‹ BackHN Continuity

Thread

'We hacked the FBI:' Hackers say they have data on all FBI employees

817 points · 614 comments · spenvo

  1. jacobgold · · focus · HN ↗
    At this point, no one seems capable of keeping a large database safe. I assume all medical and biographical information that exists is in the hands of the major state actors.

    China hacked 22.1 million records of US government employees:

    <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;2015_Office_of_Personnel_Management_data_breach" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;2015_Office_of_Personnel_Manag...

    1. titzer · · focus · HN ↗
      And the city wonders why I don&#x27;t want to put my credit card info in their crappy parking app and would instead prefer to put a quarter into the meter for 30 mins.
      1. lotsofpulp · · focus · HN ↗
        What info can be gleaned from that? Surely the mere fact that you have a credit card means your name and billing address are floating around.

        I guess your parking history around town could be valuable if someone is targeting you.

        1. ceejayoz · · focus · HN ↗
          &gt; What info can be gleaned from that?

          The card number?

          1. Barbing · · focus · HN ↗
            In USA, folks who check their statements monthly are at little risk of immediate financial pain there.

            When your lifetime of credit card transactions leaks, that could be financially painful, embarrassing, etc. (can be discriminated against, including with pricing)

            I do dislike creating a log of where I park on some random company’s server. Nice that ALPRs&#x2F;govt.-funded corp spycams&#x2F;Ring&#x2F;etc. make sure the quarter method is minimally marginally effective at protecting privacy.

            1. ceejayoz · · focus · HN ↗
              &gt; In USA, folks who check their statements monthly are at little risk of immediate financial pain there.

              I had to fight a bank for months over a clearly fraudulent charge. Sometimes it&#x27;s easy; other times it isn&#x27;t.

              1. Barbing · · focus · HN ↗
                Yikes, that’s too bad. Have had two incredibly easy chargeback experiences (lifetime).

                Can’t speak to fraudulent bank charges, by the way, only on the credit card side.

          2. chrsstrm · · focus · HN ↗
            In 2026, having my credit card number compromised is the least of my worries. At least here there is an established process for denying charges and ordering a new card. As long as you&#x27;re not using a debit card, this is not a big deal.
            1. dylan604 · · focus · HN ↗
              My bank will reverse debit card charges. Based on that, I assumed that was a standard thing now.
              1. bluGill · · focus · HN ↗
                The problem is debit cards leave a window where you don&#x27;t have access to your own money until it gets reversed.
                1. asdff · · focus · HN ↗
                  What happens with credit card? Is your line of credit reduced until it gets reversed?
                  1. bluGill · · focus · HN ↗
                    Most people have a line of credit for larger than their actual use. With a debit card that&#x27;s coming right out of your account, which means your mortgage, if it comes in before you notice the issue, is going to then fail.

                    This is also partially that people don&#x27;t put critical bills on their credit card typically. And even if your credit card does get maxed out, you typically would have a second credit card handy. But those credit card payments have to come out of your bank account and so you&#x27;re risking that you intend to pay your credit card you said Set whatever it is to send the money in but there&#x27;s no money in your account And so it doesn&#x27;t get paid and now you have late fees on other accounts

                    If your debit card is going to a different bank than what you normally pay all your bills out of, this is not a worry. That is not how most people I know handle their banking though, which is why it is a real problem to worry about.

                    1. rationalist · · focus · HN ↗
                      I put my autopay bills on a credit card that sits in my safe. The only reason it would see a fraudulent charge is if one of the few companies that has the card information, is hacked. And that actually happened once.
                  2. rationalist · · focus · HN ↗
                    My bank just removes the charge if I say it is fraudulent. If I dispute a charge (I made a purchase but the other end didn&#x27;t hold up their end), then my bank gives me a credit until the dispute is resolved.

                    Perhaps not everyone has a good credit card and&#x2F;or bank though, idk.

                2. dylan604 · · focus · HN ↗
                  Only time I&#x27;ve seen that is the stupid holds that hotels do for deposits. The time I had the bank correct a debit card issue had the money available immediately. The only real hold on the account was waiting for the new card to arrive, but the funds were available
            2. pixl97 · · focus · HN ↗
              Ok, your card is compromised. It&#x27;s been cancelled.

              One, how much money is in your pocket so you can eat?

              ok, you&#x27;ll use your second ca.... oh, it has to be cancelled now too.

              Ok, lets wait a few days for another card, and lets go use it the first time, what hacked already, I guess I need to wait a few more days.

              &gt;As long as you&#x27;re not using a debit card, this is not a big deal.

              So screw 60% of all transactions done on a card? This doesn&#x27;t seem workable.

              1. [deleted] · · focus · HN ↗

                [deleted]

              2. lotsofpulp · · focus · HN ↗
                Meh, I’ve been giving out my credit card number willy nilly for 20+ years, and it hasn’t been used without my authorization over the course of what must be tens of thousands of transactions.

                I have a text alert setup for transactions, so I presume I’d be able to successfully challenge any fraudulent ones pretty quickly.

                1. rationalist · · focus · HN ↗
                  Me too. Interestingly my card has only been fraudulently used after I gave it to a waiter at a high-end restaurant, and at a gas pump in a small town.
                  1. xkcd1963 · · focus · HN ↗
                    Please do not comment on fraudulent activities on hackernews that goes against the community guidelines
              3. cyberax · · focus · HN ↗
                Your physical wallet might also get stolen, and you can be left without cash money.

                It&#x27;s a good practice to keep an emergency debit card at home. And&#x2F;or a gift card with a couple hundred bucks on it. That&#x27;s for digital expenses.

                And you should also have a bit of emergency cash.

              4. BenjiWiebe · · focus · HN ↗
                Why do you have to cancel your second card?

                The chance is incredibly small that your second card just happens to get hacked at the same time as your first card.

                I have 6 (I think) credit cards, and mainly use 3 of them.

          3. dylan604 · · focus · HN ↗
            who stores card numbers other than the processors? that should be a hangable offense. I&#x27;ve integrated card processing on multiple sites, and not once does the form come from me. I add the processor&#x27;s JS, and it collects the data to move along. They then return to me a bit of information that includes success&#x2F;fail so that I can decide what to do from there.
            1. ceejayoz · · focus · HN ↗
              &gt; I add the processor&#x27;s JS, and it collects the data to move along.

              Consumers aren&#x27;t gonna notice the difference if the site gets hacked and that JS is swapped out for a malicious set.

              1. pixl97 · · focus · HN ↗
                Yea, it&#x27;s insane seeing this person arguing about the nature of credit card theft when we have a million different examples of how it happens and how rarely the end user knows until it&#x27;s far too late. We almost always learn about itpost ad hoc.
                1. dylan604 · · focus · HN ↗
                  You&#x27;ve moved the goal posts. A typical site isn&#x27;t storing the numbers so when they get hacked, that data is not available. If you&#x27;re suggesting hackers directly injecting malicious JS to hijack card data then that&#x27;s totally different. I&#x27;m not insane about this particular subject. You&#x27;re just standing on a soapbox
                  1. ceejayoz · · focus · HN ↗
                    The parent post just says &quot;I don&#x27;t want to put my credit card info in their crappy parking app&quot;.

                    &quot;I&#x27;m only talking about long-term storage&quot; is a goalpost move!

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.