Page 24 - ARUBA TODAY
P. 24

Friday 8 december 2017 technology
                                     A24

            Have you been ‘pwned’ in a data breach? Troy Hunt can tell




            By MATT O’BRIEN                                                                                                     and  ensuring  the  sensitive
             AP Technology Writer                                                                                               data was passed to us in a
            Troy  Hunt  has  collected                                                                                          secure  manner,”  Roy  Seh-
            a  trove  of  4.8  billion  sto-                                                                                    gal,  Imgur’s  chief  operat-
            len  identity  records  pulled                                                                                      ing officer, said in an email.
            from the darkest corners of                                                                                         PWN ALL THE THINGS
            the internet — but he isn’t                                                                                         Hunt  originally  launched
            a hacker.                                                                                                           his site “as a bit of a curios-
            Instead,  he  uses  that  re-                                                                                       ity,” he said. At the time, he
            pository  to  help  ordinary                                                                                        was a software architect at
            people navigate the grow-                                                                                           pharmaceutical  giant  Pfiz-
            ing  scourge  of  the  cor-                                                                                         er; a few years later, he quit
            porate  data  breach.  All                                                                                          to work as an independent
            that  personal  information                                                                                         information security consul-
            was  originally  taken  from                                                                                        tant and instructor.
            brand-name services such                                                                                            The researcher was analyz-
            as  LinkedIn,  Kickstarter,                                                                                         ing  data  breaches  float-
            Dropbox,  MySpace  and                                                                                              ing  around  the  web  and
            the cheating website Ash-                                                                                           noticed that many people
            ley Madison, and later as-                                                                                          were  turning  up  in  mul-
            sembled by Hunt.                                                                                                    tiple  data  breaches.  “It
            Working  barefoot  and  in                                                                                          struck  me  that  this  was
            beachwear from his home      Troy Hunt, information security author and instructor with Pluralsight, is sworn in before testifying   something  they  probably
            office  on  Australia’s  Gold   during the House Energy and Commerce Subcommittee on Oversight and Investigations hearing   didn’t know,” Hunt said in a
            Coast,  the  amiable  secu-  on Capitol Hill in Washington, Thursday, Nov. 30, 2017.                                phone interview.
            rity  researcher  set  up  his                                                                    Associated Press  People  using  his  site  can
            irreverent  website,  “Have  flows directly into the black   cial media that it’s eroded  one  of  his  sources.  Unlike  search  on  their  email  ad-
            I Been Pwned?” (POHND),  market.  “Data  breaches         traditional   methods   for  Uber, which hid a recently-  dress  to  see  whether  and
            in  2013.  Millions  of  people  are  another  commodity,   verifying  identity,  such  as  disclosed  breach  of  more  where  their  records  have
            have  since  used  the  free  like  heroin,”  Hunt  testified   usernames,  passwords  or  than  57  million  stolen  pas-  been  exposed.  Roughly
            service  to  see  if  hackers  Thursday before the House   knowledge-based     ques-   senger  and  driver  records  1.7 million people also sub-
            have  liberated  their  per-  Energy  and  Commerce       tions  about  birthdays  or  for  a  year,  Imgur  took  just  scribe  to  alerts  that  sound
            sonal  details  from  unwary  Committee.                  family history.              25 hours to go public after  when their details pop up in
            companies  and  posted  UNLIKELY MESSENGER                In  late  November,  Hunt  Hunt emailed the San Fran-     newly  discovered  breach-
            them  online.  Along  the  Hunt’s  unlikely  path  from   helped  discover  a  2014  cisco company on Thanks-       es. The website’s user base
            way,  Hunt  has  become  Queensland’s  Surfers  Par-      breach  of  the  photo-shar-  giving Day.                 has  grown  rapidly  as  big-
            a  close  student  of  data  adise  Beach  to  what  he   ing  website  Imgur  after  “Troy  Hunt  was  extremely  ger data breaches — some
            breaches and the slipshod  describes  as  “fancy  gov-    analyzing  data  from  the  helpful in bringing the data  many  years  old  —  get  at-
            security  that  makes  many  ernment things” on Capitol   hack  passed  along  by  breach  to  our  attention  tention. q
            companies  easy  prey  for  Hill has been a running joke
            attackers.  He’s  exposed  since his invitation to testify
            several such thefts himself,  was  announced.  Virginia   Delivery robots will need
            in  some  cases  identifying  Republican  Rep.  Morgan
            them  before  the  compa-    Griffith, introducing Hunt to   permits to roam San Francisco
            nies themselves did.         lawmakers,  noted  that  he
            AN EPIDEMIC OF PWNAGE        “put  on  a  suit  and  tie  for
            “Pwned”  —  a  deliberate  us when he normally wears      SAN  FRANCISCO  (AP)  —
            misspelling  of  “owned”  —  jeans and a black T-shirt.”  Delivery robots in San Fran-
            is slang used by gamers to  Hunt  said  he  splurged      cisco  will  need  permits
            mean  “utterly  defeated.”  on  the  brand-new  Hugo      before they can roam city
            It’s  an  apt  description  of  Boss  suit  and  Australian   sidewalks  under  legisla-
            what it’s like to have crimi-  outback-style  boots  be-  tion  approved  by  city  su-
            nals  use  your  Social  Se-  cause he didn’t have any-   pervisors.  San  Francisco
            curity  number,  birthdate  thing else to wear. He also   has  struggled  to  regulate
            and other personal details  downloaded  an  app  that     hometown  startups  that
            to  commit  fraud  in  your  instructed  him  on  how  to   grew  too  popular,  includ-
            name.                        tie his necktie.             ing  short-term  vacation
            Hunt  was  invited  to  ap-  “Doing my best ‘no really,   rental platform Airbnb and
            pear  before  Congress  in  I’m  a  professional’  imper-  ride-hailing service Uber.
            late  November  to  help  sonation,”     he    tweeted    Supervisor  Norman  Yee
            lawmakers wrestle with this  from the U.S. Capitol steps   proposed  an  outright  ban
            growing crisis of consumer  shortly before the hearing.   on  delivery  robots  but  set-
            data theft. In just the past  “Did it work?”              tled on a permitting system.   In this Feb. 20, 2017, file photo, a six-wheeled ground delivery
            two  years,  attackers  have  ONCE  MORE  UNTO  THE       The supervisors approved it  robot,  from  Starship  Technologies,  shares  the  sidewalk  with
            stolen sensitive information  BREACH                      Tuesday.                     pedestrians at DuPont Circle in Washington, D.C.
                                                                                                                                           Associated Press
            about hundreds of millions  Of  course,  this  “new  nor-  A  maximum  of  nine  “au-
            of  people  from  the  credit  mal”  of  massive  data    tonomous  delivery  devic-   human  operators  must  be  Marble and Postmates sub-
            bureau  Equifax,  popular  breaches  is  no  joke.  So    es” may be allowed at any  nearby.  The  robots  must  mitted a letter saying they
            online  services  such  as  much  personal  data  has     time in the city.            yield to pedestrians.        welcomed      government
            Uber  and  too  many  other  been  publicly  exposed      The  robots  can’t  go  more  Chief  executives  for  au-  regulations.
            companies to count.          through  both  theft  and    than  3  miles  per  hour  (4.8  tonomous delivery compa-  Other  cities  have  taken
            Much  of  that  stolen  data  voluntary  sharing  on  so-  kilometers  per  hour)  and  nies  Starship  Technologies,  similar steps.q
   19   20   21   22   23   24   25   26   27   28   29