointed out, and users tend to leave passwords plastered all over their desks and I had to get some of the junior guys to stop setting that as the default when resetting for users etc.
 
My data is already leaked everywhere, I don't need ANOTHER copy sitting on Troy's servers.
Nah -- Troy is very diligent. The sensitive data is hashed using a one-way hash and web requests that deal with sensitive data uses k-anonymity. The service doesn't require or store the data in raw form - it only needs to answer whether the data is in the set of leaked data and not what the exact data is, so hashes is enough.
 
Nah -- Troy is very diligent. The sensitive data is hashed using a one-way hash and web requests that deal with sensitive data uses k-anonymity. The service doesn't require or store the data in raw form - it only needs to answer whether the data is in the set of leaked data and not what the exact data is, so hashes is enough.
and he gets the hashes how? if he's generating them, he has a copy of the raw data to generate them?
 
and he gets the hashes how? if he's generating them, he has a copy of the raw data to generate them?

Of course he has the raw data. It is all stored in MySQL databases.
 
Top
Sign up to the MyBroadband newsletter
X