Hacker News
Substack confirms data breach affects users’ email addresses and phone numbers
dickiedyce
|next
[-]
lostlogin
|root
|parent
|next
[-]
A very specific folk.
Volksgemeinschaft is a German expression meaning "people's community", "folk community", "national community", or "racial community", depending on the translation of its component term Volk.
dxdm
|root
|parent
[-]
> The concept was notoriously embraced by the newly founded Nazi Party in the 1920s, and eventually became strongly associated with Nazism after Adolf Hitler's rise to power.
(From your Wikipedia link.)
BiteCode_dev
|root
|parent
|next
|previous
[-]
And plot twist, they are anti-Trump.
I'm overwhelmed.
PlatoIsADisease
|root
|parent
[-]
Before you would have: Lifelong Red Team Republican(40%), non ideological Opportunists (30%), Ideological Crazies (30%)
Today you have: Lifelong Red Team Republican(40%), non ideological Opportunists (10%), Ideological Crazies For Trump (50%)
The GOP lost that upper-middle class(opportunists) and they lost ideological believers(pre 2016 crazies). Given how fast it was lost, I expect it to come back in some manner, but Trumpism is a cult of personality rather than ideology.
roysting
|root
|parent
[-]
Is not really limited to Trump at all, even though the consequential and public nature of Trump takes everyone’s attention … ironically, with its opponents only feeding that loop in how they oppose it.
It’s a core characteristic of narcissism people rarely understand. Narcissism (individual or system) utterly depends on conflict for its “narcissistic supply”. When you “oppose it”, you are in fact only fueling that which you believe you are opposing. It’s a paradox that people have an impossible time understanding, especially all the people who see “Nazis” everywhere, while openly and violently “protesting” in this supposed “Nazi” regime they’re opposing. Narcissistic control needs that for its manipulation. That is precisely the kind of fuel narcissists love and need and relish with glee as you oppose them, because it means they have you exactly where they want you, emotional and easily manipulated and controlled.
You think the Super Bowl would happen if people stopped living the delusion of “my team” conflict with “not my team”? When you see that stadium full of people, realize that every single one of those thousands of people, will have spent on avg. ~$15,000 per person. It takes manipulation into a state of mental illness to do that. No different than Trump supporters or Nazi fighters or all the other kind of fantasy LARPing that is so pervasive in America, living a life of delusion created for them because it is profitable and makes people easily manipulated.
witnessme
|next
|previous
[-]
parable
|root
|parent
|next
[-]
meitham
|root
|parent
[-]
parable
|root
|parent
[-]
Also, keep in mind that this is a partial leak. The data was scraped from some leaky endpoint which was patched out before every user could be scraped. Only users who were in the partial leak received emails (I have two accounts, only one received an email). If you're a Substack user but didn't receive an email, I'd assume you're not in the leak. Troy Hunt should load it into HIBP eventually, and those concerned can check there if they don't want to seek the leak out on their own.
shawabawa3
|root
|parent
|next
[-]
Well let's find out
I did a tiny bit of research, pretty sure it's BreachForums (https://en.wikipedia.org/wiki/BreachForums)
direwolf20
|root
|parent
[-]
shawabawa3
|root
|parent
[-]
This source claims it's Breach forums but no idea if it's reliable
https://www.bleepingcomputer.com/news/security/newsletter-pl...
chrisjj
|root
|parent
|next
|previous
[-]
Substack PR probably love this. Like a gas tank has a partial leak.
parable
|root
|parent
[-]
Also, to clarify, I don't mean to appear as though I'm discrediting this leak or downplaying its severity. I only mentioned that it was a partial leak to offer an explanation as to why some users received emails and others didn't, as witnessme's comment seemed confused about this.
ntoskrnl_exe
|root
|parent
|next
|previous
[-]
proactivesvcs
|root
|parent
|next
|previous
[-]
ochronus
|root
|parent
|next
|previous
[-]
Mordisquitos
|root
|parent
|previous
[-]
Under GDPR, a business has the obligation to inform users if they have been affected by a data breach. That could hypothetically explain why Substack would inform some users (those protected by GDPRish legislation) while keeping it quiet towards the rest of them.
slopusila
|next
|previous
[-]
> Substack specified that more sensitive data, such as credit card numbers, passwords, and other financial information, was unaffected.
I hate it when companies do this.
passwords and credit card numbers are easily changed.
names, emails and phone numbers are not.
parable
|root
|parent
|next
[-]
The same goes for full names on file, physical addresses, and other hard-to-change information. Passwords have been the least of my concerns since password managers were invented.
You could, in theory, use a custom domain or email aliasing service like SimpleLogin or Addy to combat the email address issue, though websites like GitHub have been known to block emails created with an aliasing service. I could go on about why that move does next to nothing to combat actual abuse; any spammer worth their salt can just buy a bunch of Gmail accounts or Outlook accounts instead.
hikkerl
|root
|parent
|next
[-]
couldn't*
UqWBcuFx6NV4r
|root
|parent
|previous
[-]
jstanley
|root
|parent
|next
[-]
re
|root
|parent
[-]
https://www.merriam-webster.com/grammar/could-couldnt-care-l...
https://dictionary.cambridge.org/dictionary/english/could-ca...
parable
|root
|parent
|next
|previous
[-]
Here are the columns from the CSV file I've seen being shared around on forums, including the "internal metadata". This mostly boils down to full name on file, email, Stripe customer ID, activity metrics, usernames, and phone numbers. Everything else is largely irrelevant.
id,name,email,email_confirmed,email_confirmation_token,stripe_platform_customer_id,is_global_admin,is_ghost,created_at,anonymous_id,email_bounce_count,photo_url,publisher_agreement_accepted_at,bio,updated_at,profile_set_up_at,tos_accepted_at,email_digest_at,has_passed_captcha,import_confirmation_required,post_notification_preference,reader_installed_at,activity_items_viewed_at,dismissed_ios_app_promo_at,email_notifications_last_resumed_at,previous_name,release_group,handle,phone,bank_payment_failures,is_globally_banned,session_version
praptak
|root
|parent
|next
|previous
[-]
BiteCode_dev
|root
|parent
|next
|previous
[-]
A friend of mine received a very well-crafted physical letter at his home about resetting his cryto ledger.
He is now very stressed because there are news about people with crypto getting abducted.
And with the ledger leak they have:
- his name and address
- how much money he has on his ledger
rvz
|root
|parent
|previous
[-]
Surely a list of services that allow phone number logins exists so that one can avoid signing up in the first place and we would then see it in another connecting breach.